Agent skill

Intercom Incident Runbook

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Execute Intercom incident response procedures with triage, mitigation, and postmortem.

MITAuto-check passedDevOps & Cloud

Install Intercom Incident Runbook

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill intercom-incident-runbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace intercom-incident-runbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/intercom-incident-runbook .claude/skills/intercom-incident-runbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
intercom-incident-runbook
GitHub stars
2.8k
Token cost
~1.5k tokens
SKILL.md length
572 words
Files
4 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Execute Intercom incident response procedures with triage, mitigation, and postmortem.

  • Works in 6 steps: Assign severity. Match the symptom to… → Triage — is it you or Intercom? Run the… → Decide. If Intercom reports an incident,… → …
  • Responding to Intercom API outages
  • SKILL.md covers Overview, Prerequisites, Severity Levels and Instructions, plus 4 more sections
  • Calls curl, jq and aws; reaches status.intercom.com and api.intercom.io; needs INTERCOM_ACCESS_TOKEN

What it does

Intercom Incident Runbook is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute Intercom incident response procedures with triage, mitigation, and postmortem. Use when responding to Intercom API outages, investigating integration errors, or running post-incident reviews for Intercom failures. Trigger with phrases like "intercom incident", "intercom outage", "intercom down", "intercom on-call", "intercom emergency", "intercom broken".

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/mitigation.md`, `references/templates.md` and `references/triage.md`). Compatibility notes: Designed for Claude Code

It sits in DevOps & Cloud, covering Incident response and Runbooks and postmortems. It works with Intercom. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Responding to Intercom API outages
  • Investigating integration errors
  • Running post-incident reviews for Intercom failures
  • With phrases like intercom incident

Example prompts

  • “intercom incident”
  • “intercom outage”
  • “intercom down”
  • “/intercom-incident-runbook”

Requirements

  • A credential in INTERCOM_ACCESS_TOKEN
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Bash(curl:*), Bash(kubectl:*)

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Assign severity. Match the symptom to the table above; this sets your clock
  2. Triage — is it you or Intercom? Run the first probe to confirm reachability
  3. Decide. If Intercom reports an incident, it is their problem — enable graceful
  4. Mitigate by error type. Apply the matching remediation — token rotation for 401,
  5. Communicate. Post the internal Slack status update on a fixed cadence using the
  6. Write the postmortem. After resolution, fill in the postmortem template

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(curl:*)
    • Bash(kubectl:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq
    • aws
    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • status.intercom.com
    • api.intercom.io

    Also links to:

    • developers.intercom.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • INTERCOM_ACCESS_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Intercom Incident Runbook loads about 1.5k tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 572 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 572 words, ~1,470 tokens.

Download SKILL.mdSave it as .claude/skills/intercom-incident-runbook/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
intercom-incident-runbook
description
Execute Intercom incident response procedures with triage, mitigation, and postmortem. Use when responding to Intercom API outages, investigating integration errors, or running post-incident reviews for Intercom failures. Trigger with phrases like "intercom incident", "intercom outage", "intercom down", "intercom on-call", "intercom emergency", "intercom broken".
allowed-tools
Bash(curl:*), Bash(kubectl:*)
compatibility
Designed for Claude Code
version
1.6.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, support, messaging, intercom

Intercom Incident Runbook

Overview

Rapid incident response procedures for Intercom integration failures. The runbook takes you from alert to resolution in four phases — triage, decision, mitigation, and postmortem — with HTTP-status-code-driven branching so you always know whether the fault is yours or Intercom's. High-level workflow lives here; the full copy-paste scripts and templates live in references/.

Prerequisites

  • INTERCOM_ACCESS_TOKEN exported in your shell (a workspace admin token).
  • curl and jq installed for API + status-page probing.
  • kubectl access to the deployment running your Intercom integration (for restarts).
  • Access to your secret manager (e.g. AWS Secrets Manager) to rotate a compromised token.
  • Developer Hub access for the Intercom app, or a path to escalate to a workspace admin.

Severity Levels

LevelDefinitionResponse TimeExample
P1All Intercom API calls failing< 15 min401 auth failures, API unreachable
P2Degraded service< 1 hourHigh latency, rate limited (429)
P3Partial impact< 4 hoursWebhook delays, search timeouts
P4No user impactNext business dayMonitoring gaps, stale cache

Instructions

Work the phases in order. Each phase links to the full reference when you need depth.

  1. Assign severity. Match the symptom to the table above; this sets your clock and who you page.

  2. Triage — is it you or Intercom? Run the first probe to confirm reachability:

    bash
    curl -s -o /dev/null -w "%{http_code}" \
      -H "Authorization: Bearer $INTERCOM_ACCESS_TOKEN" \
      https://api.intercom.io/me

    Then check status.intercom.com for a platform incident and read the rate-limit headers. The full 5-step diagnostic script and the branch-by-branch decision tree are in references/triage.md.

  3. Decide. If Intercom reports an incident, it is their problem — enable graceful degradation and monitor. If not, it is your integration; branch on the status code: 401 → rotate token, 403 → add OAuth scope, 429 → queue/backoff, 5xx → retry with backoff.

  4. Mitigate by error type. Apply the matching remediation — token rotation for 401, volume reduction for 429, cached-data fallback for 5xx. Full commands (including the aws secretsmanager rotation and the kubectl rollout restart) plus the TypeScript graceful-degradation pattern are in references/mitigation.md.

  5. Communicate. Post the internal Slack status update on a fixed cadence using the template in references/templates.md.

  6. Write the postmortem. After resolution, fill in the postmortem template (timeline, root cause, impact counts, action items) from references/templates.md. Always record Intercom request_ids captured during the incident — Intercom support needs them.

Show full SKILL.md (204 more words)Show less

Output

Working through the runbook produces:

  • A severity classification (P1–P4) with a bounded response clock.
  • A fault verdict — Intercom-side platform incident vs. your integration — backed by the triage script's HTTP codes, status-page state, and rate-limit headers.
  • A mitigation applied for the specific error class (rotated token, paused sync jobs, enabled cache fallback, or retry/backoff).
  • A communication trail — timestamped Slack updates on cadence.
  • A completed postmortem with timeline, root cause, impact counts, captured Intercom request_ids, and owned action items.

Examples

Fast triage during a suspected outage — confirm reachability, then check the platform:

bash
curl -s -o /dev/null -w "API=%{http_code}\n" \
  -H "Authorization: Bearer $INTERCOM_ACCESS_TOKEN" https://api.intercom.io/me
curl -s https://status.intercom.com/api/v2/status.json | jq -r '.status.description'

A 401 with a green status page means your token, not Intercom — jump to the 401 mitigation. The full 5-step diagnostic, the decision tree, per-status mitigation commands, and the Slack/postmortem templates are all in references/:

Error Handling

IssueCauseSolution
Triage script failsToken not setExport INTERCOM_ACCESS_TOKEN
Status page unreachableDNS/networkTry mobile network or VPN
Can't rotate tokenNo Developer Hub accessEscalate to workspace admin
Cache empty during outageNo pre-warmingImplement cache warming job

Resources

For data handling compliance, see intercom-data-handling.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/.curated/intercom-incident-runbook of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/mitigation.md
  • references/templates.md
  • references/triage.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Intercom Incident Runbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Intercom Incident Runbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Intercom Incident Runbook this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.5kAutomated safety check: PassMIT
Oncallpigweed-project/pigweed548—~963Automated safety check: PassApache-2.0
Activation Governance Chaos RolloutAli-Marandi/DataSense107—~1.9kAutomated safety check: PassMIT
Incident Response686f6c61/alfred-dev117—~1.1kAutomated safety check: PassMIT
Superset Incident Triagesuperset-sh/superset15k—~1kAutomated safety check: PassCustom licence
Post-Incident DebriefVeryGoodOpenSource/vgv-wingspan109—~1.9kAutomated safety check: PassMIT

Similar skills

  • Oncall

    pigweed-project/pigweed

    Pigweed oncall rotation runbooks and maintenance workflows (such as rolling CIPD client tools for b/315378787).

    548 GitHub stars~963 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern.

    107 GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Incident Response

    686f6c61/alfred-dev

    Protocolo de respuesta ante incidentes en produccion: triaje, mitigacion, causa raiz y postmortem.

    117 GitHub stars~1.1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Superset Incident Triage

    superset-sh/superset

    Does a read-only first pass on a possible production incident: gathers deploy, Sentry and health-check signals, proposes a severity and status message, then stops for human approval.

    15k GitHub stars~1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Post-Incident Debrief

    VeryGoodOpenSource/vgv-wingspan

    Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh.

    109 GitHub stars~1.9k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • SRE Engineer

    Jeffallan/claude-skills

    Defines SLIs, SLOs and error budgets, and sets up golden-signal monitoring, blameless postmortems, toil automation and chaos experiments for production systems.

    12k GitHub stars~1.7k tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Intercom Incident Runbook

What does Intercom Incident Runbook do?

Execute Intercom incident response procedures with triage, mitigation, and postmortem. Intercom Incident Runbook is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute Intercom incident response procedures with triage, mitigation, and postmortem.

When should I use Intercom Incident Runbook?

Intercom Incident Runbook fits situations like: responding to Intercom API outages; investigating integration errors; running post-incident reviews for Intercom failures; with phrases like intercom incident.

How do I install Intercom Incident Runbook in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill intercom-incident-runbook -a claude-code`. Or copy the skill folder (skills/.curated/intercom-incident-runbook in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/intercom-incident-runbook in your project. Claude Code loads it when a task matches its description.

How do I install Intercom Incident Runbook in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill intercom-incident-runbook -a codex`. Or copy the skill folder (skills/.curated/intercom-incident-runbook in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/intercom-incident-runbook in your project. Codex loads it when a task matches its description.

Can I use Intercom Incident Runbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill intercom-incident-runbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/intercom-incident-runbook, .gemini/skills/intercom-incident-runbook, .github/skills/intercom-incident-runbook and .opencode/skills/intercom-incident-runbook in your project.

What does Intercom Incident Runbook need to run?

Going by SKILL.md and its folder, Intercom Incident Runbook needs the command-line tools its instructions call (curl, jq, aws and kubectl) and credentials named INTERCOM_ACCESS_TOKEN. Our summary lists: A credential in INTERCOM_ACCESS_TOKEN. Its frontmatter pre-approves these tools: Bash(curl:*), Bash(kubectl:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Intercom Incident Runbook access the network?

SKILL.md names 3 domains. In commands or code: status.intercom.com and api.intercom.io; the agent is likely to contact these when it follows the instructions. As links in the text: developers.intercom.com. This is read from the text; nothing was executed.

Is Intercom Incident Runbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Intercom Incident Runbook use?

Intercom Incident Runbook is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Intercom Incident Runbook use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Intercom Incident Runbook?

Skills that share tags, products or a category with Intercom Incident Runbook: Oncall (pigweed-project/pigweed, 548 stars), Activation Governance Chaos Rollout (Ali-Marandi/DataSense, 107 stars), Incident Response (686f6c61/alfred-dev, 117 stars) and Superset Incident Triage (superset-sh/superset, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Intercom Incident Runbook?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.