Agent skill

Windsurf Incident Runbook

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Execute Devin Desktop (formerly Windsurf) incident response when AI features fail or cause production issues.

MITAuto-check passedDevOps & Cloud

Install Windsurf Incident Runbook

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-incident-runbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace windsurf-incident-runbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/windsurf-incident-runbook .claude/skills/windsurf-incident-runbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windsurf-incident-runbook
GitHub stars
2.8k
Token cost
~2k tokens
SKILL.md length
367 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Execute Devin Desktop (formerly Windsurf) incident response when AI features fail or cause production issues.

  • Works in 6 steps: Immediate Mitigation → Identify Root Cause → Fix and Validate → …
  • Cascade breaks code
  • SKILL.md covers Overview, Prerequisites, Tool Use and Instructions, plus 11 more sections
  • Calls git, npm and curl; reaches status.windsurf.com

What it does

Windsurf Incident Runbook is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute Devin Desktop (formerly Windsurf) incident response when AI features fail or cause production issues. Use when Cascade breaks code, Windsurf service is down, AI-generated code causes production incidents, or team needs emergency Windsurf troubleshooting. Trigger with phrases like "windsurf incident", "windsurf outage", "windsurf broke production", "cascade caused bug", "windsurf emergency".

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Designed for Claude Code

It sits in DevOps & Cloud, covering Incident response and Runbooks and postmortems. It works with Git. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Cascade breaks code
  • Windsurf service is down
  • AI-generated code causes production incidents
  • Team needs emergency Windsurf troubleshooting

Example prompts

  • “windsurf incident”
  • “windsurf outage”
  • “windsurf broke production”
  • “/windsurf-incident-runbook”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Grep, Bash(git:*), Bash(curl:*)

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Immediate Mitigation
  2. Identify Root Cause
  3. Fix and Validate
  4. Confirm and Communicate
  5. Team Notification
  6. Workarounds During Outage

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Bash(git:*)
    • Bash(curl:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • status.windsurf.com

    Also links to:

    • windsurf.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Windsurf Incident Runbook loads about 2k tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 367 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 367 words, ~2,017 tokens.

Download SKILL.mdSave it as .claude/skills/windsurf-incident-runbook/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
windsurf-incident-runbook
description
Execute Devin Desktop (formerly Windsurf) incident response when AI features fail or cause production issues. Use when Cascade breaks code, Windsurf service is down, AI-generated code causes production incidents, or team needs emergency Windsurf troubleshooting. Trigger with phrases like "windsurf incident", "windsurf outage", "windsurf broke production", "cascade caused bug", "windsurf emergency".
allowed-tools
Read, Grep, Bash(git:*), Bash(curl:*)
compatibility
Designed for Claude Code
argument-hint
[scope or requirements]
version
1.12.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, windsurf, incident-response, runbook, troubleshooting

Windsurf Incident Runbook

Overview

Incident response procedures for Windsurf-related issues: Cascade service outages, AI-generated code causing bugs, and team workflow disruptions.

Prerequisites

  • Access to Windsurf dashboard and status page
  • Git access to affected repositories
  • Team communication channel (Slack, Teams)

Tool Use

  • Use Read to inspect only the repository files and configuration needed for the request.
  • Use Grep to locate relevant settings, rules, logs, or code without broad collection.
  • Use only the command-scoped Bash entries declared in frontmatter, with non-destructive checks before mutations.

Instructions

  1. Classify severity and assign an incident commander.
  2. Preserve evidence, stop unsafe automation, and check the official service status.
  3. Use the matching playbook below; prefer a reviewed revert through the protected delivery path.
  4. Validate recovery with production health signals and record follow-up owners.

Severity Levels

LevelDefinitionResponse TimeExamples
P1Production broken by AI code< 15 minCascade-generated code deployed with critical bug
P2Team workflow blocked< 1 hourWindsurf service outage, all Cascade down
P3Degraded AI features< 4 hoursSlow Cascade, Supercomplete intermittent
P4Minor inconvenienceNext business daySpecific model unavailable, feature regression

Quick Triage Decision Tree

Is Windsurf service itself down?
├─ YES: Check https://status.windsurf.com
│   ├─ Status page shows incident → WAIT for Windsurf to resolve
│   │   Action: Switch to manual coding, notify team
│   └─ Status page green → Local issue
│       Action: Restart Windsurf, check internet, re-authenticate
│
└─ NO: Did AI-generated code cause a production issue?
    ├─ YES → P1 INCIDENT
    │   1. Revert the deployment immediately
    │   2. Identify the Cascade-generated commit(s)
    │   3. Fix manually or with targeted Cascade prompt
    │   4. Post-incident: update review policy
    │
    └─ NO: Is Cascade giving bad suggestions?
        ├─ YES → Check .devin/rules/project.md, start fresh Cascade session
        └─ NO → See windsurf-common-errors

P1 Playbook: AI Code Caused Production Bug

Step 1: Immediate Mitigation
bash
set -euo pipefail
# Revert the deployment
git log --oneline -10  # Find the bad commit(s)

# On a dedicated incident branch created through the normal repository process:
git revert HEAD --no-edit  # Revert the confirmed bad commit
git status --short

# If multiple Cascade commits:
git revert --no-commit HEAD~3..HEAD  # Revert last 3 commits
git commit -m "revert: undo cascade changes causing [issue]"
# Push the incident branch and use the protected emergency PR/deploy lane.
Step 2: Identify Root Cause
bash
# Find all Cascade-generated commits
git log --all --oneline --grep="cascade" --since="1 week ago"
git log --all --oneline --grep="\[cascade\]" --since="1 week ago"

# Compare before/after
git diff [last-good-commit]..HEAD -- src/

# Common root causes:
# 1. Cascade modified shared utility used by many modules
# 2. Cascade changed error handling (swallowed exceptions)
# 3. Cascade "optimized" code that had intentional behavior
# 4. Cascade introduced dependency on newer API version
Step 3: Fix and Validate
bash
set -euo pipefail
git checkout -b fix/cascade-revert
# Make targeted fix
npm test
npm run typecheck
# Deploy to staging first

P2 Playbook: Windsurf Service Outage

Step 1: Confirm and Communicate
bash
# Check Windsurf status
curl -sf https://status.windsurf.com || echo "Status page unreachable"
Step 2: Team Notification
Team notification template:

Windsurf AI features are currently unavailable.
Status: https://status.windsurf.com

Impact: Cascade and Supercomplete are not working.
Workaround: Continue coding manually. Windsurf still works as a
standard VS Code editor — only AI features are affected.

ETA: Monitoring status page for updates.
Show full SKILL.md (145 more words)Show less
Step 3: Workarounds During Outage
markdown
1. Windsurf still works as VS Code (file editing, terminal, git)
2. Extensions still work (ESLint, Prettier, debugger)
3. Only Cascade, Supercomplete, and Command mode are down
4. Continue coding manually until service restores
5. Do NOT switch to a different editor mid-task (context loss)

P3 Playbook: Degraded AI Features

markdown
Symptoms and fixes:

Slow Cascade → Start fresh session, reduce workspace size
No Supercomplete → Check status bar widget, verify enabled
Wrong model → Check quota and policy state, then select an available model
MCP disconnected → Restart MCP servers (Command Palette)
Indexing stuck → Download diagnostics, then use the current indexing reset control

Post-Incident Actions

Evidence Collection
bash
set -euo pipefail
# Collect relevant data
mkdir incident-$(date +%Y%m%d)
git log --since="1 day ago" --stat > incident-$(date +%Y%m%d)/commits.txt
cp .devin/rules/project.md incident-$(date +%Y%m%d)/ 2>/dev/null || true
# See windsurf-debug-bundle for full diagnostic collection
Postmortem Template
markdown
## Incident: [Title]
**Date:** YYYY-MM-DD
**Duration:** X hours Y minutes
**Severity:** P[1-4]

### Summary
[1-2 sentence description]

### Timeline
- HH:MM — [Event]
- HH:MM — [Event]

### Root Cause
[Was this an AI-generated code issue? Windsurf service issue? Config issue?]

### What Went Wrong
- [ ] AI-generated code not reviewed thoroughly
- [ ] Missing tests for AI-modified code
- [ ] .devin/rules/project.md didn't prevent the bad pattern
- [ ] Cascade modified shared code without constraint

### Action Items
- [ ] Update .devin/rules/project.md to prevent this pattern
- [ ] Add test coverage for affected module
- [ ] Update team Cascade usage policy
- [ ] Add CI gate for AI-modified code

Output

Maintain an incident record with severity, commander, timeline, affected revision, containment action, recovery evidence, customer impact, and follow-up owners. Never place credentials or sensitive source in the record, and never bypass protected-branch controls for speed.

Error Handling

IssueImmediate ActionLong-Term Fix
AI code in prod broke featureGit revert + redeployEnforce test gates for Cascade commits
Windsurf service downCode manuallyNo action needed — external service
AI modified protected filesGit revert those filesAdd to .codeiumignore
Team lost work from CascadeRecover from git historyEnforce pre-Cascade git commit policy

Examples

Quick Health Check
bash
curl -sf https://status.windsurf.com | head -5 || echo "WINDSURF STATUS UNREACHABLE"
Find Recent Cascade Commits
bash
git log --all --oneline --since="7 days ago" | grep -i cascade

Resources

Continue with windsurf-data-handling when the incident involves sensitive context, retention questions, diagnostic evidence, or regulated-data exposure.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/windsurf-incident-runbook of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Windsurf Incident Runbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windsurf Incident Runbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windsurf Incident Runbook this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT
GreptimeDB Release RunbookGreptimeTeam/greptimedb6.7k—~1.4kAutomated safety check: PassApache-2.0
Oncallpigweed-project/pigweed548—~963Automated safety check: PassApache-2.0
Activation Governance Chaos RolloutAli-Marandi/DataSense107—~1.9kAutomated safety check: PassMIT
Incident Response686f6c61/alfred-dev117—~1.1kAutomated safety check: PassMIT
Superset Incident Triagesuperset-sh/superset15k—~1kAutomated safety check: PassCustom licence

Similar skills

  • GreptimeDB Release Runbook

    GreptimeTeam/greptimedb

    Runbook for publishing a GreptimeDB version: pick the release branch, verify the Cargo version, then tag, create the GitHub release and open the docs note PR.

    6.7k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Oncall

    pigweed-project/pigweed

    Pigweed oncall rotation runbooks and maintenance workflows (such as rolling CIPD client tools for b/315378787).

    548 GitHub stars~963 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern.

    107 GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Incident Response

    686f6c61/alfred-dev

    Protocolo de respuesta ante incidentes en produccion: triaje, mitigacion, causa raiz y postmortem.

    117 GitHub stars~1.1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Superset Incident Triage

    superset-sh/superset

    Does a read-only first pass on a possible production incident: gathers deploy, Sentry and health-check signals, proposes a severity and status message, then stops for human approval.

    15k GitHub stars~1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Release Process

    scragnog/HOT-Step-CPP

    Runbook for cutting and publishing a HOT-Step CPP release via a v git tag that triggers the multi-platform CI build and drafts a GitHub Release.

    174 GitHub stars~5.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Windsurf Incident Runbook

What does Windsurf Incident Runbook do?

Execute Devin Desktop (formerly Windsurf) incident response when AI features fail or cause production issues. Windsurf Incident Runbook is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute Devin Desktop (formerly Windsurf) incident response when AI features fail or cause production issues.

When should I use Windsurf Incident Runbook?

Windsurf Incident Runbook fits situations like: cascade breaks code; windsurf service is down; AI-generated code causes production incidents; team needs emergency Windsurf troubleshooting.

How do I install Windsurf Incident Runbook in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-incident-runbook -a claude-code`. Or copy the skill folder (skills/.curated/windsurf-incident-runbook in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/windsurf-incident-runbook in your project. Claude Code loads it when a task matches its description.

How do I install Windsurf Incident Runbook in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-incident-runbook -a codex`. Or copy the skill folder (skills/.curated/windsurf-incident-runbook in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/windsurf-incident-runbook in your project. Codex loads it when a task matches its description.

Can I use Windsurf Incident Runbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-incident-runbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windsurf-incident-runbook, .gemini/skills/windsurf-incident-runbook, .github/skills/windsurf-incident-runbook and .opencode/skills/windsurf-incident-runbook in your project.

What does Windsurf Incident Runbook need to run?

Going by SKILL.md and its folder, Windsurf Incident Runbook needs the command-line tools its instructions call (git, npm and curl). Its frontmatter pre-approves these tools: Read, Grep, Bash(git:*), Bash(curl:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Windsurf Incident Runbook access the network?

SKILL.md names 2 domains. In commands or code: status.windsurf.com; the agent is likely to contact it when it follows the instructions. As links in the text: windsurf.com. This is read from the text; nothing was executed.

Is Windsurf Incident Runbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windsurf Incident Runbook use?

Windsurf Incident Runbook is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windsurf Incident Runbook use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 97 tokens, read only when the agent opens those files.

What are the alternatives to Windsurf Incident Runbook?

Skills that share tags, products or a category with Windsurf Incident Runbook: GreptimeDB Release Runbook (GreptimeTeam/greptimedb, 6.7k stars), Oncall (pigweed-project/pigweed, 548 stars), Activation Governance Chaos Rollout (Ali-Marandi/DataSense, 107 stars) and Incident Response (686f6c61/alfred-dev, 117 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windsurf Incident Runbook?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.