Agent skill

Incident Slo Runbook

by majiayu000 in majiayu000/spellbook

Create or audit SLOs, SLIs, alert rules, incident response steps, escalation paths, postmortems, operational runbooks, and customer-impact communication.

MITAuto-check passedDevOps & Cloud

Install Incident Slo Runbook

skills CLI
$ npx skills add majiayu000/spellbook --skill incident-slo-runbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install majiayu000/spellbook incident-slo-runbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/incident-slo-runbook .claude/skills/incident-slo-runbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
incident-slo-runbook
GitHub stars
287
Token cost
~460 tokens
SKILL.md length
186 words
Files
2
Skills in repo
97
Repo updated
First seen
Licence
MIT

At a glance

Create or audit SLOs, SLIs, alert rules, incident response steps, escalation paths, postmortems, operational runbooks, and customer-impact communication.

  • Works in 7 steps: User journey or system capability. → SLI: request success, latency,… → SLO target and measurement window. → …
  • Defining production reliability
  • SKILL.md covers Purpose, SLO Design, Runbook Requirements and Incident Flow, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Incident Slo Runbook is an agent skill from majiayu000/spellbook. Create or audit SLOs, SLIs, alert rules, incident response steps, escalation paths, postmortems, operational runbooks, and customer-impact communication. Use when defining production reliability, preparing launch readiness, responding to an outage, writing a runbook, tuning alerts, or closing the loop after an incident.

Its SKILL.md is about 460 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in DevOps & Cloud, covering Runbooks and postmortems, Site reliability engineering and Incident response. The repository describes itself as: Cross-runtime skills for Claude Code, Codex, and multi-agent workflows. The licence is MIT.

When your agent uses it

  • Defining production reliability
  • Preparing launch readiness
  • Responding to an outage
  • Writing a runbook

Example prompts

  • “/incident-slo-runbook”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. User journey or system capability.
  2. SLI: request success, latency, freshness, durability, or job completion.
  3. SLO target and measurement window.
  4. Error budget and burn-rate alerts.
  5. Exclusions with rationale.
  6. Dashboard and data source.
  7. Owner and escalation path.

What it can do on your machine

Read from SKILL.md and the folder at commit ed52af7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Incident Slo Runbook loads about 460 tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 186 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~460

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from majiayu000/spellbook at commit ed52af7, republished under its MIT licence (© majiayu000). 186 words, ~460 tokens.

Download SKILL.mdSave it as .claude/skills/incident-slo-runbook/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
incident-slo-runbook
description
Create or audit SLOs, SLIs, alert rules, incident response steps, escalation paths, postmortems, operational runbooks, and customer-impact communication. Use when defining production reliability, preparing launch readiness, responding to an outage, writing a runbook, tuning alerts, or closing the loop after an incident.

Incident SLO Runbook

Purpose

Use this skill to connect observability to action. Metrics and logs are not enough; each critical user journey needs an SLO, alert, owner, response path, and post-incident learning loop.

SLO Design

Define:

  1. User journey or system capability.
  2. SLI: request success, latency, freshness, durability, or job completion.
  3. SLO target and measurement window.
  4. Error budget and burn-rate alerts.
  5. Exclusions with rationale.
  6. Dashboard and data source.
  7. Owner and escalation path.

Avoid vanity metrics. Prefer user-visible success and latency over internal counters unless internal counters are the only reliable proxy.

Runbook Requirements

Each runbook should include:

  • Symptom and alert name.
  • Impacted users or systems.
  • First 5-minute checks.
  • Triage decision tree.
  • Mitigation steps with commands.
  • Rollback or failover path.
  • Escalation owner.
  • Customer/support communication note.
  • Postmortem trigger.

Commands must be safe to run or explicitly labeled destructive.

Incident Flow

  1. Declare severity and incident commander.
  2. Confirm impact from live evidence.
  3. Stabilize with the lowest-risk mitigation.
  4. Communicate status on a fixed cadence.
  5. Preserve evidence before cleanup.
  6. Write a blameless postmortem with action items and owners.

Output Shape

text
service_or_journey:
slo:
alerts:
dashboard_or_queries:
runbook:
escalation:
postmortem_template:
verification:

© majiayu000, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/incident-slo-runbook of majiayu000/spellbook.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit ed52af7

Compare with similar skills

Incident Slo Runbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Incident Slo Runbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Incident Slo Runbook this skillmajiayu000/spellbook287—~460Automated safety check: PassMIT
SRE EngineerJeffallan/claude-skills12k—~1.7kAutomated safety check: PassMIT
Incident ResponderDokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI508—~706Automated safety check: PassCustom licence
Eng Runbooksanqiufong/slides-from-anything1321 repos~380Automated safety check: PassApache-2.0
Incident Commanderborghei/Claude-Skills891—~1.8kAutomated safety check: PassMIT
Langchain Incident Runbookjeremylongshore/tons-of-skills-marketplace2.8k—~3.8kAutomated safety check: PassMIT

Similar skills

  • SRE Engineer

    Jeffallan/claude-skills

    Defines SLIs, SLOs and error budgets, and sets up golden-signal monitoring, blameless postmortems, toil automation and chaos experiments for production systems.

    12k GitHub stars~1.7k tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Incident Responder

    Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI

    Expert SRE incident responder specializing in rapid problem resolution.

    508 GitHub stars~706 tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Eng Runbook

    sanqiufong/slides-from-anything

    An engineering runbook — service overview, alerts table, dashboards links, common procedures with copy-pasteable commands, on-call rotation, and an incident-response checklist.

    132 GitHub starsUsed in 1 repo~380 tokens
    DevOps & CloudAuto-check passed
  • Incident Commander

    borghei/Claude-Skills

    Production incident response. An agent skill from borghei/Claude-Skills.

    891 GitHub stars~1.8k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Langchain Incident Runbook

    jeremylongshore/tons-of-skills-marketplace

    Triage LangChain 1.0 / LangGraph 1.0 production incidents — LLM-specific SLOs, provider outage runbook, latency spike decision tree, cost-overrun response, agent loop containment.

    2.8k GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Makes systems debuggable and reliably operable — instrumentation, alerting that is worth waking for, service objectives, and learning from failure.

    2k GitHub stars~931 tokensUpdated 23 days ago
    DevOps & CloudAuto-check passed

More from majiayu000/spellbook

All 97 skills in this repo
  • Skill Ecosystem Doctor

    majiayu000/spellbook

    Audits and repairs how coding-agent Skills are owned, copied and exposed across runtimes, from canonical sources to quarantine and retirement.

    287 GitHub stars~3k tokensUpdated 2 days ago
    Auto-check passed
  • AGENTS.md Scaffold

    majiayu000/spellbook

    Scans a repository for real evidence and proposes, or on request writes, a small stack of root and scoped AGENTS.md files with validation commands and generated-file boundaries.

    287 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Product Demo Builder

    majiayu000/spellbook

    Plans, produces or diagnoses evidence-backed product demo videos: script, capture plan, pacing checks and verified final media built on real product behavior.

    287 GitHub stars~3.3k tokensUpdated 2 days ago
    Auto-check passed
  • Flowguard Task Guard

    majiayu000/spellbook

    Single entry point that routes long or ambiguous agent tasks, checks live state, bounds autonomous loops and leaves a resumable handoff.

    287 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Product Manager Toolkit

    majiayu000/spellbook

    Product management helpers: a RICE scoring script, an interview transcript analyzer and PRD templates for prioritizing features, synthesizing research and writing requirements.

    287 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Incident Slo Runbook

What does Incident Slo Runbook do?

Create or audit SLOs, SLIs, alert rules, incident response steps, escalation paths, postmortems, operational runbooks, and customer-impact communication. Incident Slo Runbook is an agent skill from majiayu000/spellbook. Create or audit SLOs, SLIs, alert rules, incident response steps, escalation paths, postmortems, operational runbooks, and customer-impact communication.

When should I use Incident Slo Runbook?

Incident Slo Runbook fits situations like: defining production reliability; preparing launch readiness; responding to an outage; writing a runbook.

How do I install Incident Slo Runbook in Claude Code?

Run `npx skills add majiayu000/spellbook --skill incident-slo-runbook -a claude-code`. Or copy the skill folder (skills/incident-slo-runbook in majiayu000/spellbook) into .claude/skills/incident-slo-runbook in your project. Claude Code loads it when a task matches its description.

How do I install Incident Slo Runbook in Codex?

Run `npx skills add majiayu000/spellbook --skill incident-slo-runbook -a codex`. Or copy the skill folder (skills/incident-slo-runbook in majiayu000/spellbook) into .agents/skills/incident-slo-runbook in your project. Codex loads it when a task matches its description.

Can I use Incident Slo Runbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add majiayu000/spellbook --skill incident-slo-runbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/incident-slo-runbook, .gemini/skills/incident-slo-runbook, .github/skills/incident-slo-runbook and .opencode/skills/incident-slo-runbook in your project.

What does Incident Slo Runbook need to run?

SKILL.md names no scripts, command-line tools or credentials: Incident Slo Runbook is instructions for the agent only.

Does Incident Slo Runbook access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Incident Slo Runbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Incident Slo Runbook use?

Incident Slo Runbook is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Incident Slo Runbook use?

About 460 tokens (SKILL.md is roughly 1.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Incident Slo Runbook?

Skills that share tags, products or a category with Incident Slo Runbook: SRE Engineer (Jeffallan/claude-skills, 12k stars), Incident Responder (Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI, 508 stars), Eng Runbook (sanqiufong/slides-from-anything, 132 stars) and Incident Commander (borghei/Claude-Skills, 891 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Incident Slo Runbook?

majiayu000 (a GitHub user) maintains it in majiayu000/spellbook, which has 287 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 8, 2026.

Source: majiayu000/spellbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.