Agent skill

Ticket Triage

by sandbaseai in sandbaseai/sandbase-skills

Triage and prioritize a support ticket or customer issue. An agent skill from sandbaseai/sandbase-skills.

Apache-2.0Auto-check passedSales & Support

Install Ticket Triage

skills CLI
$ npx skills add sandbaseai/sandbase-skills --skill ticket-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sandbaseai/sandbase-skills ticket-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sandbaseai/sandbase-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/marketing/ticket-triage .claude/skills/ticket-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ticket-triage
GitHub stars
203
Token cost
~3.1k tokens
SKILL.md length
1,297 words
Files
2 (incl. references)
Skills in repo
23
Repo updated
First seen
Licence
Apache-2.0

At a glance

Triage and prioritize a support ticket or customer issue. An agent skill from sandbaseai/sandbase-skills.

  • Works in 6 steps: Parse the Issue → Categorize and Prioritize → Check for Duplicates and Known Issues → …
  • A new ticket comes in and needs categorization
  • SKILL.md covers Usage, Workflow, Category Taxonomy and Priority Framework, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ticket Triage is an agent skill from sandbaseai/sandbase-skills. Triage and prioritize a support ticket or customer issue. Use when a new ticket comes in and needs categorization, assigning P1-P4 priority, deciding which team should handle it, or checking whether it's a duplicate or known issue before routing.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/sandbase-api-map.md`).

It sits in Sales & Support, covering Customer support. The repository describes itself as: 88 installable open-source Agent Skills for research, social intelligence, marketing, and business workflows—compatible with Codex, Claude Code, Cursor, Gemini CLI, and DeepSeek… The licence is Apache-2.0.

When your agent uses it

  • A new ticket comes in and needs categorization
  • Assigning P1-P4 priority
  • Deciding which team should handle it
  • Checking whether its a duplicate

Example prompts

  • “/ticket-triage”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Parse the Issue
  2. Categorize and Prioritize
  3. Check for Duplicates and Known Issues
  4. Determine Routing
  5. Generate Triage Output
  6. Offer Next Steps

What it can do on your machine

Read from SKILL.md and the folder at commit cbab581. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ticket Triage loads about 3.1k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 1,297 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sandbaseai/sandbase-skills at commit cbab581, republished under its Apache-2.0 licence (© sandbaseai). 1,297 words, ~3,086 tokens.

Download SKILL.mdSave it as .claude/skills/ticket-triage/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
ticket-triage
description
Triage and prioritize a support ticket or customer issue. Use when a new ticket comes in and needs categorization, assigning P1-P4 priority, deciding which team should handle it, or checking whether it's a duplicate or known issue before routing.

/ticket-triage

Use only support, knowledge-base, and project-tracker sources that are actually available and authorized in the host. State clearly when a source was not checked.

Categorize, prioritize, and route an incoming support ticket or customer issue. Produces a structured triage assessment with a suggested initial response.

When checking public documentation or known-issue evidence, read the SandBase API map. Resolve the listed capability with sandbase_discover, inspect its returned name with sandbase_inspect, then follow execute_as to call sandbase_run(name: "<returned name>", arguments: { ... }) using only the current schema. For async results, poll sandbase_run_get with the returned run_id within the task budget; report pending or failed runs without automatically resubmitting them.

Usage

/ticket-triage <ticket text, customer message, or issue description>

Examples:

  • /ticket-triage Customer says their dashboard has been showing a blank page since this morning
  • /ticket-triage "I was charged twice for my subscription this month"
  • /ticket-triage User can't connect their SSO — getting a 403 error on the callback URL
  • /ticket-triage Feature request: they want to export reports as PDF

Workflow

1. Parse the Issue

Read the input and extract:

  • Core problem: What is the customer actually experiencing?
  • Symptoms: What specific behavior or error are they seeing?
  • Customer context: Who is this? Any account details, plan level, or history available?
  • Urgency signals: Are they blocked? Is this production? How many users affected?
  • Emotional state: Frustrated, confused, matter-of-fact, escalating?
2. Categorize and Prioritize

Using the category taxonomy and priority framework below:

  • Assign a primary category (bug, how-to, feature request, billing, account, integration, security, data, performance) and an optional secondary category
  • Assign a priority (P1–P4) based on impact and urgency
  • Identify the product area the issue maps to
3. Check for Duplicates and Known Issues

Before routing, check available sources:

  • Support platform: Search for similar open or recently resolved tickets when available
  • Knowledge base: Check for known issues or existing documentation when available
  • Project tracker: Check if there's an existing bug report or feature request when available

Apply the duplicate detection process below. If none of these sources is available, mark duplicate and known-issue status as Not checked; never report “no duplicate” merely because no search was run.

4. Determine Routing

Using the routing rules below, recommend which team or queue should handle this based on category and complexity.

5. Generate Triage Output
## Triage: [One-line issue summary]

**Category:** [Primary] / [Secondary if applicable]
**Priority:** [P1-P4] — [Brief justification]
**Product area:** [Area/team]

### Issue Summary
[2-3 sentence summary of what the customer is experiencing]

### Key Details
- **Customer:** [Name/account if known]
- **Impact:** [Who and what is affected]
- **Workaround:** [Available / Not available / Unknown]
- **Related tickets:** [Links to similar issues if found]
- **Known issue:** [Yes — link / No — searched sources / Not checked / Checking]

### Routing Recommendation
**Route to:** [Team or queue]
**Why:** [Brief reasoning]

### Suggested Initial Response
[Draft first response to the customer — acknowledge the issue,
set expectations, provide workaround if available.
Use the auto-response templates below as a starting point.]

### Internal Notes
- [Any additional context for the agent picking this up]
- [Reproduction hints if it's a bug]
- [Escalation triggers to watch for]
6. Offer Next Steps

After presenting the triage:

  • "Want me to draft a full response to the customer?"
  • "Should I search for more context on this issue?"
  • "Want me to check if this is a known bug in the tracker?"
  • "Should I prepare an escalation package with the available evidence?"

Category Taxonomy

Assign every ticket a primary category and optionally a secondary category:

CategoryDescriptionSignal Words
BugProduct is behaving incorrectly or unexpectedlyError, broken, crash, not working, unexpected, wrong, failing
How-toCustomer needs guidance on using the productHow do I, can I, where is, setting up, configure, help with
Feature requestCustomer wants a capability that doesn't existWould be great if, wish I could, any plans to, requesting
BillingPayment, subscription, invoice, or pricing issuesCharge, invoice, payment, subscription, refund, upgrade, downgrade
AccountAccount access, permissions, settings, or user managementLogin, password, access, permission, SSO, locked out, can't sign in
IntegrationIssues connecting to third-party tools or APIsAPI, webhook, integration, connect, OAuth, sync, third-party
SecuritySecurity concerns, data access, or compliance questionsData breach, unauthorized, compliance, GDPR, SOC 2, vulnerability
DataData quality, migration, import/export issuesMissing data, export, import, migration, incorrect data, duplicates
PerformanceSpeed, reliability, or availability issuesSlow, timeout, latency, down, unavailable, degraded
Category Determination Tips
  • If the customer reports both a bug and a feature request, the bug is primary
  • If they can't log in due to a bug, category is Bug (not Account) — root cause drives the category
  • "It used to work and now it doesn't" = Bug
  • "I want it to work differently" = Feature request
  • "How do I make it work?" = How-to
  • When in doubt, lean toward Bug — it's better to investigate than dismiss

Priority Framework

Use the organization's documented SLA when available. The response times below are illustrative defaults and should not be presented as a customer commitment unless authorized.

P1 — Critical

Criteria: Production system down, data loss or corruption, security breach, all or most users affected.

  • The customer cannot use the product at all
  • Data is being lost, corrupted, or exposed
  • A security incident is in progress
  • The issue is worsening or expanding in scope

SLA expectation: Respond within 1 hour. Continuous work until resolved or mitigated. Updates every 1-2 hours.

P2 — High

Criteria: Major feature broken, significant workflow blocked, many users affected, no workaround.

  • A core workflow is broken but the product is partially usable
  • Multiple users are affected or a key account is impacted
  • The issue is blocking time-sensitive work
  • No reasonable workaround exists

SLA expectation: Respond within 4 hours. Active investigation same day. Updates every 4 hours.

Show full SKILL.md (498 more words)Show less
P3 — Medium

Criteria: Feature partially broken, workaround available, single user or small team affected.

  • A feature isn't working correctly but a workaround exists
  • The issue is inconvenient but not blocking critical work
  • A single user or small team is affected
  • The customer is not escalating urgently

SLA expectation: Respond within 1 business day. Resolution or update within 3 business days.

P4 — Low

Criteria: Minor inconvenience, cosmetic issue, general question, feature request.

  • Cosmetic or UI issues that don't affect functionality
  • Feature requests and enhancement ideas
  • General questions or how-to inquiries
  • Issues with simple, documented solutions

SLA expectation: Respond within 2 business days. Resolution at normal pace.

Priority Escalation Triggers

Automatically bump priority up when:

  • Customer has been waiting longer than the SLA allows
  • Multiple customers report the same issue (pattern detected)
  • The customer explicitly escalates or mentions executive involvement
  • A workaround that was in place stops working
  • The issue expands in scope (more users, more data, new symptoms)

Routing Rules

Route tickets based on category and complexity:

Route toWhen
Tier 1 (frontline support)How-to questions, known issues with documented solutions, billing inquiries, password resets
Tier 2 (senior support)Bugs requiring investigation, complex configuration, integration troubleshooting, account issues
EngineeringConfirmed bugs needing code fixes, infrastructure issues, performance degradation
ProductFeature requests with significant demand, design decisions, workflow gaps
SecurityData access concerns, vulnerability reports, compliance questions
Billing/FinanceRefund requests, contract disputes, complex billing adjustments

Duplicate Detection

Before creating a new ticket or routing, check available sources for duplicates:

  1. Search by symptom: Look for tickets with similar error messages or descriptions
  2. Search by customer: Check if this customer has an open ticket for the same issue
  3. Search by product area: Look for recent tickets in the same feature area
  4. Check known issues: Compare against documented known issues

If a duplicate is found:

  • Recommend linking the new ticket to the existing one
  • Draft a customer notification that this is a known issue being tracked
  • Recommend adding any new information from the new report to the existing ticket
  • Bump priority if the new report adds urgency (more customers affected, etc.)

Perform those external updates only when the user explicitly requests and authorizes them.

Auto-Response Templates by Category

Bug — Initial Response
Thank you for reporting this. I can see how [specific impact]
would be disruptive for your work.

I've classified this as a [priority] issue for investigation.
[If workaround exists: "In the meantime, you
can [workaround]."]

I'll update you within [SLA timeframe] with what we find.
How-to — Initial Response
Great question! [Direct answer or link to documentation]

[If more complex: "Let me walk you through the steps:"]
[Steps or guidance]

Let me know if that helps, or if you have any follow-up
questions.
Feature Request — Initial Response
Thank you for this suggestion — I can see why [capability]
would be valuable for your workflow.

I've documented this for product-team review.
While I can't commit to a specific timeline, your feedback
directly informs our roadmap priorities.

[If alternative exists: "In the meantime, you might find
[alternative] helpful for achieving something similar."]
Billing — Initial Response
I understand billing issues need prompt attention. Let me
look into this for you.

[If straightforward: resolution details]
[If complex: "I'm reviewing your account now and will have
an answer for you within [timeframe]."]
Security — Initial Response
Thank you for flagging this — we take security concerns
seriously and are reviewing this immediately.

This should be escalated to the security team for investigation.
We'll follow up with you within [timeframe] with our findings.

[If action is needed: "In the meantime, we recommend
[protective action]."]

Triage Best Practices

  1. Read the full ticket before categorizing — context in later messages often changes the assessment
  2. Categorize by root cause, not just the symptom described
  3. When in doubt on priority, err on the side of higher — it's easier to de-escalate than to recover from a missed SLA
  4. Check available sources for duplicates and known issues before routing; otherwise mark the check as not performed
  5. Write internal notes that help the next person pick up context quickly
  6. Include what you've already checked or ruled out to avoid duplicate investigation
  7. Flag patterns — if you're seeing the same issue repeatedly, escalate the pattern even if individual tickets are low priority

© sandbaseai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in marketing/ticket-triage of sandbaseai/sandbase-skills.

  • SKILL.md
  • references/sandbase-api-map.md

Open the folder on GitHubat commit cbab581

Compare with similar skills

Ticket Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ticket Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ticket Triage this skillsandbaseai/sandbase-skills203—~3.1kAutomated safety check: PassApache-2.0
Siftranknoperator/siftrank225—~2.9kAutomated safety check: PassMIT
Supporthaacked/dotfiles134—~2.9kAutomated safety check: PassNone
Customer Support Agentmastra-ai/mastra29k—~2.2kAutomated safety check: PassCustom licence
Add Agent Adaptersafedep/gryph172—~679Automated safety check: PassApache-2.0
Agent Support Matrixjazzyalex/agent-sessions895—~587Automated safety check: PassMIT

Similar skills

  • Siftrank

    noperator/siftrank

    Find needles in haystacks with SiftRank. An agent skill from noperator/siftrank.

    225 GitHub stars~2.9k tokensUpdated 20 days ago
    Sales & SupportAuto-check passed
  • Support

    haacked/dotfiles

    Support hero workflow — start a ticket investigation with auto-organized notes, find existing notes, or generate the weekly highlights log.

    134 GitHub stars~2.9k tokensUpdated today
    Sales & SupportAuto-check passed
  • Customer Support Agent

    mastra-ai/mastra

    Authoring playbook for building agents that triage and reply to customer messages — support tickets, email inquiries, chat questions, refund requests, or product issues.

    29k GitHub stars~2.2k tokensUpdated today
    Sales & SupportAuto-check passed
  • Add Agent Adapter

    safedep/gryph

    A skill your agent uses when adding support for a new AI coding agent to Gryph, or when changing how an existing agent adapter is wired.

    172 GitHub stars~679 tokensUpdated 4 days ago
    Sales & SupportAuto-check passed
  • Agent Support Matrix

    jazzyalex/agent-sessions

    Maintain Agent Sessions agent support matrix and JSON/JSONL parsing compatibility.

    895 GitHub stars~587 tokensUpdated yesterday
    Sales & SupportAuto-check passed
  • Company Brain Company QA

    topoteretes/cognee

    Build one company memory from a SQL database, a support ticket export and a folder of documents, linked into one graph by cognee, then answer questions that need several of those sources together.

    32k GitHub stars~750 tokensUpdated today
    Sales & SupportAuto-check: notes

More from sandbaseai/sandbase-skills

All 23 skills in this repo
  • Multi Source Search

    sandbaseai/sandbase-skills

    Portable multi-source research with cross-source validation and an offline evidence ledger.

    203 GitHub stars~1.6k tokensUpdated 14 days ago
    Auto-check passed
  • Academic Research

    sandbaseai/sandbase-skills

    Search academic papers, scholarly articles, and research publications through SandBase.

    203 GitHub stars~586 tokensUpdated 14 days ago
    Auto-check passed
  • Brand Monitoring

    sandbaseai/sandbase-skills

    Monitor brand mentions, sentiment, and reputation across Twitter, Reddit, news, and social platforms through SandBase.

    203 GitHub stars~696 tokensUpdated 14 days ago
    Auto-check passed
  • Cash Flow Snapshot

    sandbaseai/sandbase-skills

    Create a 30/60/90-day cash-flow forecast from AR, AP, opening cash, payment timing, and fixed-cost data.

    203 GitHub stars~1.9k tokensUpdated 14 days ago
    Auto-check passed
  • Competitor Monitor

    sandbaseai/sandbase-skills

    Monitor competitor websites, content changes, social activity, and market positioning through SandBase.

    203 GitHub stars~701 tokensUpdated 14 days ago
    Auto-check passed
  • Exa Deep Search

    sandbaseai/sandbase-skills

    Search, extract, and compare high-quality public sources with Exa through SandBase.

    203 GitHub stars~2k tokensUpdated 14 days ago
    Auto-check passed

Categories

Questions about Ticket Triage

What does Ticket Triage do?

Triage and prioritize a support ticket or customer issue. An agent skill from sandbaseai/sandbase-skills. Ticket Triage is an agent skill from sandbaseai/sandbase-skills. Triage and prioritize a support ticket or customer issue.

When should I use Ticket Triage?

Ticket Triage fits situations like: A new ticket comes in and needs categorization; assigning P1-P4 priority; deciding which team should handle it; checking whether its a duplicate.

How do I install Ticket Triage in Claude Code?

Run `npx skills add sandbaseai/sandbase-skills --skill ticket-triage -a claude-code`. Or copy the skill folder (marketing/ticket-triage in sandbaseai/sandbase-skills) into .claude/skills/ticket-triage in your project. Claude Code loads it when a task matches its description.

How do I install Ticket Triage in Codex?

Run `npx skills add sandbaseai/sandbase-skills --skill ticket-triage -a codex`. Or copy the skill folder (marketing/ticket-triage in sandbaseai/sandbase-skills) into .agents/skills/ticket-triage in your project. Codex loads it when a task matches its description.

Can I use Ticket Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sandbaseai/sandbase-skills --skill ticket-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ticket-triage, .gemini/skills/ticket-triage, .github/skills/ticket-triage and .opencode/skills/ticket-triage in your project.

What does Ticket Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Ticket Triage is instructions for the agent only.

Does Ticket Triage access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ticket Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ticket Triage use?

Ticket Triage is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ticket Triage use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 253 tokens, read only when the agent opens those files.

What are the alternatives to Ticket Triage?

Skills that share tags, products or a category with Ticket Triage: Siftrank (noperator/siftrank, 225 stars), Support (haacked/dotfiles, 134 stars), Customer Support Agent (mastra-ai/mastra, 29k stars) and Add Agent Adapter (safedep/gryph, 172 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ticket Triage?

sandbaseai (a GitHub organization) maintains it in sandbaseai/sandbase-skills, which has 203 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 26, 2026.

Source: sandbaseai/sandbase-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.