Agent skill

Automated Triage

by sickn33 in sickn33/agentic-awesome-skills

Triage Monte Carlo alerts interactively or build an automated workflow.

Apache-2.0Auto-check passedAgent Workflows

Install Automated Triage

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill automated-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills automated-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/automated-triage .claude/skills/automated-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
automated-triage
GitHub stars
47k
Used in
1 other repo
Token cost
~3.2k tokens
SKILL.md length
1,720 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
Apache-2.0

At a glance

Triage Monte Carlo alerts interactively or build an automated workflow.

  • Works in 4 steps: Check MCP tools → Determine intent → Run the workflow (Branch B only) → …
  • Tasks that involve MCP servers
  • SKILL.md covers When to activate this skill, When NOT to activate this skill, Available MCP tools and How to approach automated triage, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Automated Triage is an agent skill from sickn33/agentic-awesome-skills. Triage Monte Carlo alerts interactively or build an automated workflow. Fetch, score, and troubleshoot alerts using MCP tools now, or design a reusable workflow that runs on a schedule.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers and CI/CD. It works with Model Context Protocol. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve MCP servers
  • Tasks that involve CI/CD

Example prompts

  • “/automated-triage”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Check MCP tools
  2. Determine intent
  3. Run the workflow (Branch B only)
  4. Wrap up

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Automated Triage loads about 3.2k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 1,720 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its Apache-2.0 licence (© sickn33). 1,720 words, ~3,203 tokens.

Download SKILL.mdSave it as .claude/skills/automated-triage/SKILL.md (or your agent's skills folder).
name
automated-triage
description
Triage Monte Carlo alerts interactively or build an automated workflow. Fetch, score, and troubleshoot alerts using MCP tools now, or design a reusable workflow that runs on a schedule.
risk
critical
source
https://github.com/monte-carlo-data/mc-agent-toolkit/tree/main/skills/automated-triage
source_repo
monte-carlo-data/mc-agent-toolkit
source_type
community
date_added
2026-07-01
license
Apache-2.0
license_source
https://github.com/monte-carlo-data/mc-agent-toolkit/blob/main/LICENSE

Monte Carlo Automated Triage

This skill helps you design, test, and deploy an automated triage agent for Monte Carlo alerts. Rather than a fixed workflow, it gives you the building blocks — a set of MCP tools, a description of each triage stage, and a working example — so you can build a process that matches how your team actually responds to alerts.

Monte Carlo tool routing (required): Always call Monte Carlo MCP tools through this plugin's bundled server, whose fully-qualified tool names are mcp__plugin_mc-agent-toolkit_monte-carlo-mcp__<tool> (e.g. mcp__plugin_mc-agent-toolkit_monte-carlo-mcp__get_alerts). Bare tool names used in this skill (get_alerts, search, get_table, …) refer to that bundled server. If the session also has a separately-configured monte-carlo-mcp server, do not route to it — it may point at a different endpoint or credentials.

Read the reference files before proceeding:

  • Triage stages and customisation: references/triage-stages.md (relative to this file)
  • Working example workflow: references/triage-example.md (relative to this file)

When to activate this skill

Activate when the user:

  • Wants to triage or investigate recent Monte Carlo alerts (interactively or automated)
  • Wants to set up automated triage for Monte Carlo alerts
  • Asks to run agentic triage or investigate recent alert activity
  • Wants to understand what triage tools are available and how to use them
  • Is building or refining a triage prompt for their environment
  • Wants to move from manual alert review to automated or semi-automated triage

When NOT to activate this skill

Do not activate when the user is:

  • Investigating a specific known incident (help them directly)
  • Creating or configuring monitors (use the monitoring-advisor skill)
  • Running impact analysis before a code change (use the prevent skill)

Available MCP tools

All tools are available via the monte-carlo-mcp MCP server.

ToolToolsetPurpose
get_alertsdefaultFetch recent alerts for a time window
alert_assessmentdefaultScore an alert by incident likelihood and potential impact (HIGH/MEDIUM/LOW each)
run_troubleshooting_agentdefaultRun the Monte Carlo Troubleshooting Agent on a single alert; async by default — returns immediately, reuses existing results when available
get_troubleshooting_agent_resultsdefaultPoll an async troubleshooting run by incident_id; returns status (not_found/running/success/failed) and results when complete
update_alertdefaultUpdate an alert's status and/or declare an incident by setting severity
set_alert_ownerdefaultAssign an owner to an alert by email
create_or_update_alert_commentdefaultPost or update a triage comment on an alert
mark_event_as_normaldefaultMark all anomaly events in an alert as normal, triggering ML threshold recalibration to prevent re-alerting on the same pattern

How to approach automated triage

Read references/triage-stages.md for a full description of each stage and how to customise it. The high-level flow is:

  1. Fetch alerts — decide which alerts to triage and over what time window
  2. Initial investigation — score every alert by incident likelihood and potential impact using alert_assessment
  3. Deep troubleshooting — run run_troubleshooting_agent on high-signal alerts to get root cause analysis
  4. Classify — use the troubleshooting output to classify each alert
  5. Take actions — post comments, update statuses, message Slack, create tickets

The triage process is not fixed. Read the stages reference to understand the options and tradeoffs at each step, then design a workflow that fits your team's needs.

The longer-term direction

Most teams move through roughly the same arc, though the pace and path vary:

  • Start with recommendations. Run manually and have the agent post comments describing what it found and what it would do — no actual status changes or external actions. Use this to tune the workflow until the output matches how your team would respond manually.
  • Automate, still in recommendation mode. Once the output looks right, put it on a schedule. Keep it in recommendation mode while you validate it's behaving well on real traffic.
  • Replace recommendations with actions. When you're confident, swap the comment recommendations for real actions — status updates, Slack messages, ticket creation.

Don't force this progression — it's a direction, not a checklist. The path will depend on how your environment behaves and how much trust you want to build before each step.


Activation flow

When this skill is activated, follow this sequence in order.

Step 1: Check MCP tools

Verify that get_alerts, alert_assessment, and run_troubleshooting_agent are accessible. If any are missing, check that the Monte Carlo MCP server is configured and authenticated, then stop.

Step 2: Determine intent

Ask:

"Are you looking to triage some alerts right now (I'll investigate them with you using the triage tools), or set up / refine an automated triage workflow (I'll help you design a process that can run on a schedule)?"

If the user's request already makes the intent clear — e.g. "triage my freshness alerts from today" vs. "help me build a triage workflow" — skip the question and proceed directly.


Branch A: Interactive triage

The user wants to look at specific alerts now. Use the triage tools directly to investigate and report findings. Do not frame this as workflow-building.

  1. Clarify the scope (Ask about the time window and whether the user is interested in a specific domain, audience or alert type).
  2. Fetch alerts with get_alerts (applying any domain or audience filter from step 1), run alert_assessment in parallel on all of them, and report the results clearly.
  3. For any alert where both incident likelihood and potential impact are MEDIUM or higher, offer to run run_troubleshooting_agent for a deeper root cause analysis. Wait for confirmation before running it.
  4. Summarise findings. Do not prompt to save a workflow file or set up automation unless the user brings it up.

Write tools in interactive triage: After findings are clear, proactively offer relevant actions — updating status, declaring a severity, assigning an owner, posting a comment, or marking events as normal (for alerts that are natural data variation). Ask before executing.


Show full SKILL.md (792 more words)Show less
Branch B: Automated workflow

The user wants to build, test, or refine a triage workflow that can run on a schedule.

Ask how they'd like to get started:

"How would you like to approach this?

  • Use the built-in example — start from a working triage workflow ready to run as-is and adapt it as you go.
  • Adapt an existing workflow — point me to a file you already have and we'll review and run it.
  • Build from scratch — describe what you want your triage to do and I'll help design a workflow tailored to it."

Using the built-in example:

  1. Read references/triage-example.md (relative to this skill file). Give a brief description: it fetches alerts from the last 3 hours, scores every alert, runs deep troubleshooting on high-signal ones, and shows what actions it would take — no writes on a first run.
  2. Run in recommendation mode, step by step (see Step 3). No need to ask.

Adapting an existing file:

  1. Read the file and confirm the key settings: time window, filter threshold, and whether it includes a mode-selection step.
  2. Summarise what it will do, then ask: "Run straight through, or step through each stage one at a time? And recommendation or action mode?"

Building from scratch:

  1. Ask the user to describe what they want: which alerts to triage, what actions they want to take, how much they want to automate, and any constraints (e.g. specific domains, teams, or tables).
  2. Draw on references/triage-stages.md to propose a workflow structure that fits their goals. Present it for review — not as a finished document, but as a proposed approach — and iterate until they're happy.
  3. Run it step by step in recommendation mode (see Step 3) so they can validate each stage before committing to the design. Expect to refine as you go.
Step 3: Run the workflow (Branch B only)

Execute the workflow from the file, following its instructions exactly. Do not improvise steps or add actions not described in the file.

Action guard — workflow mode: Never call write tools (update_alert, set_alert_owner, create_or_update_alert_comment) while building or testing a workflow, regardless of what the workflow document says. Only describe what would be done. This guard exists to prevent accidental writes on real alerts during development; lift it only when the user explicitly switches to action mode for a production run.

For first runs (starting fresh): always run step by step — after each stage completes, summarise what it produced, proactively suggest alternatives or adjustments based on what you observed, and wait for confirmation before continuing.

At each stage, draw on the options in references/triage-stages.md to make concrete suggestions:

  • After fetching alerts — suggest filter adjustments if the set looks too broad or narrow: NOT_ACKNOWLEDGED to skip already-triaged alerts, domain/audience filters if alerts span multiple teams, a slightly longer time window for the initial testing if we need more examples to work with.
  • After scoring — Suggest whether to adjust the troubleshooting filter (e.g. run when either score is HIGH, not just both MEDIUM+) or tune alert_assessment via user_instructions.
  • After troubleshooting — if the TSA found a clear root cause, suggest whether to declare an incident severity, assign an owner.
  • After actions — note cases where the default action mapping may not fit, e.g. a verified incident that warrants a Slack message or ticket rather than just a status update.

For existing-file runs: use whichever mode the user chose in Step 2.

Step 4: Wrap up

After the workflow completes:

  1. Ask: "Want me to save a copy of our workflow to your project (e.g. triage.md) so you can customise it?" If yes, write it to the path they choose.

  2. Then present next steps based on what just happened and what you were asked to do in the first place. For example:

    "What would you like to do next?

    • Refine the workflow — walk through the stages and tune what's not working (filter, scoring weights, troubleshooting threshold, action mapping)
    • Test on a different alert set — re-run on a different time window or day to see how it handles a different set of alerts
    • Set up a schedule — automate this to run on a fixed cadence using the /schedule skill
    • Something else — just tell me"

    Adapt the options to context — if the run had many LOW-scoring alerts with no troubleshooting, lean towards refinement; if results looked solid, lean towards scheduling.

Example

User request:

Triage the latest Monte Carlo alerts, group related incidents, and identify the most likely root cause and owner.

Limitations

  • Use this skill only when the task clearly matches its upstream source and local project context.
  • Verify commands, generated code, dependencies, credentials, and external service behavior before applying changes.
  • Do not treat examples as a substitute for environment-specific tests, security review, or user approval for destructive or costly actions.

© sickn33, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/automated-triage of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Automated Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Automated Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Automated Triage this skillsickn33/agentic-awesome-skills47k1 repos~3.2kAutomated safety check: PassApache-2.0
Claude Docs Consultantcentminmod/my-claude-code-setup2.7k—~959Automated safety check: PassMIT
PolygraphBankrBot/skills1.2k—~3.4kAutomated safety check: PassNone
Neon Postgres Branchesneondatabase/agent-skills100—~3.4kAutomated safety check: NotesApache-2.0
Docs Tooling Notionlangchain-ai/docs426—~1.7kAutomated safety check: PassMIT
ReleaseWebMCP-org/npm-packages104—~1.6kAutomated safety check: NotesMIT

Similar skills

  • Claude Docs Consultant

    centminmod/my-claude-code-setup

    Consult official Claude Code documentation from code.claude.com using selective fetching.

    2.7k GitHub stars~959 tokensUpdated 3 days ago
    Agent WorkflowsAuto-check passed
  • Polygraph

    BankrBot/skills

    Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills.

    1.2k GitHub stars~3.4k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Neon Postgres Branches

    neondatabase/agent-skills

    Official

    Choose and create the right Neon branch type for testing and development.

    100 GitHub stars~3.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Docs Tooling Notion

    langchain-ai/docs

    Official

    Document new or changed docs-team tooling on the Notion tooling pages.

    426 GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Release

    WebMCP-org/npm-packages

    Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions.

    104 GitHub stars~1.6k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Azsdk Common Pipeline Analysis

    Azure/azure-sdk-tools

    Official

    Analyze Azure SDK CI/CD pipeline failures into a structured diagnosis, and define the required output format.

    134 GitHub stars~1.2k tokensUpdated yesterday
    Testing & QAAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Automated Triage

What does Automated Triage do?

Triage Monte Carlo alerts interactively or build an automated workflow. Automated Triage is an agent skill from sickn33/agentic-awesome-skills. Triage Monte Carlo alerts interactively or build an automated workflow.

When should I use Automated Triage?

Automated Triage fits situations like: tasks that involve MCP servers; tasks that involve CI/CD.

How do I install Automated Triage in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill automated-triage -a claude-code`. Or copy the skill folder (skills/automated-triage in sickn33/agentic-awesome-skills) into .claude/skills/automated-triage in your project. Claude Code loads it when a task matches its description.

How do I install Automated Triage in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill automated-triage -a codex`. Or copy the skill folder (skills/automated-triage in sickn33/agentic-awesome-skills) into .agents/skills/automated-triage in your project. Codex loads it when a task matches its description.

Can I use Automated Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill automated-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/automated-triage, .gemini/skills/automated-triage, .github/skills/automated-triage and .opencode/skills/automated-triage in your project.

What does Automated Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Automated Triage is instructions for the agent only.

Does Automated Triage access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Automated Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Automated Triage use?

Automated Triage is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Automated Triage use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Automated Triage?

Skills that share tags, products or a category with Automated Triage: Claude Docs Consultant (centminmod/my-claude-code-setup, 2.7k stars), Polygraph (BankrBot/skills, 1.2k stars), Neon Postgres Branches (neondatabase/agent-skills, 100 stars) and Docs Tooling Notion (langchain-ai/docs, 426 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Automated Triage?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.