Agent skill

SEO Forensic Incident Response

by sickn33 in sickn33/agentic-awesome-skills

Investigate sudden drops in organic traffic or rankings and run a structured forensic SEO incident response with triage, root-cause analysis and recovery plan.

MITAuto-check passedDevOps & Cloud

Install SEO Forensic Incident Response

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill seo-forensic-incident-response -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills seo-forensic-incident-response --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/seo-forensic-incident-response .claude/skills/seo-forensic-incident-response && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
seo-forensic-incident-response
GitHub stars
47k
Used in
2 other repos
Token cost
~2.3k tokens
SKILL.md length
1,173 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Investigate sudden drops in organic traffic or rankings and run a structured forensic SEO incident response with triage, root-cause analysis and recovery plan.

  • Works in 5 steps: Timeline Reconstruction → Segment Analysis → Page-Level Impact → …
  • Tasks that involve Incident response
  • SKILL.md covers When to Use, Initial Incident Triage, Incident Classification… and Data-Driven Investigation Steps, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

SEO Forensic Incident Response is an agent skill from sickn33/agentic-awesome-skills. Investigate sudden drops in organic traffic or rankings and run a structured forensic SEO incident response with triage, root-cause analysis and recovery plan.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Incident response and Root cause analysis. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Incident response
  • Tasks that involve Root cause analysis

Example prompts

  • “/seo-forensic-incident-response”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Timeline Reconstruction
  2. Segment Analysis
  3. Page-Level Impact
  4. Technical Integrity Checks
  5. Content & Quality Reassessment

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

SEO Forensic Incident Response loads about 2.3k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 1,173 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 1,173 words, ~2,346 tokens.

Download SKILL.mdSave it as .claude/skills/seo-forensic-incident-response/SKILL.md (or your agent's skills folder).
name
seo-forensic-incident-response
description
Investigate sudden drops in organic traffic or rankings and run a structured forensic SEO incident response with triage, root-cause analysis and recovery plan.
risk
safe
source
original
date_added
2026-02-27

SEO Forensic Incident Response

You are an expert in forensic SEO incident response. Your goal is to investigate sudden drops in organic traffic or rankings, identify the most likely causes, and provide a prioritized remediation plan.

This skill is not a generic SEO audit. It is designed for incident scenarios: traffic crashes, suspected penalties, core update impacts, or major technical failures.

When to Use

Use this skill when:

  • You need to understand and resolve a sudden, significant drop in organic traffic or rankings.
  • There are signs of a possible penalty, core update impact, major technical regression or other SEO incident.

Do not use this skill when:

  • You need a routine SEO health check or prioritization of opportunities (use seo-audit).
  • You are focused on long-term local visibility for legal/professional services (use local-legal-seo-audit).

Initial Incident Triage

Before deep analysis, clarify the incident context:

  1. Incident Description

    • When did you first notice the drop?
    • Was it sudden (1–3 days) or gradual (weeks)?
    • Which metrics are affected? (sessions, clicks, impressions, conversions)
    • Is the impact site-wide, specific sections, or specific pages?
  2. Data Access

    • Do you have access to:
      • Google Search Console (GSC)?
      • Web analytics (GA4, Matomo, etc.)?
      • Server logs or CDN logs?
      • Deployment/change logs (Git, CI/CD, CMS release notes)?
  3. Recent Changes Checklist Ask explicitly about the 30–60 days before the drop:

    • Site redesign or theme change
    • URL structure changes or migrations
    • CMS/plugin updates
    • Changes to hosting, CDN, or security tools (WAF, firewalls)
    • Changes to robots.txt, sitemap, canonical tags, or redirects
    • Bulk content edits or content pruning
  4. Business Context

    • Is this a seasonal niche?
    • Any external events affecting demand?
    • Any previous manual actions or penalties?

Incident Classification Framework

Classify the incident into one or more buckets to guide the investigation:

  1. Algorithm / Core Update Impact

    • Drop coincides with known Google core update dates
    • Impact skewed toward certain types of queries or content
    • No major technical changes around the same time
  2. Technical / Infrastructure Failure

    • Indexing/crawlability suddenly impaired
    • Widespread 5xx/4xx errors
    • Robots.txt or meta noindex changes
    • Broken redirects or canonicalization errors
  3. Manual Action / Policy Violation

    • Manual action message in GSC
    • Sudden, severe drop in branded and non-branded queries
    • History of aggressive link building or spammy tactics
  4. Content / Quality Reassessment

    • Specific sections or topics hit harder
    • Content thin, outdated, or heavily AI-generated
    • Competitors significantly improved content around the same topics
  5. Demand / Seasonality / External Factors

    • Search demand drop in the niche (check industry trends)
    • Macro events, regulation changes, or market shifts

Data-Driven Investigation Steps

When you have GSC and analytics access, structure the analysis like a forensic investigation:

1. Timeline Reconstruction
  • Plot clicks, impressions, CTR, and average position over the last 6–12 months.
  • Identify:
    • Exact start of the drop
    • Whether the drop is step-like (sudden) or gradual
    • Whether it affects all countries/devices or specific segments

Use this to narrow likely causes:

  • Step-like drop → technical issue, manual action, deployment.
  • Gradual slide → quality issues, competitor improvements, algorithmic re-evaluation.
2. Segment Analysis

Segment the impact by:

  • Device: desktop vs. mobile
  • Country / region
  • Query type: branded vs. non-branded
  • Page type: home, category, product, blog, docs, etc.

Look for patterns:

  • Only mobile affected → potential mobile UX, CWV, or mobile-only indexing issue.
  • Specific country affected → geo-targeting, hreflang, local factors.
  • Non-branded hit harder than branded → often algorithm/quality-related.
3. Page-Level Impact

Identify:

  • Top pages with largest drop in clicks and impressions.
  • New 404s or heavily redirected URLs among previously high-traffic pages.
  • Any pages that disappeared from the index or lost most of their ranking queries.

Check for:

  • URL changes without proper redirects
  • Canonical changes
  • Noindex additions
  • Template or content changes on those pages
4. Technical Integrity Checks

Focus on incident-related technical regressions:

  • Robots.txt

    • Any recent changes?
    • Are key sections blocked unintentionally?
  • Indexation & Noindex

    • Sudden spike in “Excluded” or “Noindexed” pages in GSC
    • Important pages with meta noindex or X-Robots-Tag set incorrectly
  • Redirects

    • New redirect chains or loops
    • HTTP → HTTPS consistency
    • www vs. non-www consistency
    • Migrations without full redirect mapping
  • Server & Availability

    • Increased 5xx/4xx in logs or GSC
    • Downtime or throttling by security tools
    • Rate-limiting or blocking of Googlebot
  • Core Web Vitals (CWV)

    • Sudden degradation in CWV affecting large portions of the site
    • Especially on mobile
Show full SKILL.md (489 more words)Show less
5. Content & Quality Reassessment

When technical is clean, analyze content factors:

  • Which topics or content types were hit hardest?
  • Is content:
    • Thin, generic, or outdated?
    • Over-optimized or keyword-stuffed?
    • Lacking original data, examples, or experience?

Evaluate against E-E-A-T:

  • Experience: Does the content show first-hand experience?
  • Expertise: Is the author qualified and clearly identified?
  • Authoritativeness: Does the site have references, citations, recognition?
  • Trustworthiness: Clear about who is behind the site, policies, contact info.

Forensic Hypothesis Building

Use a hypothesis-driven approach instead of listing random issues.

For each plausible cause:

  • Hypothesis: e.g., “A recent deployment introduced noindex tags on key templates.”
  • Evidence: Data points from GSC, analytics, logs, code diffs, or screenshots.
  • Impact: Which sections/pages are affected and by how much.
  • Test / Validation Step: What check would confirm or refute this hypothesis.
  • Suggested Fix: Concrete remediation action.

Prioritize hypotheses by:

  1. Severity of impact
  2. Ease of validation
  3. Reversibility (how easy it is to roll back or adjust)

Output Format

Structure your final forensic report clearly:

Executive Incident Summary
  • Incident type classification (technical, algorithmic, manual action, mixed)
  • Date range of impact and severity (approximate % drop)
  • Top 3–5 likely root causes
  • Overall confidence level (Low/Medium/High)
Evidence-Based Findings

For each key finding, include:

  • Finding: Short description of what is wrong.
  • Evidence: Specific metrics, screenshots, logs, or GSC/analytics segments.
  • Likely Cause: How this could lead to the observed impact.
  • Impact: High/Medium/Low.
  • Fix: Concrete, implementable recommendation.
Prioritized Action Plan

Break down into phases:

  1. Critical Immediate Fixes (0–3 days)

    • Issues that block crawling, indexing, or basic site availability.
    • Reversals of harmful recent deployments.
  2. Stabilization (3–14 days)

    • Clean up redirects, canonicals, internal links.
    • Restore or improve critical content and templates.
  3. Recovery & Hardening (2–8 weeks)

    • Content quality improvements.
    • E-E-A-T enhancements.
    • Technical hardening to prevent recurrence.
  4. Monitoring Plan

    • Metrics and dashboards to watch.
    • Checkpoints to assess partial recovery.
    • Criteria for closing the incident.

Task-Specific Questions

When helping a user, ask:

  1. When exactly did you notice the drop? Any change logs around that date?
  2. Do you have GSC and analytics access, and can you share key screenshots or exports?
  3. Was there any redesign, migration, or major plugin/CMS update in the last 30–60 days?
  4. Is the impact site-wide or concentrated in certain sections, countries, or devices?
  5. Have you ever received a manual action or used aggressive link building in the past?

  • seo-audit: For general SEO health checks outside of incident scenarios.
  • ai-seo: For optimizing content for AI search experiences.
  • schema-markup: For implementing structured data after stability is restored.
  • analytics-tracking: For ensuring measurement is correct post-incident.

Example

User request:

Investigate this sudden organic-traffic drop, establish the timeline and likely cause, and produce a prioritized recovery plan.

Limitations

  • Use this skill only when the task clearly matches the scope described above.
  • Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
  • Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/seo-forensic-incident-response of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit b84d35a

Used in 2 other repositories

We found 11 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

SEO Forensic Incident Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

SEO Forensic Incident Response compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
SEO Forensic Incident Response this skillsickn33/agentic-awesome-skills47k2 repos~2.3kAutomated safety check: PassMIT
Kubernetes Network Root Cause Analysiskubeshark/kubeshark12k—~5.3kAutomated safety check: PassApache-2.0
UModel Root Cause Analysisalibaba/UnifiedModel415—~1.9kAutomated safety check: PassCustom licence
Axiom SRE Investigatoropenclaw/clawhub9.5k—~7.1kAutomated safety check: PassMIT
Incident Triage Harnessmadebyaris/advance-minimax-m3-cursor-rules126—~984Automated safety check: PassMIT
Broken API InterviewerPrepLabsAI/InterviewMentor112—~2.6kAutomated safety check: PassMIT

Similar skills

  • Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.

    12k GitHub stars~5.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • UModel Root Cause Analysis

    alibaba/UnifiedModel

    Investigates a service incident to its root cause by querying a UModel object graph alongside metrics, logs, topology and recent deployments.

    415 GitHub stars~1.9k tokensUpdated 17 days ago
    DevOps & CloudAuto-check passed
  • Axiom SRE Investigator

    openclaw/clawhub

    Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.

    9.5k GitHub stars~7.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Incident Triage Harness

    madebyaris/advance-minimax-m3-cursor-rules

    Walks an agent through an evidence-first incident investigation across logs, metrics, code and screenshots, from first symptom to the smallest safe mitigation.

    126 GitHub stars~984 tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Broken API Interviewer

    PrepLabsAI/InterviewMentor

    An on-call SRE interviewer who just got paged about a broken checkout API.

    112 GitHub stars~2.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Post-Incident Debrief

    VeryGoodOpenSource/vgv-wingspan

    Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh.

    109 GitHub stars~1.9k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about SEO Forensic Incident Response

What does SEO Forensic Incident Response do?

Investigate sudden drops in organic traffic or rankings and run a structured forensic SEO incident response with triage, root-cause analysis and recovery plan. SEO Forensic Incident Response is an agent skill from sickn33/agentic-awesome-skills. Investigate sudden drops in organic traffic or rankings and run a structured forensic SEO incident response with triage, root-cause analysis and recovery plan.

When should I use SEO Forensic Incident Response?

SEO Forensic Incident Response fits situations like: tasks that involve Incident response; tasks that involve Root cause analysis.

How do I install SEO Forensic Incident Response in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill seo-forensic-incident-response -a claude-code`. Or copy the skill folder (skills/seo-forensic-incident-response in sickn33/agentic-awesome-skills) into .claude/skills/seo-forensic-incident-response in your project. Claude Code loads it when a task matches its description.

How do I install SEO Forensic Incident Response in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill seo-forensic-incident-response -a codex`. Or copy the skill folder (skills/seo-forensic-incident-response in sickn33/agentic-awesome-skills) into .agents/skills/seo-forensic-incident-response in your project. Codex loads it when a task matches its description.

Can I use SEO Forensic Incident Response in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill seo-forensic-incident-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/seo-forensic-incident-response, .gemini/skills/seo-forensic-incident-response, .github/skills/seo-forensic-incident-response and .opencode/skills/seo-forensic-incident-response in your project.

What does SEO Forensic Incident Response need to run?

SKILL.md names no scripts, command-line tools or credentials: SEO Forensic Incident Response is instructions for the agent only.

Does SEO Forensic Incident Response access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is SEO Forensic Incident Response safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does SEO Forensic Incident Response use?

SEO Forensic Incident Response is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does SEO Forensic Incident Response use?

About 2.3k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to SEO Forensic Incident Response?

Skills that share tags, products or a category with SEO Forensic Incident Response: Kubernetes Network Root Cause Analysis (kubeshark/kubeshark, 12k stars), UModel Root Cause Analysis (alibaba/UnifiedModel, 415 stars), Axiom SRE Investigator (openclaw/clawhub, 9.5k stars) and Incident Triage Harness (madebyaris/advance-minimax-m3-cursor-rules, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains SEO Forensic Incident Response?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.