Agent skill

Incident Response

by spencerpauly in spencerpauly/awesome-cursor-skills

Handle production incidents — triage, mitigate, communicate, and write postmortems.

CC0-1.0Auto-check passedDevOps & Cloud

Install Incident Response

skills CLI
$ npx skills add spencerpauly/awesome-cursor-skills --skill incident-response -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install spencerpauly/awesome-cursor-skills incident-response --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/spencerpauly/awesome-cursor-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/resources/incident-response .claude/skills/incident-response && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
incident-response
GitHub stars
844
Token cost
~926 tokens
SKILL.md length
297 words
Files
1
Skills in repo
60
Repo updated
First seen
Licence
CC0-1.0

At a glance

Handle production incidents — triage, mitigate, communicate, and write postmortems.

  • Works in 5 steps: Detect & Triage (first 5 minutes) → Mitigate (next 15-30 minutes) → Communicate → …
  • Tasks that involve Incident response
  • SKILL.md covers Severity Levels, Incident Workflow and Tips
  • Calls git

What it does

Incident Response is an agent skill from spencerpauly/awesome-cursor-skills. Handle production incidents — triage, mitigate, communicate, and write postmortems.

Its SKILL.md is about 930 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Incident response and Runbooks and postmortems. The repository describes itself as: A curated list of awesome skills for Cursor. The licence is CC0-1.0.

When your agent uses it

  • Tasks that involve Incident response
  • Tasks that involve Runbooks and postmortems

Example prompts

  • “/incident-response”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Detect & Triage (first 5 minutes)
  2. Mitigate (next 15-30 minutes)
  3. Communicate
  4. Resolve
  5. Postmortem (within 48 hours)

What it can do on your machine

Read from SKILL.md and the folder at commit 99cd265. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Incident Response loads about 926 tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 297 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~926

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from spencerpauly/awesome-cursor-skills at commit 99cd265, republished under its CC0-1.0 licence (© spencerpauly). 297 words, ~926 tokens.

Download SKILL.mdSave it as .claude/skills/incident-response/SKILL.md (or your agent's skills folder).
name
incident-response
description
Handle production incidents — triage, mitigate, communicate, and write postmortems.
user-invocable
true

Incident Response

Handle production incidents systematically.

Severity Levels

LevelDefinitionResponse TimeExamples
SEV1Service down, all users affectedImmediateDatabase crash, DNS failure, auth broken
SEV2Major feature broken, many users affected< 30 minPayments failing, search not working
SEV3Minor feature broken, workaround exists< 4 hoursExport button broken, slow dashboard
SEV4Cosmetic or low-impact issueNext business dayTypo in UI, minor styling bug

Incident Workflow

1. Detect & Triage (first 5 minutes)
  • Acknowledge the incident — "I'm looking into this"
  • Determine severity level
  • Check monitoring dashboards (error rates, latency, status page)
  • Check recent deployments: git log --oneline -10 — was anything deployed recently?
2. Mitigate (next 15-30 minutes)

The goal is to stop the bleeding, not find the root cause.

Quick mitigations:

  • Rollback: git revert <commit> && deploy — fastest option if a deploy caused it
  • Feature flag: Disable the broken feature
  • Scale up: Add more instances if it's a capacity issue
  • Failover: Switch to backup/secondary if primary is down
  • Block traffic: Rate-limit or block specific abusive traffic
3. Communicate

Internal:

  • Open an incident channel (#incident-2026-04-10)
  • Post status updates every 15-30 minutes
  • Assign roles: Incident Commander, Communicator, Engineers

External:

  • Update status page
  • Send email/notification to affected users if the outage is extended
  • Be honest: "We're experiencing issues with X. We've identified the cause and are working on a fix."
4. Resolve
  • Deploy the fix
  • Verify the fix works in production (check metrics, not just absence of errors)
  • Close the incident channel with a summary
5. Postmortem (within 48 hours)

Write a blameless postmortem:

markdown
# Incident: Payments failing for Stripe webhook
**Date:** 2026-04-10
**Duration:** 45 minutes (14:30 — 15:15 UTC)
**Severity:** SEV2
**Impact:** ~200 users unable to complete purchases

## Timeline
- 14:30 — Alert fires: payment success rate drops to 20%
- 14:35 — On-call engineer acknowledges, begins investigation
- 14:40 — Identified: Stripe webhook endpoint returning 500
- 14:45 — Root cause: migration added NOT NULL column without default
- 14:50 — Fix deployed: added default value to migration
- 15:00 — Payment success rate recovering
- 15:15 — Metrics back to normal, incident closed

## Root Cause
Database migration #47 added a `currency` column with NOT NULL 
but no DEFAULT value. Existing rows were fine (backfilled), but 
new webhook events failed because the insert didn't include `currency`.

## What Went Well
- Alert fired within 5 minutes of the issue starting
- Rollback was considered but the fix was faster

## What Went Wrong
- Migration wasn't tested with live webhook payloads
- No staging test for the webhook flow

## Action Items
- [ ] Add webhook integration test to CI (@alice, due 2026-04-17)
- [ ] Require DEFAULT for all new NOT NULL columns in migration review (@bob)
- [ ] Add runbook for payment failures (@charlie, due 2026-04-14)

Tips

  • Rollback first, investigate later — speed matters more than elegance
  • The most recent deploy is the most likely cause
  • Don't assign blame in postmortems — focus on process improvements
  • Maintain a runbook for common failure modes
  • Practice incident response with game days before real incidents happen

© spencerpauly, CC0-1.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in resources/incident-response of spencerpauly/awesome-cursor-skills.

Open the folder on GitHubat commit 99cd265

Compare with similar skills

Incident Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Incident Response compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Incident Response this skillspencerpauly/awesome-cursor-skills844—~926Automated safety check: PassCC0-1.0
Oncallpigweed-project/pigweed548—~963Automated safety check: PassApache-2.0
Activation Governance Chaos RolloutAli-Marandi/DataSense107—~1.9kAutomated safety check: PassMIT
Incident Response686f6c61/alfred-dev117—~1.1kAutomated safety check: PassMIT
Superset Incident Triagesuperset-sh/superset15k—~1kAutomated safety check: PassCustom licence
Post-Incident DebriefVeryGoodOpenSource/vgv-wingspan109—~1.9kAutomated safety check: PassMIT

Similar skills

  • Oncall

    pigweed-project/pigweed

    Pigweed oncall rotation runbooks and maintenance workflows (such as rolling CIPD client tools for b/315378787).

    548 GitHub stars~963 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern.

    107 GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Incident Response

    686f6c61/alfred-dev

    Protocolo de respuesta ante incidentes en produccion: triaje, mitigacion, causa raiz y postmortem.

    117 GitHub stars~1.1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Superset Incident Triage

    superset-sh/superset

    Does a read-only first pass on a possible production incident: gathers deploy, Sentry and health-check signals, proposes a severity and status message, then stops for human approval.

    15k GitHub stars~1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Post-Incident Debrief

    VeryGoodOpenSource/vgv-wingspan

    Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh.

    109 GitHub stars~1.9k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • SRE Engineer

    Jeffallan/claude-skills

    Defines SLIs, SLOs and error budgets, and sets up golden-signal monitoring, blameless postmortems, toil automation and chaos experiments for production systems.

    12k GitHub stars~1.7k tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed

More from spencerpauly/awesome-cursor-skills

All 60 skills in this repo
  • Generating Images

    spencerpauly/awesome-cursor-skills

    Generate or edit images using the OpenAI Image API (gpt-image-2).

    844 GitHub stars~3.7k tokensUpdated 2 mo ago
    Auto-check: notes
  • Babysitting PR

    spencerpauly/awesome-cursor-skills

    Monitor a pull request for CI failures, review comments, and merge conflicts — then fix them automatically.

    844 GitHub stars~930 tokensUpdated 2 mo ago
    Auto-check passed
  • Best Of N Solving

    spencerpauly/awesome-cursor-skills

    Solve a hard problem by trying multiple approaches in parallel using isolated git worktrees.

    844 GitHub stars~698 tokensUpdated 2 mo ago
    Auto-check passed
  • Grinding Until Pass

    spencerpauly/awesome-cursor-skills

    Keep iterating on code changes until the tests pass, the build succeeds, or linting is clean.

    844 GitHub stars~796 tokensUpdated 2 mo ago
    Auto-check passed
  • Parallel CI Triage

    spencerpauly/awesome-cursor-skills

    When GitHub Actions fails, fetch failing job logs and assign each failing job to a separate subagent that fixes its slice of the problem in parallel.

    844 GitHub stars~793 tokensUpdated 2 mo ago
    Auto-check passed
  • Parallel Exploring

    spencerpauly/awesome-cursor-skills

    Explore a large codebase in parallel by launching multiple explore subagents that each investigate a different area simultaneously.

    844 GitHub stars~787 tokensUpdated 2 mo ago
    Auto-check: notes

Categories

Questions about Incident Response

What does Incident Response do?

Handle production incidents — triage, mitigate, communicate, and write postmortems. Incident Response is an agent skill from spencerpauly/awesome-cursor-skills. Handle production incidents — triage, mitigate, communicate, and write postmortems.

When should I use Incident Response?

Incident Response fits situations like: tasks that involve Incident response; tasks that involve Runbooks and postmortems.

How do I install Incident Response in Claude Code?

Run `npx skills add spencerpauly/awesome-cursor-skills --skill incident-response -a claude-code`. Or copy the skill folder (resources/incident-response in spencerpauly/awesome-cursor-skills) into .claude/skills/incident-response in your project. Claude Code loads it when a task matches its description.

How do I install Incident Response in Codex?

Run `npx skills add spencerpauly/awesome-cursor-skills --skill incident-response -a codex`. Or copy the skill folder (resources/incident-response in spencerpauly/awesome-cursor-skills) into .agents/skills/incident-response in your project. Codex loads it when a task matches its description.

Can I use Incident Response in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add spencerpauly/awesome-cursor-skills --skill incident-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/incident-response, .gemini/skills/incident-response, .github/skills/incident-response and .opencode/skills/incident-response in your project.

What does Incident Response need to run?

Going by SKILL.md and its folder, Incident Response needs the command-line tools its instructions call (git).

Does Incident Response access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Incident Response safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Incident Response use?

Incident Response is published under the CC0-1.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Incident Response use?

About 926 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Incident Response?

Skills that share tags, products or a category with Incident Response: Oncall (pigweed-project/pigweed, 548 stars), Activation Governance Chaos Rollout (Ali-Marandi/DataSense, 107 stars), Incident Response (686f6c61/alfred-dev, 117 stars) and Superset Incident Triage (superset-sh/superset, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Incident Response?

spencerpauly (a GitHub user) maintains it in spencerpauly/awesome-cursor-skills, which has 844 GitHub stars. The repository holds 60 skills in this directory. The repository was last updated on August 2, 2026.

Source: spencerpauly/awesome-cursor-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.