Agent skill

Post-Incident Debrief

by VeryGoodOpenSource in VeryGoodOpenSource/vgv-wingspan

Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh.

MITAuto-check passedDevOps & Cloud

Install Post-Incident Debrief

skills CLI
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill debrief -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install VeryGoodOpenSource/vgv-wingspan debrief --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/debrief .claude/skills/debrief && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
debrief
GitHub stars
109
Token cost
~1.9k tokens
SKILL.md length
907 words
Files
2 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh.

  • Works in 7 steps: Gather initial information → Gather evidence from the codebase → Analyze root cause → …
  • Writing up a production outage after it has been resolved
  • SKILL.md covers Incident Context, Execution Flow, Output Summary and Key Principles, plus 1 more section
  • Calls git and gh

What it does

This skill writes a structured, blameless document after a production incident, failed release, flaky deploy or significant bug that deserves more than a fix. It takes the incident description as its argument; if none is given it asks what happened and will not continue until you answer. It then asks about the incident one question at a time, skipping anything already clear.

The questions cover what happened and the user-visible impact, when it started, was detected and was resolved, which platform or environment was affected, severity, how it was discovered, the fix and any temporary workaround, and links to pull requests, commits, CI runs or logs. Questioning stops once a timeline can be reconstructed or you say to proceed, and gaps are noted in the document instead of blocking it.

In parallel the agent collects evidence from the codebase: git log on the affected files over the last two weeks or a range you give, related commits, gh pr view for referenced pull requests, and gh run list and gh run view for failed CI runs, skipping CI when there is no CI context. A template in references/template.md serves as the layout for the final document.

When your agent uses it

  • Writing up a production outage after it has been resolved
  • Reviewing a failed release or flaky deploy to find the root cause
  • Turning a significant bug into a timeline with follow-up actions
  • Capturing what happened while the details are still fresh

Example prompts

  • “Write a debrief for last night's checkout outage; the fix landed in the most recent merged PR.”
  • “Debrief our failed iOS release; the CI run failed at the code signing step.”
  • “Run a blameless post-incident review of the flaky deploy we saw this week.”
  • “We hit a data-loss bug in the import job. Produce a root cause analysis with action items.”

Requirements

  • Git history of the affected project
  • The GitHub CLI (gh) for pull request and CI lookups when they are relevant
  • Compatibility (from SKILL.md): Designed for Claude Code (or similar products with agent support)

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Gather initial information
  2. Gather evidence from the codebase
  3. Analyze root cause
  4. Draft action items
  5. Set up workspace
  6. Write the debrief document
  7. Handoff

What it can do on your machine

Read from SKILL.md and the folder at commit 19e0695. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code (or similar products with agent support)

    From compatibility in the SKILL.md frontmatter.

Context cost

Post-Incident Debrief loads about 1.9k tokens when it runs, and up to ~2.3k if it reads all its reference files. Until then it costs about 32 tokens; SKILL.md has 907 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from VeryGoodOpenSource/vgv-wingspan at commit 19e0695, republished under its MIT licence (© VeryGoodOpenSource). 907 words, ~1,858 tokens.

Download SKILL.mdSave it as .claude/skills/debrief/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
debrief
description
Produces a structured post-incident analysis — timeline, root cause, and actionable follow-ups — while context is fresh.
compatibility
Designed for Claude Code (or similar products with agent support)
user-invocable
true
when_to_use
Use when user says "debrief", "post-mortem", "incident review", or "root cause analysis".
argument-hint
incident description, PR/commit refs, or error context
effort
high

Post-incident debrief

Produce a structured, blameless debrief document after an incident, failed release, or significant bug. Capture what happened, why, and what to change — while the context is still fresh.

Use this when a production incident, failed release, flaky deploy, or significant bug warrants more than just a fix — when the team needs to understand why it happened and prevent recurrence.

Incident Context

<incident_context>$ARGUMENTS</incident_context>

If the incident context above is empty, ask the user: "What incident would you like to debrief? Describe what happened, link to relevant PRs/commits, or paste error logs."

DO NOT proceed until you have a description from the user.

Execution Flow

1. Gather initial information

Use the AskUserQuestion tool to fill in gaps one question at a time. Adapt based on what the user already provided — skip questions whose answers are already clear from the incident context.

Key questions to resolve:

TopicExample Questions
What happenedWhat was the user-visible impact? What broke?
WhenWhen did it start? When was it detected? When was it resolved?
WhereWhat platform, environment, or service? (e.g., prod vs staging, iOS vs Android, specific API)
SeverityHow many users/systems were affected? Was data lost?
DetectionHow was it discovered? Alert, user report, or manual observation?
ResolutionWhat was the fix? Is it deployed? Is it a temporary workaround?
ReferencesRelevant PRs, commits, CI runs, error logs, or monitoring links?

Exit condition: Continue until you have enough context to reconstruct a timeline, OR the user says "that's all I have" or "proceed."

The skill must work with partial information. Not every debrief has full CI logs or a complete timeline. Note gaps explicitly in the document rather than blocking on them.

2. Gather evidence from the codebase

Based on the incident context, automatically collect evidence. Run these in parallel where possible:

Run these in parallel:

  • Git history: git log on affected files (last 2 weeks or user-specified range), git log --all --oneline for related commits, gh pr view for referenced PRs
  • CI/CD evidence: gh run list for recent failures, gh run view <id> for referenced runs. Skip if no CI context — do not block on missing data.
  • Affected file analysis: Check test coverage (Glob for test files), recent change frequency (git log --oneline <file>). Note files lacking tests or with high churn.
3. Analyze root cause

Synthesize the evidence to identify the root cause (specific change, gap, or condition — trace to commits or code paths) and contributing factors (missing tests, no monitoring, unclear ownership, insufficient review).

Blameless framing: Focus on systems and processes, not individuals. Ask "what made this possible?" not "who caused this?"

4. Draft action items

Generate concrete, assignable follow-ups. Each must be specific (not "improve testing"), linked to code where possible, and categorized:

TypePurposeExamples
PreventWould have stopped this incidentAdd validation, add test
DetectWould have caught it soonerAdd monitoring, add CI check
RespondWould have made recovery fasterAdd runbook, add feature flag

Action items are recorded in the document only — they become separate tickets.

5. Set up workspace

Before writing the debrief file, ensure the session is not on the base branch:

  • Run git rev-parse --abbrev-ref HEAD. If the current branch is a base branch (main, master, or develop), use AskUserQuestion to offer creating a feature branch — git checkout -b <type>/<kebab-topic>, name under 60 characters — before writing. If already on a feature branch, continue without prompting.
Show full SKILL.md (343 more words)Show less
6. Write the debrief document

Write the document to docs/debriefs/YYYY-MM-DD-<kebab-case-topic>-debrief.md.

Ensure docs/debriefs/ directory exists before writing.

Document structure:

Use the debrief template as the document structure. Adapt it to fit the available information — omit sections with no relevant data rather than filling them with "N/A." Add sections if the incident warrants it (e.g., a "Customer Communication" section for user-facing incidents).

7. Handoff

Use the AskUserQuestion tool to present next steps:

Question: "Debrief complete! What would you like to do next?"

Options:

  1. Review and refine: improve the document using structured review
  2. Generate issue previews: format action items as ready-to-copy GitHub issue drafts
  3. Done: debrief complete

If the user selects "Review and refine" → apply the @refine-approach skill to the document. When refinement is complete, present these options again (without the refine option).

If the user selects "Generate issue previews" → read the action items from the written debrief document, then:

  1. Check for issue templates: look for .github/ISSUE_TEMPLATE/ in the project root. Read every .yaml or .yml file found there (skip config.yml).

  2. If templates exist: render one preview block per action item using the most appropriate template. Map each item to a template based on its content (e.g., a missing test or validation gap → bug report; a new monitoring check → feature request; a dependency update or runbook → chore). Populate every required field defined in the template. Include a Template: line naming the chosen template file.

  3. If no templates exist: fall back to the generic format:

text
---
Title: <specific, actionable title>
Label: prevent | detect | respond
Body:
  ## Context
  Debrief: docs/debriefs/YYYY-MM-DD-<topic>-debrief.md
  Root cause: <one-line summary from debrief>

  ## What happened
  <relevant excerpt from the debrief timeline or root cause section>

  ## What to do
  <the action item, specific and linked to code/files where possible>
---

Render all previews in a single fenced block so the user can copy them. Do not call gh, glab, or any external CLI — output is display only.

Output Summary

When complete, display:

md
Debrief complete!

Document: docs/debriefs/YYYY-MM-DD-<kebab-case-topic>-debrief.md

Severity: <severity>
Root cause: [one-line summary]
Action items: <N> prevent, <N> detect, <N> respond

Key Principles

  • Blameless — Focus on systems and processes, never individuals
  • Evidence-based — Link findings to commits, PRs, code paths, and logs
  • Actionable — Every action item is specific and assignable
  • Honest about gaps — Mark unknowns explicitly rather than guessing
  • Tech-agnostic — No language or framework assumptions in the skill itself

Important

DO NOT make code changes. This skill produces a document only. Action items become separate tickets.

© VeryGoodOpenSource, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/debrief of VeryGoodOpenSource/vgv-wingspan.

  • SKILL.md
  • references/template.md

Open the folder on GitHubat commit 19e0695

Compare with similar skills

Post-Incident Debrief next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Post-Incident Debrief compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Post-Incident Debrief this skillVeryGoodOpenSource/vgv-wingspan109—~1.9kAutomated safety check: PassMIT
Conducting Post Incident Lessons Learnedmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0
Incident Postmortemgithub/awesome-copilot40k—~1.8kAutomated safety check: PassMIT
Incident Triage Harnessmadebyaris/advance-minimax-m3-cursor-rules126—~984Automated safety check: PassMIT
Incident Response LifecycleLeoYeAI/openclaw-master-skills2.2k—~5kAutomated safety check: PassApache-2.0
Post Mortemhanamizuki/solopreneur152—~1.7kAutomated safety check: PassMIT

Similar skills

  • Conducting Post Incident Lessons Learned

    mukul975/Anthropic-Cybersecurity-Skills

    Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Incident Postmortem

    github/awesome-copilot

    Official

    A skill your agent uses when an outage, production incident, or significant service degradation has occurred and the team needs to write a structured blameless post-mortem.

    40k GitHub stars~1.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Incident Triage Harness

    madebyaris/advance-minimax-m3-cursor-rules

    Walks an agent through an evidence-first incident investigation across logs, metrics, code and screenshots, from first symptom to the smallest safe mitigation.

    126 GitHub stars~984 tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Incident Response Lifecycle

    LeoYeAI/openclaw-master-skills

    Incident response process management following the NIST 800-61 lifecycle.

    2.2k GitHub stars~5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Post Mortem

    hanamizuki/solopreneur

    Trace when a bug was introduced, find the root cause commit, understand why it happened, and produce a structured post-mortem report.

    152 GitHub stars~1.7k tokensUpdated 11 days ago
    DevOps & CloudAuto-check passed
  • Post Mortem

    thananon/9arm-skills

    Write the canonical engineering record of a fixed bug — root cause, mechanism, fix, validation, and how it slipped through.

    3.2k GitHub stars~3.4k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed

More from VeryGoodOpenSource/vgv-wingspan

All 11 skills in this repo
  • On-Demand Code Review

    VeryGoodOpenSource/vgv-wingspan

    Runs parallel review agents over a branch, chosen paths or a whole project and merges their findings into one numbered report you can act on by id.

    109 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Git Rebase onto Base Branch

    VeryGoodOpenSource/vgv-wingspan

    Rebases the current feature branch onto the latest main, master or develop, stashing uncommitted work first and aborting cleanly if conflicts appear.

    109 GitHub stars~786 tokensUpdated today
    Auto-check passed
  • Feature Brainstorm

    VeryGoodOpenSource/vgv-wingspan

    Clarifies what to build before how, by asking one question at a time about a feature idea and then handing the result on to planning.

    109 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Create Pull Request

    VeryGoodOpenSource/vgv-wingspan

    Stages, commits, pushes and opens a pull request with a Conventional Commits message, after running the project's checks unless told to skip them.

    109 GitHub stars~1.3k tokensUpdated today
    Auto-check: notes
  • Targeted Emergency Bug Fix

    VeryGoodOpenSource/vgv-wingspan

    Applies a minimal fix to an emergency bug through triage, root-cause location, a hotfix branch and a blast-radius check, with tests and review still required.

    109 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Plan

    VeryGoodOpenSource/vgv-wingspan

    Turns high-level brainstorming and ideas into well-structured, actionable implementation plans.

    109 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Questions about Post-Incident Debrief

What does Post-Incident Debrief do?

Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh. This skill writes a structured, blameless document after a production incident, failed release, flaky deploy or significant bug that deserves more than a fix. It takes the incident description as its argument; if none is given it asks what happened and will not continue until you answer.

When should I use Post-Incident Debrief?

Post-Incident Debrief fits situations like: writing up a production outage after it has been resolved; reviewing a failed release or flaky deploy to find the root cause; turning a significant bug into a timeline with follow-up actions; capturing what happened while the details are still fresh.

How do I install Post-Incident Debrief in Claude Code?

Run `npx skills add VeryGoodOpenSource/vgv-wingspan --skill debrief -a claude-code`. Or copy the skill folder (skills/debrief in VeryGoodOpenSource/vgv-wingspan) into .claude/skills/debrief in your project. Claude Code loads it when a task matches its description.

How do I install Post-Incident Debrief in Codex?

Run `npx skills add VeryGoodOpenSource/vgv-wingspan --skill debrief -a codex`. Or copy the skill folder (skills/debrief in VeryGoodOpenSource/vgv-wingspan) into .agents/skills/debrief in your project. Codex loads it when a task matches its description.

Can I use Post-Incident Debrief in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add VeryGoodOpenSource/vgv-wingspan --skill debrief -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/debrief, .gemini/skills/debrief, .github/skills/debrief and .opencode/skills/debrief in your project.

What does Post-Incident Debrief need to run?

Going by SKILL.md and its folder, Post-Incident Debrief needs the command-line tools its instructions call (git and gh). Our summary lists: Git history of the affected project; The GitHub CLI (gh) for pull request and CI lookups when they are relevant. Compatibility (from SKILL.md): Designed for Claude Code (or similar products with agent support).

Does Post-Incident Debrief access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Post-Incident Debrief safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Post-Incident Debrief use?

Post-Incident Debrief is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Post-Incident Debrief use?

About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 436 tokens, read only when the agent opens those files.

What are the alternatives to Post-Incident Debrief?

Skills that share tags, products or a category with Post-Incident Debrief: Conducting Post Incident Lessons Learned (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Incident Postmortem (github/awesome-copilot, 40k stars), Incident Triage Harness (madebyaris/advance-minimax-m3-cursor-rules, 126 stars) and Incident Response Lifecycle (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Post-Incident Debrief?

VeryGoodOpenSource (a GitHub organization) maintains it in VeryGoodOpenSource/vgv-wingspan, which has 109 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 7, 2026.

Source: VeryGoodOpenSource/vgv-wingspan on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.