Agent skill

Incident Response

by WrongStack in WrongStack/WrongStack

Diagnose and recover an owned service incident with bounded changes, timeline evidence and verified health.

MITAuto-check passedDevOps & Cloud

Install Incident Response

skills CLI
$ npx skills add WrongStack/WrongStack --skill incident-response -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install WrongStack/WrongStack incident-response --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/incident-response .claude/skills/incident-response && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
incident-response
GitHub stars
371
Token cost
~844 tokens
SKILL.md length
316 words
Files
1
Skills in repo
100
Repo updated
First seen
Licence
MIT

At a glance

Diagnose and recover an owned service incident with bounded changes, timeline evidence and verified health.

  • Works in 6 steps: Define affected users/services, start… → Capture deployment/config changes,… → Choose the smallest reversible… → …
  • Tasks that involve Incident response
  • SKILL.md covers Selection card, Overview, Rules and Workflow, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Incident Response is an agent skill from WrongStack/WrongStack. Diagnose and recover an owned service incident with bounded changes, timeline evidence and verified health. Use during outages, bad deployments or data/service degradation; preserve evidence and separate mitigation from root-cause repair.

Its SKILL.md is about 840 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Incident response, Deployment and Root cause analysis. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.

When your agent uses it

  • Tasks that involve Incident response
  • Tasks that involve Deployment
  • Tasks that involve Root cause analysis

Example prompts

  • “/incident-response”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Define affected users/services, start time, severity and the current authorized response scope.
  2. Capture deployment/config changes, focused telemetry and data boundary before disruptive actions.
  3. Choose the smallest reversible mitigation supported by evidence; avoid blind restarts or repeated unbounded retries.
  4. Keep one owner for deployment/data writers and record actions/timestamps.
  5. Verify recovery through the user-facing path and relevant error/latency signals, not only process liveness.
  6. Preserve sensitive evidence securely and redact incident reports; do not erase logs/backups to manufacture a clean state.

What it can do on your machine

Read from SKILL.md and the folder at commit a744bdc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • opentelemetry.io
    • sre.google

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Incident Response loads about 844 tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 316 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~844

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from WrongStack/WrongStack at commit a744bdc, republished under its MIT licence (© WrongStack). 316 words, ~844 tokens.

Download SKILL.mdSave it as .claude/skills/incident-response/SKILL.md (or your agent's skills folder).
name
incident-response
description
Diagnose and recover an owned service incident with bounded changes, timeline evidence and verified health. Use during outages, bad deployments or data/service degradation; preserve evidence and separate mitigation from root-cause repair.
trigger
Diagnose and recover an owned service incident with bounded changes, timeline evidence and verified health. Use during outages, bad deployments or…
version
1.0.1
required-capabilities
filesystem.read
optional-capabilities
filesystem.write, execution.shell, verification.run, web.research
metadata.routing-group
operations
metadata.domain
operations

Incident Response

Selection card

  • Task: Coordinate production outage triage and recovery. / TR: Üretim kesintisi teşhisi ve kurtarmayı koordine et.
  • Start: Identify the authorized target, current health and rollback boundary.
  • Finish: apply the acceptance checks below; report observed results and unresolved constraints.

Overview

Diagnose and recover an owned service incident with bounded changes, timeline evidence and verified health. Use during outages, bad deployments or data/service degradation; preserve evidence and separate mitigation from root-cause repair..

Use current deployed versions, platform limits and actual telemetry. Stored runbooks and prior incidents guide hypotheses but do not prove this incident cause.

Rules

  1. Define affected users/services, start time, severity and the current authorized response scope.
  2. Capture deployment/config changes, focused telemetry and data boundary before disruptive actions.
  3. Choose the smallest reversible mitigation supported by evidence; avoid blind restarts or repeated unbounded retries.
  4. Keep one owner for deployment/data writers and record actions/timestamps.
  5. Verify recovery through the user-facing path and relevant error/latency signals, not only process liveness.
  6. Preserve sensitive evidence securely and redact incident reports; do not erase logs/backups to manufacture a clean state.

Workflow

  1. Establish impact, timeline and current health signals.
  2. Localize the failing boundary and compare recent releases/configuration.
  3. Execute authorized mitigation with a recovery/abort condition.
  4. Verify service and data outcomes, then monitor the agreed window.
  5. Document supported cause, actions, remaining risk and focused follow-up repairs.

Before returning

Impact/timeline and actions recorded; mitigation scope clear; user-visible recovery checked; cause and remaining uncertainty separated.

Sources

Versioned facts checked 2026-10-09; refresh authoritative sources before new installs/upgrades. OpenTelemetry, Google SRE incident guidance.

Skills in scope

  • observability — observability contracts and verification.
  • remote-debugging — diagnose a reported application failure on explicitly authorized remote hosts using bounded logs and runtime evidence.
  • release-rollback — plan and execute authorized release promotion or rollback with exact artifact and data compatibility.
  • backup-recovery — design and verify backups and restoration for owned databases, files and application state.

© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in packages/core/skills/incident-response of WrongStack/WrongStack.

Open the folder on GitHubat commit a744bdc

Compare with similar skills

Incident Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Incident Response compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Incident Response this skillWrongStack/WrongStack371—~844Automated safety check: PassMIT
Deployment Rollback InterviewerPrepLabsAI/InterviewMentor112—~3.1kAutomated safety check: PassMIT
Kubernetes Network Root Cause Analysiskubeshark/kubeshark12k—~5.3kAutomated safety check: PassApache-2.0
UModel Root Cause Analysisalibaba/UnifiedModel415—~1.9kAutomated safety check: PassCustom licence
Axiom SRE Investigatoropenclaw/clawhub9.5k—~7.1kAutomated safety check: PassMIT
Activation Governance Chaos RolloutAli-Marandi/DataSense107—~1.9kAutomated safety check: PassMIT

Similar skills

  • Deployment Rollback Interviewer

    PrepLabsAI/InterviewMentor

    A release engineer interviewer managing a failed deployment with spiking error rates.

    112 GitHub stars~3.1k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.

    12k GitHub stars~5.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • UModel Root Cause Analysis

    alibaba/UnifiedModel

    Investigates a service incident to its root cause by querying a UModel object graph alongside metrics, logs, topology and recent deployments.

    415 GitHub stars~1.9k tokensUpdated 17 days ago
    DevOps & CloudAuto-check passed
  • Axiom SRE Investigator

    openclaw/clawhub

    Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.

    9.5k GitHub stars~7.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern.

    107 GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Devops Engineer

    Yikai-Liao/symusic

    Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.

    189 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed

More from WrongStack/WrongStack

All 100 skills in this repo
  • Tech Stack

    WrongStack/WrongStack

    Validate and upgrade dependencies against live registries and official migration guides in any ecosystem.

    371 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Skill Creator

    WrongStack/WrongStack

    Create, improve and validate WrongStack SKILL.md bundles with precise discovery, progressive resources and current runtime contracts.

    371 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Bug Hunter

    WrongStack/WrongStack

    A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…

    371 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Design Craft

    WrongStack/WrongStack

    Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.

    371 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Design Critique

    WrongStack/WrongStack

    A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…

    371 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Mailbox Bridge

    WrongStack/WrongStack

    A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…

    371 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Incident Response

What does Incident Response do?

Diagnose and recover an owned service incident with bounded changes, timeline evidence and verified health. Incident Response is an agent skill from WrongStack/WrongStack. Diagnose and recover an owned service incident with bounded changes, timeline evidence and verified health.

When should I use Incident Response?

Incident Response fits situations like: tasks that involve Incident response; tasks that involve Deployment; tasks that involve Root cause analysis.

How do I install Incident Response in Claude Code?

Run `npx skills add WrongStack/WrongStack --skill incident-response -a claude-code`. Or copy the skill folder (packages/core/skills/incident-response in WrongStack/WrongStack) into .claude/skills/incident-response in your project. Claude Code loads it when a task matches its description.

How do I install Incident Response in Codex?

Run `npx skills add WrongStack/WrongStack --skill incident-response -a codex`. Or copy the skill folder (packages/core/skills/incident-response in WrongStack/WrongStack) into .agents/skills/incident-response in your project. Codex loads it when a task matches its description.

Can I use Incident Response in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill incident-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/incident-response, .gemini/skills/incident-response, .github/skills/incident-response and .opencode/skills/incident-response in your project.

What does Incident Response need to run?

SKILL.md names no scripts, command-line tools or credentials: Incident Response is instructions for the agent only.

Does Incident Response access the network?

SKILL.md names 2 domains. As links in the text: opentelemetry.io and sre.google. This is read from the text; nothing was executed.

Is Incident Response safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Incident Response use?

Incident Response is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Incident Response use?

About 844 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Incident Response?

Skills that share tags, products or a category with Incident Response: Deployment Rollback Interviewer (PrepLabsAI/InterviewMentor, 112 stars), Kubernetes Network Root Cause Analysis (kubeshark/kubeshark, 12k stars), UModel Root Cause Analysis (alibaba/UnifiedModel, 415 stars) and Axiom SRE Investigator (openclaw/clawhub, 9.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Incident Response?

WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 371 GitHub stars. The repository holds 100 skills in this directory. The repository was last updated on October 10, 2026.

Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.