Topic · DevOps & Cloud
Best incident response skills for Claude Code, Codex and other agents.
- skills
- 271
- official
- 12
Incident response skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Automates the triage of GitHub issues in the A2UI repository. | a2ui-project/ | 17k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 2 | Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time. | kubeshark/ | 12k | — | ~5.3k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 3 | Decide, don't guess — trigger on ANY combinatorial or ground-state decision where a plausible guess is worse than silence: rosters and on-call schedules, packing and placement, RAG passage… | brayonpi/ | 1.4k | — | ~5k | Automated safety check: Pass | Proprietary | 1 mo ago |
| 4 | 特定の読み手に向けて、概念・PR・設計を「冗長にならない水準」の速習資料として説明し、図と主張を道具で検証する。読み手のペルソナ(既に知っていること・知らないこと・読み方)を質問と公開情報から作り、その差分だけを書く。図は Mermaid / D2 で描いて事実シートに照らし、本文に引用するコード・出力は再実行して照合し、HTML は vlmkit のゲートに通す。Use when the… | mizchi/ | 414 | — | ~2.3k | Automated safety check: Pass | MIT | yesterday |
| 5 | Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics. | alexgreensh/ | 187 | — | ~2.5k | Automated safety check: Notes | Unknown | 10 days ago |
| 6 | Investigates a service incident to its root cause by querying a UModel object graph alongside metrics, logs, topology and recent deployments. | alibaba/ | 412 | — | ~1.9k | Automated safety check: Pass | Unknown | 13 days ago |
| 7 | 7.Oncall Pigweed oncall rotation runbooks and maintenance workflows (such as rolling CIPD client tools for b/315378787). | pigweed-project/ | 547 | — | ~992 | Automated safety check: Pass | Apache-2.0 | today |
| 8 | Database operations runbook — backup, recovery, performance tuning, troubleshooting. | OpenDCAI/ | 406 | — | ~388 | Automated safety check: Pass | Apache-2.0 | 17 days ago |
| 9 | The project's episodic memory: a timestamped ledger of rules paid for with real outages and near-misses, one entry per incident. | kortix-ai/ | 20k | — | ~1.1k | Automated safety check: Pass | Unknown | today |
| 10 | Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security. | slowmist/ | 508 | — | ~1.4k | Automated safety check: Pass | MIT | 5 mo ago |
| 11 | Turns CI failures, open issues, recent commits and chat threads into a prioritized markdown report that an automation loop can act on without inventing architecture work. | cobusgreyling/ | 11k | — | ~500 | Automated safety check: Pass | MIT | today |
| 12 | 12.Iso42001 Expert ISO 42001 AI Management System (AIMS) compliance advisor. | Sushegaad/ | 939 | 1 repo | ~3.7k | Automated safety check: Pass | MIT | 2 days ago |
| 13 | Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output. | openclaw/ | 9.5k | — | ~7.1k | Automated safety check: Pass | MIT | today |
| 14 | Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern. | Ali-Marandi/ | 107 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 15 | Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)… | grafana/ | 278 | 1 repo | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 16 | Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills. | BagelHole/ | 1.1k | — | ~4.5k | Automated safety check: Pass | MIT | 4 mo ago |
| 18 | 18.Dfir Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. | transilienceai/ | 559 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 19 | Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates. | Yikai-Liao/ | 189 | 1 repo | ~1.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 20 | Write the weekly on-call handoff: everything the incoming on-call needs, triage-ready, posted to the channel at shift boundary. | anthropics/ | 210 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 21 | Triages GitHub issues by routing to oncall teams, applying labels, and closing questions. | pytorch/ | 104k | — | ~4.2k | Automated safety check: Pass | Unknown | today |
| 22 | Diagnoses a failing scheduled TMDb Integration run, re-runs transient failures, and fixes real API drift on its own branch with a PR, merging it only when told to. | adamayoung/ | 178 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 23 | Protocolo de respuesta ante incidentes en produccion: triaje, mitigacion, causa raiz y postmortem. | 686f6c61/ | 117 | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 24 | Bootstrap a Claude-assisted on-call for this channel/repo: discover the available connectors, mine incident history into draft triage playbooks, interview the human for policy, validate against… | anthropics/ | 210 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 25 | Walks an agent through an evidence-first incident investigation across logs, metrics, code and screenshots, from first symptom to the smallest safe mitigation. | madebyaris/ | 126 | — | ~984 | Automated safety check: Pass | MIT | 3 mo ago |
| 26 | Sub-triages issues in the oncall:distributed queue by assigning distributed module labels, routing to sub-oncalls, and marking triaged. | pytorch/ | 104k | — | ~2.8k | Automated safety check: Pass | Unknown | today |
| 27 | Does a read-only first pass on a possible production incident: gathers deploy, Sentry and health-check signals, proposes a severity and status message, then stops for human approval. | superset-sh/ | 15k | — | ~1k | Automated safety check: Pass | Unknown | today |
| 28 | Drive CI green on a pushed, review-clean feature PR — On-Call diagnoses failures and hands fix tasks to the SWE. | iusztinpaul/ | 203 | — | ~607 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta. | automateyournetwork/ | 674 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 30 | Disable or re-enable Cloudflare R2 (download-r2.pytorch.org) usage in managev2.py during R2 outages. | pytorch/ | 113 | — | ~1.5k | Automated safety check: Pass | Unknown | today |
| 31 | Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. | luongnv89/ | 131 | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 32 | Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session. | avelikiy/ | 103 | — | ~884 | Automated safety check: Notes | MIT | today |
| 33 | Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning. | automateyournetwork/ | 674 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 34 | Read and record root causes in the Linear incident-alert knowledge base. | langfuse/ | 35k | — | ~1.6k | Automated safety check: Pass | Unknown | today |
| 35 | An on-call SRE interviewer who just got paged about a broken checkout API. | PrepLabsAI/ | 112 | — | ~2.6k | Automated safety check: Pass | MIT | today |
| 36 | Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh. | VeryGoodOpenSource/ | 108 | — | ~1.9k | Automated safety check: Pass | MIT | 7 days ago |
| 37 | 37.SRE Engineer Defines SLIs, SLOs and error budgets, and sets up golden-signal monitoring, blameless postmortems, toil automation and chaos experiments for production systems. | Jeffallan/ | 12k | — | ~1.7k | Automated safety check: Pass | MIT | 4 days ago |
| 38 | 38.Msp Helpdesk A skill your agent uses for anything about how your MSP runs day-to-day support: setting or questioning a ticket's priority, response and resolution targets, "the client says everything is down"… | RTFM-IT-Services-LLC/ | 112 | — | ~3.3k | Automated safety check: Pass | Unknown | 4 days ago |
| 39 | 39.Cut Release Cut a new Sculptor release candidate from main: run just cut-release (which creates the release/sculptor-vX.Y.0 branch at X.Y.0rc1, pushes the tag that triggers the RC build, and opens a PR bumping… | imbue-ai/ | 236 | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 40 | Expert SRE incident responder specializing in rapid problem resolution, modern observability, and comprehensive incident management. | davila7/ | 32k | 7 repos | ~2.6k | Automated safety check: Pass | MIT | today |
| 41 | Diagnoses compile errors, runtime exceptions, failing tests, pipeline failures and production alerts from code and logs, giving a root cause before any fix. | davidYichengWei/ | 158 | — | ~646 | Automated safety check: Pass | MIT | 6 mo ago |
| 42 | A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining… | hypnguyen1209/ | 386 | — | ~2.5k | Automated safety check: Pass | MIT | 9 days ago |
| 43 | An incident commander interviewer running a P0 outage war room. | PrepLabsAI/ | 112 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 44 | Automate PagerDuty tasks via Rube MCP (Composio): manage incidents, services, schedules, escalation policies, and on-call rotations. | davepoon/ | 3.6k | 7 repos | ~2.6k | Automated safety check: Pass | MIT | yesterday |
| 45 | 45.Ciso Advisor Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills. | alirezarezvani/ | 28k | 1 repo | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 46 | A skill your agent uses for your MSP's proactive, recurring operations: patching and update cycles, maintenance windows, backup monitoring and test restores, monitoring and alert triage, the on-call… | RTFM-IT-Services-LLC/ | 112 | — | ~2.6k | Automated safety check: Pass | Unknown | 4 days ago |
| 47 | Implement incident management processes and escalation procedures. | sickn33/ | 47k | 2 repos | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 48 | Monitor AI agent health, detect anomalies, set up alerting, and maintain observability dashboards for production multi-agent systems. | cosmicstack-labs/ | 476 | — | ~2.7k | Automated safety check: Pass | MIT | 1 mo ago |
Questions, answered from the data.
What is the best incident response skill?
A2ui Issue Triage from a2ui-project/a2ui ranks first of the 271 incident response skills listed here, with the highest score: its repository has 17k GitHub stars, its SKILL.md loads about 1.5k tokens and it passes the automated safety check with no findings. Next come Kubernetes Network Root Cause Analysis and Hexstellar.
Which incident response skills are official?
12 of the 271 incident response skills are official, published by the vendor's own GitHub organization: Alerting Irm, Handoff, Oncall Setup, Google Cloud Filestore Autoscale, Incident Postmortem and 7 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in DevOps & Cloud
- Deployment1,152
- CI/CD921
- Containers723
- Observability562
- Container orchestration519
- Infrastructure as code351
- Monitoring and alerting333
- Secrets management318
- Runbooks and postmortems277
- Cloud networking230
- Backup and disaster recovery170
- Site reliability engineering150
- Cloud architecture114
- MLOps101
- Cloud cost optimization93
- GitOps87
- Linux administration75
- Platform engineering51
- Chaos engineering28