incident-response-report

Installation
SKILL.md

Incident Response Report

Mission

Turn an investigation into a concise report that a human analyst can review and close. Optimize for clarity, evidence traceability, and remediation follow-up.

Writing rules

  • Keep the tone direct and professional.
  • Separate confirmed facts, indicators, and hypotheses.
  • Use UTC timestamps unless the user asks otherwise.
  • Cite the telemetry source or log family when possible.
  • Do not overstate certainty.
  • If evidence is partial, say what is missing and how that limits the conclusion.
  • Default to Markdown unless the user requests HTML or another format.
  • If public IPs appear in the source material and no enrichment is already present, run the required enrichment before finalizing the report.

Standard structure

  1. Executive Assessment
  2. Confirmed Facts
  3. Key Indicators
Related skills

More from crtvrffnrt/skills

Installs
6
GitHub Stars
1
First Seen
Apr 20, 2026