incident-response
Installation
SKILL.md
🚨 incident-response — Live Incident Command
One head skill for live incidents. Triage the severity, stop the bleeding, tell the truth on a cadence, then learn without blame. Every mode runs handsfree — defaults are stated inline, assumptions recorded in the deliverable, zero questions asked.
Modes — quick commands
Every invocation resolves to exactly one mode. Match the request, then load only the matched reference:
| Mode | Trigger phrases | Behavior | Reference |
|---|---|---|---|
| triage | "production is down", "sev-1", "severity", "first 15 minutes", "is this an incident" | Severity classification, escalation spine, first-15-minutes checklist | references/triage.md |
| mitigate | "stop the bleeding", "mitigate the outage", "roll back", "site is down", "data loss" | Stop-the-bleeding playbooks per incident class | references/mitigate.md |
| communicate | "status page update", "tell the client", "incident comms", "draft the update" | Status-page and client comms with severity-linked cadence | references/communicate.md |
| retro | "postmortem", "blameless retro", "what went wrong", "action items" | Blameless postmortem feeding ops/retro with tracked actions | references/retro.md |
Only the resolved mode's reference is loaded — the rest stay on disk, saving tokens on every run.