agent-incident-response

Detect and respond to AI agent security incidents with containment, forensics, and recovery workflows.

4|Updated Apr 9, 2026
One-click install
npx skills add https://github.com/thejordanleopold/claude-code-skills-distilled --skill agent-incident-response
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: agent-incident-response
Source: https://github.com/thejordanleopold/claude-code-skills-distilled/tree/main/agent-incident-response
Command: npx skills add https://github.com/thejordanleopold/claude-code-skills-distilled --skill agent-incident-response

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Provides a structured, phased approach to contain, investigate, recover from, and harden AI agent security incidents, reducing blast radius and preserving evidence across the workflow.

Core Features & Use Cases

  • Containment guidance: terminate or isolate affected sessions and limit further impact.
  • Forensics and timeline: establish evidence collection, scope, and root-cause analysis.
  • Recovery and hardening: rotate credentials, audit MCP configs, rebuild baselines, and apply post-incident safeguards.
  • Runbook and reporting: generate incident reports and update runbooks to prevent recurrence.

Quick Start

Initiate immediate containment and start forensic logging to begin the incident response workflow.

Frequently Asked Questions about agent-incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I respond to a compromised AI agent security incident?

To respond to a compromised AI agent, initiate immediate containment by isolating affected sessions, then preserve forensic evidence and guide recovery through credential rotation and hardening.

What steps are involved in AI agent incident response and containment?

AI agent incident response involves a phased workflow: containing threats by terminating sessions, collecting forensic timelines, rotating exposed credentials, and applying post-incident hardening checks.

How do I investigate unexpected behavior or credential exposure in my AI agent?

Investigate unexpected behavior or credential exposure by establishing evidence collection, defining the scope of the compromise, and performing root-cause analysis using forensic timeline logging.

Can I use this incident response workflow for a modified CLAUDE.md file?

Yes, this incident response workflow explicitly applies to modified CLAUDE.md files, supporting containment, forensic investigation, baseline rebuilding, and post-incident hardening to secure the agent.

What's the best way to harden AI agents after a security incident?

Harden AI agents post-incident by rotating credentials, auditing MCP configurations, rebuilding security baselines, and updating runbooks to prevent recurrence and reduce the blast radius.

Do I need any dependencies to run the AI agent incident response workflow?

No dependencies are required to run the AI agent incident response workflow; it relies on internal references to guide containment, forensics, recovery, and reporting phases.