incident-commander

Coordinate multi-agent incident response with Incident Command System discipline.

3|3|Updated Mar 8, 2026
One-click install
npx skills add https://github.com/jaskaranhundal/usap-skills --skill incident-commander
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-commander
Source: https://github.com/jaskaranhundal/usap-skills/tree/main/response/incident-commander
Command: npx skills add https://github.com/jaskaranhundal/usap-skills --skill incident-commander

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides decisive command and coordination for active security incidents, ensuring rapid response and clear decision-making under pressure.

Core Features & Use Cases

  • Severity Declaration: Assigns critical SEV1-SEV4 levels based on incident impact.
  • Response Coordination: Directs multi-agent response tracks (containment, investigation, notification, recovery).
  • Use Case: When ransomware is detected, this Skill declares a SEV1 incident, initiates the war room, orders network isolation, and assigns the forensics agent to identify the point of compromise.

Quick Start

Use the incident-commander skill to declare a SEV1 incident with ransomware detected on production servers.

Frequently Asked Questions about incident-commander

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I coordinate multi-agent incident response for a ransomware attack?

Multi-agent incident response is coordinated by declaring a SEV1 incident, initiating a war room, ordering network isolation, and assigning forensics agents to identify the point of compromise under Incident Command System discipline.

What is severity declaration in security incident command and control?

Severity declaration assigns critical SEV1 through SEV4 levels based on incident impact, allowing the incident commander to direct appropriate response tracks for containment, investigation, notification, and recovery.

How do I manage decision-making under time pressure during a data breach?

Decision-making during a data breach is managed by applying Incident Command System discipline to coordinate response tracks, drive rapid containment, and execute regulatory notifications before impact escalates.

Can I direct containment and investigation tracks simultaneously during critical infrastructure disruptions?

Yes, the system directs multiple response tracks simultaneously, assigning separate agents to containment, investigation, notification, and recovery to manage critical infrastructure disruptions effectively.

What is the best way to command security operations during an active security incident?

The best way to command security operations is using an incident commander that applies Incident Command System discipline, declares severity levels, assigns response tracks, and coordinates multi-agent efforts for decisive control.

When do I need to initiate regulatory notification during incident response?

Regulatory notification is initiated as a coordinated response track after severity declaration and initial containment, ensuring compliance obligations are met while investigation and recovery tracks proceed in parallel.