incident-responder

Guide OpenClaw security breach response through containment, investigation, credential rotation, and recovery.

70|10|Updated Feb 5, 2026
One-click install
npx skills add https://github.com/UseAI-pro/openclaw-skills-security --skill incident-responder-useai-pro
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-responder
Source: https://github.com/UseAI-pro/openclaw-skills-security/tree/main/skills/incident-responder
Command: npx skills add https://github.com/UseAI-pro/openclaw-skills-security --skill incident-responder-useai-pro

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides a structured, step-by-step playbook to guide users through the critical process of responding to security breaches within the OpenClaw ecosystem, minimizing damage and ensuring a thorough recovery.

Core Features & Use Cases

  • Incident Response Protocol: Guides users through distinct phases: Containment, Investigation, Credential Rotation, and Recovery.
  • Severity Level Assessment: Helps categorize incidents based on triggers and examples to prioritize actions.
  • Use Case: When a user suspects a malicious skill has been installed, they can load this skill to get immediate, actionable steps to contain the threat, investigate its impact, rotate compromised credentials, and restore their environment to a secure state.

Quick Start

Use the incident-responder skill to guide me through containing a suspected malicious skill installation.

Frequently Asked Questions about incident-responder

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I respond to a suspected malicious skill installation?

Incident response for security breaches involves a structured protocol covering containment, investigation, credential rotation, and recovery to minimize damage and restore system integrity.

What are the key phases of a security breach incident response protocol?

The key phases of an incident response protocol are containment, investigation, credential rotation, and recovery. This structured approach ensures thorough handling of security breaches from initial threat isolation to system restoration.

How do I assess the severity level of a security breach?

Assess security breach severity by categorizing incidents based on triggers and examples, such as critical data exfiltration versus policy violations, to prioritize response actions effectively.

What is the best way to contain a security breach and prevent data exfiltration?

The best way to contain a security breach is to execute quick response commands within a structured containment phase, isolating the threat immediately to prevent further critical data exfiltration.

Can I use this incident response protocol for OpenClaw policy violations?

Yes, you can use this incident response protocol for OpenClaw policy violations, as it addresses scenarios ranging from critical data exfiltration to minor policy infractions with detailed checklists.