incident-responder

Provides emergency-response steps for securing compromised systems, including quarantine, diagnosis, credential reset, and recovery workflows.

Updated Mar 15, 2026
One-click install
npx skills add https://github.com/wongdean/knowledge-base --skill incident-responder-wongdean
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-responder
Source: https://github.com/wongdean/knowledge-base/tree/main/backups/openclaw-config/20260315_232439/workspace-skills/openclaw-skills-security/skills/incident-responder
Command: npx skills add https://github.com/wongdean/knowledge-base --skill incident-responder-wongdean

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides a structured and immediate response plan for security incidents within an OpenClaw environment, minimizing damage and guiding users through critical recovery steps.

Core Features & Use Cases

  • Incident Triage: Classifies incidents based on severity levels (SEV-1 to SEV-4).
  • Phased Response: Guides users through Containment, Investigation, Credential Rotation, and Recovery.
  • Evidence Preservation: Details how to safely collect logs, screenshots, and skill configurations.
  • Use Case: When a user suspects a malicious skill has been installed, this Skill provides a clear, step-by-step checklist to immediately contain the threat, investigate its impact, rotate compromised credentials, and restore the environment to a secure state.

Quick Start

Guide me through responding to a suspected malicious skill installation.

Frequently Asked Questions about incident-responder

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I respond to a security breach in OpenClaw?

Incident response for suspected malicious skills involves immediate threat containment, impact investigation, compromised credential rotation, and secure state restoration. The protocol provides step-by-step checklists for each recovery phase.

How do I classify the severity of a security incident?

Incident triage classifies security events from SEV-1 to SEV-4 based on severity. This classification determines the phased response protocol, ensuring appropriate containment and recovery actions are taken.

What is the best way to preserve evidence during a security incident?

Evidence preservation during incident response involves safely collecting logs, screenshots, and skill configurations. This ensures structured incident documentation and accurate reporting for post-incident analysis and recovery.

How do I contain active data exfiltration from a compromised environment?

Containing active data exfiltration requires immediate execution of quick response commands to isolate the threat. The incident response protocol provides specific checklists to stop ongoing data loss and secure the environment.

Can this incident response protocol handle policy violations?

Yes, the incident response protocol handles policy violations alongside active data exfiltration scenarios. It provides structured documentation, investigation steps, and recovery checklists tailored to each specific security incident type.