incident-response

Create or update incident response plans for CNCF projects.

2|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/castrojo/cncf-skills --skill incident-response-castrojo
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-response
Source: https://github.com/castrojo/cncf-skills/tree/main/skills/incident-response
Command: npx skills add https://github.com/castrojo/cncf-skills --skill incident-response-castrojo

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps CNCF project maintainers create or update a comprehensive incident response plan, ensuring a structured and effective approach to handling security incidents and service outages.

Core Features & Use Cases

  • Structured Plan Creation: Guides users through documenting detection, triage, remediation, communication, and post-incident review processes.
  • Alignment with Security Policies: Ensures consistency with existing SECURITY.md files and graduation requirements.
  • Use Case: A project is preparing for a security audit and needs to demonstrate a clear, documented process for responding to vulnerabilities. This Skill provides the framework to build that plan.

Quick Start

Use the incident-response skill to create or update the project's incident response plan.

Frequently Asked Questions about incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I document an incident response plan for a CNCF project?

To document an incident response plan for a CNCF project, you can generate a structured runbook detailing detection, triage, remediation, communication, and post-incident review processes. This ensures alignment with security policies and graduation criteria.

What should be included in a security incident response runbook?

A security incident response runbook should include detailed processes for vulnerability detection, triage, remediation, and communication, alongside a post-incident review. It must address both security incidents and service outages while cross-referencing your security self-assessment.

Do I need a SECURITY.md file to create an incident response plan?

Having a SECURITY.md file is not strictly required, but the incident response plan ensures consistency with your existing security policies. It cross-references your security self-assessment to align the documented runbook with established project guidelines.

What's the best way to prepare a vulnerability management plan for a security audit?

The best way to prepare for a security audit is to generate a comprehensive incident response plan that demonstrates a clear, documented process for handling vulnerabilities. This framework aligns your vulnerability management procedures with CNCF graduation requirements.

Can I use GitHub templates for incident response documentation?

Yes, you can fetch GitHub templates to structure your incident response documentation. The process utilizes GitHub MCP for template fetching to guide the creation and updating of your project's security incident response plan.

Why does my incident response plan need to cover service outages?

Your incident response plan must cover service outages to ensure a structured approach to handling all types of disruptions, not just security vulnerabilities. This comprehensive coverage is required to meet CNCF project graduation criteria.