incident-response

Coordinate phase-driven incident response workflows with mandatory timelines and auditable records.

Updated Apr 1, 2026
One-click install
npx skills add https://github.com/hpsgd/claude-marketplace --skill incident-response-hpsgd
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-response
Source: https://github.com/hpsgd/claude-marketplace/tree/main/plugins/engineering/devops/skills/incident-response
Command: npx skills add https://github.com/hpsgd/claude-marketplace --skill incident-response-hpsgd

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Incident response teams need a repeatable, structured process to detect, classify, contain, and learn from outages and security events, reducing downtime and impact.

Core Features & Use Cases

  • Detect and classify incidents with standardized severity levels.
  • Mitigate quickly to stop bleeding, then perform root-cause analysis.
  • Produce post-mortems and prevention actions to prevent recurrence.

Quick Start

Initiate the five-phase incident response workflow and apply the recommended containment actions.

Frequently Asked Questions about incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a standardized incident response workflow for IT outages?

A standardized incident response workflow coordinates detection, classification, containment, and post-mortem analysis for IT outages. It applies a phase-driven procedure with mandatory timelines and auditable records to reduce downtime and data loss.

How do I perform root-cause analysis after a security event?

You perform root-cause analysis after a security event by first mitigating the issue to stop bleeding, then investigating the underlying causes. This workflow enforces a structured process to produce post-mortems and prevention actions to prevent recurrence.

Can I use this incident management process for security events and IT outages?

Yes, you can use this incident management process for IT incidents, security events, and outages. It requires rapid detection, containment, and post-mortem analysis to ensure consistent, repeatable responses across different event types.

How do I classify incidents with standardized severity levels?

You classify incidents with standardized severity levels during the detection phase of the workflow. This process coordinates incident response by applying consistent severity classifications to prioritize mitigation and containment actions effectively.

What is the best way to coordinate incident response to reduce downtime?

The best way to coordinate incident response to reduce downtime is applying a structured, phase-driven procedure. It enforces mandatory timelines and auditable records for detection, containment, and post-mortem analysis, ensuring a repeatable process.

When do I need a phase-driven procedure for incident management?

You need a phase-driven procedure for incident management when handling outages and security events requiring rapid detection and containment. It ensures consistent, repeatable responses by enforcing mandatory timelines and generating auditable records.