incident-response

Guide automated incident response workflows across triage, investigation, mitigation, resolution, and postmortem phases.

10|5|Updated Jan 5, 2026
One-click install
npx skills add https://github.com/phuthuycoding/moicle --skill incident-response-phuthuycoding
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-response
Source: https://github.com/phuthuycoding/moicle/tree/main/assets/skills/incident-response
Command: npx skills add https://github.com/phuthuycoding/moicle --skill incident-response-phuthuycoding

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill streamlines incident response by providing a structured, architecture-guided workflow to triage, investigate, mitigate, and postmortem production incidents, reducing downtime and improving learnings.

Core Features & Use Cases

  • Structured Phases: TRIAGE, INVESTIGATE, MITIGATE, RESOLVE, POSTMORTEM with recommended roles and templates.
  • Architecture Readiness: read global and project architecture references before action to ensure consistent fixes.
  • Templates & Checklists: Incident reports, root cause analyses, mitigation logs, and postmortems to standardize responses.
  • Collaboration & Communication: predefined channels for incident coordination and stakeholder updates.

Quick Start

Describe an incident scenario and agent assignments, then initiate the triage process by creating an incident channel, recording event times, and pulling the relevant architecture docs. For example, start with triage for a production outage and instruct the AI to gather logs, identify affected components, and draft an incident report.

Frequently Asked Questions about incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure incident response workflows for a production outage?

Automated incident response uses architecture-guided workflows to triage, investigate, mitigate, and postmortem production incidents. It reads global and project architecture references before acting to ensure consistent fixes and reduce downtime.

What is the best way to triage a production incident across complex architectures?

Triage production incidents by creating an incident channel, recording event times, and pulling relevant architecture documents. Then gather logs, identify affected components, and draft a standardized incident report to coordinate mitigation.

How does an automated incident response workflow handle postmortem reporting?

Postmortem reporting uses standardized templates and checklists to document root cause analyses and mitigation logs after resolution. This standardizes responses, improves learnings, and ensures reproducible incident workflows for future reference.

Do I need architecture references before starting incident triage and mitigation?

Yes, architecture readiness is required before acting on incidents. Reading global and project architecture references before triage and mitigation ensures consistent fixes and safe resolution across affected components during the response workflow.

How to coordinate stakeholder communication during an active incident response?

Coordinate stakeholder communication during incident response using predefined channels for incident coordination and updates. The structured workflow recommends specific roles and templates to ensure consistent updates throughout triage and mitigation phases.

What templates and runbooks are used for standardized incident mitigation?

Standardized incident mitigation uses templates for incident reports, root cause analyses, mitigation logs, and postmortems. These enforce predefined runbooks and escalation paths to ensure reproducible responses across different production architectures.