incident-response

Coordinate live incident triage and postmortem scaffolding for outages.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/Sokoliem/ultraprompt --skill incident-response-sokoliem
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-response
Source: https://github.com/Sokoliem/ultraprompt/tree/main/skills/incident-response
Command: npx skills add https://github.com/Sokoliem/ultraprompt --skill incident-response-sokoliem

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill provides a disciplined, collaborative workflow for live incident triage and subsequent postmortems, ensuring structured state capture, timelines, and action items.

Core Features & Use Cases

  • Live incident triage: captures symptom, blast radius, affected services, current mitigation, and detection timeline.
  • Structured postmortem scaffolding: generates root cause hypotheses, contributing factors, and measurable action items with owners.
  • Agent delegation and depth: defaults to incident-commander, with options for deeper analysis using /ultraprompt:debug or related playbooks.
  • Artifact generation: outputs a postmortem draft link and gap-ledger entries when a structural fix is required.
  • Safety and validation: enforces evidence-led outputs and measurable targets.

Quick Start

Trigger the live incident workflow by providing an incident-id or description to the assistant and review the generated timeline, root cause hypotheses, and action items.

Frequently Asked Questions about incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure live incident triage for a Sev-1 outage?

Live incident triage for a Sev-1 outage requires structured state capture, including the symptom, blast radius, affected services, current mitigation status, and detection timeline to coordinate a rapid response.

What is included in an evidence-led postmortem scaffolding process?

Evidence-led postmortem scaffolding includes generating root cause hypotheses, identifying contributing factors, and defining measurable action items with assigned owners to prevent recurrence.

Can I use this incident management workflow for recently resolved outages?

Yes, you can apply this incident management workflow to recently resolved outages to scaffold postmortems, assess the blast radius, and assign owners for structural fixes.

How do I capture a timeline during a war-room scenario?

Capturing a timeline during a war-room scenario involves recording the detection time, mitigation steps, and impact changes to produce a structured output for postmortem analysis.

What is the best way to assign owners for action items after an incident?

The best way to assign owners for action items is through structured postmortem scaffolding that generates measurable targets and gap-ledger entries for required structural fixes.

Does incident response handling require a specific incident commander setup?

Incident response handling defaults to an incident-commander delegation model but allows deeper analysis using debug playbooks for active outages and root-cause triage.