security-incident-response

Coordinate security incident response workflows for triage, containment, eradication, and recovery.

7|Updated Feb 14, 2026
One-click install
npx skills add https://github.com/KentoShimizu/sw-agent-skills --skill security-incident-response-kentoshimizu
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-incident-response
Source: https://github.com/KentoShimizu/sw-agent-skills/tree/main/skills/security-incident-response
Command: npx skills add https://github.com/KentoShimizu/sw-agent-skills --skill security-incident-response-kentoshimizu

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes assets (resource) components.

What problem does it solve?

Security incident workflow to triage, contain, eradicate, and recover with evidence handling and coordination across teams.

Core Features & Use Cases

  • Structured incident triage and classification to determine severity and priority.
  • Evidence-preserving timeline creation, containment planning, and remediation actions.
  • Recovery validation, post-incident review, and regulatory/compliance documentation.

Quick Start

Initiate the incident response workflow for a suspected security incident using the provided timeline template and escalation contacts.

Frequently Asked Questions about security-incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I coordinate a security incident response workflow to minimize blast radius?

A security incident response workflow coordinates triage, containment, eradication, and recovery planning across systems and stakeholders to minimize blast radius. It enforces evidence handling, chain-of-custody, and formal deliverables like a detailed timeline.

What is the best way to preserve digital evidence and maintain chain-of-custody during an ongoing security incident?

To preserve digital evidence during an incident, the workflow enforces strict evidence handling and chain-of-custody protocols. It generates formal deliverables including an evidence-preserving timeline and containment plan to ensure regulatory compliance.

How do I structure incident triage and classification to determine severity and priority?

Incident triage and classification structures severity and priority determination by systematically evaluating suspected security incidents. This process initiates the workflow, guiding containment planning, eradication actions, and recovery validation.

Can I use this incident response workflow for regulatory and compliance documentation after an attack?

Yes, this incident response workflow supports regulatory and compliance documentation by producing formal deliverables. It includes recovery validation, post-incident review, and evidence-preserving timelines required for compliance reporting.

What deliverables do I need for a complete security incident recovery validation and post-incident review?

Complete recovery validation and post-incident review require formal deliverables including a detailed incident timeline, containment and eradication plan, and recovery validation records. These ensure evidence integrity and coordinate stakeholder communication.