vantage-incident-triage

Create tenant-scoped incident records and generate immediate action plans.

Updated Feb 20, 2026
One-click install
npx skills add https://github.com/johngutierrez31/VantageAI --skill vantage-incident-triage
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vantage-incident-triage
Source: https://github.com/johngutierrez31/VantageAI/tree/main/.agents/skills/vantage-incident-triage
Command: npx skills add https://github.com/johngutierrez31/VantageAI --skill vantage-incident-triage

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill streamlines the initial response to security incidents by creating structured records, classifying incidents, and generating immediate action plans, preventing critical startup steps from being missed or handled inconsistently.

Core Features & Use Cases

  • Incident Record Creation: Establishes a durable, tenant-scoped record for each incident.
  • Automated Triage: Classifies incident type, severity, and ownership, then generates immediate actions, evidence collection steps, and communication plans.
  • Runbook Integration: Launches or recommends linked runbook packs for guided incident response.
  • Use Case: When a ransomware alert is triggered, this Skill can automatically create an incident record, assign an owner, define immediate containment actions, and suggest the ransomware runbook.

Quick Start

Start a new incident triage workflow for a ransomware scenario.

Frequently Asked Questions about vantage-incident-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate incident triage for ransomware and phishing alerts?

Incident triage automation creates structured, tenant-scoped incident records for ransomware and phishing alerts, then classifies severity and generates immediate action plans to standardize first-hour response.

What is the best way to launch an incident response workflow with a runbook?

Launching an incident response workflow establishes a durable record, assigns ownership, and recommends linked runbook packs to provide guided, consistent response steps for known security scenarios.

How does incident management automation handle evidence collection and communication?

Incident management automation classifies the event and automatically generates structured evidence collection steps and communication plans alongside immediate containment actions within the incident record.

Can I use incident triage automation for cloud exposure security scenarios?

Yes, incident triage automation supports guided startup for cloud exposure scenarios, creating a tenant-scoped incident record and generating immediate actions to address the security exposure.

Do I need a tenant-scoped environment to create structured incident records?

Yes, tenant-scoped incident creation is required to establish durable incident records, ensuring that triage actions, evidence collection, and ownership are properly tracked within your environment.