incident-response is agent-read markdown (skill) from cbrock84/headcount: Runs a security incident from detection to closure — triage, containment, investigation, communication, and the review afterward. Use this when a compromise is suspected or confirmed, when preparing an incident response plan or running an exercise, when deciding whether something is an incident, or when a breach may trigger notification obligations..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Incident response
> Breach notification runs on statutory clocks, measured in hours in several regimes. Involve Legal
> & Risk and qualified counsel as soon as personal data may be involved — not after the technical
> work is done.
## Decide it is an incident, and say so
The most expensive delay is the hour spent debating whether this is really an incident. Declare
early; standing down a declared incident is cheap, and discovering an hour late that it was real is
not.
Name an **incident commander** immediately. One person, coordinating, not doing the technical work.
Everyone else has a defined job. Incidents fail on coordination far more than on technical
capability.
## Order of operations
**1. Contain before investigating.** Stop the bleeding: isolate the host, revoke the credential,
disable the account, block the path. It is tempting to watch the attacker to learn more — do that
only with a deliberate decision, not by default.
**2. Preserve evidence while containing.** Snapshot before you rebuild. Capture volatile state —
memory, connections, running processes — before powering anything off. Rebuilding a compromised host
…
Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
A 17 of 17 checks passed. Deterministic, no model, same answer every run.
pass: Frontmatter block present
pass: Frontmatter declares a name
pass: Frontmatter declares a description
pass: Size between 200 bytes and 200 KB (4096 bytes)
pass: No zero-width or bidi control characters
pass: No instruction hidden inside an HTML comment
pass: No link to an exfiltration or paste host
pass: No credential-shaped string
pass: No instruction to send local credentials anywhere
pass: No text hidden with inline styles
pass: No prompt-injection phrasing
pass: No curl or wget piped into a shell
pass: No recursive delete of root, home or parent
pass: No instruction to read or print local credentials
pass: No base64 blob over 200 characters
pass: No link to a raw IP address
pass: No script tag
Source
GitHub
cbrock84/headcount · 1,664 stars · license MIT · pushed 2026-09-17 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_4bl4txtiupndnfgb
GET https://markdownregistry.com/api/v1/resolve?ref=cbrock84/headcount/incident-response
GET https://markdownregistry.com/api/v1/blob/618efd67adade17d444b68da643009e7ec6dc23128e30ac9d4b63290e4b0bb59
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
cbrock84/headcount · plugins/corporate-strategy/skills/chief-strategy-officer/SKILL.md · Owns where the business plays and how it wins over a multi-year horizon — portfolio choices, corporate development…
cbrock84/headcount · plugins/corporate-strategy/skills/market-entry/SKILL.md · Decides whether and how to enter a new market — sizing demand from the bottom up rather than from a market report…
cbrock84/headcount · plugins/corporate-strategy/skills/portfolio-strategy/SKILL.md · Decides where capital and attention go across business lines, products, and markets — what to fund, hold, harvest, or…
cbrock84/headcount · plugins/corporate-strategy/skills/scenario-planning/SKILL.md · Plans under genuine uncertainty — building scenarios, identifying which assumptions are load-bearing, setting…
cbrock84/headcount · plugins/corporate-strategy/skills/strategic-alliances/SKILL.md · Structures partnerships that change what the business can do — technology integrations, channel and reseller…
cbrock84/headcount · plugins/customer-experience/skills/chief-customer-officer/SKILL.md · Owns the customer's experience after the sale — support, success, escalation, and the feedback loop back into product…
cbrock84/headcount · plugins/customer-experience/skills/customer-onboarding-and-implementation/SKILL.md · Takes a new customer from signature to working — setting a definition of live that both sides agreed before the…
cbrock84/headcount · plugins/customer-experience/skills/customer-success-management/SKILL.md · Runs the ongoing relationship with accounts after the sale — segmenting coverage against account value, building a…
cbrock84/headcount · plugins/customer-experience/skills/escalation-management/SKILL.md · Handles customer situations that have exceeded normal support — severity assessment, incident communication, executive…
cbrock84/headcount · plugins/customer-experience/skills/self-service-and-knowledge/SKILL.md · Builds the help center, in-product guidance, and knowledge base that let customers resolve problems without contacting…
cbrock84/headcount · plugins/customer-experience/skills/support-operations/SKILL.md · Designs and runs the support function — channels, queues, routing, staffing, service levels, quality, and the metrics…
rampstackco/claude-skills · skills/incident-response/SKILL.md · Manage active production incidents through detection, triage, mitigation, communication, and resolution with structured…
hypnguyen1209/offensive-claude · skills/incident-response/SKILL.md · Use when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3…
stbenjam/skillsaw · tests/fixtures/apm/clean/.apm/skills/incident-response/SKILL.md · Triage and respond to production incidents. Use when handling an outage.
nahid-sparktales/agent-dispatcher · skills/devops/incident-response/SKILL.md · Stabilize a system that is failing right now — name the signal that flagged it, size the blast radius in numbers, keep…
aethrox/doctrine · skills/incident-response/SKILL.md · Discipline for the full incident lifecycle, declaring and sizing an incident by severity, separating the…