incident-response is agent-read markdown (skill) from eltmon/overdeck: Structured approach to production incidents.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Incident Response
## 1. Assess (First 5 minutes)
- What is the impact? (users affected, severity)
- What is the blast radius? (which services/regions)
- Is it getting worse or stable?
## 2. Mitigate (Stop the bleeding)
- Can we rollback?
- Can we feature-flag it off?
- Can we scale/redirect traffic?
- Communicate status to stakeholders
## 3. Investigate (Once stable)
- Gather logs, metrics, traces
- Identify root cause
- Document timeline of events
## 4. Fix
- Implement permanent fix
- Test thoroughly before deploying
- Deploy with extra monitoring
## 5. Postmortem
- Document: What happened, why, how we fixed it
- Identify: What would have prevented this
- Action items: Concrete improvements
Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
A 17 of 17 checks passed. Deterministic, no model, same answer every run.
pass: Frontmatter block present
pass: Frontmatter declares a name
pass: Frontmatter declares a description
pass: Size between 200 bytes and 200 KB (798 bytes)
pass: No zero-width or bidi control characters
pass: No instruction hidden inside an HTML comment
pass: No link to an exfiltration or paste host
pass: No credential-shaped string
pass: No instruction to send local credentials anywhere
pass: No text hidden with inline styles
pass: No prompt-injection phrasing
pass: No curl or wget piped into a shell
pass: No recursive delete of root, home or parent
pass: No instruction to read or print local credentials
pass: No base64 blob over 200 characters
pass: No link to a raw IP address
pass: No script tag
Source
GitHub
eltmon/overdeck · 28 stars · license MIT · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_4xwkqnujeos33ovh
GET https://markdownregistry.com/api/v1/resolve?ref=eltmon/overdeck/incident-response
GET https://markdownregistry.com/api/v1/blob/8699ae1ff8b0d48c675fb5f38cfc847f81bd2c058f0d71b9cc79b382da174f02
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
eltmon/overdeck · src/lib/caveman/skills/caveman-review/SKILL.md · Ultra-compressed code review comments. Cuts noise from PR feedback while preserving the actionable signal. Each comment…
eltmon/overdeck · src/lib/caveman/skills/caveman/SKILL.md · Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical…
eltmon/overdeck · sync-sources/dev-skills/pan-dashboard-restart/SKILL.md · Safely restart the Overdeck dashboard server (production Node 22 dist) using a detached process. Use when pan up / pan…
eltmon/overdeck · sync-sources/dev-skills/pan-skill-installer/SKILL.md · Install an external skill or Claude Code plugin into Overdeck's bundled distribution so pan sync ships it to every…
eltmon/overdeck · sync-sources/dev-skills/token-spend-report/SKILL.md · Regenerate Overdeck's public token spend report from the post-rebrand cost archive
eltmon/overdeck · sync-sources/skills/benchmark/SKILL.md · Create a benchmark issue to test Overdeck's agent pipeline. Creates a GitHub issue from a stored template with a…
cbrock84/headcount · plugins/security/skills/incident-response/SKILL.md · Runs a security incident from detection to closure — triage, containment, investigation, communication, and the review…
rampstackco/claude-skills · skills/incident-response/SKILL.md · Manage active production incidents through detection, triage, mitigation, communication, and resolution with structured…
hypnguyen1209/offensive-claude · skills/incident-response/SKILL.md · Use when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3…
stbenjam/skillsaw · tests/fixtures/apm/clean/.apm/skills/incident-response/SKILL.md · Triage and respond to production incidents. Use when handling an outage.
nahid-sparktales/agent-dispatcher · skills/devops/incident-response/SKILL.md · Stabilize a system that is failing right now — name the signal that flagged it, size the blast radius in numbers, keep…
aethrox/doctrine · skills/incident-response/SKILL.md · Discipline for the full incident lifecycle, declaring and sizing an incident by severity, separating the…