incident-response is agent-read markdown (skill) from nahid-sparktales/agent-dispatcher: Stabilize a system that is failing right now — name the signal that flagged it, size the blast radius in numbers, keep a timestamped log written as you go, find the last known-good state, then propose the smallest reversible mitigation and confirm recovery against that same signal. Use when production is degraded or down and time to mitigation matters more than a complete explanation. Not for a defect that is not currently failing (systematic-debugging), not for the root-cause investigation or t.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Incident response
Mitigation comes before explanation. The cause keeps; the outage does not. Every step here exists
to stop you from applying an unrecorded change you cannot undo and then calling a coincidence a fix.
## When this fires
A production system is failing or degraded **now** and the harm is ongoing. It stops firing the
moment the signal is stable again — then it is a debugging problem and a postmortem, not this.
If the symptom has already passed on its own, do not start mitigating. Preserve evidence and hand
it to investigation.
## Procedure
1. **Name the flagging signal exactly** — which alert, dashboard, query or user report, what
threshold, and the first bad timestamp. Everything you do later is judged against this one
signal. If nobody can name it, you do not yet know that anything is wrong.
2. **Open the log before investigating.** Append-only, UTC timestamps, one line per observation,
action and decision, each action recording who ran it and what happened. A timeline written
afterwards is a story assembled from memory of a stressful hour.
3. **Size the blast radius in numbers**: who (users, tenants, regions), what (endpoints, jobs,
…
Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
GET https://markdownregistry.com/api/v1/artifacts/art_dxpqjacxagt6lhw2
GET https://markdownregistry.com/api/v1/resolve?ref=nahid-sparktales/agent-dispatcher/incident-response
GET https://markdownregistry.com/api/v1/blob/19c3611421bfb2e0d1ad7f7f8fbc7b825eb07ee5446bba360fcad5e48d60bb17
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
nahid-sparktales/agent-dispatcher · skills/agent-dispatcher/SKILL.md · Route work to a specialist role and load its task-specific guidance. Use when the user invokes /agent-dispatcher, names…
nahid-sparktales/agent-dispatcher · skills/ai/agent-design/SKILL.md · Scope an agent or subagent before it is built — the one job it owns, the smallest tool set that closes that job, what…
nahid-sparktales/agent-dispatcher · skills/ai/agent-evals/SKILL.md · Build an eval suite that can actually detect a regression — cases pulled from real traffic, graders that check…
nahid-sparktales/agent-dispatcher · skills/ai/context-engineering/SKILL.md · Decide what actually occupies the model's window — progressive disclosure through an index, retrieval versus inlining…
nahid-sparktales/agent-dispatcher · skills/ai/llm-observability/SKILL.md · See what an agent actually did — one trace per run with nested model, tool and retrieval spans, token and latency…
nahid-sparktales/agent-dispatcher · skills/ai/mcp-design/SKILL.md · Build an MCP server, or bring an existing one into a project — choosing the transport, deciding which tools, resources…
nahid-sparktales/agent-dispatcher · skills/ai/memory-design/SKILL.md · Decide what an agent should remember, which layer holds it, who it is scoped to, and how a stale or contradicted memory…
nahid-sparktales/agent-dispatcher · skills/ai/model-routing/SKILL.md · Pick a model per job and degrade sensibly when one fails — a quality bar per call site, candidates compared on the same…
nahid-sparktales/agent-dispatcher · skills/ai/prompt-engineering/SKILL.md · Write or revise a prompt so it holds up — output contract, instruction placement, examples that earn their place, an…
nahid-sparktales/agent-dispatcher · skills/ai/prompt-injection-defense/SKILL.md · Treat everything an agent reads but did not author as data rather than instructions — an explicit trust boundary, a…
nahid-sparktales/agent-dispatcher · skills/ai/retrieval-rag/SKILL.md · Build and fix retrieval that actually returns the right passage — structure-aware chunking, one pinned embedding model…
nahid-sparktales/agent-dispatcher · skills/ai/structured-output/SKILL.md · Get parseable, trustworthy structured results out of a model — schema design, the enforcement mechanism the provider…
cbrock84/headcount · plugins/security/skills/incident-response/SKILL.md · Runs a security incident from detection to closure — triage, containment, investigation, communication, and the review…
rampstackco/claude-skills · skills/incident-response/SKILL.md · Manage active production incidents through detection, triage, mitigation, communication, and resolution with structured…
hypnguyen1209/offensive-claude · skills/incident-response/SKILL.md · Use when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3…
stbenjam/skillsaw · tests/fixtures/apm/clean/.apm/skills/incident-response/SKILL.md · Triage and respond to production incidents. Use when handling an outage.
aethrox/doctrine · skills/incident-response/SKILL.md · Discipline for the full incident lifecycle, declaring and sizing an incident by severity, separating the…