incident-postmortem skillA
incident-postmortem is agent-read markdown (skill) from khaledsaeed18/dotclaude: Write a blameless incident postmortem from the timeline, logs, chat transcripts, and the fix: impact with numbers, a minute-by-minute timeline, root cause as a chain of contributing factors rather than a single culprit, what went well and what did not in detection and response, and action items with owners and dates that address the causes rather than the symptom. Use after an outage, a data incident, a security event, or a near miss, or when an existing postmortem reads as blame or as a fix lis.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
A postmortem exists so the same failure cannot happen the same way again. It is blameless because the person who typed the command is never the root cause; the system that let that command do damage is. Write it within a week, while the timeline is still recoverable. ## Gather - The timeline sources: alerts (first fired), chat channel export, deploy log, commits, dashboards (screenshots with timestamps), customer reports, the incident ticket. - The fix: the PR or command that resolved it, and when the symptom cleared. - Metrics for impact: requests failed, users affected, duration, data affected, revenue or SLO budget consumed. Convert every timestamp to one timezone (UTC) with the local offset stated once. ## Structure ```markdown # Postmortem: <short title> (INC-1234) Date of incident: 2026-09-18 | Duration: 47 min (14:03 to 14:50 UTC) | Severity: SEV2 Authors: ... | Reviewed: ... | Status: action items open (3 of 5) ## Summary Three sentences: what broke, who it affected and how much, what fixed it. ## Impact …
Read the whole file at its exact version.
How to install
mdr add khaledsaeed18/dotclaude/incident-postmortem@git:20260921.8d3f9ebmdr add khaledsaeed18/dotclaude/incident-postmortem@sha256:65aefd205596ce62Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_snyp5t2qrrkl5taj)
1 badge views in 30 days
Versions
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (4384 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
khaledsaeed18/dotclaude · 5 stars · license MIT · pushed 2026-09-22 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_snyp5t2qrrkl5taj GET https://markdownregistry.com/api/v1/resolve?ref=khaledsaeed18/dotclaude/incident-postmortem GET https://markdownregistry.com/api/v1/blob/65aefd205596ce6298e2a946da93fc6efe607d42e9660073e8d8862ef18dc259
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
More from khaledsaeed18/dotclaude
Every file in khaledsaeed18/dotclaude