incident-response is agent-read markdown (skill) from drafthq/draft: Incident management lifecycle — triage, communicate, mitigate, postmortem. Three modes — new (start incident), update (status update), postmortem (blameless RCA report)..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Incident Response
You are managing an incident through its full lifecycle using structured incident management practices.
## Red Flags — STOP if you're
- Fixing before communicating (stakeholders must know first)
- Skipping severity classification
- Writing a postmortem with blame (blameless only)
- Closing an incident without prevention items
- Ignoring rollback as a mitigation option
**Communicate first. Fix second. Learn always.**
---
## Pre-Check
1. Check for Draft context:
```bash
ls draft/ 2>/dev/null
```
This skill works standalone — incidents don't wait for project setup.
2. If available, follow the base procedure in `core/shared/draft-context-loading.md`.
## Step 1: Parse Arguments
- `/draft:incident-response new <description>` — Start new incident
- `/draft:incident-response update <status>` — Post status update
- `/draft:incident-response postmortem` — Generate postmortem report
- `/draft:incident-response` (no args) — Interactive: ask which mode
---
## NEW Mode — Start Incident
### Step 2: Triage
Classify severity:
| Level | Response Time | Who | Examples |
|-------|--------------|-----|---------|
…
Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
A 17 of 17 checks passed. Deterministic, no model, same answer every run.
pass: Frontmatter block present
pass: Frontmatter declares a name
pass: Frontmatter declares a description
pass: Size between 200 bytes and 200 KB (8421 bytes)
pass: No zero-width or bidi control characters
pass: No instruction hidden inside an HTML comment
pass: No link to an exfiltration or paste host
pass: No credential-shaped string
pass: No instruction to send local credentials anywhere
pass: No text hidden with inline styles
pass: No prompt-injection phrasing
pass: No curl or wget piped into a shell
pass: No recursive delete of root, home or parent
pass: No instruction to read or print local credentials
pass: No base64 blob over 200 characters
pass: No link to a raw IP address
pass: No script tag
Source
GitHub
drafthq/draft · 40 stars · license MIT · pushed 2026-09-23 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_ydd7vit5caclg4k7
GET https://markdownregistry.com/api/v1/resolve?ref=drafthq/draft/incident-response
GET https://markdownregistry.com/api/v1/blob/db3afdeda7a003613511cf77bc6b60d14935065b871fb4f8780203ed73fde0b3
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
drafthq/draft · skills/bughunt/SKILL.md · Performs an exhaustive 14-dimension bug hunt across the codebase using Draft context (architecture, tech-stack…
drafthq/draft · skills/coverage/SKILL.md · Compute code coverage for active track or module. Targets 95%+ coverage with report and justification for uncovered…
drafthq/draft · skills/decompose/SKILL.md · Decompose project or track into modules with dependency mapping. Project scope updates architecture.md and derives…
drafthq/draft · skills/deep-review/SKILL.md · Single-module production readiness audit (ACID, resilience, observability). Use to audit one service/module end-to-end…
cbrock84/headcount · plugins/security/skills/incident-response/SKILL.md · Runs a security incident from detection to closure — triage, containment, investigation, communication, and the review…
rampstackco/claude-skills · skills/incident-response/SKILL.md · Manage active production incidents through detection, triage, mitigation, communication, and resolution with structured…
hypnguyen1209/offensive-claude · skills/incident-response/SKILL.md · Use when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3…
stbenjam/skillsaw · tests/fixtures/apm/clean/.apm/skills/incident-response/SKILL.md · Triage and respond to production incidents. Use when handling an outage.
nahid-sparktales/agent-dispatcher · skills/devops/incident-response/SKILL.md · Stabilize a system that is failing right now — name the signal that flagged it, size the blast radius in numbers, keep…
aethrox/doctrine · skills/incident-response/SKILL.md · Discipline for the full incident lifecycle, declaring and sizing an incident by severity, separating the…