Home / drafthq / draft · skills/incident-response/SKILL.md · GitHub

incident-response skillA

incident-response is agent-read markdown (skill) from drafthq/draft: Incident management lifecycle — triage, communicate, mitigate, postmortem. Three modes — new (start incident), update (status update), postmortem (blameless RCA report)..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# Incident Response

You are managing an incident through its full lifecycle using structured incident management practices.

## Red Flags — STOP if you're

- Fixing before communicating (stakeholders must know first)
- Skipping severity classification
- Writing a postmortem with blame (blameless only)
- Closing an incident without prevention items
- Ignoring rollback as a mitigation option

**Communicate first. Fix second. Learn always.**

---

## Pre-Check

1. Check for Draft context:

```bash
ls draft/ 2>/dev/null
```

This skill works standalone — incidents don't wait for project setup.

2. If available, follow the base procedure in `core/shared/draft-context-loading.md`.

## Step 1: Parse Arguments

- `/draft:incident-response new <description>` — Start new incident
- `/draft:incident-response update <status>` — Post status update
- `/draft:incident-response postmortem` — Generate postmortem report
- `/draft:incident-response` (no args) — Interactive: ask which mode

---

## NEW Mode — Start Incident

### Step 2: Triage

Classify severity:

| Level | Response Time | Who | Examples |
|-------|--------------|-----|---------|
…

Read the whole file at its exact version.

How to install

Latest version
mdr add drafthq/draft/incident-response@git:20260819.fda278e
Exact content
mdr add drafthq/draft/incident-response@sha256:db3afdeda7a00361

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_ydd7vit5caclg4k7.svg)](https://markdownregistry.com/a/art_ydd7vit5caclg4k7)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260819.fda278e latest2026-08-19 fda278e 8,421 BA view · diff
git:20260517.6abc7982026-05-17 6abc798 8,415 BA view · diff
git:20260510.83cfec72026-05-10 83cfec7 7,073 BA view · diff
git:20260510.63773a12026-05-10 63773a1 6,920 BA view · diff
git:20260426.17a20372026-04-26 17a2037 6,930 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (8421 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

drafthq/draft · 40 stars · license MIT · pushed 2026-09-23 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_ydd7vit5caclg4k7
GET https://markdownregistry.com/api/v1/resolve?ref=drafthq/draft/incident-response
GET https://markdownregistry.com/api/v1/blob/db3afdeda7a003613511cf77bc6b60d14935065b871fb4f8780203ed73fde0b3

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from drafthq/draft

CLAUDE.md claude
drafthq/draft · CLAUDE.md
git:20260922.4c0dba0 · audit A · 40 stars
AGENTS.md@integrations/agents agents
drafthq/draft · integrations/agents/AGENTS.md
git:20260922.ade990d · audit C · 40 stars
adr skill
drafthq/draft · skills/adr/SKILL.md · Create and manage Architecture Decision Records. Documents significant technical decisions with context, alternatives…
git:20260819.fda278e · audit A · 40 stars
assist-review skill
drafthq/draft · skills/assist-review/SKILL.md · Reviewing someone else's PR for handoff/sign-off. Isolates structural changes from trivial edits, flags HLD/LLD drift…
git:20260819.fda278e · audit A · 40 stars
bughunt skill
drafthq/draft · skills/bughunt/SKILL.md · Performs an exhaustive 14-dimension bug hunt across the codebase using Draft context (architecture, tech-stack…
git:20260819.fda278e · audit B · 40 stars
change skill
drafthq/draft · skills/change/SKILL.md · Handle mid-track requirement changes. Analyzes impact on completed and pending tasks, proposes amendments to spec.md…
git:20260819.fda278e · audit A · 40 stars
coverage skill
drafthq/draft · skills/coverage/SKILL.md · Compute code coverage for active track or module. Targets 95%+ coverage with report and justification for uncovered…
git:20260819.fda278e · audit A · 40 stars
debug skill
drafthq/draft · skills/debug/SKILL.md · Structured debugging session. Reproduce, isolate, diagnose, and fix bugs using systematic investigation. Invoked by…
git:20260819.fda278e · audit A · 40 stars
decompose skill
drafthq/draft · skills/decompose/SKILL.md · Decompose project or track into modules with dependency mapping. Project scope updates architecture.md and derives…
git:20260819.fda278e · audit A · 40 stars
deep-review skill
drafthq/draft · skills/deep-review/SKILL.md · Single-module production readiness audit (ACID, resilience, observability). Use to audit one service/module end-to-end…
git:20260819.fda278e · audit A · 40 stars
deploy-checklist skill
drafthq/draft · skills/deploy-checklist/SKILL.md · Pre-deployment verification checklist. Generates customized checklists based on tech-stack with rollback triggers…
git:20260819.fda278e · audit A · 40 stars
discover skill
drafthq/draft · skills/discover/SKILL.md · Primary router for discovery, debugging, investigation, quality, and exploration workflows. Analyzes user intent and…
git:20260614.c276954 · audit A · 40 stars

Every file in drafthq/draft

Other files named incident-response

incident-response skill
cbrock84/headcount · plugins/security/skills/incident-response/SKILL.md · Runs a security incident from detection to closure — triage, containment, investigation, communication, and the review…
git:20260916.0e7cd01 · audit A · 1,664 stars
incident-response skill
rampstackco/claude-skills · skills/incident-response/SKILL.md · Manage active production incidents through detection, triage, mitigation, communication, and resolution with structured…
git:20260810.e5bc675 · audit A · 898 stars
incident-response skill
hypnguyen1209/offensive-claude · skills/incident-response/SKILL.md · Use when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3…
git:20260630.df7d895 · audit A · 378 stars
incident-response skill
miosa-osa/osa · priv/skills/incident-response/SKILL.md · Investigate suspected compromise, preserve incident evidence, build a timeline and plan containment, recovery and…
v1.0.200 · audit A · 74 stars
incident-response skill
stbenjam/skillsaw · tests/fixtures/apm/clean/.apm/skills/incident-response/SKILL.md · Triage and respond to production incidents. Use when handling an outage.
v1.2 · audit A · 66 stars
incident-response skill
nahid-sparktales/agent-dispatcher · skills/devops/incident-response/SKILL.md · Stabilize a system that is failing right now — name the signal that flagged it, size the blast radius in numbers, keep…
git:20260919.a0d4f55 · audit A · 49 stars
incident-response skill
eltmon/overdeck · sync-sources/skills/incident-response/SKILL.md · Structured approach to production incidents
git:20260522.817c2c7 · audit A · 28 stars
incident-response skill
aethrox/doctrine · skills/incident-response/SKILL.md · Discipline for the full incident lifecycle, declaring and sizing an incident by severity, separating the…
git:20260809.2a45dbb · audit A · 18 stars

Browse by kind, by grade A, or by owner.