Incidents & on-call
856 rows from 236 repositories
When it is already broken in production.
What Incidents & on-call skills agree on
203 skill files read, by 209 of the 214 authors on this shelf whose files we hold, 2026-09-06
Counted by distinct author, so one author publishing three of these counts once. Where a claim sits in fewer files than authors, that is said: a claim held by forty authors across three files is one file people copied, not forty people who agreed. Near-identical wordings are grouped and the other wordings are shown, so the grouping is yours to check.
What they tell the agent to do
- Give each action item an owner and due date25 of 209 in 23 filesalso worded as Assign each action item an owner and due date; give every action item an owner and deadline
- Conduct blameless postmortem within 48 hours13 of 209 in 10 filesalso worded as Write a post-mortem within 48 hours; Conduct blameless post-mortems within 48 hours
- Mitigate impact before investigating root cause11 of 209 in 10 filesalso worded as Mitigate before diagnosing root cause; Mitigate customer impact before investigating root cause
- Apply Five Whys to identify root cause11 of 209 in 9 filesalso worded as Use five-whys for root cause analysis; Run 5-Whys to the root cause
- Try rollback first when a recent deploy caused it9 of 209 in 8 filesalso worded as roll back first when the incident correlates with a deploy; Roll back first when onset follows a deploy
- Keep post-mortems blameless8 of 209 in 7 filesalso worded as Facilitate blameless postmortems; Run post-mortems blamelessly
- Write blameless postmortems for all incidents8 of 209 in 6 filesalso worded as Write a blameless postmortem after incidents; Write blameless postmortem with action items and owners
- Create a runbook for every new alert8 of 209also worded as Link each alert to its runbook; Map every monitoring alert to a runbook
- Track action items to completion7 of 209also worded as Track action item completion to prevent recurrence; Track action items to closure
- Run automated enumeration scripts like linPEAS or winPEAS7 of 209 in 2 filesalso worded as Run automated enumeration scripts
- Update stakeholders every 15-30 minutes7 of 209 in 5 filesalso worded as Update stakeholders every 15-30 minutes during critical incidents; Send stakeholder updates every 30 minutes
- Give every action item an owner and priority7 of 209also worded as give each action item an owner and done-condition; Assign every action item an owner
- Assign an Incident Commander7 of 209also worded as Assign an Incident Commander to own coordination; Assign one named incident commander
- Detect and classify incident severity6 of 209 in 4 filesalso worded as Determine incident severity; classify incident severity before mitigating
- Contain the incident before investigating root cause6 of 209also worded as Contain impact before diagnosing root cause; Contain the incident before investigating.
What they tell it not to do
- Do not blame individuals21 of 209 in 18 filesalso worded as Do not blame individuals; Do not blame individuals in postmortems
- Do not skip postmortems or assign blame11 of 209 in 8 filesalso worded as Skipping the post-mortem; Never assign blame in postmortems
- Never blame individuals11 of 209also worded as blaming individuals; Never blame individuals
- Do not test without written authorization9 of 209 in 4 filesalso worded as Testing clusters without written authorization; Never operate without written authorization
- Do not alert on symptoms without actionable runbooks7 of 209 in 5 filesalso worded as Creating an alert without a runbook; Alerting on causes instead of symptoms
- Do not blame the author7 of 209also worded as Blaming individuals for the incident; Do not blame the author
- Do not stop at first-order effects6 of 209 in 4 filesalso worded as Stopping at first-order effects; Do not stop at the first symptom
- Do not skip small incidents6 of 209 in 4 filesalso worded as Skipping post-mortems for small incidents; Don't skip small incidents
- Do not use blame language6 of 209also worded as Never use blame language in customer messages; Don't use blame language
- Do not exceed three variables per scenario5 of 209 in 3 filesalso worded as Exceeding three variables per scenario; more than three variables per scenario
What they expect to be installed
- git log16 of 209
- kubectl14 of 209 in 9 files
- jq13 of 209 in 11 files
- grep11 of 209
- git10 of 209
- curl10 of 209
- Slack10 of 209
- PagerDuty9 of 209
- Terraform9 of 209 in 7 files
- LinPEAS8 of 209 in 3 files
What they ask it to produce
- Postmortem document45 of 209 in 40 filesalso worded as Blameless postmortem document; Post-mortem document
- Incident timeline18 of 209 in 16 filesalso worded as Timestamped incident timeline; Live incident timeline
- Status page updates17 of 209 in 15 filesalso worded as Status page updates and stakeholder briefings; Status page update
- Action items with owners and due dates15 of 209 in 13 filesalso worded as Action items with owners and deadlines; Action items with owners, dates, and tickets
- Blameless postmortems15 of 209 in 13 filesalso worded as blameless postmortem; Blameless post-mortem document
- Root cause analysis7 of 209 in 5 filesalso worded as 5-Whys root-cause analysis; root cause analysis with session evidence
- Incident response report7 of 209also worded as Incident report; Inline incident response report
- Postmortem with action items and owners7 of 209also worded as Postmortem with owned action items; Postmortem action items
When Incidents & on-call authors say to reach for one
The situations these authors wrote into their own files, counted out of the same 209 authors, with the skills that name each one
- User asks to document an incident10 of 209
- Defining SLIs or SLOs7 of 209 in 5 files
- SEV1 or SEV2 incident occurs7 of 209 in 5 files
- Incident response
- and 3 more on this shelf
- Production incident requiring immediate response7 of 209 in 5 files
- Incident response incident response
- and 2 more on this shelf
- An alert fires6 of 209
- Incident response
- and 3 more on this shelf
- Strategic decision with major downside5 of 209 in 3 files
- Scenario war room
- and 1 more on this shelf
How Incidents & on-call skills are built
730 skill directories by 218 authors, read from their repositories’ own file trees 2026-08-05
The middle bundle among those shipping files is 3 files, 21.0 KB beside SKILL.md
Counted by distinct author, same as above, so one author publishing forty template copies counts once. SKILL.md itself is not counted as a file, so a single-file skill is one where that file is the whole skill.
The shape
- SKILL.md is the whole skill104 of 218 authors, 383 of 730 skills
- files ship beside it114 of 218 authors, 347 of 730 skills
- executable scripts ship inside38 of 218 authors, 128 of 730 skills
The folders they converge on
- references/73 of 218 authors, 249 of 730 skills
- scripts/34 of 218 authors, 118 of 730 skills
- assets/15 of 218 authors, 29 of 730 skills
- evals/11 of 218 authors, 20 of 730 skills
- resources/10 of 218 authors, 14 of 730 skills
- examples/8 of 218 authors, 9 of 730 skills
Rootly-AI-Labs/Rootly-MCP-server/com.rootly/mcp-server MCP server
45★ repoIncident management, on-call scheduling, and intelligent analysis powered by Rootly.
Iam deceptive escalation auditor
anyshift-io/sre-skills/skills/iam-deceptive-escalation-auditor Skill
17★ repoOpen-source library of methodology-shaped SRE skills for AI agents (Apache 2.0)
Aiops autonomous incident response
ivanshamaev/de-agent-skills/group_skills/infra_dataops_group_skills/aiops_autonomous_incident_response Skill
no license15★ repoПрофессиональные Data Engineering Agent Skills для разработки AI Agentic Data Platform
runframe/runframe-mcp-server/io.github.runframe/runframe-mcp-server MCP server
4★ repoMCP server for Runframe incident management covering incidents, on-call, postmortems, and more.
obielin/responsible-ai-skills/skills/ai-incident-response Skill
2★ repoSkills framework for coding agents that enforces responsible AI practices — bias assessment, fairness testing, explainability, governance documentation, and alignment review. Auto-activates when building AI systems.
Incident Response MCP for Apache Airflow
madamak/apache-airflow-mcp-server/io.github.madamak/apache-airflow-mcp-server MCP server
2★ repoDiagnose Airflow failures from UI links with bounded logs and optional recovery actions.
nothingtosurprise/dev-docs-suite Skill
no license1★Claude Skill that generates post-mortems, ADRs, API docs & onboarding guides in seconds
sgui/sgui-stakeholder-update Skill
1★Stakeholder update skill for PO/BA/PM: reframe raw status by audience, cadence, and channel with so what + the ask.
jasontang-ai/acp/skills/abstention-escalation Skill
1★ repoACP is a reusable democratic coordination primitive for discussion under load. Relay is the reference implementation used to validate that primitive in practice.
mihailShumilov/solana-incident-response-skill/skill Skill
0★ repoLive security incident-response & war-room playbook skill for Solana (Solana AI Kit).
tarangdeep-goel-by/claude-harness/claude/skills/debug-escalation Skill
0★ repoDev-focused Claude Code harness — workflow-engine skills, in-repo memory, session continuity (/recall ↔ /vault-push), local telemetry, + a ready-to-fill vault scaffold. clone + ./install.sh and go.
joyboy257/usk/spec/examples/escalation-handling Skill
0★ repoUniversal Skills Library — a Rust schema, CLI, adapter system, and optional registry for portable AI-agent skills across Claude Code, Codex, and future harnesses.
satishTheLegend/risk-register-csf Skill
0★Claude Code skill: a solo security program as durable artifacts — a living risk register, NIST CSF 2.0 self-assessment, and a lightweight incident-response plan. The right-sized GRC slice, no SOC2 ceremony.
FastMCP server that pages on-call via 100+ notification channels (Apprise wrappe
adelaidasofia/paging-mcp/io.github.adelaidasofia/paging-mcp MCP server
0★ repoFastMCP server that pages on-call via 100+ notification channels (Apprise wrapper)
reshadat/outage-mcp/io.github.reshadat/outage-mcp MCP server
0★ repoLive service outage data from 100+ status pages. Ask your AI if Cloudflare is down.
realnaka/alphaloop/skills/agent-tool-escalation Skill
19★ repo人机投研闭环:你出方向,AI 帮你查证/选股/记账,决策权归人。A human-agent investment-research operating model as an installable skill suite.
GeoffreyCoulaud/bgcpm/plugins/post-mortem/skills/post-mortem Skill
4★ repoBiggie G's Claude Plugin Markeplace
Berektassuly/solana-audit-skill/skills/solana-incident-response Skill
3★ repoEvidence-backed Solana audit skill for Claude Code and Agent Skills: report-backed taxonomy, workflows, checklists, and public finding corpus for Anchor and native Solana security reviews.
Iabstergo1/pdf-to-study-kb/.agents/skills/kb-postmortem Skill
1★ repo对话式 agent(Claude Code / Codex)驱动的本地知识库编译器:把 PDF/DOCX/PPTX/Markdown 增量编译进一个去重、互联、可复现的 Obsidian 学习知识库。
almasumdev/awesome-mobile-observability-agent-skills/.github/skills/alerts/on-call-mobile Skill
no license1★ repoAgent skills for logging, metrics, tracing, crash reporting, and analytics in mobile apps.
anmolg1997/prepostmortem-skills/postmortem-analyst Skill
1★ repoPre-mortems and postmortems for AI coding agents: 261 tagged real-world incidents + a 12-class agentic-AI failure model, shipped as Claude Code skills.
mvdmakesthings/skills/plugins/delivery/skills/pir Skill
no license0★ repoA curated set of Claude Code plugins that add structured workflows to your AI sessions
nhattrung0911/shipwright/skills/operating-production-services Skill
0★ repoProduction-grade engineering discipline for AI coding agents — 5 composable skills (plan, build, secure, operate) for Claude Code, Codex & Gemini. Never skips a step, never fakes done.
SkillMedev/incident-response-command/skills/crisis-comms-external Skill
0★ repoSRE skills for triage, runbooks, alerting, and SLO-driven reliability ops
dunkeln/skills/skills/postmortem Skill
no license0★ reposkills like a senior developer
sarfaraz-munir/Claude-Code-Cyber-agents/.claude/skills/ciso-incident-response Skill
0★ repoHierarchical CISO AI agent swarm for Claude Code — 10 specialist agents covering risk governance, compliance, threat intelligence, vulnerability management, incident response, and AI security (OWASP LLM Top 10 / MITRE ATLAS). Includes MCP tools, Claude Code skills etc.
Ibraheemolasupogit/google-adk-healthcare-pathway-escalation-agent/skills/generate_escalation Skill
0★ repoA secure Google ADK multi-agent system for synthetic NHS pathway assessment, MCP-based evidence retrieval, guardrails and human-in-the-loop escalation review.
nexu-io/open-design/design-templates/eng-runbook Skill
85,608★ repo🎨 The open-source Claude Design alternative. 🖥️ Local-first desktop app. 🖼️ Your coding agent becomes the design engine: prototypes, landing pages, dashboards, slides, images & video — real files, HTML/PDF/PPTX/MP4 export. 🤖 Claude Code / Codex / Cursor / Gemini / OpenCode / Qwen & 20+ CLIs via BYOK.
nexu-io/open-design/plugins/_official/examples/eng-runbook Skill
85,608★ repo🎨 The open-source Claude Design alternative. 🖥️ Local-first desktop app. 🖼️ Your coding agent becomes the design engine: prototypes, landing pages, dashboards, slides, images & video — real files, HTML/PDF/PPTX/MP4 export. 🤖 Claude Code / Codex / Cursor / Gemini / OpenCode / Qwen & 20+ CLIs via BYOK.
Incident response incident response
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/incident-response-incident-response Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/incident-response-smart-fix Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/linux-privilege-escalation Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/on-call-handoff-patterns Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/pagerduty-automation Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/postmortem-writing Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/privilege-escalation-methods Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
Seo forensic incident response
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/seo-forensic-incident-response Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/windows-privilege-escalation Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
Incident response incident response
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/incident-response-incident-response Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/incident-response-smart-fix Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/linux-privilege-escalation Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/on-call-handoff-patterns Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/pagerduty-automation Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/postmortem-writing Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/privilege-escalation-methods Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
Seo forensic incident response
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/seo-forensic-incident-response Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/windows-privilege-escalation Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-bundle-aas-observability-ir/skills/postmortem-writing Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-bundle-aas-security-engineer/skills/linux-privilege-escalation Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-bundle-observability-monitoring/skills/postmortem-writing Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-bundle-security-engineer/skills/linux-privilege-escalation Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
Incident response incident response
sickn33/agentic-awesome-skills/skills/incident-response-incident-response Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/incident-response-smart-fix Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/linux-privilege-escalation Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/on-call-handoff-patterns Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/pagerduty-automation Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/postmortem-writing Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/privilege-escalation-methods Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
Seo forensic incident response
sickn33/agentic-awesome-skills/skills/seo-forensic-incident-response Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/windows-privilege-escalation Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.