agentsclimarketplace

Pilot incident response setup

Skill TeoSlayer/pilot-skills/skills/pilot-incident-response-setup

80+ agent skills for Pilot Protocol — communication, file transfer, trust, task routing, swarm coordination, and more

Install
npx -y skills add TeoSlayer/pilot-skills --skill pilot-incident-response-setup

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 7 stars7 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Deploy an incident response pipeline with 4 agents. Use this skill when: 1. User wants to set up automated incident detection and response 2. User is configuring a detector, triage, remediation, or notification agent 3. User asks about automated alerting, remediation, or escalation workflows Do NOT use this skill when: - User wants a single watchdog check (use pilot-watchdog instead) - User wants to send a one-off alert (use pilot-alert instead)

The file declares its own license as AGPL-3.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

6.2 KB, as published. Nobody here has run it

Incident Response Setup

Deploy 4 agents: detector, triage, remediator, and notifier.

Roles

RoleHostnameSkillsPurpose
detector<prefix>-detectorpilot-watchdog, pilot-alert, pilot-audit-log, pilot-metricsMonitors for anomalies
triage<prefix>-triagepilot-alert, pilot-event-filter, pilot-priority-queue, pilot-slaClassifies and routes incidents
remediator<prefix>-remediatorpilot-task-router, pilot-cron, pilot-audit-log, pilot-quarantineExecutes automated fixes
notifier<prefix>-notifierpilot-slack-bridge, pilot-email-bridge, pilot-webhook-bridge, pilot-audit-logNotifies humans

Setup Procedure

Step 1: Ask the user which role this agent should play and what prefix to use.

Step 2: Install the skills for the chosen role:

# For detector:
clawhub install pilot-watchdog pilot-alert pilot-audit-log pilot-metrics
# For triage:
clawhub install pilot-alert pilot-event-filter pilot-priority-queue pilot-sla
# For remediator:
clawhub install pilot-task-router pilot-cron pilot-audit-log pilot-quarantine
# For notifier:
clawhub install pilot-slack-bridge pilot-email-bridge pilot-webhook-bridge pilot-audit-log

Step 3: Set the hostname and write the manifest to ~/.pilot/setups/incident-response.json.

Step 4: Tell the user to initiate handshakes.

Manifest Templates Per Role

detector

{
  "setup": "incident-response", "role": "detector", "role_name": "Anomaly Detector",
  "hostname": "<prefix>-detector",
  "skills": {
    "pilot-watchdog": "Monitor for unusual traffic, error spikes, resource exhaustion.",
    "pilot-alert": "Emit structured anomaly alerts to triage.",
    "pilot-audit-log": "Log all detected anomalies for forensics.",
    "pilot-metrics": "Track detection rates, false positive ratios."
  },
  "data_flows": [{ "direction": "send", "peer": "<prefix>-triage", "port": 1002, "topic": "anomaly-detected", "description": "Raw anomaly alerts" }],
  "handshakes_needed": ["<prefix>-triage"]
}

triage

{
  "setup": "incident-response", "role": "triage", "role_name": "Incident Triage",
  "hostname": "<prefix>-triage",
  "skills": {
    "pilot-alert": "Receive raw alerts, classify severity (P1-P4).",
    "pilot-event-filter": "Filter noise and duplicates.",
    "pilot-priority-queue": "Queue incidents by priority for routing.",
    "pilot-sla": "Apply SLA policies to determine response deadlines."
  },
  "data_flows": [
    { "direction": "receive", "peer": "<prefix>-detector", "port": 1002, "topic": "anomaly-detected", "description": "Raw alerts" },
    { "direction": "send", "peer": "<prefix>-remediator", "port": 1002, "topic": "incident-action", "description": "Actionable incidents" },
    { "direction": "send", "peer": "<prefix>-notifier", "port": 1002, "topic": "incident-alert", "description": "Classified incidents" }
  ],
  "handshakes_needed": ["<prefix>-detector", "<prefix>-remediator", "<prefix>-notifier"]
}

remediator

{
  "setup": "incident-response", "role": "remediator", "role_name": "Auto-Remediator",
  "hostname": "<prefix>-remediator",
  "skills": {
    "pilot-task-router": "Execute remediation actions (restart, scale, quarantine).",
    "pilot-cron": "Run scheduled health checks.",
    "pilot-audit-log": "Log all remediation actions.",
    "pilot-quarantine": "Isolate compromised nodes."
  },
  "data_flows": [
    { "direction": "receive", "peer": "<prefix>-triage", "port": 1002, "topic": "incident-action", "description": "Actionable incidents" },
    { "direction": "send", "peer": "<prefix>-notifier", "port": 1002, "topic": "remediation-complete", "description": "Remediation reports" }
  ],
  "handshakes_needed": ["<prefix>-triage", "<prefix>-notifier"]
}

notifier

{
  "setup": "incident-response", "role": "notifier", "role_name": "Human Notifier",
  "hostname": "<prefix>-notifier",
  "skills": {
    "pilot-slack-bridge": "Post incident alerts to Slack channels.",
    "pilot-email-bridge": "Send escalation emails for P1 incidents.",
    "pilot-webhook-bridge": "Trigger external integrations (PagerDuty, Opsgenie).",
    "pilot-audit-log": "Log all notifications sent."
  },
  "data_flows": [
    { "direction": "receive", "peer": "<prefix>-triage", "port": 1002, "topic": "incident-alert", "description": "Classified incidents" },
    { "direction": "receive", "peer": "<prefix>-remediator", "port": 1002, "topic": "remediation-complete", "description": "Remediation reports" }
  ],
  "handshakes_needed": ["<prefix>-triage", "<prefix>-remediator"]
}

Data Flows

  • detector → triage : raw anomaly alerts (port 1002)
  • triage → remediator : actionable incidents (port 1002)
  • triage → notifier : classified incidents (port 1002)
  • remediator → notifier : remediation reports (port 1002)

Workflow Example

# On detector:
pilotctl --json publish <prefix>-triage anomaly-detected '{"source":"web-01","type":"error_spike","rate":450}'
# On triage:
pilotctl --json publish <prefix>-remediator incident-action '{"id":"INC-2847","severity":"P1","action":"restart_service"}'
pilotctl --json publish <prefix>-notifier incident-alert '{"id":"INC-2847","severity":"P1","summary":"Error spike on web-01"}'
# On remediator:
pilotctl --json publish <prefix>-notifier remediation-complete '{"id":"INC-2847","action":"restart_service","result":"success"}'

Dependencies

Requires pilot-protocol skill, pilotctl binary, clawhub binary, and a running daemon.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.