CtrlK
BlogDocsLog inGet started
Tessl Logo

incident-commander

Comprehensive incident response framework from detection through resolution and post-incident review. Battle-tested SRE/DevOps practices: severity classification, timeline reconstruction, structured post-incident analysis. Use when declaring an incident, coordinating multi-team response during an outage, leading a post-mortem, or setting up on-call practices for a new service.

59

Quality

67%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

The risk profile of this skill

Fix and improve this skill with Tessl

tessl review fix ./engineering-team/skills/incident-commander/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

48%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is actionable with solid executable examples and a coherent framework, but it is over-verbose and inlines reference-grade material that belongs in the provided bundle files, with validation gaps in its batch generation workflows.

Suggestions

Move the full severity matrix, communication templates, and stakeholder cadence tables into the existing reference files (incident_severity_matrix.md, communication_templates.md, sla-management-guide.md) and keep SKILL.md as an overview that links to them.

Add explicit validation/verification steps to the timeline reconstruction and PIR generation workflows (e.g., verify timeline gaps, confirm PIR completeness before output).

Trim generic best-practice prose ('Maintain Calm Leadership', 'Blameless Culture') that reiterates concepts Claude already knows, or relocate it to a reference file.

DimensionReasoningScore

Conciseness

The 470-line body inlines extensive reference material (full severity matrix, multiple long templates, stakeholder tables) that largely restates well-known incident-response concepts, making it noticeably verbose.

2 / 5

Actionability

It provides concrete, executable usage examples with actual python commands referencing real scripts and sample assets, with only minor gaps around script options and prerequisites.

4 / 5

Workflow Clarity

Multi-step response phases and the runbook template are sequenced, but batch/destructive operations like timeline reconstruction and PIR generation lack explicit validation or verification checkpoints, capping the score at 3.

3 / 5

Progressive Disclosure

While real references/ and scripts/ bundles exist, the body inlines large amounts of content (severity matrix, templates, stakeholder matrix) that should live in those reference files, and references like reference-information.md are only sparsely signaled.

3 / 5

Total

12

/

20

Passed

Description

86%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description with concrete capabilities and an explicit 'Use when' trigger clause that addresses both what and when. Minor improvement possible by adding more natural synonyms and clarifying the SEV-label distinction more sharply.

Suggestions

Add a few more natural trigger synonyms (e.g., 'incident report', 'outage postmortem', 'SEV review') to broaden trigger coverage.

Sharpen the distinctiveness note by stating up front that this skill covers operational/availability incidents only, ahead of the security routing sentence.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions (severity classification, timeline reconstruction, structured post-incident analysis) alongside battle-tested practices, giving comprehensive coverage of capabilities.

5 / 5

Completeness

It explicitly answers both 'what' (the framework's components and practices) and 'when' via a concrete 'Use when...' clause enumerating trigger scenarios.

5 / 5

Trigger Term Quality

It includes natural phrases like 'declaring an incident', 'coordinating multi-team response during an outage', 'leading a post-mortem', and 'on-call practices', though it omits a few common synonyms such as 'incident report' or file extensions.

4 / 5

Distinctiveness Conflict Risk

The operational-impact framing and explicit routing of security events to 'incident-response' carve out a clear niche, but SEV1-SEV4 label overlap with the security skill leaves minor conflict risk.

4 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.