CtrlK
BlogDocsLog inGet started
Tessl Logo

incident-commander

Comprehensive incident response framework from detection through resolution and post-incident review. Battle-tested SRE/DevOps practices: severity classification, timeline reconstruction, structured post-incident analysis. Use when declaring an incident, coordinating multi-team response during an outage, leading a post-mortem, or setting up on-call practices for a new service.

56

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.gemini/skills/incident-commander/SKILL.md

The canonical home for this skill is incident-commander in alirezarezvani/claude-skills

SKILL.md
Quality
Evals
Security

Quality

Content

38%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is rich and well-sectioned but bloated with generic best-practice and tool-list padding, inlines material that should live in reference files, and references script/asset files that are not shipped. Executability is undermined by the missing bundle.

Suggestions

Move the full communication templates, runbook template, and best-practices/tool-integration lists into files under references/ and keep SKILL.md as a concise overview with one-level-deep links, so the referenced paths actually exist.

Ship the referenced scripts/ and assets/ files (incident_classifier.py, timeline_reconstructor.py, pir_generator.py and the sample JSON) so the Usage Example commands are genuinely executable, or replace them with inline self-contained examples.

Trim generic guidance Claude already knows ('Maintain Calm Leadership', 'Use clear, jargon-free language', the PagerDuty/Datadog inventory) to reduce token overhead and raise conciseness.

DimensionReasoningScore

Conciseness

Noticeably verbose: large inlined communication templates, a runbook template, and a 'Best Practices' section ('Maintain Calm Leadership', 'Use clear, jargon-free language') plus a tool-integration list (PagerDuty, Datadog, etc.) that largely restates knowledge Claude already has.

2 / 5

Actionability

Usage Examples give concrete bash invocations with real flags (--detect-phases, --rca-method fishbone), but the referenced scripts (scripts/incident_classifier.py) and assets do not exist in the bundle, so the commands are not actually runnable, and templates remain placeholder fill-in-the-blanks.

3 / 5

Workflow Clarity

The framework is sequenced (detection → response → recovery → PIR) and the runbook template offers checkboxed steps with validation checkpoints, but validation is template-level/implicit rather than enforced in the main Usage Example flow (classify → timeline → PIR has no verify gates).

3 / 5

Progressive Disclosure

Heavy inlining of content that belongs in separate files (full communication templates, runbook template, best practices, tool lists), and the single signaled reference ('→ See references/reference-information.md') plus the scripts/assets paths point to files that are absent from the bundle.

2 / 5

Total

10

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, concrete description that clearly states capabilities and explicit use-when triggers. Minor room to add operational synonyms and an explicit disambiguation from security incident response.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'severity classification, timeline reconstruction, structured post-incident analysis' and 'declaring an incident, coordinating multi-team response... leading a post-mortem, setting up on-call practices' — covering the framework comprehensively.

5 / 5

Completeness

Explicitly answers both what ('Comprehensive incident response framework... severity classification, timeline reconstruction, structured post-incident analysis') and when ('Use when declaring an incident...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Strong natural triggers ('declaring an incident', 'during an outage', 'leading a post-mortem', 'on-call practices'), but missing common operational synonyms like SEV1/SEV2, war room, or status page that users would also say.

4 / 5

Distinctiveness Conflict Risk

Operational niche is clear (outage, on-call, SRE/DevOps, post-mortem), but 'incident response' framing carries minor overlap risk with a security incident-response skill; the description itself does not state the availability-vs-security boundary.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 11 missing

Warning

Total

15

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.