CtrlK
BlogDocsLog inGet started
Tessl Logo

incident-response

Manage active production incidents through detection, triage, mitigation, communication, and resolution with structured roles and decision-making. Use this skill whenever the user has an active incident, a production issue, a service outage, a security incident, or needs to plan incident response procedures. Triggers on incident response, production incident, outage, service down, site down, P0, P1, severity, downtime, on-call, incident commander, status page, postmortem prep. Also triggers when something is actively broken in production and the user is figuring out what to do.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, highly actionable incident framework with explicit validation checkpoints and a properly signaled single reference file. Its main weaknesses are minor verbosity in the data-availability section and duplication of severity/status-page material that also lives in the reference.

Suggestions

Tighten the "If required data is unavailable" section to a sentence or two; the gap-stating rule is useful but currently reads as a philosophical essay.

Deduplicate the severity rubric and status-page templates: keep a concise version in the body and defer full definitions/templates to references/incident-playbook.md, or vice versa, so the split is clean rather than overlapping.

Trim restated principles (e.g., "mitigate first" appears in the Mitigation section, Decision-making, Workflow, and Failure patterns) to a single canonical statement with back-references.

DimensionReasoningScore

Conciseness

The body is mostly lean and assumes Claude's competence (terse tables, bullet lists, no "what is an incident" preamble), but the "If required data is unavailable" paragraph is somewhat philosophical/wordy and a few principles are restated, placing it just below the fully-trimmed anchor 5.

4 / 5

Actionability

Despite being an instruction-only skill with no code, the guidance is highly concrete and copy-paste ready: a severity rubric table, named mitigation patterns, explicit communication cadences ("every 15 minutes"), verbatim status-page message templates, decision rubrics, and a filled output-format template — meeting the anchor 5 bar for specific guidance covering common cases.

5 / 5

Workflow Clarity

The 5-phase framework and 10-step workflow are clearly sequenced with an explicit validation checkpoint ("Verify mitigation. Don't trust dashboards alone; test the user flow"), feedback loops ("Re-evaluate as more info emerges", severity de-escalation), and a resolution-criteria checklist, matching anchor 5 even though mitigations like rollback are risky — validation is present rather than missing.

5 / 5

Progressive Disclosure

Structure is good with a real, one-level-deep, clearly-signaled reference (references/incident-playbook.md exists and is described), but the severity rubric, roles table, and status-page templates are duplicated between the body and the playbook — content that should be split is inlined, the minor organization gap that holds it at anchor 4 rather than 5.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a strong, complete trigger specification: it states concrete capabilities, gives a rich set of natural trigger terms, and explicitly covers both what and when. It is distinguishable from adjacent skills and free of vague fluff.

DimensionReasoningScore

Specificity

The description names the domain and enumerates multiple concrete actions across the incident lifecycle: "detection, triage, mitigation, communication, and resolution" plus "structured roles and decision-making", giving comprehensive coverage rather than the 1-2 actions at anchor 3 or the minor-gaps coverage at anchor 4.

5 / 5

Completeness

It explicitly answers both "what" (manage incidents through the five phases with roles and decision-making) and "when" ("Use this skill whenever..." plus an explicit "Triggers on..." list plus a fallback clause), matching the anchor 5 example that pairs a concrete capability statement with explicit trigger phrases.

5 / 5

Trigger Term Quality

It lists extensive natural terms and synonyms users would actually say — "outage, service down, site down, P0, P1, severity, downtime, on-call, incident commander, status page" — matching the comprehensive synonym/abbreviation coverage of the anchor 5 example.

5 / 5

Distinctiveness Conflict Risk

The niche is clearly active production incidents with distinct, specialized triggers (incident commander, status page, P0/P1, on-call) that few other skills would match; the broad fallback clause is a minor concern but does not raise overlap risk above the anchor 5 bar.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
rampstackco/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.