All skills
cursor avatar
by cursorcursor/plugins9.1k stars
857

Use for 'why does X work this way', 'why we picked Y', design rationale, regressions, postmortems, or data-backed thresholds. Discovers available MCPs and queries each evidence category (source control, issue tracker, long-form docs, real-time chat, infrastructure observability, error tracking, product analytics warehouse) in parallel, then returns a cited read on decisions and tradeoffs. Use how for runtime behavior.

Use this Skill: https://skilld.dev/gh/cursor/plugins/why

This session only. Nothing lands on disk.

referencessourcesincident-postmortem.md

≈494 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Incident & Postmortem Context

Not a separate source, a cross-cutting angle. Incidents often motivate defensive code ("we added this check after the X outage"), so if the target looks defensive (null checks, retry logic, timeout handling, rate limiting, feature flags), specifically hunt for incident history across every available source:

  • Notion: search for postmortems mentioning the target file, feature, or error string
  • Linear: look for tickets labeled incident, sev-*, postmortem-action-item, reliability
  • Slack: search #sev-* and #incident-* channels around the dates the target code was added
  • Git: commits with messages like "fix for incident", "add defensive check", "revert" followed by "re-apply with..." are strong signals
  • Datadog: search_datadog_incidents for formal incident records with timelines, dashboards and monitors created as postmortem action items
  • Sentry: issues whose first-seen/last-seen window aligns with the target's PR ship date, stack traces through the target
  • Databricks: product-analytics events that classify an error condition (client-reported failures, user-visible retry events, etc.) often spike during an incident window. A drop in that event count after the target PR ships is circumstantial support that the target code resolved the user-visible symptom, even when Datadog/Sentry signal is noisy.

If you find an incident link, fetch the full postmortem. Postmortems typically have an "Action Items" section that ties directly to code changes. When multiple sources corroborate (a Datadog incident ID appears in a Linear ticket, which appears in a Notion postmortem, which appears in a Slack thread that links to the target PR, and the Databricks error-event count drops after the fix), the evidence is especially strong.

Worth spending time on when the code's defensive character makes an incident-driven origin plausible. Skip it for code that doesn't look defensive.

Source: SKILL.md on GitHub

1 warning7d3 checks · Risk SAFE
  • Gen Agent Trust Hub7d

    The skill is a professional investigative tool designed to analyze the rationale behind code by aggregating data from various engineering tools. It is categorized as low risk due to the potential for indirect prompt injection from the diverse data sources it processes.

  • Socket7d

    No alerts

  • Snyk7d

    Risk: MEDIUM · 1 issue

Signed by skilld at 12d587d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
disable-model-invocation
true

README badge

README badge for cursor/plugins/why