All skills
simota avatar

/triage

@c805268
by shingo imotasimota/agent-skills85 stars
15

Responding to incidents: identifies impact scope, formulates recovery procedures, creates postmortems. Use when incident response or disaster recovery is needed. Delegates fixes to Builder.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/triage

This session only. Nothing lands on disk.

referencecollaboration-flows.md

≈2.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Triage Collaboration Flows Reference

Detailed collaboration patterns and flow diagrams for incident response.

Purpose: Read this when Triage must choose or explain the exact handoff flow for standard, critical, security, rollback, postmortem, or multi-service incidents.

Contents:

  • Pattern A: Standard Incident Flow (SEV3/SEV4): Scout → Builder → Radar baseline path
  • Pattern B: Critical Incident Flow (SEV1/SEV2): urgent path with Lens evidence capture
  • Pattern C: Security Incident: Sentinel-led incident routing
  • Pattern D: Postmortem Flow: evidence collection and postmortem closure
  • Pattern E: Rollback Coordination: Gear rollback and Radar stability verification
  • Pattern F: Multi-Service Incident: parallel per-service investigation routing

Pattern A: Standard Incident Flow (SEV3/SEV4)

Incident Detected
       ↓
┌─────────────────────────────────────────────┐
│ Triage: Classify & Assess                   │
│ - Severity: SEV3/SEV4                       │
│ - Impact scope identified                   │
│ - Initial mitigation (if quick fix)         │
└──────────────────┬──────────────────────────┘
                   ↓
         TRIAGE_TO_SCOUT_HANDOFF
                   ↓
┌─────────────────────────────────────────────┐
│ Scout: Root Cause Analysis                  │
│ - Investigate symptoms                      │
│ - Identify root cause                       │
│ - Recommend fix location                    │
└──────────────────┬──────────────────────────┘
                   ↓
         SCOUT_TO_BUILDER_HANDOFF
                   ↓
┌─────────────────────────────────────────────┐
│ Builder: Implement Fix                      │
│ - Apply fix                                 │
│ - Deploy to production                      │
└──────────────────┬──────────────────────────┘
                   ↓
         BUILDER_TO_RADAR_HANDOFF
                   ↓
┌─────────────────────────────────────────────┐
│ Radar: Verify Fix                           │
│ - Run regression tests                      │
│ - Confirm no new issues                     │
└──────────────────┬──────────────────────────┘
                   ↓
         RADAR_TO_TRIAGE_HANDOFF
                   ↓
  Triage: Close Incident + Postmortem

Pattern B: Critical Incident Flow (SEV1/SEV2)

SEV1/SEV2 Detected
       ↓
┌─────────────────────────────────────────────┐
│ Triage: Immediate Response                  │
│ - Severity confirmed: SEV1/SEV2             │
│ - Stakeholders notified                     │
│ - Status page updated                       │
└──────────────────┬──────────────────────────┘
                   ↓
    ┌──────────────┴──────────────┐
    ↓                             ↓
TRIAGE_TO_SCOUT         TRIAGE_TO_LENS
(Root cause)            (Evidence capture)
    ↓                             ↓
Scout investigates      Lens captures state
    ↓                             ↓
    └──────────────┬──────────────┘
                   ↓
         SCOUT_TO_BUILDER_HANDOFF (urgent)
                   ↓
  Builder: Hotfix → Deploy → Verify
                   ↓
  Triage: Extended verification (30 min)
                   ↓
  Triage: Close + Mandatory postmortem (24h)

Pattern C: Security Incident

Security Issue Detected
       ↓
┌─────────────────────────────────────────────┐
│ Triage: Security Classification             │
│ - Assess breach scope                       │
│ - Activate security protocol                │
└──────────────────┬──────────────────────────┘
                   ↓
         TRIAGE_TO_SENTINEL_HANDOFF
                   ↓
┌─────────────────────────────────────────────┐
│ Sentinel: Security Analysis                 │
│ - Assess vulnerability                      │
│ - Determine exposure                        │
│ - Recommend remediation                     │
└──────────────────┬──────────────────────────┘
                   ↓
    Scout assists with technical RCA
                   ↓
    Builder implements security fix
                   ↓
    Sentinel verifies fix effectiveness
                   ↓
  Triage: Security postmortem + disclosure plan

Pattern D: Postmortem Flow

Incident Resolved
       ↓
┌─────────────────────────────────────────────┐
│ Triage: Gather Postmortem Data              │
│ - Timeline from all agents                  │
│ - Evidence from Lens                        │
│ - Root cause from Scout                     │
└──────────────────┬──────────────────────────┘
                   ↓
┌─────────────────────────────────────────────┐
│ Triage: Write Postmortem                    │
│ - 5 Whys analysis                           │
│ - Action items with owners                  │
│ - Lessons learned                           │
└──────────────────┬──────────────────────────┘
                   ↓
  Update PROJECT.md and triage.md

Pattern E: Rollback Coordination

Fix Failed or Regression Detected
       ↓
┌─────────────────────────────────────────────┐
│ Triage: Rollback Decision                   │
│ - Trigger: ON_ROLLBACK_DECISION             │
│ - User confirms rollback                    │
└──────────────────┬──────────────────────────┘
                   ↓
         TRIAGE_TO_GEAR_HANDOFF
                   ↓
┌─────────────────────────────────────────────┐
│ Gear: Execute Rollback                      │
│ - Identify rollback target                  │
│ - Execute deployment rollback               │
│ - Verify rollback success                   │
└──────────────────┬──────────────────────────┘
                   ↓
         GEAR_TO_RADAR_HANDOFF
                   ↓
  Radar: Verify system stability
                   ↓
  Triage: Continue investigation

Pattern F: Multi-Service Incident

Multiple Services Affected
       ↓
┌─────────────────────────────────────────────┐
│ Triage: Coordinate Multi-Service Response   │
│ - Identify all affected services            │
│ - Prioritize by impact                      │
│ - Assign investigation per service          │
└──────────────────┬──────────────────────────┘
                   ↓
    ┌──────────────┼──────────────┐
    ↓              ↓              ↓
Scout (Svc A)  Scout (Svc B)  Scout (Svc C)
    ↓              ↓              ↓
    └──────────────┼──────────────┘
                   ↓
  Triage: Aggregate findings
                   ↓
  Builder: Coordinated fixes
                   ↓
  Radar: Cross-service verification

Source: SKILL.md on GitHub

1 warning13d5 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill is a comprehensive incident response framework following industry-standard SRE best practices (NIST, Google SRE, FEMA ICS). It operates as a coordinator that delegates technical actions to other agents with explicit human-in-the-loop approvals, confidence thresholds, and dedicated security runbooks to handle risks like prompt injection and credential exposure.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    1/5 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at c805268. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/triage