← Back to Skills Marketplace
1kalin

Incident Response Playbook

by 1kalin · GitHub ↗ · v1.0.0
cross-platform ✓ Security Clean
795
Downloads
0
Stars
3
Active Installs
1
Versions
Install in OpenClaw
/install afrexai-incident-response
Description
Guides business and IT teams through incident detection, severity classification, containment, resolution, communication, and post-mortem with automated time...
README (SKILL.md)

Incident Response Playbook

Structured incident response for business and IT teams. Guides you through detection, triage, containment, resolution, and post-mortem — with auto-generated timelines and action items.

What It Does

When triggered with an incident description, this skill:

  1. Classifies severity (P1-P4) based on impact and urgency
  2. Generates a response checklist tailored to incident type (outage, data breach, security event, service degradation, vendor failure)
  3. Builds a communication plan — who to notify, when, what channels
  4. Creates a real-time timeline as you log updates
  5. Produces a post-mortem template with root cause analysis and prevention steps

Usage

Tell your agent about an incident:

"Production API is returning 500 errors for 20% of requests. Started 10 minutes ago."

Or trigger proactively:

"Create an incident response plan for a potential data breach scenario"

Incident Types Covered

  • Service outages — full or partial downtime
  • Security incidents — breaches, unauthorized access, phishing
  • Data incidents — corruption, loss, privacy violations
  • Vendor failures — third-party SLA breaches
  • Performance degradation — latency spikes, capacity issues

Severity Matrix

Level Impact Response Time Escalation
P1 - Critical Business stopped Immediate Executive + all hands
P2 - High Major feature down \x3C 30 min Engineering lead + PM
P3 - Medium Degraded experience \x3C 2 hours On-call team
P4 - Low Minor issue Next business day Ticket queue

Response Framework

1. Detection & Triage (First 5 minutes)

  • Confirm the incident is real (not a false alarm)
  • Classify severity using the matrix above
  • Assign incident commander
  • Open a dedicated communication channel

2. Containment (First 30 minutes)

  • Identify blast radius — what's affected?
  • Apply immediate mitigation (rollback, feature flag, scaling)
  • Communicate status to stakeholders

3. Resolution

  • Root cause investigation
  • Implement fix with verification
  • Monitor for recurrence
  • Update all stakeholders

4. Post-Mortem (Within 48 hours)

  • Timeline of events
  • Root cause analysis (5 Whys)
  • What went well / what didn't
  • Action items with owners and deadlines
  • Process improvements

Integration

Works with any monitoring stack. Feed alerts from PagerDuty, Datadog, Grafana, or manual reports.

Pro Tip

Pair this with a full AI Operations Context Pack for your industry. Pre-built incident taxonomies, compliance-aware escalation paths, and automated stakeholder templates.

Browse packs: https://afrexai-cto.github.io/context-packs/

Free tools:

Usage Guidance
This skill is an instruction-only incident response playbook and appears internally consistent. Before installing or using it, avoid pasting sensitive PII or credentials into prompts, verify any recommended actions against your organization's runbooks and change control policies, and be cautious if you later connect the agent to real monitoring/notification systems (PagerDuty, Datadog, etc.) — those integrations will require separate credentials and should be granted using least privilege. If you want higher assurance, review the external links (afrexai-cto.github.io) and confirm the publisher's trustworthiness.
Capability Analysis
Type: OpenClaw Skill Name: afrexai-incident-response Version: 1.0.0 The skill bundle is designed to guide an AI agent through incident response, generating plans and templates. The `SKILL.md` and `README.md` files contain descriptive instructions for the agent's reasoning process and informational links to external resources (e.g., `afrexai-cto.github.io`). There is no evidence of prompt injection attempts, malicious execution commands, data exfiltration, persistence mechanisms, or obfuscation. The external links are presented as resources for the user, not as instructions for the agent to interact with in a harmful way.
Capability Assessment
Purpose & Capability
The skill's name and the SKILL.md content align: it describes classification, checklists, communication plans, timelines, and post-mortems. No unrelated credentials, binaries, or installs are required.
Instruction Scope
Runtime instructions are limited to generating playbooks, timelines, and communication plans based on user-provided incident descriptions. The SKILL.md does not tell the agent to read system files, access environment variables, or contact hidden endpoints.
Install Mechanism
There is no install spec and no code files—this is instruction-only, so nothing is written to disk or downloaded during install.
Credentials
The skill requires no environment variables, credentials, or config paths. Suggested integrations (PagerDuty, Datadog, Grafana) are referenced generically and are not required by the skill itself.
Persistence & Privilege
The skill does not request always:true and does not modify other skills or system-wide settings. It uses the platform's normal autonomous-invocation model by default.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install afrexai-incident-response
  3. After installation, invoke the skill by name or use /afrexai-incident-response
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.0
Initial release: Launches a comprehensive, structured playbook for business and IT incident response. - Automatic severity classification and tailored response checklists for common incident types - Step-by-step guidance for detection, triage, containment, resolution, and post-mortem - Auto-generates communication plans, real-time incident timelines, and post-mortem templates - Compatible with standard monitoring tools (e.g., PagerDuty, Datadog, Grafana) and manual alerts - Supports incidents like outages, security breaches, data loss, vendor failures, and performance issues
Metadata
Slug afrexai-incident-response
Version 1.0.0
License
All-time Installs 3
Active Installs 3
Total Versions 1
Frequently Asked Questions

What is Incident Response Playbook?

Guides business and IT teams through incident detection, severity classification, containment, resolution, communication, and post-mortem with automated time... It is an AI Agent Skill for Claude Code / OpenClaw, with 795 downloads so far.

How do I install Incident Response Playbook?

Run "/install afrexai-incident-response" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is Incident Response Playbook free?

Yes, Incident Response Playbook is completely free (open-source). You can download, install and use it at no cost.

Which platforms does Incident Response Playbook support?

Incident Response Playbook is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created Incident Response Playbook?

It is built and maintained by 1kalin (@1kalin); the current version is v1.0.0.

💬 Comments