Incident 文档排查
- 作者仓库星标 1
- 作者仓库 claude-skills
Incident Postmortem Writer
Overview
Write postmortems that improve systems, not narratives that assign blame.
Core Workflow
- Build a factual timeline from logs, alerts, tickets, and communications.
- Quantify impact, affected users, duration, and detection quality.
- Identify the triggering cause, contributing factors, and why safeguards did not stop the incident.
- Convert remediation into clear action items with owners, priority, and prevention intent when possible.
- Write the final document in a blameless tone with facts separated from inference.
Deliver
- Include a short executive summary before the detailed timeline.
- Make the distinction between root cause and contributing conditions explicit.
- End with concrete preventive actions instead of vague lessons learned.
Guardrails
- Do not hide uncertainty; mark missing evidence clearly.
- Avoid naming individuals as the cause.
- Keep the document useful for both technical and operational follow-up.
- 流狐分类
- 安全
- 作者声明 Agent
- 未找到明确声明;不据此推断已兼容或已测试
- 静态检查
- 88 / 100 · 启发式扫描,不代表运行安全
- 作者 / 版本 / 许可
- @00PrabalK00 · 未声明 license
- 流狐 Token 估算
- 低消耗
- 流狐接入估算
- 需简单配置
- 是否需要外部 API Key
- 未发现要求
- 检测到的系统要求
- 未声明
- 底层运行要求
- 未声明
- 检测到的文件与系统行为
-
- 只读
- 允许写入 / 修改
- Shell 执行
- 检测到的网络行为
- 仅限本地
- 安装命令数
- 无(仅作为资料)
档案由构建时根据 SKILL.md 与安装命令自动衍生,可能与作者实际意图存在差异。
需要注意: 未限定 allowed-tools,默认拥有全部工具权限。
作者没有在当前 SKILL.md 中定义固定输出样例。 Write postmortems that improve systems, not narratives that assign blame.
Build a factual timeline from logs, alerts, tickets, and communications. Quantify impact, affected users, duration, and detection quality. Identify the triggering cause, contributing factors, and why safeguards did not stop the incident.
Include a short executive summary before the detailed timeline. Make the distinction between root cause and contributing conditions explicit. End with concrete preventive actions instead of vague lessons learned.
Do not hide uncertainty; mark missing evidence clearly. Avoid naming individuals as the cause. Keep the document useful for both technical and operational follow-up.
# Incident Postmortem Writer
## Overview
Write postmortems that improve systems, not narratives that assign blame.
## Core Workflow
1. Build a factual timeline from logs, alerts, tickets, and communications.
2. Quantify impact, affected users, duration, and detection quality.
3. Identify the triggering cause, contributing factors, and why safeguards did not stop the incident.
4. Convert remediation into clear action items with owners, priority, and prevention intent when possible.
5. Write the final document in a blameless tone with facts separated from inference.
## Deliver
- Include a short executive summary before the detailed timeline.
- Make the distinction between root cause and contributing conditions explicit.
- End with concrete preventive actions instead of vague lessons learned.
## Guardrails
- Do not hide uncertainty; mark missing evidence clearly.
- Avoid naming individuals as the cause.
- Keep the document useful for both technical and operational follow-up. 作者原文负责流程事实;流狐只索引当前章节、要点、文件与命令。
章节 -> Overview → Core Workflow → Deliver → Guardrails
要点 -> Write postmortems that improve systems, not narratives that assign blame. · 1. Build a factual timeline from logs, alerts, tickets, and communications. · - Include a short executive summary before the detailed timeline. · - Do not hide uncertainty; mark missing evidence clearly.
文件/命令 -> 原文未列出明确文件或命令
内容 SHA-256 -> 9808da817cb8
方法与流程
适用与边界
原文中的明确线索