一键导入
canon-incident
Use when you need a governed incident packet for an existing system with explicit blast-radius, containment, and follow-up readiness.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Use when you need a governed incident packet for an existing system with explicit blast-radius, containment, and follow-up readiness.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Use when you need a governed Canon review of a real diff or pull-request range instead of a loose chat summary.
Use when a repository does not have Canon runtime state yet and you need to initialize .canon before any governed workflow.
Use when you need a governed Canon policy-shaping run to shape a new or modified policy with mandatory impact evaluation.
Use when you need a governed backlog run that decomposes bounded upstream decisions into delivery epics and slices.
Use when you need a governed Canon architecture run to record decisions, tradeoffs, and risk-gated approvals.
Use when you need a governed change run in a live codebase where invariants and existing behavior matter.
| name | canon-incident |
| description | Use when you need a governed incident packet for an existing system with explicit blast-radius, containment, and follow-up readiness. |
available-nowdefault visibility: discoverable-standardExpose the delivered Canon incident workflow as a governed run started from your AI assistant.
$canon-requirements first.$canon-change.RISKZONEOptional:
OWNER when the user wants to override Git-derived ownership explicitlycanon is on PATH. If missing, point to the install guide..canon/ exists. If missing, point to $canon-init.--system-context existing for this skill.canon-input/ as read-only source material.canon-input/incident.md or canon-input/incident/ as the canonical authored-input locations for this mode.canon-input/incident/, treat brief.md as the authoritative incident brief and any sibling notes as carried-forward context; the current brief still needs to restate the bounded operational surface directly.--input-text instead of materializing a repo file automatically.--input from the active editor file, open tabs, recent .canon/ artifacts, or published packets.$canon-requirements or $canon-change instead of inventing incident detail.low-impact, bounded-impact, or systemic-impact.green, yellow, or red.Canon does not invent the incident body for you. Canon governs, validates, and
persists the packet. You (the assistant) MUST author the real incident content
from the bounded source material BEFORE calling canon run --mode incident.
Do this every time, even when the user only handed you a short outage note:
canon-input/incident/brief.md (or use --input-text for a one-shot inline brief). The file MUST include all of the following H2 sections, populated with concrete content tied to the source you just read:
## Incident Scope## Trigger And Current State## Operational Constraints## Known Facts## Working Hypotheses## Evidence Gaps## Impacted Surfaces## Propagation Paths## Confidence And Unknowns## Immediate Actions## Ordered Sequence## Stop Conditions## Decision Points## Approved Actions## Deferred Actions## Verification Checks## Release Readiness## Follow-Up Work## Missing Authored Body marker when required sections are absent, and gate the result through risk, containment, architecture, and readiness checks.If you cannot author a credible incident body because the impacted surface is still too vague, say so directly and redirect to $canon-requirements or $canon-change instead of submitting an empty brief.
Author the packet as an incident commander structuring bounded containment guidance for operators and approvers.
canon run --mode incident --system-context existing --risk <RISK> --zone <ZONE> [--owner <OWNER>] (--input <INPUT_PATH> | --input-text <INPUT_TEXT>)gate:risk approval first; once approved, the packet can complete without a separate execution-resume path.continue, resume, or same run, or supplies a RUN_ID.$canon-status for the compact summary and canon inspect refinement --run <RUN_ID> when the user needs the advisory continuation state Canon persisted for the run..canon/runs/<RUN_ID>/artifacts/incident/working-brief.md exists for this mode unless Canon emits that surface in a future slice.recommendation-only).canon/artifacts/<RUN_ID>/incident/ paths when Canon emitted themAction Chips: when the host supports chips, preserve the full objects Canon already returned in mode_result.action_chips; do not collapse them to label-only bullets. In text-only hosts, render each chip's text_fallback instead. Must be the last element of the response; do not place any text after this section.canon is missing, show the supported install path from README..canon/ is missing, point to $canon-init.$canon-requirements instead of guessing blast radius or containment detail.$canon-change instead of pretending the incident packet is the implementation plan.AwaitingApproval, surface the exact approval target Canon produced and keep the packet recommendation-only.incident-frame.md, blast-radius-map.md, containment-plan.md, and follow-up-verification.md.$canon-inspect-artifacts first.$canon-inspect-evidence when the user needs lineage, approvals, or policy rationale.$canon-approve when a systemic or red-zone incident packet is ready for explicit risk approval.$canon-change when the next real step is bounded live-codebase change planning.$canon-review when the user wants a governed challenge of the incident packet itself.$canon-status$canon-inspect-artifacts$canon-inspect-evidence$canon-approve$canon-change$canon-requirementscanon-input/incident.mdcanon-input/incident/