Run a thorough, methodology-aware post-incident root cause analysis on a software outage or production incident. Use this skill whenever the user wants to understand *why* something really broke — after the incident is resolved and they hand over some mix of incident summary, timeline, logs, or a draft postmortem. Also use it when they say things like "do an RCA," "5 whys on this," "extended postmortem," "fishbone this incident," "root cause analysis," "contributing factors," or "what really went wrong." The skill combines narrative 5-whys and fishbone categorization with explicit layer separation (trigger / proximate / contributing / systemic) and corrective actions tagged by type (Prevent / Detect / Mitigate / Respond), and produces a structured engineering-grade writeup. Distinct from active incident triage — use `engineering:incident` / `engineering:incident-response` for that.
2026-04-19