一键导入
validator-incident-response
Use during validator incidents for slashing-risk assessment, forensics, recovery, and external verification.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Use during validator incidents for slashing-risk assessment, forensics, recovery, and external verification.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Use when changing or deploying a public blockchain node-guides service, its source data, UI, contribution content, or cache.
Audit servers to identify blockchain nodes, listening ports, and effective network exposure.
Use when exiting, retiring, or decommissioning a validator with transaction, unbonding, key-retention, and shutdown gates.
Use when migrating validator workloads with freeze, key uniqueness, cutover, rollback, and downstream verification.
Use when onboarding or registering a validator with readiness, key-custody, parameter, transaction, and monitoring gates.
Use when recovering validator or full nodes from snapshots with integrity, state, rollback, and sync verification.
| name | validator-incident-response |
| description | Use during validator incidents for slashing-risk assessment, forensics, recovery, and external verification. |
Use for validator outages, missed blocks, jailing or slashing risk, crash loops, sync stalls, resource exhaustion, database faults, and suspected duplicate signing.
This public skill is environment-neutral. Resolve the authorized target_ref, network_ref, signer role, expected service, monitors, and escalation path through private knowledge and live state. Never embed or guess inventory.
Classify severity by signing risk, data/key risk, duration, missed blocks, validator state, and customer/network impact.
Before recovery, answer:
If duplicate signing or key compromise is plausible, contain signing before ordinary uptime recovery. Do not copy or display key contents.
Prefer read-only checks:
Avoid full environment dumps, secret-bearing configuration, large log dumps, broad filesystem searches, and destructive diagnostics.
Separate confirmed facts, likely cause, alternatives, and unknowns. Prefer the lowest-risk check that can distinguish them.
Common classes include:
Do not repeatedly restart a crash loop without learning from its failure.
Choose the smallest reversible action that restores safe signing:
Preserve logs and rollback evidence. Ask before destructive data replacement, key movement, transaction broadcast, or materially broader changes unless the active request explicitly includes them.
A service marked active is not recovery proof. Require applicable evidence:
Continue a bounded watch after apparent recovery.
Send a concise operator update: impact, slashing/data risk, cause confidence, actions, proof of recovery, and remaining watch items.
For meaningful incidents, record a timeline, root cause, contributing factors, recovery, validation, and follow-up in the private incident/decision knowledge layer. Generalize the reusable lesson into a guide, script, monitor, or skill update without copying private infrastructure into this package.