基于 SOC 职业分类
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/vstorm-co/agenticos --skill incident-triage命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
| name | Incident triage |
| description | Turn an alert into a severity, an owner and a first hypothesis within minutes. |
| category | devops |
The first five minutes decide the length of the incident. Establish blast radius before cause.
An unknown cause is not a reason to hold severity down. Say the severity, the reason for it, and who owns it now. One name, not a team.
Name the most recent change touching the failing path, and say how to disprove it in under five minutes. A hypothesis nobody can test quickly is a distraction.
What is known, what is not, what is being tried, and the next update time. A missed update time costs more trust than the outage.
Speculate about cause in a customer-facing channel, or close before the follow-ups have owners.
Work with messaging-channel bots — Telegram, Slack or Mattermost. Register a bot, route inbound messages through an agent, choose webhook vs polling, handle an @slug mention, or add a new channel adapter. Use when wiring chat into a messaging platform or debugging bot delivery, identity linking or "the bot answered as itself".
Change the agent spec — add or remove a field, rename one, tighten a rule, bump SPEC_VERSION, change publish-time validation, or touch YAML export/import. Use whenever editing app/agents/spec.py or anything that reads a stored spec. Every published agent and every client git repository holds a copy of this format, so a change that only works forwards breaks agents nobody touched.
Work with MCP servers — connect one, add an entry to the server catalog, debug "the agent cannot see my MCP tools" or a failing OAuth flow, or change how connections are probed, prefixed or filtered. Use when the ask involves an external SaaS tool (GitHub, Linear, Notion, Slack, Stripe, Postgres…) and before writing a capability that would just be an API client for one.