Install
$ agentstack add skill-aws-samples-sample-skills-for-aws-devops-agent-china-incident-triage ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
China Incident Triage
Routing is governed by china-region-multi-account-routing. This skill assumes an incident signal has just arrived and needs initial classification in 5%, MCP endpoint down | | SEV-3 | Degraded latency, single-AZ impact, partial feature failure | | SEV-4 | Monitoring-only, internal tool affected, no customer impact | | SEV-5 | Informational, metric threshold crossed without user-visible effect |
Default to SEV-3 when the signal is ambiguous — escalate via RCA findings later if needed.
Step 4 — Dedup check
Before handing off, query:
aws cloudwatch describe-alarms --alarm-name-prefix
aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue= \
--max-items 20 --start-time
If a very similar alarm fired within the last 24 hours and is still active or recently resolved, mark Duplicate? Yes with the original incident ID. This prevents RCA duplication.
Step 5 — Hand off
Emit the Triage Card. Based on severity:
- SEV-1 / SEV-2 → "Escalating to RCA; will auto-invoke china-incident-rca."
- SEV-3 → "Triage complete. Run RCA when ready."
- SEV-4 / SEV-5 → "Low impact; log and monitor. Skip RCA unless trend develops."
Things not to do
- Do not start RCA investigation during triage. Triage is
Duplicate? Next step: Hand off to china-incident-rca
**Input**: "aws-cn-2 Lambda throwing AuthFailure since 14:00"
**Action**:
Account: aws-cn-2 (cn-north-1) Class: Identity/Credentials Severity: SEV-2 (likely wide-impact — credentials power all calls) Resource: First seen: ~14:00 today Duplicate? Check recent AuthFailure rate Next step: Hand off to china-incident-rca (prioritize: check recent Secrets Manager update, check IAM key age)
**Input**: "中国区好像不太对劲"
**Action**: Signal too vague for triage. Ask: "Which account, aws-cn or
aws-cn-2? And what symptom — slow response, error, or metric anomaly?"
Do not emit a Triage Card on speculation.
## Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- **Author:** [aws-samples](https://github.com/aws-samples)
- **Source:** [aws-samples/sample-skills-for-AWS-Devops-agent](https://github.com/aws-samples/sample-skills-for-AWS-Devops-agent)
- **License:** MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.