AgentStack
SKILL verified MIT Self-run

China Incident Triage

skill-aws-samples-sample-skills-for-aws-devops-agent-china-incident-triage · by aws-samples

First-response triage for an incoming alarm, ticket, or failure

No reviews yet
0 installs
13 views
0.0% view→install

Install

$ agentstack add skill-aws-samples-sample-skills-for-aws-devops-agent-china-incident-triage

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of China Incident Triage? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

China Incident Triage

Routing is governed by china-region-multi-account-routing. This skill assumes an incident signal has just arrived and needs initial classification in 5%, MCP endpoint down | | SEV-3 | Degraded latency, single-AZ impact, partial feature failure | | SEV-4 | Monitoring-only, internal tool affected, no customer impact | | SEV-5 | Informational, metric threshold crossed without user-visible effect |

Default to SEV-3 when the signal is ambiguous — escalate via RCA findings later if needed.

Step 4 — Dedup check

Before handing off, query:

aws cloudwatch describe-alarms --alarm-name-prefix 
aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue= \
  --max-items 20 --start-time 

If a very similar alarm fired within the last 24 hours and is still active or recently resolved, mark Duplicate? Yes with the original incident ID. This prevents RCA duplication.

Step 5 — Hand off

Emit the Triage Card. Based on severity:

  • SEV-1 / SEV-2 → "Escalating to RCA; will auto-invoke china-incident-rca."
  • SEV-3 → "Triage complete. Run RCA when ready."
  • SEV-4 / SEV-5 → "Low impact; log and monitor. Skip RCA unless trend develops."

Things not to do

  • Do not start RCA investigation during triage. Triage is

Duplicate? Next step: Hand off to china-incident-rca


**Input**: "aws-cn-2 Lambda throwing AuthFailure since 14:00"

**Action**:

Account: aws-cn-2 (cn-north-1) Class: Identity/Credentials Severity: SEV-2 (likely wide-impact — credentials power all calls) Resource: First seen: ~14:00 today Duplicate? Check recent AuthFailure rate Next step: Hand off to china-incident-rca (prioritize: check recent Secrets Manager update, check IAM key age)


**Input**: "中国区好像不太对劲"

**Action**: Signal too vague for triage. Ask: "Which account, aws-cn or
aws-cn-2? And what symptom — slow response, error, or metric anomaly?"
Do not emit a Triage Card on speculation.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [aws-samples](https://github.com/aws-samples)
- **Source:** [aws-samples/sample-skills-for-AWS-Devops-agent](https://github.com/aws-samples/sample-skills-for-AWS-Devops-agent)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.