AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Incident Summary Writer

skill-nicholashidalgo-claude-skillforge-incident-root-cause-writer · by nicholashidalgo

Generates a structured, factual incident summary from raw on-call notes.

No reviews yet
0 installs
28 views
0.0% view→install

Install

$ agentstack add skill-nicholashidalgo-claude-skillforge-incident-root-cause-writer

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-nicholashidalgo-claude-skillforge-incident-root-cause-writer)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
4mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Incident Summary Writer? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

incident-summary-writer

Purpose: Convert messy on-call notes into a clean, timeline-based incident summary with root cause, impact, and action items. No hedging, no vague attribution.

Input Schema

| Field | Type | Required | |---|---|---| | incident_id | string | yes | | timeline_notes | string | yes - raw notes with timestamps | | severity | string | yes - SEV1/SEV2/SEV3 | | affected_systems | string[] | yes | | root_cause | string | yes | | action_items | string[] | yes | | preserve_facts | string[] | yes |

{
  "incident_id": "INC-2024-0314",
  "timeline_notes": "9:41pm pages fired. checked logs. 11:23pm resolved. load balancer config was wrong after the deploy",
  "severity": "SEV2",
  "affected_systems": ["checkout", "payments-api"],
  "root_cause": "Misconfigured load balancer after 11pm deploy",
  "action_items": ["Add LB config validation to deploy checklist", "Lower alert threshold to p95 > 500ms"],
  "preserve_facts": ["INC-2024-0314", "9:41 PM", "11:23 PM", "4,300 timed-out requests"]
}

Output Schema

{
  "title": "INC-2024-0314 - SEV2 - Checkout outage (March 14)",
  "summary": "...",
  "timeline": [{"time": "9:41 PM", "event": "..."}, ...],
  "root_cause": "...",
  "impact": "...",
  "action_items": [{"owner": "TBD", "item": "...", "due": "TBD"}]
}

Prompt Flow

Pass 1: Structure into title, summary, timeline, root cause, impact, action items. Remove: significance inflation (P1), promotional adjectives (P4), weasel words (P5), AI vocab (P7), knowledge-cutoff disclaimers (P20), filler (P22), excessive hedging (P23).

Pass 2: "What sounds like AI-generated filler in this report?" -> final clean rewrite.

Examples

Short

Before: "We experienced some technical difficulties that may have potentially caused issues for certain users." After: "Checkout returned 502s for 4,300 requests between 9:41 PM and 11:23 PM PT on March 14."

Medium (summary)

Before: "The incident marks a pivotal moment in our infrastructure journey, underscoring the vital importance of robust configuration management going forward." After: "Root cause: a load balancer config pushed at 11 PM set the health check timeout to 1ms instead of 500ms. Every backend instance failed health checks and was removed from the pool."

Long (full report)

Unit Tests

# tests/skills/test_incident_summary_writer.py
from ai_pattern_scrubber import detect_patterns

SUMMARY = "Checkout returned 502s for 4,300 requests between 9:41 PM and 11:23 PM PT on March 14."
ROOT_CAUSE = "Root cause: a load balancer config pushed at 11 PM set the health check timeout to 1ms instead of 500ms."

def test_summary_no_hedging():
    assert not [h for h in detect_patterns(SUMMARY) if h.id == 23]

def test_root_cause_no_weasel_words():
    assert not [h for h in detect_patterns(ROOT_CAUSE) if h.id == 5]

def test_summary_no_high_severity():
    assert not [h for h in detect_patterns(SUMMARY) if h.severity == "high"]

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.