Install
$ agentstack add skill-wyre-ai-msp-claude-plugins-incidents ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Better Stack Incidents
Overview
Incidents in Better Stack are triggered automatically when uptime monitors detect downtime, or created manually for ad-hoc issues. Each incident tracks the timeline from detection through acknowledgment to resolution, with associated monitors, status page updates, and on-call notifications.
Anti-triggers
- A security incident — Better Stack incidents are uptime events
with no threat model, no indicators, and no remediation flow; use huntress-incidents.
- The MSP's major-incident process — if the question is about
incident commanders, customer comms, or postmortems rather than a failing check, use rootly-incidents or pagerduty-incidents.
- Billable follow-up work — an incident is not a PSA ticket; use
autotask, halopsa, or connectwise-psa.
- Telling end users about the outage — use
betterstack-status-pages.
Key Concepts
Incident Lifecycle
- Triggered - Monitor detects downtime and creates an incident
- Acknowledged - On-call responder acknowledges the incident
- Resolved - The issue is fixed and the incident is closed
- Auto-resolved - Monitor detects recovery and automatically resolves
Incident Attributes
- Started at - When the incident was first detected
- Acknowledged at - When a responder acknowledged
- Resolved at - When the incident was resolved
- Cause - The monitor or manual source that triggered it
- Call - Whether a phone call alert was triggered
- SMS - Whether an SMS alert was sent
- Email - Whether an email alert was sent
Incident Severity
Better Stack does not enforce severity levels on incidents directly -- severity is determined by the monitor's configuration and escalation policy. However, incidents from monitors with shorter check intervals and immediate escalation are implicitly higher priority.
API Patterns
List Incidents
betterstack_list_incidents
Parameters:
page- Pagination cursorper_page- Results per pagefrom- Start date filter (ISO 8601)to- End date filter (ISO 8601)
Example response:
{
"data": [
{
"id": "67890",
"type": "incident",
"attributes": {
"name": "Example Website is down",
"cause": "HTTP 503 Service Unavailable",
"started_at": "2026-03-27T08:15:00Z",
"acknowledged_at": null,
"resolved_at": null,
"call": true,
"sms": true,
"email": true
},
"relationships": {
"monitor": {
"data": { "id": "12345", "type": "monitor" }
}
}
}
]
}
Get Incident Details
betterstack_get_incident
Parameters:
incident_id- The incident ID
Acknowledge Incident
betterstack_acknowledge_incident
Parameters:
incident_id- The incident ID
Resolve Incident
betterstack_resolve_incident
Parameters:
incident_id- The incident ID
Common Workflows
Daily Incident Triage
- Call
betterstack_list_incidentswith date filters for the current period - Identify unacknowledged incidents (acknowledged_at is null)
- Group incidents by monitor to identify patterns
- Acknowledge incidents that are being investigated
- Resolve incidents that have auto-recovered
Incident Investigation
- Get incident details with
betterstack_get_incident - Identify the associated monitor and check its current status
- Review the incident timeline (started, acknowledged, resolved)
- Check if the monitor has recovered or is still down
- Cross-reference with logs using
betterstack_query_logs - Acknowledge the incident if actively investigating
- Resolve once the root cause is addressed
Post-Incident Review
- List incidents for the review period
- Calculate mean time to acknowledge (MTTA) and mean time to resolve (MTTR)
- Identify monitors with recurring incidents
- Review escalation policy effectiveness
- Update monitors and alerts based on findings
Error Handling
Incident Not Found
Cause: Invalid incident ID or incident was deleted Solution: List incidents to verify the correct ID
Incident Already Resolved
Cause: Attempting to acknowledge or resolve an already-resolved incident Solution: Check incident status before taking action
Incident Already Acknowledged
Cause: Attempting to acknowledge an already-acknowledged incident Solution: Proceed to resolve if the issue is fixed
Best Practices
- Acknowledge incidents promptly to stop escalation chains
- Use date filters to scope incident lists to relevant periods
- Track MTTA and MTTR metrics per client for SLA compliance
- Cross-reference incidents with log data for root cause analysis
- Set up auto-resolve so monitors close incidents when services recover
- Review recurring incidents to identify systemic issues
- Create PSA tickets for incidents requiring follow-up work
Related Skills
- [api-patterns](../api-patterns/SKILL.md) - Pagination and error handling
- [monitors](../monitors/SKILL.md) - Monitors that trigger incidents
- [status-pages](../status-pages/SKILL.md) - Status page incident updates
- [oncall](../oncall/SKILL.md) - On-call notifications for incidents
- [logging](../logging/SKILL.md) - Log investigation during incidents
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: WYRE-AI
- Source: WYRE-AI/msp-claude-plugins
- License: Apache-2.0
- Homepage: https://mcp.wyre.ai/getting-started/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.