AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Better Stack Incidents

skill-wyre-ai-msp-claude-plugins-incidents · by WYRE-AI

>

— No reviews yet
0 installs
19 views
0.0% view→install

Install

$ agentstack add skill-wyre-ai-msp-claude-plugins-incidents

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-wyre-ai-msp-claude-plugins-incidents)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● 1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Better Stack Incidents? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Better Stack Incidents

Overview

Incidents in Better Stack are triggered automatically when uptime monitors detect downtime, or created manually for ad-hoc issues. Each incident tracks the timeline from detection through acknowledgment to resolution, with associated monitors, status page updates, and on-call notifications.

Anti-triggers

  • A security incident — Better Stack incidents are uptime events

with no threat model, no indicators, and no remediation flow; use huntress-incidents.

  • The MSP's major-incident process — if the question is about

incident commanders, customer comms, or postmortems rather than a failing check, use rootly-incidents or pagerduty-incidents.

  • Billable follow-up work — an incident is not a PSA ticket; use

autotask, halopsa, or connectwise-psa.

  • Telling end users about the outage — use

betterstack-status-pages.

Key Concepts

Incident Lifecycle

  1. Triggered - Monitor detects downtime and creates an incident
  2. Acknowledged - On-call responder acknowledges the incident
  3. Resolved - The issue is fixed and the incident is closed
  4. Auto-resolved - Monitor detects recovery and automatically resolves

Incident Attributes

  • Started at - When the incident was first detected
  • Acknowledged at - When a responder acknowledged
  • Resolved at - When the incident was resolved
  • Cause - The monitor or manual source that triggered it
  • Call - Whether a phone call alert was triggered
  • SMS - Whether an SMS alert was sent
  • Email - Whether an email alert was sent

Incident Severity

Better Stack does not enforce severity levels on incidents directly -- severity is determined by the monitor's configuration and escalation policy. However, incidents from monitors with shorter check intervals and immediate escalation are implicitly higher priority.

API Patterns

List Incidents

betterstack_list_incidents

Parameters:

  • page - Pagination cursor
  • per_page - Results per page
  • from - Start date filter (ISO 8601)
  • to - End date filter (ISO 8601)

Example response:

{
  "data": [
    {
      "id": "67890",
      "type": "incident",
      "attributes": {
        "name": "Example Website is down",
        "cause": "HTTP 503 Service Unavailable",
        "started_at": "2026-03-27T08:15:00Z",
        "acknowledged_at": null,
        "resolved_at": null,
        "call": true,
        "sms": true,
        "email": true
      },
      "relationships": {
        "monitor": {
          "data": { "id": "12345", "type": "monitor" }
        }
      }
    }
  ]
}

Get Incident Details

betterstack_get_incident

Parameters:

  • incident_id - The incident ID

Acknowledge Incident

betterstack_acknowledge_incident

Parameters:

  • incident_id - The incident ID

Resolve Incident

betterstack_resolve_incident

Parameters:

  • incident_id - The incident ID

Common Workflows

Daily Incident Triage

  1. Call betterstack_list_incidents with date filters for the current period
  2. Identify unacknowledged incidents (acknowledged_at is null)
  3. Group incidents by monitor to identify patterns
  4. Acknowledge incidents that are being investigated
  5. Resolve incidents that have auto-recovered

Incident Investigation

  1. Get incident details with betterstack_get_incident
  2. Identify the associated monitor and check its current status
  3. Review the incident timeline (started, acknowledged, resolved)
  4. Check if the monitor has recovered or is still down
  5. Cross-reference with logs using betterstack_query_logs
  6. Acknowledge the incident if actively investigating
  7. Resolve once the root cause is addressed

Post-Incident Review

  1. List incidents for the review period
  2. Calculate mean time to acknowledge (MTTA) and mean time to resolve (MTTR)
  3. Identify monitors with recurring incidents
  4. Review escalation policy effectiveness
  5. Update monitors and alerts based on findings

Error Handling

Incident Not Found

Cause: Invalid incident ID or incident was deleted Solution: List incidents to verify the correct ID

Incident Already Resolved

Cause: Attempting to acknowledge or resolve an already-resolved incident Solution: Check incident status before taking action

Incident Already Acknowledged

Cause: Attempting to acknowledge an already-acknowledged incident Solution: Proceed to resolve if the issue is fixed

Best Practices

  • Acknowledge incidents promptly to stop escalation chains
  • Use date filters to scope incident lists to relevant periods
  • Track MTTA and MTTR metrics per client for SLA compliance
  • Cross-reference incidents with log data for root cause analysis
  • Set up auto-resolve so monitors close incidents when services recover
  • Review recurring incidents to identify systemic issues
  • Create PSA tickets for incidents requiring follow-up work

Related Skills

  • [api-patterns](../api-patterns/SKILL.md) - Pagination and error handling
  • [monitors](../monitors/SKILL.md) - Monitors that trigger incidents
  • [status-pages](../status-pages/SKILL.md) - Status page incident updates
  • [oncall](../oncall/SKILL.md) - On-call notifications for incidents
  • [logging](../logging/SKILL.md) - Log investigation during incidents

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.