incident-management

incident-management is a skill for Claude Code from cbrock84/headcount. It costs 90 tokens per session (940 once invoked), scanned A, original, MIT.

A set of working practices for handling unplanned service disruptions from detection through review. It covers assigning an incident commander, coordinating recovery and communication, recording events, and tracking follow-up actions.

In plain words
What is it for?
Use it to declare incidents, coordinate responders, maintain a timeline, decide when service is restored, and turn the review into completed improvements.
Why use it?
It gives teams a shared structure for making decisions and communicating when normal work is interrupted and time is limited.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the operations plugin — 12 skills shipped together

Good fit Use it to declare incidents, coordinate responders, maintain a timeline, decide when service is restored, and turn the review into completed improvements.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/cbrock84/headcount/incident-management
About the project

headcount is an organization of independently installable Claude Code plugins, each grouping skills for a department such as finance, security, or demand generation. Claude Code users install the departments they need and invoke their skills for specialized work; the catalogue entries are skills and related agent tooling from that organization.

cbrock84/headcount · 1,300 stars · on GitHub · cbrock84.github.io

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add cbrock84/headcount --skill incident-management
Clone the repo
git clone --depth 1 https://github.com/cbrock84/headcount

Made for: Claude Code.

Or install operations, the plugin that ships this one along with the rest of its 12 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for incident-management

README.md
[![agentmods](https://agentmods.dev/badge/skills/cbrock84/headcount/incident-management.svg)](https://agentmods.dev/skills/cbrock84/headcount/incident-management)
Your own site
<a href="https://agentmods.dev/skills/cbrock84/headcount/incident-management"><img src="https://agentmods.dev/badge/skills/cbrock84/headcount/incident-management.svg" alt="Measured on agentmods" height="20"></a>
Per session 90 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 940 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00090 $0.00940
Opus 5 $0.00045 $0.00470
Sonnet 5 $0.00018 $0.00188
Haiku 4.5 $0.00009 $0.00094

Measured 4d ago against content hash f8ff2762415d, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

incident-management scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/operations/skills/incident-management/SKILL.md · 88 lines

How it starts

The opening of the file, as written. The whole thing — 88 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Incident management

An incident is any unplanned disruption significant enough that normal work stops until it is resolved. The discipline exists because the instincts that serve people well in ordinary work — investigate thoroughly, decide carefully, keep everyone informed — all fail under time pressure unless someone has structured them in advance.

This covers operational incidents generally. For security incidents, where evidence preservation and disclosure obligations change the order of operations, see security:incident-response.

Declare it, and say so out loud

The most expensive minutes are the ones spent deciding whether this is an incident. Set a low threshold for declaring and accept that some declarations will be withdrawn — an incident stood down after twenty minutes costs far less than one that ran for two hours as a conversation between three people who each assumed someone else had it.

Severity should be defined in advance, in terms of customer impact rather than internal inconvenience, with each level carrying a stated response: who is notified, how fast, and who can be woken.

Name a commander who does not fix anything

One person owns the incident: they decide, they sequence, they assign. They should not be the person with their hands in the system — the moment the commander starts debugging, nobody is running the incident and the timeline stops being kept.

Separate three roles even in a small response: the commander, the people restoring service, and one person handling communication. Combining the first and third is survivable; combining the first and second is how incidents run long without anyone noticing they have.

Restore first, understand later

The goal during the incident is service restored, not cause understood. Roll back, fail over, disable the feature, add capacity — whatever returns the customer to working. Diagnosis is tomorrow's work, and pursuing it while people are affected is the most common way a thirty-minute outage becomes a four-hour one.

Read the full file on GitHub · 88 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 88 lines · 90 tokens per session scan A f8ff2762415d

Subscribe to this mod's changes

incident-management is a skill published in the GitHub repository cbrock84/headcount (1,300 stars, last pushed 4d ago), licensed MIT. It adds 90 tokens to every session and 940 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

user-story-map

Build an interactive, drag-and-drop user story map so the user can re-slice work across release phases. Use when the user wants a story map, a phased roadmap, release slicing, a backbone/activities journey map, or to decide "which stories go in which phase" and move them around.

Cavalry-Collective/visual-stack · 65 tokens

agile-ledger

Plain-Markdown Scrum / Agile product-management system for Claude Code. Manage a product backlog of Epics and User Stories, plan and run sprints, drive a board, track velocity, cut Major.Minor releases, and keep GitHub branches/commits/PRs traceable to stories — all from slash commands, with no Jira and no database.…

nunoamorim99/agile-ledger · 193 tokens

agile-ledger-workspace

Optional multi-repo orchestrator for Agile-Ledger. Install once at a workspace root to manage many repositories at once: discover new repositories on a GitHub org (including ones nobody told you about), clone and bootstrap them, run a single cross-repo "what changed while I was away" sync, and reconstruct undocumented…

nunoamorim99/agile-ledger · 179 tokens

people-integration

Design the first 90 days for acquired product talent so they stay, contribute, and feel ownership. Produces decision map session template, mentor pairing matrix, 30/60/90 ownership plan, retention risk review (purpose and influence), and 1:1 coaching question library.

enalbenerraw/blanewarrene · 61 tokens

roadmap-convergence

Facilitate the post-acquisition roadmap convergence process across Weeks 1 to 8. Produces the conflict log, three-session facilitation guides, merged 90-day plus 12-month roadmap, and the 30/60/90 execution plan.

enalbenerraw/blanewarrene · 56 tokens

week-0-readiness

Run a product leader through pre-close (Week 0) integration readiness for an acquisition. Produces the integration lead charter, decision rights one-pager, combined product narrative draft, customer commitment inventory, and the five-question Day 1 readiness check.

enalbenerraw/blanewarrene · 56 tokens