Skip to content
Back to skills

Ai Incident Response

ASecurity

Use when preventing, detecting, triaging, communicating, recovering from, or reviewing AI incidents, AI errors, RCA, and postmortems.

  • 28 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added May 28, 2026
developmentgosecurity

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 20, 2026

npx -y skills add peterbamuhigire/skills-web-dev --skill ai-incident-response --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ai Incident Response?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ai Incident Response
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/peterbamuhigire-ai-incident-response/badge)](https://www.skillsdirectory.com/skills/peterbamuhigire-ai-incident-response)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ai-incident-response
description: Use when preventing, detecting, triaging, communicating, recovering from, or reviewing AI incidents, AI errors, RCA, and postmortems.
metadata:
  portable: true
  compatible_with:
  - claude-code
  - codex
---

# AI Incident Response

## Operating contract

## Inputs

| Input | Required | Purpose |
|---|---|---|
| Domain evidence | yes | incident signal, affected model or feature versions, tenant scope, traces, severity criteria, and response contacts |

## Outputs

- Produce: severity verdict, containment actions, evidence timeline, recovery checks, communications, and post-incident actions.

## Capability and permission boundaries

Default to read-only analysis. Read only scoped records; redact secrets and regulated data. Writes, execution, network calls, production configuration, customer communication, billing changes, and delegation require explicit authority and an identified owner. Never widen tenant, time-window, or system scope implicitly.

## Degraded mode

When required telemetry, evidence, execution, network access, or write authority is unavailable, return a partial result with each unassessed item labelled, preserve the safest existing state, and state the evidence or approval needed to continue. Never convert missing evidence into a pass.

## Decision rules

| Condition | Action |
|---|---|
| Scope, owner, or threshold is missing | Stop the affected decision and request it |
| Evidence is incomplete but read-only analysis is safe | Produce a qualified partial result and gap list |
| A mutation exceeds authority or tenant boundary | Block it and route for approval |
| Evidence meets the stated threshold | Issue the output with provenance and owner |

## Anti-Patterns

- Treating absent evidence as success. Fix: mark the check unassessed and name the missing source.
- Expanding one tenant or workflow to all tenants. Fix: enforce supplied scope at every query and action.
- Performing a production write during analysis. Fix: emit a reviewed change plan until authority is explicit.
- Reporting a metric without population, window, or source. Fix: attach all three.
- Hiding a failed threshold inside an average. Fix: report failure slices and the remediation owner.

Acknowledgement: Shared by Peter Bamuhigire, techguypeter.com, +256 784 464178.

<!-- dual-compat-start -->

## Use When

- Design AI incident detection, triage, recovery, customer communications, drills, RCA, and postmortems.
- Handle AI error prevention, error handling, evidence capture, and incident runbooks.
- Turn production AI failures into remediations, controls, evals, and customer-safe communications.

## Do Not Use When

- The work is not AI-specific or agentic-AI-specific.
- A narrower retained AI parent skill fits the request better.

## Required Inputs

- Product, tenant, user, data, risk, and operational context relevant to the AI workflow.
- Target artifact: design, implementation plan, audit, test strategy, UX flow, commercial policy, or runbook.
- Constraints from security, privacy, reliability, billing, support, and compliance stakeholders when relevant.

## Workflow

1. Read this SKILL.md first.
2. Load [references/routing.md](references/routing.md) to select the absorbed child reference that matches the task.
3. Load only the selected child reference files needed for the current request.
4. Produce execution-oriented output with assumptions, risks, evidence, and next actions where relevant.

## Quality Standards

- Keep routing explicit: name which reference files were used when the work depends on absorbed material.
- Preserve tenant isolation, auditability, cost controls, safety gates, and operational evidence when they matter.
- Prefer concrete contracts, checklists, tables, schemas, runbooks, and decision records over broad summaries.

## Anti-Patterns

- Loading every absorbed reference by default.
- Treating AI-specific billing, compliance, safety, or UX concerns as generic SaaS work without checking AI failure modes.
- Hiding retired skill names; old slugs must remain discoverable through [references/routing.md](references/routing.md).

## Outputs

- A concrete deliverable matched to the request: architecture, implementation plan, audit, policy, runbook, UX flow, test strategy, or operating model.
- The selected consolidated reference files and any assumptions, risks, evidence requirements, or follow-up actions that affect execution.
## References

- [references/routing.md](references/routing.md) maps retired child skill slugs to their consolidated reference folders.

## Consolidated Child References

- Load [references/routing.md](references/routing.md) to map retired AI child skill slugs to their reference modules.
## Evidence Produced

| Category | Artifact | Format | Example |
| --- | --- | --- | --- |
| Operability | AI incident timeline and recovery record | Markdown | detection, containment, kill action, tenant impact, evidence preservation, recovery, and follow-up |

<!-- dual-compat-end -->

Files in this skill

  • SKILL.md2.7 KB
  • references/ai-error-handling/entrypoint.md4.7 KB
  • references/ai-error-handling/references/skill-deep-dive.md11.2 KB
  • references/ai-error-prevention/entrypoint.md5 KB
  • references/ai-error-prevention/references/app-specific-prevention.md11 KB
  • references/ai-error-prevention/references/failure-modes.md8 KB
  • references/ai-error-prevention/references/prevention-strategies.md10.1 KB
  • references/ai-error-prevention/references/skill-deep-dive.md13.1 KB
  • references/ai-incident-customer-comms/entrypoint.md7.8 KB
  • references/ai-incident-customer-comms/references/per-tenant-notification-templates.md5.7 KB
  • references/ai-incident-customer-comms/references/regulator-notification-templates.md6.4 KB
  • references/ai-incident-customer-comms/references/status-page-templates.md5.4 KB
  • references/ai-incident-detection-and-triage/entrypoint.md9.5 KB
  • references/ai-incident-detection-and-triage/references/detection-signal-catalogue.md4.7 KB
  • references/ai-incident-detection-and-triage/references/severity-matrix.md4.6 KB
  • references/ai-incident-detection-and-triage/references/triage-decision-tree.md6.5 KB
  • references/ai-incident-drill-and-game-day/entrypoint.md10.4 KB
  • references/ai-incident-drill-and-game-day/references/drill-cadence.md3.1 KB
  • references/ai-incident-drill-and-game-day/references/game-day-exercises.md8.6 KB
  • references/ai-incident-evidence-capture/entrypoint.md12.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…