Incident Triage Skill
Purpose
Streamline incident response with SOPs, indicator extraction, and memory-backed timelines.
Process
- Apply triage SOP from SKILL.md
- Extract indicators from logs (via extract_indicators.py)
- Escalate per matrix in references/escalation_matrix.md
- Write timeline to memory with TTL (30 days)
- Generate postmortem template
Scripts
extract_indicators.py: Pull signals from logsgenerate_timeline.py: Create incident timeline
Memory Integration
Incidents auto-expire after 30 days via TTL.
Incident Triage v1.0.0