- Home
- Skills
- DevOps & Cloud
- incident review writer
incident review writer
Generate blameless incident postmortems, 5-Whys analysis, and verifiable action items from raw logs and Slack threads.
$5
Works with the AI tools you already use
incident review writer
Example session with this skill installed
Write a postmortem from these facts: 14:02 PagerDuty SEV-1 'API Latency', 14:05 Sarah: 'Seeing 500s on checkout', 14:12 Log: 'DB connection pool exhausted', 14:20 Mark: 'Reverted PR #402', 14:25 Resolved.
- Read your context and instructions
- Compiled the incident review writer
I have processed the incident data. I have flagged the causal link between PR #402 and the connection pool exhaustion as an assumption until the PR diff is reviewed.
Incident Review: SEV-1 API Latency (Checkout)
| Time (UTC) | Event | Source |
|---|---|---|
| 14:02 | Alert: SEV-1 API Latency triggered | PagerDuty |
| 14:05 | Detection: Reports of 500 errors on checkout service | Slack (Sarah) |
| 14:12 | Diagnosis: Database connection pool exhaustion identified | Logs |
| 14:20 | Mitigation: Reversion of PR #402 initiated | Slack (Mark) |
| 14:25 | Resolution: Latency returned to baseline; checkout 500s ceased | Fact |
Summary
On October 24, the checkout service experienced a 23-minute outage due to database connection pool exhaustion. The incident was triggered by a code change and resolved by reverting the offending pull request.
Root Cause Analysis (5-Whys)
- Why were users seeing 500 errors? The checkout service could not connect to the database.
- Why could it not connect? The connection pool was exhausted by long-running queries.
- Why were queries long-running? (Hypothesis) PR #402 introduced a non-indexed join on the orders table.
Why was this not caught in staging? Staging environment lacks production-scale data volume to trigger latent query inefficiencies.
5.
Systemic Root Cause: Deployment pipeline lacks automated performance regression testing for database-heavy changes.
Action Items
| Action Item | Owner | Deadline |
|---|---|---|
| Conduct retrospective review of PR #402 diff to confirm missing index | Data Team | Oct 27 |
| Implement connection pool saturation alerts at 80% threshold | SRE | Nov 1 |
| Document staging data anonymization plan to improve load test fidelity | Engineering Lead | Nov 15 |
Next steps
- Confirm if PR #402 specifically contained the non-indexed query mentioned in the hypothesis.
- Provide the log snippet from 14:12 to confirm the exact error code for the connection failure.
- Assign a specific engineer from the Data Team to the PR review action item.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Engineering teams spend hours manually parsing Slack threads and logs to write incident reports. These reports often lack systemic depth, contain finger-pointing, or fail to produce verifiable action items.
What it does
- Converts raw Slack exports and alert logs into a structured, minute-by-minute incident timeline.
- Performs a 5-Whys root cause analysis focused on systemic failures rather than individual errors.
- Generates full, blameless postmortems ready for Confluence or Notion.
- Audits action items to ensure they are specific, verifiable, and have assigned owners and deadlines.
Why this beats prompting it yourself
Generic prompts often invent missing data or use accusatory language that damages team culture. This skill enforces strict blamelessness and explicitly separates proven facts from assumptions, ensuring your reports meet senior leadership standards without manual editing.
Use cases
- Turning a chaotic SEV-1 Slack war room thread into a professional postmortem.
- Gap analysis of incident evidence to identify where logs or monitoring are missing.
- Standardizing action items across multiple engineering squads to ensure accountability.
Known limitations
Requires raw text evidence (logs, chats, alerts) to function. Cannot independently verify external financial impact data unless provided by the user.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 18 days ago
- Passed all security checks, Safe to install