incident review writer

    1

    Generate blameless incident postmortems, 5-Whys analysis, and verifiable action items from raw logs and Slack threads.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    incident review writer

    Example session with this skill installed

    Write a postmortem from these facts: 14:02 PagerDuty SEV-1 'API Latency', 14:05 Sarah: 'Seeing 500s on checkout', 14:12 Log: 'DB connection pool exhausted', 14:20 Mark: 'Reverted PR #402', 14:25 Resolved.

    • Read your context and instructions
    • Compiled the incident review writer

    I have processed the incident data. I have flagged the causal link between PR #402 and the connection pool exhaustion as an assumption until the PR diff is reviewed.

    Incident Review: SEV-1 API Latency (Checkout)

    Time (UTC)EventSource
    14:02Alert: SEV-1 API Latency triggeredPagerDuty
    14:05Detection: Reports of 500 errors on checkout serviceSlack (Sarah)
    14:12Diagnosis: Database connection pool exhaustion identifiedLogs
    14:20Mitigation: Reversion of PR #402 initiatedSlack (Mark)
    14:25Resolution: Latency returned to baseline; checkout 500s ceasedFact

    Summary

    On October 24, the checkout service experienced a 23-minute outage due to database connection pool exhaustion. The incident was triggered by a code change and resolved by reverting the offending pull request.

    Root Cause Analysis (5-Whys)

    1. Why were users seeing 500 errors? The checkout service could not connect to the database.
    2. Why could it not connect? The connection pool was exhausted by long-running queries.
    3. Why were queries long-running? (Hypothesis) PR #402 introduced a non-indexed join on the orders table.

    Why was this not caught in staging? Staging environment lacks production-scale data volume to trigger latent query inefficiencies.
    5.

    Systemic Root Cause: Deployment pipeline lacks automated performance regression testing for database-heavy changes.

    Action Items

    Action ItemOwnerDeadline
    Conduct retrospective review of PR #402 diff to confirm missing indexData TeamOct 27
    Implement connection pool saturation alerts at 80% thresholdSRENov 1
    Document staging data anonymization plan to improve load test fidelityEngineering LeadNov 15

    Next steps

    • Confirm if PR #402 specifically contained the non-indexed query mentioned in the hypothesis.
    • Provide the log snippet from 14:12 to confirm the exact error code for the connection failure.
    • Assign a specific engineer from the Data Team to the PR review action item.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Convert messy Slack war-room threads into structured incident timelines.Perform systemic 5-Whys analysis without blaming individual developers.Audit and rewrite vague action items into verifiable tasks with owners.Identify evidence gaps in incident data before final report submission.

    About this skill

    The problem

    Engineering teams spend hours manually parsing Slack threads and logs to write incident reports. These reports often lack systemic depth, contain finger-pointing, or fail to produce verifiable action items.

    What it does

    • Converts raw Slack exports and alert logs into a structured, minute-by-minute incident timeline.
    • Performs a 5-Whys root cause analysis focused on systemic failures rather than individual errors.
    • Generates full, blameless postmortems ready for Confluence or Notion.
    • Audits action items to ensure they are specific, verifiable, and have assigned owners and deadlines.

    Why this beats prompting it yourself

    Generic prompts often invent missing data or use accusatory language that damages team culture. This skill enforces strict blamelessness and explicitly separates proven facts from assumptions, ensuring your reports meet senior leadership standards without manual editing.

    Use cases

    • Turning a chaotic SEV-1 Slack war room thread into a professional postmortem.
    • Gap analysis of incident evidence to identify where logs or monitoring are missing.
    • Standardizing action items across multiple engineering squads to ensure accountability.

    Known limitations

    Requires raw text evidence (logs, chats, alerts) to function. Cannot independently verify external financial impact data unless provided by the user.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 18 days ago

    • Passed all security checks, Safe to install

    Listed18 days ago

    What's inside

    Frequently Asked Questions