Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Agent Incident Postmortem

ASecurity

Run a blameless postmortem for an incident caused by an AI agent or LLM feature — hallucinated facts shipped to users, runaway tool use, prompt injection, cost blowouts, or wrong actions taken autonomously. Use when asked to write up an AI incident, analyse why an agent did something wrong, or produce corrective actions after an LLM failure. Produces a structured postmortem with trace reconstruction, a root-cause layer analysis, and corrective actions including a permanent regression case. Fo...

1,330 stars
0 votes
0 copies
0 views
Added 9/3/2026
ai-agentsrustgorailsgit

Security Analysis

A100/100

Scanned 9/3/2026

$npx -y skills add mohitagw15856/pm-claude-skills --skill agent-incident-postmortem --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Agent Incident Postmortem?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Agent Incident Postmortem
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/mohitagw15856-agent-incident-postmortem/badge)](https://www.skillsdirectory.com/skills/mohitagw15856-agent-incident-postmortem)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: agent-incident-postmortem
description: "Run a blameless postmortem for an incident caused by an AI agent or LLM feature — hallucinated facts shipped to users, runaway tool use, prompt injection, cost blowouts, or wrong actions taken autonomously. Use when asked to write up an AI incident, analyse why an agent did something wrong, or produce corrective actions after an LLM failure. Produces a structured postmortem with trace reconstruction, a root-cause layer analysis, and corrective actions including a permanent regression case. For non-AI production incidents use incident-postmortem."
homepage: https://mohitagw15856.github.io/pm-claude-skills/skill/agent-incident-postmortem.html
metadata:
  {
    "openclaw": { "emoji": "🦾" }
  }
---

# Agent Incident Postmortem Skill

AI incidents differ from outages: the system didn't go down — it did something wrong, confidently, and maybe only once. This skill adapts blameless postmortem practice to nondeterministic systems, where "can we reproduce it?" needs traces, not just steps.

## What This Skill Produces

- A **blameless postmortem document** with timeline and user/business impact
- A **trace reconstruction** of what the agent saw, decided, and did
- A **root-cause analysis across the AI failure layers** (not "the model hallucinated" as a conclusion)
- **Corrective actions** — always including a new permanent case in the regression suite

## Required Inputs

Ask for (if not already provided):
- **What the agent did** and what it should have done
- **The trace** — the full request: system prompt, context, tool calls and results, output. If no trace exists, that absence is itself a finding
- **Blast radius** — how many users/requests, over what window, and whether it's ongoing
- **Detection** — how it was noticed (user report? monitor? luck?) and how long after it started

## Root-Cause Layers

Walk the layers in order; the root cause is usually the *earliest* layer that could have prevented the outcome. "The model was wrong" is a starting point, never the conclusion — models are known to be fallible, so the question is what let a fallible output become an incident.

| Layer | Ask |
|---|---|
| **Input / context** | Was the context wrong, stale, contradictory, or poisoned (injection)? Did retrieval feed it bad ground truth? |
| **Model behaviour** | Given that context, was the output a foreseeable failure mode (fabrication under missing data, over-compliance with injected text)? |
| **Guardrails** | What check should have caught this output and didn't exist / didn't fire? (schema validation, groundedness check, action allow-list) |
| **Action layer** | Why could the wrong output become a real action or reach a user without the appropriate gate for its risk level? |
| **Detection** | Why did we learn about it this way, this late? What signal would have caught it in minutes? |

## Nondeterminism Discipline

- **Reproduce with the trace, not the anecdote:** replay the exact context; then re-run N times to measure frequency — a 1-in-20 failure at 10k requests/day is 500 incidents/day.
- **Pin everything when replaying:** model version, prompt version, temperature, tool results.
- **If it can't be reproduced:** say so, keep the trace as the evidence, and treat frequency as unknown — not as "rare".

## Output Format

### AI Incident Postmortem: [title] — [date]

**Severity:** [level] · **Status:** [resolved/monitoring] · **Owner:** [name]

**Summary:** [3 sentences: what the agent did, impact, root cause layer]

**Impact:** [users/requests affected, window, cost, trust/regulatory dimension]

**Timeline:** [first bad output → detection → mitigation → resolution, with the detection gap called out]

**Trace reconstruction:** [what was in the window; which tool calls ran; where the path diverged from intended behaviour]

**Root cause by layer:**
| Layer | Finding |
|---|---|
| Input/context | |
| Model behaviour | |
| Guardrails | |
| Action layer | |
| Detection | |

**Reproduction:** [replayed? failure frequency over N runs / not reproducible — evidence is the trace]

**Corrective actions:**
| Action | Layer | Owner | Due |
|---|---|---|---|
| Add this trace as a permanent regression case | eval | | |
| [guardrail/monitor/context fix] | | | |

**What went well / what got lucky:** [both, honestly]

## Quality Checks

- [ ] The postmortem is blameless toward humans *and* useful about the system — "prompt engineer error" and "model hallucinated" are both banned conclusions
- [ ] Root cause identifies the earliest layer that could have prevented impact, not just the layer that misbehaved
- [ ] The trace (or its absence) is in the document; findings cite it
- [ ] Failure frequency was measured or explicitly marked unknown
- [ ] Corrective actions include the permanent regression case and at least one detection improvement

## Anti-Patterns

- [ ] Do not close with "improved the prompt" as the only action — the same class of output must also be caught by a guardrail or gate next time
- [ ] Do not assess frequency from one replay — nondeterministic failures hide at low temperatures and reappear at scale
- [ ] Do not skip the injection question when any untrusted text (web, user docs, tickets) was in the window
- [ ] Do not let "the model will be better next version" close an action item — upgrades are migrations (see model-migration-plan), not fixes
- [ ] Do not write it as an outage report — the system was up; the failure was behavioural, and the doc must analyse behaviour

Attribution

mohitagw15856mohitagw15856
View sourceSee grades on GitHubMore from mohitagw15856 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →