# Run Incident Response

> Coordinate a production incident from declaration through mitigation, recovery, and learning. Use for live outages, elevated errors, security events, or material data-integrity risk.

- Skill: `sylphxai/run-incident-response` (Agent Skill)
- Install (CLI): `npx skillmds@latest add sylphxai/run-incident-response`
- Raw SKILL.md: https://api.skillmd.com/api/skills/sylphxai/run-incident-response/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: SylphxAI (https://skillmd.com/u/sylphxai)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/sylphxai/run-incident-response

---


# Run Incident Response

Stabilize first. Communicate observed facts, actions underway, and the next update time. Keep estimates labeled as estimates. Keep security-sensitive and personal data in authorized incident channels. A timeline of inferences is not a timeline of observations. Do not wait for root cause before stopping active harm.

Use `maintain-product` once harm is stable and the owning repair remains. Use `write-high-signal-update` for the customer or internal update text.

