Incident Postmortem Research

On-demand Category 1 researcher for publicly-reported dev-tooling / supply-chain / AI-system incidents relevant to a current bank decision. Pulls the public postmortem (vendor disclosure, CISA advisory, post-incident analyst commentary, peer-bank disclosure if applicable), distills the technique + the missing control + the lesson, and maps to the org's current posture. Output at vault/research/incident/YYYY-MM-DD-{slug}.md. The Mini Shai-Hulud research at [[2026-06-20-actions-hardening-post-shai-hulud]] is an existing instance of this skill's output. Use when the user asks to research, distill, or learn from a specific publicly-reported incident — producing a fresh, cited research note mapped to org posture — not for internal incidents (org incident-response process), the recurring news sweep (weekly-intelligence-digest), or landscape-level supply-chain questions (supply-chain-security-watch).

themarmack fb8d60b 6.0 KB Updated

File contents

themarmack/research-bot/tree/main/.claude/skills/incident-postmortem-research commit fb8d60be0e

Frequently asked questions

npx skillmds@latest add themarmack/incident-postmortem-research