security-incident-response

Coordinate security incident response workflows for triage, containment, eradication, and recovery.

7|Updated Feb 14, 2026
One-click install
npx skills add https://github.com/KentoShimizu/sw-agent-skills --skill security-incident-response-kentoshimizu
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-incident-response
Source: https://github.com/KentoShimizu/sw-agent-skills/tree/main/skills/security-incident-response
Command: npx skills add https://github.com/KentoShimizu/sw-agent-skills --skill security-incident-response-kentoshimizu

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes assets (resource) components.

What problem does it solve?

Security incident workflow to triage, contain, eradicate, and recover with evidence handling and coordination across teams.

Core Features & Use Cases

  • Structured incident triage and classification to determine severity and priority.
  • Evidence-preserving timeline creation, containment planning, and remediation actions.
  • Recovery validation, post-incident review, and regulatory/compliance documentation.

Quick Start

Initiate the incident response workflow for a suspected security incident using the provided timeline template and escalation contacts.

Frequently Asked Questions about security-incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I coordinate a security incident response workflow to minimize blast radius?▼

A security incident response workflow coordinates triage, containment, eradication, and recovery planning across systems and stakeholders to minimize blast radius. It enforces evidence handling, chain-of-custody, and formal deliverables like a detailed timeline.

What is the best way to preserve digital evidence and maintain chain-of-custody during an ongoing security incident?▼

To preserve digital evidence during an incident, the workflow enforces strict evidence handling and chain-of-custody protocols. It generates formal deliverables including an evidence-preserving timeline and containment plan to ensure regulatory compliance.

How do I structure incident triage and classification to determine severity and priority?▼

Incident triage and classification structures severity and priority determination by systematically evaluating suspected security incidents. This process initiates the workflow, guiding containment planning, eradication actions, and recovery validation.

Can I use this incident response workflow for regulatory and compliance documentation after an attack?▼

Yes, this incident response workflow supports regulatory and compliance documentation by producing formal deliverables. It includes recovery validation, post-incident review, and evidence-preserving timelines required for compliance reporting.

What deliverables do I need for a complete security incident recovery validation and post-incident review?▼

Complete recovery validation and post-incident review require formal deliverables including a detailed incident timeline, containment and eradication plan, and recovery validation records. These ensure evidence integrity and coordinate stakeholder communication.