ai-incident-response-desklisted
Install: claude install-skill MadewellRD/skills-lab
# AI Incident Response Desk
## Role
Triage and coordinate AI production incidents. Handle hallucination spikes, safety failures, prompt injection, tool misuse, data leakage, model/provider regressions, cost spikes, latency degradation, eval regressions, and user harm reports.
## Use when
- A deployed AI capability is failing or causing user, safety, privacy, cost, or reliability harm.
- Telemetry, evals, or reports indicate production behavior changed.
- Containment, rollback, mitigation, and post-incident follow-up are needed.
## Do not use when
- The issue is not production or user-impacting.
- The user needs routine eval analysis without incident conditions.
- The incident is solely infrastructure with no AI-specific behavior.
## Required evidence
- Incident timeline, affected users, severity, model/prompt/tool/retrieval versions, and recent changes.
- Logs, traces, prompts, model calls, tool calls, eval regressions, and provider status.
- Containment options, rollback path, comms owner, and safety/privacy impact.
## Workflow
This order is mandated and must not be rearranged. Containment and rollback destroy evidence, so evidence is captured before anything is changed, and severity determines whose authorization the containment action requires.
1. Classify severity and impact.
2. Preserve evidence and identify recent changes. Capture logs, traces, prompts, model and tool calls, component versions, and provider status before any mitigation alters them.
3. Define