Skip to content
FunCoding

Search

Search docs, Skills and MCP

agent-incident-postmortem

Run a blameless postmortem for an incident caused by an AI agent or LLM feature — hallucinated facts shipped to users, runaway tool use, prompt injection, cost blowouts, or wrong actions taken autonomously. Use when asked to write up an AI incident, analyse why an agent did something wrong, or produce corrective actions after an LLM failure. Produces a structured postmortem with trace reconstruction, a root-cause layer analysis, and corrective actions including a permanent regression case. For non-AI production incidents use incident-postmortem.

AI 与智能体1.4kskills/agent-incident-postmortem/SKILL.md

Install

Send this to Claude Code, Codex or Cursor. The agent checks the Skill for safety first and installs it only after you confirm.

读取 https://funcoding.ai/skills/mohitagw15856/pm-claude-skills/agent-incident-postmortem/install.md ,按里面的步骤帮我安装这个 Skill。

SKILL.md

Agent Incident Postmortem Skill

AI incidents differ from outages: the system didn't go down — it did something wrong, confidently, and maybe only once. This skill adapts blameless postmortem practice to nondeterministic systems, where "can we reproduce it?" needs traces, not just steps.

What This Skill Produces

  • A blameless postmortem document with timeline and user/business impact
  • A trace reconstruction of what the agent saw, decided, and did
  • A root-cause analysis across the AI failure layers (not "the model hallucinated" as a conclusion)
  • Corrective actions — always including a new permanent case in the regression suite

Required Inputs

Ask for (if not already provided):

  • What the agent did and what it should have done
  • The trace — the full request: system prompt, context, tool calls and results, output. If no trace exists, that absence is itself a finding
  • Blast radius — how many users/requests, over what window, and whether it's ongoing
  • Detection — how it was noticed (user report? monitor? luck?) and how long after it started

Root-Cause Layers

Walk the layers in order; the root cause is usually the earliest layer that could have prevented the outcome. "The model was wrong" is a starting point, never the conclusion — models are known to be fallible, so the question is what let a fallible output become an incident.

LayerAsk
Input / contextWas the context wrong, stale, contradictory, or poisoned (injection)? Did retrieval feed it bad ground truth?
Model behaviourGiven that context, was the output a foreseeable failure mode (fabrication under missing data, over-compliance with injected text)?
GuardrailsWhat check should have caught this output and didn't exist / didn't fire? (schema validation, groundedness check, action allow-list)
Action layerWhy could the wrong output become a real action or reach a user without the appropriate gate for its risk level?
DetectionWhy did we learn about it this way, this late? What signal would have caught it in minutes?

Nondeterminism Discipline

  • Reproduce with the trace, not the anecdote: replay the exact context; then re-run N times to measure frequency — a 1-in-20 failure at 10k requests/day is 500 incidents/day.
  • Pin everything when replaying: model version, prompt version, temperature, tool results.
  • If it can't be reproduced: say so, keep the trace as the evidence, and treat frequency as unknown — not as "rare".

Output Format

AI Incident Postmortem: [title] — [date]

Severity: [level] · Status: [resolved/monitoring] · Owner: [name]

Summary: [3 sentences: what the agent did, impact, root cause layer]

Impact: [users/requests affected, window, cost, trust/regulatory dimension]

Timeline: [first bad output → detection → mitigation → resolution, with the detection gap called out]

Trace reconstruction: [what was in the window; which tool calls ran; where the path diverged from intended behaviour]

Root cause by layer:

LayerFinding
Input/context
Model behaviour
Guardrails
Action layer
Detection

Reproduction: [replayed? failure frequency over N runs / not reproducible — evidence is the trace]

Corrective actions:

ActionLayerOwnerDue
Add this trace as a permanent regression caseeval
[guardrail/monitor/context fix]

What went well / what got lucky: [both, honestly]

Quality Checks

  • The postmortem is blameless toward humans and useful about the system — "prompt engineer error" and "model hallucinated" are both banned conclusions
  • Root cause identifies the earliest layer that could have prevented impact, not just the layer that misbehaved
  • The trace (or its absence) is in the document; findings cite it
  • Failure frequency was measured or explicitly marked unknown
  • Corrective actions include the permanent regression case and at least one detection improvement

Anti-Patterns

  • Do not close with "improved the prompt" as the only action — the same class of output must also be caught by a guardrail or gate next time
  • Do not assess frequency from one replay — nondeterministic failures hide at low temperatures and reappear at scale
  • Do not skip the injection question when any untrusted text (web, user docs, tickets) was in the window
  • Do not let "the model will be better next version" close an action item — upgrades are migrations (see model-migration-plan), not fixes
  • Do not write it as an outage report — the system was up; the failure was behavioural, and the doc must analyse behaviour

Example Trigger Phrases

  • "Write up an AI incident."
  • "Analyse why an agent did something wrong."
  • "Produce corrective actions after an LLM failure."

Similar Skills

brand-guidelines
anthropics/skills180k

brand-guidelines

Applies Anthropic's official brand colors and typography to any sort of artifact that may benefit from having Anthropic's look-and-feel. Use it when brand colors or style guidelines, visual formatting, or company design standards apply.

AI & agents

internal-comms
anthropics/skills180k

internal-comms

A set of resources to help me write all kinds of internal communications, using the formats that my company likes to use. Claude should use this skill whenever asked to write some sort of internal communications (status reports, leadership updates, 3P updates, company newsletters, FAQs, incident reports, project updates, etc.).

AI & agents

template-skill
anthropics/skills180k

template-skill

Replace with description of the skill and when Claude should use it.

AI & agents

mcp-builder
anthropics/skills180k

mcp-builder

Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).

AI & agents

algorithmic-art
anthropics/skills180k

algorithmic-art

Creating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems. Create original algorithmic art rather than copying existing artists' work to avoid copyright violations.

AI & agents

academy-guide
anthropics/skills180k

academy-guide

Stop and check this skill before finishing any reply to a question about how to use Claude or a Claude product — it recommends matching courses, tutorials, and use cases from Claude Academy (academy.claude.com), Anthropic's learning hub. Trigger on: "how do I", "how can I", "getting started with", "what can Claude do", "teach me", "learn to use"; questions about artifacts, projects, skills, plugins, connectors, MCP; requests about rolling Claude out to a team, class, or organization; and any ask for training materials, onboarding content, or learning resources. Use it when the user is learning how to use a feature or product — not when they are mid-task and just want the task done. This skill composes with other skills: after consulting product documentation to answer how a Claude feature works, also check here for a matching course or tutorial — a docs-grounded answer and an Academy recommendation belong together. Only recommend on a strong match; never invent Academy content.

AI & agents