skills/incident-escalation/SKILL.md
Standard protocol for responding to federation incidents: service outages, security breaches, constitutional violations, or agent misbehavior.
npx skillsauth add ariffazil/openclaw-workspace Incident Escalation ProtocolInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
When something goes wrong in the federation, speed and clarity matter. This skill provides the canonical escalation ladder.
| Level | Name | Examples | Response Time | |-------|------|----------|---------------| | 1 | info | Minor drift, stale docs | Next business day | | 2 | warning | Service slow, test flaky | 4 hours | | 3 | error | Service down, agent confused | 1 hour | | 4 | critical | Security breach, data loss, constitutional violation | 15 minutes | | 5 | emergency | Active attack, irreversible damage in progress | Immediate |
Agent detects incident
↓
Agent applies skill (if trained)
↓
Escalate to domain agent (GEOX/WEALTH/WELL/A-FORGE)
↓
Escalate to AAA control plane (routing + visibility)
↓
Escalate to arifOS 888_JUDGE (constitutional / irreversible)
↓
Escalate to Arif (human sovereign)
Determine severity level. When in doubt, escalate one level higher.
| Level | Notify | |-------|--------| | 1-2 | Log + dashboard | | 3 | Domain agent + AAA | | 4 | arifOS judge + Arif (Telegram) | | 5 | Arif immediately + all agents |
Use appropriate skills:
service-health-triagesecret-safety-scanagent-onboarding (re-read SOUL.md)parallel-authority-detectionSkill version 1.0.0 — AAA Skill Library
development
Check every skill’s “use when” and “do not use when” clauses for collisions, missing negatives, and vague verbs like “help,” “assist,” or “improve.” Load when linting, reviewing, or validating trigger boundaries.
development
Bootstrap, design, and package new skills. Load when capturing user intent for a new skill or drafting its initial instruction framework.
content-media
Diagnose which federation services are up, down, or drifting. Produce a prioritized remediation plan.
business
Scan a repo or workspace for exposed secrets, tokens, keys, and credentials. Produce a findings report with remediation steps.