MCP HubMCP Hub
스킬 목록으로 돌아가기

response-coordinator

guia-matthieu
업데이트됨 2 days ago
6 조회
111
20
111
GitHub에서 보기
메타general

정보

response-coordinator 스킬은 플레이북 템플릿, 커뮤니케이션 프레임워크, 팀 협업 도구를 제공하여 개발자들이 구조화된 위기 관리 체계를 구현하도록 돕습니다. 이 스킬은 확립된 PPRR 및 사건 지휘 방법론을 기반으로, 실제 위기 대응, 훈련 시나리오, 사후 분석을 위해 설계되었습니다. 이 스킬은 대응 계획을 구조화하고 커뮤니케이션 초안을 작성하는 동시에, 최종적인 실행 여부 결정은 사용자에게 맡깁니다.

빠른 설치

Claude Code

추천
기본
npx skills add guia-matthieu/clawfu-skills -a claude-code
플러그인 명령대체
/plugin add https://github.com/guia-matthieu/clawfu-skills
Git 클론대체
git clone https://github.com/guia-matthieu/clawfu-skills.git ~/.claude/skills/response-coordinator

Claude Code에서 이 명령을 복사하여 붙여넣어 스킬을 설치하세요

문서

Crisis Response Coordinator

Orchestrate effective crisis response through structured playbooks, clear communication templates, and coordinated team actions.

When to Use This Skill

  • Active crisis situations
  • Building crisis playbooks
  • Training response teams
  • Creating communication templates
  • Post-crisis improvement

Methodology Foundation

Based on Burson-Marsteller crisis playbook and PPRR model (Prevention, Preparedness, Response, Recovery), combining:

  • Incident command structure
  • Stakeholder communication
  • Timeline management
  • Documentation practices

What Claude Does vs What You Decide

Claude DoesYou Decide
Structures response playbookGo/no-go decisions
Drafts communicationsApproval authority
Coordinates timelinesResource deployment
Documents actionsSpokesperson selection
Suggests escalation pathsLegal implications

Instructions

Step 1: Activate Crisis Protocol

Activation Checklist:

  • Confirm crisis status (not false alarm)
  • Identify crisis type and scope
  • Assemble core response team
  • Establish communication channels
  • Begin documentation log

Step 2: Establish Command Structure

Crisis Team Roles:

RoleResponsibilityTypical Owner
Crisis LeadOverall coordinationCEO/COO
Comms LeadExternal messagingCMO/PR Head
Operations LeadFix the problemCTO/VP Ops
Legal CounselLegal guidanceGeneral Counsel
Customer LeadCustomer communicationVP CX
HR LeadInternal/employeeCHRO

Step 3: Execute Response

Response Phases:

PhaseDurationFocus
Contain0-2 hoursStop bleeding, assess scope
Communicate2-4 hoursStakeholder notifications
Resolve4-24 hoursFix root cause
Recover1-7 daysReturn to normal
Learn7-30 daysPost-mortem, improvements

Step 4: Manage Communications

Stakeholder Priority:

StakeholderWhen to NotifyChannel
Internal teamImmediatelySlack/Teams
Board/InvestorsWithin 1 hourCall/Email
Affected customersWithin 2 hoursDirect
All customersWithin 4 hoursEmail/Social
MediaReactivePress statement
PublicAs neededWebsite/Social

Step 5: Document Everything

Crisis Log Template:

TIME | ACTION | OWNER | OUTCOME
-----|--------|-------|--------
10:00 | Alert received | [Name] | Verified
10:15 | Team assembled | [Name] | 5/6 present
10:30 | Root cause identified | [Name] | DB issue
...

Examples

Example 1: Crisis Response Playbook

Input:

Create a crisis response playbook for a data breach scenario.

Output:

## Crisis Playbook: Data Breach

### Severity Classification

| Level | Criteria | Response |
|-------|----------|----------|
| **Critical** | PII exposed, >10K records | Full activation |
| **High** | PII exposed, <10K records | Partial activation |
| **Medium** | Non-PII data exposed | Contained response |
| **Low** | Attempted breach, blocked | Monitor and report |

---

### Activation Trigger

**Automatic activation when:**
- Confirmed unauthorized data access
- Evidence of data exfiltration
- Regulatory notification required
- Media awareness possible

---

## Phase 1: CONTAIN (0-2 Hours)

### Immediate Actions

| Time | Action | Owner | Checklist |
|------|--------|-------|-----------|
| +0 min | Isolate affected systems | IT Security | [ ] |
| +0 min | Preserve forensic evidence | IT Security | [ ] |
| +15 min | Assemble crisis team | Crisis Lead | [ ] |
| +30 min | Brief team on situation | IT Security | [ ] |
| +30 min | Legal notification | Legal | [ ] |
| +1 hr | Scope assessment complete | IT Security | [ ] |
| +1 hr | Impact assessment complete | Ops Lead | [ ] |

### Crisis Team Assembly

**Mandatory Attendees:**
- [ ] CEO (Crisis Lead)
- [ ] CTO (Technical Lead)
- [ ] CISO (Security Lead)
- [ ] General Counsel (Legal Lead)
- [ ] CMO (Communications Lead)
- [ ] VP Customer Success (Customer Lead)

**Optional (as needed):**
- [ ] CHRO (if employee data)
- [ ] CFO (if financial impact)
- [ ] Board liaison

### Initial Assessment Template

BREACH ASSESSMENT

Discovery Time: [TIME] Breach Window: [START] to [END]

Data Involved:

  • Names
  • Email addresses
  • Phone numbers
  • Passwords
  • Payment data
  • SSN/Government ID
  • Health information
  • Other: ___________

Records Affected: [NUMBER] Customers Affected: [NUMBER]

Attack Vector: [DESCRIPTION] Current Status: [CONTAINED/ONGOING] Confidence Level: [HIGH/MEDIUM/LOW]


---

## Phase 2: COMMUNICATE (2-4 Hours)

### Communication Sequence

| Priority | Stakeholder | When | Channel | Owner |
|----------|-------------|------|---------|-------|
| 1 | Board/Investors | +2hr | Call | CEO |
| 2 | Regulators | +2hr | Formal notice | Legal |
| 3 | Affected customers | +3hr | Email | CX Lead |
| 4 | All employees | +3hr | All-hands | HR |
| 5 | Media (if inquiries) | +4hr | Statement | Comms |
| 6 | Public | +4hr | Website | Comms |

---

### Communication Templates

#### Customer Notification (Direct Victims)

Subject: Important Security Notice - Action Required

Dear [Name],

We're writing to inform you about a security incident that may have involved your personal information.

WHAT HAPPENED On [DATE], we discovered unauthorized access to [SYSTEM]. The incident occurred between [DATE] and [DATE].

WHAT INFORMATION WAS INVOLVED Based on our investigation, the following information may have been accessed:

  • [List specific data types]

WHAT WE'RE DOING

  • We immediately secured our systems
  • We engaged cybersecurity experts to investigate
  • We notified law enforcement
  • We are providing [credit monitoring/identity protection]

WHAT YOU CAN DO

  1. [Specific action 1]
  2. [Specific action 2]
  3. [Specific action 3]

CONTACT US If you have questions, please contact our dedicated support line:

  • Phone: [NUMBER] (24/7 for next 30 days)
  • Email: [EMAIL]
  • FAQ: [URL]

We sincerely apologize for this incident and any concern it causes.

[Signature]


#### All-Customer Notification

Subject: Security Update from [Company]

Dear [Customer],

We're writing with an important security update.

On [DATE], we discovered a security incident affecting some customer accounts. We want to be transparent about what happened and what we're doing.

THE INCIDENT [2-3 sentence summary of what happened]

YOUR ACCOUNT Based on our investigation, your account [was / was not] affected. [If affected: See separate email with specific details]

OUR RESPONSE

  • [Action taken 1]
  • [Action taken 2]
  • [Action taken 3]

GOING FORWARD [Steps being taken to prevent future incidents]

We're deeply sorry this occurred and are committed to earning back your trust.

[Signature]


#### Media Statement

STATEMENT FROM [COMPANY] REGARDING SECURITY INCIDENT

[DATE]

[Company] recently discovered unauthorized access to certain company systems. Upon discovery, we immediately took steps to secure our systems and engaged leading cybersecurity experts to investigate.

Based on our investigation:

  • [Key fact 1]
  • [Key fact 2]
  • [Key fact 3]

We have notified the appropriate authorities and are working closely with law enforcement.

Affected individuals are being notified directly and we are providing [specific remediation].

We take the security of our customers' information extremely seriously. We apologize for this incident and are taking steps to prevent similar incidents in the future.

For more information, please visit: [URL]

Media Contact: [Name], [Email]


---

## Phase 3: RESOLVE (4-24 Hours)

### Technical Remediation

| Action | Owner | Deadline | Status |
|--------|-------|----------|--------|
| Patch vulnerability | Security | +6hr | [ ] |
| Reset affected credentials | IT | +8hr | [ ] |
| Deploy additional monitoring | Security | +12hr | [ ] |
| Third-party security audit | Security | +7 days | [ ] |

### Customer Remediation

| Action | Owner | Deadline | Status |
|--------|-------|----------|--------|
| Credit monitoring enrollment | CX | +24hr | [ ] |
| Password reset flow | Product | +24hr | [ ] |
| Support surge staffing | CX | +24hr | [ ] |
| FAQ page live | Marketing | +6hr | [ ] |

---

## Phase 4: RECOVER (1-7 Days)

### Operational Recovery

| Milestone | Target | Owner |
|-----------|--------|-------|
| Normal operations | +24hr | Ops |
| Support queue normal | +72hr | CX |
| Security audit complete | +7 days | Security |
| All notifications sent | +72hr | Legal |

### Communication Recovery

| Activity | Timing | Owner |
|----------|--------|-------|
| Progress update #1 | +24hr | Comms |
| Progress update #2 | +72hr | Comms |
| Final resolution notice | +7 days | Comms |
| Thank you to customers | +14 days | CEO |

---

## Phase 5: LEARN (7-30 Days)

### Post-Incident Review

**Schedule within 7 days of resolution**

Agenda:
1. Timeline reconstruction
2. What worked well
3. What needs improvement
4. Action items for prevention
5. Communication effectiveness
6. Documentation updates

### Playbook Updates

Based on learnings, update:
- [ ] Detection capabilities
- [ ] Response procedures
- [ ] Communication templates
- [ ] Team training
- [ ] Vendor relationships

Example 2: Real-Time Response Coordination

Input:

We're in the middle of a crisis - product recall needed.
Contaminated ingredient found in batch.
What do we do now?

Output:

## ACTIVE CRISIS: Product Recall

### STATUS: PHASE 1 - CONTAIN

---

### IMMEDIATE ACTIONS (Next 60 Minutes)

| # | Action | Owner | Done |
|---|--------|-------|------|
| 1 | STOP all shipments of affected batch | Operations | [ ] |
| 2 | Identify batch numbers affected | QC | [ ] |
| 3 | Pull from retail shelves (notify partners) | Sales | [ ] |
| 4 | Count units sold vs. in inventory | Operations | [ ] |
| 5 | Assemble full crisis team | CEO | [ ] |
| 6 | Contact legal counsel | CEO | [ ] |
| 7 | Notify regulatory authority (FDA/etc) | Legal | [ ] |

---

### INFORMATION NEEDED NOW

Fill in as you gather:

AFFECTED BATCH:

  • Batch number(s): _______________
  • Production date(s): _______________
  • Contamination type: _______________
  • Health risk level: [ ] Low [ ] Medium [ ] High [ ] Critical

DISTRIBUTION:

  • Units produced: _______________
  • Units shipped: _______________
  • Units in warehouse: _______________
  • Retailers received: _______________
  • Units sold to consumers (est): _______________

CUSTOMERS AT RISK:

  • Can you identify purchasers? [ ] Yes [ ] No
  • Geographic distribution: _______________

---

### COMMUNICATION PRIORITY

| Priority | Who | When | Message |
|----------|-----|------|---------|
| 1 | Retail partners | NOW | Stop sales, pull from shelves |
| 2 | Regulatory body | Within 1hr | Formal notification |
| 3 | Identified customers | Within 2hr | Direct recall notice |
| 4 | All customers | Within 4hr | Public recall announcement |
| 5 | Media | As needed | Press statement ready |

---

### HOLDING STATEMENT (Use if media calls NOW)

"We are aware of an issue with [product] and are taking immediate action. Customer safety is our top priority. We will have a full statement within [X] hours.

In the meantime, customers who have purchased [product] should [specific action].

Questions: [contact]"


---

### CUSTOMER COMMUNICATION TEMPLATE

URGENT PRODUCT RECALL NOTICE

[Company] is voluntarily recalling [Product Name] due to potential contamination with [substance].

AFFECTED PRODUCTS:

  • Product: [Name]
  • Batch #: [Numbers]
  • Expiration dates: [Dates]
  • Sold at: [Retailers]

WHAT TO DO:

  1. STOP using the product immediately
  2. [Disposal instructions OR return instructions]
  3. Contact us for full refund: [phone/email/url]

IF YOU'VE CONSUMED THE PRODUCT:

  • [Symptoms to watch for]
  • [When to seek medical attention]
  • [Who to call]

We sincerely apologize for this situation and are taking all steps to ensure this doesn't happen again.

Questions: [24/7 Hotline Number]


---

### NEXT CHECK-IN: 30 MINUTES

At that time, confirm:
- [ ] All shipments stopped
- [ ] Batch scope finalized
- [ ] Retail partners notified
- [ ] Regulatory notification sent
- [ ] Customer communication ready

Skill Boundaries

What This Skill Does Well

  • Structuring response playbooks
  • Creating communication templates
  • Coordinating response timelines
  • Organizing team actions

What This Skill Cannot Do

  • Make legal determinations
  • Access your systems
  • Speak on your behalf
  • Know regulatory requirements

Iteration Guide

Follow-up Prompts:

  • "Create a playbook for [crisis type]"
  • "Draft communication for [stakeholder]"
  • "What should our next 30 minutes look like?"
  • "How do we communicate [specific development]?"

References

  • Burson Crisis Communications
  • PPRR Crisis Management Model
  • FEMA Incident Command System
  • Harvard Business Review Crisis Response

Related Skills

  • crisis-detector - Early warning
  • social-listening - Monitoring
  • reputation-recovery - Post-crisis

Skill Metadata

  • Domain: Crisis
  • Complexity: Advanced
  • Mode: centaur
  • Time to Value: Immediate in crisis
  • Prerequisites: Stakeholder alignment, authority to act

GitHub 저장소

guia-matthieu/clawfu-skills
경로: skills/crisis/response-coordinator
0
ai-skillsanthropicclaude-codeclaude-skillsmarketingmcp-server

연관 스킬

content-collections

메타

이 스킬은 콘텐츠 콜렉션(Content Collections)을 위한 프로덕션 검증된 설정을 제공합니다. 콘텐츠 콜렉션은 Markdown/MDX 파일을 Zod 검증이 포함된 타입 안전한 데이터 콜렉션으로 변환해주는 TypeScript 최우선 도구입니다. 블로그, 문서 사이트 또는 콘텐츠 중심의 Vite + React 애플리케이션을 구축할 때 타입 안전성과 자동 콘텐츠 검증을 보장하기 위해 사용하세요. Vite 플러그인 구성과 MDX 컴파일부터 배포 최적화 및 스키마 검증에 이르기까지 모든 것을 다룹니다.

스킬 보기

polymarket

메타

이 스킬은 개발자들이 Polymarket 예측 시장 플랫폼을 활용한 애플리케이션을 구축할 수 있도록 지원하며, 거래 및 시장 데이터를 위한 API 통합 기능을 포함합니다. 또한 WebSocket을 통한 실시간 데이터 스트리밍을 제공하여 실시간 거래와 시장 활동을 모니터링할 수 있습니다. 이를 통해 거래 전략을 구현하거나 실시간 시장 업데이트를 처리하는 도구를 생성하는 데 활용할 수 있습니다.

스킬 보기

creating-opencode-plugins

메타

이 스킬은 개발자들이 명령어, 파일, LSP 작업 등 25개 이상의 이벤트 유형에 연결되는 OpenCode 플러그인을 만들 수 있도록 돕습니다. JavaScript/TypeScript 모듈을 위한 플러그인 구조, 이벤트 API 명세, 구현 패턴을 제공합니다. OpenCode AI 어시스턴트의 라이프사이클을 사용자 정의 이벤트 기반 로직으로 가로채거나, 모니터링하거나, 확장해야 할 때 사용하세요.

스킬 보기

sglang

메타

SGLang은 RadixAttention 프리픽스 캐싱을 활용하여 JSON, 정규식, 에이전트 워크플로우를 위한 고속 구조화 생성에 특화된 고성능 LLM 서빙 프레임워크입니다. 특히 반복되는 프리픽스가 있는 작업에서 상당히 빠른 추론 속도를 제공하여 복잡한 구조화 출력 및 다중 턴 대화에 이상적입니다. 제약 디코딩이 필요하거나 광범위한 프리픽스 공유가 있는 애플리케이션을 구축할 때는 vLLM과 같은 대안보다 SGLang을 선택하십시오.

스킬 보기