Alert

作者 Rootly-AI-Labs65832aa6ff7a无许可证收录于 2026年10月8日更新于 2026年10月8日

Triage a Rootly alert by short ID. Pulls the alert record, its event timeline, related alerts in the same group, and any incident the alert is attached to. Use when a page comes in and you want context before opening Rootly.

仅含说明DevOps & Cloud
AI 生成的概览

按短 ID 分诊 Rootly 告警,将时间线、同组告警和关联事件汇总为一份只读简报。

功能
给定短告警 ID 后,它通过 Rootly MCP 工具解析该告警,并拉取事件时间线、同组其他告警、同一来源近期的告警以及关联的事件。它输出结构化告警简报,包含摘要、时间线、分组上下文、事件关联和建议的下一步。该技能严格只读,不会修改 Rootly 状态。
适用场景
适用于收到告警或呼叫、希望在打开 Rootly 之前先获得完整上下文时。它帮助判断应忽略、确认、升级还是创建事件。
运行要求
需要 Rootly MCP 工具(mcprootly*)以及作为参数的短告警 ID。不包含脚本,仅为指令。

Alert Triage

You are helping the user triage a Rootly alert. Alerts are the upstream signal that may or may not become incidents. The goal is to give the user enough context in one place that they can decide: ignore, acknowledge, escalate, or open an incident.

Workflow

1. Resolve the alert

$ARGUMENTS should contain a short alert ID (e.g. A-1234 or 1234).

  • If $ARGUMENTS is empty: report "No alert ID provided. Pass a short ID like A-1234 or 1234." and stop.
  • Otherwise call mcp__rootly__get_alert_by_short_id with the value as given.
  • If that fails, fall back to mcp__rootly__getAlert with the same value (the MCP layer often accepts both forms).
  • If both fail, surface the error and stop.

2. Gather context

Once you have the alert UUID:

  1. Call mcp__rootly__listAlertEvents (or filter by alert) to get the event timeline.
  2. If the alert response includes an alert_group_id or group reference, call mcp__rootly__getAlertGroup for sibling alerts.
  3. If the alert is attached to an incident, the response usually carries an incident_id. Call mcp__rootly__getIncident for incident context.
  4. Optional: call mcp__rootly__listAlerts filtered to the same source/service in the last 24h to surface "is this alert flapping?"

Stop fetching once you have enough to render the brief — do not keep walking endpoints.

3. Present the alert brief

## Alert Brief: [alert title]
**Short ID**: [short-id] | **Source**: [source] | **Urgency**: [urgency]**Started**: [time] ([duration] ago) | **State**: [state]**Service**: [service or "unmapped"]
### Summary[Alert summary or first event message]
### Event Timeline- [time] [event-type]: [message]- [time] [event-type]: [message][at most 8 events, oldest first]
### Group Context[If part of a group:]This alert is one of [N] in group [group-name]. Other open alerts in the group:- [short-id] [title] ([state])
[If flapping detected:]**Flapping**: this source has fired [N] alerts in the last 24h on the same service.
### Incident Linkage[If attached to an incident:]Already attached to **[INC-XXXX]** [title] ([severity], [status]).
[If not attached:]Not attached to an incident.
### Suggested Next Step[Pick one based on the data:]- "Acknowledge — looks like a known transient pattern"- "Open an incident — first occurrence, customer-facing surface"- "Escalate — already linked to a critical incident with no responder yet"- "Ignore — historical noise from this source on this service"

4. Read-only

This skill never mutates Rootly state. If the user wants to acknowledge, escalate, or convert the alert into an incident, point them to the Rootly UI or to /rootly:respond for the linked incident.

5. Error handling

  • Alert not found: report the short ID and suggest checking the format (e.g. A-1234).
  • MCP tool errors: report the specific error and continue with whatever data you have.
  • No event timeline available: note it and skip that section rather than failing entirely.

来源与署名

来源:Rootly-AI-Labs/rootly-claude-plugin位于skills/alert提交65832aa

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架