Alert

作者 Rootly-AI-Labs65832aa6ff7a無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Triage a Rootly alert by short ID. Pulls the alert record, its event timeline, related alerts in the same group, and any incident the alert is attached to. Use when a page comes in and you want context before opening Rootly.

僅含說明DevOps & Cloud
AI 產生的概覽

依短 ID 分診 Rootly 告警,將時間軸、同群組告警與關聯事件彙整成一份唯讀簡報。

功能
給定短告警 ID 後,它會透過 Rootly MCP 工具解析該告警,並取得事件時間軸、同群組的其他告警、同一來源近期的告警,以及任何關聯的事件。它會輸出結構化的告警簡報,包含摘要、時間軸、群組脈絡、事件關聯與建議的下一步。此技能嚴格唯讀,不會變更 Rootly 狀態。
適用情境
適用於收到告警或呼叫、希望在開啟 Rootly 之前先取得完整脈絡時。它有助於判斷應忽略、確認、升級或建立事件。
執行需求
需要 Rootly MCP 工具(mcprootly*),以及作為參數的短告警 ID。不含指令碼,僅有指示。

Alert Triage

You are helping the user triage a Rootly alert. Alerts are the upstream signal that may or may not become incidents. The goal is to give the user enough context in one place that they can decide: ignore, acknowledge, escalate, or open an incident.

Workflow

1. Resolve the alert

$ARGUMENTS should contain a short alert ID (e.g. A-1234 or 1234).

  • If $ARGUMENTS is empty: report "No alert ID provided. Pass a short ID like A-1234 or 1234." and stop.
  • Otherwise call mcp__rootly__get_alert_by_short_id with the value as given.
  • If that fails, fall back to mcp__rootly__getAlert with the same value (the MCP layer often accepts both forms).
  • If both fail, surface the error and stop.

2. Gather context

Once you have the alert UUID:

  1. Call mcp__rootly__listAlertEvents (or filter by alert) to get the event timeline.
  2. If the alert response includes an alert_group_id or group reference, call mcp__rootly__getAlertGroup for sibling alerts.
  3. If the alert is attached to an incident, the response usually carries an incident_id. Call mcp__rootly__getIncident for incident context.
  4. Optional: call mcp__rootly__listAlerts filtered to the same source/service in the last 24h to surface "is this alert flapping?"

Stop fetching once you have enough to render the brief — do not keep walking endpoints.

3. Present the alert brief

## Alert Brief: [alert title]
**Short ID**: [short-id] | **Source**: [source] | **Urgency**: [urgency]**Started**: [time] ([duration] ago) | **State**: [state]**Service**: [service or "unmapped"]
### Summary[Alert summary or first event message]
### Event Timeline- [time] [event-type]: [message]- [time] [event-type]: [message][at most 8 events, oldest first]
### Group Context[If part of a group:]This alert is one of [N] in group [group-name]. Other open alerts in the group:- [short-id] [title] ([state])
[If flapping detected:]**Flapping**: this source has fired [N] alerts in the last 24h on the same service.
### Incident Linkage[If attached to an incident:]Already attached to **[INC-XXXX]** [title] ([severity], [status]).
[If not attached:]Not attached to an incident.
### Suggested Next Step[Pick one based on the data:]- "Acknowledge — looks like a known transient pattern"- "Open an incident — first occurrence, customer-facing surface"- "Escalate — already linked to a critical incident with no responder yet"- "Ignore — historical noise from this source on this service"

4. Read-only

This skill never mutates Rootly state. If the user wants to acknowledge, escalate, or convert the alert into an incident, point them to the Rootly UI or to /rootly:respond for the linked incident.

5. Error handling

  • Alert not found: report the short ID and suggest checking the format (e.g. A-1234).
  • MCP tool errors: report the specific error and continue with whatever data you have.
  • No event timeline available: note it and skip that section rather than failing entirely.

來源與署名

來源:Rootly-AI-Labs/rootly-claude-plugin位於skills/alert提交65832aa

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架