{"id":"62682fcc-1903-4e9b-bac2-a29e81ebbe16","slug":"kootik-infra-detective","name":"infra-detective","description":"Infrastructure incident investigator and postmortem generator for DevOps/SRE teams. Uses multi-agent orchestration to parallelize log analysis, metrics correlation, and timeline reconstruction. Generates structured incident reports and blameless postmortems. Use when investigating production incidents, analyzing outage timelines, correlating logs with metrics, generating postmortems, or performing chaos engineering reviews. Do NOT use for: code review (use refactor), security scanning (use security audit tools), general monitoring setup (use docs or runbooks directly). Triggers on \"investigate incident\", \"what happened in prod\", \"outage analysis\", \"postmortem\", \"root cause analysis\", \"RCA\", \"incident timeline\", \"расследовать инцидент\", \"постмортем\", \"анализ аварии\", \"что упало в проде\", or explicit /infra-detective command.","canonicalUrl":"https://www.xpersona.co/agent/kootik-infra-detective","sourceUrl":"https://github.com/kootik/infra-detective","homepage":null,"source":"GITHUB_OPENCLEW","vendor":{"slug":"kootik","label":"Kootik","url":"https://github.com/kootik/infra-detective"},"protocols":["OPENCLEW"],"capabilities":[],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":null,"freshnessAt":"2026-04-15T01:14:05.213Z","freshnessLabel":"Apr 15, 2026","securityReviewed":true,"openapiReady":false,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"OpenClaw"},{"label":"Freshness","value":"Apr 15, 2026"},{"label":"Vendor","value":"Kootik"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"Unpublished"}],"factsPreview":[{"factKey":"vendor","label":"Vendor","value":"Kootik","category":"vendor","href":"https://github.com/kootik/infra-detective","sourceUrl":"https://github.com/kootik/infra-detective","sourceType":"profile","confidence":"medium","observedAt":"2026-04-15T05:21:22.124Z","isPublic":true,"metadata":{}},{"factKey":"protocols","label":"Protocol compatibility","value":"OpenClaw","category":"compatibility","href":"https://www.xpersona.co/api/v1/agents/kootik-infra-detective/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/kootik-infra-detective/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-04-15T05:21:22.124Z","isPublic":true,"metadata":{}},{"factKey":"docs_crawl","label":"Crawlable docs","value":"6 indexed pages on the official domain","category":"integration","href":"https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar","sourceUrl":"https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar","sourceType":"search_document","confidence":"medium","observedAt":"2026-04-15T05:03:46.393Z","isPublic":true,"metadata":{}},{"factKey":"handshake_status","label":"Handshake status","value":"UNKNOWN","category":"security","href":"https://www.xpersona.co/api/v1/agents/kootik-infra-detective/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/kootik-infra-detective/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true,"metadata":{}}],"highlights":["Trust evidence available"],"agentCard":{"name":"infra-detective","description":"Infrastructure incident investigator and postmortem generator for DevOps/SRE teams. Uses multi-agent orchestration to parallelize log analysis, metrics correlation, and timeline reconstruction. Generates structured incident reports and blameless postmortems. Use when investigating production incidents, analyzing outage timelines, correlating logs with metrics, generating postmortems, or performing chaos engineering reviews. Do NOT use for: code review (use refactor), security scanning (use security audit tools), general monitoring setup (use docs or runbooks directly). Triggers on \"investigate incident\", \"what happened in prod\", \"outage analysis\", \"postmortem\", \"root cause analysis\", \"RCA\", \"incident timeline\", \"расследовать инцидент\", \"постмортем\", \"анализ аварии\", \"что упало в проде\", or explicit /infra-detective command.","source":"GITHUB_OPENCLEW","sourceId":"github:1161636185","repository":"https://github.com/kootik/infra-detective","documentation":"https://www.xpersona.co/agent/kootik-infra-detective","protocols":["OPENCLEW"],"languages":["typescript"],"install":{"command":"git clone https://github.com/kootik/infra-detective.git","ecosystem":"git"},"examples":[{"kind":"example","language":"text","snippet":"Layer 5: User-facing (HTTP 5xx, latency SLO breach)\n  Layer 4: Application (OOM, crash loops, connection pool exhaustion)\n  Layer 3: Platform (K8s scheduling, DNS, service mesh)\n  Layer 2: Infrastructure (node failure, disk pressure, network partition)\n  Layer 1: External (cloud provider, third-party API, DNS root)"},{"kind":"example","language":"markdown","snippet":"# 🚨 Incident Triage: [Title]\n\n**Severity**: SEV-[1-4] | **Status**: Active / Mitigated / Resolved\n**Blast Radius**: [scope description]\n**Started**: [timestamp] | **Detected**: [timestamp] | **MTTD**: [duration]\n\n## Affected Systems\n| System | Impact | Status |\n|--------|--------|--------|\n| [service] | [description] | 🔴/🟡/🟢 |\n\n## Initial Signal\n> [First error/alert that indicated the problem]\n\n## Suspected Cause\n[Best current hypothesis with confidence level]\n\n## Immediate Actions\n1. [ ] [Action with specific command or procedure]\n2. [ ] [Action]\n3. [ ] [Action]\n\n## Escalation\n- [ ] Page [team/person] if [condition]\n- [ ] Communicate to [stakeholders] via [channel]"}]}}