CANDIDATE CANDIDATE NEW BOUNDED TASK · Operations Web Function 0.1.0. Turn a web observation into a defensible classification, severity, owner, service-level target, preservation decision, next safe action, and incident receipt. Use when a monitor alerts, a site appears down or blocked, crawler and human views differ, spam or compromise is suspected, a deploy regresses, or a website problem needs diagnosis and handoff without premature remediation.
Canonical owner: operations-web-function:triage-web-incidents · Task registration: TASK_LIBRARY_REGISTRATION_PENDING
Broader definitive hub · Exact Task Library page: TASK_LIBRARY_REGISTRATION_PENDING
Download the complete plugin · Source skill SHA-256: 4b76055db3f0784915361e465702d8ff9d0ad91181ed29a0ff563d8c5bad7ced
Candidate source: dennisyu/blitzmetrics-skills · commit: PENDING_MERGE · path: skills/triage-web-incidents/SKILL.md
Triage determines what is known, what remains unknown, how urgent the finding is, who owns the next action, and whether changing the system would destroy evidence.
BLOCKED and UNREACHABLE require investigation; they are not infection verdicts.$preserve-web-incident before any repair.Use SUSPECT for one hostile-looking signal, two symptoms derived from the same response, or a finding not yet reproduced with passing controls. Use INFECTED only when controls pass and either:
A casino title and casino words in the same Googlebot response are one signal family, not two. Classification can be upgraded or downgraded as evidence changes; preserve the earlier receipt.
Every incident declares whether a stability window is required, its duration, required automatic checks, and completed checks. The organization sets these values by incident class; do not invent them at runtime. A recurrence-prone compromise cannot move to RESOLVED before the declared window passes.
Communications are separate approved jobs. A resolution claim requires a linked verification receipt; otherwise state what is confirmed, what remains unknown, the owner, and the next update time.
SUSPECT or UNKNOWN; do not inflate certainty.Every open incident has: stable ID; target; exact evidence; observed and reproduced times; current lifecycle; owner and backup; due time; permission required; preservation status; next action; next automatic check; communication state; stability window; prior-attempt state; and closure criteria. From the plugin root, use schemas/incident.schema.json.
Do not accept “working on it,” “agent running,” or “will update” as a handoff. Use $verify-web-outcome before resolution and $document-web-lessons after it.
This is a generated candidate implementation page, not automatically a definitive article or accepted Task Library task. It delegates to the named canonical owner until reviewed registration and merge receipts exist.