Free
$0
- Web timeline viewer with forensic digest
- Markdown, HTML, JSON, and CSV export
- Critical summary MD for ticket paste
- Basic CLI (
render,validate)
Agent session forensics
When a Cursor or Claude Code session goes wrong, IncidentScribe parses the JSONL export into a forensic timeline — surfacing destructive commands like DROP DATABASE and force pushes with evidence you can paste into tickets, postmortems, and stakeholder updates.
30-day satisfaction guarantee · Instant ZIP download after checkout — no account required for the pack · Use the filled sample in your next incident tonight
After an agent deletes a database or force-pushes main, your team is left scrolling raw JSONL exports or chat logs — hunting for the destructive command among thousands of lines. Manual grep is slow, error-prone, and hard to share with stakeholders who need a clear sequence of facts, not raw JSON.
Raw JSONL grep finds strings; IncidentScribe produces a structured audit trail with critical highlighting and export formats your team can share.
| Capability | Manual grep | Forensic export |
|---|---|---|
| Speed | Hours scrolling chat logs and piping JSONL through ad-hoc scripts | Drop a file — timeline, digest, and critical events in seconds |
| Critical highlighting | Regex misses context; destructive commands buried in noise | Destructive patterns flagged automatically (DROP, force push, recursive delete) |
| Export formats | Copy-paste fragments; no consistent structure for stakeholders | MD, HTML, JSON, CSV, and critical-summary MD from CLI or browser |
IncidentScribe uses tolerant JSONL parsing for each export shape — malformed lines produce warnings instead of aborting the run.
| Agent / source | What we parse |
|---|---|
| Cursor | Native JSONL export; shell, apply_patch, write, and StrReplace tool shapes mapped to file edits with paths in summaries. |
| Claude Code | Claude Code session export lines normalized to shell, file edit, and message events. |
| OpenCode | OpenCode export format with tool and terminal activity preserved in the timeline. |
| Codex / Agents SDK | Codex and OpenAI Agents SDK JSONL — shell commands and file edits from agent tool invocations. |
| MCP tool calls | MCP server invocations surfaced as tool_call events with server and tool names in summaries. |
| Windsurf | Cascade transcript JSONL and hook events — shell commands, code_action file edits, and planner messages from agent sessions. |
| GitHub Copilot Chat | Copilot CLI and agent-mode events.jsonl — tool executions, terminal commands, and user/assistant messages. |
| Generic JSONL | Any JSONL with recognizable type or kind fields; unknown lines are skipped with warnings. |
Download or render from the browser or CLI (incidentscribe render --format) without uploading session data to a server.
| Format | Tier | Best for |
|---|---|---|
| Markdown | Free | Ticket paste, docs, and blameless postmortem drafts |
| HTML | Free | Shareable read-only timeline in email or wikis |
| JSON | Free | Programmatic replay and custom integrations |
| CSV | Free | Spreadsheets and SIEM correlation |
| Critical summary MD | Free | Critical-only excerpt for incident channels |
| Slack Block Kit | Free | Post critical events to Slack via incoming webhook or workflow |
| incident.io JSON | Free | Import timeline events into incident.io with severity flags |
| Team | Print-ready forensic report with git commit correlation |
Team exports (PDF and git correlation) require the Shopify subscription — see the Team pricing card below.
This read-only preview is built from the committed cursor-sample.jsonl fixture — including a critical DROP DATABASE event.
Drop a JSONL file, paste below, or try the sample timeline
Raw critical event: DROP DATABASE production;
Rendered (timeline row + filled section):
| +13168920s | ... | shell | DROP DATABASE production; | critical |
## Impact
Production database outage observed after agent session. Service unavailable following the critical shell commands in the timeline.
## Root Cause
Agent executed `DROP DATABASE production;` followed by `rm -rf /tmp/build-cache`. The session message requested investigation of the outage; `read_file` and follow-up message located the issue in the deploy script.DROP DATABASE, force pushes, and recursive deletes are flagged in the timeline and exported reports.incidentscribe render) without uploading session data to a server.$0
render, validate)$12 one-time
Complete stakeholder postmortems from your timelines
Produce a complete blameless postmortem with timeline evidence you can paste into tickets and stakeholder updates in minutes.
Free surfaces the facts. Pack finishes the report in minutes.
| +13168920s | ... | shell | DROP DATABASE production; | critical |
## Root Cause
Agent executed `DROP DATABASE production;` followed by `rm -rf /tmp/build-cache`.Secure Stripe checkout via Hermes Plant · Instant download · Use immediately
30-day satisfaction guarantee · Instant ZIP download after checkout — no account required for the pack · Use the filled sample in your next incident tonight
After checkout — your next 5 minutes:
$12/mo
Shopify subscription — ongoing archive + webhooks