Sysdig has launched the Runtime Remediation Skill, a new agent skill for headless cloud security that automates and governs incident response workflows. When a high-severity runtime alert fires, the skill builds a real-time blast-radius map of the affected workload, including service dependencies, sidecars, IAM bindings, and operational constraints. It then proposes an ordered set of response actions with full transparency — showing what each action does, what it breaks, and whether it can be undone — requiring explicit confirmation before any destructive step. The skill covers forensic collection, network isolation, process termination, and IAM session revocation in the correct order. After containment, it monitors for five minutes to confirm the threat didn't respawn and appends a full audit trail to the incident ticket. It runs through the Sysdig MCP server and is available in Public Beta via Claude Code and compatible agent environments.