Security incident response for agent environments: a staged flow of classification, containment, evidence collection, recovery, and postmortem — covering secret leaks, prompt-injection triggers, dependency poisoning, and unauthorized actions, with command evidence for every step. Use when a DSH/agent environment shows a suspected security incident needing response and postmortem; not for day-to-day development or routine maintenance.