Claude Skill

log-analysis

Use this skill when you need to analyze logs into evidence, timelines, anomalies, and follow-up hypotheses; triggers include log analysis.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download naodeng-awesome-qa-skills-skills_en_testing-types_log-analysis-c44b892.zip · 5 KB
Part of naodeng/awesome-qa-skills — 97 skills

Install

skills CLI npx skills add https://github.com/naodeng/awesome-qa-skills/tree/main/skills/en/testing-types/log-analysis
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install naodeng-awesome-qa-skills@llmmart
Git git clone https://github.com/naodeng/awesome-qa-skills.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole naodeng/awesome-qa-skills collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Log Analysis

When to Use

  • Use this skill when you need to reconstruct events from structured and unstructured logs, detect anomalies, and form testable causal hypotheses.
  • Use it to review an existing plan, result, or evidence set and produce actionable improvements.
  • Use it when context is incomplete but a bounded first pass is still valuable.

Output Format Options

  • Default to Markdown for review, execution, and incremental refinement.
  • When the user requests tables, CSV, JSON, or ticket fields, preserve risk, evidence, priority, and boundary information.
  • For machine-consumed output, confirm the schema, enums, and required fields first.

How to Use

  1. Read and follow prompts/log-analysis.md, including its input contract, execution rules, minimum coverage, and output order.
  2. Add only context that changes the decision: scope, environment, version, constraints, evidence, and success criteria.
  3. Audit the input, then separate confirmed facts, working assumptions, and open questions.
  4. Rank by risk and evidence strength, and produce an artifact that can be executed or reviewed directly.
  5. If information is missing, deliver a bounded first pass and state which conclusions remain unsupported.

Reference Files

  • Always read prompts/log-analysis.md; it is the complete execution specification for this skill.
  • For evaluation or regression, read evals/eval.yaml and the relevant cases under evals/cases/.
  • Load references/, examples/, scripts/, or output-formats.md only when those directories exist and the task needs them.

Core Constraints

  • do not treat a log line as root cause
  • redact sensitive data
  • state timezone, sampling, and missing-log limitations
  • Never invent system behavior, fields, data, metrics, or root causes absent from the evidence.
  • Link important conclusions to evidence; mark unsupported conclusions as hypotheses with a verification method.
  • Explain priority using business impact, likelihood, or detectability.

Delivery Checklist

  • Covered: timeline, error clustering, context correlation, frequency shifts, sensitive data, logging gaps, cross-service consistency, change correlation.
  • Separated facts, assumptions, gaps, and recommendations.
  • Gave high-risk items a priority, evidence basis, owner or next action.
  • Defined verifiable decision criteria instead of generic advice.
  • Performed no unauthorized production writes or destructive actions.

Common Pitfalls

  • Listing checks without preconditions, expected outcomes, or evidence.
  • Marking everything high priority and avoiding tradeoffs.
  • Substituting tool names or generic theory for domain reasoning.
  • Refusing incomplete input, or pretending incomplete evidence supports certainty.

Best Practices

  • Start with paths most likely to cause business loss, safety issues, or release blockage.
  • Reduce uncertainty through the smallest verifiable experiment and record reproduction conditions.
  • Make the artifact executable and independently reviewable by another engineer.
Files (awesome-qa-skills)
  • agents
    • openai.yaml 265 B
      version: 1
      metadata:
        key: log-analysis
      interface:
        display_name: "Log Analysis"
        short_description: "Extract timelines, anomalies, and evidence from logs"
        default_prompt: "Use the log-analysis skill to analyze logs."
      policy:
        allow_implicit_invocation: true
      
  • evals
    • cases
      • basic-success.yaml 845 B
        id: basic-success
        title: "Log Analysis: domain-complete scenario"
        description: |
          Checks that the skill produces domain-specific, evidence-based, prioritized, executable output.
        
        input:
          prompt: |
            Use the log-analysis skill for this scenario: payment failures rise after release, with partial gateway and payment-service logs and a deployment timeline. The basic scope is available. Provide risk priorities, core execution items, expected results or decision criteria, evidence, and open questions.
        
        expect:
          must_contain:
            - "Task Understanding"
            - "Input Audit"
            - "Risks"
            - "P0"
            - "expected"
          must_not_contain:
            - "TODO"
            - "I cannot"
            - "unable to help"
        
        judge:
          type: rule_based
          success:
            - output_contains:
                all:
                  - "Task Understanding"
                  - "Input Audit"
                  - "Risks"
        
      • edge-incomplete-input.yaml 886 B
        id: edge-incomplete-input
        title: "Log Analysis: bounded first pass with incomplete input"
        description: |
          Checks that missing context leads to a bounded first pass with assumptions and gaps, not refusal or invention.
        
        input:
          prompt: |
            Use the log-analysis skill. The only known fact is: payment failures rise after release, with partial gateway and payment-service logs and a deployment timeline. No environment, version, or supporting evidence is available. Deliver a useful first pass and state which conclusions are unsupported.
        
        expect:
          must_contain:
            - "Working Assumptions"
            - "Open Questions"
            - "evidence"
            - "Next Actions"
          must_not_contain:
            - "TODO"
            - "I cannot"
            - "unable to help"
        
        judge:
          type: rule_based
          success:
            - output_contains:
                all:
                  - "Working Assumptions"
                  - "Open Questions"
                  - "evidence"
        
      • edge-risk-priority.yaml 845 B
        id: edge-risk-priority
        title: "Log Analysis: high-risk boundary and tradeoffs"
        description: |
          Checks that a constrained window produces risk focus plus stop, escalation, or human-handoff boundaries.
        
        input:
          prompt: |
            Use the log-analysis skill for: payment failures rise after release, with partial gateway and payment-service logs and a deployment timeline. The execution window is half a day and no destructive production action is authorized. Bound the scope, prioritize P0/P1, and state residual risk plus stop or escalation conditions.
        
        expect:
          must_contain:
            - "P0"
            - "P1"
            - "Residual Risk"
            - "condition"
          must_not_contain:
            - "TODO"
            - "I cannot"
            - "unable to help"
        
        judge:
          type: rule_based
          success:
            - output_contains:
                all:
                  - "P0"
                  - "P1"
                  - "Residual Risk"
        
    • eval.yaml 557 B
      schema_version: v1alpha1
      
      environment:
        type: none
      
      skills:
        - source: local_path
          path: .
      
      engine:
        name: claude_code
        # model is optional; omit to use engine default
        # model:
        #   provider: anthropic
        #   name: claude-sonnet-4-6
      
      cases:
        files:
          - evals/cases/basic-success.yaml
          - evals/cases/edge-incomplete-input.yaml
          - evals/cases/edge-risk-priority.yaml
        defaults:
          timeout_seconds: 180
          max_turns: 8
          expect:
            exit_code: 0
            must_not_contain:
              - "TODO"
              - "I cannot"
      
      report:
        formats: [json]
      
  • prompts
    • log-analysis.md 3.3 KB
      # Log Analysis Prompt
      
      Reconstruct events from structured and unstructured logs, detect anomalies, and form testable causal hypotheses and produce an artifact that can be executed, reviewed, and tracked directly.
      
      ## Role
      
      You are a senior risk- and evidence-driven QA practitioner who controls conclusion boundaries when context is incomplete.
      
      ## Input
      
      Prefer real materials supplied by the user:
      
      - log samples
      - time range
      - services and environment
      - request identifiers
      - deployment and alert timeline
      - scope, environment, version, time budget, toolchain, and prohibited actions
      - existing results, historical failures, monitoring evidence, and stakeholder concerns
      
      If critical input is absent, list `Working Assumptions` and `Open Questions`, then still deliver a bounded first pass.
      
      ## What to do
      
      1. Restate the objective, subject, and success criteria in one sentence.
      2. Audit input completeness, credibility, recency, and comparability.
      3. Build a risk or failure model and prioritize high-impact, likely, or hard-to-detect issues.
      4. Convert analysis into concrete scenarios, assertions, verification steps, or decision gates.
      5. Report residual risk, evidence gaps, and next actions without presenting hypotheses as facts.
      
      ## Execution Rules
      
      - do not treat a log line as root cause
      - redact sensitive data
      - state timezone, sampling, and missing-log limitations
      - Give an evidence basis for every important conclusion; label unsupported claims as `Hypothesis to Verify`.
      - Each scenario must include preconditions, action or stimulus, expected behavior, and required evidence.
      - Use P0/P1/P2/P3 or an equivalent scale and explain the ranking.
      - Reuse the current toolchain and assets; avoid large code samples unless the user requests them.
      - For production, security, or privacy work, default to least privilege, masked data, mocks, dry runs, or isolated environments.
      
      ## Minimum Coverage Checklist
      
      Unless the user narrows the scope, cover at least:
      
      - timeline
      - error clustering
      - context correlation
      - frequency shifts
      - sensitive data
      - logging gaps
      - cross-service consistency
      - change correlation
      - confirmed facts, working assumptions, and open questions
      - blockers for execution, release, or decision making
      - residual risk and how it will be accepted, mitigated, or investigated
      
      ## Output
      
      Use this order:
      
      ### 1. Task Understanding and Scope
      - objective, subject, success criteria, inclusions, and exclusions
      
      ### 2. Input Audit
      - confirmed facts, working assumptions, open questions, and evidence quality
      
      ### 3. Risks and Priorities
      - P0/P1/P2/P3, impact, rationale, and sequence
      
      ### 4. Core Analysis and Execution Items
      - event summary
      - anomaly patterns
      - evidence excerpts
      - candidate causes
      - verification queries
      - observability improvements
      - include preconditions, steps, expected result or decision criterion, and evidence for each item
      
      ### 5. Blockers and Residual Risk
      - stop, escalation, rollback, or human-handoff conditions
      
      ### 6. Next Actions and Open Questions
      - smallest verification actions, suggested owners, and missing materials
      
      ## Quality Bar
      
      - Tailor the content to the input; do not merely rename a generic template.
      - Make high-risk paths concrete with failure modes, expected behavior, and evidence.
      - Never invent numbers, root causes, or system behavior.
      - Let an executor act without guessing and a reviewer trace every important judgment.
      
  • SKILL.md 3.2 KB
    ---
    name: log-analysis
    description: Use this skill when you need to analyze logs into evidence, timelines, anomalies, and follow-up hypotheses; triggers include log analysis.
    ---
    
    # Log Analysis
    
    ## When to Use
    
    - Use this skill when you need to reconstruct events from structured and unstructured logs, detect anomalies, and form testable causal hypotheses.
    - Use it to review an existing plan, result, or evidence set and produce actionable improvements.
    - Use it when context is incomplete but a bounded first pass is still valuable.
    
    ## Output Format Options
    
    - Default to Markdown for review, execution, and incremental refinement.
    - When the user requests tables, CSV, JSON, or ticket fields, preserve risk, evidence, priority, and boundary information.
    - For machine-consumed output, confirm the schema, enums, and required fields first.
    
    ## How to Use
    
    1. Read and follow `prompts/log-analysis.md`, including its input contract, execution rules, minimum coverage, and output order.
    2. Add only context that changes the decision: scope, environment, version, constraints, evidence, and success criteria.
    3. Audit the input, then separate confirmed facts, working assumptions, and open questions.
    4. Rank by risk and evidence strength, and produce an artifact that can be executed or reviewed directly.
    5. If information is missing, deliver a bounded first pass and state which conclusions remain unsupported.
    
    ## Reference Files
    
    - Always read `prompts/log-analysis.md`; it is the complete execution specification for this skill.
    - For evaluation or regression, read `evals/eval.yaml` and the relevant cases under `evals/cases/`.
    - Load `references/`, `examples/`, `scripts/`, or `output-formats.md` only when those directories exist and the task needs them.
    
    ## Core Constraints
    
    - do not treat a log line as root cause
    - redact sensitive data
    - state timezone, sampling, and missing-log limitations
    - Never invent system behavior, fields, data, metrics, or root causes absent from the evidence.
    - Link important conclusions to evidence; mark unsupported conclusions as hypotheses with a verification method.
    - Explain priority using business impact, likelihood, or detectability.
    
    ## Delivery Checklist
    
    - [ ] Covered: timeline, error clustering, context correlation, frequency shifts, sensitive data, logging gaps, cross-service consistency, change correlation.
    - [ ] Separated facts, assumptions, gaps, and recommendations.
    - [ ] Gave high-risk items a priority, evidence basis, owner or next action.
    - [ ] Defined verifiable decision criteria instead of generic advice.
    - [ ] Performed no unauthorized production writes or destructive actions.
    
    ## Common Pitfalls
    
    - Listing checks without preconditions, expected outcomes, or evidence.
    - Marking everything high priority and avoiding tradeoffs.
    - Substituting tool names or generic theory for domain reasoning.
    - Refusing incomplete input, or pretending incomplete evidence supports certainty.
    
    ## Best Practices
    
    - Start with paths most likely to cause business loss, safety issues, or release blockage.
    - Reduce uncertainty through the smallest verifiable experiment and record reproduction conditions.
    - Make the artifact executable and independently reviewable by another engineer.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related