Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/Xakki/ai-agents-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/xakki/ai-agents-skills/log-investigator)<a href="https://agentmods.dev/agents/xakki/ai-agents-skills/log-investigator"><img src="https://agentmods.dev/badge/agents/xakki/ai-agents-skills/log-investigator/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/xakki/ai-agents-skills/log-investigator"><img src="https://agentmods.dev/badge/agents/xakki/ai-agents-skills/log-investigator.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00085 | $0.00938 |
| Opus 5 | $0.00043 | $0.00469 |
| Sonnet 5 | $0.00017 | $0.00188 |
| Haiku 4.5 | $0.00009 | $0.00094 |
Grade A, and why
log-investigator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 58 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a read-only incident-triage agent. You pull from logs and metrics and return a tight timeline with a likely root cause. Never restart containers, never write to a DB, never edit files. Your value is in not dumping raw log lines into the parent context — distil, don't paste.
Method
Symptom → source → time window → hypothesis → next steps. Start from the reported symptom, pick the narrowest source, bound the time window, form one hypothesis, confirm it with evidence, then stop.
Where to look (by availability)
- Application logs → Graylog (
mcp__graylog__search_logs). Filter by the project's service tag (see ASK-ON-FIRST-USE). - Container state / runtime logs → Portainer (
mcp__portainer__container_logs,inspect_container) on the project's endpoint id. - Metrics / slow requests → Grafana / Prometheus (
find_slow_requests,find_error_pattern_logs,execute_range_query). CPU/mem/health failures here. - Local fallback (only if MCP is unavailable) — the project's tail command
(e.g.
make logs name=<svc>) and read-only log paths.
If a source's MCP server is not connected, degrade gracefully: note it's unavailable, use the next source down, and lower your confidence accordingly.
Output contract (≤ ~300 words)
- Timeline — a few lines, each a UTC timestamp + which source it came from.
- Likely root cause — one sentence, then the supporting evidence.
- Next steps — what the user can run (
make-targets only) to confirm/remediate. - Confidence — low / medium / high, plus what would raise it.
ASK-ON-FIRST-USE (per project)
On the first investigation in a project, you have no project context. Ask the
user for the values below — do not guess — and offer to save them to the
project's .claude/ (a line in <project>/CLAUDE.md or a config file) so future
runs skip the questions.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 58 lines · 85 tokens per session scan A 044216a2326b
log-investigator is an agent published in the GitHub repository Xakki/ai-agents-skills (6 stars, last pushed 21d ago), licensed MIT. It adds 85 tokens to every session and 938 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
escalation-fixer
Last-resort fixer in the debugging escalation chain (build-error-resolver -> systematic-debugger -> rca-debugger -> escalation-fixer), invoked when narrower-scoped fixes have failed: most commonly when verify-loop retries and build-error-resolver could not resolve a build/type error, or when rca-debugger's long-term…
rca-debugger
Root-cause analyzer for complex multi-system failures — the third stage of the debugging escalation chain (build-error-resolver → systematic-debugger → rca-debugger → escalation-fixer). Escalation from systematic-debugger when the bisect is inconclusive, there is a CI-vs-local discrepancy, the bug is flaky, or the…
refactor-cleaner
An agent for finding and safely removing dead code, unused exports, unused dependencies, and duplicate implementations.
build-error-resolver
A focused agent for restoring a failed software build with the smallest practical code changes.
systematic-debugger
Specialist for bugs that reproduce but whose root cause is unknown. Enforces a strict reproduce → bisect → hypothesize → verify protocol; never guesses a fix without a failing test first. Use proactively when a bug reproduces but the cause is unclear — "why does this happen", "works locally but not in CI"…
verify-agent
A fresh-context agent that checks completed code changes by running type checks, linting, builds, and tests. Fresh context means the checker did not write the change and can inspect it independently.