Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/davidmatousek/tachi/root-cause-analyzernpx skills add davidmatousek/tachi --skill root-cause-analyzergit clone --depth 1 https://github.com/davidmatousek/tachiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/davidmatousek/tachi/root-cause-analyzer)<a href="https://agentmods.dev/skills/davidmatousek/tachi/root-cause-analyzer"><img src="https://agentmods.dev/badge/skills/davidmatousek/tachi/root-cause-analyzer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00068 | $0.02776 |
| Opus 5 | $0.00034 | $0.01388 |
| Sonnet 5 | $0.00014 | $0.00555 |
| Haiku 4.5 | $0.00007 | $0.00278 |
Grade A, and why
root-cause-analyzer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- root-cause-analyzer — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 409 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Root Cause Analyzer Skill
Purpose
Systematically identifies root causes of complex problems using the 5 Whys methodology from docs/5-WHYS-METHODOLOGY.md. Documents findings in docs/development-learnings/ and updates Knowledge Base (docs/kb/) using make kb-pattern. Implements FR-009 from the feature specification.
Knowledge Base Integration
IMPORTANT: Before starting root cause analysis, check the Knowledge Base for existing patterns.
Pre-Analysis KB Check
from scripts.kb.search import kb_search, kb_get_pattern
# Search for similar issues
results = kb_search(
query="[error message or symptom]",
category="[ARCH/DB/API/TEST/etc]",
min_quality_score=60,
limit=5
)
if results:
print(f"Found {len(results)} existing patterns!")
# Review top pattern
pattern = kb_get_pattern(results[0].id)
if pattern:
# Apply existing solution instead of re-analyzing
print("Applying existing root cause analysis from KB")
else:
print("No existing patterns found. Proceeding with new 5 Whys analysis")
When to Check KB
- Before starting 5 Whys: Search for error messages, symptoms, or similar problems
- During analysis: Browse relevant categories (ARCH, DB, API, TEST, ERROR) for design patterns
- After finding root cause: Search again to see if this is a known systemic issue
- Before documenting: Check if similar pattern exists to avoid duplication
What to Search For
- Exact error messages: Copy error text into search query
- Symptom keywords: "timeout", "connection pool", "race condition", etc.
- Technology + problem: "postgresql connection pool exhausted"
- Pattern category: Use category filter to narrow results
If Pattern Found
- Review the existing pattern's 5 Whys analysis
- Check if root cause matches current issue
- Apply existing solution if applicable
- Update pattern usage count if applied
- Add cross-reference in your documentation
If No Pattern Found
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 409 lines · 68 tokens per session scan A b8614825c578
root-cause-analyzer is a skill published in the GitHub repository davidmatousek/tachi (90 stars, last pushed 24d ago), licensed Apache-2.0. It adds 68 tokens to every session and 2,776 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
anti-debug-bypass
Detect and neutralize anti-debug / anti-VM checks — IsDebuggerPresent, ptrace, NtGlobalFlag, timing, hardware-breakpoint detection.
malware-triage
Fast malware triage workflow — static (PE/Mach-O/ELF format, strings, imports, signatures, entropy/packed indicators), dynamic (sandbox with INetSim, Wireshark, Process Monitor, Procmon, time-shift), unpack (Scylla/PE-sieve), then full RE with Ghidra/IDA. Designed for ≤15 min initial verdict.
packer-unpacking
Identify and unpack common binary packers — UPX, ASPack, Themida, VMProtect, MPRESS, PECompact, Enigma.
ghidra
Deep binary analysis via Ghidra — headless analyzeHeadless or live MCP bridge with 245 tools. Decompilation, xrefs, function listing, batch operations, P-code emulation, convention enforcement.
triage
Fast-path binary triage — identify format/arch/mitigations, grab high-signal strings and imports in under a minute.
command-injection-exploitation
OS Command Injection — exploiting applications that pass user input to OS commands without sanitization. Covers injection operators (;, |, ||, &&, $(), backticks, newline), blind detection (time-based, OOB callback), and bypass techniques (space, keyword, encoding).