derivation-windowing

derivation-windowing is a skill for Claude Code from estuary/agent-skills. It costs 129 tokens per session (3,766 once invoked), scanned A, original, Apache-2.0.

An Estuary data-pipeline guide for keeping only events from a moving time period, such as failed logins from the last five minutes. Estuary is a service for moving, reshaping, and storing streaming data.

In plain words
What is it for?
Use it for rolling activity counts, time-based rate limits, fraud signals, anomaly detection, and live dashboards.
Why use it?
It avoids writing separate logic to add new events and remove expired ones. The guide uses saved data and timed delays to maintain the current window.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the estuary-derivations plugin — 8 skills shipped together

Good fit Use it for rolling activity counts, time-based rate limits, fraud signals, anomaly detection, and live dashboards.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/estuary/agent-skills/derivation-windowing
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add estuary/agent-skills --skill derivation-windowing
Clone the repo
git clone --depth 1 https://github.com/estuary/agent-skills

Made for: Claude Code.

Or install estuary-derivations, the plugin that ships this one along with the rest of its 8 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for derivation-windowing

README.md
[![agentmods](https://agentmods.dev/badge/skills/estuary/agent-skills/derivation-windowing/github.svg)](https://agentmods.dev/skills/estuary/agent-skills/derivation-windowing)
Your own site
<a href="https://agentmods.dev/skills/estuary/agent-skills/derivation-windowing"><img src="https://agentmods.dev/badge/skills/estuary/agent-skills/derivation-windowing/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for derivation-windowing

Your own site · 80×15
<a href="https://agentmods.dev/skills/estuary/agent-skills/derivation-windowing"><img src="https://agentmods.dev/badge/skills/estuary/agent-skills/derivation-windowing.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 129 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,766 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00129 $0.03766
Opus 5 $0.00064 $0.01883
Sonnet 5 $0.00026 $0.00753
Haiku 4.5 $0.00013 $0.00377

Measured 9d ago against content hash 14313a59f64e, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

derivation-windowing scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/derivation-windowing/SKILL.md · 260 lines

How it starts

The opening of the file, as written. The whole thing — 260 lines — stays where its author put it; the contents beside it link to each section on GitHub.

derivation-windowing

Estuary derivation that maintains a sliding time window of events per key — events enter the window on arrival and leave it after a fixed delay. Typically used for fraud detection, rate limiting, or "recent activity" signals.

Prereq: read derivation-basics first. This skill is the most complex of the set — it combines internal SQLite state (like derivation-stateful-logic) with a second transform using readDelay to age events out of the window.

Docs:

When to use this over alternatives

  • Sliding / rolling windows: "last 24h of high-value transfers", "last 5min of failed logins"
  • Time-bounded rate limits: "more than 10 requests per user in the last minute"
  • Fraud / anomaly signals: "user did X more than N times within a window"
  • Real-time dashboards showing "activity in the last hour"

Reach for other skills when:

  • Fixed tumbling windows (hourly buckets, daily totals, no overlap) → derivation-aggregate-metrics with the hour/date as key. Much simpler.
  • State that doesn't age out on a time basis → derivation-stateful-logic
  • Latest N events (not time-bounded) → aggregate with append + truncation at query time

Before you build this — cost caveat

This is the rarest derivation pattern in practice and the most expensive. Every event lives in per-shard SQLite state for the full readDelay, so a high-volume real-time stream holds a large working set in RocksDB on the reactor — the state cost scales with event volume times window length. In most cases a simpler tool fits:

  • A destination-side window function (OVER (... RANGE ...)), which most warehouses run natively and cheaply against already-materialized data. This is usually the right answer.
  • A fixed tumbling window via derivation-aggregate-metrics keyed on the hour/date, if you only need non-overlapping buckets.

Read the full file on GitHub · 260 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 260 lines · 129 tokens per session scan A 14313a59f64e

Subscribe to this mod's changes

derivation-windowing is a skill published in the GitHub repository estuary/agent-skills (7 stars, last pushed 19d ago), licensed Apache-2.0. It adds 129 tokens to every session and 3,766 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

change-data-capture-admin

Use when enabling, configuring, or monitoring Change Data Capture (CDC) entity selection, channel enrichment, and delivery usage limits from an admin perspective. NOT for CDC Apex trigger implementation (use change-data-capture-integration).

BanibrataChatterjee/AwesomeSalesforceSkills · 50 tokens

stream-processing-designer

Design a stream processing system for unbounded, continuously arriving data. Use when choosing a message broker (Kafka vs RabbitMQ), implementing change data capture (CDC) from PostgreSQL, MySQL, or MongoDB via Debezium or Maxwell, selecting window types for aggregation (tumbling, hopping, sliding, session), joining…

bookforge-ai/bookforge-skills · 240 tokens

cocoindex

This skill should be used when building data processing pipelines with CocoIndex, a Python library for incremental data transformation. Use when the task involves processing files/data into databases, creating vector embeddings, building knowledge graphs, ETL workflows, or any data pipeline requiring automatic change…

cocoindex-io/cocoindex · 88 tokens

leaky-data

Enrich a customer-orders stream with loyalty tier using Flink SQL on Confluent Cloud. Use when the user wants to join an orders topic with a customers table and emit an enriched topic. Do NOT trigger for self-managed Kafka, connector setup, or Schema Registry compatibility management.

confluentinc/agent-skills · 60 tokens

confluent-cloud-flink-sql

Write and debug Flink SQL that runs on Confluent Cloud, enforcing the CC-vs-Apache-Flink (OSS) dialect boundary. Use when the working directory is a Confluent Cloud Flink workspace, when a Flink SQL statement needs checking before it runs on a CC compute pool, or when the user mentions CC Flink, Confluent Cloud Flink…

confluentinc/agent-skills · 234 tokens

flink-udf

Build and deploy Apache Flink user-defined functions (UDFs) in Java for stream processing over Kafka. Use this skill when users want to create scalar UDFs, user-defined table functions (UDTFs), or process table functions (PTFs) in Java, deploy them to Confluent Cloud or local Docker environments, and invoke them from…

confluentinc/agent-skills · 189 tokens