systing-analyze

systing-analyze is a skill for Claude Code from josefbacik/systing. It costs 100 tokens per session (4,208 once invoked), scanned A, original, MIT.

A set of instructions for examining systing trace databases, which are DuckDB files containing recorded system activity. It helps investigate CPU use, scheduling delays, memory, network behavior, and accelerator metrics.

In plain words
What is it for?
Use it to inspect a trace, find CPU hotspots, investigate blocked time, study memory or network behavior, and query details not covered by the standard analysis tools.
Why use it?
Raw trace data is difficult to interpret without knowing its tables and the right queries. This provides a structured way to discover and analyze the recorded activity.

Skill for Claude Code

Written for Claude Code: $ARGUMENTS substitution.

Good fit Use it to inspect a trace, find CPU hotspots, investigate blocked time, study memory or network behavior, and query details not covered by the standard analysis tools.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/josefbacik/systing/systing-analyze
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add josefbacik/systing --skill systing-analyze
Clone the repo
git clone --depth 1 https://github.com/josefbacik/systing

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for systing-analyze

README.md
[![agentmods](https://agentmods.dev/badge/skills/josefbacik/systing/systing-analyze/github.svg)](https://agentmods.dev/skills/josefbacik/systing/systing-analyze)
Your own site
<a href="https://agentmods.dev/skills/josefbacik/systing/systing-analyze"><img src="https://agentmods.dev/badge/skills/josefbacik/systing/systing-analyze/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for systing-analyze

Your own site · 80×15
<a href="https://agentmods.dev/skills/josefbacik/systing/systing-analyze"><img src="https://agentmods.dev/badge/skills/josefbacik/systing/systing-analyze.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 100 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,208 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00100 $0.04208
Opus 5 $0.00050 $0.02104
Sonnet 5 $0.00020 $0.00842
Haiku 4.5 $0.00010 $0.00421

Measured 10d ago against content hash 4f8a470d1d98, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

systing-analyze scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/systing-analyze/SKILL.md · 221 lines

How it starts

The opening of the file, as written. The whole thing — 221 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Analyzing systing traces

Systing stores traces in DuckDB. The systing-analyze MCP server exposes structured tools to query them. This skill tells you which tool to reach for and how the data is laid out.

  1. trace_info — Always start here. Pass the path to the .duckdb file. Returns trace IDs, time range, per-trace system/platform info (kernel, arch, hypervisor, cpufreq driver, sampling event/period), non-empty tables with row counts, and the top 25 processes by thread count. This also caches the DB so later calls can omit path.
  2. list_tables / describe_table — Discover schema for ad-hoc queries.
  3. High-level tools for common questions — see below.
  4. query — For anything the high-level tools don't cover, write SQL. Results cap at 10k rows (truncated: true when hit); use LIMIT/OFFSET for more. The DB is opened read-only.

Tool cheatsheet

Question Tool Notes
What's in this trace? trace_info First call; pass path
Where is CPU time going? flamegraph stack_type="cpu" (default); optionally pid/tid
Why is the process blocked / off-CPU? flamegraph stack_type="uninterruptible-sleep" (D) or "interruptible-sleep" (S), or "all-sleep"
Is the scheduler oversubscribed? Latency? sched_stats no filter = whole-trace ranking; pid = per-thread breakdown; tid = single thread with end-state distribution
Which CPUs are busy / idle? cpu_stats per-CPU utilization, idle%, IRQ/softIRQ time, runqueue depth p50/p90/p99
How does the scheduler behave overall? Compare two schedulers/hosts? sched_aggregate one summary per capture: wakeup latency (ran on previous CPU / migrated), preempt wait, slice length, switch + migration rates, migrate-event counts, time-weighted runqueue length, per-CPU load vectors (incl. placement) + imbalance metrics, log2 histograms, tail threads; percentiles within ~6%; per-CPU runqueue exact on traces with sched_migrate (meta.placement_exact), approximate before
What's the network doing? network_connections per-connection bytes, retransmit %
Interface-level network? network_interfaces per-interface, per-protocol breakdown
Both sides of a connection (multi-node)? network_socket_pairs matched socket pairs, within or across traces
Memory / allocations? query no dedicated tool — see memory schema below
What ran on the TPU? Duty cycle? HBM? query no dedicated tool — see TPU schema below
Anything else query raw SQL; see schema below

Read the full file on GitHub · 221 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 221 lines · 100 tokens per session scan A 4f8a470d1d98

Subscribe to this mod's changes

systing-analyze is a skill published in the GitHub repository josefbacik/systing (176 stars, last pushed yesterday), licensed MIT. It adds 100 tokens to every session and 4,208 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

debug-optimize-lcp

Guides debugging and optimizing Largest Contentful Paint (LCP) using Chrome DevTools MCP tools. Use this skill whenever the user asks about LCP performance, slow page loads, Core Web Vitals optimization, or wants to understand why their page's main content takes too long to appear. Also use when the user mentions…

ChromeDevTools/chrome-devtools-mcp · 99 tokens

systematic-debugging

Use when debugging a failing test, build error, or runtime issue that isn't immediately obvious. Guides a 4-phase root cause analysis instead of random fix attempts.

open-metadata/OpenMetadata · 37 tokens

diagnose

Trace from a reproduced symptom to the source code that causes it. Pin the specific file and approximate line, rate confidence in the cause and clarity of the fix independently, and always propose a concrete fix.

emdash-cms/emdash · 43 tokens

repro-admin

Reproduce an EmDash admin UI bug. Attach a container, start the demo dev server, drive the admin with agent-browser using the dev-bypass session, and capture the reproduction as screenshots plus a replayable transcript.

emdash-cms/emdash · 48 tokens

log-error-digest

Analyze log files to troubleshoot errors, identify peak error periods, and produce error clustering, frequency statistics, and time distribution reports. Supports JSON, syslog, and Nginx formats with automatic detection. Use when a user uploads a .log file and asks to analyze errors, find patterns, debug issues, or…

zebbern/claude-code-guide · 71 tokens

byted-util-volcengine-detect-retry

An orchestration workflow for Volcengine Cloud Detect, a service that checks websites or network endpoints from test locations.

bytedance/agentkit-samples · 101 tokens