Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/splunk/splunk-agent-skills/splunk-searchnpx skills add splunk/splunk-agent-skills --skill splunk-searchgit clone --depth 1 https://github.com/splunk/splunk-agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/splunk/splunk-agent-skills/splunk-search)<a href="https://agentmods.dev/skills/splunk/splunk-agent-skills/splunk-search"><img src="https://agentmods.dev/badge/skills/splunk/splunk-agent-skills/splunk-search.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00044 | $0.01839 |
| Opus 5 | $0.00022 | $0.00920 |
| Sonnet 5 | $0.00009 | $0.00368 |
| Haiku 4.5 | $0.00004 | $0.00184 |
Grade A, and why
splunk-search scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 186 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Splunk Search
Use Splunk Search when a user needs read-only Splunk evidence but the result
set may be too large for the agent context. The splsearch CLI writes search
results to a local SQLite table and returns compact JSON with the table name.
Treat the saved table as the artifact, then bring only focused summaries,
small samples, or exact evidence back into the conversation.
Prerequisites
The splsearch CLI is installed and available on PATH, or the runtime
provides an equivalent splsearch binary for this skill. In this repository,
the packaged Go source for that CLI lives in tools/splsearch. From the
repository root, build the tool artifact with
make -C tools/splsearch build, then put tools/splsearch/bin on PATH
before using the skill locally.
The user has read-only access to the target Splunk Enterprise or Splunk Cloud Platform environment and can provide the target URL, time window, and search intent. Do not ask for passwords, cookies, tokens, or raw credential files.
When to Use
Use this skill for Splunk log investigation, production or staging incident
triage, saved result-table analysis, and requests that mention splsearch,
Splunk search, SPL execution, or querying saved Splunk results.
Do not use this skill for changing Splunk configuration, editing knowledge objects, deleting data, restarting services, creating alerts, modifying indexes, or handling secrets. If the user wants SPL authoring help without running a search or inspecting saved results, answer without invoking this skill.
Workflow Overview
- Identify the target Splunk URL, time window, impact scope, and strongest available filters.
- Check cached auth with
splsearch auth status --output=jsonwhen the target is unclear. - Validate a specific target with
splsearch auth status --url=<splunk-url> --output=jsonbefore deciding whether browser login is needed. - Run one bounded table-writing search with a useful time range and result table name.
- Keep the returned
tablename and use it for every follow-up command. - Review any saved warnings before continuing. If a broad fetch was intentional, record that by accepting the warning.
- Inspect schema or metadata before writing SQL against the saved table.
- Use text search, summary, ordered events, or bounded SQL to reduce the saved results locally.
- Bring only the compact answer set, evidence snippets, and command summary back into chat.
- Keep the result table while the incident or handoff is active, then drop it when evidence has been captured elsewhere.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 186 lines · 44 tokens per session scan A f4bfdb0cb759
splunk-search is a skill published in the GitHub repository splunk/splunk-agent-skills (28 stars, last pushed 15d ago), licensed Apache-2.0. It adds 44 tokens to every session and 1,839 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
schema-exploration
Lists tables, describes columns and data types, identifies foreign key relationships, and maps entity relationships in a database. Use when the user asks about database schema, table structure, column types, what tables exist, ERD, foreign keys, or how entities relate.
debugging
How to debug tursodb using Bytecode comparison, logging, ThreadSanitizer, deterministic simulation, and corruption analysis tools.
sdk-design
Doctrine for designing and evolving any SDK Grida ships — TypeScript, Rust, or otherwise. "SDK" here means a surface that crosses a foreign-or-foreign-treated boundary: published packages, separately-versioned consumers, FFI bindings, public-by-design modules. An SDK's job is to refuse; a strict, honest surface…
ha-data-stores
Map of Hope Agent's local data stores and safe read-only query workflow. Use when the user asks where Hope Agent stores data, wants to inspect sessions/messages/memory/logs/background jobs/knowledge indexes/settings, asks the model to query local app data, or debugging requires checking persisted state. Trigger…
supabase
Supabase / PostgREST Row-Level-Security playbook — pull the anon (or leaked servicerole) key out of the frontend JS, map tables from the auto-generated OpenAPI spec, test anonymous RLS READ disclosures (PII/secret leaks), and anonymous RLS WRITE abuse (insert/update/delete — e.g. forging…
nornicdb-cypher-queries
Pick fast, predictable Cypher query shapes in NornicDB — point lookups, batch retrieval, pagination, search, traversal, batched UNWIND/MERGE writes, cleanup, multi-tenant isolation. Use when writing or reviewing Cypher whose latency or throughput matters; maps user intent to the executor's hot-path query templates.