Agent skill

Analyze Logs

by activepieces in activepieces/activepieces

Analyze application logs from the .evlog/logs/ directory. An agent skill from activepieces/activepieces.

MITAuto-check passedDevelopment

Install Analyze Logs

skills CLI
$ npx skills add activepieces/activepieces --skill analyze-logs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install activepieces/activepieces analyze-logs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/activepieces/activepieces.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/analyze-logs .claude/skills/analyze-logs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyze-logs
GitHub stars
25k
Used in
1 other repo
Token cost
~1.6k tokens
SKILL.md length
626 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Analyze application logs from the .evlog/logs/ directory. An agent skill from activepieces/activepieces.

  • Works in 3 steps: Read the most recent log file → Identify the relevant events → Analyze and explain
  • Debugging errors
  • SKILL.md covers When to Use, Finding the logs, If no logs are found and Log format, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Analyze Logs is an agent skill from activepieces/activepieces. Analyze application logs from the .evlog/logs/ directory. Use when debugging errors, investigating slow requests, understanding request patterns, or answering questions about application behavior. Reads structured NDJSON wide events written by evlog's file system drain.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering MCP servers and Workflow automation. It works with Model Context Protocol. The repository describes itself as: AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents. The licence is MIT.

When your agent uses it

  • Debugging errors
  • Investigating slow requests
  • Understanding request patterns
  • Answering questions about application behavior

Example prompts

  • “/analyze-logs”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Read the most recent log file
  2. Identify the relevant events
  3. Analyze and explain

What it can do on your machine

Read from SKILL.md and the folder at commit 8656fb8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analyze Logs loads about 1.6k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 626 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from activepieces/activepieces at commit 8656fb8, republished under its MIT licence (© activepieces). 626 words, ~1,617 tokens.

Download SKILL.mdSave it as .claude/skills/analyze-logs/SKILL.md (or your agent's skills folder).
name
analyze-logs
description
Analyze application logs from the .evlog/logs/ directory. Use when debugging errors, investigating slow requests, understanding request patterns, or answering questions about application behavior. Reads structured NDJSON wide events written by evlog's file system drain.
license
MIT
metadata.author
HugoRCD
metadata.version
0.1

Analyze application logs

Read and analyze structured wide-event logs from the local .evlog/logs/ directory to debug errors, investigate performance issues, and understand application behavior.

When to Use

  • User asks to debug an error, investigate a bug, or understand why something failed
  • User asks about request patterns, slow endpoints, or error rates
  • User asks "what happened" or "what's going on" with their application
  • User asks to analyze logs, check recent errors, or review application behavior
  • User mentions a specific error message or status code they're seeing

Finding the logs

Logs are written by evlog's file system drain as .jsonl files, organized by date.

Format detection: The drain supports two modes:

  • NDJSON (default, pretty: false): One compact JSON object per line. Parse line-by-line.
  • Pretty (pretty: true): Multi-line indented JSON per event. Parse by reading the entire file and splitting on top-level objects (e.g. JSON.parse('[' + content.replace(/\}\n\{/g, '},{') + ']')) or use a streaming JSON parser.

Always check the first few bytes of the file to detect the format: if the second character is a newline or ", it's NDJSON; if it's a space or newline followed by spaces, it's pretty-printed.

Search order — check these locations relative to the project root:

  1. .evlog/logs/ (default)
  2. Any .evlog/logs/ inside app directories (monorepos: apps/*/.evlog/logs/)

Use glob to find log files:

.evlog/logs/*.jsonl
*/.evlog/logs/*.jsonl
apps/*/.evlog/logs/*.jsonl

Files are named by date: 2026-03-14.jsonl. Start with the most recent file.

If no logs are found

The file system drain may not be enabled. Guide the user to set it up:

typescript
import { createFsDrain } from 'evlog/fs'

// Nuxt / Nitro: server/plugins/evlog-drain.ts
export default defineNitroPlugin((nitroApp) => {
  nitroApp.hooks.hook('evlog:drain', createFsDrain())
})

// Hono / Express / Elysia: pass in middleware options
app.use(evlog({ drain: createFsDrain() }))

// Fastify: pass in plugin options
await app.register(evlog, { drain: createFsDrain() })

// NestJS: pass in module options
EvlogModule.forRoot({ drain: createFsDrain() })

// Standalone: pass to initLogger
initLogger({ drain: createFsDrain() })

After setup, the user needs to trigger some requests to generate logs, then re-analyze.

Log format

Each line is a self-contained JSON object (wide event). Key fields:

FieldTypeDescription
timestampstringISO 8601 timestamp
levelstringinfo, warn, error, debug
servicestringService name
environmentstringdevelopment, production, etc.
methodstringHTTP method (GET, POST, etc.)
pathstringRequest path (/api/checkout)
statusnumberHTTP response status code
durationstringRequest duration ("234ms")
requestIdstringUnique request identifier
errorobjectError details: name, message, stack, statusCode, data
error.data.whystringHuman-readable explanation of what went wrong
error.data.fixstringSuggested fix for the error
sourcestringclient for browser logs, absent for server logs
userAgentobjectParsed browser/OS/device info

All other fields are application-specific context added via log.set() (e.g. user, cart, payment).

How to analyze

Show full SKILL.md (251 more words)Show less
Step 1: Read the most recent log file

Read the latest .jsonl file. Each line is one JSON event. Parse each line independently.

Step 2: Identify the relevant events

Filter based on the user's question:

  • Errors: look for "level":"error" or status >= 400
  • Specific endpoint: match on path
  • Slow requests: parse duration (e.g. "706ms") and filter high values
  • Specific user/action: match on application-specific fields
  • Client-side issues: filter by "source":"client"
  • Time range: compare timestamp values
Step 3: Analyze and explain

For each relevant event:

  1. What happened: summarize the path, method, status, level
  2. Why it failed (errors): read error.message, error.data.why, and the stack trace
  3. How to fix: check error.data.fix for suggested remediation
  4. Context: examine application-specific fields for business context (user info, payment details, etc.)
  5. Patterns: look for recurring errors, degrading performance, or correlated failures

Analysis patterns

Find all errors
Filter: level === "error"
Group by: error.message or path
Look for: recurring patterns, common failure modes
Find slow requests
Filter: parse duration string, compare > threshold (e.g. 1000ms)
Sort by: duration descending
Look for: specific endpoints, time-of-day patterns
Trace a specific request
Filter: requestId === "the-request-id"
Result: single wide event with all context for that request
Error rate by endpoint
Group events by: path
Count: total events vs error events per path
Look for: endpoints with high error ratios
Client vs server errors
Split by: source === "client" vs no source field
Compare: error patterns between client and server
Look for: client errors that don't have corresponding server errors (network issues)

Important notes

  • Each line is a complete, self-contained event. Unlike traditional logs, you don't need to correlate multiple lines — one line has all the context for one request.
  • The error.data.why and error.data.fix fields are evlog-specific structured error fields. When present, they provide the most actionable information.
  • Duration values are strings with units (e.g. "706ms"). Parse the numeric part for comparisons.
  • Events with "source":"client" originated from browser-side logging and were sent to the server via the transport endpoint.
  • Log files are .gitignore'd automatically — they exist only on the local machine or server where the app runs.

© activepieces, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/analyze-logs of activepieces/activepieces.

Open the folder on GitHubat commit 8656fb8

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in activepieces/activepieces, which our catalogue first saw on October 8, 2026.

Compare with similar skills

Analyze Logs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyze Logs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyze Logs this skillactivepieces/activepieces25k1 repos~1.6kAutomated safety check: PassMIT
CC Workflow Studio AI Editorbreaking-brake/cc-wf-studio5.4k—~561Automated safety check: PassCustom licence
ObservalObserval/Observal4.2k—~2.2kAutomated safety check: PassApache-2.0
Zapier Statuszapier/zapier-mcp428—~1.8kAutomated safety check: PassMIT
n8n Multi-Instance Targetingczlonkowski/n8n-skills6.4k—~3.2kAutomated safety check: PassMIT
Agents Onboardingfazer-ai/agents118—~4.4kAutomated safety check: PassApache-2.0

Similar skills

  • CC Workflow Studio AI Editor

    breaking-brake/cc-wf-studio

    Creates and edits visual agent workflows in CC Workflow Studio through conversation, with the agent reading and writing the canvas over MCP.

    5.4k GitHub stars~561 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Observal

    Observal/Observal

    A skill your agent uses when starting any task the organization may already have an approved skill, prompt, MCP server, or Agent for: reviewing code, a commit, a diff, or a pull request; writing…

    4.2k GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Zapier Status

    zapier/zapier-mcp

    Official

    Check the health of your Zapier MCP setup. An agent skill from zapier/zapier-mcp.

    428 GitHub stars~1.8k tokensUpdated 2 mo ago
    Productivity & AutomationAuto-check passed
  • n8n Multi-Instance Targeting

    czlonkowski/n8n-skills

    Keeps an n8n MCP session pointed at the right n8n instance, with rules for discovering, switching and verifying the target before credential writes and for recovering from misroutes.

    6.4k GitHub stars~3.2k tokensUpdated 22 days ago
    Productivity & AutomationAuto-check passed
  • Agents Onboarding

    fazer-ai/agents

    Conduz a jornada de onboarding 'do zero ao agente de atendimento' do fazer.ai agents num VPS, escolhendo o orquestrador de deploy (Tier A Coolify, B Portainer, C compose genérico para VM crua ou…

    118 GitHub stars~4.4k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Project Pull Request

    swimmwatch/cloakbrowser-mcp

    Create, update, prepare, or review a cloakbrowser-mcp GitHub Pull Request only when the user explicitly requests PR work.

    161 GitHub stars~1k tokensUpdated 6 days ago
    DevelopmentAuto-check passed

More from activepieces/activepieces

All 13 skills in this repo
  • Activepieces Design System

    activepieces/activepieces

    Design system for Activepieces (open-source AI automation platform, "open source replacement for Zapier").

    25k GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Piece Builder

    activepieces/activepieces

    Build and edit Activepieces pieces (integrations) — creating new pieces, adding actions or triggers, or fixing bugs in existing ones.

    25k GitHub stars~3.1k tokensUpdated today
    Auto-check: notes
  • Profile App Cpu

    activepieces/activepieces

    Find what is burning CPU in a live app container without restarting it: separate the JS thread from GC and libuv, open the V8 inspector in place with SIGUSR1, take a CPU profile over CDP, and…

    25k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Profile Worker Memory

    activepieces/activepieces

    Diagnose a worker that is growing memory or being OOM-killed: separate a JS-heap leak from native growth, take a V8 heap snapshot of a live worker in place (never uploading it), and walk the…

    25k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Triage Dependabot Alerts

    activepieces/activepieces

    Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and…

    25k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Triage Image Cves

    activepieces/activepieces

    Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity.

    25k GitHub stars~3.6k tokensUpdated today
    Auto-check passed

Questions about Analyze Logs

What does Analyze Logs do?

Analyze application logs from the .evlog/logs/ directory. An agent skill from activepieces/activepieces. Analyze Logs is an agent skill from activepieces/activepieces.evlog/logs/ directory.

When should I use Analyze Logs?

Analyze Logs fits situations like: debugging errors; investigating slow requests; understanding request patterns; answering questions about application behavior.

How do I install Analyze Logs in Claude Code?

Run `npx skills add activepieces/activepieces --skill analyze-logs -a claude-code`. Or copy the skill folder (.agents/skills/analyze-logs in activepieces/activepieces) into .claude/skills/analyze-logs in your project. Claude Code loads it when a task matches its description.

How do I install Analyze Logs in Codex?

Run `npx skills add activepieces/activepieces --skill analyze-logs -a codex`. Or copy the skill folder (.agents/skills/analyze-logs in activepieces/activepieces) into .agents/skills/analyze-logs in your project. Codex loads it when a task matches its description.

Can I use Analyze Logs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add activepieces/activepieces --skill analyze-logs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyze-logs, .gemini/skills/analyze-logs, .github/skills/analyze-logs and .opencode/skills/analyze-logs in your project.

What does Analyze Logs need to run?

SKILL.md names no scripts, command-line tools or credentials: Analyze Logs is instructions for the agent only.

Does Analyze Logs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Analyze Logs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Analyze Logs use?

Analyze Logs is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyze Logs use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Analyze Logs?

Skills that share tags, products or a category with Analyze Logs: CC Workflow Studio AI Editor (breaking-brake/cc-wf-studio, 5.4k stars), Observal (Observal/Observal, 4.2k stars), Zapier Status (zapier/zapier-mcp, 428 stars) and n8n Multi-Instance Targeting (czlonkowski/n8n-skills, 6.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyze Logs?

activepieces (a GitHub organization) maintains it in activepieces/activepieces, which has 24,941 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 8, 2026.

Source: activepieces/activepieces on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.