Kubernetes Network Root Cause Analysis
kubeshark/kubeshark
Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.
Write the weekly on-call handoff: everything the incoming on-call needs, triage-ready, posted to the channel at shift boundary.
$ npx skills add anthropics/oncall-kit --skill handoff -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install anthropics/oncall-kit handoff --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/anthropics/oncall-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/handoff .claude/skills/handoff && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "handoff" agent skill from https://github.com/anthropics/oncall-kit/tree/main/skills/handoff into .claude/skills/handoff/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "handoff", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/anthropics/oncall-kit/tree/main/skills/handoffType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add anthropics/oncall-kit --skill handoff -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install anthropics/oncall-kit handoff --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/oncall-kit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/handoff .agents/skills/handoff && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "handoff" agent skill from https://github.com/anthropics/oncall-kit/tree/main/skills/handoff into .agents/skills/handoff/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "handoff", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anthropics/oncall-kit --skill handoff -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install anthropics/oncall-kit handoff --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/oncall-kit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/handoff .cursor/skills/handoff && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "handoff" agent skill from https://github.com/anthropics/oncall-kit/tree/main/skills/handoff into .cursor/skills/handoff/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "handoff", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/anthropics/oncall-kit.git --path skills/handoff--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add anthropics/oncall-kit --skill handoff -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install anthropics/oncall-kit handoff --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/oncall-kit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/handoff .gemini/skills/handoff && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "handoff" agent skill from https://github.com/anthropics/oncall-kit/tree/main/skills/handoff into .gemini/skills/handoff/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "handoff", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install anthropics/oncall-kit handoffInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add anthropics/oncall-kit --skill handoff -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/anthropics/oncall-kit.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/handoff .github/skills/handoff && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "handoff" agent skill from https://github.com/anthropics/oncall-kit/tree/main/skills/handoff into .github/skills/handoff/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "handoff", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anthropics/oncall-kit --skill handoff -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install anthropics/oncall-kit handoff --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/oncall-kit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/handoff .opencode/skills/handoff && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "handoff" agent skill from https://github.com/anthropics/oncall-kit/tree/main/skills/handoff into .opencode/skills/handoff/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "handoff", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
handoffWrite the weekly on-call handoff: everything the incoming on-call needs, triage-ready, posted to the channel at shift boundary.
Handoff is an agent skill from anthropics/oncall-kit, published by the product's own GitHub organization. Write the weekly on-call handoff: everything the incoming on-call needs, triage-ready, posted to the channel at shift boundary. Use when the weekly routine fires, or when someone asks for a handoff / shift summary / "catch the next on-call up".
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Incident response. The repository describes itself as: Starter kit for a Claude-assisted on-call: mines your incident history into triage playbooks, sets up through human-approved gates, and runs read-only in your Slack channel —… The licence is Apache-2.0.
Read from SKILL.md and the folder at commit c03282c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Handoff loads about 1.2k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 639 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from anthropics/oncall-kit at commit c03282c, republished under its Apache-2.0 licence (© anthropics). 639 words, ~1,164 tokens.
.claude/skills/handoff/SKILL.md (or your agent's skills folder).<!-- Copyright 2026 Anthropic PBC -->
<!-- SPDX-License-Identifier: Apache-2.0 -->
Standing rules in CLAUDE.md apply — especially rules 10 and 11: fresh
reader, lead with what to do. The incoming on-call missed everything; this
document is their entire week's context, and it must arrive as work they
can start, not "here's what happened".
Fan out across every capability in STACK.md for the shift window
(default: the week since the last handoff):
pager — every page and incident: state, severity, resolutionalert-channels — what fired, what people said, what never got a threadcode — merges/PRs touching on-call-relevant paths; reverts; deploysmetrics — week-over-week trend of the health signals in ONCALL.mdlessons.md — every entry appended this shiftCross-reference: an alert with no thread, a lessons entry with no incident, a metric trending wrong with no alert — these orphans are usually the "watch this week" items.
Post to the channel as a message with the exec summary, full doc attached or linked:
📋 On-call handoff — week of {{date}}
Exec summary: N incidents (n resolved, n monitoring). N pages. Anything systemic in one clause. On-call health: the required weekly metric — incidents and pages vs. last week, split by business-hours / off-hours, false pages, the rubber-stamp fraction (diagnoses acted on with no recorded verification step — the early warning that humans stopped cross-examining; see eval/replay.md), and whether the trend is up or down. This section is how the whole setup is measured over time (see eval/replay.md), so never omit it and never soften it. Intake health: median and worst time from symptom onset to incident declared this week (onset from the alert/thread timeline; declaration from the incident record). If incidents routinely run 40 minutes before anyone declares one, that's the process finding of the week — you can't fix an intake path you don't measure. Watch this week: the 1–3 things most likely to page you, each with why and a link to its pattern (
lessons.mdtag or reference file). Start here: the single highest-priority open item, with its current state and next action. Full doc: [link] · New to this channel? ReadONBOARD.md— how to read a diagnosis, challenge one, or silence a routine.
The full doc, per incident: what happened (one fresh-reader sentence, links) · what it means (pattern or one-off? systemic risk?) · what you should do (nothing / monitor / action, with the action named).
Then: open items ranked by "will this page you?", not by age. Preventable repeats called out as playbook gaps with proposed reference-file amendments (rule 9 — fix the playbook, not just the incident).
The ground moves between incidents; this is where the kit notices. Each week, flag:
STACK.md binding that failed or 403'd during the week's workdeploys feed or announcement channels suggesting the
infrastructure changed under the playbooks — a migration completed, a
tool replaced, a service renamedEach flag arrives as a proposal, never an edit (rule 9): "re-run Discover for this binding," a reference-file amendment PR, or "re-run the replay against post-change incidents" (see eval/replay.md's re-validation triggers). A quiet week with no drift gets one line: "no drift detected."
© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/handoff of anthropics/oncall-kit.
Open the folder on GitHubat commit c03282c
Handoff next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Handoff this skillanthropics/oncall-kit | 210 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Kubernetes Network Root Cause Analysiskubeshark/kubeshark | 12k | — | ~5.3k | Automated safety check: Pass | Apache-2.0 | |
| UModel Root Cause Analysisalibaba/UnifiedModel | 412 | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Learningskortix-ai/suna | 20k | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| Oncallpigweed-project/pigweed | 548 | — | ~992 | Automated safety check: Pass | Apache-2.0 | |
| Loop Triage Reportcobusgreyling/loop-engineering | 11k | — | ~500 | Automated safety check: Pass | MIT |
kubeshark/kubeshark
Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.
alibaba/UnifiedModel
Investigates a service incident to its root cause by querying a UModel object graph alongside metrics, logs, topology and recent deployments.
kortix-ai/suna
The project's episodic memory: a timestamped ledger of rules paid for with real outages and near-misses, one entry per incident.
pigweed-project/pigweed
Pigweed oncall rotation runbooks and maintenance workflows (such as rolling CIPD client tools for b/315378787).
cobusgreyling/loop-engineering
Turns CI failures, open issues, recent commits and chat threads into a prioritized markdown report that an automation loop can act on without inventing architecture work.
openclaw/clawhub
Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.
anthropics/oncall-kit
The optional standing status report ("the weather"): compile open incidents, build health, merge-queue stats, and deploy lag into one always-current report page, and post to the channel only when a…
anthropics/oncall-kit
Bootstrap a Claude-assisted on-call for this channel/repo: discover the available connectors, mine incident history into draft triage playbooks, interview the human for policy, validate against…
anthropics/oncall-kit
Investigate an alert or incident in this channel: classify the symptom, load the matching triage reference, check lessons.md for known causes, and post a grounded first-pass diagnosis with evidence…
Categories
Write the weekly on-call handoff: everything the incoming on-call needs, triage-ready, posted to the channel at shift boundary. Handoff is an agent skill from anthropics/oncall-kit, published by the product's own GitHub organization. Write the weekly on-call handoff: everything the incoming on-call needs, triage-ready, posted to the channel at shift boundary.
Handoff fits situations like: the weekly routine fires; someone asks for a handoff / shift summary / catch the next on-call up.
Run `npx skills add anthropics/oncall-kit --skill handoff -a claude-code`. Or copy the skill folder (skills/handoff in anthropics/oncall-kit) into .claude/skills/handoff in your project. Claude Code loads it when a task matches its description.
Run `npx skills add anthropics/oncall-kit --skill handoff -a codex`. Or copy the skill folder (skills/handoff in anthropics/oncall-kit) into .agents/skills/handoff in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/oncall-kit --skill handoff -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/handoff, .gemini/skills/handoff, .github/skills/handoff and .opencode/skills/handoff in your project.
SKILL.md names no scripts, command-line tools or credentials: Handoff is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Handoff is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Handoff: Kubernetes Network Root Cause Analysis (kubeshark/kubeshark, 12k stars), UModel Root Cause Analysis (alibaba/UnifiedModel, 412 stars), Learnings (kortix-ai/suna, 20k stars) and Oncall (pigweed-project/pigweed, 548 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
anthropics (a GitHub organization, an official publisher) maintains it in anthropics/oncall-kit, which has 210 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on August 6, 2026.
Source: anthropics/oncall-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.