Agent skill

Cross Source Correlation

by aozyildirim in aozyildirim/Agena

Correlate near-in-time events across PR merges, deploys, monitoring (Sentry/NewRelic/Datadog/AppDynamics) and ticket trackers (Jira/Azure DevOps) into confidence-scored clusters that answer "which…

MITAuto-check passedDevOps & Cloud

Install Cross Source Correlation

skills CLI
$ npx skills add aozyildirim/Agena --skill cross-source-correlation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aozyildirim/Agena cross-source-correlation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aozyildirim/Agena.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agena/cross-source-correlation .claude/skills/cross-source-correlation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cross-source-correlation
GitHub stars
101
Token cost
~756 tokens
SKILL.md length
308 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Correlate near-in-time events across PR merges, deploys, monitoring (Sentry/NewRelic/Datadog/AppDynamics) and ticket trackers (Jira/Azure DevOps) into confidence-scored clusters that answer "which…

  • Works in 5 steps: Pick a time window (default 60 minutes… → Score candidate clusters using a… → Surface only clusters ≥ 70. Below that… → …
  • DevOps & Cloud work in your project
  • SKILL.md covers How to apply this pattern, Example and Notes
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cross Source Correlation is an agent skill from aozyildirim/Agena. Correlate near-in-time events across PR merges, deploys, monitoring (Sentry/NewRelic/Datadog/AppDynamics) and ticket trackers (Jira/Azure DevOps) into confidence-scored clusters that answer "which deploy caused this bug" without manual tab-switching.

Its SKILL.md is about 760 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with New Relic, Sentry, Azure DevOps and Datadog. The repository describes itself as: Agentic AI platform with pixel agent technology — autonomous code generation, PR automation & multi-tenant SaaS. The licence is MIT.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “which deploy caused this bug”
  • “/cross-source-correlation”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Pick a time window (default 60 minutes ending now) and pull every
  2. Score candidate clusters using a heuristic that rewards co-location
  3. Surface only clusters ≥ 70. Below that the noise / signal ratio
  4. Persist the cluster with: primary_kind, primary_label,
  5. Offer triage actions on each cluster: confirm, false-positive,

What it can do on your machine

Read from SKILL.md and the folder at commit 63db0e2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cross Source Correlation loads about 756 tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 308 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~756

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aozyildirim/Agena at commit 63db0e2, republished under its MIT licence (© aozyildirim). 308 words, ~756 tokens.

Download SKILL.mdSave it as .claude/skills/cross-source-correlation/SKILL.md (or your agent's skills folder).
name
cross-source-correlation
description
Correlate near-in-time events across PR merges, deploys, monitoring (Sentry/NewRelic/Datadog/AppDynamics) and ticket trackers (Jira/Azure DevOps) into confidence-scored clusters that answer "which deploy caused this bug" without manual tab-switching.
tags
observability, incident-response, correlation, ai-agent, devops
publisher
agena

Cross-Source Correlation

When a Sentry alert fires, a senior engineer mentally cross-references the last deploy time, recent PRs, NewRelic apdex, and the support tickets opened in the last hour. AGENA's Cross-Source Correlation engine does the same correlation deterministically, producing a single confidence-scored cluster per incident.

How to apply this pattern

  1. Pick a time window (default 60 minutes ending now) and pull every event your platform observed inside it: PR merges, deploys, error imports (Sentry / NewRelic / Datadog / AppDynamics), and work-item imports (Jira / Azure DevOps).

  2. Score candidate clusters using a heuristic that rewards co-location in time + repo:

    • PR merge inside the window → +40
    • Deploy from the same repo inside the window → +20
    • One monitoring signal in the window → +20 (+30 if more than one)
    • One work-item opened in the window → +10 (+20 if more than one)
    • Bonus +10 when a PR is present alongside any monitoring signal
  3. Surface only clusters ≥ 70. Below that the noise / signal ratio collapses; above it you get the "vay" moment for incident triage.

  4. Persist the cluster with: primary_kind, primary_label, related_events[], confidence, severity, narrative, repo_mapping_id. Keep a fingerprint for idempotency so repeated poller runs don't double-insert the same cluster.

  5. Offer triage actions on each cluster: confirm, false-positive, undo, and (when a PR is the prime suspect) one-click rollback.

Example

🔴 CRITICAL · confidence 94%

PR #4519 (erinc, merged 14:18) in checkout-api correlates with
2 monitoring signal(s) (sentry, newrelic) and 1 work-item opened
in the same window.

Timeline:
  14:18  🔀 PR #4519 merged — payment_service.py, +47/-12
  14:18  🚀 deploy a1b2c3d4 → production
  14:23  🚨 Sentry: TypeError in payment_service.py:88 (47×)
  14:24  📡 NewRelic: apdex 0.92 → 0.41
  14:31  🪐 Jira SUP-128 opened — 12 customers report failed checkout

Notes

  • Run as a background poller every ~5 minutes on a fresh window — no webhook fan-out needed when you control all the sources.
  • Sub-70 clusters can still be useful for trending dashboards even if you don't want to surface them as actionable.
  • Store the cluster's narrative as a one-sentence summary (LLM-generated off the timeline) so it's readable in Slack alerts and post-mortem docs.
  • Designed to be agnostic to specific monitoring backends — add a new source by writing a single mapper that emits (timestamp, kind, ref, label) rows into the same window query.

© aozyildirim, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/agena/cross-source-correlation of aozyildirim/Agena.

Open the folder on GitHubat commit 63db0e2

Compare with similar skills

Cross Source Correlation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cross Source Correlation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cross Source Correlation this skillaozyildirim/Agena101—~756Automated safety check: PassMIT
Sentry Observabilityjeremylongshore/tons-of-skills-marketplace2.8k—~3.7kAutomated safety check: PassMIT
Tool ConnectorZhixiangLuo/10xProductivity478—~925Automated safety check: PassMIT
Ops MonitorLifecycle-Innovations-Limited/claude-ops5401 repos~1.5kAutomated safety check: NotesMIT
Error HandlerEliasOulkadi/shokunin114—~3.6kAutomated safety check: NotesMIT
Sentry Migration Deep Divejeremylongshore/tons-of-skills-marketplace2.8k—~2.6kAutomated safety check: NotesMIT

Similar skills

  • Sentry Observability

    jeremylongshore/tons-of-skills-marketplace

    Integrate Sentry with your observability stack — logging, metrics, APM, and dashboards.

    2.8k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Tool Connector

    ZhixiangLuo/10xProductivity

    Connect any tool you use at work to your agent — including internal company tools, custom-built systems, deployment portals, incident trackers, internal knowledge bases, HR systems, and commercial…

    478 GitHub stars~925 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Ops Monitor

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "datadog", "APM alerts", or…

    540 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check: notes
  • Error Handler

    EliasOulkadi/shokunin

    Design error handling, structured logging, and observability with OpenTelemetry (traces, metrics, logs), error classification, recovery patterns (retry with jitter, circuit breaker, bulkhead…

    114 GitHub stars~3.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Sentry Migration Deep Dive

    jeremylongshore/tons-of-skills-marketplace

    Migrate to Sentry from other error tracking tools like Rollbar, Bugsnag, or New Relic.

    2.8k GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Sentry Alert Tuner

    LeoYeAI/openclaw-master-skills

    Reduce Sentry alert fatigue by surgically tuning issue grouping, fingerprint rules, severity mapping, sample rates, before-send filters, sourcemap pipelines, and release-health gates.

    2.2k GitHub stars~7.3k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from aozyildirim/Agena

  • Integration Rule Engine

    aozyildirim/Agena

    A declarative routing engine that turns ticket / error attributes (reporter, label, project, area path, error class, environment) into a tag + AI agent + priority assignment, so cross-source…

    101 GitHub stars~976 tokensUpdated 2 mo ago
    Auto-check passed
  • Owasp Reviewer Prompt

    aozyildirim/Agena

    A paranoid OWASP-Top-10-aware system prompt for AI code review that traces data flow, treats every input as malicious, maps each finding to an OWASP category, and outputs a structured Summary /…

    101 GitHub stars~978 tokensUpdated 2 mo ago
    Auto-check passed
  • Review Backlog Killer

    aozyildirim/Agena

    Detect pull requests aging past warn / critical thresholds, score severity, and nudge reviewers via Slack DM, channel, email, or directly as a PR comment — with one-time auto-escalation when a PR…

    101 GitHub stars~802 tokensUpdated 2 mo ago
    Auto-check passed
  • Stale Ticket Triage

    aozyildirim/Agena

    Replace the weekly "look at every ticket older than X days" meeting with a scheduled AI scan that picks close / snooze / keep per ticket plus a one-sentence reason, so a PM can bulk-approve in 90…

    101 GitHub stars~714 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Cross Source Correlation

What does Cross Source Correlation do?

Correlate near-in-time events across PR merges, deploys, monitoring (Sentry/NewRelic/Datadog/AppDynamics) and ticket trackers (Jira/Azure DevOps) into confidence-scored clusters that answer "which…. Cross Source Correlation is an agent skill from aozyildirim/Agena. Correlate near-in-time events across PR merges, deploys, monitoring (Sentry/NewRelic/Datadog/AppDynamics) and ticket trackers (Jira/Azure DevOps) into confidence-scored clusters that answer "which deploy caused this bug" without manual tab-switching.

When should I use Cross Source Correlation?

Cross Source Correlation fits situations like: devOps & Cloud work in your project.

How do I install Cross Source Correlation in Claude Code?

Run `npx skills add aozyildirim/Agena --skill cross-source-correlation -a claude-code`. Or copy the skill folder (skills/agena/cross-source-correlation in aozyildirim/Agena) into .claude/skills/cross-source-correlation in your project. Claude Code loads it when a task matches its description.

How do I install Cross Source Correlation in Codex?

Run `npx skills add aozyildirim/Agena --skill cross-source-correlation -a codex`. Or copy the skill folder (skills/agena/cross-source-correlation in aozyildirim/Agena) into .agents/skills/cross-source-correlation in your project. Codex loads it when a task matches its description.

Can I use Cross Source Correlation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aozyildirim/Agena --skill cross-source-correlation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cross-source-correlation, .gemini/skills/cross-source-correlation, .github/skills/cross-source-correlation and .opencode/skills/cross-source-correlation in your project.

What does Cross Source Correlation need to run?

SKILL.md names no scripts, command-line tools or credentials: Cross Source Correlation is instructions for the agent only.

Does Cross Source Correlation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cross Source Correlation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cross Source Correlation use?

Cross Source Correlation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cross Source Correlation use?

About 756 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cross Source Correlation?

Skills that share tags, products or a category with Cross Source Correlation: Sentry Observability (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Tool Connector (ZhixiangLuo/10xProductivity, 478 stars), Ops Monitor (Lifecycle-Innovations-Limited/claude-ops, 540 stars) and Error Handler (EliasOulkadi/shokunin, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cross Source Correlation?

aozyildirim (a GitHub user) maintains it in aozyildirim/Agena, which has 101 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on August 2, 2026.

Source: aozyildirim/Agena on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.