Agent skill

Observability LLM Obs

by aspectrr in aspectrr/deer

Monitor LLMs and agentic apps: performance, token/cost, response quality, and workflow orchestration.

MITAuto-check passedDevOps & Cloud

Install Observability LLM Obs

skills CLI
$ npx skills add aspectrr/deer --skill observability-llm-obs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aspectrr/deer observability-llm-obs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/deer-cli/internal/skill/defaults/observability-llm-obs .claude/skills/observability-llm-obs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
observability-llm-obs
GitHub stars
405
Token cost
~858 tokens
SKILL.md length
160 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Monitor LLMs and agentic apps: performance, token/cost, response quality, and workflow orchestration.

  • The user asks about LLM monitoring
  • SKILL.md covers Where to look, Data available, Use cases and query patterns and Workflow, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • GenAI observability

What it does

Observability LLM Obs is an agent skill from aspectrr/deer. Monitor LLMs and agentic apps: performance, token/cost, response quality, and workflow orchestration. Use when the user asks about LLM monitoring, GenAI observability, or AI cost/quality.

Its SKILL.md is about 860 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Observability, LLM cost and token optimization and LLM observability. It works with OpenTelemetry. The repository describes itself as: 🦌 The AI Elasticsearch Engineer. The licence is MIT.

When your agent uses it

  • The user asks about LLM monitoring
  • GenAI observability
  • AI cost/quality

Example prompts

  • “/observability-llm-obs”

What it can do on your machine

Read from SKILL.md and the folder at commit e4f9845. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are esql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Observability LLM Obs loads about 858 tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 160 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~858

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aspectrr/deer at commit e4f9845, republished under its MIT licence (© aspectrr). 160 words, ~858 tokens.

Download SKILL.mdSave it as .claude/skills/observability-llm-obs/SKILL.md (or your agent's skills folder).
name
observability-llm-obs
description
Monitor LLMs and agentic apps: performance, token/cost, response quality, and workflow orchestration. Use when the user asks about LLM monitoring, GenAI observability, or AI cost/quality.
metadata.author
elastic
metadata.version
0.1.0
metadata.source
elastic/agent-skills//skills/observability/llm-obs

LLM and Agentic Observability

Monitor LLMs and agentic components using data ingested into Elastic. Focus on performance, cost/token utilization, response quality, and call chaining.

Where to look

  • Trace data (APM / OTel): traces* for LLM spans from OTel/EDOT instrumentations
  • Integration metrics/logs: metrics* and logs* from Elastic LLM integrations (OpenAI, Azure, Bedrock, Vertex AI)
  • Discover first: Use GET _data_stream or GET traces*/_mapping to find available data

Data available

From traces (traces*)
PurposeExample attribute names (OTel GenAI)
Operation / providergen_ai.operation.name, gen_ai.provider.name
Modelgen_ai.request.model, gen_ai.response.model
Token usagegen_ai.usage.input_tokens, gen_ai.usage.output_tokens
Errorserror.type

Use duration and event.outcome for latency and success/failure. Use trace.id and parent/child relationships for call chaining analysis.

Use cases and query patterns

LLM performance
esql
FROM traces*
| WHERE @timestamp >= "2025-03-01T00:00:00Z" AND @timestamp <= "2025-03-01T23:59:59Z"
  AND span.attributes.gen_ai.provider.name IS NOT NULL
| STATS request_count = COUNT(*), failures = COUNT(*) WHERE event.outcome == "failure",
    avg_duration_us = AVG(span.duration.us)
  BY span.attributes.gen_ai.request.model
| EVAL error_rate = failures / request_count
| LIMIT 100
Token usage over time
esql
FROM traces*
| WHERE @timestamp >= "2025-03-01T00:00:00Z" AND @timestamp <= "2025-03-01T23:59:59Z"
  AND span.attributes.gen_ai.provider.name IS NOT NULL
| STATS input_tokens = SUM(span.attributes.gen_ai.usage.input_tokens),
    output_tokens = SUM(span.attributes.gen_ai.usage.output_tokens)
  BY BUCKET(@timestamp, 1 hour), span.attributes.gen_ai.request.model
| SORT @timestamp
| LIMIT 500
Agentic workflow (trace-level view)
esql
FROM traces*
| WHERE @timestamp >= "2025-03-01T00:00:00Z" AND @timestamp <= "2025-03-01T23:59:59Z"
  AND span.attributes.gen_ai.operation.name IS NOT NULL
| STATS span_count = COUNT(*), total_duration_us = SUM(span.duration.us) BY trace.id
| WHERE span_count > 1
| SORT total_duration_us DESC
| LIMIT 50

Workflow

text
- [ ] Step 1: Determine available data (traces*, metrics*, integration data streams)
- [ ] Step 2: Discover LLM-related field names (mapping or sample doc)
- [ ] Step 3: Run ES|QL queries for the user's question
- [ ] Step 4: Check active alerts/SLOs on LLM-related data
- [ ] Step 5: Summarize findings from ingested data only

Guidelines

  • Use only data collected in Elastic. Do not rely on external UIs.
  • Discover field names from _mapping or sample documents before querying.
  • Prefer ES|QL and Elasticsearch APIs over Kibana UI.
  • Use LIMIT and coarse time buckets for performance.

© aspectrr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in deer-cli/internal/skill/defaults/observability-llm-obs of aspectrr/deer.

Open the folder on GitHubat commit e4f9845

Compare with similar skills

Observability LLM Obs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Observability LLM Obs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Observability LLM Obs this skillaspectrr/deer405—~858Automated safety check: PassMIT
Caveman Gateway SetupJuliusBrussee/caveman110k1 repos~2.6kAutomated safety check: WarnApache-2.0
Agent Kill Switchvivekchand/clawmetry425—~1.1kAutomated safety check: PassMIT
Clawmetry Selfcheckvivekchand/clawmetry425—~515Automated safety check: PassMIT
Agent Platform Alert Configurationgoogle/skills21k—~4.2kAutomated safety check: PassApache-2.0
Clawmetryvivekchand/clawmetry425—~992Automated safety check: PassMIT

Similar skills

  • Caveman Gateway Setup

    JuliusBrussee/caveman

    Routes every LLM call in a repository through the Caveman Cloud gateway in record mode, so requests and costs are measured without changing behavior.

    110k GitHub starsUsed in 1 repo~2.6k tokens
    DevOps & CloudAuto-check: warnings
  • Agent Kill Switch

    vivekchand/clawmetry

    Give the human an off switch and a cost meter for the coding agents on this machine, using ClawMetry.

    425 GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Clawmetry Selfcheck

    vivekchand/clawmetry

    Read your own agent telemetry from ClawMetry (waste, progress, cost) and act on it before finishing a task.

    425 GitHub stars~515 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Clawmetry

    vivekchand/clawmetry

    Real-time observability for OpenClaw agents — local dashboard + optional encrypted cloud sync.

    425 GitHub stars~992 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Arize Phoenix

    Arize-ai/phoenix

    Open-source AI observability platform for tracing, evaluating, and improving LLM applications with OpenTelemetry integration

    12k GitHub starsUsed in 1 repo~3.8k tokens
    DevOps & CloudAuto-check passed

More from aspectrr/deer

All 14 skills in this repo
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Elasticsearch Authn

    aspectrr/deer

    Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.

    405 GitHub stars~1.2k tokensUpdated 5 mo ago
    Auto-check: notes
  • Elasticsearch Authz

    aspectrr/deer

    Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    405 GitHub stars~684 tokensUpdated 5 mo ago
    Auto-check passed
  • Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.

    405 GitHub stars~4.9k tokensUpdated 5 mo ago
    Auto-check passed
  • Kafka

    aspectrr/deer

    Kafka topic management, consumer group monitoring, message production/consumption, and cluster health diagnostics.

    405 GitHub stars~946 tokensUpdated 5 mo ago
    Auto-check passed

Works with

Categories

Questions about Observability LLM Obs

What does Observability LLM Obs do?

Monitor LLMs and agentic apps: performance, token/cost, response quality, and workflow orchestration. Observability LLM Obs is an agent skill from aspectrr/deer. Monitor LLMs and agentic apps: performance, token/cost, response quality, and workflow orchestration.

When should I use Observability LLM Obs?

Observability LLM Obs fits situations like: the user asks about LLM monitoring; genAI observability; AI cost/quality.

How do I install Observability LLM Obs in Claude Code?

Run `npx skills add aspectrr/deer --skill observability-llm-obs -a claude-code`. Or copy the skill folder (deer-cli/internal/skill/defaults/observability-llm-obs in aspectrr/deer) into .claude/skills/observability-llm-obs in your project. Claude Code loads it when a task matches its description.

How do I install Observability LLM Obs in Codex?

Run `npx skills add aspectrr/deer --skill observability-llm-obs -a codex`. Or copy the skill folder (deer-cli/internal/skill/defaults/observability-llm-obs in aspectrr/deer) into .agents/skills/observability-llm-obs in your project. Codex loads it when a task matches its description.

Can I use Observability LLM Obs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aspectrr/deer --skill observability-llm-obs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/observability-llm-obs, .gemini/skills/observability-llm-obs, .github/skills/observability-llm-obs and .opencode/skills/observability-llm-obs in your project.

What does Observability LLM Obs need to run?

SKILL.md names no scripts, command-line tools or credentials: Observability LLM Obs is instructions for the agent only.

Does Observability LLM Obs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Observability LLM Obs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Observability LLM Obs use?

Observability LLM Obs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Observability LLM Obs use?

About 858 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Observability LLM Obs?

Skills that share tags, products or a category with Observability LLM Obs: Caveman Gateway Setup (JuliusBrussee/caveman, 110k stars), Agent Kill Switch (vivekchand/clawmetry, 425 stars), Clawmetry Selfcheck (vivekchand/clawmetry, 425 stars) and Agent Platform Alert Configuration (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Observability LLM Obs?

aspectrr (a GitHub user) maintains it in aspectrr/deer, which has 405 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on April 21, 2026.

Source: aspectrr/deer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.