Agent skill

Investigate Macserver Sync Issue

by blotcms in blotcms/blot

Investigate an "iCloud resync requested" admin email ("A resync was requested for site blog…") or any other iCloud / macserver sync problem.

AGPL-3.0Auto-check: warnings

Install Investigate Macserver Sync Issue

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add blotcms/blot --skill investigate-macserver-sync-issue -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install blotcms/blot investigate-macserver-sync-issue --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/blotcms/blot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/investigate-macserver-sync-issue .claude/skills/investigate-macserver-sync-issue && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
investigate-macserver-sync-issue
GitHub stars
2k
Token cost
~3k tokens
SKILL.md length
1,486 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Investigate an "iCloud resync requested" admin email ("A resync was requested for site blog…") or any other iCloud / macserver sync problem.

  • Works in 7 steps: Find the resync request(s) on the… → Get the failure itself. Take the blog's… → Check the server side for the same window → …
  • The user pastes
  • SKILL.md covers What the alert means, Access and safety, Method and Incident log
  • Calls ssh, docker and node

What it does

Investigate Macserver Sync Issue is an agent skill from blotcms/blot. Investigate an "iCloud resync requested" admin email ("A resync was requested for site blog…") or any other iCloud / macserver sync problem. Reads the macserver's pm2 logs over ssh macserver to find which watcher action (upload/remove/mkdir) failed and why, cross-checks the production container logs and the blog's iCloud account state, classifies the cause, then appends a short entry to this skill's incident log. Use when the user pastes or forwards one of these alerts, or asks to look into iCloud / macserver sync.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Turns a folder into a website. The licence is AGPL-3.0.

When your agent uses it

  • The user pastes
  • Forwards one of these alerts
  • Asks to look into iCloud / macserver sync

Example prompts

  • “iCloud resync requested”
  • “A resync was requested for site blog…”
  • “/investigate-macserver-sync-issue”

Requirements

  • Docker

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Find the resync request(s) on the macserver. The email is capped
  2. Get the failure itself. Take the blog's lines around that time,
  3. Check the server side for the same window
  4. Check the account state if the failure suggests it (409 setup
  5. Classify as one of
  6. Report to the user in chat (identifying details are fine here, never
  7. Append an entry to the Incident log below (newest last), following

What it can do on your machine

Read from SKILL.md and the folder at commit 92e37a1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • ssh
    • docker
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use ssh and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Investigate Macserver Sync Issue loads about 3k tokens when it runs. Until then it costs about 139 tokens; SKILL.md has 1,486 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~139
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • NoteMentions a .env fileSKILL.md:51
    `.env`, touch the iCloud folders, or run `scripts/icloud/resync.js` unless
  • NoteMentions a .env fileSKILL.md:55
    lients/icloud/macserver`, config in its `.env`, key
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:59
    `~/.ssh/config` at a copy outside `~/Library/Mobile Documents`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from blotcms/blot at commit 92e37a1, republished under its AGPL-3.0 licence (© blotcms). 1,486 words, ~2,974 tokens.

Download SKILL.mdSave it as .claude/skills/investigate-macserver-sync-issue/SKILL.md (or your agent's skills folder).
name
investigate-macserver-sync-issue
description
Investigate an "iCloud resync requested" admin email ("A resync was requested for site blog_…") or any other iCloud / macserver sync problem. Reads the macserver's pm2 logs over `ssh macserver` to find which watcher action (upload/remove/mkdir) failed and why, cross-checks the production container logs and the blog's iCloud account state, classifies the cause, then appends a short entry to this skill's incident log. Use when the user pastes or forwards one of these alerts, or asks to look into iCloud / macserver sync.

Investigate a macserver (iCloud) sync issue

What the alert means

Blot's iCloud client is two halves:

  • macserver (app/clients/icloud/macserver/, ESM, pm2 process macserver, Express on port 3000) runs on a Mac signed into iCloud Drive. It watches <ICLOUD_DRIVE_DIRECTORY>/<blogID>/ with chokidar plus an fs.watch reconciler (watcher/) and pushes every change to Blot over HTTP (httpClient/{upload,remove,mkdir}.js → POST /clients/icloud/{upload,delete,mkdir}).
  • Server (app/clients/icloud/routes/site/) applies those changes, and pushes dashboard edits the other way via the macserver's own routes (app/clients/icloud/write.js, sync/util/remote*.js).

ICLOUD_RESYNC_REQUESTED has exactly one trigger: a watcher action on the macserver failed even after retrying (macserver/watcher/actions.js — withRetries, 4 attempts, each fetch itself retried 3× with a 10s timeout, 60s for uploads). The macserver then calls httpClient/resync.js, which POSTs {resyncRequested:true} to /clients/icloud/status. The server (routes/site/status.js) dedups for 10s, takes the folder sync lock (replying 423 if it's held, so the macserver retries up to 20× with backoff ≤5 min), sends the email, and runs syncFromiCloud with iCloud as the source of truth (can clobber files that only existed on Blot's side, e.g. dashboard template edits).

The email carries no reason. The reason is only in the macserver log: Requesting resync for blogID: <id> (<action> for <path> failed after retries). So always start on the macserver.

There is no scheduled iCloud integrity check (unlike Dropbox's hourly validation): runValidation / resyncAllConnected exist in app/clients/icloud/init.js but their schedules were commented out in 98dc9405c Disable sync validation. The iCloud: Scheduling hourly sync validation / Scheduling daily resync log lines still print at boot and are misleading — nothing runs. The only active checks are monitorMacServerStats (minutely GET /stats: down/recovered/disk/quota emails) and this on-failure resync. A manual full resync of one or all blogs is scripts/icloud/resync.js (writes; never run without approval).

Access and safety

Ask the user before every command against production or the macserver, even read-only ones, and stick to read-only commands (log reads, pm2 describe/pm2 jlist, ls, Redis reads). Never pm2 restart, edit .env, touch the iCloud folders, or run scripts/icloud/resync.js unless explicitly asked.

  • macserver: ssh macserver (user admin, repo at /Users/admin/blot, app in app/clients/icloud/macserver, config in its .env, key ~/Projects/macserver.pem). If it fails with Load key …: Operation not permitted, the key is being read from iCloud Drive, which macOS privacy controls (TCC) block for the Claude app; ask the user to point ~/.ssh/config at a copy outside ~/Library/Mobile Documents. Check with ssh -o BatchMode=yes macserver true.
  • pm2 isn't on the PATH for non-interactive ssh (command not found: pm2). Read the log files directly: ~/.pm2/logs/macserver-out.log and macserver-error.log, rotated at midnight Mac time into macserver-{out,error}__<date>_00-00-01.log. A rotated file holds the day before its date. If you need pm2 itself, use zsh -lc 'pm2 …'.
  • brctl monitor event lines name the iCloud users who own or edited a shared item. That is personal data: fine in chat, never in the log below.
  • prod: ssh blot, containers blot-container-{blue,green,yellow} (see investigate-production-container-restarts). Macserver HTTP requests can land on any container, so grep all three. Docker logs are lost when a deploy recreates a container, so if the alert is older than the container's CreatedAt the server side is gone — say so.
  • macserver lines are prefixed with clfdate() (local time on the Mac); docker --timestamps are UTC. Note the offset when you line them up.

Method

  1. Find the resync request(s) on the macserver. The email is capped at one per blog per hour (Resync email suppressed on the server), so one email can stand for a whole burst of requests.
    ssh macserver "grep -h 'Requesting resync for blogID\|Resync acknowledged\|Failed to request resync\|Deduplicating resync' ~/.pm2/logs/macserver-*.log | tail -60"
    The (… failed after retries) suffix names the action and path. Note the time, and whether this blog (or many blogs at once) keeps doing it.
  2. Get the failure itself. Take the blog's lines around that time, dropping the raw watcher events:
    ssh macserver "grep -h '<blog12>' ~/.pm2/logs/macserver-*.log | grep -v 'Chokidar Event\|FS Watch Event' | tail -300"
    Then read the error log from the start of the window. Its multi-line stack traces don't carry timestamps, so take a line range rather than grepping:
    ssh macserver "f=~/.pm2/logs/<error log file>; n=\$(grep -n '<dd/Mon/yyyy:HH:M>' \$f | head -1 | cut -d: -f1); sed -n \"\${n},\$((n+250))p\" \$f | cut -c1-300"
    To see what the user did just before, read the raw watcher events, including Chokidar Event, FS Watch Event and brctl monitor event (adds, renames, deletes):
    ssh macserver "grep -h '<blog12>' ~/.pm2/logs/macserver-out*.log | grep '<dd/Mon/yyyy:HH>:' | grep -v 'Preparing to upload' | head -150 | cut -c1-250"
    Things to look for: failed on attempt N/4, failed after 4 attempts, Request failed:, Request timed out, the HTTP status, and macserver-side errors from the upload client (Stat failed:, Download failed: — the brctl download of an evicted file — or Failed to read file:).
  3. Check the server side for the same window:
    ssh blot "for c in blue green yellow; do echo == \$c; docker logs blot-container-\$c --timestamps 2>&1 | grep '<blog12>' | tail -150; done"
    Several server lines don't carry the blog ID (Error in /upload:, Syncing folder:, Failed to sync folder tree), so also grep those strings over a time window (awk '$1>"<UTC start>" && $1<"<UTC end>"'). Look for Error in /upload (and delete/mkdir), [ICLOUD SYNC LOCK] (423: a dashboard write or another sync held the lock), Resync requested from iCloud, Resync request deduplicated, Error in requestResync, Failed to sync folder tree, and the resync's own Syncing folder: / Resync complete status. Many failing blogs at once points to the server, so check for a deploy or restart at that time (docker ps -a, restart skill).
  4. Check the account state if the failure suggests it (409 setup incomplete, 403, error codes): the Redis hash blot:clients:icloud-drive:blogs:<blogID> (fields setupComplete, transferringToiCloud, error, errorCode, errorSince, …; see app/clients/icloud/database.js, error.js). Read it with a one-off read-only node -e inside a container (pattern in investigate-template-tags-in-content), with approval.
  5. Classify as one of:
    • Local file race (benign but noisy). The file was deleted, renamed or evicted between the watcher event and the upload (Stat failed ENOENT, a brctl download failure for a path that's gone), and the resync converged. Typical trigger: a whole folder dropped into the blog folder, then renamed or deleted, while its uploads were still queued. The server's resync then holds the lock, so the next queued mkdir/upload calls get 423 Locked, fail, and request yet another resync. Those 423 requests are kept on purpose: the server ignores a resync request while one is in flight, and a 423 from an unrelated lock holder must still lead to a resync, or the change is lost.
    • Server unavailable or slow (transient). 5xx, timeout or connection reset during a deploy, restart or overload window. Usually many blogs at once.
    • Lock contention. Repeated 423s because another sync or a dashboard write held the folder lock for longer than the retries.
    • Account/setup state. 409 (setupComplete false), 403, or a stored error code. The blog isn't fully connected.
    • Bug. The server rejected a valid request (Error in /upload with a stack, bad path encoding, size or placeholder handling), or the same path fails every time.
  6. Report to the user in chat (identifying details are fine here, never in the committed log). Include the blog, the times (Mac local and UTC), the action and path, the timeline, the classification, and whether anything needs fixing. Don't change code unless asked. If a fix is warranted, add a compact line to the root TODO.
  7. Append an entry to the Incident log below (newest last), following its privacy rules, ~5 lines. Update the Method if you found a better query.
Show full SKILL.md (346 more words)Show less

Incident log

Read this first: a repeated pattern changes the classification. Newest entries last.

Privacy: this file is committed to the repo, so entries must contain no customer information. Do not write blog IDs, handles, domains, file names, folder/file paths, post titles or anything else identifying a customer or their content; describe things generically ("an image in a subfolder was replaced while it was being uploaded"). Keep out userbase/infra size numbers too. Do give precise timestamps (Mac local and UTC, to the second) for the resync request and key events, plus the container name, so a future agent can re-find the incident while the logs still exist.

Entry template:

### <date> <HH:MM:SS> UTC resync request — <classification>
- Alert / trigger: …
- Key events (UTC, to the second): …
- Cause: …
- Follow-up: …
2026-10-07 06:08:15 UTC resync burst — local file race (benign, noisy)
  • Alert: one of a burst of ICLOUD_RESYNC_REQUESTED emails for one blog. The macserver sent at least 20 resync requests, roughly one every 10s, from 06:08:15 to 06:11:46 UTC (23:08–23:11 Mac time, -0700). Each was acknowledged on the first attempt.
  • Key events (UTC): 06:05:24, a collaborator on the shared iCloud folder added a whole code project (with .git, which is ignored, and .claude) into the blog folder. It was then renamed between an underscore and a plain name, and the folder was deleted at 06:12:09. From 06:05:55, queued uploads failed with Stat failed: ENOENT (file already moved) four times each, half a second apart, and each requested a resync. Some queued mkdirs also got 423 Locked, because the server's resync held the folder lock.
  • Server-side logs were gone: a deploy recreated all three containers at 08:16 UTC.
  • Cause: nothing broken on Blot's side. ENOENT on a queued upload is treated as a failure that needs a full resync, when it means "the file moved; a delete or rename event will follow". The 10s dedup on each side turns one folder move into one email per 10s.
  • Follow-up: fixed in the PR for this entry. A queued upload whose file is gone now logs Skipping upload: file no longer exists and requests no resync. The admin email is capped at one per blog per hour (Resync email suppressed, app/clients/icloud/util/notificationCap.js).

© blotcms, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/investigate-macserver-sync-issue of blotcms/blot.

Open the folder on GitHubat commit 92e37a1

Compare with similar skills

Investigate Macserver Sync Issue next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Investigate Macserver Sync Issue compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Investigate Macserver Sync Issue this skillblotcms/blot2k—~3kAutomated safety check: WarnAGPL-3.0
Emailasgeirtj/system_prompts_leaks69k—~3.5kAutomated safety check: PassCC0-1.0
Investigating Phishing Email Incidentmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Emailscoreyhaines31/marketingskills54k1 repos~2.6kAutomated safety check: PassMIT
Analyzing Email Headers For Phishing Investigationmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Email ManagerLeoYeAI/openclaw-master-skills2.2k—~5.5kAutomated safety check: PassMIT

Similar skills

  • Email

    asgeirtj/system_prompts_leaks

    Read or triage email, clean up an inbox, draft or send messages, and check delivery.

    69k GitHub stars~3.5k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Investigating Phishing Email Incident

    mukul975/Anthropic-Cybersecurity-Skills

    Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Emails

    coreyhaines31/marketingskills

    When the user wants to create or optimize an email sequence, drip campaign, automated email flow, or lifecycle email program.

    54k GitHub starsUsed in 1 repo~2.6k tokens
    Marketing & SEOAuto-check passed
  • Analyzing Email Headers For Phishing Investigation

    mukul975/Anthropic-Cybersecurity-Skills

    Parse and analyze email headers (Received chain, Return-Path, Message-ID) to trace the true origin of a phishing email and validate SPF, DKIM, and DMARC results to confirm or rule out sender spoofing.

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Email Manager

    LeoYeAI/openclaw-master-skills

    When user asks to write email, draft reply, manage inbox, email template, follow up email, cold email, professional email, email subject line, thank you email, apology email, meeting request email…

    2.2k GitHub stars~5.5k tokensUpdated 2 mo ago
    Writing & ContentAuto-check passed
  • Guides agents through integrating transactional email sending via Mailtrap's Email API, including sandbox testing, domain verification, and API authentication.

    275k GitHub starsUsed in 1 repo~955 tokens
    Backend & APIsAuto-check passed

More from blotcms/blot

All 8 skills in this repo
  • Review what Blot's request-time folder-link rewrite (app/blog/render/replaceFolderLinks) still does in production, from the [folder-links] and [folder-asset-origin] log lines, to decide what has to…

    2k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Investigate a "Dropbox sync issue" alert email from Blot's hourly Dropbox sync validation (each flagged blog lists unsynced changes, Fix() repairs, errors and/or a stuck folder lock; the changes…

    2k GitHub stars~3.9k tokensUpdated yesterday
    Auto-check passed
  • Work out why the blot-container-{blue,green,yellow} Docker containers from the most recent production deployment have restarted — distinguishing a normal deploy-triggered restart from a crash (V8…

    2k GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed
  • Scan the production openresty access log (/var/instance-ssd/logs/access.log) for requests with slow upstream response times (st=, the time the node containers took to answer), triage and rank them…

    2k GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Analyze production Node.js app container response times to find slow-rendering sites, cross-checking against nginx queuing delay to rule out false positives (a site only looks slow because the event…

    2k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Triage Fix() repairs reported in a "<Client sync issue" digest email (Dropbox sync issue, etc.; the "Fix() repaired:" lines under a blog) or in a "Resync found changes" email.

    2k GitHub stars~3.8k tokensUpdated yesterday
    Auto-check passed

Questions about Investigate Macserver Sync Issue

What does Investigate Macserver Sync Issue do?

Investigate an "iCloud resync requested" admin email ("A resync was requested for site blog…") or any other iCloud / macserver sync problem. Investigate Macserver Sync Issue is an agent skill from blotcms/blot. Investigate an "iCloud resync requested" admin email ("A resync was requested for site blog…") or any other iCloud / macserver sync problem.

When should I use Investigate Macserver Sync Issue?

Investigate Macserver Sync Issue fits situations like: the user pastes; forwards one of these alerts; asks to look into iCloud / macserver sync.

How do I install Investigate Macserver Sync Issue in Claude Code?

Run `npx skills add blotcms/blot --skill investigate-macserver-sync-issue -a claude-code`. Or copy the skill folder (.claude/skills/investigate-macserver-sync-issue in blotcms/blot) into .claude/skills/investigate-macserver-sync-issue in your project. Claude Code loads it when a task matches its description.

How do I install Investigate Macserver Sync Issue in Codex?

Run `npx skills add blotcms/blot --skill investigate-macserver-sync-issue -a codex`. Or copy the skill folder (.claude/skills/investigate-macserver-sync-issue in blotcms/blot) into .agents/skills/investigate-macserver-sync-issue in your project. Codex loads it when a task matches its description.

Can I use Investigate Macserver Sync Issue in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add blotcms/blot --skill investigate-macserver-sync-issue -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/investigate-macserver-sync-issue, .gemini/skills/investigate-macserver-sync-issue, .github/skills/investigate-macserver-sync-issue and .opencode/skills/investigate-macserver-sync-issue in your project.

What does Investigate Macserver Sync Issue need to run?

Going by SKILL.md and its folder, Investigate Macserver Sync Issue needs the command-line tools its instructions call (ssh, docker and node). Our summary lists: Docker.

Does Investigate Macserver Sync Issue access the network?

SKILL.md contains no URLs. Its commands use ssh and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Investigate Macserver Sync Issue safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Investigate Macserver Sync Issue use?

Investigate Macserver Sync Issue is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Investigate Macserver Sync Issue use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Investigate Macserver Sync Issue?

Skills that share tags, products or a category with Investigate Macserver Sync Issue: Email (asgeirtj/system_prompts_leaks, 69k stars), Investigating Phishing Email Incident (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Emails (coreyhaines31/marketingskills, 54k stars) and Analyzing Email Headers For Phishing Investigation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Investigate Macserver Sync Issue?

blotcms (a GitHub organization) maintains it in blotcms/blot, which has 1,983 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 7, 2026.

Source: blotcms/blot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.