Agent skill

Flight Recorder

by bolivian-peru in bolivian-peru/os-moda

Black box flight recorder for the server. An agent skill from bolivian-peru/os-moda.

Apache-2.0Auto-check passedSecurity

Install Flight Recorder

skills CLI
$ npx skills add bolivian-peru/os-moda --skill flight-recorder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bolivian-peru/os-moda flight-recorder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bolivian-peru/os-moda.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/flight-recorder .claude/skills/flight-recorder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
flight-recorder
GitHub stars
119
Token cost
~624 tokens
SKILL.md length
90 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Black box flight recorder for the server. An agent skill from bolivian-peru/os-moda.

  • Works in 4 steps: Pull flight recorder snapshots → Pull journal logs for the incident window → Pull audit ledger → …
  • Tasks that involve Digital forensics
  • SKILL.md covers Snapshot Capture (run every 5…, Post-Incident Analysis and Data Retention
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Flight Recorder is an agent skill from bolivian-peru/os-moda. Black box flight recorder for the server. Capture system state snapshots for forensic analysis after incidents. Continuous telemetry ring buffer.

Its SKILL.md is about 620 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Digital forensics. The repository describes itself as: An operating system built for AI agents — talk to your NixOS server instead of SSH-ing in. Typed, audited tool access with atomic rollback on every change. Research-grade; run it… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Digital forensics

Example prompts

  • “/flight-recorder”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Pull flight recorder snapshots
  2. Pull journal logs for the incident window
  3. Pull audit ledger
  4. Reconstruct the incident

What it can do on your machine

Read from SKILL.md and the folder at commit b8e418f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Flight Recorder loads about 624 tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 90 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~624

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bolivian-peru/os-moda at commit b8e418f, republished under its Apache-2.0 licence (© bolivian-peru). 90 words, ~624 tokens.

Download SKILL.mdSave it as .claude/skills/flight-recorder/SKILL.md (or your agent's skills folder).
name
flight-recorder
description
Black box flight recorder for the server. Capture system state snapshots for forensic analysis after incidents. Continuous telemetry ring buffer.
tools
system_health, shell_exec, journal_logs, event_log, memory_store, memory_recall
activation
auto

Flight Recorder — Server Black Box

Continuous state capture for post-incident forensics.

Snapshot Capture (run every 5 minutes via heartbeat)

Capture a lightweight system snapshot:

system_health()
shell_exec({ command: "ps aux --sort=-%mem | head -10" })
shell_exec({ command: "ss -s" })  # connection summary

Store as a compact memory entry:

memory_store({
  summary: "Flight recorder: CPU 12%, RAM 4.1G, load 0.3, 142 connections",
  detail: "Top processes: postgres 1.2G, openclaw 380M, node 210M. Net: 142 established, 12 listening.",
  category: "system.config",
  tags: "flight-recorder,snapshot,telemetry"
})

Post-Incident Analysis

When investigating "what happened at 3 AM":

1. Pull flight recorder snapshots
memory_recall({ query: "flight-recorder snapshot", timeframe: "24h", max_results: 50 })
2. Pull journal logs for the incident window
journal_logs({ since: "2 hours ago", priority: "warning", lines: 100 })
3. Pull audit ledger
event_log({ limit: 50 })
4. Reconstruct the incident

Present a forensic timeline:

Incident Report — Server Crash at 03:12 UTC

Timeline:
  02:00  Flight recorder: CPU 15%, RAM 5.2G (normal)
  02:30  Flight recorder: CPU 23%, RAM 5.8G (rising)
  02:47  Flight recorder: CPU 89%, RAM 7.1G (critical)
  02:47  OOM killer triggered (killed: postgres worker)
  02:48  PostgreSQL: 3 connections terminated
  02:49  App health check failed → Caddy returned 502
  02:51  systemd restarted PostgreSQL automatically
  02:52  All services recovered
  02:55  Flight recorder: CPU 12%, RAM 4.1G (normal)

Root cause: PostgreSQL autovacuum on users table (12M rows)
during traffic spike. Memory peaked at 7.4/7.6 GB.

Recommendations:
  1. Add 2GB swap (NixOS config change)
  2. Schedule autovacuum for low-traffic hours
  3. Consider 16GB RAM plan ($6/mo more on Hetzner)

All data sourced from flight recorder snapshots,
journal logs, and audit ledger. Chain verified.

Data Retention

Flight recorder snapshots are compact (~200 bytes each). At 5-minute intervals: 288/day, ~56KB/day, ~1.7MB/month. Keep 30 days of snapshots. Memory recall handles the rest.

© bolivian-peru, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/flight-recorder of bolivian-peru/os-moda.

Open the folder on GitHubat commit b8e418f

Compare with similar skills

Flight Recorder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Flight Recorder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Flight Recorder this skillbolivian-peru/os-moda119—~624Automated safety check: PassApache-2.0
Campaign Attribution Evidence Analysismukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Oss ForensicsTommy-yw/RunbookHermes5463 repos~5kAutomated safety check: PassMIT
Ctf Malwareljagiello/ctf-skills3.4k—~2.1kAutomated safety check: NotesMIT
LNK and Jump List Forensicsmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Malware Persistence Analysis with Autorunsmukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.0

Similar skills

  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Oss Forensics

    Tommy-yw/RunbookHermes

    Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.

    546 GitHub starsUsed in 3 repos~5k tokens
    SecurityAuto-check passed
  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub stars~2.1k tokensUpdated 27 days ago
    SecurityAuto-check: notes
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    563 GitHub stars~1.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from bolivian-peru/os-moda

All 17 skills in this repo
  • App Deployer

    bolivian-peru/os-moda

    Deploy and manage user applications as managed systemd services

    119 GitHub stars~774 tokensUpdated 3 mo ago
    Auto-check passed
  • Deploy AI Agent

    bolivian-peru/os-moda

    Deploy and manage AI agent workloads with GPU checks, API key management, and health monitoring

    119 GitHub stars~1.1k tokensUpdated 3 mo ago
    Auto-check passed
  • Drift Detection

    bolivian-peru/os-moda

    Detect configuration drift — manual changes that exist outside NixOS management.

    119 GitHub stars~584 tokensUpdated 3 mo ago
    Auto-check passed
  • Generation Timeline

    bolivian-peru/os-moda

    NixOS generation-aware debugging and time-travel. An agent skill from bolivian-peru/os-moda.

    119 GitHub stars~777 tokensUpdated 3 mo ago
    Auto-check passed
  • Morning Briefing

    bolivian-peru/os-moda

    Generate a concise daily infrastructure briefing. An agent skill from bolivian-peru/os-moda.

    119 GitHub stars~897 tokensUpdated 3 mo ago
    Auto-check passed
  • Natural Language Config

    bolivian-peru/os-moda

    Translate natural language requests into NixOS configuration changes.

    119 GitHub stars~761 tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Flight Recorder

What does Flight Recorder do?

Black box flight recorder for the server. An agent skill from bolivian-peru/os-moda. Flight Recorder is an agent skill from bolivian-peru/os-moda. Black box flight recorder for the server.

When should I use Flight Recorder?

Flight Recorder fits situations like: tasks that involve Digital forensics.

How do I install Flight Recorder in Claude Code?

Run `npx skills add bolivian-peru/os-moda --skill flight-recorder -a claude-code`. Or copy the skill folder (skills/flight-recorder in bolivian-peru/os-moda) into .claude/skills/flight-recorder in your project. Claude Code loads it when a task matches its description.

How do I install Flight Recorder in Codex?

Run `npx skills add bolivian-peru/os-moda --skill flight-recorder -a codex`. Or copy the skill folder (skills/flight-recorder in bolivian-peru/os-moda) into .agents/skills/flight-recorder in your project. Codex loads it when a task matches its description.

Can I use Flight Recorder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bolivian-peru/os-moda --skill flight-recorder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/flight-recorder, .gemini/skills/flight-recorder, .github/skills/flight-recorder and .opencode/skills/flight-recorder in your project.

What does Flight Recorder need to run?

SKILL.md names no scripts, command-line tools or credentials: Flight Recorder is instructions for the agent only.

Does Flight Recorder access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Flight Recorder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Flight Recorder use?

Flight Recorder is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Flight Recorder use?

About 624 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Flight Recorder?

Skills that share tags, products or a category with Flight Recorder: Campaign Attribution Evidence Analysis (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Oss Forensics (Tommy-yw/RunbookHermes, 546 stars), Ctf Malware (ljagiello/ctf-skills, 3.4k stars) and LNK and Jump List Forensics (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Flight Recorder?

bolivian-peru (a GitHub user) maintains it in bolivian-peru/os-moda, which has 119 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on June 24, 2026.

Source: bolivian-peru/os-moda on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.