TimesFM Forecasting
google-research/timesfm
Forecasts any univariate time series zero-shot with Google's TimesFM model, returning point forecasts and calibrated prediction intervals without training.
Detect cluster abnormalities by comparing recent activity (last 1h) to a baseline (preceding 24h) using the raw query tool.
$ npx skills add chmonitor/chmonitor --skill anomaly-detection -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install chmonitor/chmonitor anomaly-detection --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/anomaly-detection .claude/skills/anomaly-detection && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "anomaly-detection" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/anomaly-detection into .claude/skills/anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anomaly-detection", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/anomaly-detectionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add chmonitor/chmonitor --skill anomaly-detection -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install chmonitor/chmonitor anomaly-detection --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/anomaly-detection .agents/skills/anomaly-detection && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "anomaly-detection" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/anomaly-detection into .agents/skills/anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anomaly-detection", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add chmonitor/chmonitor --skill anomaly-detection -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install chmonitor/chmonitor anomaly-detection --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/anomaly-detection .cursor/skills/anomaly-detection && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "anomaly-detection" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/anomaly-detection into .cursor/skills/anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anomaly-detection", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/chmonitor/chmonitor.git --path .agents/skills/anomaly-detection--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add chmonitor/chmonitor --skill anomaly-detection -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install chmonitor/chmonitor anomaly-detection --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/anomaly-detection .gemini/skills/anomaly-detection && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "anomaly-detection" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/anomaly-detection into .gemini/skills/anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anomaly-detection", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install chmonitor/chmonitor anomaly-detectionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add chmonitor/chmonitor --skill anomaly-detection -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/anomaly-detection .github/skills/anomaly-detection && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "anomaly-detection" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/anomaly-detection into .github/skills/anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anomaly-detection", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add chmonitor/chmonitor --skill anomaly-detection -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install chmonitor/chmonitor anomaly-detection --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/anomaly-detection .opencode/skills/anomaly-detection && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "anomaly-detection" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/anomaly-detection into .opencode/skills/anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anomaly-detection", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
anomaly-detectionDetect cluster abnormalities by comparing recent activity (last 1h) to a baseline (preceding 24h) using the raw query tool.
Anomaly Detection is an agent skill from chmonitor/chmonitor. Detect cluster abnormalities by comparing recent activity (last 1h) to a baseline (preceding 24h) using the raw query tool.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Data & Analytics, covering Anomaly detection. The repository describes itself as: Open-source operational advisor for ClickHouse — real-time monitoring plus AI-driven index/partition/materialized-view recommendations. The licence is GPL-3.0.
Read from SKILL.md and the folder at commit fc39ef0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are sql).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Anomaly Detection loads about 2.3k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 353 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from chmonitor/chmonitor at commit fc39ef0, republished under its GPL-3.0 licence (© chmonitor). 353 words, ~2,277 tokens.
.claude/skills/anomaly-detection/SKILL.md (or your agent's skills folder).Use this skill when no dedicated tool covers anomaly detection. All recipes below
use the query tool with raw SQL. Compare a recent window (last 1 hour) to a
baseline window (preceding 24 hours) and surface ratios or deltas that exceed
the thresholds in the interpretation section.
Column availability varies by ClickHouse version — load system-tables-reference
before modifying any query.
Source: system.query_log (per-query granularity) + system.errors (server-wide counters).
-- Ratio of failed queries: recent vs baseline
-- recent = last 1 hour, baseline = prior 24 hours
SELECT
countIf(type = 'ExceptionWhileProcessing' AND event_time >= now() - INTERVAL 1 HOUR) AS recent_failures,
countIf(type != 'QueryStart' AND event_time >= now() - INTERVAL 1 HOUR) AS recent_total,
countIf(type = 'ExceptionWhileProcessing' AND event_time < now() - INTERVAL 1 HOUR
AND event_time >= now() - INTERVAL 25 HOUR) AS baseline_failures,
countIf(type != 'QueryStart' AND event_time < now() - INTERVAL 1 HOUR
AND event_time >= now() - INTERVAL 25 HOUR) AS baseline_total,
round(recent_failures / nullIf(recent_total, 0) * 100, 2) AS recent_error_pct,
round(baseline_failures / nullIf(baseline_total, 0) * 100, 2) AS baseline_error_pct
FROM system.query_log
WHERE is_initial_query = 1-- Top error codes in the recent window
SELECT exception_code, count() AS n, any(exception) AS sample
FROM system.query_log
WHERE type = 'ExceptionWhileProcessing'
AND is_initial_query = 1
AND event_time >= now() - INTERVAL 1 HOUR
GROUP BY exception_code
ORDER BY n DESC
LIMIT 20-- system.errors: codes whose value jumped since last hour
-- (no time column — compare last_error_time as a proxy)
SELECT name, code, value, last_error_time, last_error_message
FROM system.errors
WHERE last_error_time >= now() - INTERVAL 1 HOUR
ORDER BY value DESC
LIMIT 20Source: system.query_log.
-- p95 duration: recent 1h vs baseline 24h
SELECT
quantileIf(0.95)(query_duration_ms,
event_time >= now() - INTERVAL 1 HOUR) AS p95_recent_ms,
quantileIf(0.95)(query_duration_ms,
event_time < now() - INTERVAL 1 HOUR
AND event_time >= now() - INTERVAL 25 HOUR) AS p95_baseline_ms,
round(p95_recent_ms / nullIf(p95_baseline_ms, 0), 2) AS ratio
FROM system.query_log
WHERE type = 'QueryFinish'
AND is_initial_query = 1
AND event_time >= now() - INTERVAL 25 HOUR-- Break down by user to find who regressed
SELECT
user,
quantileIf(0.95)(query_duration_ms,
event_time >= now() - INTERVAL 1 HOUR) AS p95_recent_ms,
quantileIf(0.95)(query_duration_ms,
event_time < now() - INTERVAL 1 HOUR
AND event_time >= now() - INTERVAL 25 HOUR) AS p95_baseline_ms,
round(p95_recent_ms / nullIf(p95_baseline_ms, 0), 2) AS ratio
FROM system.query_log
WHERE type = 'QueryFinish'
AND is_initial_query = 1
AND event_time >= now() - INTERVAL 25 HOUR
GROUP BY user
ORDER BY ratio DESC
LIMIT 20Source: system.query_log.
-- Queries per minute: recent 1h vs baseline hourly average
SELECT
countIf(event_time >= now() - INTERVAL 1 HOUR) AS recent_count,
countIf(event_time < now() - INTERVAL 1 HOUR
AND event_time >= now() - INTERVAL 25 HOUR) / 24 AS baseline_hourly_avg,
round(recent_count / nullIf(baseline_hourly_avg, 0), 2) AS ratio
FROM system.query_log
WHERE type != 'QueryStart'
AND is_initial_query = 1
AND event_time >= now() - INTERVAL 25 HOUR-- Per-minute breakdown of the last 2 hours (spot sudden spikes or drops)
SELECT
toStartOfMinute(event_time) AS minute,
count() AS queries
FROM system.query_log
WHERE type != 'QueryStart'
AND is_initial_query = 1
AND event_time >= now() - INTERVAL 2 HOUR
GROUP BY minute
ORDER BY minuteSource: system.query_log (memory_usage is per-query peak).
-- Peak memory_usage: recent p95 vs baseline p95
SELECT
quantileIf(0.95)(memory_usage,
event_time >= now() - INTERVAL 1 HOUR) AS p95_recent_bytes,
quantileIf(0.95)(memory_usage,
event_time < now() - INTERVAL 1 HOUR
AND event_time >= now() - INTERVAL 25 HOUR) AS p95_baseline_bytes,
formatReadableSize(p95_recent_bytes) AS p95_recent,
formatReadableSize(p95_baseline_bytes) AS p95_baseline,
round(p95_recent_bytes / nullIf(p95_baseline_bytes, 0), 2) AS ratio
FROM system.query_log
WHERE type = 'QueryFinish'
AND is_initial_query = 1
AND event_time >= now() - INTERVAL 25 HOUR-- Top memory consumers in the last hour
SELECT
user, substring(query, 1, 200) AS query_preview,
formatReadableSize(memory_usage) AS mem,
query_duration_ms
FROM system.query_log
WHERE type = 'QueryFinish'
AND is_initial_query = 1
AND event_time >= now() - INTERVAL 1 HOUR
ORDER BY memory_usage DESC
LIMIT 10-- Current server-wide memory tracking (instantaneous)
SELECT metric, value, description
FROM system.metrics
WHERE metric IN ('MemoryTracking', 'MemoryAllocated')Source: system.parts. High active-part counts per table indicate merge
backpressure or excessive insert batching.
-- Tables with the most active parts right now
SELECT
database,
table,
count() AS active_parts,
sum(rows) AS total_rows,
formatReadableSize(sum(bytes_on_disk)) AS disk_size
FROM system.parts
WHERE active = 1
GROUP BY database, table
ORDER BY active_parts DESC
LIMIT 30-- Flag tables that exceeded a threshold in the last day
-- (join today vs yesterday snapshot via modification_time proxy)
SELECT
database,
table,
countIf(modification_time >= now() - INTERVAL 1 HOUR) AS parts_added_1h,
countIf(modification_time >= now() - INTERVAL 25 HOUR) AS parts_total_25h,
count() AS active_parts
FROM system.parts
WHERE active = 1
GROUP BY database, table
HAVING active_parts > 300 OR parts_added_1h > 50
ORDER BY active_parts DESC
LIMIT 20Use the get_merge_status tool to check if background merges are keeping up. See
troubleshooting for error code 252 (too many parts).
Source: system.replicas. absolute_delay is seconds behind the leader.
-- Tables with non-zero replication lag
SELECT
database,
table,
is_leader,
is_readonly,
absolute_delay,
queue_size,
inserts_in_queue,
merges_in_queue,
active_replicas,
total_replicas
FROM system.replicas
WHERE absolute_delay > 0 OR is_readonly = 1 OR active_replicas < total_replicas
ORDER BY absolute_delay DESC-- Trend: max absolute_delay across all replicated tables
SELECT
database,
table,
absolute_delay,
formatReadableTimeDelta(absolute_delay) AS lag_human
FROM system.replicas
ORDER BY absolute_delay DESC
LIMIT 10For diagnosis and recovery steps, load the replication-guide skill.
| Signal | Threshold (guide, not absolute) | Action |
|---|---|---|
Error-rate ratio recent_error_pct / baseline_error_pct | > 2× | Investigate top error codes; load troubleshooting |
| p95 duration ratio | > 1.5× | Check new/changed queries, index usage; load query-optimization |
| Query volume ratio | < 0.3× or > 3× | Verify application health; check for batch jobs or traffic anomaly |
| Memory p95 ratio | > 2× | Find heavy queries; consider max_memory_usage; load troubleshooting |
active_parts per table | > 300 (MergeTree default warn zone) | Check merge queue via get_merge_status; consider OPTIMIZE |
absolute_delay | > 300 s (5 min) | Replication is lagging; load replication-guide |
Noise vs real anomaly: a ratio spike in a 1-hour window with fewer than ~50
total events is likely noise (small sample). Check the raw counts (recent_total,
baseline_total) before escalating. A sustained anomaly across two consecutive
1-hour windows is more actionable.
Baseline window caveat: the 24-hour baseline includes the recent 1 hour in
some queries above for simplicity. If you want a strictly prior baseline, replace
INTERVAL 25 HOUR with INTERVAL 24 HOUR and add AND event_time < now() - INTERVAL 1 HOUR to the baseline predicate.
system-tables-reference — exact column names before modifying any SQL abovetroubleshooting — error codes, OOM, stuck mutationsreplication-guide — replication lag diagnosis and recoveryquery-optimization — EXPLAIN, PREWHERE, JOIN tuning for duration regressionsstorage-optimization — disk pressure if part-count explosion fills the disk© chmonitor, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/anomaly-detection of chmonitor/chmonitor.
Open the folder on GitHubat commit fc39ef0
Anomaly Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Anomaly Detection this skillchmonitor/chmonitor | 299 | — | ~2.3k | Automated safety check: Pass | GPL-3.0 | |
| TimesFM Forecastinggoogle-research/timesfm | 34k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | |
| Anomalib Adding A Modelopen-edge-platform/anomalib | 6.2k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Anomalib Tiled Ensembleopen-edge-platform/anomalib | 6.2k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Kqlmicrosoft/fabric-rti-mcp | 131 | — | ~6.2k | Automated safety check: Pass | MIT | |
| Time Series Analytics Useropen-edge-platform/edge-ai-libraries | 169 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 |
google-research/timesfm
Forecasts any univariate time series zero-shot with Google's TimesFM model, returning point forecasts and calibrated prediction intervals without training.
open-edge-platform/anomalib
Adds a new anomaly-detection model to anomalib under src/anomalib/models/.
open-edge-platform/anomalib
Runs and configures the anomalib tiled-ensemble pipeline, which trains/evaluates one model per image tile and merges results (with optional seam smoothing) for high-resolution anomaly detection.
microsoft/fabric-rti-mcp
KQL language expertise for writing correct, efficient Kusto queries using the Fabric RTI MCP tools.
open-edge-platform/edge-ai-libraries
Build a new time-series analytics use case on top of the deployed Time Series Analytics microservice — bring it up with Docker Compose (from a repo clone, or by fetching the compose files from…
Dynatrace/dynatrace-for-ai
Analyze dashboards and notebooks using Davis analyzers — anomaly detection, novelty scoring, and correlation.
chmonitor/chmonitor
Non-animation creative direction for HyperFrames videos. An agent skill from chmonitor/chmonitor.
chmonitor/chmonitor
Audio and media assets for HyperFrames compositions, produced by one shared audio engine (scripts/audio.mjs) — multi-provider TTS (HeyGen / ElevenLabs / Kokoro local), background music + sound…
chmonitor/chmonitor
Port an existing Remotion (React) composition to HyperFrames HTML.
chmonitor/chmonitor
A skill your agent uses when the user has a music track (an audio file, or a video to pull audio from) and wants a beat-synced HyperFrames video, calm to hard-hitting.
chmonitor/chmonitor
All animation knowledge for HyperFrames — atomic motion rules, multi-phase scene blueprints, scene transitions, broader motion-design techniques, AND the seven runtime adapters (GSAP default, plus…
chmonitor/chmonitor
turn arbitrary text — an article, notes, a topic, a brief — into a faceless explainer video, up to ~3 min (sweet spot 30-90s), where every visual is invented (typography, abstract graphics…
Categories
Detect cluster abnormalities by comparing recent activity (last 1h) to a baseline (preceding 24h) using the raw query tool. Anomaly Detection is an agent skill from chmonitor/chmonitor. Detect cluster abnormalities by comparing recent activity (last 1h) to a baseline (preceding 24h) using the raw query tool.
Anomaly Detection fits situations like: tasks that involve Anomaly detection.
Run `npx skills add chmonitor/chmonitor --skill anomaly-detection -a claude-code`. Or copy the skill folder (.agents/skills/anomaly-detection in chmonitor/chmonitor) into .claude/skills/anomaly-detection in your project. Claude Code loads it when a task matches its description.
Run `npx skills add chmonitor/chmonitor --skill anomaly-detection -a codex`. Or copy the skill folder (.agents/skills/anomaly-detection in chmonitor/chmonitor) into .agents/skills/anomaly-detection in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add chmonitor/chmonitor --skill anomaly-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/anomaly-detection, .gemini/skills/anomaly-detection, .github/skills/anomaly-detection and .opencode/skills/anomaly-detection in your project.
SKILL.md names no scripts, command-line tools or credentials: Anomaly Detection is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Anomaly Detection is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Anomaly Detection: TimesFM Forecasting (google-research/timesfm, 34k stars), Anomalib Adding A Model (open-edge-platform/anomalib, 6.2k stars), Anomalib Tiled Ensemble (open-edge-platform/anomalib, 6.2k stars) and Kql (microsoft/fabric-rti-mcp, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
chmonitor (a GitHub organization) maintains it in chmonitor/chmonitor, which has 299 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 5, 2026.
Source: chmonitor/chmonitor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.