Agent skill

Pstack

by chmonitor in chmonitor/chmonitor

Project-local pstack validation router for chmonitor. An agent skill from chmonitor/chmonitor.

GPL-3.0Auto-check passedDevOps & Cloud

Install Pstack

skills CLI
$ npx skills add chmonitor/chmonitor --skill pstack -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install chmonitor/chmonitor pstack --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/pstack .claude/skills/pstack && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pstack
GitHub stars
298
Token cost
~2.3k tokens
SKILL.md length
1,184 words
Files
18
Skills in repo
53
Repo updated
First seen
Licence
GPL-3.0

At a glance

Project-local pstack validation router for chmonitor. An agent skill from chmonitor/chmonitor.

  • Works in 5 steps: Read the matching file under features/. → Choose the CI job that owns the changed… → Drive the smallest mapped path that can… → …
  • Proving a dashboard
  • SKILL.md covers Operating rules, UI and mode contracts, Launch and Doctor, plus 4 more sections
  • Calls gh, git and bun; needs CHM_API_KEY_SECRET

What it does

Pstack is an agent skill from chmonitor/chmonitor. Project-local pstack validation router for chmonitor. Use when proving a dashboard, API, auth or security, PeerDB, alerts and webhooks, Helm and GitOps, deployment, or CLI change. Prefer CI checks and capture observable evidence instead of running heavy local builds.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files (for example `README.md`, `features/README.md` and `features/api-auth-security.md`).

It sits in DevOps & Cloud, covering Container orchestration, Webhooks and GitOps. The repository describes itself as: Open-source operational advisor for ClickHouse — real-time monitoring plus AI-driven index/partition/materialized-view recommendations. The licence is GPL-3.0.

When your agent uses it

  • Proving a dashboard
  • Alerts and webhooks
  • Helm and GitOps

Example prompts

  • “/pstack”

Requirements

  • Docker
  • A credential in CHM_API_KEY_SECRET

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read the matching file under features/.
  2. Choose the CI job that owns the changed surface. Prefer required checks for
  3. Drive the smallest mapped path that can fail for the claimed behavior.
  4. If the job is pending, report pending, not verified. If its prerequisite
  5. Re-run the same observation after a fix. Do not claim that a proxy, a test

What it can do on your machine

Read from SKILL.md and the folder at commit fc39ef0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git
    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CHM_API_KEY_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pstack loads about 2.3k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 1,184 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from chmonitor/chmonitor at commit fc39ef0, republished under its GPL-3.0 licence (© chmonitor). 1,184 words, ~2,318 tokens.

Download SKILL.mdSave it as .claude/skills/pstack/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.
name
pstack
description
Project-local pstack validation router for chmonitor. Use when proving a dashboard, API, auth or security, PeerDB, alerts and webhooks, Helm and GitOps, deployment, or CLI change. Prefer CI checks and capture observable evidence instead of running heavy local builds.

chmonitor pstack validation

This is a project-local adapter to the pstack method from michael-denyer/pstack-claude. The adapter adds chmonitor's CI-first validation contract and feature map; it also has a pinned, supplemental copy of the upstream skills-only tree at upstream/. The source, loading boundary, and provenance are documented in README.md and upstream/SOURCE.md. The maintained feature map starts at features/README.md, and the inventory and CI matrix are in docs/knowledge/pstack-validation.md.

Use this skill as the project rule for validation. The default proof is the CI run for the commit under review. Do not infer that a change works because a local file parses, a build used to pass, or a proxy reports a cached result.

Operating rules

  • CI owns dependency installation, lint, type checks, unit tests, builds, browser test setup, Rust builds, Helm rendering, and deployment checks.
  • Do not start a local app, install a QA toolchain, or run a heavy pnpm, bun, cargo, helm, docker, or browser command by default. Use the matching workflow and capture its job result instead.
  • Use stable user entry points and observable state. Do not use internal setters, a different route, or a mocked response as a substitute for the mapped feature.
  • A missing path-filtered job is not a pass. Record the exact workflow, trigger, and prerequisite that were absent.
  • Use verified, verified-unreachable, or blocked as the result. Never silently turn a skipped or non-required check into verified.
  • Keep credentials, cookies, API keys, passwords, private webhook URLs, and full response bodies containing them out of commands, logs, and evidence.
  • The parent OpenCode runtime owns the model choice. This skill does not override the configured model or add Claude-only slash commands.

UI and mode contracts

Use the product-design and cloud-saas-mode skills as the expected-state reference while reviewing CI evidence. In particular, a dashboard proof should respect the existing semantic-token and shadcn boundary, the ?host=N route contract, hooks at the deepest consumer, the shared loading/empty/error states, and the stale-data behavior. Do not “fix” a UI proof by editing components/ui/ or by creating a new visual primitive in this skill.

For cloud and auth claims, keep OSS and Cloud behavior distinct. Public demo visibility, hidden demo data for signed-in users, per-user connection isolation, and anonymous guest-agent exceptions are contracts to test, not alternate interpretations of a failed response.

For dashboard UI expectations, read the sibling product-design skill. For cloud, auth, and per-user connection boundaries, read cloud-saas-mode. The older verify-chmonitor skill is still the detailed local CLI/TUI recipe. Use it only for a requested CLI proof, not as a substitute for the CI matrix.

Launch

For a pull request, launch means identifying the CI run for the exact commit. Start with file inspection and the checks API:

bash
git status --short --branch
git diff --name-only origin/main...HEAD
gh pr checks <PR> --watch=false

Map changed paths to the workflows in the feature file. A deployment change can be path-filtered, so also inspect the run's job list before deciding that a surface was not exercised.

For a post-deploy smoke proof, use the existing dashboard harness from its package directory. The unauthenticated form needs no secret:

bash
cd apps/dashboard
bun scripts/verify-deploy.ts --skip-auth

The Cloudflare workflow supplies CHM_API_KEY_SECRET only inside CI and calls the same script for its authenticated deployment check. Do not copy that variable into a local shell, a commit, or a transcript.

A CLI proof has a different launch model. The existing helper builds this checkout's Rust binary, so it is optional and heavier than the CI path:

bash
.cursor/skills/verify-chmonitor/scripts/launch.sh

Do not run the helper merely to validate documentation. The Rust workflow owns the normal build and test proof.

Doctor

Run a read-only identity and scope check before interpreting a result:

bash
git status --short --branch
git diff --check
gh pr checks <PR> --watch=false

For an approved live deployment, distinguish the three health contracts before making a claim:

  • GET /healthz is the static process liveness endpoint.
  • GET /api/health is the minimal public deployment health response.
  • GET /api/healthz is ClickHouse-gated readiness and may return 503 while the monitored database is unavailable.

Use the current workflow URL and the existing verify-deploy.ts rather than inventing a request or copying a secret-bearing curl. For the CLI, the identity-only doctor helper is .cursor/skills/verify-chmonitor/scripts/doctor.sh; it does not contact the hosted dashboard by default. A failed connectivity row after an identity pass is a separate observation, not proof of a wrong binary.

Show full SKILL.md (498 more words)Show less

Drive

  1. Read the matching file under features/.
  2. Choose the CI job that owns the changed surface. Prefer required checks for merge claims and use informational checks as supporting evidence.
  3. Drive the smallest mapped path that can fail for the claimed behavior.
  4. If the job is pending, report pending, not verified. If its prerequisite is absent, report verified-unreachable with the route or command attempted and the unmet prerequisite.
  5. Re-run the same observation after a fix. Do not claim that a proxy, a test fixture, or a different surface repaired the original failure.

The feature files name the concrete workflow paths, route shapes, and test families. They do not ask an agent to run a local build as a substitute for a red or absent CI job.

Evidence

For each feature, record the following in the handoff or an uncommitted run note:

  • commit SHA, pull request, workflow, job, and check status;
  • the user entry point or API route driven;
  • the expected state and the state actually observed;
  • the CI log or artifact location, when one exists;
  • the result label: verified, verified-unreachable, or blocked.

A useful failure citation includes the assertion, route, and job output rather than a generic “CI passed.” For a deployed smoke check, save the JSON report from verify-deploy.ts in a protected scratch location and redact it before sharing. A compile, lint, or passing unit test is evidence for that check only; it is not evidence that a UI, external service, or webhook behaved correctly.

When a check fails, inspect the durable record first. The repository documents gh run view <RUN_ID> --job <JOB_ID> --log-failed for failed-job logs. Quote the relevant output, not a secret-bearing environment dump.

Cleanup

CI runs and deployed workers are shared infrastructure. Do not cancel a shared workflow, kill a process by name, or mutate a hosted connection to make a proof look better.

If the optional local CLI helper was used, tear down only the session and scratch state that it created:

bash
.cursor/skills/verify-chmonitor/scripts/cleanup.sh

Keep proof artifacts. Remove temporary browser profiles, local config scratch, and test doubles after they have been checked for secrets. Never remove the operator's normal ~/.config/chm or a shared deployment as cleanup.

Helpers

Use helpers only when their source is present in this checkout and their output can be redacted.

HelperUseBoundary
gh pr checks <PR> --watch=falseRead the current CI resultThe normal project proof.
gh run view <RUN_ID> --job <JOB_ID> --log-failedInspect a failed jobDo not paste secrets.
apps/dashboard/scripts/verify-deploy.tsProbe a live WorkerCI injects credentials; --skip-auth is the local safe form.
.cursor/skills/verify-chmonitor/scripts/doctor.shProve CLI binary identityOptional local helper; not the merge gate.
.cursor/skills/verify-chmonitor/scripts/drive.shDrive one mapped CLI featureRequires the isolated CLI setup.
.cursor/skills/verify-chmonitor/scripts/cleanup.shRemove helper-created statePreserve evidence.
.cursor/skills/verify-chmonitor/scripts/redact-check.shCheck a CLI evidence directoryRun only on a redacted copy.
.claude/skills/ui-ux-audit/Manual broad browser auditLegacy target details; not the default CI path.

Keep the local feature map and docs/knowledge/pstack-validation.md in sync when a route, workflow, or verification contract changes.

© chmonitor, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 17 other files in .claude/skills/pstack of chmonitor/chmonitor.

  • SKILL.md
  • README.md
  • features/README.md
  • features/api-auth-security.md
  • features/custom-webhooks.md
  • features/dashboard-ui.md
  • features/deploy-cli.md
  • features/helm-gitops.md
  • features/peerdb.md
  • upstream/CHANGES.md
  • upstream/LICENSE
  • upstream/LICENSE-cursor-team-kit
  • upstream/NOTICE-skills.md
  • upstream/NOTICE.md
  • upstream/README.md
  • upstream/SOURCE.md
  • upstream/VERSION
  • upstream/skills

Open the folder on GitHubat commit fc39ef0

Compare with similar skills

Pstack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pstack compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pstack this skillchmonitor/chmonitor298—~2.3kAutomated safety check: PassGPL-3.0
Gitops Cluster Debugfluxcd/agent-skills230—~4.2kAutomated safety check: PassApache-2.0
Kubernetes ArchitectCybereason-Public/owLSM2808 repos~2.6kAutomated safety check: PassGPL-2.0
Kubernetes SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Devopsnicepkg/auto-company1922 repos~814Automated safety check: PassMIT
Gitops Repo Auditfluxcd/agent-skills230—~3.8kAutomated safety check: PassApache-2.0

Similar skills

  • Gitops Cluster Debug

    fluxcd/agent-skills

    Debug and troubleshoot Flux CD on live Kubernetes clusters (not local repo files) via the Flux MCP server — inspects Flux resource status, reads controller logs, traces dependency chains, and…

    230 GitHub stars~4.2k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Kubernetes Architect

    Cybereason-Public/owLSM

    Expert Kubernetes architect specializing in cloud-native infrastructure, advanced GitOps workflows (ArgoCD/Flux), and enterprise container orchestration.

    280 GitHub starsUsed in 8 repos~2.6k tokens
    DevOps & CloudAuto-check passed
  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    192 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed
  • Gitops Repo Audit

    fluxcd/agent-skills

    Audit and validate Flux CD GitOps repositories by scanning local repo files (not live clusters) — runs Kubernetes schema validation, detects deprecated Flux APIs, reviews RBAC/multi-tenancy/secrets…

    230 GitHub stars~3.8k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Cluster Health

    Diaoul/home-ops

    Full cluster health check for the home-ops Kubernetes cluster.

    120 GitHub stars~2.7k tokensUpdated today
    DevOps & CloudAuto-check passed

More from chmonitor/chmonitor

All 53 skills in this repo
  • Hyperframes Creative

    chmonitor/chmonitor

    Non-animation creative direction for HyperFrames videos. An agent skill from chmonitor/chmonitor.

    298 GitHub starsUsed in 5 repos~1.3k tokens
    Auto-check passed
  • Hyperframes Media

    chmonitor/chmonitor

    Audio and media assets for HyperFrames compositions, produced by one shared audio engine (scripts/audio.mjs) — multi-provider TTS (HeyGen / ElevenLabs / Kokoro local), background music + sound…

    298 GitHub starsUsed in 1 repo~2.8k tokens
    Auto-check: notes
  • Remotion To Hyperframes

    chmonitor/chmonitor

    Port an existing Remotion (React) composition to HyperFrames HTML.

    298 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Music To Video

    chmonitor/chmonitor

    A skill your agent uses when the user has a music track (an audio file, or a video to pull audio from) and wants a beat-synced HyperFrames video, calm to hard-hitting.

    298 GitHub starsUsed in 1 repo~4k tokens
    Auto-check: notes
  • Hyperframes Animation

    chmonitor/chmonitor

    All animation knowledge for HyperFrames — atomic motion rules, multi-phase scene blueprints, scene transitions, broader motion-design techniques, AND the seven runtime adapters (GSAP default, plus…

    298 GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • Faceless Explainer

    chmonitor/chmonitor

    turn arbitrary text — an article, notes, a topic, a brief — into a faceless explainer video, up to ~3 min (sweet spot 30-90s), where every visual is invented (typography, abstract graphics…

    298 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check: notes

Categories

Questions about Pstack

What does Pstack do?

Project-local pstack validation router for chmonitor. An agent skill from chmonitor/chmonitor. Pstack is an agent skill from chmonitor/chmonitor. Project-local pstack validation router for chmonitor.

When should I use Pstack?

Pstack fits situations like: proving a dashboard; alerts and webhooks; helm and GitOps.

How do I install Pstack in Claude Code?

Run `npx skills add chmonitor/chmonitor --skill pstack -a claude-code`. Or copy the skill folder (.claude/skills/pstack in chmonitor/chmonitor) into .claude/skills/pstack in your project. Claude Code loads it when a task matches its description.

How do I install Pstack in Codex?

Run `npx skills add chmonitor/chmonitor --skill pstack -a codex`. Or copy the skill folder (.claude/skills/pstack in chmonitor/chmonitor) into .agents/skills/pstack in your project. Codex loads it when a task matches its description.

Can I use Pstack in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add chmonitor/chmonitor --skill pstack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pstack, .gemini/skills/pstack, .github/skills/pstack and .opencode/skills/pstack in your project.

What does Pstack need to run?

Going by SKILL.md and its folder, Pstack needs the command-line tools its instructions call (gh, git and bun) and credentials named CHM_API_KEY_SECRET. Our summary lists: Docker; A credential in CHM_API_KEY_SECRET.

Does Pstack access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Pstack safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pstack use?

Pstack is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pstack use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pstack?

Skills that share tags, products or a category with Pstack: Gitops Cluster Debug (fluxcd/agent-skills, 230 stars), Kubernetes Architect (Cybereason-Public/owLSM, 280 stars), Kubernetes Specialist (Jeffallan/claude-skills, 12k stars) and Devops (nicepkg/auto-company, 192 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pstack?

chmonitor (a GitHub organization) maintains it in chmonitor/chmonitor, which has 298 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 5, 2026.

Source: chmonitor/chmonitor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.