Agent skill

Cx Infra

by coralogix in coralogix/cx-cli

Query Coralogix infrastructure resources with the cx infra CLI: resource types, filterable attributes, resource lists, health, raw data and configuration changes.

Apache-2.0Auto-check passedDevOps & Cloud

Install Cx Infra

skills CLI
$ npx skills add coralogix/cx-cli --skill cx-infra -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install coralogix/cx-cli cx-infra --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/coralogix/cx-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cx-infra .claude/skills/cx-infra && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cx-infra
GitHub stars
121
Token cost
~2.2k tokens
SKILL.md length
892 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

Query Coralogix infrastructure resources with the cx infra CLI: resource types, filterable attributes, resource lists, health, raw data and configuration changes.

  • Works in 3 steps: filters first. Attribute names and… → list with the filters → Zero rows is an answer. Don't retry. A…
  • The user asks to show resource types
  • SKILL.md covers Resource ids, Finding resources, Health and Raw data, plus 2 more sections
  • Calls jq

What it does

Cx Infra is an agent skill from coralogix/cx-cli. Query Coralogix infrastructure resources with the cx infra CLI: resource types, filterable attributes, resource lists, health, raw data and configuration changes. Use when the user asks to "show resource types", "list infrastructure resources", "what resources of this kind are monitored", "is this resource healthy", "why is this resource critical", "which health policy is failing", "when did this resource go critical", "get raw resource data", "find resources by name", "filter resources by service or…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. The repository describes itself as: This is the Coralogix CLI. The licence is Apache-2.0.

When your agent uses it

  • The user asks to show resource types
  • List infrastructure resources
  • What resources of this kind are monitored
  • Is this resource healthy

Example prompts

  • “show resource types”
  • “list infrastructure resources”
  • “what resources of this kind are monitored”
  • “/cx-infra”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. filters first. Attribute names and values differ per type, so never guess.
  2. list with the filters
  3. Zero rows is an answer. Don't retry. A wrong attribute or value is refused

What it can do on your machine

Read from SKILL.md and the folder at commit c071372. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cx Infra loads about 2.2k tokens when it runs. Until then it costs about 213 tokens; SKILL.md has 892 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~213
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from coralogix/cx-cli at commit c071372, republished under its Apache-2.0 licence (© coralogix). 892 words, ~2,163 tokens.

Download SKILL.mdSave it as .claude/skills/cx-infra/SKILL.md (or your agent's skills folder).
name
cx-infra
description
Query Coralogix infrastructure resources with the `cx infra` CLI: resource types, filterable attributes, resource lists, health, raw data and configuration changes. Use when the user asks to "show resource types", "list infrastructure resources", "what resources of this kind are monitored", "is this resource healthy", "why is this resource critical", "which health policy is failing", "when did this resource go critical", "get raw resource data", "find resources by name", "filter resources by service or environment", "critical hosts in a region", "what can I filter resources by", "resources in this cluster or namespace", "which resources changed recently", "what changed in this resource", "configuration drift", "did anything change before the incident", "what was this config last week", or wants to explore infrastructure resources.
metadata.version
0.2.0

Infrastructure Resources

All commands live under cx infra resources and are read-only. Run cx infra resources <command> --help for flags.

"Infrastructure monitoring is not enabled for this team" means the team has no infrastructure data. Stop and say so. Do not retry or change filters.

A stderr line starting warning: ... could not verify that infrastructure monitoring is enabled is informational: the enablement check itself failed and the command still ran.

CommandAnswers
typeswhich (category, type) pairs exist
filterswhich attributes can be filtered on, and their accepted values
listwhich resources match, with their health policies
health-historydaily health per resource, oldest first
raw-datathe raw resource document, now or at a past time
config-changeswhich resources changed configuration in a window
config-diffwhat changed, field by field

Resource ids

  • Take them from list (resource_id) and pass them as-is, quoted.
  • health-history, config-changes and config-diff take up to 100 ids per call. Pass them all in one call, not one call each. Over 100, the CLI refuses. Split into batches.
  • An id belongs to one team, so the id commands refuse more than one -p. Only types, filters and list fan out across profiles. From a multi-profile list, use the row's profile to pick the one to query.
  • Ids mean nothing outside this skill. To reach other skills, use the resource name or its Service value.

Finding resources

  1. filters first. Attribute names and values differ per type, so never guess. Per attribute: kind (string is free text, status a fixed set), values (the accepted set) and wildcard (whether * works).
  2. list with the filters:
    • Every --match-all must match, at least one --match-any must match, and the two groups are ANDed. --match-all OS=linux --match-any Health=Critical --match-any Region=eu-west-1 means OS=linux AND (Health=Critical OR Region=eu-west-1).
    • Commas give one attribute several values. In --match-any any one matches. In --match-all all must, which only makes sense for wildcards: --match-all 'Name=*alert*,*processing*'.
    • Name an attribute once, in one flag. A repeat is refused.
    • --category and --type are plain filters, not requirements, and are not attributes (no --match-all Category=...). At least one filter or scope flag is required.
    • Exact values are case-sensitive (OS=linux, not OS=Linux). Wildcards are not. Quote wildcards so the shell leaves * alone.
    • --name-filter and --scope (service, environment, team) are legacy flags. They need both --category and --type, and cannot mix with --match-*. --match-all 'Name=*web*' does what --name-filter web does.
  3. Zero rows is an answer. Don't retry. A wrong attribute or value is refused with the accepted ones listed.

list -o json is an envelope: {total_count, returned_count, resources}. The other commands return plain arrays or objects.

  • It returns one window, rows 0 to 100 by default (--start-row, and --end-row which is exclusive). Keep paging while start_row + returned_count < total_count.
  • A window cannot pass row 10,000. For bigger results, narrow the query.
  • With several profiles, each one pages against its own total_count (see counts_by_profile).

Health

  • list rows carry health_policies: [{id, name, status}] with status one of healthy, critical or pending (not evaluated yet). A critical policy says why a resource is critical. No extra call needed.
  • health-history returns [{resource_id, health_history: [{timestamp, status}]}] with status one of Healthy, Critical or Unmonitored. The two sets of statuses have different casing.
  • Ids that don't parse, and repeats, are dropped. A shorter answer is normal and stderr gives the count. Returned ids are normalized, so they may not string-match the ones sent.
  • Infra health is not Service Catalog health. Correlate it with telemetry rather than treating the two as the same.
bash
cx infra resources list --match-all Health=Critical -o json \
  | jq '.resources[] | {name, failing: [.health_policies[] | select(.status == "critical") | .name]}'

cx infra resources health-history "1001234:host_id=i-abc" "1001234:host_id=i-def" -o json \
  | jq '.[] | {resource_id, critical: [.health_history[] | select(.status == "Critical") | .timestamp]}'
Show full SKILL.md (311 more words)Show less

Raw data

raw-data -o json returns {version_timestamp, raw_data}.

  • --timestamp (now-7d or ISO-8601) gets the newest version at or before that time. version_timestamp says which version came back, and can be passed back as --timestamp to get it again.
  • raw_data: null means no document. That is not an error. version_timestamp: null with a document means the document has no version.

Configuration changes

Two steps: find out which resources changed, then see what changed.

bash
cx infra resources config-changes --resource-id "1001234:host_id=i-abc" \
  --resource-id "1001234:host_id=i-def" --from now-24h -o json

cx infra resources config-diff --resource-id "1001234:host_id=i-abc" --from now-24h -o json \
  | jq '.[] | select(.outcome == "changed") | .changes[] | {field, before, after}'
  • config-changes lists only resources that changed. Empty means nothing changed. Don't retry with a wider window.
  • Rows are per resource and source. A resource with two collectors can give two rows.
  • Some cloud and agent types report an update every collection cycle, so config-changes can flag them when nothing changed. Check with config-diff before telling the user something changed.
  • config-diff has no row for a resource with no history in the 14 days before --from or inside the window. Read outcome before changes:
outcomemeaning
changedthe versions before and inside the window differ
unchangedthey don't differ, or nothing happened inside the window
createdthe resource first appeared inside the window
priorStateUnavailableit changed, but no version exists in the 14 days before --from. Not a failure. Move --from earlier to reach an older version
comparisonUnavailableboth versions exist, but one could not be read
  • before and after are raw JSON. null means the field was added or removed. A new or removed subtree is one entry.
  • To look at a single change, narrow --from and --to around it.

Bridge with the resource name or its Service value:

  • cx-telemetry-querying: cx search-fields "<name>" -s value finds the log and span fields holding the name. cx logs "filter $l.subsystemname == '<service>'" gets its telemetry.
  • cx-alerts: cx alerts list --name "<name-or-service>".
  • cx-dashboards: cx dashboards search "<name-or-service> ...". After search-fields -s value, cx dashboards query-search --field <field> finds queries on that field.

© coralogix, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cx-infra of coralogix/cx-cli.

Open the folder on GitHubat commit c071372

Compare with similar skills

Cx Infra next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cx Infra compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cx Infra this skillcoralogix/cx-cli121—~2.2kAutomated safety check: PassApache-2.0
Monitor CInrwl/nx29k6 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw36k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k8 repos~4.3kAutomated safety check: PassNone
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 6 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    36k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 8 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from coralogix/cx-cli

All 21 skills in this repo
  • Cx AI Center

    coralogix/cx-cli

    A skill your agent uses for any question or action about the user's AI/GenAI applications or agents — their behavior, prompts/responses, quality, hallucinations, guardrails, security, cost/tokens…

    121 GitHub stars~2.5k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Alerts

    coralogix/cx-cli

    This skill should be used when the user asks to "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "investigate firing alerts"…

    121 GitHub stars~2.5k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Coding Agents

    coralogix/cx-cli

    A skill your agent uses when the user asks about AI Center Coding Agents data, wants to reproduce or extend the Coding Agents dashboards, or asks questions about usage, cost, tokens, sessions…

    121 GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Cost Optimization

    coralogix/cx-cli

    A skill your agent uses when the user asks to "check data usage", "list TCO policies", "reduce Coralogix costs", "optimize observability spend", "lower our logging bill", "data budget exceeded"…

    121 GitHub stars~3.4k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Data Pipeline

    coralogix/cx-cli

    A skill your agent uses when the user asks to "set up parsing", "create parsing rule", "extract fields from logs", "regex extraction", "log parsing", "enrich logs", "add context to logs", "custom…

    121 GitHub stars~3k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Telemetry Querying

    coralogix/cx-cli

    A skill your agent uses for any question involving telemetry data: "investigate an issue", "debug a problem", "find out why something is slow", "check error rates", "analyze user behavior"…

    121 GitHub stars~2.6k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Cx Infra

What does Cx Infra do?

Query Coralogix infrastructure resources with the cx infra CLI: resource types, filterable attributes, resource lists, health, raw data and configuration changes. Cx Infra is an agent skill from coralogix/cx-cli. Query Coralogix infrastructure resources with the cx infra CLI: resource types, filterable attributes, resource lists, health, raw data and configuration changes.

When should I use Cx Infra?

Cx Infra fits situations like: the user asks to show resource types; list infrastructure resources; what resources of this kind are monitored; is this resource healthy.

How do I install Cx Infra in Claude Code?

Run `npx skills add coralogix/cx-cli --skill cx-infra -a claude-code`. Or copy the skill folder (skills/cx-infra in coralogix/cx-cli) into .claude/skills/cx-infra in your project. Claude Code loads it when a task matches its description.

How do I install Cx Infra in Codex?

Run `npx skills add coralogix/cx-cli --skill cx-infra -a codex`. Or copy the skill folder (skills/cx-infra in coralogix/cx-cli) into .agents/skills/cx-infra in your project. Codex loads it when a task matches its description.

Can I use Cx Infra in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add coralogix/cx-cli --skill cx-infra -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cx-infra, .gemini/skills/cx-infra, .github/skills/cx-infra and .opencode/skills/cx-infra in your project.

What does Cx Infra need to run?

Going by SKILL.md and its folder, Cx Infra needs the command-line tools its instructions call (jq).

Does Cx Infra access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cx Infra safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cx Infra use?

Cx Infra is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cx Infra use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cx Infra?

Skills that share tags, products or a category with Cx Infra: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 36k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Analyze GitHub Action Logs (withastro/astro, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cx Infra?

coralogix (a GitHub organization) maintains it in coralogix/cx-cli, which has 121 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.

Source: coralogix/cx-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.