Agent skill

Dd Audit Cost Spike Investigation

by datadog-labs in datadog-labs/agent-skills

Investigate a Datadog product usage or cost spike by correlating Usage Metering data (when/what spiked) with Audit Trail config changes (who changed what in the preceding window).

MITAuto-check passedBackend & APIs

Install Dd Audit Cost Spike Investigation

skills CLI
$ npx skills add datadog-labs/agent-skills --skill dd-audit-cost-spike-investigation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install datadog-labs/agent-skills dd-audit-cost-spike-investigation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/datadog-labs/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/dd-audit/cost-spike-investigation .claude/skills/dd-audit-cost-spike-investigation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dd-audit-cost-spike-investigation
GitHub stars
177
Token cost
~1.3k tokens
SKILL.md length
275 words
Files
1
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

Investigate a Datadog product usage or cost spike by correlating Usage Metering data (when/what spiked) with Audit Trail config changes (who changed what in the preceding window).

  • Works in 4 steps: Identify the spike window and product… → Pinpoint the spike → Search Audit Trail for config changes in… → …
  • Tasks that involve Payments and billing
  • SKILL.md covers Prerequisites, Scope Boundary, Investigation Workflow and Output Format, plus 2 more sections
  • Calls jq and curl; needs DD_API_KEY and DD_APP_KEY

What it does

Dd Audit Cost Spike Investigation is an agent skill from datadog-labs/agent-skills. Investigate a Datadog product usage or cost spike by correlating Usage Metering data (when/what spiked) with Audit Trail config changes (who changed what in the preceding window).

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Payments and billing. It works with Datadog. The repository describes itself as: Public repository for Datadog Agent Skills. The licence is MIT.

When your agent uses it

  • Tasks that involve Payments and billing

Example prompts

  • “/dd-audit-cost-spike-investigation”

Requirements

  • A credential in DD_API_KEY
  • A credential in DD_APP_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Identify the spike window and product family
  2. Pinpoint the spike
  3. Search Audit Trail for config changes in the 24h preceding the spike
  4. Narrow to product-relevant config changes

What it can do on your machine

Read from SKILL.md and the folder at commit d2411cc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.datadoghq.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DD_API_KEY
    • DD_APP_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dd Audit Cost Spike Investigation loads about 1.3k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 275 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from datadog-labs/agent-skills at commit d2411cc, republished under its MIT licence (© datadog-labs). 275 words, ~1,340 tokens.

Download SKILL.mdSave it as .claude/skills/dd-audit-cost-spike-investigation/SKILL.md (or your agent's skills folder).
name
dd-audit-cost-spike-investigation
description
Investigate a Datadog product usage or cost spike by correlating Usage Metering data (when/what spiked) with Audit Trail config changes (who changed what in the preceding window).
metadata.version
0.1.0
metadata.author
datadog-labs
metadata.repository
https://github.com/datadog-labs/agent-skills
metadata.tags
datadog,audit,cost,usage,spike,finops,dd-audit
metadata.alwaysApply
false

Audit Trail: Cost / Usage Spike Investigation

Identify what caused a Datadog usage spike by correlating billing data with configuration change history.

The causal chain is: someone changed something → that change increased data volume → usage spiked → cost went up. Usage Metering tells you when and what; Audit Trail tells you who made the change.

Prerequisites

bash
pup auth login   # OAuth2 (recommended) — covers audit queries
# Usage Metering queries also need DD_API_KEY + DD_APP_KEY
export DD_API_KEY=<your-api-key>
export DD_APP_KEY=<your-app-key>
export DD_SITE=datadoghq.com

Scope Boundary

This skill identifies configuration changes that may have caused a spike. It does not identify which specific user or process submitted the data (e.g., which service sent the LLM spans). For per-submission attribution, use LLM Observability traces or APM instrumentation.

Investigation Workflow

Step 1 — Identify the spike window and product family
bash
START=$(date -u -v-7d +"%Y-%m-%dT%H:%M:%SZ" 2>/dev/null || date -u -d "7 days ago" +"%Y-%m-%dT%H:%M:%SZ")
END=$(date -u +"%Y-%m-%dT%H:%M:%SZ")

curl -s -G "https://api.${DD_SITE}/api/v2/usage/hourly_usage" \
  -H "DD-API-KEY: ${DD_API_KEY}" \
  -H "DD-APPLICATION-KEY: ${DD_APP_KEY}" \
  --data-urlencode "filter[timestamp][start]=${START}" \
  --data-urlencode "filter[timestamp][end]=${END}" \
  --data-urlencode "filter[product_families]=all" \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      product: .attributes.product_family,
      measurements: [.attributes.measurements[] | {type: .usage_type, value: .value}]
    }]'

Product families with LLM/AI coverage: llm_observability, bits_ai, logs, apm

Step 2 — Pinpoint the spike

From Step 1, identify the hour/day where volume jumped. Note the timestamp as SPIKE_TIME.

Step 3 — Search Audit Trail for config changes in the 24h preceding the spike
bash
pup audit-logs search \
  --query "@action:(created OR modified OR deleted)" \
  --from "SPIKE_TIME_MINUS_24H" \
  --to "SPIKE_TIME" \
  --limit 200 \
  -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      user: .attributes.attributes.usr.email,
      actor_type: .attributes.attributes.evt.actor.type,
      action: .attributes.attributes.action,
      event_category: .attributes.attributes.evt.name,
      resource_type: .attributes.attributes.asset.type,
      resource_id: .attributes.attributes.asset.id
    }]'

Note: --from and --to accept ISO timestamps (e.g., 2026-05-01T14:00:00Z) or relative values (1h, 24h, 7d).

Step 4 — Narrow to product-relevant config changes

Filter to the audit categories most likely to affect the spiking product:

If this product spikedAdd to query
llm_observability@evt.name:(Integration OR APM OR "Log Management")
logs / indexed_logs@evt.name:"Log Management" @asset.type:(pipeline OR index OR exclusion_filter)
apm / indexed_spans@evt.name:APM @asset.type:(retention_filter OR sampling_rate)
rum@evt.name:RUM
metrics@evt.name:Metrics

Example for LLM Observability spike:

bash
pup audit-logs search \
  --query "@evt.name:(Integration OR APM OR \"Log Management\") @action:(created OR modified)" \
  --from "SPIKE_TIME_MINUS_24H" \
  --to "SPIKE_TIME" \
  --limit 100 \
  -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      user: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      category: .attributes.attributes.evt.name,
      resource_type: .attributes.attributes.asset.type,
      resource_id: .attributes.attributes.asset.id
    }]'

Output Format

Usage spike detected:
  Product: <product_family>
  Spike time: <SPIKE_TIME>
  Volume: <baseline> → <spike_value> (<magnitude>×)

Configuration changes in 24h preceding spike:
  <timestamp> | <user_email> | <action> <resource_type> <resource_id> | <category>

Likely causal change: <most-proximate change matching the product family>

Confidence: HIGH (single clear change) / MEDIUM (multiple candidates) / LOW (no matching changes)

Next steps:
  - Confirm with <user_email> whether the change was intentional
  - If unintentional: revert <resource_id> and monitor volume
  - If intentional: update cost forecasts and alert thresholds

When No Causal Change Is Found

  1. The change may predate the 24h window — expand to 72h
  2. The increase may be from application-side instrumentation changes — check deploys
  3. The increase may be organic traffic growth — correlate with product launch or traffic event

References

© datadog-labs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in dd-audit/cost-spike-investigation of datadog-labs/agent-skills.

Open the folder on GitHubat commit d2411cc

Compare with similar skills

Dd Audit Cost Spike Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dd Audit Cost Spike Investigation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dd Audit Cost Spike Investigation this skilldatadog-labs/agent-skills177—~1.3kAutomated safety check: PassMIT
Tool AssistantAtmosphere/atmosphere3.8k—~412Automated safety check: PassApache-2.0
Billing Automationwshobson/agents40k13 repos~473Automated safety check: PassMIT
Serverless IntegrationsDataDog/dd-trace-js837—~1.1kAutomated safety check: PassCustom licence
Stripe Best Practicesfossasia/eventyay1.7k1 repos~1.7kAutomated safety check: PassApache-2.0
Pinme Uniwebpayglitternetwork/pinme3.8k—~7.3kAutomated safety check: PassMIT

Similar skills

  • Tool Assistant

    Atmosphere/atmosphere

    Tool-calling assistant with backend functions for time, city time, weather, and temperature conversion, plus cost metering and approval workflows.

    3.8k GitHub stars~412 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Billing Automation

    wshobson/agents

    Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.

    40k GitHub starsUsed in 13 repos~473 tokens
    Backend & APIsAuto-check passed
  • Serverless Integrations

    DataDog/dd-trace-js

    Official

    A skill your agent uses when adding, modifying, debugging, or reviewing dd-trace-js serverless platform integrations that create root invocation spans for AWS Lambda, Azure Functions, Google Cloud…

    837 GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Stripe Best Practices

    fossasia/eventyay

    Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents)…

    1.7k GitHub starsUsed in 1 repo~1.7k tokens
    Backend & APIsAuto-check passed
  • Pinme Uniwebpay

    glitternetwork/pinme

    A skill your agent uses when generating, modifying, or reviewing PinMe Worker (Cloudflare Worker TypeScript) code that accepts payments through UniwebPay — payment links, products/prices, checkout…

    3.8k GitHub stars~7.3k tokensUpdated 29 days ago
    Backend & APIsAuto-check passed
  • PayRam Payment Analytics

    PayRam/payram-mcp

    Queries a PayRam server's dashboard data through its REST APIs with a Bearer token: payment search, daily volume, unswept balances, sweep history and on-ramp metrics.

    158 GitHub stars~4.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from datadog-labs/agent-skills

All 39 skills in this repo
  • Bootstrap a reproducible LLM Observability experiment through the Python ddtrace SDK or the Node dd-trace SDK.

    177 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • Dd Account Setup

    datadog-labs/agent-skills

    Ensure the user has an authenticated Datadog account with a valid DDAPIKEY on the right region before any Datadog setup or instrumentation.

    177 GitHub stars~4.5k tokensUpdated 2 days ago
    Auto-check: notes
  • Dd Orchestrator

    datadog-labs/agent-skills

    Entry point for Datadog onboarding. An agent skill from datadog-labs/agent-skills.

    177 GitHub stars~6.7k tokensUpdated 2 days ago
    Auto-check passed
  • Dd Apm

    datadog-labs/agent-skills

    APM - install, onboard, instrument, enable, set up, configure, traces, services, dependencies, performance analysis, Data Streams Monitoring (DSM), queue lag, pipeline latency.

    177 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Agent Install

    datadog-labs/agent-skills

    Install the Datadog Agent on Kubernetes using the Datadog Operator — required before enabling Single Step Instrumentation (SSI), which automatically instruments applications for APM without code…

    177 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check: warnings
  • Dd AWS Integration

    datadog-labs/agent-skills

    Set up the Datadog AWS integration with Terraform - creates the cross-account IAM role Datadog assumes (external ID, no stored credentials), attaches the permission policies Datadog publishes, and…

    177 GitHub stars~6.8k tokensUpdated 2 days ago
    Auto-check: notes

Works with

Questions about Dd Audit Cost Spike Investigation

What does Dd Audit Cost Spike Investigation do?

Investigate a Datadog product usage or cost spike by correlating Usage Metering data (when/what spiked) with Audit Trail config changes (who changed what in the preceding window). Dd Audit Cost Spike Investigation is an agent skill from datadog-labs/agent-skills. Investigate a Datadog product usage or cost spike by correlating Usage Metering data (when/what spiked) with Audit Trail config changes (who changed what in the preceding window).

When should I use Dd Audit Cost Spike Investigation?

Dd Audit Cost Spike Investigation fits situations like: tasks that involve Payments and billing.

How do I install Dd Audit Cost Spike Investigation in Claude Code?

Run `npx skills add datadog-labs/agent-skills --skill dd-audit-cost-spike-investigation -a claude-code`. Or copy the skill folder (dd-audit/cost-spike-investigation in datadog-labs/agent-skills) into .claude/skills/dd-audit-cost-spike-investigation in your project. Claude Code loads it when a task matches its description.

How do I install Dd Audit Cost Spike Investigation in Codex?

Run `npx skills add datadog-labs/agent-skills --skill dd-audit-cost-spike-investigation -a codex`. Or copy the skill folder (dd-audit/cost-spike-investigation in datadog-labs/agent-skills) into .agents/skills/dd-audit-cost-spike-investigation in your project. Codex loads it when a task matches its description.

Can I use Dd Audit Cost Spike Investigation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add datadog-labs/agent-skills --skill dd-audit-cost-spike-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dd-audit-cost-spike-investigation, .gemini/skills/dd-audit-cost-spike-investigation, .github/skills/dd-audit-cost-spike-investigation and .opencode/skills/dd-audit-cost-spike-investigation in your project.

What does Dd Audit Cost Spike Investigation need to run?

Going by SKILL.md and its folder, Dd Audit Cost Spike Investigation needs the command-line tools its instructions call (jq and curl) and credentials named DD_API_KEY and DD_APP_KEY. Our summary lists: A credential in DD_API_KEY; A credential in DD_APP_KEY.

Does Dd Audit Cost Spike Investigation access the network?

SKILL.md names 1 domain. As links in the text: docs.datadoghq.com. This is read from the text; nothing was executed.

Is Dd Audit Cost Spike Investigation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dd Audit Cost Spike Investigation use?

Dd Audit Cost Spike Investigation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dd Audit Cost Spike Investigation use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dd Audit Cost Spike Investigation?

Skills that share tags, products or a category with Dd Audit Cost Spike Investigation: Tool Assistant (Atmosphere/atmosphere, 3.8k stars), Billing Automation (wshobson/agents, 40k stars), Serverless Integrations (DataDog/dd-trace-js, 837 stars) and Stripe Best Practices (fossasia/eventyay, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dd Audit Cost Spike Investigation?

datadog-labs (a GitHub organization) maintains it in datadog-labs/agent-skills, which has 177 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on October 8, 2026.

Source: datadog-labs/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.