Official agent skill

Resolve Muzzle CI

by DataDog in DataDog/dd-trace-java

Diagnose and resolve dd-trace-java CI failures from a module's muzzle task or the runMuzzle aggregate.

OfficialApache-2.0Auto-check passedTesting & QA

Install Resolve Muzzle CI

skills CLI
$ npx skills add DataDog/dd-trace-java --skill resolve-muzzle-ci -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DataDog/dd-trace-java resolve-muzzle-ci --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DataDog/dd-trace-java.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/resolve-muzzle-ci .claude/skills/resolve-muzzle-ci && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
resolve-muzzle-ci
GitHub stars
736
Token cost
~3.2k tokens
SKILL.md length
1,604 words
Files
4 (incl. references)
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Diagnose and resolve dd-trace-java CI failures from a module's muzzle task or the runMuzzle aggregate.

  • Works in 3 steps: Read the CI job log far enough to… → Confirm that the task is a module… → As soon as it is confirmed, tell the…
  • CI names muzzle/runMuzzle
  • SKILL.md covers Confirm and chime in, Classify before editing, Choose the smallest honest… and Leave the reason beside the…, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Resolve Muzzle CI is an agent skill from DataDog/dd-trace-java, published by the product's own GitHub organization. Diagnose and resolve dd-trace-java CI failures from a module's muzzle task or the runMuzzle aggregate. Use when CI names muzzle/runMuzzle, reports Muzzle validation or version-range resolution failures, or starts failing after a newly published library version. Distinguishes transient repository or MagicMirror failures from actionable compatibility, artifact, and validation-JDK defects; do not use for unrelated Gradle dependency or test failures.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/ci-log-access.md`, `references/failure-signatures-and-remedies.md` and `references/jira-handoff.md`).

It sits in Testing & QA, covering Failing and flaky tests. It works with Java, Gradle and Datadog. The repository describes itself as: Datadog APM client for Java. The licence is Apache-2.0.

When your agent uses it

  • CI names muzzle/runMuzzle
  • Reports Muzzle validation
  • Version-range resolution failures
  • Starts failing after a newly published library version

Example prompts

  • “/resolve-muzzle-ci”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read the CI job log far enough to identify the full Gradle task path and first causal exception,
  2. Confirm that the task is a module :muzzle* task or the runMuzzle aggregate, or that the stack
  3. As soon as it is confirmed, tell the user briefly

What it can do on your machine

Read from SKILL.md and the folder at commit 89321ee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Resolve Muzzle CI loads about 3.2k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 117 tokens; SKILL.md has 1,604 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from DataDog/dd-trace-java at commit 89321ee, republished under its Apache-2.0 licence (© DataDog). 1,604 words, ~3,166 tokens.

Download SKILL.mdSave it as .claude/skills/resolve-muzzle-ci/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
resolve-muzzle-ci
description
Diagnose and resolve dd-trace-java CI failures from a module's muzzle task or the runMuzzle aggregate. Use when CI names muzzle/runMuzzle, reports Muzzle validation or version-range resolution failures, or starts failing after a newly published library version. Distinguishes transient repository or MagicMirror failures from actionable compatibility, artifact, and validation-JDK defects; do not use for unrelated Gradle dependency or test failures.

Resolve muzzle CI

Treat the failing task and its first causal exception as the routing evidence. A failed job that happens to download dependencies is not necessarily a muzzle failure.

Match the user's requested scope. For investigation-only requests, gather evidence and report the classification, root cause, and proposed remedy; stop before editing repository files, retrying CI, or creating Jira issues unless those actions are also authorized. Requests to fix or resolve the failure proceed through implementation and verification without another confirmation for already authorized work. Apply the separate CI-retry and Jira authorization rules below.

Confirm and chime in

For GitLab job logs, read CI log access when CLI authentication or job retrieval is needed; the GitHub PR's repository is not necessarily the GitLab CI project.

  1. Read the CI job log far enough to identify the full Gradle task path and first causal exception, not only the final Muzzle validation failed wrapper.

  2. Confirm that the task is a module :muzzle* task or the runMuzzle aggregate, or that the stack is from datadog.gradle.plugin.muzzle / MuzzleVersionScanPlugin.

  3. As soon as it is confirmed, tell the user briefly:

    text
    This is a muzzle CI failure in <task/module>. I am checking whether it is repository
    infrastructure, an artifact/JDK issue, or a real compatibility regression.

    If it is not a muzzle failure, say which task actually failed and stop using this skill.

Before changing a build file, read:

  • docs/how_to_work_with_gradle.md
  • docs/how_instrumentations_work.md, especially its Muzzle and JApiCmp sections
  • .agents/skills/apm-integrations/references/muzzle.md
  • the affected module's build.gradle and adjacent versioned modules
  • failure signatures and remedies

Classify before editing

Preserve the complete relevant log and CI URL. Record the affected task, module, directive, artifact coordinates, tested version, repository host, and first causal exception.

Use release age only to prioritize investigation. An established version that previously passed suggests checking infrastructure and dependency-graph changes; a newly published version suggests comparing its API and publication with the last passing release. Neither age alone nor a green aggregate rerun justifies a retry, version cap, or skip. See the worked scenarios.

Classify the failure as exactly one of:

  • Transient platform/repository failure: timeouts, connection resets, TLS/DNS failures, HTTP 429/5xx, incomplete metadata from MagicMirror/Depot, or several unrelated artifacts failing to download. There is no concrete muzzle mismatch for an already resolved application classpath.
  • Defective or unavailable published artifact: the same version or one of its transitive coordinates is persistently absent, has a broken POM/archive, or cannot form a valid classpath, including when checked outside the transient proxy path.
  • Compatibility regression: muzzle resolved the application classpath and reports missing or changed classes, methods, fields, flags, or a class-loader mismatch.
  • Validation-JDK mismatch: UnsupportedClassVersionError occurs while loading a resolved root or transitive library class that requires a newer JDK than the Muzzle worker.
  • Declared-failure mismatch: MUZZLE PASSED ... BUT FAILURE WAS EXPECTED shows that a fail range or inverse expectation is false.
  • Helper injection failure: FAILED HELPER INJECTION shows incomplete, misordered, invisible, or incompatible helpers.
  • Muzzle tooling/JDK failure: worker, toolchain, module-access, bytecode-parser, or JVM failure; fix the tooling path without changing the library compatibility range.
  • Unresolved: the available log is truncated or contradictory. Gather the missing evidence; do not edit a version range merely to make CI green.

For a transient platform failure, do not change repository, version, skip, or exclusion settings. The muzzle resolver already retries range resolution with backoff. If authorized, retry the failed job once after repository recovery, then report an infrastructure incident if the repository remains unhealthy. Stop here; do not create a Jira ticket from this workflow.

For the other classifications, reproduce the smallest task with diagnostic output:

bash
./gradlew :dd-java-agent:instrumentation:<path>:muzzle --stacktrace --info --rerun-tasks

Large ranges are reduced before execution, so a green rerun is not proof that a deterministic mid-range failure disappeared. Rerun the module muzzle task and confirm from its output or report that the exact generated version task ran. If necessary, temporarily narrow a local diagnostic copy of the directive to versions = "[<exact-version>]"; never commit that diagnostic narrowing.

Choose the smallest honest remedy

Choose directly from the observed cause and prove the remedy against the current artifact and API evidence.

The major remedies are:

  • Fix the instrumentation when the new release is intended to remain supported and a bounded code change can restore compatibility. Add or update version-specific tests.
  • Cap the pass range at the first incompatible version when that version introduces a real API or linkage boundary that this module does not support. Check whether a sibling module should take over; do not skipVersions around an ongoing incompatible line.
  • Add skipVersions only for isolated bad releases whose own POM, artifact, or version metadata is defective and where later releases can still be supported.
  • Add excludeDependency 'group:module' only for a transitive dependency that is not referenced by the advice, helpers, matcher requirements, explicit muzzle references, or class-loader matcher. Prefer an exact coordinate; use a group wildcard only when the entire group is proven irrelevant.
  • Add an exact extraDependency only when it belongs to the library's valid runtime/application classpath but is not present in the resolved graph.
  • Ensure a narrowly scoped Gradle repository entry exists when a valid target artifact or required application dependency is intentionally hosted outside the configured repositories. Add extraRepository to the Muzzle directive when version discovery also requires that repository. extraRepository configures Aether version discovery; it does not configure Gradle dependency resolution.
  • Correct the target artifact/module when the directive follows a relocated or obsolete coordinate.
  • Set per-directive javaVersion = "<N>" when a valid resolved dependency requires that JDK to load. Split at a known JDK boundary when useful and verify both sides of each boundary.
  • Change the expected compatibility outcome of a fail block or assertInverse only when MUZZLE PASSED ... BUT FAILURE WAS EXPECTED demonstrates that the expectation is false. Replacing generated inverses with equivalent explicit checks must preserve the expected outcomes and version coverage.
  • Repair helper completeness, ordering, linkage, or visibility for FAILED HELPER INJECTION; cap a range only when the helper failure proves a real target-library compatibility boundary.
  • Repair Muzzle tooling or CI toolchain provisioning for worker, parser, or JVM failures; do not change the dependency support range.

Generated assertInverse directives do not inherit javaVersion, extraDependency, or extraRepository. When inverse checks need these inputs, replace the generated inverse with explicit fail directives covering the same unsupported ranges, with suitable JDKs, dependencies, and repositories for those versions. Disable assertInverse only after providing equivalent coverage. Ensure Gradle can also resolve the dependencies. Verify that each negative check fails for the intended compatibility mismatch, not a missing classpath input or a repository/JDK failure. Sibling coverage alone does not establish the original module's expected compatibility outcome.

Never broaden support, remove an inverse assertion, or exclude a dependency solely because it makes the task pass. javaVersion changes only the worker JDK; it does not fix library linkage or change the agent, test, or bytecode baselines. Muzzle does not prove that a type named only in a matcher exists; use an explicit muzzle reference or runtime test when that fact matters.

For a symbol mismatch, run the module's printReferences task to trace the generated reference and compare the last passing and first failing artifacts when useful:

bash
./gradlew :dd-java-agent:instrumentation:<path>:printReferences
./gradlew japicmp -Partifact=<group>:<module> -Pbaseline=<last-pass> -Ptarget=<first-fail>

Muzzle validates binary references and helper injection, not behavior. If code or supported runtime semantics change, add a behavior test and exercise a coherent library dependency stack.

Show full SKILL.md (429 more words)Show less

Leave the reason beside the workaround

When a fix changes Muzzle configuration or adds a build-file workaround, leave a brief comment beside the affected directive or setting explaining the concrete failure and compatibility consequence. Include a removal condition or upstream issue when the workaround is temporary.

For a source-only fix, keep any necessary explanation beside the relevant code or regression test; no build.gradle edit is required. Record the affected version and changed linkage or runtime assumption where useful. Avoid comments that only say fix muzzle, CI failure, or broken version.

Verify

Rerun the module muzzle task and verify according to the selected remedy:

  • Restored support: confirm that the exact previously failing version ran and passed; use a temporary local diagnostic directive if range sampling omits it.
  • Containment by cap or skip: the original pass task is deliberately removed. Confirm the revised range or skip, exercise retained supported versions around the boundary or isolated skip, and run applicable inverse or explicit negative checks on resolvable classpaths. Report the excluded version as unsupported; an unavailable or defective publication cannot establish a binary mismatch.

Run the affected module's relevant tests when executable code, helper requirements, or claimed support changed. For javaVersion, confirm the selected worker JDK and test both sides of any split. Inspect the diff, then report the exact commands and results; do not call an infrastructure-only retry a code validation.

Hand off the follow-up in Jira

Create a Jira follow-up only when muzzle exposes a compatibility gap in a newly published target library version and the completed change leaves that version unsupported, normally by capping the current module below it. The ticket tracks restoring support for that new version. Do not create a ticket for transient platform/repository failures, defective or missing publications, irrelevant transitive artifacts, tooling/JDK failures, stale inverse assertions, or a change that already restores and verifies support.

For a qualifying new-version gap, read the Jira handoff after the analysis and local verification are complete. If the current request authorizes Jira creation, create the ticket. If it does not, ask whether the user wants the gap logged and, if so, which Jira project/board to use; continue safe local work while waiting. Do not guess the destination or claim the ticket was created when no Jira integration is available.

Finish with the classification, root cause, resolution and its compatibility consequence, validation, any owner or removal condition, and—only for a qualifying new-version support gap—the Jira disposition (key/link, copy-ready draft, declined, or not requested). Preserve authorization conditions, name the exact task/module, distinguish proposed, completed, and blocked checks, and retain remedy-specific validation requirements.

© DataDog, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in .agents/skills/resolve-muzzle-ci of DataDog/dd-trace-java.

  • SKILL.md
  • references/ci-log-access.md
  • references/failure-signatures-and-remedies.md
  • references/jira-handoff.md

Open the folder on GitHubat commit 89321ee

Compare with similar skills

Resolve Muzzle CI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Resolve Muzzle CI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Resolve Muzzle CI this skillDataDog/dd-trace-java736—~3.2kAutomated safety check: PassApache-2.0
Fix Broken Datadog Provider TestsDataDog/terraform-provider-datadog468—~2.4kAutomated safety check: NotesMPL-2.0
Dd Unblock PRDataDog/pup1k—~1.7kAutomated safety check: PassApache-2.0
Unblock PRdatadog-labs/agent-skills177—~2.7kAutomated safety check: PassMIT
Rota Check Periodic Jobsoracle/graalpython1.7k—~792Automated safety check: PassCustom licence
Analyze Azdo BuildDataDog/dd-trace-dotnet573—~3.5kAutomated safety check: PassApache-2.0

Similar skills

  • Fix Broken Datadog Provider Tests

    DataDog/terraform-provider-datadog

    Official

    Runs an end-to-end workflow to diagnose, reproduce, fix and validate a failing integration test in the Datadog Terraform provider, ending with a draft PR.

    468 GitHub stars~2.4k tokensUpdated today
    Testing & QAAuto-check: notes
  • Dd Unblock PR

    DataDog/pup

    Official

    Load when investigating a failing PR CI pipeline or checking PR health.

    1k GitHub stars~1.7k tokensUpdated today
    Testing & QAAuto-check passed
  • Unblock PR

    datadog-labs/agent-skills

    Load when investigating a failing PR CI pipeline or checking PR health.

    177 GitHub stars~2.7k tokensUpdated 4 days ago
    Testing & QAAuto-check passed
  • Rota Check Periodic Jobs

    oracle/graalpython

    Official

    Analyze current GraalPy periodic job failures for ROTA. An agent skill from oracle/graalpython.

    1.7k GitHub stars~792 tokensUpdated today
    Testing & QAAuto-check passed
  • Analyze Azdo Build

    DataDog/dd-trace-dotnet

    Official

    Analyze Azure DevOps CI build failures in dd-trace-dotnet pipeline.

    573 GitHub stars~3.5k tokensUpdated today
    Testing & QAAuto-check passed
  • Add Gc Test

    DataDog/jmxfetch

    Official

    Add integration tests to TestGCMetrics.java for new GC collector support added to new-gc-default-jmx-metrics.yaml.

    109 GitHub stars~1.1k tokensUpdated 2 mo ago
    Testing & QAAuto-check passed

More from DataDog/dd-trace-java

All 9 skills in this repo
  • Apm Integrations

    DataDog/dd-trace-java

    Official

    Write a new library instrumentation end-to-end. An agent skill from DataDog/dd-trace-java.

    736 GitHub stars~3.7k tokensUpdated today
    Auto-check: notes
  • Perf Review

    DataDog/dd-trace-java

    Official

    Performance-overhead review of a code diff / branch / PR for the dd-trace-java tracer.

    736 GitHub stars~3.6k tokensUpdated today
    Auto-check: notes
  • Fix Continuation Leakage

    DataDog/dd-trace-java

    Official

    Diagnose and fix scope or continuation lifecycle failures in dd-trace-java instrumentation tests.

    736 GitHub stars~1.6k tokensUpdated today
    Auto-check: notes
  • Techdebt

    DataDog/dd-trace-java

    Official

    Review a code diff / branch / PR for technical debt — code duplication, unnecessary complexity / over-engineering, and redundant or dead code.

    736 GitHub stars~565 tokensUpdated today
    Auto-check: notes
  • Clarify Java Comments

    DataDog/dd-trace-java

    Official

    Clarify or review Java Javadocs, Javadoc tags, and explanatory code comments for legibility, accuracy, and source alignment.

    736 GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Migrate Groovy To Java

    DataDog/dd-trace-java

    Official

    Converts Spock/Groovy test files in a Gradle module to equivalent JUnit 5 Java tests.

    736 GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Questions about Resolve Muzzle CI

What does Resolve Muzzle CI do?

Diagnose and resolve dd-trace-java CI failures from a module's muzzle task or the runMuzzle aggregate. Resolve Muzzle CI is an agent skill from DataDog/dd-trace-java, published by the product's own GitHub organization. Diagnose and resolve dd-trace-java CI failures from a module's muzzle task or the runMuzzle aggregate.

When should I use Resolve Muzzle CI?

Resolve Muzzle CI fits situations like: CI names muzzle/runMuzzle; reports Muzzle validation; version-range resolution failures; starts failing after a newly published library version.

How do I install Resolve Muzzle CI in Claude Code?

Run `npx skills add DataDog/dd-trace-java --skill resolve-muzzle-ci -a claude-code`. Or copy the skill folder (.agents/skills/resolve-muzzle-ci in DataDog/dd-trace-java) into .claude/skills/resolve-muzzle-ci in your project. Claude Code loads it when a task matches its description.

How do I install Resolve Muzzle CI in Codex?

Run `npx skills add DataDog/dd-trace-java --skill resolve-muzzle-ci -a codex`. Or copy the skill folder (.agents/skills/resolve-muzzle-ci in DataDog/dd-trace-java) into .agents/skills/resolve-muzzle-ci in your project. Codex loads it when a task matches its description.

Can I use Resolve Muzzle CI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DataDog/dd-trace-java --skill resolve-muzzle-ci -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/resolve-muzzle-ci, .gemini/skills/resolve-muzzle-ci, .github/skills/resolve-muzzle-ci and .opencode/skills/resolve-muzzle-ci in your project.

What does Resolve Muzzle CI need to run?

SKILL.md names no scripts, command-line tools or credentials: Resolve Muzzle CI is instructions for the agent only.

Does Resolve Muzzle CI access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Resolve Muzzle CI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Resolve Muzzle CI use?

Resolve Muzzle CI is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Resolve Muzzle CI use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.

What are the alternatives to Resolve Muzzle CI?

Skills that share tags, products or a category with Resolve Muzzle CI: Fix Broken Datadog Provider Tests (DataDog/terraform-provider-datadog, 468 stars), Dd Unblock PR (DataDog/pup, 1k stars), Unblock PR (datadog-labs/agent-skills, 177 stars) and Rota Check Periodic Jobs (oracle/graalpython, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Resolve Muzzle CI?

DataDog (a GitHub organization, an official publisher) maintains it in DataDog/dd-trace-java, which has 736 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: DataDog/dd-trace-java on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.