Code Design Rationale Investigator
cursor/plugins
Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.
End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and…
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Dynatrace/dynatrace-for-ai dt-alerting --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dt-alerting .claude/skills/dt-alerting && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dt-alerting" agent skill from https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-alerting into .claude/skills/dt-alerting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dt-alerting", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-alertingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Dynatrace/dynatrace-for-ai dt-alerting --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dt-alerting .agents/skills/dt-alerting && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dt-alerting" agent skill from https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-alerting into .agents/skills/dt-alerting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dt-alerting", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Dynatrace/dynatrace-for-ai dt-alerting --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dt-alerting .cursor/skills/dt-alerting && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dt-alerting" agent skill from https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-alerting into .cursor/skills/dt-alerting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dt-alerting", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Dynatrace/dynatrace-for-ai.git --path skills/dt-alerting--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Dynatrace/dynatrace-for-ai dt-alerting --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dt-alerting .gemini/skills/dt-alerting && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dt-alerting" agent skill from https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-alerting into .gemini/skills/dt-alerting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dt-alerting", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Dynatrace/dynatrace-for-ai dt-alertingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dt-alerting .github/skills/dt-alerting && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dt-alerting" agent skill from https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-alerting into .github/skills/dt-alerting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dt-alerting", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Dynatrace/dynatrace-for-ai dt-alerting --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dt-alerting .opencode/skills/dt-alerting && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dt-alerting" agent skill from https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-alerting into .opencode/skills/dt-alerting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dt-alerting", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dt-alertingEnd-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and…
Dt Alerting is an agent skill from Dynatrace/dynatrace-for-ai. End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and denoising by root cause analysis, and workflow-based notification routing (email, Slack, ServiceNow, webhook). Use when configuring alerting, choosing between detector types, querying alert event history, understanding why alerts merged into a problem, or setting up problem-triggered notifications.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/anomaly-detectors.md`, `references/davis-events.md` and `references/workflow-notifications.md`).
It sits in Development, covering Root cause analysis and Webhooks. It works with Slack and ServiceNow. The repository describes itself as: Skills, prompts, and instructions for building AI agents on top of Dynatrace production context. The licence is Apache-2.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4f9aa71. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are dql).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dt Alerting loads about 3.3k tokens when it runs, and up to ~26k if it reads all its reference files. Until then it costs about 126 tokens; SKILL.md has 1,240 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Dynatrace/dynatrace-for-ai at commit 4f9aa71, republished under its Apache-2.0 licence (© Dynatrace). 1,240 words, ~3,250 tokens.
.claude/skills/dt-alerting/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Configure and understand the full alerting lifecycle in Dynatrace — from anomaly detector setup through Grail event storage, problem grouping, and workflow notification delivery.
┌─────────────────────────────────────────────────────────────────────┐
│ Alert Sources — five categories, each fires a DAVIS_EVENT │
│ ───────────────────────────────────────────────────────────────── │
│ 1. DQL-based · Grail-scheduled server-side detector │
│ 2. Edge · OneAgent on monitored host or process │
│ 3. Pipeline · OpenPipeline ingest-stream filter matcher │
│ 4. Synthetic · Worldwide synthetic checker node │
│ 5. External · Events API, Workflow, or OneAgent local ingest │
└──────────────────────────────┬──────────────────────────────────────┘
│ DAVIS_EVENT created per trigger per entity
▼
┌─────────────────────────────────────┐
│ Event stored in Grail │ Persisted and queryable via DQL.
└──────────────────┬──────────────────┘ One event per trigger per entity.
│ correlated by root-cause and impact graph
▼
┌─────────────────────────────────────┐
│ Problem (Denoising) │ Events sharing the same root-cause
└──────────────────┬──────────────────┘ and impact graph → one Problem.
│ problem event triggers workflow
▼
┌─────────────────────────────────────┐
│ Workflow Notification │ Filters problems and routes to
└─────────────────────────────────────┘ email, Slack, ServiceNow, webhook.First step for any alerting setup request — Before recommending a specific
detector or model, load references/anomaly-detectors.md and use its category
and model decision guide to identify which detector category (DQL-based, Edge,
Pipeline, Synthetic, External) and which model (Static, Adaptive, Seasonal)
best fits the user's use-case. Only proceed with configuration guidance once
the right detector type has been established.
Consolidate, don't multiply — When a user asks to alert on multiple
entities of the same kind (e.g. "alert on services A, B, and C"), always
recommend a single combined detector rather than one detector per entity.
Use by: { <dimension> } in the DQL timeseries call to split results per
entity, and a single filter: clause to scope to the relevant entities.
Pair the combined detector with a single dt.alert_group tag shared
across all alert conditions and the corresponding workflow notification filter.
This keeps the number of detector configs small, ensures consistent routing,
and makes the workflow notification channel reusable for future entities added
to the same group.
Example for three services — one detector, one workflow:
timeseries avg(dt.service.request.response_time),
by: { dt.smartscape.service },
filter: { in(dt.smartscape.service, {toSmartscapeId("SERVICE-0000000000000001"), toSmartscapeId("SERVICE-0000000000000002"), toSmartscapeId("SERVICE-0000000000000003")}) }Set dt.alert_group: "checkout-team" in the detector's event properties, then
filter the notification workflow on matchesPhrase(dt.alert_group, "checkout-team").
If a new service must be covered, add it to the single filter: list — no new
detector or workflow rule needed.
| User Request | Action | Reference |
|---|---|---|
| "how to alert on ...", "create an alert on ...", "create anomaly detector", "set up alerting", "configure alert rule" | Explain detector categories and variants, guide through model selection | anomaly-detectors.md |
| "what kinds of anomaly detectors", "edge alert", "pipeline alert", "synthetic alert", "OneAgent alert" | Explain the five alert source categories and their trade-offs | anomaly-detectors.md |
| "static vs adaptive", "which detector model", "seasonal detector" | Compare models, apply decision guide | anomaly-detectors.md |
| "query alert history", "which alerts fired", "Davis events in Grail" | Query dt.davis.events in Grail via fetch dt.davis.events | davis-events.md |
| "why did alerts merge", "problem grouping", "denoising" | Do NOT explain merging rules here — load dt-obs-problems and refer to problem-merging.md for the full merge logic | dt-obs-problems/references/problem-merging.md |
| "send Slack notification", "email on problem", "ServiceNow ticket", "notify on alert" | Explain problem-triggered workflow setup | workflow-notifications.md |
| "alert storm", "too many notifications", "reduce noise" | Filtering strategy, denoising, sensitivity tuning | workflow-notifications.md + anomaly-detectors.md |
Analyzing existing problems — If the user wants to query or investigate active/closed problems (root cause, impact, trending), load
dt-obs-problemsinstead. This skill covers configuration and flow, not problem query analytics.
Detector health monitoring — If the user asks whether detectors are running or failing, load
dt-platform(ANALYZER_EXECUTION_EVENT, ANOMALY_DETECTOR_STATUS_EVENT). This skill covers setup, not operational health.
dt.davis.eventsdt-dql-essentials before writing DQL queries| # | Reference | Content |
|---|---|---|
| 1 | anomaly-detectors.md | Detector types, model selection, configuration, best practices |
| 2 | davis-events.md | Davis event storage in Grail, key fields, DQL query patterns |
| 3 | workflow-notifications.md | Problem-triggered workflows, filtering, notification channels |
Five fundamental categories of anomaly detectors, distinguished by where detection runs and how the alert event reaches Dynatrace:
| # | Category | Detection runs on | Latency | Alert logic owner |
|---|---|---|---|---|
| 1 | DQL-based | Grail (server-side, scheduled) | Minutes | Dynatrace |
| 2 | Edge | OneAgent on the monitored host/process | Seconds | Dynatrace (OneAgent) |
| 3 | Pipeline | OpenPipeline ingest path (in-stream) | Near-zero | Dynatrace (pipeline rule) |
| 4 | Synthetic | Synthetic checker node (worldwide) | Seconds | Dynatrace (synthetic node) |
| 5 | External | Customer / external tool | Caller-defined | Customer |
See references/anomaly-detectors.md for the full breakdown of each category,
including trade-offs and configuration entry points.
| Model | Threshold | Best for |
|---|---|---|
| Static | Fixed value you define | Known hard limits (e.g. error rate > 5%) |
| Adaptive baseline | Learned from recent history | Metrics with no fixed limit but clear normal behavior |
| Seasonal baseline | Learned with time-of-day / day-of-week awareness | Traffic, request rate, or any metric with recurring patterns |
| Concept | Table | Scope |
|---|---|---|
| Davis event | fetch dt.davis.events | One record per detector trigger per entity |
| Problem | fetch dt.davis.problems | One record per correlated group of events sharing root-cause and impact |
A single problem typically contains multiple events. Querying problems gives the operational view; querying events gives the raw alert history.
For questions about why alerts merged into a problem or how Davis groups
events, load dt-obs-problems — the merge logic and rules are documented in
dt-obs-problems/references/problem-merging.md. This skill covers alert
configuration and flow only.
fetch dt.davis.events, from: -24h
| filter event.status == "ACTIVE"
| summarize alert_count = count(), by: {event.name, event.category, dt.smartscape_source.id}
| sort alert_count desc
| limit 20fetch dt.davis.events, from: -24h
| summarize count = count(), by: {event.category, event.status}
| sort count descfetch dt.davis.problems, from: -24h
| filter not(dt.davis.is_duplicate) and event.status == "ACTIVE"
| fields event.start, display_id, event.name, event.category
| sort event.start desc
| limit 20event.severity <= 2 problems to
on-call channels immediately; route event.severity >= 3 problems to lower-
urgency channels. Either set severity in the detector config or assign in a pipeline rule or workflow.dt.alert_group event property for routing — Assign dt.alert_group to route alerts to the right team. Either set a static value in the detector config, use dynamic assignment through DQL query result mapping or assign in a pipeline rule.by: { <dimension> } and a combined
filter: clause. Assign the same dt.alert_group value to every condition
in that detector and point the workflow notification channel at that single
group. One detector + one workflow per logical alert group scales better than
N detectors + N notification rules, and adding a new entity is a one-line
filter change rather than a full detector/workflow addition.© Dynatrace, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/dt-alerting of Dynatrace/dynatrace-for-ai.
Open the folder on GitHubat commit 4f9aa71
Dt Alerting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dt Alerting this skillDynatrace/dynatrace-for-ai | 163 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Code Design Rationale Investigatorcursor/plugins | 11k | 9 repos | ~2.6k | Automated safety check: Pass | None | |
| Channel Debug Corevercel-labs/vercel-openclaw-archived | 117 | — | ~2k | Automated safety check: Notes | MIT | |
| Kibana Connectorsaspectrr/deer | 405 | — | ~2k | Automated safety check: Pass | MIT | |
| Chat SDKdatabuddy-analytics/Databuddy | 1.2k | — | ~2.6k | Automated safety check: Pass | AGPL-3.0 | |
| Axiom SRE Investigatoropenclaw/clawhub | 9.5k | — | ~7.1k | Automated safety check: Pass | MIT |
cursor/plugins
Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.
vercel-labs/vercel-openclaw-archived
Channel webhook triage for vercel-openclaw Slack/Telegram/Discord/WhatsApp issues: prove deployment state, collect admin readiness endpoints, build evidence-first handoff before fixes.
aspectrr/deer
Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform.
databuddy-analytics/Databuddy
Build multi-platform chat bots with Chat SDK (chat npm package).
openclaw/clawhub
Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.
Consensys/c0
Debug deployed Cloudflare Workers using the cfobservability MCP, Wrangler, D1/R2 state, repo evidence, and safe live reproduction.
Dynatrace/dynatrace-for-ai
Analyze dashboards and notebooks using Davis analyzers — anomaly detection, novelty scoring, and correlation.
Dynatrace/dynatrace-for-ai
Set up the Dynatrace iOS SDK (OneAgent) in an iOS project using Swift Package Manager.
Dynatrace/dynatrace-for-ai
AWS cloud resource monitoring including EC2, RDS, Lambda, ECS/EKS, VPC networking, load balancers, S3, DynamoDB, SQS/SNS, and cost optimization.
Dynatrace/dynatrace-for-ai
3rd-party test and monitor result ingestion into Dynatrace Grail via the platform events ingest API (platform/ingest/custom/events/).
Dynatrace/dynatrace-for-ai
DAVIS problem analysis including root cause identification, impact assessment, and correlation with other telemetry.
Dynatrace/dynatrace-for-ai
Service performance monitoring with RED metrics (Rate, Errors, Duration) and runtime-specific telemetry for Java, .NET, Node.js, Python, PHP, and Go.
Works with
Categories
End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and…. Dt Alerting is an agent skill from Dynatrace/dynatrace-for-ai. End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and denoising by root cause analysis, and workflow-based notification routing (email, Slack, ServiceNow, webhook).
Dt Alerting fits situations like: configuring alerting; choosing between detector types; querying alert event history; understanding why alerts merged into a problem.
Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a claude-code`. Or copy the skill folder (skills/dt-alerting in Dynatrace/dynatrace-for-ai) into .claude/skills/dt-alerting in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a codex`. Or copy the skill folder (skills/dt-alerting in Dynatrace/dynatrace-for-ai) into .agents/skills/dt-alerting in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dt-alerting, .gemini/skills/dt-alerting, .github/skills/dt-alerting and .opencode/skills/dt-alerting in your project.
SKILL.md names no scripts, command-line tools or credentials: Dt Alerting is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dt Alerting is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dt Alerting: Code Design Rationale Investigator (cursor/plugins, 11k stars), Channel Debug Core (vercel-labs/vercel-openclaw-archived, 117 stars), Kibana Connectors (aspectrr/deer, 405 stars) and Chat SDK (databuddy-analytics/Databuddy, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Dynatrace (a GitHub organization) maintains it in Dynatrace/dynatrace-for-ai, which has 163 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.
Source: Dynatrace/dynatrace-for-ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.