Official agent skill

Ecs PR Triage

by elastic in elastic/ecs

Triages an ECS pull request. An agent skill from elastic/ecs.

OfficialApache-2.0Auto-check passedDevelopment

Install Ecs PR Triage

skills CLI
$ npx skills add elastic/ecs --skill ecs-pr-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/ecs ecs-pr-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/ecs.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ecs-pr-triage .claude/skills/ecs-pr-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ecs-pr-triage
GitHub stars
1.1k
Token cost
~1.5k tokens
SKILL.md length
678 words
Files
3
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Triages an ECS pull request. An agent skill from elastic/ecs.

  • Works in 4 steps: Inventory the PR context → Classify the change → Check completeness → …
  • Tasks that involve Pull requests
  • SKILL.md covers Execution steps, Decision defaults, Important repo facts and Related assets
  • Calls gh and make

What it does

Ecs PR Triage is an agent skill from elastic/ecs, published by the product's own GitHub organization. Triages an ECS pull request. Analyzes the PR diff and metadata, classifies the change (schema / tooling / docs / mixed), routes it to the correct contribution path (direct PR vs RFC Proposal vs needs-discussion), checks PR completeness, and produces a structured Triage Report.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `classification-rules.md` and `report-template.md`).

It sits in Development, covering Pull requests. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Pull requests

Example prompts

  • “Use the ecs-pr-triage skill to triage an ECS pull request. An agent skill from elastic/ecs”
  • “/ecs-pr-triage”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Inventory the PR context
  2. Classify the change
  3. Check completeness
  4. Produce the triage report

What it can do on your machine

Read from SKILL.md and the folder at commit 9868ff5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ecs PR Triage loads about 1.5k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 678 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elastic/ecs at commit 9868ff5, republished under its Apache-2.0 licence (© elastic). 678 words, ~1,493 tokens.

Download SKILL.mdSave it as .claude/skills/ecs-pr-triage/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
ecs-pr-triage
description
Triages an ECS pull request. Analyzes the PR diff and metadata, classifies the change (schema / tooling / docs / mixed), routes it to the correct contribution path (direct PR vs RFC Proposal vs needs-discussion), checks PR completeness, and produces a structured Triage Report.

ECS PR triage

This skill triages an ECS pull request. The agent needs access to the PR diff, changed file list, PR description, and metadata — either already present in context or fetched via tools (e.g. gh). It analyzes that context, makes a routing decision, and delivers a triage report.

Execution steps

1. Inventory the PR context

From the PR context available to you (or fetched via gh pr view, gh pr diff, etc.), extract:

  • PR number, title, author.
  • Changed file paths — bucket every path into one of these categories:
    • schemas/ — source schema YAML (the key signal for routing)
    • generated/ — build outputs (should only change as a side effect of schema + make)
    • scripts/ — generator tooling, tests, templates
    • docs/ — hand-authored docs vs generated reference (docs/reference/ecs-*.md)
    • rfcs/ — RFC markdown and supporting YAML
    • .github/ — CI workflows, templates, issue config
    • release/ — release-process artifacts: version file, CHANGELOG.md rotation, release-note shuffling in docs/
    • Root config — Makefile, version, CHANGELOG.next.md, etc.
  • PR description body — check which of the 7 template sections from .github/PULL_REQUEST_TEMPLATE.md are filled vs empty/placeholder.
  • Diff content — scan for signals: new field set files, field removals, type: changes, new reusable entries, allowed_values additions, alpha/beta changes, etc.
2. Classify the change

Walk the decision tree in classification-rules.md in priority order:

  1. Check for release process PR first — if the PR exclusively touches release mechanics (version bumps, changelog rotation, moving/updating release notes in docs/, CHANGELOG.md consolidation) it is always Direct PR. Release PRs never require an RFC or discussion regardless of how many files change.
  2. Check §1 (RFC triggers) — any match means classification is Needs RFC. Triggers: new schemas/*.yml file, breaking changes (field removal, type change, semantic redefinition), new reuse topology, novel use case, ECS-wide scope, >10 new leaf fields.
  3. Check §3 (ambiguous) — any match (without §1) means classification is Needs Discussion. Includes: 3–10 new fields in one field set, new allowed_values on categorization fields (event.category, event.type, event.kind), maturity promotions, unjustified object/flattened.
  4. Otherwise §2 — all remaining low-risk patterns → classification is Direct PR.

Assign labels:

  • Change type: Schema Change | Tooling | Documentation | Mixed
  • Scope: Minor | Moderate | Substantial
3. Check completeness

Evaluate against the checklist in ecs-pr-completeness rule:

  • PR description: all 7 template sections answered (not empty/placeholder).
  • CHANGELOG.next.md entry: only expected when schemas/ or scripts/ files change (i.e. schema changes or tooling changes). RFC-only PRs (rfcs/ only), pure documentation PRs, CI-only PRs, and release process PRs do not require a changelog entry. When required, verify it is in the correct section (Schema Changes vs Tooling and Artifact Changes) and includes #NNNN.
  • If schema change: generated/ and docs/reference/ artifacts present in the diff (evidence that make was run and outputs committed).
  • If new/changed fields relate to OTel semconv: otel: metadata is encouraged but not required.
  • No hand-edits to files that should only be generator output (docs/reference/ecs-*.md, generated/).

Mark each item as met or missing.

Show full SKILL.md (214 more words)Show less
4. Produce the triage report

Fill report-template.md completely. Rules:

  • Cite specific triggers. E.g. "New file schemas/foo.yml detected → RFC required per classification-rules §1."
  • List every missing checklist item with clear remediation (e.g. "Add a CHANGELOG.next.md entry under Schema Changes > Added with #NNNN").
  • If Needs RFC: point the contributor to rfcs/PROCESS.md and the RFC template at rfcs/0000-rfc-template.md. Reference the ecs-rfc-guide skill for a detailed walkthrough.
  • If Needs Discussion: state exactly what is ambiguous and what a maintainer should weigh in on.

Decision defaults

  • Conservative: when borderline, prefer Needs Discussion or Needs RFC over Direct PR. Under-triaging is worse than over-triaging.
  • No approval authority: the agent triages and reports. It does not approve, request changes, or merge.

Important repo facts

  • Source of truth for fields: schemas/*.yml. Hand-edits to generated/ or docs/reference/ecs-*.md without a corresponding schema change are errors — flag them.
  • Build pipeline: make regenerates all artifacts; make test runs unit tests; make check runs generate + test + diff (CI parity).
  • RFC process: single Proposal stage per rfcs/PROCESS.md; template at rfcs/0000-rfc-template.md.
  • OTel mapping: otel: metadata on fields is optional; encouraged when a clear semconv counterpart exists but not a merge gate.

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in .agents/skills/ecs-pr-triage of elastic/ecs.

  • SKILL.md
  • classification-rules.md
  • report-template.md

Open the folder on GitHubat commit 9868ff5

Compare with similar skills

Ecs PR Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ecs PR Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ecs PR Triage this skillelastic/ecs1.1k—~1.5kAutomated safety check: PassApache-2.0
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
PR Design DocOpenHands/OpenHands90k—~2.4kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • PR Design Doc

    OpenHands/OpenHands

    For a non-trivial pull request, write a self-contained HTML design doc under the temporary .pr/ directory and link a visibility-appropriate preview in the PR description, so maintainers grasp the…

    90k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Record PR Demo

    payloadcms/payload

    A skill your agent uses when a Payload pull request needs a concise visual walkthrough for reviewers.

    45k GitHub stars~1k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from elastic/ecs

  • Ecs Rfc Guide

    elastic/ecs

    Official

    Guides contributors through the Elastic Common Schema (ECS) RFC (Proposal) process: template sections, target maturity (alpha/beta), rfcs/text artifacts, and optional OTel mapping.

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Ecs PR Triage

What does Ecs PR Triage do?

Triages an ECS pull request. An agent skill from elastic/ecs. Ecs PR Triage is an agent skill from elastic/ecs, published by the product's own GitHub organization. Triages an ECS pull request.

When should I use Ecs PR Triage?

Ecs PR Triage fits situations like: tasks that involve Pull requests.

How do I install Ecs PR Triage in Claude Code?

Run `npx skills add elastic/ecs --skill ecs-pr-triage -a claude-code`. Or copy the skill folder (.agents/skills/ecs-pr-triage in elastic/ecs) into .claude/skills/ecs-pr-triage in your project. Claude Code loads it when a task matches its description.

How do I install Ecs PR Triage in Codex?

Run `npx skills add elastic/ecs --skill ecs-pr-triage -a codex`. Or copy the skill folder (.agents/skills/ecs-pr-triage in elastic/ecs) into .agents/skills/ecs-pr-triage in your project. Codex loads it when a task matches its description.

Can I use Ecs PR Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/ecs --skill ecs-pr-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ecs-pr-triage, .gemini/skills/ecs-pr-triage, .github/skills/ecs-pr-triage and .opencode/skills/ecs-pr-triage in your project.

What does Ecs PR Triage need to run?

Going by SKILL.md and its folder, Ecs PR Triage needs the command-line tools its instructions call (gh and make).

Does Ecs PR Triage access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ecs PR Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ecs PR Triage use?

Ecs PR Triage is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ecs PR Triage use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ecs PR Triage?

Skills that share tags, products or a category with Ecs PR Triage: Finishing a Development Branch (obra/superpowers, 297k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars) and PR Design Doc (OpenHands/OpenHands, 90k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ecs PR Triage?

elastic (a GitHub organization, an official publisher) maintains it in elastic/ecs, which has 1,124 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 8, 2026.

Source: elastic/ecs on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.