Official agent skill

Ecs Rfc Guide

by elastic in elastic/ecs

Guides contributors through the Elastic Common Schema (ECS) RFC (Proposal) process: template sections, target maturity (alpha/beta), rfcs/text artifacts, and optional OTel mapping.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Ecs Rfc Guide

skills CLI
$ npx skills add elastic/ecs --skill ecs-rfc-guide -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/ecs ecs-rfc-guide --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/ecs.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ecs-rfc-guide .claude/skills/ecs-rfc-guide && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ecs-rfc-guide
GitHub stars
1.1k
Token cost
~1.2k tokens
SKILL.md length
501 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides contributors through the Elastic Common Schema (ECS) RFC (Proposal) process: template sections, target maturity (alpha/beta), rfcs/text artifacts, and optional OTel mapping.

  • Works in 5 steps: Single Proposal stage — template must… → Contributor opens a PR that adds the RFC… → Specify Target maturity: alpha, beta, or… → …
  • A change needs an RFC
  • SKILL.md covers When this applies, Current process (short), Template walkthrough and rfcs/text// folder, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ecs Rfc Guide is an agent skill from elastic/ecs, published by the product's own GitHub organization. Guides contributors through the Elastic Common Schema (ECS) RFC (Proposal) process: template sections, target maturity (alpha/beta), rfcs/text artifacts, and optional OTel mapping. Use when a change needs an RFC, when drafting or reviewing RFC PRs, or when the user asks how to propose new ECS field sets or substantial schema changes.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with OpenTelemetry and Elasticsearch. The licence is Apache-2.0.

When your agent uses it

  • A change needs an RFC
  • Reviewing RFC PRs
  • The user asks how to propose new ECS field sets
  • Substantial schema changes

Example prompts

  • “Use the ecs-rfc-guide skill to guide contributors through the Elastic Common Schema (ECS) RFC (Proposal) process: template sections, target maturity…”
  • “/ecs-rfc-guide”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Single Proposal stage — template must keep Stage: Proposal.
  2. Contributor opens a PR that adds the RFC markdown under rfcs/ (name like 0000-.md until numbered).
  3. Specify Target maturity: alpha, beta, or mixture (see Field stability).
  4. The PR author assigns the next available RFC number (scan rfcs/text/ for the highest existing number). ECS team reviews holistically and…
  5. If applicable, the RFC PR should include the schema changes (schemas/*.yml, generated artifacts, docs) at the agreed maturity level…

What it can do on your machine

Read from SKILL.md and the folder at commit 9868ff5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ecs Rfc Guide loads about 1.2k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 501 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elastic/ecs at commit 9868ff5, republished under its Apache-2.0 licence (© elastic). 501 words, ~1,213 tokens.

Download SKILL.mdSave it as .claude/skills/ecs-rfc-guide/SKILL.md (or your agent's skills folder).
name
ecs-rfc-guide
description
Guides contributors through the Elastic Common Schema (ECS) RFC (Proposal) process: template sections, target maturity (alpha/beta), rfcs/text artifacts, and optional OTel mapping. Use when a change needs an RFC, when drafting or reviewing RFC PRs, or when the user asks how to propose new ECS field sets or substantial schema changes.

ECS RFC (Proposal) guide

When this applies

Use after ecs-pr-triage (or equivalent judgment) says Needs RFC, or when the user is starting a new field set, breaking change, novel use case, or ECS-wide design.

Authoritative process: rfcs/PROCESS.md. Template: rfcs/0000-rfc-template.md. High-level triggers: rfcs/README.md.

Current process (short)

  1. Single Proposal stage — template must keep Stage: **Proposal**.
  2. Contributor opens a PR that adds the RFC markdown under rfcs/ (name like 0000-<dash-separated-name>.md until numbered).
  3. Specify Target maturity: alpha, beta, or mixture (see Field stability).
  4. The PR author assigns the next available RFC number (scan rfcs/text/ for the highest existing number). ECS team reviews holistically and merges on approval.
  5. If applicable, the RFC PR should include the schema changes (schemas/*.yml, generated artifacts, docs) at the agreed maturity level — proposal and implementation land together in a single PR.

Template walkthrough

Copy rfcs/0000-rfc-template.md. Remove HTML comments as sections are filled.

SectionWhat “good” looks like
Summary2–5 sentences: what, why, impact.
UsageEnd-to-end: producer → storage → queries/dashboards/detections.
FieldsEvery proposed field: name, type, description, level/maturity, example. Prefer YAML blocks. If object/flattened without children, justify shape and conflict avoidance (see schemas/README.md).
Source data≥2 real examples (JSON/logs); link or place large payloads under rfcs/text/<n>/.
Scope of impactIngestion (Beats/Agents), Kibana/apps, ECS repo (docs/tooling).
ConcernsRisks + resolved mitigations; OTel overlap; naming; adoption.
PeopleAuthor, SMEs, reviewers.
ReferencesPrior art, semconv links, related issues/PRs.

rfcs/text/<number>/ folder

When the RFC adds or changes fields:

  • Create rfcs/text/<number>/ with standalone YAML snippets, large JSON examples, or mappings — especially when the markdown would be huge.
  • Use the next free folder number (scan rfcs/text/; duplicates get fixed at merge per template notes).
  • Align filenames with affected field sets (e.g. faas.yml, gen_ai.yaml) for reviewer navigation.
Show full SKILL.md (219 more words)Show less

OTel alignment (optional)

ECS tracks relationships between its fields and OTel semconv via otel: metadata tags in schemas/*.yml.

  • When a new or changed field has a clear OTel semconv counterpart, adding an otel: block (with relation: match | equivalent | related | conflict | na) is encouraged but not required.
  • The otel: metadata is used to generate alignment documentation — it is not a gate for merging.
  • If unsure whether an OTel mapping applies, omit it; it can be added later.

Maturity choice (alpha vs beta)

  • Alpha — earlier, may change more; good for exploratory or fast-moving domains.
  • Beta — clearer adoption path; still subject to change before GA.
  • Mixture — some fields alpha, some beta; explain per field or group.

Promotion after merge is out of band from the RFC (team process per PROCESS.md).

PR hygiene

  • Link the Proposal PR at the bottom of the RFC (### RFC Pull Requests).
  • Do not replace process with old multi-stage labels found in historical RFCs under rfcs/text/*.md; those are legacy examples only.

Example RFCs (depth reference)

Implementation in the RFC PR

The RFC PR itself should include the schema implementation: schemas/*.yml changes, make-generated artifacts, and a CHANGELOG.next.md entry. There is no separate "handoff" — proposal and schema land together.

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/ecs-rfc-guide of elastic/ecs.

Open the folder on GitHubat commit 9868ff5

Compare with similar skills

Ecs Rfc Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ecs Rfc Guide compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ecs Rfc Guide this skillelastic/ecs1.1k—~1.2kAutomated safety check: PassApache-2.0
UModel Root Cause Analysisalibaba/UnifiedModel412—~1.9kAutomated safety check: PassCustom licence
Aspire Diagnosticsexceptionless/Exceptionless2.5k—~769Automated safety check: PassApache-2.0
Kibana Otel Instrumentationelastic/kibana21k—~5.1kAutomated safety check: PassCustom licence
Observability Onboardingelastic/agent-skills592—~4.1kAutomated safety check: PassApache-2.0
Observability K8s Investigationelastic/agent-skills592—~8.3kAutomated safety check: PassApache-2.0

Similar skills

  • UModel Root Cause Analysis

    alibaba/UnifiedModel

    Investigates a service incident to its root cause by querying a UModel object graph alongside metrics, logs, topology and recent deployments.

    412 GitHub stars~1.9k tokensUpdated 14 days ago
    DevOps & CloudAuto-check passed
  • Aspire Diagnostics

    exceptionless/Exceptionless

    Inspect local Aspire resource health, logs, traces, and browser telemetry.

    2.5k GitHub stars~769 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Implement and quality-check OpenTelemetry metric instrumentation in Kibana code that uses @kbn/metrics.

    21k GitHub stars~5.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Observability Onboarding

    elastic/agent-skills

    Official

    Onboard an application into Elastic Observability with the Elastic Distribution of OpenTelemetry (EDOT): route on language and runtime, detect and replace a classic Elastic APM agent, apply the…

    592 GitHub stars~4.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    Investigate Kubernetes workload, node, and control-plane issues using OTel telemetry (EDOT).

    592 GitHub stars~8.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Observability Sre Triage

    elastic/agent-skills

    Official

    Triage a degraded or suspect service end to end: read SLO status and burn rate, check active alerting rules and ML anomalies, measure throughput, latency, and error rate, assess dependency health…

    592 GitHub stars~7.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from elastic/ecs

  • Ecs PR Triage

    elastic/ecs

    Official

    Triages an ECS pull request. An agent skill from elastic/ecs.

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Ecs Rfc Guide

What does Ecs Rfc Guide do?

Guides contributors through the Elastic Common Schema (ECS) RFC (Proposal) process: template sections, target maturity (alpha/beta), rfcs/text artifacts, and optional OTel mapping. Ecs Rfc Guide is an agent skill from elastic/ecs, published by the product's own GitHub organization. Guides contributors through the Elastic Common Schema (ECS) RFC (Proposal) process: template sections, target maturity (alpha/beta), rfcs/text artifacts, and optional OTel mapping.

When should I use Ecs Rfc Guide?

Ecs Rfc Guide fits situations like: A change needs an RFC; reviewing RFC PRs; the user asks how to propose new ECS field sets; substantial schema changes.

How do I install Ecs Rfc Guide in Claude Code?

Run `npx skills add elastic/ecs --skill ecs-rfc-guide -a claude-code`. Or copy the skill folder (.agents/skills/ecs-rfc-guide in elastic/ecs) into .claude/skills/ecs-rfc-guide in your project. Claude Code loads it when a task matches its description.

How do I install Ecs Rfc Guide in Codex?

Run `npx skills add elastic/ecs --skill ecs-rfc-guide -a codex`. Or copy the skill folder (.agents/skills/ecs-rfc-guide in elastic/ecs) into .agents/skills/ecs-rfc-guide in your project. Codex loads it when a task matches its description.

Can I use Ecs Rfc Guide in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/ecs --skill ecs-rfc-guide -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ecs-rfc-guide, .gemini/skills/ecs-rfc-guide, .github/skills/ecs-rfc-guide and .opencode/skills/ecs-rfc-guide in your project.

What does Ecs Rfc Guide need to run?

SKILL.md names no scripts, command-line tools or credentials: Ecs Rfc Guide is instructions for the agent only.

Does Ecs Rfc Guide access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ecs Rfc Guide safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ecs Rfc Guide use?

Ecs Rfc Guide is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ecs Rfc Guide use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ecs Rfc Guide?

Skills that share tags, products or a category with Ecs Rfc Guide: UModel Root Cause Analysis (alibaba/UnifiedModel, 412 stars), Aspire Diagnostics (exceptionless/Exceptionless, 2.5k stars), Kibana Otel Instrumentation (elastic/kibana, 21k stars) and Observability Onboarding (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ecs Rfc Guide?

elastic (a GitHub organization, an official publisher) maintains it in elastic/ecs, which has 1,123 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 7, 2026.

Source: elastic/ecs on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.