Official agent skill

Elasticsearch Anomaly Detection Explainer

by elastic in elastic/agent-skills

Explain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation.

OfficialApache-2.0Auto-check passedData & Analytics

Install Elasticsearch Anomaly Detection Explainer

skills CLI
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection-explainer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection-explainer .claude/skills/elasticsearch-anomaly-detection-explainer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
elasticsearch-anomaly-detection-explainer
GitHub stars
592
Token cost
~4.5k tokens
SKILL.md length
1,806 words
Files
2 (incl. references)
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Explain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation.

  • Works in 7 steps: Decide whether to fetch data or… → Verify connectivity when calling the… → Resolve the job ID and load config. When… → …
  • The user asks why a score is high
  • SKILL.md covers Environment Configuration, Process, Common multi-step workflows and Critical principles, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Elasticsearch Anomaly Detection Explainer is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Explain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation. Use when the user asks why a score is high or low, how the model learns, what the numbers mean, or how to troubleshoot unexpected anomaly scores.

Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/explainer-reference.md`). Compatibility notes: Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API and the standard search API against .ml-anomalies- —…

It sits in Data & Analytics, covering Search implementation and Anomaly detection. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.

When your agent uses it

  • The user asks why a score is high
  • How the model learns
  • What the numbers mean
  • How to troubleshoot unexpected anomaly scores

Example prompts

  • “/elasticsearch-anomaly-detection-explainer”

Requirements

  • Compatibility (from SKILL.md): Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API and the standard _search API against .ml-anomalies-* — no ES|QL. User needs monitor_ml privilege for ML APIs.

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Decide whether to fetch data or interpret what the user supplied. If the user embeds an anomaly record (or job
  2. Verify connectivity when calling the cluster. Call GET /. If the call fails, stop and surface the connection
  3. Resolve the job ID and load config. When the job ID is unknown, call GET /_ml/anomaly_detectors to list
  4. Retrieve anomaly records for the time range. Call POST /.ml-anomalies-*/_search with result_type: record, the
  5. Classify the score pattern before speculating on causes.
  6. Quantify renormalization across the job (optional). Re-query POST /.ml-anomalies-*/_search for records in the
  7. Add context when the user asks "what caused this?" or "why so low/high?"

What it can do on your machine

Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API and the standard _search API against .ml-anomalies-* — no ES|QL. User needs monitor_ml privilege for ML APIs.

    From compatibility in the SKILL.md frontmatter.

Context cost

Elasticsearch Anomaly Detection Explainer loads about 4.5k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 70 tokens; SKILL.md has 1,806 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~4.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,806 words, ~4,458 tokens.

Download SKILL.mdSave it as .claude/skills/elasticsearch-anomaly-detection-explainer/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
elasticsearch-anomaly-detection-explainer
description
Explain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation. Use when the user asks why a score is high or low, how the model learns, what the numbers mean, or how to troubleshoot unexpected anomaly scores.
compatibility
Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API and the standard _search API against .ml-anomalies-* — no ES|QL. User needs monitor_ml privilege for ML APIs.
metadata.author
elastic
metadata.version
0.3.0
metadata.universal
true

Anomaly Detection Score Explainer

Explain anomaly scores, model behavior, and why results look the way they do. Use the ML REST API for job config and the standard _search API against .ml-anomalies-* for results — no ES|QL, fully compatible with Elastic Serverless. For job lifecycle (create, start, stop), use the elasticsearch-anomaly-detection skill.

<!-- begin-partial: preamble -->

Environment Configuration

This skill executes Elasticsearch operations through the elastic CLI. If the elastic CLI is not installed, tell the user what it is needed for. Do not guess credentials, call the HTTP API directly, or attempt other workarounds.

This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping, GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API directly.

<!-- end-partial: preamble -->

Prerequisite: ML anomaly detection requires a Platinum-equivalent license on self-managed clusters. Serverless projects include ML. The caller needs monitor_ml to read job config and anomaly results.

Serverless note: The _ml/.../results/* REST endpoints return HTTP 410 in Elastic Serverless. Always use POST /.ml-anomalies-*/_search for result queries instead — fully supported everywhere this skill runs.

Process

  1. Decide whether to fetch data or interpret what the user supplied. If the user embeds an anomaly record (or job config) in the prompt, interpret it directly using the domain knowledge below — do not call APIs to re-fetch fields already present. If the job ID, time range, or record is missing, retrieve it from the cluster.

    The decision: proceed with judgment-only explanation when the record contains record_score, initial_record_score, actual, typical, and function; otherwise fetch the missing pieces before explaining.

  2. Verify connectivity when calling the cluster. Call GET /. If the call fails, stop and surface the connection error — do not guess endpoints or credentials.

  3. Resolve the job ID and load config. When the job ID is unknown, call GET /_ml/anomaly_detectors to list candidates. Call GET /_ml/anomaly_detectors/{job_id} for full analysis_config (bucket_span, detectors, custom_rules, use_null, model_plot_config) and GET /_ml/anomaly_detectors/{job_id}/_stats for state, model_size_stats.memory_status, and data counts.

    The decision: confirm detector function and direction match the user's question before interpreting scores. A low_count job legitimately fires on drops; a high_count job does not.

  4. Retrieve anomaly records for the time range. Call POST /.ml-anomalies-*/_search with result_type: record, the job ID, a timestamp range, and optional record_score filter. Read initial_record_score, record_score, actual, typical, function, multi_bucket_impact, and anomaly_score_explanation.

    Always show both initial_record_score and record_score. The gap is the renormalization story.

  5. Classify the score pattern before speculating on causes.

    • initial_record_score >> record_score — Renormalization. A later, more extreme anomaly rescale this record downward. This is expected, healthy model behavior — not a broken model or reason to distrust the detection. Use initial_record_score for alerting severity; show both scores and explain the gap explicitly.
    • initial_record_score == record_score — No renormalization has occurred since detection.
    • actual << typical with low_count, count, or low_mean — Absence / drop anomaly. A high score is legitimate — the job detected an outage, pipeline stall, or service failure. This is not a false positive. Recommend incident investigation, not score tuning.
    • actual >> typical with high_count or high_mean — Spike anomaly; confirm with single_bucket_impact.

    Only cite anomaly_score_explanation factors present in the record. If high_variance_penalty is false, do not blame variance. If a factor is absent, note that it was not returned — do not invent it.

  6. Quantify renormalization across the job (optional). Re-query POST /.ml-anomalies-*/_search for records in the time range sorted by timestamp ascending. Compute score_drift = initial_record_score − record_score per record and filter to |score_drift| ≥ 20. Large negative drift (initial >> record) confirms renormalization after a more extreme anomaly appeared later.

  7. Add context when the user asks "what caused this?" or "why so low/high?"

    • Model bounds — If model_plot_config.enabled is true, call POST /.ml-anomalies-*/_search with result_type: model_plot for the same job and time range. Compare actual to model_lower / model_upper.
    • Influencers — Call POST /.ml-anomalies-*/_search with result_type: influencer for the bucket time range; sort by influencer_score descending.
    • Categorization jobs — Call POST /.ml-anomalies-*/_search with result_type: category_definition to list learned log patterns (terms, regex, examples per category_id).

    For aggregations, cross-job queries, bucket-level results, or custom filters beyond score and time, see references/explainer-reference.md.

Common multi-step workflows

TaskSteps (in order)
Explain a specific anomalyjob config → records (job + exact time) → show initial_record_score vs record_score + score factors.
Why is my score low?job config → records → renormalization check → model plot (if enabled) → explain score factors.
Why is my score high?job config → records → check function direction, insufficient history, use_null, cardinality.
Renormalization driftrecords (timestamp sort) → compute score_drift → list records where initial >> record.
Which entities contributed?influencers (job + time range) → sort by influencer_score.
Visualize model boundsmodel plot (job + time range) → compare model_lower/model_upper vs actual.
Categorization job patternscategory_definition (job_id) → terms, regex, examples per category.

Critical principles

  • Retrieve the record first (or use the one the user supplied). Never explain scores without initial_record_score, record_score, actual, typical, and function.
  • Renormalization is healthy. When initial_record_score >> record_score, a more extreme anomaly appeared later and lowered this score — expected behavior, not a model failure.
  • Direction matters. low_count fires when values drop; high_count fires on spikes. A high score on a traffic stop with low_count is correct detection, not a false positive.
  • Explain factors before speculating. Read anomaly_score_explanation from the record. Only address factors that are present and relevant.
  • Job config is essential. bucket_span, detector function, custom_rules, use_null, and memory status all affect scores. Inspect job config when a score is surprising.
  • Model plot is the most visual explanation. When enabled, show model bounds to illustrate where the actual value falls relative to the expected range.
  • For job health ("missing documents", "memory limit", "datafeed not running") use the elasticsearch-anomaly-detection skill.

Domain knowledge

Score types
TermMeaning
record_scoreNormalized 0–100 for a single anomaly record; updated by renormalization. >75 critical.
initial_record_scoreScore assigned at detection time, before renormalization. Use for alerting.
anomaly_scoreBucket-level severity aggregated across all detectors in a job.
influencer_scoreHow unusual a specific entity (host, user, service) is in a bucket; high = likely cause.
multi_bucket_impact0–5; how much sustained, multi-bucket behavior raised the score. ≥3 = behavioral shift.
anomaly_score_explanation factors

The anomaly_score_explanation field on each record breaks the score into components:

FactorDirectionMeaning
anomaly_lengthRaisesNumber of consecutive buckets the anomaly spans. Longer → higher score.
single_bucket_impactRaisesExtremity of this single bucket. Lower probability → higher impact.
multi_bucket_impactRaisesContribution of sustained multi-bucket pattern.
anomaly_characteristics_impactRaisesWhether the anomaly is a mean shift vs. variance change.
high_variance_penaltyLowersNoisy data or early training → wide confidence bounds → score reduced.
incomplete_bucket_penaltyLowersBucket had less data than expected (delayed data, sparse events).
Show full SKILL.md (732 more words)Show less
Why a score might be unexpectedly low
  • high_variance_penalty: The metric is historically noisy — wide confidence bounds absorb the spike.
  • Renormalization: A more extreme anomaly appeared later and pushed this score down (initial_record_score >> record_score).
  • Insufficient training history: Need ≥3 weeks for weekly seasonality, ≥2 full cycles for any detected period.
  • bucket_span too large: Short-duration spikes get smoothed. Use a smaller bucket_span for high-frequency events.
  • Detector function mismatch: mean vs high_mean, count vs high_count — only one direction fires.
  • incomplete_bucket_penalty: Bucket received less data than expected (ingest latency or gaps).
  • custom_rules: A detector filter may be suppressing the anomaly.
Why a score might be unexpectedly high
  • Insufficient history: Model hasn't learned the normal pattern yet — early anomalies are unreliable.
  • Model split thin: High-cardinality partition_field or by_field → very few points per entity → unreliable probabilities.
  • use_null: If use_null: true, missing entities produce "null" anomalies that may not be meaningful.
  • Absence / drop detection: With low_count or low_mean, actual << typical produces a legitimately high score — treat as a real incident, not a false positive.
Model behavior concepts
ConceptMeaning
actualObserved value. typical is what the model expected. The direction matters.
Absence anomalyactual << typical with count, low_count, or low_mean → outage, pipeline stop, service failure.
by_fieldIndependent baseline per entity (e.g., per host). Each entity compared to its own history.
over_fieldPopulation analysis — entity compared to its peer group in the same bucket, not its own history.
partition_fieldFully independent sub-models with separate score normalization per partition.
Model plot and categories
  • Model plot: Shows the model's learned upper and lower bounds at each time point. If actual is within bounds, no anomaly; if outside, the score depends on the distance from bounds. Only available when model_plot_config is enabled on the job. Query via POST /.ml-anomalies-*/_search with result_type: model_plot.
  • Categories: For jobs with a categorization_field_name, query result_type: category_definition to show log message patterns (terms, regex, examples per category_id). Anomaly records use by_field_value = <category_id>.

Score troubleshooting protocol

  1. List jobs — Call GET /_ml/anomaly_detectors when the job ID is unknown.
  2. Get job config and stats — Call GET /_ml/anomaly_detectors/{job_id} and GET /_ml/anomaly_detectors/{job_id}/_stats. Verify bucket_span, detector function, custom_rules, use_null, job state (opened/closed/failed), and model_size_stats.memory_status.
  3. Retrieve the record — Call POST /.ml-anomalies-*/_search with result_type: record, the job ID, time range, and optional minimum record_score. Inspect initial_record_score, record_score, actual, typical, function, multi_bucket_impact, and anomaly_score_explanation.
  4. Check renormalization — Compare initial_record_score vs record_score. If initial >> record, re-query records sorted by timestamp and compute score_drift to quantify renormalization across the job.
  5. Visualize model bounds — If model_plot_config is enabled, query result_type: model_plot and show where the actual value fell relative to model_lower and model_upper.
  6. Influencers — Query result_type: influencer for the anomaly bucket time range; sort by influencer_score.
  7. Explain factors — From the record's anomaly_score_explanation, address each present relevant factor: high_variance_penalty, incomplete_bucket_penalty, anomaly_length, single_bucket_impact, multi_bucket_impact. Do not cite factors absent from the record.

Examples

  • "Why is my anomaly score only 15 when the spike looks huge?" → Check renormalization: initial_record_score (~92) >> record_score (~15). The spike was real; the current score was rescaled down. Use the initial score for alerting.
  • "Traffic stopped and I got a HIGH score — false positive?" → No. low_count with actual far below typical is legitimate absence detection. Investigate the outage.
  • "Which entities contributed most to the anomalies in job X last night?" → Query influencers for the time range.
  • "Show me the model bounds for this job." → Query model plot when model_plot_config is enabled.
  • "List records where the score was renormalized down a lot." → Records sorted by timestamp; filter large initial_record_score − record_score.

Guidelines

  • Report only what the API or the user-supplied record contains; do not invent scores, timestamps, entity values, or explanation factors.
  • Always show both initial_record_score and record_score when explaining a record; state explicitly whether renormalization occurred.
  • When a score factor is missing from the record, do not assert it; note that the field was not returned.
  • Do not attribute low scores to high_variance_penalty or incomplete_bucket_penalty when those flags are false or absent in the record.
  • For investigation ("what caused this?", "which service is responsible?") query influencers or construct cross-job searches via references/explainer-reference.md.
  • For job health use the elasticsearch-anomaly-detection skill.

Operations

HTTP API (shorthand)elastic CLI command
GET /elastic es info
GET /_ml/anomaly_detectorselastic es ml get-jobs
GET /_ml/anomaly_detectors/{job_id}elastic es ml get-jobs --job-id '<job_id>'
GET /_ml/anomaly_detectors/{job_id}/_statselastic es ml get-job-stats --job-id '<job_id>'
POST /.ml-anomalies-*/_searchelastic es search --index '.ml-anomalies-*' --input-file '<search-body.json>'

Query body shapes for each result_type (record, influencer, model_plot, category_definition) are documented in references/explainer-reference.md.

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/elasticsearch/elasticsearch-anomaly-detection-explainer of elastic/agent-skills.

  • SKILL.md
  • references/explainer-reference.md

Open the folder on GitHubat commit baa5111

Compare with similar skills

Elasticsearch Anomaly Detection Explainer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Elasticsearch Anomaly Detection Explainer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Elasticsearch Anomaly Detection Explainer this skillelastic/agent-skills592—~4.5kAutomated safety check: PassApache-2.0
Amazon Opensearch Serviceaws/agent-toolkit-for-aws2.8k—~2.4kAutomated safety check: PassApache-2.0
Elasticsearch File IngestKilo-Org/kilo-marketplace190—~2.8kAutomated safety check: PassApache-2.0
Product Full-Text Searchlobehub/lobehub83k—~4.1kAutomated safety check: PassCustom licence
Time Series Analytics Useropen-edge-platform/edge-ai-libraries169—~3.1kAutomated safety check: PassApache-2.0
Elasticsearch Auditaspectrr/deer405—~1.7kAutomated safety check: PassMIT

Similar skills

  • Amazon Opensearch Service

    aws/agent-toolkit-for-aws

    Official

    Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…

    2.8k GitHub stars~2.4k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Elasticsearch File Ingest

    Kilo-Org/kilo-marketplace

    Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    190 GitHub stars~2.8k tokensUpdated 10 days ago
    Backend & APIsAuto-check passed
  • Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.

    83k GitHub stars~4.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Time Series Analytics User

    open-edge-platform/edge-ai-libraries

    Build a new time-series analytics use case on top of the deployed Time Series Analytics microservice — bring it up with Docker Compose (from a repo clone, or by fetching the compose files from…

    169 GitHub stars~3.1k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Foundatio Repositories

    exceptionless/Exceptionless

    Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.

    2.5k GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from elastic/agent-skills

All 26 skills in this repo
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    Auto-check: notes
  • Security Case Management

    elastic/agent-skills

    Official

    Create, search, update, and manage SOC cases via the Kibana Cases API.

    592 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Kibana Dashboards

    elastic/agent-skills

    Official

    Create and manage Kibana Dashboards and Lens visualizations.

    592 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Official

    Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

    592 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Cloud Onboarding

    elastic/agent-skills

    Official

    Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…

    592 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Elasticsearch Anomaly Detection Explainer

What does Elasticsearch Anomaly Detection Explainer do?

Explain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation. Elasticsearch Anomaly Detection Explainer is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Explain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation.

When should I use Elasticsearch Anomaly Detection Explainer?

Elasticsearch Anomaly Detection Explainer fits situations like: the user asks why a score is high; how the model learns; what the numbers mean; how to troubleshoot unexpected anomaly scores.

How do I install Elasticsearch Anomaly Detection Explainer in Claude Code?

Run `npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a claude-code`. Or copy the skill folder (skills/elasticsearch/elasticsearch-anomaly-detection-explainer in elastic/agent-skills) into .claude/skills/elasticsearch-anomaly-detection-explainer in your project. Claude Code loads it when a task matches its description.

How do I install Elasticsearch Anomaly Detection Explainer in Codex?

Run `npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a codex`. Or copy the skill folder (skills/elasticsearch/elasticsearch-anomaly-detection-explainer in elastic/agent-skills) into .agents/skills/elasticsearch-anomaly-detection-explainer in your project. Codex loads it when a task matches its description.

Can I use Elasticsearch Anomaly Detection Explainer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch-anomaly-detection-explainer, .gemini/skills/elasticsearch-anomaly-detection-explainer, .github/skills/elasticsearch-anomaly-detection-explainer and .opencode/skills/elasticsearch-anomaly-detection-explainer in your project.

What does Elasticsearch Anomaly Detection Explainer need to run?

SKILL.md names no scripts, command-line tools or credentials: Elasticsearch Anomaly Detection Explainer is instructions for the agent only. Compatibility (from SKILL.md): Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API and the standard _search API against .ml-anomalies-* — no ES|QL. User needs monitor_ml privilege for ML APIs. .

Does Elasticsearch Anomaly Detection Explainer access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Elasticsearch Anomaly Detection Explainer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Elasticsearch Anomaly Detection Explainer use?

Elasticsearch Anomaly Detection Explainer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Elasticsearch Anomaly Detection Explainer use?

About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Elasticsearch Anomaly Detection Explainer?

Skills that share tags, products or a category with Elasticsearch Anomaly Detection Explainer: Amazon Opensearch Service (aws/agent-toolkit-for-aws, 2.8k stars), Elasticsearch File Ingest (Kilo-Org/kilo-marketplace, 190 stars), Product Full-Text Search (lobehub/lobehub, 83k stars) and Time Series Analytics User (open-edge-platform/edge-ai-libraries, 169 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Elasticsearch Anomaly Detection Explainer?

elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.

Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.