Amazon Opensearch Service
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
Explain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation.
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection-explainer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection-explainer .claude/skills/elasticsearch-anomaly-detection-explainer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "elasticsearch-anomaly-detection-explainer" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection-explainer into .claude/skills/elasticsearch-anomaly-detection-explainer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-anomaly-detection-explainer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection-explainerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection-explainer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection-explainer .agents/skills/elasticsearch-anomaly-detection-explainer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "elasticsearch-anomaly-detection-explainer" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection-explainer into .agents/skills/elasticsearch-anomaly-detection-explainer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-anomaly-detection-explainer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection-explainer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection-explainer .cursor/skills/elasticsearch-anomaly-detection-explainer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "elasticsearch-anomaly-detection-explainer" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection-explainer into .cursor/skills/elasticsearch-anomaly-detection-explainer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-anomaly-detection-explainer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elastic/agent-skills.git --path skills/elasticsearch/elasticsearch-anomaly-detection-explainer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection-explainer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection-explainer .gemini/skills/elasticsearch-anomaly-detection-explainer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "elasticsearch-anomaly-detection-explainer" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection-explainer into .gemini/skills/elasticsearch-anomaly-detection-explainer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-anomaly-detection-explainer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection-explainerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection-explainer .github/skills/elasticsearch-anomaly-detection-explainer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "elasticsearch-anomaly-detection-explainer" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection-explainer into .github/skills/elasticsearch-anomaly-detection-explainer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-anomaly-detection-explainer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection-explainer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection-explainer .opencode/skills/elasticsearch-anomaly-detection-explainer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "elasticsearch-anomaly-detection-explainer" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection-explainer into .opencode/skills/elasticsearch-anomaly-detection-explainer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-anomaly-detection-explainer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
elasticsearch-anomaly-detection-explainerExplain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation.
Elasticsearch Anomaly Detection Explainer is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Explain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation. Use when the user asks why a score is high or low, how the model learns, what the numbers mean, or how to troubleshoot unexpected anomaly scores.
Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/explainer-reference.md`). Compatibility notes: Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API and the standard search API against .ml-anomalies- —…
It sits in Data & Analytics, covering Search implementation and Anomaly detection. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API and the standard _search API against .ml-anomalies-* — no ES|QL. User needs monitor_ml privilege for ML APIs.
From compatibility in the SKILL.md frontmatter.
Elasticsearch Anomaly Detection Explainer loads about 4.5k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 70 tokens; SKILL.md has 1,806 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,806 words, ~4,458 tokens.
.claude/skills/elasticsearch-anomaly-detection-explainer/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Explain anomaly scores, model behavior, and why results look the way they do. Use the ML REST API for job config and
the standard _search API against .ml-anomalies-* for results — no ES|QL, fully compatible with Elastic
Serverless. For job lifecycle (create, start, stop), use the elasticsearch-anomaly-detection skill.
<!-- begin-partial: preamble -->
This skill executes Elasticsearch operations through the elastic CLI. If the
elastic CLI is not installed, tell the user what it is needed for. Do
not guess credentials, call the HTTP API directly, or attempt other workarounds.
This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping,
GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document
maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API
directly.
<!-- end-partial: preamble -->
Prerequisite: ML anomaly detection requires a Platinum-equivalent license on self-managed clusters. Serverless projects include ML. The caller needs
monitor_mlto read job config and anomaly results.Serverless note: The
_ml/.../results/*REST endpoints return HTTP 410 in Elastic Serverless. Always usePOST /.ml-anomalies-*/_searchfor result queries instead — fully supported everywhere this skill runs.
Decide whether to fetch data or interpret what the user supplied. If the user embeds an anomaly record (or job config) in the prompt, interpret it directly using the domain knowledge below — do not call APIs to re-fetch fields already present. If the job ID, time range, or record is missing, retrieve it from the cluster.
The decision: proceed with judgment-only explanation when the record contains record_score, initial_record_score,
actual, typical, and function; otherwise fetch the missing pieces before explaining.
Verify connectivity when calling the cluster. Call GET /. If the call fails, stop and surface the connection
error — do not guess endpoints or credentials.
Resolve the job ID and load config. When the job ID is unknown, call GET /_ml/anomaly_detectors to list
candidates. Call GET /_ml/anomaly_detectors/{job_id} for full analysis_config (bucket_span, detectors,
custom_rules, use_null, model_plot_config) and GET /_ml/anomaly_detectors/{job_id}/_stats for state,
model_size_stats.memory_status, and data counts.
The decision: confirm detector function and direction match the user's question before interpreting scores. A
low_count job legitimately fires on drops; a high_count job does not.
Retrieve anomaly records for the time range. Call POST /.ml-anomalies-*/_search with result_type: record, the
job ID, a timestamp range, and optional record_score filter. Read initial_record_score, record_score, actual,
typical, function, multi_bucket_impact, and anomaly_score_explanation.
Always show both initial_record_score and record_score. The gap is the renormalization story.
Classify the score pattern before speculating on causes.
initial_record_score >> record_score — Renormalization. A later, more extreme anomaly rescale this
record downward. This is expected, healthy model behavior — not a broken model or reason to distrust the detection.
Use initial_record_score for alerting severity; show both scores and explain the gap explicitly.initial_record_score == record_score — No renormalization has occurred since detection.actual << typical with low_count, count, or low_mean — Absence / drop anomaly. A high score is
legitimate — the job detected an outage, pipeline stall, or service failure. This is not a false positive.
Recommend incident investigation, not score tuning.actual >> typical with high_count or high_mean — Spike anomaly; confirm with single_bucket_impact.Only cite anomaly_score_explanation factors present in the record. If high_variance_penalty is false, do
not blame variance. If a factor is absent, note that it was not returned — do not invent it.
Quantify renormalization across the job (optional). Re-query POST /.ml-anomalies-*/_search for records in the
time range sorted by timestamp ascending. Compute score_drift = initial_record_score − record_score per record
and filter to |score_drift| ≥ 20. Large negative drift (initial >> record) confirms renormalization after a more
extreme anomaly appeared later.
Add context when the user asks "what caused this?" or "why so low/high?"
model_plot_config.enabled is true, call POST /.ml-anomalies-*/_search with
result_type: model_plot for the same job and time range. Compare actual to model_lower / model_upper.POST /.ml-anomalies-*/_search with result_type: influencer for the bucket time range;
sort by influencer_score descending.POST /.ml-anomalies-*/_search with result_type: category_definition to list
learned log patterns (terms, regex, examples per category_id).For aggregations, cross-job queries, bucket-level results, or custom filters beyond score and time, see references/explainer-reference.md.
| Task | Steps (in order) |
|---|---|
| Explain a specific anomaly | job config → records (job + exact time) → show initial_record_score vs record_score + score factors. |
| Why is my score low? | job config → records → renormalization check → model plot (if enabled) → explain score factors. |
| Why is my score high? | job config → records → check function direction, insufficient history, use_null, cardinality. |
| Renormalization drift | records (timestamp sort) → compute score_drift → list records where initial >> record. |
| Which entities contributed? | influencers (job + time range) → sort by influencer_score. |
| Visualize model bounds | model plot (job + time range) → compare model_lower/model_upper vs actual. |
| Categorization job patterns | category_definition (job_id) → terms, regex, examples per category. |
initial_record_score,
record_score, actual, typical, and function.initial_record_score >> record_score, a more extreme anomaly appeared later and
lowered this score — expected behavior, not a model failure.low_count fires when values drop; high_count fires on spikes. A high score on a traffic
stop with low_count is correct detection, not a false positive.anomaly_score_explanation from the record. Only address factors that
are present and relevant.bucket_span, detector function, custom_rules, use_null, and memory status all
affect scores. Inspect job config when a score is surprising.elasticsearch-anomaly-detection
skill.| Term | Meaning |
|---|---|
| record_score | Normalized 0–100 for a single anomaly record; updated by renormalization. >75 critical. |
| initial_record_score | Score assigned at detection time, before renormalization. Use for alerting. |
| anomaly_score | Bucket-level severity aggregated across all detectors in a job. |
| influencer_score | How unusual a specific entity (host, user, service) is in a bucket; high = likely cause. |
| multi_bucket_impact | 0–5; how much sustained, multi-bucket behavior raised the score. ≥3 = behavioral shift. |
The anomaly_score_explanation field on each record breaks the score into components:
| Factor | Direction | Meaning |
|---|---|---|
| anomaly_length | Raises | Number of consecutive buckets the anomaly spans. Longer → higher score. |
| single_bucket_impact | Raises | Extremity of this single bucket. Lower probability → higher impact. |
| multi_bucket_impact | Raises | Contribution of sustained multi-bucket pattern. |
| anomaly_characteristics_impact | Raises | Whether the anomaly is a mean shift vs. variance change. |
| high_variance_penalty | Lowers | Noisy data or early training → wide confidence bounds → score reduced. |
| incomplete_bucket_penalty | Lowers | Bucket had less data than expected (delayed data, sparse events). |
initial_record_score >>
record_score).bucket_span for high-frequency events.mean vs high_mean, count vs high_count — only one direction fires.partition_field or by_field → very few points per entity → unreliable
probabilities.use_null: true, missing entities produce "null" anomalies that may not be meaningful.low_count or low_mean, actual << typical produces a legitimately high score —
treat as a real incident, not a false positive.| Concept | Meaning |
|---|---|
| actual | Observed value. typical is what the model expected. The direction matters. |
| Absence anomaly | actual << typical with count, low_count, or low_mean → outage, pipeline stop, service failure. |
| by_field | Independent baseline per entity (e.g., per host). Each entity compared to its own history. |
| over_field | Population analysis — entity compared to its peer group in the same bucket, not its own history. |
| partition_field | Fully independent sub-models with separate score normalization per partition. |
actual is within bounds, no
anomaly; if outside, the score depends on the distance from bounds. Only available when model_plot_config is enabled
on the job. Query via POST /.ml-anomalies-*/_search with result_type: model_plot.categorization_field_name, query result_type: category_definition to show log
message patterns (terms, regex, examples per category_id). Anomaly records use by_field_value = <category_id>.GET /_ml/anomaly_detectors when the job ID is unknown.GET /_ml/anomaly_detectors/{job_id} and
GET /_ml/anomaly_detectors/{job_id}/_stats. Verify bucket_span, detector function, custom_rules, use_null,
job state (opened/closed/failed), and model_size_stats.memory_status.POST /.ml-anomalies-*/_search with result_type: record, the job ID, time range,
and optional minimum record_score. Inspect initial_record_score, record_score, actual, typical, function,
multi_bucket_impact, and anomaly_score_explanation.initial_record_score vs record_score. If initial >> record, re-query records
sorted by timestamp and compute score_drift to quantify renormalization across the job.model_plot_config is enabled, query result_type: model_plot and show where the
actual value fell relative to model_lower and model_upper.result_type: influencer for the anomaly bucket time range; sort by influencer_score.anomaly_score_explanation, address each present relevant factor:
high_variance_penalty, incomplete_bucket_penalty, anomaly_length, single_bucket_impact,
multi_bucket_impact. Do not cite factors absent from the record.initial_record_score (~92) >>
record_score (~15). The spike was real; the current score was rescaled down. Use the initial score for alerting.low_count with actual far below typical is
legitimate absence detection. Investigate the outage.model_plot_config is enabled.initial_record_score − record_score.initial_record_score and record_score when explaining a record; state explicitly whether
renormalization occurred.high_variance_penalty or incomplete_bucket_penalty when those flags are false or
absent in the record.elasticsearch-anomaly-detection skill.| HTTP API (shorthand) | elastic CLI command |
|---|---|
GET / | elastic es info |
GET /_ml/anomaly_detectors | elastic es ml get-jobs |
GET /_ml/anomaly_detectors/{job_id} | elastic es ml get-jobs --job-id '<job_id>' |
GET /_ml/anomaly_detectors/{job_id}/_stats | elastic es ml get-job-stats --job-id '<job_id>' |
POST /.ml-anomalies-*/_search | elastic es search --index '.ml-anomalies-*' --input-file '<search-body.json>' |
Query body shapes for each result_type (record, influencer, model_plot, category_definition) are documented in
references/explainer-reference.md.
© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/elasticsearch/elasticsearch-anomaly-detection-explainer of elastic/agent-skills.
Open the folder on GitHubat commit baa5111
Elasticsearch Anomaly Detection Explainer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Elasticsearch Anomaly Detection Explainer this skillelastic/agent-skills | 592 | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | |
| Amazon Opensearch Serviceaws/agent-toolkit-for-aws | 2.8k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Elasticsearch File IngestKilo-Org/kilo-marketplace | 190 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Product Full-Text Searchlobehub/lobehub | 83k | — | ~4.1k | Automated safety check: Pass | Custom licence | |
| Time Series Analytics Useropen-edge-platform/edge-ai-libraries | 169 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Elasticsearch Auditaspectrr/deer | 405 | — | ~1.7k | Automated safety check: Pass | MIT |
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
Kilo-Org/kilo-marketplace
Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.
lobehub/lobehub
Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.
open-edge-platform/edge-ai-libraries
Build a new time-series analytics use case on top of the deployed Time Series Analytics microservice — bring it up with Docker Compose (from a repo clone, or by fetching the compose files from…
aspectrr/deer
Enable, configure, and query Elasticsearch security audit logs.
exceptionless/Exceptionless
Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
elastic/agent-skills
Create, search, update, and manage SOC cases via the Kibana Cases API.
elastic/agent-skills
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).
elastic/agent-skills
Create and manage Kibana Dashboards and Lens visualizations.
elastic/agent-skills
Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.
elastic/agent-skills
Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…
Works with
Categories
Explain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation. Elasticsearch Anomaly Detection Explainer is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Explain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation.
Elasticsearch Anomaly Detection Explainer fits situations like: the user asks why a score is high; how the model learns; what the numbers mean; how to troubleshoot unexpected anomaly scores.
Run `npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a claude-code`. Or copy the skill folder (skills/elasticsearch/elasticsearch-anomaly-detection-explainer in elastic/agent-skills) into .claude/skills/elasticsearch-anomaly-detection-explainer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a codex`. Or copy the skill folder (skills/elasticsearch/elasticsearch-anomaly-detection-explainer in elastic/agent-skills) into .agents/skills/elasticsearch-anomaly-detection-explainer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection-explainer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch-anomaly-detection-explainer, .gemini/skills/elasticsearch-anomaly-detection-explainer, .github/skills/elasticsearch-anomaly-detection-explainer and .opencode/skills/elasticsearch-anomaly-detection-explainer in your project.
SKILL.md names no scripts, command-line tools or credentials: Elasticsearch Anomaly Detection Explainer is instructions for the agent only. Compatibility (from SKILL.md): Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API and the standard _search API against .ml-anomalies-* — no ES|QL. User needs monitor_ml privilege for ML APIs. .
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Elasticsearch Anomaly Detection Explainer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Elasticsearch Anomaly Detection Explainer: Amazon Opensearch Service (aws/agent-toolkit-for-aws, 2.8k stars), Elasticsearch File Ingest (Kilo-Org/kilo-marketplace, 190 stars), Product Full-Text Search (lobehub/lobehub, 83k stars) and Time Series Analytics User (open-edge-platform/edge-ai-libraries, 169 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.
Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.