Build Connector
elastic/kibana
End-to-end orchestrator that creates a new connector from scratch, reviews the code, activates it in Kibana, tests it via an Agent Builder agent, iterates until quality is met, and delivers a…
Create and manage Kibana Agent Builder agents and custom tools.
$ npx skills add elastic/agent-skills --skill kibana-agent-builder -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elastic/agent-skills kibana-agent-builder --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kibana/kibana-agent-builder .claude/skills/kibana-agent-builder && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kibana-agent-builder" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-agent-builder into .claude/skills/kibana-agent-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kibana-agent-builder", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-agent-builderType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elastic/agent-skills --skill kibana-agent-builder -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elastic/agent-skills kibana-agent-builder --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/kibana/kibana-agent-builder .agents/skills/kibana-agent-builder && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kibana-agent-builder" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-agent-builder into .agents/skills/kibana-agent-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kibana-agent-builder", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill kibana-agent-builder -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elastic/agent-skills kibana-agent-builder --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/kibana/kibana-agent-builder .cursor/skills/kibana-agent-builder && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kibana-agent-builder" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-agent-builder into .cursor/skills/kibana-agent-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kibana-agent-builder", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elastic/agent-skills.git --path skills/kibana/kibana-agent-builder--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elastic/agent-skills --skill kibana-agent-builder -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elastic/agent-skills kibana-agent-builder --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/kibana/kibana-agent-builder .gemini/skills/kibana-agent-builder && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kibana-agent-builder" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-agent-builder into .gemini/skills/kibana-agent-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kibana-agent-builder", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elastic/agent-skills kibana-agent-builderInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elastic/agent-skills --skill kibana-agent-builder -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/kibana/kibana-agent-builder .github/skills/kibana-agent-builder && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kibana-agent-builder" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-agent-builder into .github/skills/kibana-agent-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kibana-agent-builder", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill kibana-agent-builder -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elastic/agent-skills kibana-agent-builder --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/kibana/kibana-agent-builder .opencode/skills/kibana-agent-builder && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kibana-agent-builder" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-agent-builder into .opencode/skills/kibana-agent-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kibana-agent-builder", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kibana-agent-builderCreate and manage Kibana Agent Builder agents and custom tools.
Kibana Agent Builder is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create and manage Kibana Agent Builder agents and custom tools. Use when asked to create, update, delete, test, or inspect agents or tools in Agent Builder, or when the user wants to understand what agents or tools already exist.
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/architecture-guide.md` and `references/use-cases.md`).
It sits in AI & LLM Engineering, covering Building AI agents. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Kibana Agent Builder loads about 3.4k tokens when it runs, and up to ~8.8k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 1,223 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,223 words, ~3,378 tokens.
.claude/skills/kibana-agent-builder/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Create, inspect, update, delete, and test Agent Builder tools and agents. Ground LLM responses in Elasticsearch data through scoped search tools, parameterized ES|QL, and workflow integrations.
<!-- begin-partial: preamble -->
This skill executes Elasticsearch operations through the elastic CLI. If the
elastic CLI is not installed, tell the user what it is needed for. Do
not guess credentials, call the HTTP API directly, or attempt other workarounds.
This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping,
GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document
maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API
directly.
<!-- end-partial: preamble -->
Agent Builder exposes three distinct resource kinds — do not conflate them:
| Kind | Purpose | Typical API |
|---|---|---|
| Tool | Reusable function an agent invokes to retrieve or act on data (index_search, esql, workflow) | POST kbn:/api/agent_builder/tools |
| Agent | LLM entity with instructions and a curated toolset | POST kbn:/api/agent_builder/agents |
| Chat / conversation | Ephemeral messaging session with an existing agent | POST kbn:/api/agent_builder/converse/async |
Creating a tool does not create an agent. Listing or chatting with an agent does not create a tool. When the user asks to "create an agent" or "create a tool," identify which resource they mean before calling a write API.
Built-in tools use the platform.core.* prefix (for example platform.core.search). Custom tools and agents are
user-defined. Read architecture-guide.md for built-in tool inventory, context
engineering, and security notes.
Classify the task. Decide whether the user needs a tool, an agent, or chat with an existing agent. If they ask what already exists ("what agents are there?", "list agents"), treat the request as read-only discovery — answer from live data before proposing any create, update, or delete.
Discover existing resources before any write. When creating or updating:
GET kbn:/api/agent_builder/tools to list available tools (built-in and custom). Do not invent tool IDs.GET kbn:/api/agent_builder/agents to list existing agents and avoid duplicate IDs or names.When the user only asks what agents exist, stop after GET kbn:/api/agent_builder/agents. Enumerate each agent's id
and name. If the list is empty, say so plainly — do not fabricate agents. Only proceed to creation when the user
explicitly asks to create one and you have confirmed the target id is unused.
Choose the tool type (for tool tasks). Match intent to the narrowest tool type:
index_search with a specific pattern (for example
customer-feedback-*), never * or all-indices scope unless the user explicitly requires it.esql with ?param placeholders and a params
object (use {} when there are no parameters).workflow referencing an existing workflow id.For ES|QL syntax and query design, follow the elasticsearch-esql skill. For workflow YAML, follow the
kibana-workflows skill.
Build the tool payload. Required fields: id, type, description, configuration. Optional: tags.
API constraints (violations return 400):
id, type, description, configuration, tags. name is not valid on tools."pattern", not "index"."params" even when empty: "params": {}.type and description — not default or optional. Hard-code defaults in the query.description, configuration, and tags. id and type are immutable.Index search example (scoped pattern):
{
"id": "customer_feedback_search",
"type": "index_search",
"description": "Searches customer feedback and support tickets in the customer-feedback indices.",
"configuration": {
"pattern": "customer-feedback-*"
}
}ES|QL example (parameterized, with LIMIT):
{
"id": "feedback_sentiment_trend",
"type": "esql",
"description": "Returns positive vs negative feedback counts by product category over a lookback window.",
"configuration": {
"query": "FROM customer-feedback-* | WHERE @timestamp >= NOW() - ?lookback_days::integer * 1d | STATS positive = COUNT(*) WHERE sentiment == \"positive\", negative = COUNT(*) WHERE sentiment == \"negative\" BY product_category | SORT negative DESC | LIMIT 20",
"params": {
"lookback_days": {
"type": "integer",
"description": "Number of days to look back, e.g. 7, 30, 90"
}
}
}
}Create and verify the tool. Call POST kbn:/api/agent_builder/tools with the payload. Confirm success by calling
GET kbn:/api/agent_builder/tools/{toolId} and reporting the created id, type, description, and configuration back
to the user — do not claim success without a live API response.
Optionally validate ES|QL tools with POST kbn:/api/agent_builder/tools/_execute, passing tool_id and
tool_params. Always include | LIMIT N in ES|QL queries to control token use.
Build the agent payload (for agent tasks). Required fields: id, name, description, configuration.
Configuration must include instructions and a tools array with tool_ids drawn from Step 2 — only IDs returned
by GET kbn:/api/agent_builder/tools.
Derive a stable id from the name (lowercase, hyphens, alphanumeric). Check Step 2's agent list for conflicts before
posting.
{
"id": "customer-feedback-agent",
"name": "Customer Feedback Analyst",
"description": "Analyzes customer sentiment and feedback trends.",
"configuration": {
"instructions": "Always use tools to retrieve data. Never answer data questions from memory.",
"tools": [
{
"tool_ids": ["customer_feedback_search", "platform.core.search"]
}
]
}
}Agent update constraints: PUT accepts only description, configuration, and tags (plus avatar/labels when
applicable). Do not send immutable fields like id, name, or type on update — they cause 400 errors.
Create and verify the agent. Call POST kbn:/api/agent_builder/agents. Confirm with
GET kbn:/api/agent_builder/agents or GET kbn:/api/agent_builder/agents/{agentId}. Report the live response.
Update or delete (when requested). Confirm destructive actions with the user first.
PUT kbn:/api/agent_builder/tools/{toolId}DELETE kbn:/api/agent_builder/tools/{toolId}PUT kbn:/api/agent_builder/agents/{agentId}DELETE kbn:/api/agent_builder/agents/{agentId}Chat (when requested). Chat is not agent or tool creation. Use POST kbn:/api/agent_builder/converse/async with
an existing agent_id and user input. Expect multi-step reasoning and tool calls; allow sufficient time for
streaming completion.
customer-feedback-* over *. Broad patterns increase noise, token cost, and
RBAC surface area.User: "Create a custom Agent Builder tool that searches the customer-feedback-* index. Use the tool id 'eval-feedback-search'."
eval-feedback-search does not already exist.index_search scoped to customer-feedback-* (not *).configuration.pattern.User: "I want to create a new agent in Kibana Agent Builder. What agents already exist?"
GET kbn:/api/agent_builder/agents — read-only.User: "Create a sales-helper agent using the esql-sales-data tool."
esql-sales-data exists.| HTTP API (shorthand) | elastic CLI command |
|---|---|
GET kbn:/api/agent_builder/tools | elastic kb agent-builder get-agent-builder-tools |
POST kbn:/api/agent_builder/tools | elastic kb agent-builder post-agent-builder-tools --id '<id>' --type '<type>' --description '<desc>' --configuration '<json>' |
GET kbn:/api/agent_builder/tools/{toolId} | elastic kb agent-builder get-agent-builder-tools-toolid --tool-id '<toolId>' |
PUT kbn:/api/agent_builder/tools/{toolId} | elastic kb agent-builder put-agent-builder-tools-toolid --tool-id '<toolId>' [--description '<desc>'] [--configuration '<json>'] |
DELETE kbn:/api/agent_builder/tools/{toolId} | elastic kb agent-builder delete-agent-builder-tools-toolid --tool-id '<toolId>' [--force] |
POST kbn:/api/agent_builder/tools/_execute | elastic kb agent-builder post-agent-builder-tools-execute --tool-id '<toolId>' --tool-params '<json>' |
GET kbn:/api/agent_builder/agents | elastic kb agent-builder get-agent-builder-agents |
POST kbn:/api/agent_builder/agents | elastic kb agent-builder post-agent-builder-agents --id '<id>' --name '<name>' --description '<desc>' --configuration '<json>' |
GET kbn:/api/agent_builder/agents/{agentId} | elastic kb agent-builder get-agent-builder-agents-id --id '<agentId>' |
PUT kbn:/api/agent_builder/agents/{agentId} | elastic kb agent-builder put-agent-builder-agents-id --id '<agentId>' [--description '<desc>'] [--configuration '<json>'] |
DELETE kbn:/api/agent_builder/agents/{agentId} | elastic kb agent-builder delete-agent-builder-agents-id --id '<agentId>' |
POST kbn:/api/agent_builder/converse/async | elastic kb agent-builder post-agent-builder-converse-async --agent-id '<agentId>' --input '<message>' |
© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in skills/kibana/kibana-agent-builder of elastic/agent-skills.
Open the folder on GitHubat commit baa5111
Kibana Agent Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Kibana Agent Builder this skillelastic/agent-skills | 592 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Build Connectorelastic/kibana | 21k | — | ~4.7k | Automated safety check: Notes | Custom licence | |
| Agent Builder Tool Reviewelastic/kibana | 21k | — | ~2.9k | Automated safety check: Pass | Custom licence | |
| Agent BuildershareAI-lab/learn-claude-code | 78k | 5 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Paperclip Create Agentpaperclipai/paperclip | 99k | 1 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Senior Prompt Engineermaslennikov-ig/claude-code-orchestrator-kit | 260 | 3 repos | ~1.4k | Automated safety check: Pass | Custom licence |
elastic/kibana
End-to-end orchestrator that creates a new connector from scratch, reviews the code, activates it in Kibana, tests it via an Agent Builder agent, iterates until quality is met, and delivers a…
elastic/kibana
Review Agent Builder tool registrations for availability scoping, MCP hygiene, description quality, return value design, single responsibility, and annotation correctness.
shareAI-lab/learn-claude-code
Design and build AI agents for any domain. An agent skill from shareAI-lab/learn-claude-code.
paperclipai/paperclip
Create new agents in Paperclip with governance-aware hiring.
maslennikov-ig/claude-code-orchestrator-kit
Provides reference guides and Python scripts for prompt optimization, RAG evaluation, and agent orchestration when building or tuning LLM systems.
gnekt/My-Brain-Is-Full-Crew
Create a new custom agent from scratch. An agent skill from gnekt/My-Brain-Is-Full-Crew.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
elastic/agent-skills
Create, search, update, and manage SOC cases via the Kibana Cases API.
elastic/agent-skills
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).
elastic/agent-skills
Create and manage Kibana Dashboards and Lens visualizations.
elastic/agent-skills
Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.
elastic/agent-skills
Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…
Works with
Categories
Create and manage Kibana Agent Builder agents and custom tools. Kibana Agent Builder is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create and manage Kibana Agent Builder agents and custom tools.
Kibana Agent Builder fits situations like: asked to create; tools in Agent Builder; the user wants to understand what agents; tools already exist.
Run `npx skills add elastic/agent-skills --skill kibana-agent-builder -a claude-code`. Or copy the skill folder (skills/kibana/kibana-agent-builder in elastic/agent-skills) into .claude/skills/kibana-agent-builder in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elastic/agent-skills --skill kibana-agent-builder -a codex`. Or copy the skill folder (skills/kibana/kibana-agent-builder in elastic/agent-skills) into .agents/skills/kibana-agent-builder in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill kibana-agent-builder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kibana-agent-builder, .gemini/skills/kibana-agent-builder, .github/skills/kibana-agent-builder and .opencode/skills/kibana-agent-builder in your project.
SKILL.md names no scripts, command-line tools or credentials: Kibana Agent Builder is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Kibana Agent Builder is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Kibana Agent Builder: Build Connector (elastic/kibana, 21k stars), Agent Builder Tool Review (elastic/kibana, 21k stars), Agent Builder (shareAI-lab/learn-claude-code, 78k stars) and Paperclip Create Agent (paperclipai/paperclip, 99k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.
Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.