Official agent skill

Kibana Agent Builder

by elastic in elastic/agent-skills

Create and manage Kibana Agent Builder agents and custom tools.

OfficialApache-2.0Auto-check passedAI & LLM Engineering

Install Kibana Agent Builder

skills CLI
$ npx skills add elastic/agent-skills --skill kibana-agent-builder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/agent-skills kibana-agent-builder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kibana/kibana-agent-builder .claude/skills/kibana-agent-builder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kibana-agent-builder
GitHub stars
592
Token cost
~3.4k tokens
SKILL.md length
1,223 words
Files
3 (incl. references)
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create and manage Kibana Agent Builder agents and custom tools.

  • Works in 9 steps: Classify the task. Decide whether the… → Discover existing resources before any… → Choose the tool type (for tool tasks).… → …
  • Asked to create
  • SKILL.md covers Environment Configuration, Resource model, Process and Guidelines, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Kibana Agent Builder is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create and manage Kibana Agent Builder agents and custom tools. Use when asked to create, update, delete, test, or inspect agents or tools in Agent Builder, or when the user wants to understand what agents or tools already exist.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/architecture-guide.md` and `references/use-cases.md`).

It sits in AI & LLM Engineering, covering Building AI agents. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.

When your agent uses it

  • Asked to create
  • Tools in Agent Builder
  • The user wants to understand what agents
  • Tools already exist

Example prompts

  • “/kibana-agent-builder”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Classify the task. Decide whether the user needs a tool, an agent, or chat with an existing agent. If
  2. Discover existing resources before any write. When creating or updating
  3. Choose the tool type (for tool tasks). Match intent to the narrowest tool type
  4. Build the tool payload. Required fields: id, type, description, configuration. Optional: tags.
  5. Create and verify the tool. Call POST kbn:/api/agent_builder/tools with the payload. Confirm success by calling
  6. Build the agent payload (for agent tasks). Required fields: id, name, description, configuration.
  7. Create and verify the agent. Call POST kbn:/api/agent_builder/agents. Confirm with
  8. Update or delete (when requested). Confirm destructive actions with the user first.
  9. Chat (when requested). Chat is not agent or tool creation. Use POST kbn:/api/agent_builder/converse/async with

What it can do on your machine

Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kibana Agent Builder loads about 3.4k tokens when it runs, and up to ~8.8k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 1,223 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,223 words, ~3,378 tokens.

Download SKILL.mdSave it as .claude/skills/kibana-agent-builder/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
kibana-agent-builder
description
Create and manage Kibana Agent Builder agents and custom tools. Use when asked to create, update, delete, test, or inspect agents or tools in Agent Builder, or when the user wants to understand what agents or tools already exist.
metadata.author
elastic
metadata.version
0.3.0
metadata.universal
true

Kibana Agent Builder

Create, inspect, update, delete, and test Agent Builder tools and agents. Ground LLM responses in Elasticsearch data through scoped search tools, parameterized ES|QL, and workflow integrations.

<!-- begin-partial: preamble -->

Environment Configuration

This skill executes Elasticsearch operations through the elastic CLI. If the elastic CLI is not installed, tell the user what it is needed for. Do not guess credentials, call the HTTP API directly, or attempt other workarounds.

This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping, GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API directly.

<!-- end-partial: preamble -->

Resource model

Agent Builder exposes three distinct resource kinds — do not conflate them:

KindPurposeTypical API
ToolReusable function an agent invokes to retrieve or act on data (index_search, esql, workflow)POST kbn:/api/agent_builder/tools
AgentLLM entity with instructions and a curated toolsetPOST kbn:/api/agent_builder/agents
Chat / conversationEphemeral messaging session with an existing agentPOST kbn:/api/agent_builder/converse/async

Creating a tool does not create an agent. Listing or chatting with an agent does not create a tool. When the user asks to "create an agent" or "create a tool," identify which resource they mean before calling a write API.

Built-in tools use the platform.core.* prefix (for example platform.core.search). Custom tools and agents are user-defined. Read architecture-guide.md for built-in tool inventory, context engineering, and security notes.

Process

  1. Classify the task. Decide whether the user needs a tool, an agent, or chat with an existing agent. If they ask what already exists ("what agents are there?", "list agents"), treat the request as read-only discovery — answer from live data before proposing any create, update, or delete.

  2. Discover existing resources before any write. When creating or updating:

    • Call GET kbn:/api/agent_builder/tools to list available tools (built-in and custom). Do not invent tool IDs.
    • Call GET kbn:/api/agent_builder/agents to list existing agents and avoid duplicate IDs or names.

    When the user only asks what agents exist, stop after GET kbn:/api/agent_builder/agents. Enumerate each agent's id and name. If the list is empty, say so plainly — do not fabricate agents. Only proceed to creation when the user explicitly asks to create one and you have confirmed the target id is unused.

  3. Choose the tool type (for tool tasks). Match intent to the narrowest tool type:

    • Open-ended search over a known index pattern → index_search with a specific pattern (for example customer-feedback-*), never * or all-indices scope unless the user explicitly requires it.
    • Fixed analytics, aggregations, or parameterized queries → esql with ?param placeholders and a params object (use {} when there are no parameters).
    • Multi-step automation beyond retrieval → workflow referencing an existing workflow id.

    For ES|QL syntax and query design, follow the elasticsearch-esql skill. For workflow YAML, follow the kibana-workflows skill.

  4. Build the tool payload. Required fields: id, type, description, configuration. Optional: tags.

    API constraints (violations return 400):

    • POST accepts only id, type, description, configuration, tags. name is not valid on tools.
    • Index search configuration uses "pattern", not "index".
    • ES|QL tools require "params" even when empty: "params": {}.
    • Each param accepts only type and description — not default or optional. Hard-code defaults in the query.
    • PUT on tools accepts only description, configuration, and tags. id and type are immutable.

    Index search example (scoped pattern):

    json
    {
      "id": "customer_feedback_search",
      "type": "index_search",
      "description": "Searches customer feedback and support tickets in the customer-feedback indices.",
      "configuration": {
        "pattern": "customer-feedback-*"
      }
    }

    ES|QL example (parameterized, with LIMIT):

    json
    {
      "id": "feedback_sentiment_trend",
      "type": "esql",
      "description": "Returns positive vs negative feedback counts by product category over a lookback window.",
      "configuration": {
        "query": "FROM customer-feedback-* | WHERE @timestamp >= NOW() - ?lookback_days::integer * 1d | STATS positive = COUNT(*) WHERE sentiment == \"positive\", negative = COUNT(*) WHERE sentiment == \"negative\" BY product_category | SORT negative DESC | LIMIT 20",
        "params": {
          "lookback_days": {
            "type": "integer",
            "description": "Number of days to look back, e.g. 7, 30, 90"
          }
        }
      }
    }
  5. Create and verify the tool. Call POST kbn:/api/agent_builder/tools with the payload. Confirm success by calling GET kbn:/api/agent_builder/tools/{toolId} and reporting the created id, type, description, and configuration back to the user — do not claim success without a live API response.

    Optionally validate ES|QL tools with POST kbn:/api/agent_builder/tools/_execute, passing tool_id and tool_params. Always include | LIMIT N in ES|QL queries to control token use.

  6. Build the agent payload (for agent tasks). Required fields: id, name, description, configuration. Configuration must include instructions and a tools array with tool_ids drawn from Step 2 — only IDs returned by GET kbn:/api/agent_builder/tools.

    Derive a stable id from the name (lowercase, hyphens, alphanumeric). Check Step 2's agent list for conflicts before posting.

    json
    {
      "id": "customer-feedback-agent",
      "name": "Customer Feedback Analyst",
      "description": "Analyzes customer sentiment and feedback trends.",
      "configuration": {
        "instructions": "Always use tools to retrieve data. Never answer data questions from memory.",
        "tools": [
          {
            "tool_ids": ["customer_feedback_search", "platform.core.search"]
          }
        ]
      }
    }

    Agent update constraints: PUT accepts only description, configuration, and tags (plus avatar/labels when applicable). Do not send immutable fields like id, name, or type on update — they cause 400 errors.

  7. Create and verify the agent. Call POST kbn:/api/agent_builder/agents. Confirm with GET kbn:/api/agent_builder/agents or GET kbn:/api/agent_builder/agents/{agentId}. Report the live response.

  8. Update or delete (when requested). Confirm destructive actions with the user first.

    • Update tool: PUT kbn:/api/agent_builder/tools/{toolId}
    • Delete tool: DELETE kbn:/api/agent_builder/tools/{toolId}
    • Update agent: PUT kbn:/api/agent_builder/agents/{agentId}
    • Delete agent: DELETE kbn:/api/agent_builder/agents/{agentId}
  9. Chat (when requested). Chat is not agent or tool creation. Use POST kbn:/api/agent_builder/converse/async with an existing agent_id and user input. Expect multi-step reasoning and tool calls; allow sufficient time for streaming completion.

Show full SKILL.md (446 more words)Show less

Guidelines

  • Discover before create. Always list agents (and tools when relevant) before creating resources. When asked "what agents exist?", answer that question first — read-only — even if the user also mentions wanting a new agent later.
  • Scope index search narrowly. Prefer customer-feedback-* over *. Broad patterns increase noise, token cost, and RBAC surface area.
  • Write descriptive tool descriptions. The agent selects tools based on descriptions alone — include when to use each tool and example trigger phrases.
  • Minimize toolsets. Every assigned tool adds tokens to the agent system prompt on every turn.
  • Validate ES|QL before deployment. Execute the tool after creation when parameters or query shape are non-trivial.
  • Use aggregations and KEEP. Prefer summary stats over raw document dumps for analytics questions.

Examples

Create an index search tool (eval pattern)

User: "Create a custom Agent Builder tool that searches the customer-feedback-* index. Use the tool id 'eval-feedback-search'."

  1. List tools — confirm eval-feedback-search does not already exist.
  2. Choose index_search scoped to customer-feedback-* (not *).
  3. POST the tool with id, description, and configuration.pattern.
  4. GET the tool by id and confirm creation to the user.
Answer "what agents already exist?" before creating

User: "I want to create a new agent in Kibana Agent Builder. What agents already exist?"

  1. Call GET kbn:/api/agent_builder/agents — read-only.
  2. Enumerate existing agent ids and names (or state that none exist).
  3. Do not create, update, or delete anything in this step.
  4. Only if the user then asks to create, pick an unused id informed by the list above.
Create an agent after discovery

User: "Create a sales-helper agent using the esql-sales-data tool."

  1. List tools — confirm esql-sales-data exists.
  2. List agents — confirm no conflicting id.
  3. POST agent with instructions and selected tool IDs.
  4. GET agent to verify and report back.

References

  • architecture-guide.md — Built-in tools, context engineering, token optimization, MCP/A2A integration, permissions
  • use-cases.md — Playbooks for customer feedback, marketing campaign, and contract analysis agents with example tool and agent payloads

Operations

HTTP API (shorthand)elastic CLI command
GET kbn:/api/agent_builder/toolselastic kb agent-builder get-agent-builder-tools
POST kbn:/api/agent_builder/toolselastic kb agent-builder post-agent-builder-tools --id '<id>' --type '<type>' --description '<desc>' --configuration '<json>'
GET kbn:/api/agent_builder/tools/{toolId}elastic kb agent-builder get-agent-builder-tools-toolid --tool-id '<toolId>'
PUT kbn:/api/agent_builder/tools/{toolId}elastic kb agent-builder put-agent-builder-tools-toolid --tool-id '<toolId>' [--description '<desc>'] [--configuration '<json>']
DELETE kbn:/api/agent_builder/tools/{toolId}elastic kb agent-builder delete-agent-builder-tools-toolid --tool-id '<toolId>' [--force]
POST kbn:/api/agent_builder/tools/_executeelastic kb agent-builder post-agent-builder-tools-execute --tool-id '<toolId>' --tool-params '<json>'
GET kbn:/api/agent_builder/agentselastic kb agent-builder get-agent-builder-agents
POST kbn:/api/agent_builder/agentselastic kb agent-builder post-agent-builder-agents --id '<id>' --name '<name>' --description '<desc>' --configuration '<json>'
GET kbn:/api/agent_builder/agents/{agentId}elastic kb agent-builder get-agent-builder-agents-id --id '<agentId>'
PUT kbn:/api/agent_builder/agents/{agentId}elastic kb agent-builder put-agent-builder-agents-id --id '<agentId>' [--description '<desc>'] [--configuration '<json>']
DELETE kbn:/api/agent_builder/agents/{agentId}elastic kb agent-builder delete-agent-builder-agents-id --id '<agentId>'
POST kbn:/api/agent_builder/converse/asyncelastic kb agent-builder post-agent-builder-converse-async --agent-id '<agentId>' --input '<message>'

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/kibana/kibana-agent-builder of elastic/agent-skills.

  • SKILL.md
  • references/architecture-guide.md
  • references/use-cases.md

Open the folder on GitHubat commit baa5111

Compare with similar skills

Kibana Agent Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kibana Agent Builder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kibana Agent Builder this skillelastic/agent-skills592—~3.4kAutomated safety check: PassApache-2.0
Build Connectorelastic/kibana21k—~4.7kAutomated safety check: NotesCustom licence
Agent Builder Tool Reviewelastic/kibana21k—~2.9kAutomated safety check: PassCustom licence
Agent BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
Paperclip Create Agentpaperclipai/paperclip99k1 repos~2.1kAutomated safety check: PassMIT
Senior Prompt Engineermaslennikov-ig/claude-code-orchestrator-kit2603 repos~1.4kAutomated safety check: PassCustom licence

Similar skills

  • Build Connector

    elastic/kibana

    Official

    End-to-end orchestrator that creates a new connector from scratch, reviews the code, activates it in Kibana, tests it via an Agent Builder agent, iterates until quality is met, and delivers a…

    21k GitHub stars~4.7k tokensUpdated today
    AI & LLM EngineeringAuto-check: notes
  • Official

    Review Agent Builder tool registrations for availability scoping, MCP hygiene, description quality, return value design, single responsibility, and annotation correctness.

    21k GitHub stars~2.9k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Agent Builder

    shareAI-lab/learn-claude-code

    Design and build AI agents for any domain. An agent skill from shareAI-lab/learn-claude-code.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    AI & LLM EngineeringAuto-check passed
  • Paperclip Create Agent

    paperclipai/paperclip

    Create new agents in Paperclip with governance-aware hiring.

    99k GitHub starsUsed in 1 repo~2.1k tokens
    AI & LLM EngineeringAuto-check passed
  • Senior Prompt Engineer

    maslennikov-ig/claude-code-orchestrator-kit

    Provides reference guides and Python scripts for prompt optimization, RAG evaluation, and agent orchestration when building or tuning LLM systems.

    260 GitHub starsUsed in 3 repos~1.4k tokens
    AI & LLM EngineeringAuto-check passed
  • Create Agent

    gnekt/My-Brain-Is-Full-Crew

    Create a new custom agent from scratch. An agent skill from gnekt/My-Brain-Is-Full-Crew.

    3.9k GitHub stars~3.1k tokensUpdated 3 mo ago
    AI & LLM EngineeringAuto-check passed

More from elastic/agent-skills

All 26 skills in this repo
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    Auto-check: notes
  • Security Case Management

    elastic/agent-skills

    Official

    Create, search, update, and manage SOC cases via the Kibana Cases API.

    592 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Kibana Dashboards

    elastic/agent-skills

    Official

    Create and manage Kibana Dashboards and Lens visualizations.

    592 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Official

    Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

    592 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Cloud Onboarding

    elastic/agent-skills

    Official

    Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…

    592 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Kibana Agent Builder

What does Kibana Agent Builder do?

Create and manage Kibana Agent Builder agents and custom tools. Kibana Agent Builder is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create and manage Kibana Agent Builder agents and custom tools.

When should I use Kibana Agent Builder?

Kibana Agent Builder fits situations like: asked to create; tools in Agent Builder; the user wants to understand what agents; tools already exist.

How do I install Kibana Agent Builder in Claude Code?

Run `npx skills add elastic/agent-skills --skill kibana-agent-builder -a claude-code`. Or copy the skill folder (skills/kibana/kibana-agent-builder in elastic/agent-skills) into .claude/skills/kibana-agent-builder in your project. Claude Code loads it when a task matches its description.

How do I install Kibana Agent Builder in Codex?

Run `npx skills add elastic/agent-skills --skill kibana-agent-builder -a codex`. Or copy the skill folder (skills/kibana/kibana-agent-builder in elastic/agent-skills) into .agents/skills/kibana-agent-builder in your project. Codex loads it when a task matches its description.

Can I use Kibana Agent Builder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill kibana-agent-builder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kibana-agent-builder, .gemini/skills/kibana-agent-builder, .github/skills/kibana-agent-builder and .opencode/skills/kibana-agent-builder in your project.

What does Kibana Agent Builder need to run?

SKILL.md names no scripts, command-line tools or credentials: Kibana Agent Builder is instructions for the agent only.

Does Kibana Agent Builder access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Kibana Agent Builder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kibana Agent Builder use?

Kibana Agent Builder is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kibana Agent Builder use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.5k tokens, read only when the agent opens those files.

What are the alternatives to Kibana Agent Builder?

Skills that share tags, products or a category with Kibana Agent Builder: Build Connector (elastic/kibana, 21k stars), Agent Builder Tool Review (elastic/kibana, 21k stars), Agent Builder (shareAI-lab/learn-claude-code, 78k stars) and Paperclip Create Agent (paperclipai/paperclip, 99k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kibana Agent Builder?

elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.

Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.