Debug Oas
elastic/kibana
A skill your agent uses when debugging OpenAPI (OAS) issues for a specific API area in Kibana by scoping validation output with one or more --path filters, then separating structural invalid-OAS…
Create, search, update, and manage SOC cases via the Kibana Cases API.
$ npx skills add elastic/agent-skills --skill security-case-management -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elastic/agent-skills security-case-management --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/case-management .claude/skills/security-case-management && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-case-management" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/security/case-management into .claude/skills/security-case-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-case-management", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elastic/agent-skills/tree/main/skills/security/case-managementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elastic/agent-skills --skill security-case-management -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elastic/agent-skills security-case-management --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security/case-management .agents/skills/security-case-management && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-case-management" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/security/case-management into .agents/skills/security-case-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-case-management", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill security-case-management -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elastic/agent-skills security-case-management --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security/case-management .cursor/skills/security-case-management && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-case-management" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/security/case-management into .cursor/skills/security-case-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-case-management", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elastic/agent-skills.git --path skills/security/case-management--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elastic/agent-skills --skill security-case-management -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elastic/agent-skills security-case-management --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security/case-management .gemini/skills/security-case-management && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-case-management" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/security/case-management into .gemini/skills/security-case-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-case-management", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elastic/agent-skills security-case-managementInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elastic/agent-skills --skill security-case-management -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security/case-management .github/skills/security-case-management && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-case-management" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/security/case-management into .github/skills/security-case-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-case-management", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill security-case-management -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elastic/agent-skills security-case-management --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security/case-management .opencode/skills/security-case-management && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-case-management" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/security/case-management into .opencode/skills/security-case-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-case-management", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-case-managementCreate, search, update, and manage SOC cases via the Kibana Cases API.
Security Case Management is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create, search, update, and manage SOC cases via the Kibana Cases API. Use when tracking incidents, linking alerts to cases, adding investigation notes, or managing triage output.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/kibana-cases-api.md`, `scripts/case-manager.js` and `scripts/kibana-client.js`). Compatibility notes: Requires Node.js 22+, network access to Kibana. Environment variables: KIBANAURL, plus KIBANAAPIKEY or KIBANAUSERNAME/KIBANAPASSWORD.
It sits in Backend & APIs. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodenpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
KIBANA_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires Node.js 22+, network access to Kibana. Environment variables: KIBANA_URL, plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD.
From compatibility in the SKILL.md frontmatter.
Security Case Management loads about 2.6k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 51 tokens; SKILL.md has 951 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
environment variables (or add them to a `.env` file in the workspace root):Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 951 words, ~2,601 tokens.
.claude/skills/security-case-management/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Manage SOC cases through the Kibana Cases API. All cases are scoped to securitySolution — this skill operates
exclusively within Elastic Security. Cases appear in Kibana Security and can be assigned to analysts, linked to alerts,
and pushed to external incident management systems via connectors.
Install dependencies before first use from the skills/security directory:
cd skills/security && npm installSet the required environment variables (or add them to a .env file in the workspace root):
export KIBANA_URL="https://your-cluster.kb.cloud.example.com:443"
export KIBANA_API_KEY="your-kibana-api-key"owner: securitySolutionAll commands run from the workspace root. All output is JSON. Call the tools directly — do not read the skill file or
explore the workspace first. For attach-alert/attach-alerts, --rule-id and --rule-name are required by the Kibana
API (use --rule-id unknown --rule-name unknown if unknown). Use attach-alerts for batch with automatic rate-limit
retry and 2-second spacing between API calls.
| Task | Tools to call (in order) |
|---|---|
| Create a case | case_manager create (title, description, tags, severity) |
| Find cases for a host | case_manager find --tags "agent_id:<id>" or find --search "<hostname>" |
| Attach alert to case | case_manager attach-alert (case-id, alert-id, alert-index, rule-id/name) |
| Add investigation notes | case_manager add-comment (case-id, comment text) |
| List recent open cases | case_manager list --status open --per-page <n> |
| Update case | case_manager update (case-id, status/severity/tags changes) |
Finding cases for a host: Use find --search "<hostname>" to search by hostname across title, description, and
comments. Alternatively use find --tags "agent_id:<agent_id>" if the agent ID is known. Always add --status open to
filter to active cases only. Report the exact total count and each case title verbatim from the API response.
# Create (syncAlerts enabled by default; disable with --sync-alerts false)
node skills/security/case-management/scripts/case-manager.js create --title "Malicious DLL sideloading on host1" --description "Crypto clipper malware detected via DLL sideloading..." --tags "classification:malicious" "confidence:88" "mitre:T1574.002" --severity critical --yes
# Find, list, get
node skills/security/case-management/scripts/case-manager.js find --tags "agent_id:550888e5-357d-4bc1-a154-486eb7b4e076"
node skills/security/case-management/scripts/case-manager.js find --search "DLL sideloading" --status open
node skills/security/case-management/scripts/case-manager.js list --status open --per-page 10
node skills/security/case-management/scripts/case-manager.js get --case-id <case_id>
# Attach single alert
node skills/security/case-management/scripts/case-manager.js attach-alert --case-id <case_id> --alert-id <alert_doc_id> --alert-index .ds-.alerts-security.alerts-default-2025.12.01-000013 --rule-id <rule_uuid> --rule-name "Malware Detection Alert"
# Attach multiple alerts (batch)
node skills/security/case-management/scripts/case-manager.js attach-alerts --case-id <case_id> --alert-ids <id1> <id2> <id3> --alert-index .ds-.alerts-security.alerts-default-2026.02.16-000016 --rule-id <rule_uuid> --rule-name "Malware Detection Alert"
# Add comment, update (--tags merges with existing tags, does not replace)
node skills/security/case-management/scripts/case-manager.js add-comment --case-id <case_id> --comment "Process tree analysis shows..."
node skills/security/case-management/scripts/case-manager.js update --case-id <case_id> --status closed --severity low --yesWrite operations (create, update) prompt for confirmation by default. Pass --yes to skip the prompt (required when
called by an agent).
When reporting results from list or find:
total count from the JSON response (e.g., "There are 12 open cases total").<title> | <severity> | <case_id_short> | <created_at>. Copy the
exact title verbatim from the title field — do not rephrase, abbreviate, or summarize.Use structured tags for machine-searchable metadata:
| Tag pattern | Example | Purpose |
|---|---|---|
classification:<value> | classification:malicious | Triage classification (benign/unknown/malicious) |
confidence:<score> | confidence:85 | Confidence score 0-100 |
mitre:<technique> | mitre:T1574.002 | MITRE ATT&CK technique IDs |
agent_id:<id> | agent_id:550888e5-... | Elastic agent ID for correlation |
rule:<name> | rule:Malicious Behavior Detection | Detection rule name |
| Classification | Kibana severity |
|---|---|
| benign (score 0-19) | low |
| unknown (score 20-60) | medium |
| malicious (score 61-80) | high |
| malicious (score 81-100) | critical |
The syncAlerts setting (enabled by default) synchronizes case status with attached alert statuses. This feature is
only available for Security Solution cases. Pass --sync-alerts false when creating a case if alert sync is not needed.
The Kibana API enforces rate limits. When attaching multiple alerts, the attach-alerts batch command automatically
handles 429 responses with retry. If using attach-alert one at a time, space calls ~10 seconds apart.
find --search on ServerlessThe find --search parameter may return 500 errors on Kibana Serverless deployments. Use find --tags for filtering
instead, or list to browse recent cases.
find --tags requires exact matchTag searches are exact-match only. find --tags "agent_id:abc123" works, but partial matches do not.
For detailed API endpoints, request/response formats, and examples, see references/kibana-cases-api.md.
total field.create, update) prompt for confirmation. Pass --yes or -y to skip when called by an agent.KIBANA_URL and KIBANA_API_KEY point to the intended cluster before running any command.securitySolution — this skill does not affect Observability or other Kibana case owners.| Variable | Required | Description |
|---|---|---|
KIBANA_URL | Yes | Kibana base URL (e.g., https://my-kibana.kb.cloud.example.com) |
KIBANA_API_KEY | Yes | Kibana API key for authentication |
© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/security/case-management of elastic/agent-skills.
Open the folder on GitHubat commit baa5111
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in elastic/agent-skills, which our catalogue first saw on October 7, 2026.
Security Case Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Case Management this skillelastic/agent-skills | 592 | 1 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | |
| Debug Oaselastic/kibana | 21k | — | ~1.4k | Automated safety check: Pass | Custom licence | |
| Product Full-Text Searchlobehub/lobehub | 83k | — | ~4.1k | Automated safety check: Pass | Custom licence | |
| Kratos Developmentaide-family/moon | 253 | — | ~1.5k | Automated safety check: Pass | None | |
| Foundatio Repositoriesexceptionless/Exceptionless | 2.5k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Elasticsearch Authnaspectrr/deer | 405 | — | ~1.2k | Automated safety check: Notes | MIT |
elastic/kibana
A skill your agent uses when debugging OpenAPI (OAS) issues for a specific API area in Kibana by scoping validation output with one or more --path filters, then separating structural invalid-OAS…
lobehub/lobehub
Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.
aide-family/moon
Develops Go microservices with Kratos v2 following official design philosophy, DDD/Clean Architecture layout, Protobuf API, error/config/middleware patterns, and observability.
exceptionless/Exceptionless
Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.
aspectrr/deer
Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.
aspectrr/deer
Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
elastic/agent-skills
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).
elastic/agent-skills
Create and manage Kibana Dashboards and Lens visualizations.
elastic/agent-skills
Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.
elastic/agent-skills
Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…
elastic/agent-skills
Create and manage Elastic ML anomaly detection jobs via the API.
Works with
Categories
Create, search, update, and manage SOC cases via the Kibana Cases API. Security Case Management is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create, search, update, and manage SOC cases via the Kibana Cases API.
Security Case Management fits situations like: tracking incidents; linking alerts to cases; adding investigation notes; managing triage output.
Run `npx skills add elastic/agent-skills --skill security-case-management -a claude-code`. Or copy the skill folder (skills/security/case-management in elastic/agent-skills) into .claude/skills/security-case-management in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elastic/agent-skills --skill security-case-management -a codex`. Or copy the skill folder (skills/security/case-management in elastic/agent-skills) into .agents/skills/security-case-management in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill security-case-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-case-management, .gemini/skills/security-case-management, .github/skills/security-case-management and .opencode/skills/security-case-management in your project.
Going by SKILL.md and its folder, Security Case Management needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and npm) and credentials named KIBANA_API_KEY. Our summary lists: Node.js; A credential in KIBANA_API_KEY. Compatibility (from SKILL.md): Requires Node.js 22+, network access to Kibana. Environment variables: KIBANA_URL, plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD. .
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Security Case Management is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security Case Management: Debug Oas (elastic/kibana, 21k stars), Product Full-Text Search (lobehub/lobehub, 83k stars), Kratos Development (aide-family/moon, 253 stars) and Foundatio Repositories (exceptionless/Exceptionless, 2.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.
Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.