Amazon Opensearch Service
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
A skill your agent uses when the user has a known, already-observed anomaly in their data — a metric spike or drop, an outlier, an unexpected number — and wants its root cause diagnosed, not guessed.
$ npx skills add gaasher/Agent-Loop-Skills --skill anomaly-investigation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install gaasher/Agent-Loop-Skills anomaly-investigation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/gaasher/Agent-Loop-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/loops/anomaly-investigation .claude/skills/anomaly-investigation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "anomaly-investigation" agent skill from https://github.com/gaasher/Agent-Loop-Skills/tree/main/loops/anomaly-investigation into .claude/skills/anomaly-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anomaly-investigation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/gaasher/Agent-Loop-Skills/tree/main/loops/anomaly-investigationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add gaasher/Agent-Loop-Skills --skill anomaly-investigation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install gaasher/Agent-Loop-Skills anomaly-investigation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gaasher/Agent-Loop-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/loops/anomaly-investigation .agents/skills/anomaly-investigation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "anomaly-investigation" agent skill from https://github.com/gaasher/Agent-Loop-Skills/tree/main/loops/anomaly-investigation into .agents/skills/anomaly-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anomaly-investigation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gaasher/Agent-Loop-Skills --skill anomaly-investigation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install gaasher/Agent-Loop-Skills anomaly-investigation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gaasher/Agent-Loop-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/loops/anomaly-investigation .cursor/skills/anomaly-investigation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "anomaly-investigation" agent skill from https://github.com/gaasher/Agent-Loop-Skills/tree/main/loops/anomaly-investigation into .cursor/skills/anomaly-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anomaly-investigation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/gaasher/Agent-Loop-Skills.git --path loops/anomaly-investigation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add gaasher/Agent-Loop-Skills --skill anomaly-investigation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install gaasher/Agent-Loop-Skills anomaly-investigation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gaasher/Agent-Loop-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/loops/anomaly-investigation .gemini/skills/anomaly-investigation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "anomaly-investigation" agent skill from https://github.com/gaasher/Agent-Loop-Skills/tree/main/loops/anomaly-investigation into .gemini/skills/anomaly-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anomaly-investigation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install gaasher/Agent-Loop-Skills anomaly-investigationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add gaasher/Agent-Loop-Skills --skill anomaly-investigation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/gaasher/Agent-Loop-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/loops/anomaly-investigation .github/skills/anomaly-investigation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "anomaly-investigation" agent skill from https://github.com/gaasher/Agent-Loop-Skills/tree/main/loops/anomaly-investigation into .github/skills/anomaly-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anomaly-investigation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gaasher/Agent-Loop-Skills --skill anomaly-investigation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install gaasher/Agent-Loop-Skills anomaly-investigation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gaasher/Agent-Loop-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/loops/anomaly-investigation .opencode/skills/anomaly-investigation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "anomaly-investigation" agent skill from https://github.com/gaasher/Agent-Loop-Skills/tree/main/loops/anomaly-investigation into .opencode/skills/anomaly-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "anomaly-investigation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
anomaly-investigationA skill your agent uses when the user has a known, already-observed anomaly in their data — a metric spike or drop, an outlier, an unexpected number — and wants its root cause diagnosed, not guessed.
Anomaly Investigation is an agent skill from gaasher/Agent-Loop-Skills. Use when the user has a known, already-observed anomaly in their data — a metric spike or drop, an outlier, an unexpected number — and wants its root cause diagnosed, not guessed. Forms a slate of candidate causes, tests each against the data, and eliminates the ones the data refutes, narrowing the live candidates until exactly one survives refutation and passes a positive confirming test. The result is an investigation log with the confirmed root cause and the evidence that ruled out the alternatives. Not for…
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `examples/run.example.yaml`). Compatibility notes: Requires Python 3.9+
It sits in Data & Analytics, covering Root cause analysis and Data analysis. The repository describes itself as: Loop until it's better — drop-in agentic loops (autoresearch, scientific writing, data analysis, code/SQL/prompt optimization, red-teaming) as open-standard Agent Skills… The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f1169e6. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
uvFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires Python 3.9+
From compatibility in the SKILL.md frontmatter.
Anomaly Investigation loads about 2.1k tokens when it runs. Until then it costs about 194 tokens; SKILL.md has 1,047 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from gaasher/Agent-Loop-Skills at commit f1169e6, republished under its MIT licence (© gaasher). 1,047 words, ~2,119 tokens.
.claude/skills/anomaly-investigation/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.A form → test → eliminate → confirm loop — root-cause analysis as a search. The artifact is an investigation log; the feedback signal is the count of live candidate explanations, driven down toward a single cause that is confirmed, not merely consistent. Each iteration you test one candidate against the data and drop the ones the data refutes, narrowing the field until one survives.
The discipline this enforces: a cause is "root" only when it both survives an honest attempt to refute it and makes a positive prediction that checks out (e.g. "if this is the cause, removing it restores normal" — and it does). A story that merely could explain the anomaly is a hypothesis, not a finding.
Use this when an anomaly is already in hand — you know roughly what looks wrong and want the cause diagnosed by elimination against the data. Default to a broad initial slate of mutually distinguishable causes, then test the one that splits the field fastest; if the anomaly is vague, your first job is to make it precise (iteration 0). Not for open-ended exploration of a dataset with no anomaly to chase (use data-analysis), and not for verifying an external claim against the literature (use claim-verify).
Resolve bindings interactively. If loop.run.yaml exists in the working dir, load it, confirm the
values in one line, and skip to the loop. Otherwise: on Claude Code (the AskUserQuestion tool is
available) infer a likely value for each binding and present it as the recommended option; on other
hosts ask each as a quoted plain-text prompt. Then write loop.run.yaml (format:
examples/run.example.yaml) and confirm the values before creating any other files.
| binding | meaning | default | how to infer |
|---|---|---|---|
<dataset> | data (or logs) to investigate; read-only ground truth | — | scan the working dir for a data/log file |
<anomaly> | what looks wrong: the metric, where/when, and how big the deviation is | — | ask the user; make precise in iter 0 |
<analysis_cmd> | interpreter that runs analysis snippets in the user's env | python3 | pyproject.toml/.venv/uv in the working dir |
<log> | output investigation log | <sandbox_root>/investigation.md | — |
<sandbox_root> | where snippets + ledger live | ./sandbox | — |
<budget> | max iterations | 8 | — |
Analysis snippets run in the user's environment via <analysis_cmd>, so they may use whatever the
user has installed. Keep helper code stdlib-first (csv, statistics): if a snippet needs
pandas/numpy, probe with try/except ImportError and degrade to a stdlib path, or offer a
consented uv pip install "pandas==<ver>" — never assume the package is installed.
Copy this checklist and tick items off:
<log>.<sandbox_root>/iter<N>/test.py, run with <analysis_cmd>, redirect to out.txt.<budget>.Iteration 0 — characterize. Quantify the anomaly precisely: write and run a snippet that pins down
what deviated, where/when, and how big the deviation is against the normal baseline (the same
metric on surrounding periods/segments). Then form an initial slate of candidate causes — mutually
distinguishable explanations, broad enough to contain the truth (a real change, a composition/mix
shift, a data-quality bug, a measurement change, seasonality, an outlier segment). List them in
<log> as the live candidates. Record nothing as confirmed yet.
Then, until stop (one confirmed cause, or budget):
<sandbox_root>/iter<N>/test.py that computes the thing that would refute or
support it (slice by segment/source/time, recompute the metric, compare distributions). Run it
with <analysis_cmd>, redirecting output to <sandbox_root>/iter<N>/out.txt (never flood your
context).<log> with the evidence; drop it from the live set.Observational equivalence. Two mechanistically different candidates can make identical predictions in the data you have (e.g. a bot flood and a pipeline double-count both look like "sessions spike, conversions flat" in daily aggregates). When that happens you cannot separate them here — do not pick one arbitrarily. Report them as a single confirmed cause at the resolution of the available data, and name the additional data that would distinguish them (finer-grained logs, raw event records, an upstream check). Distinguish, too, the mechanism (how the metric moved) from the root cause (why the inputs were wrong) — confirming the mechanism is progress, but is not the cause.
<sandbox_root>/ledger.tsv, tab-separated, never commas in the text. Header:
iter candidate_tested verdict live_candidatesverdict ∈ {characterize, refuted, supported, confirmed}. Example:
iter candidate_tested verdict live_candidates
0 characterize anomaly + slate characterize 5
1 real drop across all segments refuted 4
2 one segment's conversions fell refuted 3
3 one source's sessions inflated supported 2
4 removing that source restores normal confirmed 1Report the confirmed root cause with its confirming evidence, the alternatives and how each was ruled out, and — if you stop without a single confirmed cause — the remaining live candidates and the test that would separate them.
<log>.<dataset> — never modify it, because it is the ground truth every test is checked
against. The sandbox is self-contained (no ../ escapes).<budget> iterations reached without a single confirmed cause; report the live set.© gaasher, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in loops/anomaly-investigation of gaasher/Agent-Loop-Skills.
Open the folder on GitHubat commit f1169e6
Anomaly Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Anomaly Investigation this skillgaasher/Agent-Loop-Skills | 174 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Amazon Opensearch Serviceaws/agent-toolkit-for-aws | 2.8k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Data Analysis Standardmohitagw15856/pm-claude-skills | 1.4k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Exploratory Data Analysisspacering-net/codeg | 3.9k | 14 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Excel and CSV Data Analysisbytedance/deer-flow | 84k | 4 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Exploratory Data AnalysisOleafly/Oleafly | 212 | 2 repos | ~3.4k | Automated safety check: Notes | MIT |
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
mohitagw15856/pm-claude-skills
Structure a product data analysis, metric deep-dive, funnel analysis, or cohort study.
spacering-net/codeg
Perform comprehensive exploratory data analysis on scientific data files across 200+ file formats.
bytedance/deer-flow
Analyzes uploaded Excel and CSV files with SQL through DuckDB, producing schema inspections, statistical summaries and exports to CSV, JSON or Markdown.
Oleafly/Oleafly
Perform bounded, local exploratory analysis of explicitly supported scientific files.
Jeffallan/claude-skills
Handles pandas DataFrame work: cleaning, merging, groupby aggregation, pivots, time-series resampling and memory tuning, with checks on dtypes, shapes and nulls.
gaasher/Agent-Loop-Skills
A skill your agent uses when the user wants to evolve an ML model/program through population-based search rather than a single sequential refine loop — a generational evolution where parallel…
gaasher/Agent-Loop-Skills
A skill your agent uses when the user has concrete failing cases in code or a guardrail/classifier/filter/prompt/API they own — a red-team failure catalogue OR a CI/CD test-failure report (failing…
gaasher/Agent-Loop-Skills
A skill your agent uses when the user wants an iterative, self-checking exploratory analysis of a dataset — surfacing findings that are each verified by re-running the computation, not asserted.
gaasher/Agent-Loop-Skills
A skill your agent uses when the user wants to generate and literature-vet a pool of novel, testable research hypotheses for a question or domain.
gaasher/Agent-Loop-Skills
A skill your agent uses when the user wants the LLM to do its own ML research: a fully-autonomous loop that hacks the training code, runs it, and keeps changes that lower a single scalar metric (e.g.
gaasher/Agent-Loop-Skills
A skill your agent uses when the user wants two approaches raced head-to-head on a single shared metric — e.g.
Categories
A skill your agent uses when the user has a known, already-observed anomaly in their data — a metric spike or drop, an outlier, an unexpected number — and wants its root cause diagnosed, not guessed. Anomaly Investigation is an agent skill from gaasher/Agent-Loop-Skills. Use when the user has a known, already-observed anomaly in their data — a metric spike or drop, an outlier, an unexpected number — and wants its root cause diagnosed, not guessed.
Anomaly Investigation fits situations like: the user has a known; already-observed anomaly in their data — a metric spike; an unexpected number — and wants its root cause diagnosed.
Run `npx skills add gaasher/Agent-Loop-Skills --skill anomaly-investigation -a claude-code`. Or copy the skill folder (loops/anomaly-investigation in gaasher/Agent-Loop-Skills) into .claude/skills/anomaly-investigation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add gaasher/Agent-Loop-Skills --skill anomaly-investigation -a codex`. Or copy the skill folder (loops/anomaly-investigation in gaasher/Agent-Loop-Skills) into .agents/skills/anomaly-investigation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gaasher/Agent-Loop-Skills --skill anomaly-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/anomaly-investigation, .gemini/skills/anomaly-investigation, .github/skills/anomaly-investigation and .opencode/skills/anomaly-investigation in your project.
Going by SKILL.md and its folder, Anomaly Investigation needs the command-line tools its instructions call (uv). Our summary lists: Python 3. Compatibility (from SKILL.md): Requires Python 3.9+.
SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Anomaly Investigation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Anomaly Investigation: Amazon Opensearch Service (aws/agent-toolkit-for-aws, 2.8k stars), Data Analysis Standard (mohitagw15856/pm-claude-skills, 1.4k stars), Exploratory Data Analysis (spacering-net/codeg, 3.9k stars) and Excel and CSV Data Analysis (bytedance/deer-flow, 84k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
gaasher (a GitHub user) maintains it in gaasher/Agent-Loop-Skills, which has 174 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on June 30, 2026.
Source: gaasher/Agent-Loop-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.