Agent skill

Diag Tuning

by haumacher in haumacher/phoneblock

Tune the PhoneBlock diagnostics log analysis — inspect aggregated log signatures, find noise / signature fragmentation / PII leaks, and propose, audit and promote scrub rules (and detection rules)…

GPL-3.0Auto-check passedAgent Workflows

Install Diag Tuning

skills CLI
$ npx skills add haumacher/phoneblock --skill diag-tuning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install haumacher/phoneblock diag-tuning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/haumacher/phoneblock.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/diag-tuning .claude/skills/diag-tuning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
diag-tuning
GitHub stars
367
Token cost
~2.1k tokens
SKILL.md length
1,070 words
Files
2
Skills in repo
4
Repo updated
First seen
Licence
GPL-3.0

At a glance

Tune the PhoneBlock diagnostics log analysis — inspect aggregated log signatures, find noise / signature fragmentation / PII leaks, and propose, audit and promote scrub rules (and detection rules)…

  • Works in 3 steps: Scrub (Scrubber.java) runs first and… → Normalize (LogNormalizer) then replaces… → Signature = the normalized+scrubbed…
  • Asked to look at the diagnostics results
  • SKILL.md covers Access — the phoneblock-diag MCP, Mental model — the pipeline, Two symptoms worth hunting and Workflow, plus 3 more sections
  • Runs Python scripts from its folder; reaches phoneblock.net

What it does

Diag Tuning is an agent skill from haumacher/phoneblock. Tune the PhoneBlock diagnostics log analysis — inspect aggregated log signatures, find noise / signature fragmentation / PII leaks, and propose, audit and promote scrub rules (and detection rules) over the admin API. Use when asked to look at the diagnostics results, "what rules could we add", reduce log noise, or clean up how server/dongle log lines are grouped. Backed by the local phoneblock-diag MCP server.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `mcp/diag_mcp.py`).

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: Der Spam-Filter für Dein Telefon. The licence is GPL-3.0.

When your agent uses it

  • Asked to look at the diagnostics results
  • What rules could we add
  • Reduce log noise
  • Clean up how server/dongle log lines are grouped

Example prompts

  • “what rules could we add”
  • “/diag-tuning”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Scrub (Scrubber.java) runs first and masks high-confidence PII shapes
  2. Normalize (LogNormalizer) then replaces variable tokens with ,
  3. Signature = the normalized+scrubbed string; its content hash is sigId.

What it can do on your machine

Read from SKILL.md and the folder at commit 9287ad7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • phoneblock.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Diag Tuning loads about 2.1k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 1,070 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from haumacher/phoneblock at commit 9287ad7, republished under its GPL-3.0 licence (© haumacher). 1,070 words, ~2,146 tokens.

Download SKILL.mdSave it as .claude/skills/diag-tuning/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
diag-tuning
description
Tune the PhoneBlock diagnostics log analysis — inspect aggregated log signatures, find noise / signature fragmentation / PII leaks, and propose, audit and promote scrub rules (and detection rules) over the admin API. Use when asked to look at the diagnostics results, "what rules could we add", reduce log noise, or clean up how server/dongle log lines are grouped. Backed by the local `phoneblock-diag` MCP server.

Diagnostics log tuning

The diagnostics framework (branch diagnostics-framework, PR #473) reads the server and dongle logs, scrubs PII, normalizes each line to a signature, and rolls signatures up into DIAG_* aggregate tables. On top of the always-on built-in scrubber sits a hot-editable layer of scrub rules and a set of detection rules that can raise a user-facing help mail. This skill is the loop for keeping that analysis honest: collapse fragmented signatures, plug PII leaks, and turn recurring failures into actionable rules.

The test system reads the live server's logs (including server errors), so its data is real production traffic. Base URL: https://phoneblock.net/pb-test/api.

Access — the phoneblock-diag MCP

Tools come from the local MCP server registered in .mcp.json (.claude/skills/diag-tuning/mcp/diag_mcp.py, zero-dependency Python). Two servers are registered: phoneblock-diag targets production (the default — this is where the framework runs), and phoneblock-diag-test targets pb-test. Each reads its own admin token from ~/.m2/settings.xml (<password>/<passphrase>) via the server id in PHONEBLOCK_TOKEN_SERVER: phoneblock-admin for prod, phoneblock-admin-test for test — the token never lives in the repo. Prefer the prod tools unless you deliberately want test.

Key tools: ingest_status, list_signatures (returns a volume-ranked, compact list), get_signature, audit_scrub, list_scrub_rules, create_scrub_rule, set_scrub_state, list_rules, list_notifications, origin_timeline.

Always use these MCP tools — do not hand-roll curl plus token extraction from settings.xml. The server exists precisely to hold the token and the endpoints for you. If you find yourself writing a shell script to hit the API, stop: the MCP is either not loaded (check .mcp.json is trusted, reload the session) or a tool is missing something worth adding. The 1:1 mapping to `GET/POST

<base>/admin/diag/…` is documentation of what each tool does and a stopgap for
when the MCP **process itself** is down — not a routine alternative.

Mental model — the pipeline

Per log line: scrub → normalize → signature.

  1. Scrub (Scrubber.java) runs first and masks high-confidence PII shapes (email, sip:/tel: phone, international subscriber number). It deliberately does not mask bare digit runs (those are HTTP/SIP codes, uptimes, byte counts). Built-in rules are always on; LIVE DIAG_SCRUB_RULE rows layer on top.
  2. Normalize (LogNormalizer) then replaces variable tokens with <N>, <ARG>, <UUID>, <TOKEN>, <username>, etc. — this is what produces the <N> you see in signatures. Because scrub runs before normalize, a scrub rule matches the raw text, and its output is what gets normalized.
  3. Signature = the normalized+scrubbed string; its content hash is sigId.

The retained sample is scrubbed-but-not-normalized, so get_signature shows you the real raw tail — that is what you design a rule against.

applies_to splits the scrub pass: SIGNATURE shapes only the grouping key, SAMPLE only the retained text, BOTH shapes both.

Two symptoms worth hunting

  • Signature fragmentation — one real error split across many signatures because a variable tail (a username, path, hostname) survives into the key. This hides true volume in the ranking. Fix: a SIGNATURE-anchored scrub rule that collapses the tail.
  • PII leak — a real identifier the built-in scrubber missed (classic case: a URL-encoded email like phoneblock%40gaerti.de, since %40 ≠ @). Fix: a BOTH rule so it is masked in samples too.

Workflow

  1. ingest_status — confirm the ingestor is live and not badly lagged.
  2. list_signatures (rank by totalEvents) — scan for noise, fragmented families (same tag, near-identical text differing only in a tail), and PII.
  3. For a candidate family: get_signature on a couple of members to read the raw sample tails.
  4. Design an anchored scrub rule (see below). Prove the collapse locally (a quick Python re.sub over the sample strings), then run audit_scrub with the candidatePattern against live samples — confirm it hits only the intended tag and roughly the expected volume.
  5. create_scrub_rule — lands as DRAFT (stored, not applied). Review.
  6. Promote with set_scrub_state → LIVE (admin token required). A scrub rule only shapes events going forward; it does not retro-merge existing signatures.
Show full SKILL.md (451 more words)Show less
Rule design rules-of-thumb
  • Anchor on a stable prefix and capture it: (Prevent deleting card: ).* → $1<CARD>. Never write a bare .* that could match unrelated lines.
  • Match the raw tail (scrub runs before normalize) — e.g. \d+, not <N>.
  • Beware repeated anchors in one line: if a token appears twice (e.g. /addresses/ in both an arg and the real path), anchor on the fuller, unique prefix.
  • SIGNATURE when the tail is diagnostically useful and low-sensitivity (keep it visible in samples); BOTH when the tail is PII or a possible secret.
  • Don't lower the built-in phone threshold to catch short partials (+4990) — it would eat legit country prefixes (+49). Collapse those with a context-anchored rule instead.

Scrub rules vs detection rules

  • Scrub rules (DIAG_SCRUB_RULE, this skill's main focus) only mask — safe, additive, tune grouping/anonymization.
  • Detection rules (list_rules, e.g. DongleSilenceDetector) match a signature and can raise a help mail. They carry SHADOW→LIVE state and a kill-switch; treat promotion as outbound-affecting and confirm first.

Scrub rules currently LIVE (server source)

Three scrub rules run against the SERVER source, each collapsing a fragmented family (list_scrub_rules). Scrub rules apply to new events only — they do not retro-merge the pre-existing fragmented signatures, which linger in the ranking and just stop growing:

  • diag-dyndns-host — (wrong password \(\d+ characters\): ).* → $1<DYNDNS-HOST>, SIGNATURE (folded ~1.3k DynIpServlet events into one signature; keeps the raw tail in samples so the fb-fb-… config-bug and which hosts are hammered stay visible — flip to BOTH if the occasional password-in-username matters).
  • diag-addressbook-path — (/phoneblock/contacts/addresses/)[^/]+/[^'\s]* → $1<BOOK>/<CARD>, BOTH (~0.8k events; also masks the URL-encoded email leak).
  • diag-address-card — (Prevent deleting card: ).* → $1<CARD>, BOTH (~0.5k).

Open observations from the live logs

Surfaced from the logs, not yet acted on:

  • Scanning / recon clusters → candidates for a category=SECURITY tag (track, don't mail): auth scanning (DB: Invalid user name ~3.7k, invalid password, DynDNS wrong-password ~1.4k, login failures — the largest block); DNS-server recon (DnsServer: No zone found for: version.bind. / id.server. / shadowserver.org. / . plus ~360 malformed-packet WireParseExceptions); and SIP scanning (SipProvider: … OPTIONS sip:nm … — sipvicious/svmap).
  • Onboarding signal: CardDavServlet: … not found: / Benutzername/ — a user pasted the literal placeholder "Benutzername" from a setup guide into their CardDAV client. Low volume, but a concrete docs/UX fix.
  • No stale-fragment cleanup: there is no step to prune signatures with no recent events, so pre-rule fragments stay visible in the ranking indefinitely.

Already handled (do not re-propose):

  • Answerbot registration failures (SipService: … register ab-<N> … Timeout) are the retry churn of the existing mechanism: SipService.onRegistrationFailure disables a bot after disableTimeout (3 days) and, for a bot that had registered before, sends sendDiableMail. A never-registered ("temporary") bot is disabled silently (no mail) — the one arguable gap.
  • Two code bugs — the Goolge typo and the Google/IndexNow log flood (~62% of events) — fixed in this PR (backoff + one-shot logging in the two index services).

© haumacher, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/diag-tuning of haumacher/phoneblock.

  • SKILL.md
  • mcp/diag_mcp.py

Open the folder on GitHubat commit 9287ad7

Compare with similar skills

Diag Tuning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Diag Tuning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Diag Tuning this skillhaumacher/phoneblock367—~2.1kAutomated safety check: PassGPL-3.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Context Mode Output Sandboxmksglu/context-mode26k—~4.1kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    Agent WorkflowsAuto-check passed

More from haumacher/phoneblock

  • Cleanup Workspace

    haumacher/phoneblock

    Park a finished worktree — commit real work, delete temporary/generated leftovers, then switch to the throwaway branch named after the workspace directory and reset it to origin/master.

    367 GitHub stars~1.1k tokensUpdated 8 days ago
    Auto-check: notes
  • Dongle Crash Analysis

    haumacher/phoneblock

    Decode and analyze an ESP32 dongle crash report (uploaded .coredump).

    367 GitHub stars~1.9k tokensUpdated 8 days ago
    Auto-check: notes
  • Fix Issue

    haumacher/phoneblock

    Start work on a GitHub issue — verify a clean workspace, read the issue, branch off the correct base (the branch where the fix will ship) as issue-<nr-<short-description, then plan the implementation.

    367 GitHub stars~1.1k tokensUpdated 8 days ago
    Auto-check: notes

Categories

Questions about Diag Tuning

What does Diag Tuning do?

Tune the PhoneBlock diagnostics log analysis — inspect aggregated log signatures, find noise / signature fragmentation / PII leaks, and propose, audit and promote scrub rules (and detection rules)…. Diag Tuning is an agent skill from haumacher/phoneblock. Tune the PhoneBlock diagnostics log analysis — inspect aggregated log signatures, find noise / signature fragmentation / PII leaks, and propose, audit and promote scrub rules (and detection rules) over the admin API.

When should I use Diag Tuning?

Diag Tuning fits situations like: asked to look at the diagnostics results; what rules could we add; reduce log noise; clean up how server/dongle log lines are grouped.

How do I install Diag Tuning in Claude Code?

Run `npx skills add haumacher/phoneblock --skill diag-tuning -a claude-code`. Or copy the skill folder (.claude/skills/diag-tuning in haumacher/phoneblock) into .claude/skills/diag-tuning in your project. Claude Code loads it when a task matches its description.

How do I install Diag Tuning in Codex?

Run `npx skills add haumacher/phoneblock --skill diag-tuning -a codex`. Or copy the skill folder (.claude/skills/diag-tuning in haumacher/phoneblock) into .agents/skills/diag-tuning in your project. Codex loads it when a task matches its description.

Can I use Diag Tuning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add haumacher/phoneblock --skill diag-tuning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/diag-tuning, .gemini/skills/diag-tuning, .github/skills/diag-tuning and .opencode/skills/diag-tuning in your project.

What does Diag Tuning need to run?

Going by SKILL.md and its folder, Diag Tuning needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Diag Tuning access the network?

SKILL.md names 1 domain. In commands or code: phoneblock.net; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Diag Tuning safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Diag Tuning use?

Diag Tuning is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Diag Tuning use?

About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Diag Tuning?

Skills that share tags, products or a category with Diag Tuning: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Crush Configuration (charmbracelet/crush, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Diag Tuning?

haumacher (a GitHub user) maintains it in haumacher/phoneblock, which has 367 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 3, 2026.

Source: haumacher/phoneblock on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.