Agent skill

Anomaly Alert

by hoangsonww in hoangsonww/Claude-Code-Agent-Monitor

Identify anomalous sessions using Agent Monitor data — cost outliers from the pricing engine, token anomalies (cache miss spikes, compaction baseline surges), unusual event type ratios…

MITAuto-check passedData & Analytics

Install Anomaly Alert

skills CLI
$ npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill anomaly-alert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hoangsonww/Claude-Code-Agent-Monitor anomaly-alert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hoangsonww/Claude-Code-Agent-Monitor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ccam-insights/skills/anomaly-alert .claude/skills/anomaly-alert && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
anomaly-alert
GitHub stars
1.1k
Token cost
~744 tokens
SKILL.md length
272 words
Files
2
Skills in repo
78
Repo updated
First seen
Licence
MIT

At a glance

Identify anomalous sessions using Agent Monitor data — cost outliers from the pricing engine, token anomalies (cache miss spikes, compaction baseline surges), unusual event type ratios…

  • Works in 4 steps: Fetch baseline data from… → Compute baselines for each metric → Detect anomalies using statistical… → …
  • Tasks that involve Anomaly detection
  • SKILL.md covers Input, Procedure and Output Format
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Anomaly Alert is an agent skill from hoangsonww/Claude-Code-Agent-Monitor. Identify anomalous sessions using Agent Monitor data — cost outliers from the pricing engine, token anomalies (cache miss spikes, compaction baseline surges), unusual event type ratios (PreToolUse/PostToolUse gaps, APIError clusters), behavioral deviations from workflow intelligence (complexity score outliers, error propagation anomalies), and sessions with abnormal metadata (extreme turncount, high thinkingblocks, zero turnduration).

Its SKILL.md is about 740 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Data & Analytics, covering Anomaly detection. The repository describes itself as: 🚀 A real-time monitoring dashboard for Claude Code & Codex, built with SQLite3, Node.js, Express, React, Vite, TailwindCSS, & WebSockets. It tracks sessions, agent activity… The licence is MIT.

When your agent uses it

  • Tasks that involve Anomaly detection

Example prompts

  • “/anomaly-alert”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Fetch baseline data from http://localhost:4820
  2. Compute baselines for each metric
  3. Detect anomalies using statistical thresholds
  4. Classify each anomaly

What it can do on your machine

Read from SKILL.md and the folder at commit a06db03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Anomaly Alert loads about 744 tokens when it runs. Until then it costs about 114 tokens; SKILL.md has 272 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~114
When it runs · the whole SKILL.md, loaded when a task matches
~744

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hoangsonww/Claude-Code-Agent-Monitor at commit a06db03, republished under its MIT licence (© hoangsonww). 272 words, ~744 tokens.

Download SKILL.mdSave it as .claude/skills/anomaly-alert/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
anomaly-alert
description
Identify anomalous sessions using Agent Monitor data — cost outliers from the pricing engine, token anomalies (cache miss spikes, compaction baseline surges), unusual event type ratios (PreToolUse/PostToolUse gaps, APIError clusters), behavioral deviations from workflow intelligence (complexity score outliers, error propagation anomalies), and sessions with abnormal metadata (extreme turn_count, high thinking_blocks, zero turn_duration).

Anomaly Alert

Detect anomalous sessions in Claude Code Agent Monitor data.

Input

The user provides: $ARGUMENTS

This may be:

  • "all" or empty (default: check all anomaly types)
  • "cost" for cost anomalies only
  • "duration" for duration anomalies only
  • "errors" for error rate anomalies only
  • A sensitivity level: "strict" (1σ), "normal" (2σ), "relaxed" (3σ)

Procedure

  1. Fetch baseline data from http://localhost:4820:

    • GET /api/sessions?limit=500 — historical sessions for baseline
    • GET /api/analytics — aggregated metrics
    • GET /api/pricing/cost — cost data per session
  2. Compute baselines for each metric:

    • Mean, median, standard deviation
    • P25, P75, P90, P95, P99 percentiles
    • Interquartile range (IQR) for robust outlier detection
  3. Detect anomalies using statistical thresholds:

    Cost Anomalies
    • Sessions costing >2σ above mean
    • Single sessions exceeding daily average
    • Sudden cost spikes (session-over-session increase >200%)
    Duration Anomalies
    • Sessions lasting >2σ above mean duration
    • Extremely short sessions (<1 minute) that still incur cost
    • Sessions with unusual active-vs-idle ratios
    Error Rate Anomalies
    • Sessions with error rates >2σ above baseline
    • New error types not seen in previous sessions
    • Sessions with >3 consecutive tool failures
    Behavioral Anomalies
    • Unusual tool combinations not seen before
    • Sessions with abnormally high compaction counts
    • Model switches mid-session (if unexpected)
    • Sessions with no tool usage (pure conversation)
    Token Anomalies
    • Input/output token ratio far from historical norm
    • Cache miss rate significantly higher than average
    • Token usage growing faster than session count
  4. Classify each anomaly:

    • 🔴 Critical: Likely indicates a real problem requiring attention
    • 🟡 Warning: Unusual but may be expected for certain tasks
    • 🔵 Info: Interesting deviation worth noting

Output Format

Present as an Anomaly Report:

═══════════════════════════════════════════════
  ANOMALY DETECTION REPORT
  Analyzed: N sessions | Baseline: last 30 days
  Anomalies found: N (🔴 N critical, 🟡 N warn, 🔵 N info)
═══════════════════════════════════════════════

For each anomaly:

  • Session ID and timestamp
  • Anomaly type and severity
  • Observed value vs expected range
  • Possible explanation
  • Recommended action (if any)

© hoangsonww, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/ccam-insights/skills/anomaly-alert of hoangsonww/Claude-Code-Agent-Monitor.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit a06db03

Compare with similar skills

Anomaly Alert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Anomaly Alert compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Anomaly Alert this skillhoangsonww/Claude-Code-Agent-Monitor1.1k—~744Automated safety check: PassMIT
TimesFM Forecastinggoogle-research/timesfm34k—~4.7kAutomated safety check: PassApache-2.0
Anomalib Adding A Modelopen-edge-platform/anomalib6.2k—~1.9kAutomated safety check: PassApache-2.0
Anomalib Tiled Ensembleopen-edge-platform/anomalib6.2k—~1.4kAutomated safety check: PassApache-2.0
Kqlmicrosoft/fabric-rti-mcp131—~6.2kAutomated safety check: PassMIT
Time Series Analytics Useropen-edge-platform/edge-ai-libraries171—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • TimesFM Forecasting

    google-research/timesfm

    Forecasts any univariate time series zero-shot with Google's TimesFM model, returning point forecasts and calibrated prediction intervals without training.

    34k GitHub stars~4.7k tokensUpdated 11 days ago
    Data & AnalyticsAuto-check passed
  • Anomalib Adding A Model

    open-edge-platform/anomalib

    Adds a new anomaly-detection model to anomalib under src/anomalib/models/.

    6.2k GitHub stars~1.9k tokensUpdated yesterday
    Data & AnalyticsAuto-check passed
  • Anomalib Tiled Ensemble

    open-edge-platform/anomalib

    Runs and configures the anomalib tiled-ensemble pipeline, which trains/evaluates one model per image tile and merges results (with optional seam smoothing) for high-resolution anomaly detection.

    6.2k GitHub stars~1.4k tokensUpdated yesterday
    Data & AnalyticsAuto-check passed
  • Kql

    microsoft/fabric-rti-mcp

    Official

    KQL language expertise for writing correct, efficient Kusto queries using the Fabric RTI MCP tools.

    131 GitHub stars~6.2k tokensUpdated 10 days ago
    Data & AnalyticsAuto-check passed
  • Time Series Analytics User

    open-edge-platform/edge-ai-libraries

    Build a new time-series analytics use case on top of the deployed Time Series Analytics microservice — bring it up with Docker Compose (from a repo clone, or by fetching the compose files from…

    171 GitHub stars~3.1k tokensUpdated yesterday
    Data & AnalyticsAuto-check passed
  • Dt Obs Analytics

    Dynatrace/dynatrace-for-ai

    Analyze dashboards and notebooks using Davis analyzers — anomaly detection, novelty scoring, and correlation.

    163 GitHub stars~3.9k tokensUpdated 9 days ago
    Data & AnalyticsAuto-check passed

More from hoangsonww/Claude-Code-Agent-Monitor

All 78 skills in this repo
  • Version Release

    hoangsonww/Claude-Code-Agent-Monitor

    Choose and apply the correct semantic version bump for this repository.

    1.1k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Budget Set

    hoangsonww/Claude-Code-Agent-Monitor

    Define a spend budget for Claude Code and, optionally, create a cost alert rule that fires when usage crosses the limit, via POST /api/alerts/rules on the Agent Monitor dashboard.

    1.1k GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Cache Efficiency

    hoangsonww/Claude-Code-Agent-Monitor

    Analyze prompt-cache effectiveness for Claude Code usage from the Agent Monitor dashboard — cache hit rate (totalcacheread / (totalcacheread + totalinput)), cachewrite vs cacheread reuse, cache-read…

    1.1k GitHub stars~966 tokensUpdated yesterday
    Auto-check passed
  • Cost Breakdown

    hoangsonww/Claude-Code-Agent-Monitor

    Break down Claude Code costs using the Agent Monitor pricing engine.

    1.1k GitHub stars~845 tokensUpdated yesterday
    Auto-check passed
  • Dag Map

    hoangsonww/Claude-Code-Agent-Monitor

    Render the multi-agent orchestration DAG for a session — parent→child subagent edges, tree depth, and fan-out — from the Agent Monitor workflow intelligence API.

    1.1k GitHub stars~564 tokensUpdated yesterday
    Auto-check passed
  • Dashboard Status

    hoangsonww/Claude-Code-Agent-Monitor

    Quick dashboard health and status overview — checks the Agent Monitor API (port 4820), reports session/agent/event counts from /api/stats, confirms WebSocket connectivity, reads the redacted hook…

    1.1k GitHub stars~600 tokensUpdated yesterday
    Auto-check passed

Questions about Anomaly Alert

What does Anomaly Alert do?

Identify anomalous sessions using Agent Monitor data — cost outliers from the pricing engine, token anomalies (cache miss spikes, compaction baseline surges), unusual event type ratios…. Anomaly Alert is an agent skill from hoangsonww/Claude-Code-Agent-Monitor. Identify anomalous sessions using Agent Monitor data — cost outliers from the pricing engine, token anomalies (cache miss spikes, compaction baseline surges), unusual event type ratios (PreToolUse/PostToolUse gaps, APIError clusters), behavioral deviations from workflow intelligence (complexity score outliers, error propagation anomalies), and sessions with abnormal metadata (extreme turncount, high thinkingblocks, zero turnduration).

When should I use Anomaly Alert?

Anomaly Alert fits situations like: tasks that involve Anomaly detection.

How do I install Anomaly Alert in Claude Code?

Run `npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill anomaly-alert -a claude-code`. Or copy the skill folder (plugins/ccam-insights/skills/anomaly-alert in hoangsonww/Claude-Code-Agent-Monitor) into .claude/skills/anomaly-alert in your project. Claude Code loads it when a task matches its description.

How do I install Anomaly Alert in Codex?

Run `npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill anomaly-alert -a codex`. Or copy the skill folder (plugins/ccam-insights/skills/anomaly-alert in hoangsonww/Claude-Code-Agent-Monitor) into .agents/skills/anomaly-alert in your project. Codex loads it when a task matches its description.

Can I use Anomaly Alert in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill anomaly-alert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/anomaly-alert, .gemini/skills/anomaly-alert, .github/skills/anomaly-alert and .opencode/skills/anomaly-alert in your project.

What does Anomaly Alert need to run?

SKILL.md names no scripts, command-line tools or credentials: Anomaly Alert is instructions for the agent only.

Does Anomaly Alert access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Anomaly Alert safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Anomaly Alert use?

Anomaly Alert is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Anomaly Alert use?

About 744 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Anomaly Alert?

Skills that share tags, products or a category with Anomaly Alert: TimesFM Forecasting (google-research/timesfm, 34k stars), Anomalib Adding A Model (open-edge-platform/anomalib, 6.2k stars), Anomalib Tiled Ensemble (open-edge-platform/anomalib, 6.2k stars) and Kql (microsoft/fabric-rti-mcp, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Anomaly Alert?

hoangsonww (a GitHub user) maintains it in hoangsonww/Claude-Code-Agent-Monitor, which has 1,058 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 10, 2026.

Source: hoangsonww/Claude-Code-Agent-Monitor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.