Agent skill

Investigate

by Houseofmvps in Houseofmvps/ultraship

Root cause investigation — structured debugging with module freeze.

MITAuto-check passedDevelopment

Install Investigate

skills CLI
$ npx skills add Houseofmvps/ultraship --skill investigate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Houseofmvps/ultraship investigate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/investigate .claude/skills/investigate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
investigate
GitHub stars
123
Token cost
~1.3k tokens
SKILL.md length
587 words
Files
1
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Root cause investigation — structured debugging with module freeze.

  • Works in 5 steps: Scope Lock → Evidence Collection → Hypothesis → …
  • Encountering any bug
  • SKILL.md covers The Iron Law, Process, Red Flags and Integration with Guard, plus 1 more section
  • Calls git and node

What it does

Investigate is an agent skill from Houseofmvps/ultraship. Root cause investigation — structured debugging with module freeze. No fixes without investigation. Use when encountering any bug, error, or unexpected behavior.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Root cause analysis and Debugging. The repository describes itself as: "ULTRASHIP" Claude Code plugin — 39 skills, 33 tools, 11 agents for ship-ready workflows: planning, review, pentesting, safety guardrails, canary monitoring, SEO/AI-readiness… The licence is MIT.

When your agent uses it

  • Encountering any bug
  • Unexpected behavior

Example prompts

  • “/investigate”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Scope Lock
  2. Evidence Collection
  3. Hypothesis
  4. Test
  5. Fix

What it can do on your machine

Read from SKILL.md and the folder at commit ed232cb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Investigate loads about 1.3k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 587 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Houseofmvps/ultraship at commit ed232cb, republished under its MIT licence (© Houseofmvps). 587 words, ~1,304 tokens.

Download SKILL.mdSave it as .claude/skills/investigate/SKILL.md (or your agent's skills folder).
name
investigate
description
Root cause investigation — structured debugging with module freeze. No fixes without investigation. Use when encountering any bug, error, or unexpected behavior.
argument-hint
<error-or-symptom-description>
disallowed-tools
Edit, Write, NotebookEdit

Investigate — Root Cause Analysis

Investigation is the discipline of understanding a problem before fixing it. This skill enforces a strict protocol: no fixes until the root cause is found.

Enforced: while this skill is active, Edit, Write, and NotebookEdit are removed via disallowed-tools. The no-fixes rule is a hard constraint here, not a request. Once you have found and stated the root cause, conclude the investigation — the fix happens as a separate step outside this skill.

Announce at start: "I'm using the investigate skill — no fixes until we find the root cause."

The Iron Law

┌──────────────────────────────────────────────┐
│  NO FIXES WITHOUT ROOT CAUSE INVESTIGATION   │
│                                              │
│  If you haven't found the root cause,        │
│  you cannot propose a fix.                   │
└──────────────────────────────────────────────┘

This is not a suggestion. This is a hard constraint. Guessing causes more bugs than it fixes.

Process

Phase 1: Scope Lock

Before investigating, lock the investigation scope to prevent it from sprawling:

  1. State the symptom — What exactly is broken? Be precise.
  2. Identify the module — Which part of the codebase is affected?
  3. Freeze to module — Investigation stays within this module until evidence points elsewhere.

Example:

Symptom: API returns 500 on POST /api/webhooks
Module: packages/api/src/routes/webhooks.ts
Freeze: Investigation limited to webhook handler + its direct dependencies

Why freeze? Without scope, investigation becomes exploration. Exploration finds interesting things but doesn't fix bugs.

Phase 2: Evidence Collection

Gather evidence BEFORE forming any hypothesis:

  1. Read the error — Full stack trace, error message, error code. Not a glance — read every line.

  2. Reproduce — Can you trigger it reliably? What are the exact steps?

    • If reproducible: proceed
    • If intermittent: gather more data points, don't guess
  3. Check the timeline — What changed recently?

    bash
    git log --oneline -20
    git diff HEAD~3
  4. Trace the data flow — Follow the data from input to error:

    • What value enters the function?
    • What transformation happens?
    • Where does it break?
    • Trace BACKWARD from the error to the source
  5. Check boundaries — For multi-component systems, verify data at each boundary:

    • API → service: is the request correct?
    • Service → database: is the query correct?
    • Database → response: is the result expected?
Phase 3: Hypothesis

Form ONE hypothesis based on evidence:

"I think [X] is the root cause because [evidence Y shows Z]"

Requirements:

  • Must be specific (not "something is wrong with auth")
  • Must be supported by evidence collected in Phase 2
  • Must be testable with a single, minimal change
Phase 4: Test

Test the hypothesis with the SMALLEST possible change:

  1. Make ONE change
  2. Run the reproduction steps
  3. Did it fix the issue?
    • Yes → Proceed to Phase 5
    • No → Return to Phase 2 with new information. Do NOT add more fixes.

Critical: If 3 hypotheses fail, STOP. The problem is likely architectural, not a simple bug. Discuss with the user before attempting fix #4.

Show full SKILL.md (216 more words)Show less
Phase 5: Fix

Now — and only now — implement the proper fix:

  1. Write a failing test that reproduces the exact bug
  2. Implement the fix — address the root cause, not the symptom
  3. Verify the test passes
  4. Run the full test suite — ensure no regressions
  5. Save the learning — record what you found for future reference:
    bash
    node ${CLAUDE_PLUGIN_ROOT}/tools/learnings-manager.mjs save --title "Root cause of webhook 500" --body "The webhook handler wasn't awaiting the database write, causing a race condition with the response" --tags "debugging,webhooks,async"

Red Flags

If you catch yourself doing any of these, STOP and return to Phase 2:

  • "Let me just try this quick fix"
  • "It's probably X, let me change it"
  • "I'll add multiple changes and see which works"
  • "I don't fully understand but this might work"
  • "Here are 3 possible fixes" (without investigation)
  • Proposing solutions before tracing the data flow

Integration with Guard

For critical systems, activate /guard before investigating to prevent accidental changes:

/guard → /investigate → fix → /canary

Guard ensures no destructive commands run during investigation, and canary verifies the fix in production.

Relationship to Systematic Debugging

This skill shares principles with ultraship:systematic-debugging but adds:

  • Module freeze — scoped investigation prevents sprawl
  • Learning capture — every investigation produces a learning
  • Guard integration — safety during critical system debugging
  • Escalation protocol — clear rules for when to stop and rethink

© Houseofmvps, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/investigate of Houseofmvps/ultraship.

Open the folder on GitHubat commit ed232cb

Compare with similar skills

Investigate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Investigate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Investigate this skillHouseofmvps/ultraship123—~1.3kAutomated safety check: PassMIT
OpenLogi macOS Permissions TriageAprilNEA/OpenLogi23k—~2.5kAutomated safety check: NotesApache-2.0
Bug Finder for daisyUIsaadeghi/daisyui43k—~2.3kAutomated safety check: PassMIT
Root Cause Debugginggarrytan/gstack136k—~1.4kAutomated safety check: PassMIT
Graph-Based Bug Tracingtirth8205/code-review-graph32k1 repos~287Automated safety check: PassMIT
Systematic DebuggingChrisWiles/claude-code-showcase6.1k3 repos~1.2kAutomated safety check: PassNone

Similar skills

  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Bug Finder for daisyUI

    saadeghi/daisyui

    Investigates suspected bugs in the daisyUI monorepo through read-only analysis, then writes a decision-ready fix plan in tmp/bugs without changing any product code.

    43k GitHub stars~2.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Root Cause Debugging

    garrytan/gstack

    Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.

    136k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Graph-Based Bug Tracing

    tirth8205/code-review-graph

    Traces a bug through a code knowledge graph, following callers, callees and execution flow before opening source files, within a small token budget.

    32k GitHub starsUsed in 1 repo~287 tokens
    DevelopmentAuto-check passed
  • Systematic Debugging

    ChrisWiles/claude-code-showcase

    Applies a four-phase debugging routine that finds the root cause of a bug or failing test before any fix is written.

    6.1k GitHub starsUsed in 3 repos~1.2k tokens
    DevelopmentAuto-check passed
  • Debugging and Error Recovery

    addyosmani/agent-skills

    Applies a stop-the-line rule and a step-by-step triage when tests fail, builds break or something stops working, aiming at the root cause instead of guesses.

    104k GitHub starsUsed in 1 repo~2.6k tokens
    DevelopmentAuto-check passed

More from Houseofmvps/ultraship

All 28 skills in this repo
  • Using Ultraship

    Houseofmvps/ultraship

    A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions

    123 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • A11y

    Houseofmvps/ultraship

    Accessibility audit + auto-fix (WCAG 2.2 A/AA). An agent skill from Houseofmvps/ultraship.

    123 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check: notes
  • Architecture

    Houseofmvps/ultraship

    Living Architecture Map — auto-generate Mermaid diagrams of your codebase.

    123 GitHub stars~708 tokensUpdated 3 mo ago
    Auto-check: notes
  • Clone Patterns

    Houseofmvps/ultraship

    Learn From the Best — analyze patterns from any codebase and apply them to yours.

    123 GitHub stars~682 tokensUpdated 3 mo ago
    Auto-check: notes
  • Code Review

    Houseofmvps/ultraship

    Code review with principal-engineer-level depth. An agent skill from Houseofmvps/ultraship.

    123 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Compete

    Houseofmvps/ultraship

    Competitive X-Ray — analyze any competitor URL vs your site.

    123 GitHub stars~1.1k tokensUpdated 3 mo ago
    Auto-check: notes

Categories

Questions about Investigate

What does Investigate do?

Root cause investigation — structured debugging with module freeze. Investigate is an agent skill from Houseofmvps/ultraship. Root cause investigation — structured debugging with module freeze.

When should I use Investigate?

Investigate fits situations like: encountering any bug; unexpected behavior.

How do I install Investigate in Claude Code?

Run `npx skills add Houseofmvps/ultraship --skill investigate -a claude-code`. Or copy the skill folder (skills/investigate in Houseofmvps/ultraship) into .claude/skills/investigate in your project. Claude Code loads it when a task matches its description.

How do I install Investigate in Codex?

Run `npx skills add Houseofmvps/ultraship --skill investigate -a codex`. Or copy the skill folder (skills/investigate in Houseofmvps/ultraship) into .agents/skills/investigate in your project. Codex loads it when a task matches its description.

Can I use Investigate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Houseofmvps/ultraship --skill investigate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/investigate, .gemini/skills/investigate, .github/skills/investigate and .opencode/skills/investigate in your project.

What does Investigate need to run?

Going by SKILL.md and its folder, Investigate needs the command-line tools its instructions call (git and node).

Does Investigate access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Investigate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Investigate use?

Investigate is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Investigate use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Investigate?

Skills that share tags, products or a category with Investigate: OpenLogi macOS Permissions Triage (AprilNEA/OpenLogi, 23k stars), Bug Finder for daisyUI (saadeghi/daisyui, 43k stars), Root Cause Debugging (garrytan/gstack, 136k stars) and Graph-Based Bug Tracing (tirth8205/code-review-graph, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Investigate?

Houseofmvps (a GitHub user) maintains it in Houseofmvps/ultraship, which has 123 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on July 8, 2026.

Source: Houseofmvps/ultraship on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.