When application logs cannot explain a failure, this skill drives `kubectl gadget run` to watch live kernel events such as syscalls, network packets, DNS lookups, capability checks and OOM kills. Each event is labeled with its Kubernetes namespace, pod, container and node, so a symptom like a silently failing file open or a reset connection can be traced to the workload behind it. Everything it does is read-only.
The agent first checks that the gadget plugin and the in-cluster agent are present and, if not, follows the install reference and asks the operator before deploying a privileged DaemonSet. It never relies on remembered flags: each gadget's own help output is read at run time. Symptoms are routed to a domain (networking, security, process lifecycle, storage and filesystem, or performance), then to a candidate gadget, run in a bounded and scoped way and repeated until the root cause shows up. Reference files cover each domain, a gadget catalog and common flags.