Agent skill

Linux Troubleshooting with Inspektor Gadget

by inspektor-gadget in inspektor-gadget/inspektor-gadget

Debugs a single Linux host or container runtime at the kernel level with the standalone ig binary and eBPF gadgets, read-only and without Kubernetes.

Apache-2.0Auto-check: notesDevOps & Cloud

Install Linux Troubleshooting with Inspektor Gadget

skills CLI
$ npx skills add inspektor-gadget/inspektor-gadget --skill linux-troubleshooting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install inspektor-gadget/inspektor-gadget linux-troubleshooting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/inspektor-gadget/inspektor-gadget.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/linux-troubleshooting .claude/skills/linux-troubleshooting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
linux-troubleshooting
GitHub stars
2.9k
Token cost
~2.4k tokens
SKILL.md length
889 words
Files
6 (incl. references)
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Debugs a single Linux host or container runtime at the kernel level with the standalone ig binary and eBPF gadgets, read-only and without Kubernetes.

  • Works in 4 steps: Route. Map the symptom to a domain… → Discover. Run :latest --help to read the… → Run bounded. Scope and time-box → …
  • Tracing DNS or TCP failures on a host where application logs show nothing
  • SKILL.md covers Prerequisite: confirm IG is…, The one rule: discover, don't…, The loop (repeat until root… and Symptom → first gadget…, plus 2 more sections
  • Calls kubectl and jq

What it does

The ig binary runs the same eBPF gadgets as Inspektor Gadget's Kubernetes integration, but against one machine and its local container runtime (Docker, containerd, CRI-O or podman). It suits VMs, edge nodes and CI runners where logs fall short: DNS or TCP failures, resets and retransmits, processes exiting or being killed, failed file opens, permission, capability, seccomp or LSM denials, slow disk I/O, and questions like which process made a syscall or connection. Events carry the container name and runtime, and --host adds non-container processes.

The central rule is to discover rather than guess: each gadget is an OCI image pulled on demand, so the agent reads its --help and field list instead of recalling flags. The loop is to route the symptom to a domain (networking, security, process lifecycle, storage or performance), discover the gadget's options, run it bounded with a timeout and filters by container, command or pid, and repeat until the root cause shows. It needs ig on PATH, root and a BTF-enabled kernel, and asks the operator before installing on a host that is not yours. Kubernetes clusters go to kubernetes-troubleshooting.

When your agent uses it

  • Tracing DNS or TCP failures on a host where application logs show nothing
  • Finding which process opened a missing file or was killed by the kernel
  • Diagnosing permission, capability or seccomp denials in a container
  • Investigating slow disk or file I/O on a CI runner or edge node

Example prompts

  • “DNS lookups from this CI runner keep failing; trace them with ig.”
  • “Find out which process is killing my container and whether it is an OOM kill.”
  • “Which process tries to open /etc/app/config.yaml and gets ENOENT?”
  • “Trace TCP retransmits on this VM for ten seconds and tell me who is affected.”

Requirements

  • The standalone ig binary on PATH
  • Root access (CAP_BPF and CAP_SYS_ADMIN)
  • A BTF-enabled Linux kernel
  • Compatibility (from SKILL.md): Requires the standalone `ig` binary on PATH, run as root (CAP_BPF + CAP_SYS_ADMIN), on a BTF-enabled kernel (`/sys/kernel/btf/vmlinux`) for CO-RE. An optional container runtime (containerd/Docker/CRI-O/podman) enriches events; `--host` traces bare-host processes. Read-only. If `ig` is missing, see references/install.md — ask the operator before installing.

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Route. Map the symptom to a domain (networking / security /
  2. Discover. Run :latest --help to read the real flags and fields.
  3. Run bounded. Scope and time-box
  4. Read the columns. Inspect the fields (runtime.*, proc.*, error codes)

What it can do on your machine

Read from SKILL.md and the folder at commit 1f292a7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the standalone `ig` binary on PATH, run as root (CAP_BPF + CAP_SYS_ADMIN), on a BTF-enabled kernel (`/sys/kernel/btf/vmlinux`) for CO-RE. An optional container runtime (containerd/Docker/CRI-O/podman) enriches events; `--host` traces bare-host processes. Read-only. If `ig` is missing, see references/install.md — ask the operator before installing.

    From compatibility in the SKILL.md frontmatter.

Context cost

Linux Troubleshooting with Inspektor Gadget loads about 2.4k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 200 tokens; SKILL.md has 889 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~200
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:27
    I runners, or any box where you can run `sudo ig`. Events are
  • NoteRuns commands with sudoSKILL.md:53
    sudo ig run <gadget>:latest --help       # flags + a "--fields" block listing every data source & field
  • NoteRuns commands with sudoSKILL.md:54
    sudo ig run <gadget>:latest --timeout 5 -o json \
  • NoteRuns commands with sudoSKILL.md:69
    `sudo ig run <gadget>:latest --runtimes containerd -c <name> --timeout <sec> -o json`
  • NoteRuns commands with sudoSKILL.md:127
    e-host skill, swap `kubectl gadget run`→`sudo ig run` and `-n`/`-p`→

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from inspektor-gadget/inspektor-gadget at commit 1f292a7, republished under its Apache-2.0 licence (© inspektor-gadget). 889 words, ~2,359 tokens.

Download SKILL.mdSave it as .claude/skills/linux-troubleshooting/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
linux-troubleshooting
description
Debug a single Linux host, VM, or container runtime at the kernel level with Inspektor Gadget via the standalone `ig` binary — no Kubernetes required. Use when something on a bare host, edge node, CI runner, or Docker/containerd/CRI-O box is failing and logs aren't enough: DNS or TCP failures, connection resets / retransmits / drops, processes exiting or being killed (OOM/signal), failed or missing file opens, permission / capability / seccomp / LSM denials, slow disk or file I/O, or "which process made this syscall / connection". Traces real kernel events with eBPF; enriches with container name/runtime when a runtime is present. Read-only. Not for Kubernetes clusters (use kubernetes-troubleshooting for `kubectl gadget`), plain application logs, or metrics dashboards.
compatibility
Requires the standalone `ig` binary on PATH, run as root (CAP_BPF + CAP_SYS_ADMIN), on a BTF-enabled kernel (`/sys/kernel/btf/vmlinux`) for CO-RE. An optional container runtime (containerd/Docker/CRI-O/podman) enriches events; `--host` traces bare-host processes. Read-only. If `ig` is missing, see references/install.md — ask the operator before installing.

Linux host / container-runtime troubleshooting with Inspektor Gadget

The standalone ig binary runs the same eBPF gadgets as the Kubernetes integration, but against a single Linux host and its local container runtime (Docker / containerd / CRI-O / podman) — no cluster, no kubectl. Use it on VMs, edge nodes, CI runners, or any box where you can run sudo ig. Events are enriched with container name + runtime (not pod/namespace) when a runtime is present; with --host you also see host (non-container) processes.

Reach for ig when host logs/metrics can't answer "what is the kernel doing right now?" — a syscall failing silently, a connection reset before the app notices, a file open returning ENOENT.

Prerequisite: confirm IG is available (check first, then route)

This skill drives the standalone ig binary. Confirm it's usable before the loop:

bash
command -v ig >/dev/null 2>&1 && ig version || echo "ig MISSING -> references/install.md"

If ig is missing, open references/install.md and follow it — don't guess an install command. ig needs root (CAP_BPF / CAP_SYS_ADMIN) and a BTF-enabled kernel; ask the operator before installing on a host you don't own.

The one rule: discover, don't guess

Never hardcode a gadget's flags or field names from memory. Enumerate the real interface at run time:

bash
sudo ig run <gadget>:latest --help       # flags + a "--fields" block listing every data source & field
sudo ig run <gadget>:latest --timeout 5 -o json \
  | jq -s '(.[0] // {}) | if type == "array" then (.[0] // {}) else . end | keys'

Each gadget is an OCI image pulled on demand; there is no list-gadgets command and no fixed list to memorize. The gadget's own --help/--fields is the source of truth. See references/discovering-params-and-fields.md.

The loop (repeat until root cause)

  1. Route. Map the symptom to a domain (networking / security / process-lifecycle / storage-fs / performance) and a candidate gadget using the table below + references/gadget-catalog.md.
  2. Discover. Run <gadget>:latest --help to read the real flags and fields.
  3. Run bounded. Scope and time-box: sudo ig run <gadget>:latest --runtimes containerd -c <name> --timeout <sec> -o json (-c filters by container, --comm/--pid by process; add --host for host processes; always set --timeout; --max-entries for top/snapshot). See references/common-flags.md.
  4. Read the columns. Inspect the fields (runtime.*, proc.*, error codes) to confirm or refute, then narrow and repeat.

Symptom → first gadget (confirm flags/fields with --help)

SymptomDomainStart withThen / disambiguate
DNS fails / slow / NXDOMAINnetworkingtrace_dnslatency in latency_ns
Connection reset / refused / hangsnetworkingtrace_tcptrace_tcpretrans, trace_tcpdrop
Packet loss / high latencynetworkingtrace_tcpdropprofile_tcprtt, top_tcp, tcpdump
TLS/cert/SNI issuenetworkingtrace_snitrace_ssl
Port bind fails / "address already in use"networkingsnapshot_sockettrace_bind (bind + errno)
Process exits / restarts unexpectedlyprocess-lifecycletrace_exectrace_signal (filter --signal 9/15 — Go SIGURG / glibc SIGRTMIN async-preempt noise), trace_oomkill
Process killed / OOMprocess-lifecycletrace_oomkilltop_process, profile_cpu
Container died too fast to trace live (post-mortem)process-lifecycletraceloopreplays recent syscalls from the ring buffer; empty if it wasn't already recording
Watch an interactive shell / tty / pts / keystrokesprocess-lifecyclettysnoopno --tty/--pts selector — scope by --pid/--comm/container
"no such file" / missing pathstorage-fstrace_open --failedsnapshot_file, top_file
Slow disk / file I/Ostorage-fstrace_fsslowerprofile_blockio, top_blockio
Unexpected mount/umount, or suspicious hardlink/symlink (escape)storage-fstrace_mounttrace_link (type = HARDLINK/SYMLINK cuts the noise)
fd leak / "too many open files" / inotify watch stormstorage-fsfdpassfsnotify; snapshot_file (unclosed fds in one proc)
Permission denied despite correct FS permssecuritytrace_capabilitiesaudit_seccomp; host audit logs for AppArmor/SELinux
Seccomp denialsecurityaudit_seccompthe code + syscall identify the seccomp action; advise_seccomp to author a profile
AppArmor/SELinux denialsecurityhost audit logstrace_lsm can correlate hook activity, but does not expose another LSM's verdict
Kernel module loaded / rootkit / unexpected insmodsecuritytrace_init_moduletrace_capabilities (CAP_SYS_MODULE)
Harden / author a seccomp or NetworkPolicy profilesecurityadvise_seccompadvise_networkpolicy
High CPU, or slow despite low CPU% (CFS throttling / cgroup CPU limit)performanceprofile_cputop_cpu_throttle (capped?), top_process
Memory growth / leak (userspace)performancetrace_malloc (libc malloc only — statically-linked Go runtime allocator invisible)trace_malloc --collect-ustack (the leak site)
App hung / mutex deadlockperformancedeadlock (pthread only — Go sync.Mutex invisible)profile_cpu
GPU / CUDA out-of-memoryperformancetop_cuda_memorydevice vs pinned; profile_cuda = libcuda Driver-API
Quantify eBPF/gadget CPU or memory overhead (self-profiling)metabpfstatsneeds an active window — longer --timeout
Show full SKILL.md (263 more words)Show less

This is a deliberately thin shortlist, not the catalog — it names the few gadgets that fit the most common symptoms so you don't scan the full bundled set, keeping this always-loaded router small. Symptom not listed, or unsure which row fits? Read references/gadget-catalog.md — it groups all bundled gadgets by domain with the disambiguation reasoning (which of the TCP/file/TLS/CPU gadgets to pick). The authoritative live list is whatever sudo ig run <name>:latest --help resolves; confirm a gadget's flags/fields there before relying on them.

References (load only the one you need)

  • references/gadget-catalog.md — all upstream gadgets grouped by domain, with per-domain disambiguation.
  • references/discovering-params-and-fields.md — discover-don't-guess mechanics (ig variant).
  • references/common-flags.md — host/container scope, output, timeouts, gotchas.
  • references/install.md — detect whether ig is usable; install it + requirements (root, BTF) if missing.
  • references/kubernetes-companion.md — when to switch to kubectl gadget (clusters).
Per-domain deep-dive playbooks (shared with the k8s skill)

The five per-domain playbooks (networking, security, process-lifecycle, storage-fs, performance) live in the kubernetes-troubleshooting skill's references/ tree and apply verbatim here — the gadgets, flags, and fields are identical; only the launcher and scope flags differ. To use one from this single-host skill, swap kubectl gadget run→sudo ig run and -n/-p→ -c/--host (full mapping in references/kubernetes-companion.md):

  • ../kubernetes-troubleshooting/references/domain-networking.md — DNS / TCP / drops / retransmits / TLS-SNI / pcap / NetworkPolicy.
  • ../kubernetes-troubleshooting/references/domain-security.md — capabilities / LSM / seccomp / kernel-module loading.
  • ../kubernetes-troubleshooting/references/domain-process-lifecycle.md — exec / signals / OOM / snapshots / traceloop / tty.
  • ../kubernetes-troubleshooting/references/domain-storage-fs.md — open / slow FS / block I/O / mounts / links / fd / fsnotify.
  • ../kubernetes-troubleshooting/references/domain-performance.md — CPU / throttle / RTT / deadlock / malloc / GPU.

Safety

Observation is read-only — gadgets never modify the host or containers. ig needs elevated privileges (typically sudo, CAP_BPF/CAP_SYS_ADMIN) to load eBPF. Always bound streaming gadgets with --timeout and cap top/snapshot with --max-entries.

© inspektor-gadget, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/linux-troubleshooting of inspektor-gadget/inspektor-gadget.

  • SKILL.md
  • references/common-flags.md
  • references/discovering-params-and-fields.md
  • references/gadget-catalog.md
  • references/install.md
  • references/kubernetes-companion.md

Open the folder on GitHubat commit 1f292a7

Compare with similar skills

Linux Troubleshooting with Inspektor Gadget next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Linux Troubleshooting with Inspektor Gadget compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Linux Troubleshooting with Inspektor Gadget this skillinspektor-gadget/inspektor-gadget2.9k—~2.4kAutomated safety check: NotesApache-2.0
.NET Crash Dump Collectiondotnet/skills5.6k2 repos~1.1kAutomated safety check: PassMIT
Minimegasandia-minimega/minimega160—~3.2kAutomated safety check: PassGPL-3.0-only
Setup Cpu Proxy Serverdrawthingsai/draw-things-community582—~3.8kAutomated safety check: PassGPL-3.0
Podmansickn33/agentic-awesome-skills47k1 repos~2.2kAutomated safety check: NotesMIT
Sshepherdsickn33/agentic-awesome-skills47k1 repos~1.6kAutomated safety check: WarnMIT

Similar skills

  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Minimega

    sandia-minimega/minimega

    This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…

    160 GitHub stars~3.2k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Setup Cpu Proxy Server

    drawthingsai/draw-things-community

    Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.

    582 GitHub stars~3.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Podman

    sickn33/agentic-awesome-skills

    Manage containers using Podman, the daemonless container engine.

    47k GitHub starsUsed in 1 repo~2.2k tokens
    DevOps & CloudAuto-check: notes
  • Sshepherd

    sickn33/agentic-awesome-skills

    Zero-knowledge SSH ops CLI — server health checks, docker/systemd control, log tailing, Postgres introspection, and declarative deploys, without ever exposing credentials to the agent.

    47k GitHub starsUsed in 1 repo~1.6k tokens
    DevOps & CloudAuto-check: warnings
  • Podman

    BagelHole/DevOps-Security-Agent-Skills

    Manage containers using Podman, the daemonless container engine.

    1.1k GitHub stars~1.9k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes

More from inspektor-gadget/inspektor-gadget

  • Kubernetes Troubleshooting with Inspektor Gadget

    inspektor-gadget/inspektor-gadget

    Traces what the kernel is doing for a misbehaving pod using Inspektor Gadget's eBPF tools, tagged with namespace, pod, container and node, without changing workloads.

    2.9k GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Linux Troubleshooting with Inspektor Gadget

What does Linux Troubleshooting with Inspektor Gadget do?

Debugs a single Linux host or container runtime at the kernel level with the standalone ig binary and eBPF gadgets, read-only and without Kubernetes. The ig binary runs the same eBPF gadgets as Inspektor Gadget's Kubernetes integration, but against one machine and its local container runtime (Docker, containerd, CRI-O or podman). It suits VMs, edge nodes and CI runners where logs fall short: DNS or TCP failures, resets and retransmits, processes exiting or being killed, failed file opens, permission, capability, seccomp or LSM denials, slow disk I/O, and questions like which process made a syscall or connection.

When should I use Linux Troubleshooting with Inspektor Gadget?

Linux Troubleshooting with Inspektor Gadget fits situations like: tracing DNS or TCP failures on a host where application logs show nothing; finding which process opened a missing file or was killed by the kernel; diagnosing permission, capability or seccomp denials in a container; investigating slow disk or file I/O on a CI runner or edge node.

How do I install Linux Troubleshooting with Inspektor Gadget in Claude Code?

Run `npx skills add inspektor-gadget/inspektor-gadget --skill linux-troubleshooting -a claude-code`. Or copy the skill folder (skills/linux-troubleshooting in inspektor-gadget/inspektor-gadget) into .claude/skills/linux-troubleshooting in your project. Claude Code loads it when a task matches its description.

How do I install Linux Troubleshooting with Inspektor Gadget in Codex?

Run `npx skills add inspektor-gadget/inspektor-gadget --skill linux-troubleshooting -a codex`. Or copy the skill folder (skills/linux-troubleshooting in inspektor-gadget/inspektor-gadget) into .agents/skills/linux-troubleshooting in your project. Codex loads it when a task matches its description.

Can I use Linux Troubleshooting with Inspektor Gadget in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add inspektor-gadget/inspektor-gadget --skill linux-troubleshooting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/linux-troubleshooting, .gemini/skills/linux-troubleshooting, .github/skills/linux-troubleshooting and .opencode/skills/linux-troubleshooting in your project.

What does Linux Troubleshooting with Inspektor Gadget need to run?

Going by SKILL.md and its folder, Linux Troubleshooting with Inspektor Gadget needs the command-line tools its instructions call (kubectl and jq). Our summary lists: The standalone ig binary on PATH; Root access (CAP_BPF and CAP_SYS_ADMIN); A BTF-enabled Linux kernel. Compatibility (from SKILL.md): Requires the standalone `ig` binary on PATH, run as root (CAP_BPF + CAP_SYS_ADMIN), on a BTF-enabled kernel (`/sys/kernel/btf/vmlinux`) for CO-RE. An optional container runtime (containerd/Docker/CRI-O/podman) enriches events; `--host` traces bare-host processes. Read-only. If `ig` is missing, see references/install.md — ask the operator before installing..

Does Linux Troubleshooting with Inspektor Gadget access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Linux Troubleshooting with Inspektor Gadget safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Linux Troubleshooting with Inspektor Gadget use?

Linux Troubleshooting with Inspektor Gadget is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Linux Troubleshooting with Inspektor Gadget use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.5k tokens, read only when the agent opens those files.

What are the alternatives to Linux Troubleshooting with Inspektor Gadget?

Skills that share tags, products or a category with Linux Troubleshooting with Inspektor Gadget: .NET Crash Dump Collection (dotnet/skills, 5.6k stars), Minimega (sandia-minimega/minimega, 160 stars), Setup Cpu Proxy Server (drawthingsai/draw-things-community, 582 stars) and Podman (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Linux Troubleshooting with Inspektor Gadget?

inspektor-gadget (a GitHub organization) maintains it in inspektor-gadget/inspektor-gadget, which has 2,936 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 9, 2026.

Source: inspektor-gadget/inspektor-gadget on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.