Agent skill

Investigate First

by JuliusBrussee in JuliusBrussee/caveman

“Diagnose ambiguous failures before editing. Use for unknown causes, intermittent behavior, performance regressions, or investigations needing evidence-ranked hypotheses.”

— description from SKILL.md by JuliusBrussee
Apache-2.0Auto-check passedDevelopment

Install Investigate First

skills CLI
$ npx skills add JuliusBrussee/caveman --skill investigate-first -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install JuliusBrussee/caveman investigate-first --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/JuliusBrussee/caveman.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/investigate-first .claude/skills/investigate-first && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
investigate-first
GitHub stars
111k
Used in
1 other repo
Token cost
~172 tokens
SKILL.md length
63 words
Files
2
Skills in repo
18
Repo updated
First seen
Licence
Apache-2.0

At a glance

  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

About this skill

Investigate First is a skill in JuliusBrussee/caveman (111k stars). Its SKILL.md is about 172 tokens, with 1 other file in the folder, and copies of it appear in 1 other owners' repositories. Licence: Apache-2.0.

What it can do on your machine

Read from SKILL.md and the folder at commit 2e08b91. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Investigate First loads about 172 tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 63 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~172

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from JuliusBrussee/caveman at commit 2e08b91, republished under its Apache-2.0 licence (© JuliusBrussee). 63 words, ~172 tokens.

Download SKILL.mdSave it as .claude/skills/investigate-first/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
investigate-first
description
Diagnose ambiguous failures before editing. Use for unknown causes, intermittent behavior, performance regressions, or investigations needing evidence-ranked hypotheses.

Investigate first

Gather evidence before changing product code.

  • Separate observed symptom from inferred cause.
  • Trace inputs, state transitions, ownership boundaries, and failure output.
  • Rank hypotheses by evidence and cheap falsification value.
  • Do not edit until one credible mechanism explains evidence.
  • Stop exploration when evidence is sufficient to name cause or exact blocker.

Report cause and proof. Make no fix unless task authorizes implementation.

© JuliusBrussee, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/investigate-first of JuliusBrussee/caveman.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 2e08b91

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in JuliusBrussee/caveman, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Investigate First next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Investigate First compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Investigate First this skillJuliusBrussee/caveman111k1 repos~172Automated safety check: PassApache-2.0
OpenLogi macOS Permissions TriageAprilNEA/OpenLogi23k—~2.5kAutomated safety check: NotesApache-2.0
Bug Finder for daisyUIsaadeghi/daisyui43k—~2.3kAutomated safety check: PassMIT
Root Cause Debugginggarrytan/gstack136k—~1.4kAutomated safety check: PassMIT
Graph-Based Bug Tracingtirth8205/code-review-graph32k1 repos~287Automated safety check: PassMIT
Systematic DebuggingChrisWiles/claude-code-showcase6.1k3 repos~1.2kAutomated safety check: PassNone

Similar skills

  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Bug Finder for daisyUI

    saadeghi/daisyui

    Investigates suspected bugs in the daisyUI monorepo through read-only analysis, then writes a decision-ready fix plan in tmp/bugs without changing any product code.

    43k GitHub stars~2.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Root Cause Debugging

    garrytan/gstack

    Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.

    136k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Graph-Based Bug Tracing

    tirth8205/code-review-graph

    Traces a bug through a code knowledge graph, following callers, callees and execution flow before opening source files, within a small token budget.

    32k GitHub starsUsed in 1 repo~287 tokens
    DevelopmentAuto-check passed
  • Systematic Debugging

    ChrisWiles/claude-code-showcase

    Applies a four-phase debugging routine that finds the root cause of a bug or failing test before any fix is written.

    6.1k GitHub starsUsed in 3 repos~1.2k tokens
    DevelopmentAuto-check passed
  • Debugging and Error Recovery

    addyosmani/agent-skills

    Applies a stop-the-line rule and a step-by-step triage when tests fail, builds break or something stops working, aiming at the root cause instead of guesses.

    105k GitHub starsUsed in 1 repo~2.6k tokens
    DevelopmentAuto-check passed

More from JuliusBrussee/caveman

All 18 skills in this repo
  • Caveman Workflow Labeler

    JuliusBrussee/caveman

    Finds every LLM workflow in a repository, proposes a labeling table and, once you agree, wires labels so Caveman Cloud groups spend per workflow.

    111k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Caveman Evidence Review

    JuliusBrussee/caveman

    Read-only review of Caveman Cloud data to explain where LLM spend goes: cost, score, workflows, traces, latency, errors, routing and verified savings.

    111k GitHub starsUsed in 1 repo~927 tokens
    Auto-check passed
  • Caveman Experiment Manager

    JuliusBrussee/caveman

    Reads the state and results of Caveman Cloud experiments and reports one recommendation or a block, without changing an experiment's lifecycle itself.

    111k GitHub starsUsed in 1 repo~975 tokens
    Auto-check passed
  • Caveman Optimization Evaluator

    JuliusBrussee/caveman

    Turns a Caveman report-only optimization observation into one minimal code change and a paired baseline evaluation, after the operator picks which to pursue.

    111k GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Caveman Gateway Setup

    JuliusBrussee/caveman

    Routes every LLM call in a repository through the Caveman Cloud gateway in record mode, so requests and costs are measured without changing behavior.

    111k GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check: warnings
  • Caveman Help Card

    JuliusBrussee/caveman

    Quick-reference card for the three caveman skills and their commands. Trigger: /caveman-help or "caveman help".

    111k GitHub stars~690 tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Investigate First

How do I install Investigate First in Claude Code?

Run `npx skills add JuliusBrussee/caveman --skill investigate-first -a claude-code`. Or copy the skill folder (skills/investigate-first in JuliusBrussee/caveman) into .claude/skills/investigate-first in your project. Claude Code loads it when a task matches its description.

How do I install Investigate First in Codex?

Run `npx skills add JuliusBrussee/caveman --skill investigate-first -a codex`. Or copy the skill folder (skills/investigate-first in JuliusBrussee/caveman) into .agents/skills/investigate-first in your project. Codex loads it when a task matches its description.

Can I use Investigate First in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add JuliusBrussee/caveman --skill investigate-first -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/investigate-first, .gemini/skills/investigate-first, .github/skills/investigate-first and .opencode/skills/investigate-first in your project.

What does Investigate First need to run?

SKILL.md names no scripts, command-line tools or credentials: Investigate First is instructions for the agent only.

Does Investigate First access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Investigate First safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Investigate First use?

Investigate First is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Investigate First use?

About 172 tokens (SKILL.md is roughly 688 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Investigate First?

Skills that share tags, products or a category with Investigate First: OpenLogi macOS Permissions Triage (AprilNEA/OpenLogi, 23k stars), Bug Finder for daisyUI (saadeghi/daisyui, 43k stars), Root Cause Debugging (garrytan/gstack, 136k stars) and Graph-Based Bug Tracing (tirth8205/code-review-graph, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Investigate First?

JuliusBrussee (a GitHub user) maintains it in JuliusBrussee/caveman, which has 110,815 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 9, 2026.

Source: JuliusBrussee/caveman on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.