Agent skill

Root-Cause Investigation Workflow

by LING71671 in LING71671/Open-ClaudeCode

Diagnoses a bug, crash, regression or flaky behavior by reproducing it and testing several causes before applying the smallest fix.

Custom licenceAuto-check: notesDevelopment

Install Root-Cause Investigation Workflow

skills CLI
$ npx skills add LING71671/Open-ClaudeCode --skill gstack-investigate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LING71671/Open-ClaudeCode gstack-investigate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LING71671/Open-ClaudeCode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/gstack-workflows/skills/gstack-investigate .claude/skills/gstack-investigate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gstack-investigate
GitHub stars
961
Token cost
~322 tokens
SKILL.md length
146 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
Custom licence

At a glance

Diagnoses a bug, crash, regression or flaky behavior by reproducing it and testing several causes before applying the smallest fix.

  • Works in 8 steps: State the observed symptom and the… → Reproduce the issue with the smallest… → Trace the relevant path through the code… → …
  • A command or test fails and the cause is unknown
  • SKILL.md covers Workflow, Rules and Output
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The agent states the observed symptom against the expected behavior, reproduces it with the smallest command, fixture or log slice available, and traces the code path before proposing anything. It then forms at least three plausible causes, tests each with targeted checks, logs or assertions, and picks the one with the strongest evidence.

No fix is applied before reproduction or strong evidence, and fixes stay minimal with no unrelated refactors. If an attempt fails, the agent records why and changes strategy. After the fix it reruns the original reproduction plus one nearby regression check and reports the symptom, root cause, fix, verification step and residual risk. The skill lists Read, Grep, Glob, Bash, Edit and Write as its allowed tools.

When your agent uses it

  • A command or test fails and the cause is unknown
  • Investigating a regression after a recent change
  • Debugging flaky behavior or unexplained output

Example prompts

  • “The nightly import crashes with a null pointer, so find the root cause before changing anything.”
  • “Our login test passes locally but fails now and then in CI; investigate why.”
  • “The export command output changed after yesterday's merge, so work out what caused it.”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, Edit, Write

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. State the observed symptom and the expected behavior.
  2. Reproduce the issue with the smallest command, UI flow, fixture, or log slice available.
  3. Trace the relevant path through the code before proposing a fix.
  4. Form at least three plausible causes.
  5. Test the causes with targeted checks, logs, assertions, or isolated commands.
  6. Pick the cause with the strongest evidence.
  7. Apply the smallest fix that addresses that cause.
  8. Re-run the original reproduction and one nearby regression check.

What it can do on your machine

Read from SKILL.md and the folder at commit 2980105. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • Edit
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Root-Cause Investigation Workflow loads about 322 tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 146 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~322

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, Edit, Write

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 146 words (~322 tokens).

“Use this skill to diagnose before fixing.”

— opening of SKILL.md by LING71671, Custom licence
name
gstack-investigate
allowed-tools
Read, Grep, Glob, Bash, Edit, Write

Read the full SKILL.md on GitHub

Files

Just SKILL.md in plugins/gstack-workflows/skills/gstack-investigate of LING71671/Open-ClaudeCode.

Open the folder on GitHubat commit 2980105

Compare with similar skills

Root-Cause Investigation Workflow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Root-Cause Investigation Workflow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Root-Cause Investigation Workflow this skillLING71671/Open-ClaudeCode961—~322Automated safety check: NotesCustom licence
OpenLogi macOS Permissions TriageAprilNEA/OpenLogi23k—~2.5kAutomated safety check: NotesApache-2.0
Bug Finder for daisyUIsaadeghi/daisyui43k—~2.3kAutomated safety check: PassMIT
Root Cause Debugginggarrytan/gstack136k—~1.4kAutomated safety check: PassMIT
Graph-Based Bug Tracingtirth8205/code-review-graph32k1 repos~287Automated safety check: PassMIT
Systematic DebuggingChrisWiles/claude-code-showcase6.1k3 repos~1.2kAutomated safety check: PassNone

Similar skills

  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated 4 days ago
    DevelopmentAuto-check: notes
  • Bug Finder for daisyUI

    saadeghi/daisyui

    Investigates suspected bugs in the daisyUI monorepo through read-only analysis, then writes a decision-ready fix plan in tmp/bugs without changing any product code.

    43k GitHub stars~2.3k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Root Cause Debugging

    garrytan/gstack

    Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.

    136k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Graph-Based Bug Tracing

    tirth8205/code-review-graph

    Traces a bug through a code knowledge graph, following callers, callees and execution flow before opening source files, within a small token budget.

    32k GitHub starsUsed in 1 repo~287 tokens
    DevelopmentAuto-check passed
  • Systematic Debugging

    ChrisWiles/claude-code-showcase

    Applies a four-phase debugging routine that finds the root cause of a bug or failing test before any fix is written.

    6.1k GitHub starsUsed in 3 repos~1.2k tokens
    DevelopmentAuto-check passed
  • Debugging and Error Recovery

    addyosmani/agent-skills

    Applies a stop-the-line rule and a step-by-step triage when tests fail, builds break or something stops working, aiming at the root cause instead of guesses.

    103k GitHub starsUsed in 1 repo~2.6k tokens
    DevelopmentAuto-check passed

More from LING71671/Open-ClaudeCode

  • Gstack Document Release

    LING71671/Open-ClaudeCode

    Brings project documentation back in line with shipped behavior by reading the current diff for user-visible changes and updating only the docs they affect.

    961 GitHub stars~282 tokensUpdated 2 mo ago
    Auto-check: notes
  • Gstack Cso

    LING71671/Open-ClaudeCode

    Security audit workflow for OPC code, providers, plugins, Electron surfaces, local HTTP bridges, filesystem access, and command execution.

    961 GitHub stars~321 tokensUpdated 2 mo ago
    Auto-check: notes
  • Gstack QA Only

    LING71671/Open-ClaudeCode

    Read-only QA report for an OPC desktop flow, CLI command, local URL, staging URL, or documented user journey.

    961 GitHub stars~282 tokensUpdated 2 mo ago
    Auto-check: notes
  • Gstack Pre-Landing Review

    LING71671/Open-ClaudeCode

    Runs a staff-engineer style review over the current diff before merging, listing findings by severity with file, impact and a suggested fix.

    961 GitHub stars~316 tokensUpdated 2 mo ago
    Auto-check: notes

Categories

Questions about Root-Cause Investigation Workflow

What does Root-Cause Investigation Workflow do?

Diagnoses a bug, crash, regression or flaky behavior by reproducing it and testing several causes before applying the smallest fix. The agent states the observed symptom against the expected behavior, reproduces it with the smallest command, fixture or log slice available, and traces the code path before proposing anything. It then forms at least three plausible causes, tests each with targeted checks, logs or assertions, and picks the one with the strongest evidence.

When should I use Root-Cause Investigation Workflow?

Root-Cause Investigation Workflow fits situations like: A command or test fails and the cause is unknown; investigating a regression after a recent change; debugging flaky behavior or unexplained output.

How do I install Root-Cause Investigation Workflow in Claude Code?

Run `npx skills add LING71671/Open-ClaudeCode --skill gstack-investigate -a claude-code`. Or copy the skill folder (plugins/gstack-workflows/skills/gstack-investigate in LING71671/Open-ClaudeCode) into .claude/skills/gstack-investigate in your project. Claude Code loads it when a task matches its description.

How do I install Root-Cause Investigation Workflow in Codex?

Run `npx skills add LING71671/Open-ClaudeCode --skill gstack-investigate -a codex`. Or copy the skill folder (plugins/gstack-workflows/skills/gstack-investigate in LING71671/Open-ClaudeCode) into .agents/skills/gstack-investigate in your project. Codex loads it when a task matches its description.

Can I use Root-Cause Investigation Workflow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LING71671/Open-ClaudeCode --skill gstack-investigate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gstack-investigate, .gemini/skills/gstack-investigate, .github/skills/gstack-investigate and .opencode/skills/gstack-investigate in your project.

What does Root-Cause Investigation Workflow need to run?

SKILL.md names no scripts, command-line tools or credentials: Root-Cause Investigation Workflow is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Edit, Write.

Does Root-Cause Investigation Workflow access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Root-Cause Investigation Workflow safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Root-Cause Investigation Workflow use?

Root-Cause Investigation Workflow has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Root-Cause Investigation Workflow use?

About 322 tokens (SKILL.md is roughly 1.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Root-Cause Investigation Workflow?

Skills that share tags, products or a category with Root-Cause Investigation Workflow: OpenLogi macOS Permissions Triage (AprilNEA/OpenLogi, 23k stars), Bug Finder for daisyUI (saadeghi/daisyui, 43k stars), Root Cause Debugging (garrytan/gstack, 136k stars) and Graph-Based Bug Tracing (tirth8205/code-review-graph, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Root-Cause Investigation Workflow?

LING71671 (a GitHub user) maintains it in LING71671/Open-ClaudeCode, which has 961 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on July 22, 2026.

Source: LING71671/Open-ClaudeCode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.