Agent skill

Log And Error Bucketing

by mrmps in mrmps/classifier-dev

Turn a stream of log lines or error messages into a histogram of causes — timeouts, auth, quota, bad input, upstream, unknown — by deduplicating to templates, redacting, and classifying one exemplar…

MITAuto-check passed

Install Log And Error Bucketing

skills CLI
$ npx skills add mrmps/classifier-dev --skill log-and-error-bucketing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mrmps/classifier-dev log-and-error-bucketing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mrmps/classifier-dev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/log-and-error-bucketing .claude/skills/log-and-error-bucketing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
log-and-error-bucketing
GitHub stars
424
Token cost
~1.5k tokens
SKILL.md length
574 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

Turn a stream of log lines or error messages into a histogram of causes — timeouts, auth, quota, bad input, upstream, unknown — by deduplicating to templates, redacting, and classifying one exemplar…

  • Works in 4 steps: collapse to templates, keep the counts → name the buckets, then classify → read the shape → …
  • An incident dump
  • SKILL.md covers What leaves the machine, When not to use it, Step 1: collapse to templates,… and Step 2: name the buckets, then…, plus 3 more sections
  • Calls npx

What it does

Log And Error Bucketing is an agent skill from mrmps/classifier-dev. Turn a stream of log lines or error messages into a histogram of causes — timeouts, auth, quota, bad input, upstream, unknown — by deduplicating to templates, redacting, and classifying one exemplar each, so a million lines cost a few hundred calls. Use when an incident dump, CI log or error table is too big to read. Triggers on "what is failing here", "bucket these errors", "group these exceptions", "top causes".

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Zero-shot text classification over plain HTTP — no API key, no account. One Cloudflare Worker, a CLI, and an MCP server. https://classifier.dev. The licence is MIT.

When your agent uses it

  • An incident dump
  • Error table is too big to read
  • What is failing here
  • Bucket these errors

Example prompts

  • “what is failing here”
  • “bucket these errors”
  • “group these exceptions”
  • “/log-and-error-bucketing”

Requirements

  • Python 3
  • Node.js

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. collapse to templates, keep the counts
  2. name the buckets, then classify
  3. read the shape
  4. the gates

What it can do on your machine

Read from SKILL.md and the folder at commit 629df75. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • classifier.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Log And Error Bucketing loads about 1.5k tokens when it runs. Until then it costs about 110 tokens; SKILL.md has 574 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~110
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mrmps/classifier-dev at commit 629df75, republished under its MIT licence (© mrmps). 574 words, ~1,485 tokens.

Download SKILL.mdSave it as .claude/skills/log-and-error-bucketing/SKILL.md (or your agent's skills folder).
name
log-and-error-bucketing
description
Turn a stream of log lines or error messages into a histogram of causes — timeouts, auth, quota, bad input, upstream, unknown — by deduplicating to templates, redacting, and classifying one exemplar each, so a million lines cost a few hundred calls. Use when an incident dump, CI log or error table is too big to read. Triggers on "what is failing here", "bucket these errors", "group these exceptions", "top causes".
license
MIT

Bucket a log stream by cause

A log is mostly the same twenty lines with different numbers in them. Read it by collapsing it to those twenty, labelling each by cause and weighting them by how often they occurred. The labelling step below is classifier.dev: keyless HTTP, your bucket names, a calibrated confidence, no text generated.

What leaves the machine

Log lines carry tokens, emails and account numbers. One redacted line per template goes out, nothing else: no file, no host name, no context.

python
import re
PATTERNS = [(r"(?i)\b(?:bearer|basic)\s+[\w.\-+/=]{8,}", "<CRED>"),
    (r"(?i)\b[\w.-]*(?:key|token|secret|password|pwd)[\w.-]*\s*[=:]\s*[^\s\"',&]{6,}", "<CRED>"),
    (r"\b[A-Za-z0-9+/]{32,}={0,2}\b", "<BLOB>"), (r"\b[0-9a-f]{16,}\b", "<BLOB>"),
    (r"[\w.+-]+@[\w-]+\.[\w.]{2,}", "<EMAIL>"), (r"\b(?:\d[ -]?){13,16}\b", "<CARD>"),
    (r"\b\d{3}-\d{2}-\d{4}\b", "<SSN>"), (r"\b\d{7,}\b", "<NUM>")]

def redact(t):
    for p, tag in PATTERNS:
        t = re.sub(p, tag, t)
    return t

def sendable(t):                      # never send a mostly-redacted line
    kept = len(re.sub(r"<[A-Z]+>", "", redact(t)))
    return kept >= 25 and kept >= 0.5 * len(t)

Two lines through it, classified:

ERROR [api] auth failed: authorization: <CRED> upstream returned 401
   -> authentication or permission denied   1.00
WARN retry: <CRED> quota exhausted for project <NUM>
   -> quota or rate limit exceeded          1.00

The credential and the project id are gone; the cause still reads at 1.00. A line that is mostly placeholders afterwards is one nobody could bucket, so sendable keeps it at home.

When not to use it

If the logs may not leave the building, keep the workflow and change the classifier: the shape is dedupe, label, weight, gate, and anything returning a calibrated confidence fits — your own model over the same bucket names, or a local zero-shot model. classifier.dev is the keyless example because it needs no account; it states that it stores no input text and passes it to the model that answers (https://classifier.dev/privacy).

Skip it as well for logs that already carry an error code (group by the code, free and exact), for triage you can read in a second, and for finding one rare line: this counts what is common.

Step 1: collapse to templates, keep the counts

python
import collections
def norm(line):
    s = re.sub(r"\b\d{1,3}(\.\d{1,3}){3}(:\d+)?", "<ip>", line)
    s = re.sub(r"\b[0-9a-f]{8,}\b", "<hex>", s)
    s = re.sub(r"\b(Mon|Tue|Wed|Thu|Fri|Sat|Sun)\b", "<day>", s)
    return " ".join(re.sub(r"\d+", "<n>", s).split())

groups = collections.OrderedDict()
for line in lines:                    # ERROR and WARN only
    groups.setdefault(norm(line), []).append(line)
exemplars = [redact(v[0]) for v in groups.values() if sendable(v[0])]

Send the first real line of each group, redacted, not the masked template: <n> and <ip> read less like language than the line they came from.

On 1,926 error and warning lines from the public loghub samples (ZooKeeper, OpenStack, Apache) this gave 21 templates: one classification per 92 lines. The weekday mask earns its place — without it the same Apache error from a Sunday and a Monday are two templates, and the list is 25.

Show full SKILL.md (258 more words)Show less

Step 2: name the buckets, then classify

POST the exemplars as inputs, your bucket names as labels, the sentence below as instructions; 21 templates came back in 268 ms. The CLI does it too, fetched at a pinned version and left uninstalled:

L='timed out waiting for something,authentication or permission denied,quota or rate limit exceeded,bad or malformed input from the caller,an upstream or dependent service failed,resource exhausted: memory disk or connections,unknown or other'
npx --yes classifier-dev@0.1.3 "$L" -i "Bucket the log line by the underlying cause of the failure it reports." --count < redacted.txt

That is one vote per template: 17 of the 21 landed in unknown or other. CLI labels are comma-separated, so no label may contain a comma.

Step 3: read the shape

Weighted by group size, those seven buckets put 1,805 of the 1,926 lines in unknown or other, mostly at 0.4 to 0.7 confidence. That is not a broken model: a fat unknown bucket at middling confidence means your labels are missing a cause. These lines were peer churn and worker lifecycle. Add two labels, rerun the same 21:

   1138  a worker or child process started, exited or restarted
    711  a network connection to a peer dropped or was reset
     41  unknown or other
     32  authentication or permission denied
      3  an upstream or dependent service failed

unknown fell from 1,805 lines to 41, in 254 ms. Four of the 21 templates are still under 0.5: read those yourself.

Step 4: the gates

  • 0.9 and above — file the template under that cause.
  • 0.5 to 0.9 — file it, but show the exemplar in the report, or re-ask on --smart ("tier": "smart").
  • below 0.5 — leave it in unknown; --review 0.5 prints those rows.
  • confidence: null with an unscored reason — no comparable provider score is available, so leave the row for review. Scores do not validate the input: include noise or separator and unknown or other when those inputs are possible.

Done looks like

A table of causes with line counts, each traceable to a template and a redacted line; the sub-0.5 and unscored rows listed apart.

© mrmps, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/log-and-error-bucketing of mrmps/classifier-dev.

Open the folder on GitHubat commit 629df75

Compare with similar skills

Log And Error Bucketing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Log And Error Bucketing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Log And Error Bucketing this skillmrmps/classifier-dev424—~1.5kAutomated safety check: PassMIT
Messages Opsaffaan-m/ECC276k1 repos~724Automated safety check: PassMIT
AWS Messaging And Streamingaws/agent-toolkit-for-aws2.8k—~3.1kAutomated safety check: PassApache-2.0
Investigating LogsPostHog/posthog40k—~2.1kAutomated safety check: PassCustom licence
Logging and Error Reporting for Warpwarpdotdev/warp65k1 repos~5.6kAutomated safety check: PassAGPL-3.0
Growth Logaffaan-m/ECC276k1 repos~1.7kAutomated safety check: PassMIT

Similar skills

  • Messages Ops

    affaan-m/ECC

    Evidence-first live messaging workflow for ECC. An agent skill from affaan-m/ECC.

    276k GitHub starsUsed in 1 repo~724 tokens
    Productivity & AutomationAuto-check passed
  • AWS Messaging And Streaming

    aws/agent-toolkit-for-aws

    Official

    Guides general use of AWS messaging and streaming services. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Investigating Logs

    PostHog/posthog

    Official

    Investigate logs in a PostHog project: verify a service or deployment is healthy, explain an error spike, triage an incident, or understand what a log stream is saying.

    40k GitHub stars~2.1k tokensUpdated today
    DatabasesAuto-check passed
  • Guides log level choices and when to raise a structured Sentry event instead of a plain log line in the Warp Rust codebase, keeping secrets out of logs.

    65k GitHub starsUsed in 1 repo~5.6k tokens
    DevelopmentAuto-check passed
  • Growth Log

    affaan-m/ECC

    Write growth log entries that extract reusable patterns from completed work — root cause, transferable rule, and a recognizable signal — instead of diary-style event narration, with a 4-8 sentence…

    276k GitHub starsUsed in 1 repo~1.7k tokens
    DevelopmentAuto-check passed
  • Clickhouse Logs Queries

    supabase/supabase

    Official

    Write, review, and migrate Supabase logs queries against the ClickHouse-backed logs table (the logs.all.otel analytics endpoint).

    111k GitHub stars~2.4k tokensUpdated today
    DatabasesAuto-check passed

More from mrmps/classifier-dev

All 21 skills in this repo
  • Bulk Classify

    mrmps/classifier-dev

    Sort many texts into your own categories without reading them, using a keyless HTTP API that returns a calibrated confidence per answer.

    424 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Computer Use Action Picker

    mrmps/classifier-dev

    Pick a browser or desktop agent's next action by choosing among the actions actually on screen instead of inventing one.

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Content Moderation Gate

    mrmps/classifier-dev

    Check user-generated text against a written policy before it is published.

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Label each context chunk keep, drop or replace-with-a-pointer and pass the survivors through byte for byte instead of summarising, with key-shaped chunks decided locally and never sent, and a…

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Document Intake Routing

    mrmps/classifier-dev

    Label each page of an intake packet with a document type and a page role before extraction runs, so only confident pages reach an extractor and the rest reach a person.

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Headline Filter Map Reduce

    mrmps/classifier-dev

    Filter hundreds or thousands of headlines, search results or feed items against a written brief before opening any of them, using a two-stage cascade that spends a fast model on everything and a…

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed

Questions about Log And Error Bucketing

What does Log And Error Bucketing do?

Turn a stream of log lines or error messages into a histogram of causes — timeouts, auth, quota, bad input, upstream, unknown — by deduplicating to templates, redacting, and classifying one exemplar…. Log And Error Bucketing is an agent skill from mrmps/classifier-dev. Turn a stream of log lines or error messages into a histogram of causes — timeouts, auth, quota, bad input, upstream, unknown — by deduplicating to templates, redacting, and classifying one exemplar each, so a million lines cost a few hundred calls.

When should I use Log And Error Bucketing?

Log And Error Bucketing fits situations like: an incident dump; error table is too big to read; what is failing here; bucket these errors.

How do I install Log And Error Bucketing in Claude Code?

Run `npx skills add mrmps/classifier-dev --skill log-and-error-bucketing -a claude-code`. Or copy the skill folder (skills/log-and-error-bucketing in mrmps/classifier-dev) into .claude/skills/log-and-error-bucketing in your project. Claude Code loads it when a task matches its description.

How do I install Log And Error Bucketing in Codex?

Run `npx skills add mrmps/classifier-dev --skill log-and-error-bucketing -a codex`. Or copy the skill folder (skills/log-and-error-bucketing in mrmps/classifier-dev) into .agents/skills/log-and-error-bucketing in your project. Codex loads it when a task matches its description.

Can I use Log And Error Bucketing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mrmps/classifier-dev --skill log-and-error-bucketing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/log-and-error-bucketing, .gemini/skills/log-and-error-bucketing, .github/skills/log-and-error-bucketing and .opencode/skills/log-and-error-bucketing in your project.

What does Log And Error Bucketing need to run?

Going by SKILL.md and its folder, Log And Error Bucketing needs the command-line tools its instructions call (npx). Our summary lists: Python 3; Node.js.

Does Log And Error Bucketing access the network?

SKILL.md names 1 domain. As links in the text: classifier.dev. This is read from the text; nothing was executed.

Is Log And Error Bucketing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Log And Error Bucketing use?

Log And Error Bucketing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Log And Error Bucketing use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Log And Error Bucketing?

Skills that share tags, products or a category with Log And Error Bucketing: Messages Ops (affaan-m/ECC, 276k stars), AWS Messaging And Streaming (aws/agent-toolkit-for-aws, 2.8k stars), Investigating Logs (PostHog/posthog, 40k stars) and Logging and Error Reporting for Warp (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Log And Error Bucketing?

mrmps (a GitHub user) maintains it in mrmps/classifier-dev, which has 424 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.

Source: mrmps/classifier-dev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.