Agent skill

Query Netdata Agents

by netdata in netdata/netdata

Query or explain direct Netdata Agent APIs and Functions; review direct-query recipes or helpers; troubleshoot bearer authentication.

GPL-3.0Auto-check: notesDevOps & Cloud

Install Query Netdata Agents

skills CLI
$ npx skills add netdata/netdata --skill query-netdata-agents -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install netdata/netdata query-netdata-agents --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/netdata-ai/skills/query-netdata-agents .claude/skills/query-netdata-agents && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
query-netdata-agents
GitHub stars
81k
Token cost
~2k tokens
SKILL.md length
892 words
Files
19 (incl. scripts)
Skills in repo
27
Repo updated
First seen
Licence
GPL-3.0

At a glance

Query or explain direct Netdata Agent APIs and Functions; review direct-query recipes or helpers; troubleshoot bearer authentication.

  • DevOps & Cloud work in your project
  • SKILL.md covers Choose The Task, Domain Guides, Prerequisites and Safe Execution, plus 1 more section
  • Runs Shell and Python scripts from its folder; calls curl, git and jq; needs NETDATA_CLOUD_TOKEN

What it does

Query Netdata Agents is an agent skill from netdata/netdata. Query or explain direct Netdata Agent APIs and Functions; review direct-query recipes or helpers; troubleshoot bearer authentication. Use query-netdata-cloud for Cloud-proxied calls.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 20 other files, including scripts (for example `authentication.md`, `how-tos/INDEX.md` and `how-tos/audit-stored-flow-timestamps-direct.md`).

It sits in DevOps & Cloud. The repository describes itself as: The fastest path to AI-powered full stack observability, even for lean teams. The licence is GPL-3.0.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/query-netdata-agents”

Requirements

  • Python 3
  • A Bash shell
  • A credential in NETDATA_CLOUD_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 2c378f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • curl
    • git
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NETDATA_CLOUD_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Query Netdata Agents loads about 2k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 892 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:49
    env`. It sources the checkout's trusted `.env`; query wrappers themselves do not load
  • NoteMentions a .env fileSKILL.md:53
    v-key placeholders; the user configures `.env` locally.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from netdata/netdata at commit 2c378f0, republished under its GPL-3.0 licence (© netdata). 892 words, ~1,990 tokens.

Download SKILL.mdSave it as .claude/skills/query-netdata-agents/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.
name
query-netdata-agents
description
Query or explain direct Netdata Agent APIs and Functions; review direct-query recipes or helpers; troubleshoot bearer authentication. Use query-netdata-cloud for Cloud-proxied calls.

Query Netdata Agents Directly

Use this skill for direct HTTP access to an Agent, parent or child, usually on port 19999. It serves operators and assistants helping them. The sibling Cloud skill covers Cloud transport; matching Function payloads use the same underlying Agent schemas.

Choose The Task

  • Explain or review: read the relevant guide and helper as reference material. Do not source helpers, load credentials, mint bearers or run live requests just because the skill was loaded.
  • Run a requested query: use Prerequisites, Safe Execution and the relevant domain guide. A query request does not authorize DynCfg updates or other state-changing Functions.
  • Diagnose authentication or maintain the helper: read authentication.md and the relevant symbol in scripts/_lib.sh. Preserve authorization already given for the current task.

For Cloud team members, Cloud transport is the default when no direct route was requested. Direct access avoids the Cloud request round trip, but this skill's bearer wrapper still needs a reusable cache or Cloud access to mint. agents_call_function defaults to --via cloud; --via agent is explicit and has no automatic Cloud fallback.

Domain Guides

DomainRead
Generic Functions and discoveryquery-functions.md
Logs: systemd-journal, windows-events, macos-logs, otel-logsquery-logs.md
Topology, including topology:snmpquery-topology.md
Network flows: flows:netflowquery-flows.md
Alerts through v3 pathsquery-alerts.md
DynCfg: /api/v3/configquery-dyncfg.md
Time-series metrics: /api/v3/dataquery-metrics.md
Node identity, hardware and vnodesquery-nodes.md
Streaming, parent/child and replicationquery-streaming.md
Operational recipeshow-tos/INDEX.md

Read the matching guide for body schemas rather than loading every domain. End users MAY use the helpers as a black box or read their source as a reference implementation.

Prerequisites

Explanation and saved-data review need no live credentials. The shipped executable recipes require Bash, Git, curl, jq and a repository checkout containing the helper. Direct calls require network access to the selected Agent.

For the managed bearer flow, configure NETDATA_CLOUD_TOKEN and NETDATA_CLOUD_HOSTNAME locally, then load the helper and call agents_load_env. It sources the checkout's trusted .env; query wrappers themselves do not load that file. Supply the target node UUID, machine GUID and host:port to direct wrappers. Space/room IDs are needed only by endpoints that use them. Do not require them for every direct call.

Never request credential values in conversation. Use env-key placeholders; the user configures .env locally. Configuration documents existing key roles and identity lookup. The direct wrapper always resolves a bearer, including for open endpoints; it does not detect protection or switch to unauthenticated access. For an unauthenticated reachability check, discard the potentially sensitive info body:

bash
curl -sS --max-time 10 -o /dev/null -w '%{http_code}\n' \
  "http://${AGENT_HOST:?set the Agent host:port}/api/v3/info"

An HTTP success establishes reachability for that request, not permission to call every API. See Protection And Headers for status interpretation.

Show full SKILL.md (466 more words)Show less

Safe Execution

Use agents_query_cloud, agents_query_agent or agents_call_function for credential-bearing requests. Do not write raw curl commands containing live auth headers or invoke internal mint helpers directly. Header notation in the auth reference describes the protocol, not a request to expose credentials. Unauthenticated probes and local processing MAY use ordinary commands when they capture or suppress sensitive response fields.

The wrappers mask request-auth values in their command log and keep internal mint/claim discovery private. They forward endpoint responses unchanged: logs, config and identity responses can contain secrets or identifiers. Cloud tokens, Agent bearers and claim IDs MUST NOT reach assistant-visible output. Capture sensitive responses in a shell variable or private local artifact, or pipe directly to an appropriate field projection before display. Do not use a general query wrapper to display a credential-issuing endpoint's response. Masked request logging is not response sanitization; do not enable shell tracing around credentials.

For example, after choosing the requested target locally:

bash
source "$(git rev-parse --show-toplevel)/docs/netdata-ai/skills/query-netdata-agents/scripts/_lib.sh"
agents_load_env
agents_query_agent \
  --node "${NODE_UUID:?set the node UUID}" --host "${AGENT_HOST:?set the Agent host:port}" \
  --machine-guid "${AGENT_MG:?set the machine GUID}" \
  POST '/api/v3/function?function=systemd-journal' '{"info":true}' \
  | jq '{status, type}'

For an execution recipe, provide a complete runnable invocation and the response fields needed for the question. Explanations and reviews do not need an unrelated live command appended. Function-specific parameters and output projections belong in the domain guide. Helper Interfaces records all public interfaces, credential/cache handling and safe test commands.

Bearers stay in local configuration/cache or private in-memory variables. Never commit credential values, claim IDs, node UUIDs or machine GUIDs. Repository users follow .agents/sensitive-data-discipline.md; outside a checkout, apply the same redaction to shared artifacts. A private cache is not an artifact to display or publish.

Knowledge Capture

  • For answer-only questions, deliver the requested answer. If the work reveals a reusable, evidence-backed recipe not already documented, you MUST preserve a sanitized note with the finding, supporting evidence, and proposed owning guide. In a repository checkout, use <repo-root>/.local/audits/<subject>/followups.md, reusing this skill's audit directory when available. Outside a checkout, use an appropriate local workspace. If no writable workspace is available, include the sanitized follow-up in the response instead.
  • Briefly report reusable documentation discoveries and proposed updates in the answer-only final response, even when recorded locally. Obtain authorization before those guide edits; do not delay the answer while awaiting it.
  • During authorized implementation, you MUST update this skill or its guides for reusable, evidence-backed discoveries made while doing the work, even when the documentation is not required for the code change. This needs no separate authorization. Keep how-tos/INDEX.md consistent and report the updates.
  • Guide edits arising from answer-only questions require separate authorization. Documentation capture records observed behavior; it does not authorize additional implementation or new product contracts. Commit and publication require authorization too.
  • Prefer updating an existing guide over duplicating it. Keep recipes operator-facing: fetching or using Agent data. Developer contract validation for topology producers, schemas, fixtures, UI adapters, or aggregator handoffs belongs in the relevant project developer skill, not in this public skill.

© netdata, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 18 other files (scripts) in docs/netdata-ai/skills/query-netdata-agents of netdata/netdata.

  • SKILL.md
  • authentication.md
  • how-tos/INDEX.md
  • how-tos/audit-stored-flow-timestamps-direct.md
  • how-tos/export-cpu-io-memory-three-days-direct.md
  • how-tos/find-containers-for-topology-port-direct.md
  • how-tos/group-network-topology-by-kubernetes-pod-direct.md
  • how-tos/validate-direct-local-flow-function.md
  • query-alerts.md
  • query-dyncfg.md
  • query-flows.md
  • query-functions.md
  • query-logs.md
  • query-metrics.md
  • query-nodes.md
  • query-streaming.md
  • query-topology.md
  • scripts/_lib.sh
  • scripts/test_wrappers.py

Open the folder on GitHubat commit 2c378f0

Compare with similar skills

Query Netdata Agents next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Query Netdata Agents compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Query Netdata Agents this skillnetdata/netdata81k—~2kAutomated safety check: NotesGPL-3.0
Azure Storage File Datalake Pyaiskillstore/marketplace4304 repos~1.5kAutomated safety check: PassNone
Time Series Analytics Devopen-edge-platform/edge-ai-libraries169—~1.5kAutomated safety check: NotesApache-2.0
Firecrawl Incident Runbookjeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
Firecrawl Observabilityjeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k1 repos~3.1kAutomated safety check: PassCustom licence

Similar skills

  • Azure Storage File Datalake Py

    aiskillstore/marketplace

    Azure Data Lake Storage Gen2 SDK for Python. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 4 repos~1.5k tokens
    DevOps & CloudAuto-check passed
  • Time Series Analytics Dev

    open-edge-platform/edge-ai-libraries

    Develop the Time Series Analytics microservice itself (FastAPI + Kapacitor) — build and deploy it locally via Docker Compose or Helm, run the mocked unit test suite (tests/runtests.sh) and the…

    169 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Firecrawl Incident Runbook

    jeremylongshore/tons-of-skills-marketplace

    Analyze and mitigate Firecrawl integration incidents involving outage, credits, throttling, policy denial, job failure, webhook loss, or unsafe content.

    2.8k GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Firecrawl Observability

    jeremylongshore/tons-of-skills-marketplace

    Instrument Firecrawl v2 requests, async jobs, queue pressure, credits, origin status, webhooks, output quality, and downstream delivery without logging content.

    2.8k GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub starsUsed in 1 repo~3.1k tokens
    DevOps & CloudAuto-check passed
  • Azure Pricing

    Azure/Copilot-Studio-and-Azure

    Official

    Fetches real-time Azure retail pricing using the Azure Retail Prices API (prices.azure.com) and estimates Copilot Studio agent credit consumption.

    110 GitHub starsUsed in 3 repos~2.4k tokens
    DevOps & CloudAuto-check passed

More from netdata/netdata

All 27 skills in this repo
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Repo Mirror Sources

    netdata/netdata

    Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.

    81k GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Triage Agent Events

    netdata/netdata

    Investigate Netdata crashes, panics and fatals from agent-events captures or authorized fleet queries.

    81k GitHub stars~2.4k tokensUpdated today
    Auto-check: notes
  • Triage Codacy

    netdata/netdata

    Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers.

    81k GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • Triage Coverity

    netdata/netdata

    Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested.

    81k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Triage Sonarqube

    netdata/netdata

    Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.

    81k GitHub stars~2.8k tokensUpdated today
    Auto-check: notes

Questions about Query Netdata Agents

What does Query Netdata Agents do?

Query or explain direct Netdata Agent APIs and Functions; review direct-query recipes or helpers; troubleshoot bearer authentication. Query Netdata Agents is an agent skill from netdata/netdata. Query or explain direct Netdata Agent APIs and Functions; review direct-query recipes or helpers; troubleshoot bearer authentication.

When should I use Query Netdata Agents?

Query Netdata Agents fits situations like: devOps & Cloud work in your project.

How do I install Query Netdata Agents in Claude Code?

Run `npx skills add netdata/netdata --skill query-netdata-agents -a claude-code`. Or copy the skill folder (docs/netdata-ai/skills/query-netdata-agents in netdata/netdata) into .claude/skills/query-netdata-agents in your project. Claude Code loads it when a task matches its description.

How do I install Query Netdata Agents in Codex?

Run `npx skills add netdata/netdata --skill query-netdata-agents -a codex`. Or copy the skill folder (docs/netdata-ai/skills/query-netdata-agents in netdata/netdata) into .agents/skills/query-netdata-agents in your project. Codex loads it when a task matches its description.

Can I use Query Netdata Agents in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add netdata/netdata --skill query-netdata-agents -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/query-netdata-agents, .gemini/skills/query-netdata-agents, .github/skills/query-netdata-agents and .opencode/skills/query-netdata-agents in your project.

What does Query Netdata Agents need to run?

Going by SKILL.md and its folder, Query Netdata Agents needs a shell and Python for the scripts in its folder, the command-line tools its instructions call (curl, git and jq) and credentials named NETDATA_CLOUD_TOKEN. Our summary lists: Python 3; A Bash shell; A credential in NETDATA_CLOUD_TOKEN.

Does Query Netdata Agents access the network?

SKILL.md contains no URLs. Its commands use curl and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Query Netdata Agents safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Query Netdata Agents use?

Query Netdata Agents is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Query Netdata Agents use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Query Netdata Agents?

Skills that share tags, products or a category with Query Netdata Agents: Azure Storage File Datalake Py (aiskillstore/marketplace, 430 stars), Time Series Analytics Dev (open-edge-platform/edge-ai-libraries, 169 stars), Firecrawl Incident Runbook (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Firecrawl Observability (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Query Netdata Agents?

netdata (a GitHub organization) maintains it in netdata/netdata, which has 80,838 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 8, 2026.

Source: netdata/netdata on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.