Agent skill

Triage Support Bundle

by netdata in netdata/netdata

Investigate a Netdata support bundle offline - the archive netdata-support-bundle produces - to explain one host's alerts, missing data, collector failures, crashes, high CPU or memory, streaming…

GPL-3.0Auto-check passedDevOps & Cloud

Install Triage Support Bundle

skills CLI
$ npx skills add netdata/netdata --skill triage-support-bundle -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install netdata/netdata triage-support-bundle --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/triage-support-bundle .claude/skills/triage-support-bundle && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
triage-support-bundle
GitHub stars
81k
Token cost
~2.7k tokens
SKILL.md length
1,229 words
Files
13 (incl. scripts)
Skills in repo
27
Repo updated
First seen
Licence
GPL-3.0

At a glance

Investigate a Netdata support bundle offline - the archive netdata-support-bundle produces - to explain one host's alerts, missing data, collector failures, crashes, high CPU or memory, streaming…

  • Works in 3 steps: The symptom in the reporter's words, and… → The incident timestamp, and whether it… → Which host this is, and for a streaming…
  • Analyse this support bundle
  • SKILL.md covers Owners, Before You Start, Choose The Investigation and Rules
  • Runs Shell scripts from its folder

What it does

Triage Support Bundle is an agent skill from netdata/netdata. Investigate a Netdata support bundle offline - the archive netdata-support-bundle produces - to explain one host's alerts, missing data, collector failures, crashes, high CPU or memory, streaming, cloud claiming, retention, dashboard reachability, permissions, install and update, container and Windows problems. Use for "analyse this support bundle", "a customer sent a bundle", "what does this bundle say", "why did this agent crash", "why is this collector showing no data", "why are alerts not firing", or when…

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including scripts (for example `alerts.md`, `bundle-map.md` and `connectivity.md`).

It sits in DevOps & Cloud. The repository describes itself as: The fastest path to AI-powered full stack observability, even for lean teams. The licence is GPL-3.0.

When your agent uses it

  • Analyse this support bundle
  • A customer sent a bundle
  • What does this bundle say
  • Why did this agent crash

Example prompts

  • “analyse this support bundle”
  • “a customer sent a bundle”
  • “what does this bundle say”
  • “/triage-support-bundle”

Requirements

  • A Bash shell
  • Docker

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. The symptom in the reporter's words, and what they expected instead.
  2. The incident timestamp, and whether it falls inside the bundle's log window. The window is a flag
  3. Which host this is, and for a streaming or Cloud question, whether you also need the other end.

What it can do on your machine

Read from SKILL.md and the folder at commit 9fe30d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Triage Support Bundle loads about 2.7k tokens when it runs. Until then it costs about 238 tokens; SKILL.md has 1,229 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~238
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from netdata/netdata at commit 9fe30d9, republished under its GPL-3.0 licence (© netdata). 1,229 words, ~2,684 tokens.

Download SKILL.mdSave it as .claude/skills/triage-support-bundle/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.
name
triage-support-bundle
description
Investigate a Netdata support bundle offline - the archive `netdata-support-bundle` produces - to explain one host's alerts, missing data, collector failures, crashes, high CPU or memory, streaming, cloud claiming, retention, dashboard reachability, permissions, install and update, container and Windows problems. Use for "analyse this support bundle", "a customer sent a bundle", "what does this bundle say", "why did this agent crash", "why is this collector showing no data", "why are alerts not firing", or when reading `MANIFEST.json`, `summary.txt`, `status-file.json`, or anything under `01-system` through `09-permissions`. Not for SNMP evidence under `06-state/snmp-diagnostics` (triage-snmp-diagnostics), not for fleet-wide crash or regression clustering (triage-agent-events), not for live queries against an Agent or Cloud (query-netdata-agents, query-netdata-cloud), and not for changing the bundle collector itself.

Support bundle triage

A support bundle is one host, one collection run, sanitized. Collection is not atomic: files carry independent timestamps and can rotate while it runs, so artifacts are not a simultaneous snapshot. This skill turns a reported symptom into a supported conclusion about that host, or into a statement that the bundle cannot settle it. The bundle's own contents and rationale are owned by its two documents; what follows is the routing, the absence semantics, and the traps.

Read ./orientation.md first if you do not already hold a causal model of the Agent. Everything else is reached from the tables below.

Owners

Owner sectionWhat you must get from it
packaging/installer/SUPPORT-BUNDLE.md#what-is-collected-and-whyevery collected item and the support ask it answers
packaging/installer/SUPPORT-BUNDLE.md#what-is-never-collectedthe hard exclusions; what a bundle can never show
packaging/installer/SUPPORT-BUNDLE.md#sanitizationwhat the sanitizer rewrites, and its documented scope limits
packaging/installer/SUPPORT-BUNDLE.md#redaction-philosophywhy a key is judged by its name, not its value
packaging/installer/SUPPORT-BUNDLE.md#the-streaming-api-key-exceptionthe one secret kept verbatim, and where it is still redacted
packaging/installer/SUPPORT-BUNDLE.md#encoding-fidelityBOM, line terminators and missing final newline survive, so encoding faults stay visible
packaging/installer/SUPPORT-BUNDLE.md#bundle-format-contractschema id, provenance headers, which files carry them
packaging/installer/SUPPORT-BUNDLE.md#design-contract-do-not-regress-thesecaps, timeouts, the global deadline, read-only guarantees
packaging/installer/SUPPORT-BUNDLE.md#platform-supportwhich implementation produced the bundle
packaging/installer/SUPPORT-BUNDLE.md#raw-snmp-evidencewhat the opt-in SNMP store holds and that it is unsanitized
docs/developer-and-contributor-corner/netdata-support-bundle.md#optionsthe flags that shaped this bundle, including the log window
docs/developer-and-contributor-corner/netdata-support-bundle.md#privacy-and-sanitizationwhat to tell the customer about what they sent
docs/developer-and-contributor-corner/netdata-support-bundle.md#include-snmp-diagnosticshow to ask for another bundle with SNMP evidence

Sibling skills, one line each. triage-snmp-diagnostics owns every SNMP question and the whole 06-state/snmp-diagnostics/ store, including its SNMP-scoped reading of 04-config/ and 05-logs/; hand over as soon as the symptom is SNMP-scoped, and take back only host-level causes that are not SNMP-specific. triage-agent-events owns fleet-wide crash, panic and fatal clustering against the live agent-events namespace; escalate to it once you hold this host's signature and the question becomes "is this known, is it fixed, how widespread". query-netdata-agents and query-netdata-cloud own everything live, which is where every question this bundle cannot answer goes. query-snmp-traps owns received traps.

Before You Start

The bundle does not carry the incident. Establish these before interpreting any file, and ask rather than infer:

  1. The symptom in the reporter's words, and what they expected instead.
  2. The incident timestamp, and whether it falls inside the bundle's log window. The window is a flag on the run (docs/developer-and-contributor-corner/netdata-support-bundle.md#options); outside it, silence means nothing.
  3. Which host this is, and for a streaming or Cloud question, whether you also need the other end.

Then run the inventory before reading any single file - from the repository root that is .agents/skills/triage-support-bundle/scripts/bundle-summary.sh <bundle>, or ./scripts/bundle-summary.sh from this skill's own directory. It reports what the bundle holds, what is absent, what was truncated or withheld, and whether the incident time falls inside the window. Reading files without that inventory is how absence gets misread as evidence.

Keep working notes under <repo-root>/.local/audits/support-bundle/<case>/. Bundle contents are customer data: never paste them into a public issue, a commit, a fixture, or a review prompt.

Choose The Investigation

Ordered by how often each class reaches support, which is not the order summary.txt prints. The bundle's own READ ORDER FOR TRIAGE is a fixed seven-class list that leads with SNMP and crashes and never mentions alerts. Read it, then use this table.

SymptomStart withGuide
Alert did not fire, fires always, or flapssilencers, then the alert's own config and the health transition records./alerts.md
A notification never arrived though the alert did raisethe notification configuration and its delivery surface, not silencers./alerts.md
A chart, collector or job shows nothingthe dyncfg job states where the bundle carries them, then the collector log; reach for plugin capabilities only when those are absent or inconclusive./no-data.md
A specific collector fails, or service discovery finds nothingthe job's own state and its config, then the collector log./no-data.md
Agent will not start, died, restarted, or was killedthe daemon status file, then the kernel messages, then the logs./lifecycle.md
High CPU, memory, file descriptors, or disk I/Oper-thread CPU and the self-monitoring captures./lifecycle.md
Retention shorter than expected, or a tier looks emptyper-tier disk usage against the effective config./lifecycle.md
Install, update, or auto-update failureinstall type and the install-time environment./lifecycle.md
Child not on parent, rejected, flapping, or duplicatedthe receiver's rejection reason, then the stream config on both ends./connectivity.md
Node offline or stale in Cloud, or claiming failsclaim state and the ACLK view, then the network probes./connectivity.md
Dashboard unreachable, TLS error, or a proxy in front failsthe socket inventory and the effective web config./connectivity.md
Permission denied, a plugin silently collects nothing, or a capability was lostthe permissions captures./environment.md
Container, Docker or Kubernetes behaviourthe container context and cgroup evidence./environment.md
Anything on a Windows hostthe merged event log and the Windows-only captures./windows.md
"My config is ignored"the effective running config, then dyncfg./no-data.md
Anything SNMPhand to triage-snmp-diagnostics-

Two files support every branch: ./bundle-map.md is the artifact reference - what each path holds, which platform produces it, and what its absence means - and ./evidence-limits.md is what a bundle structurally cannot answer. Check ./false-signals.md before reporting any conclusion.

Show full SKILL.md (362 more words)Show less

Rules

Enforced by the bundle collector, so you can rely on them:

  • MANIFEST.json indexes every file except itself, and its bytes matches the file on disk; the CI workflow .github/workflows/netdata-support-bundle.yml asserts that parity. Use it as the navigation contract rather than walking the tree (packaging/installer/SUPPORT-BUNDLE.md#bundle-format-contract).
  • Every standard capture is sanitized. sanitized: false appears only for raw SNMP evidence, and its presence also clears the top-level pii_obfuscated and secrets_redacted flags (packaging/installer/SUPPORT-BUNDLE.md#raw-snmp-evidence).
  • The streaming API key in the collected stream.conf is verbatim, scoped by source filename and exact key; the same key stays redacted in the access log and in log lines (packaging/installer/SUPPORT-BUNDLE.md#the-streaming-api-key-exception).
  • Caps cut at line boundaries; a capped tail with no line break is withheld whole, and a sanitizer failure withholds the file (packaging/installer/SUPPORT-BUNDLE.md#design-contract-do-not-regress-these).
  • Source bytes are preserved through sanitization, so a BOM, a CR-only file, or a missing final newline in the customer's config is still visible as itself (packaging/installer/SUPPORT-BUNDLE.md#encoding-fidelity).
  • Pseudonyms are stable within one bundle and meaningless across two; the map is written beside the archive and never inside it (packaging/installer/SUPPORT-BUNDLE.md#sanitization).

Hand-reviewed, because nothing checks them:

  • Never read a missing file as evidence. Resolve it through ./bundle-map.md first: not collected on this platform, capped, deadline-skipped, API down, withheld by the sanitizer, or genuinely absent.
  • Never compare pseudonyms across two bundles, and never ask the customer to send the pseudonym map unless the identity is load-bearing for the conclusion.
  • Prefer the effective running config over the on-disk netdata.conf; they disagree whenever an environment override or an unrecognized option is involved. It is the merged daemon config only - it does not contain collector job configuration, so a UI- or API-created job override is visible only in the dynamic configuration area.
  • State the collection window with any negative finding. "No errors in the log" means "none inside the window that survived the caps".
  • Separate what the bundle shows from what you infer. Where the bundle cannot settle the question, say so and name the live query or the second bundle that would (./evidence-limits.md).
  • Root-cause frequencies in these guides come from support-corpus analysis and are written as "commonly", never as a measured ranking; do not harden them into claims the evidence does not support.

© netdata, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 12 other files (scripts) in .agents/skills/triage-support-bundle of netdata/netdata.

  • SKILL.md
  • alerts.md
  • bundle-map.md
  • connectivity.md
  • environment.md
  • evidence-limits.md
  • false-signals.md
  • lifecycle.md
  • no-data.md
  • orientation.md
  • scripts/_lib.sh
  • scripts/bundle-summary.sh
  • windows.md

Open the folder on GitHubat commit 9fe30d9

Compare with similar skills

Triage Support Bundle next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Triage Support Bundle compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Triage Support Bundle this skillnetdata/netdata81k—~2.7kAutomated safety check: PassGPL-3.0
Axiom Dashboard Builderopenclaw/clawhub9.5k—~4.9kAutomated safety check: PassMIT
Axiom Cost Controlopenclaw/clawhub9.5k—~1.7kAutomated safety check: PassMIT
ML Pipeline ExpertJeffallan/claude-skills12k1 repos~1.9kAutomated safety check: PassMIT
Sf AI Agentforce ObservabilityJaganpro/sf-skills424—~1.8kAutomated safety check: PassMIT
Verify CI Impactgodatadriven/whirl205—~1.3kAutomated safety check: PassApache-2.0

Similar skills

  • Axiom Dashboard Builder

    openclaw/clawhub

    Designs and deploys Axiom dashboards through the API, choosing chart types and writing APL or metrics queries, with templates and migration notes for Splunk and Grafana.

    9.5k GitHub stars~4.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Axiom Cost Control

    openclaw/clawhub

    Finds unused data in Axiom by analyzing query patterns, then deploys a cost dashboard and ingest monitors to keep spend under the contract limit.

    9.5k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • ML Pipeline Expert

    Jeffallan/claude-skills

    Designs ML pipeline infrastructure: experiment tracking with MLflow or Weights & Biases, Kubeflow and Airflow orchestration, Feast feature stores and model validation gates.

    12k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Agentforce session tracing extraction and analysis. An agent skill from Jaganpro/sf-skills.

    424 GitHub stars~1.8k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Verify CI Impact

    godatadriven/whirl

    Before committing, work out which Whirl examples need a CI run to verify changes still work, then run them after confirming with the user.

    205 GitHub stars~1.3k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Add React Analytics

    gotempsh/temps

    Add Temps analytics to React applications with comprehensive tracking capabilities including page views, custom events, scroll tracking, engagement monitoring, session recording, and Web Vitals…

    822 GitHub stars~2.7k tokensUpdated today
    DevOps & CloudAuto-check passed

More from netdata/netdata

All 27 skills in this repo
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Repo Mirror Sources

    netdata/netdata

    Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.

    81k GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Triage Agent Events

    netdata/netdata

    Investigate Netdata crashes, panics and fatals from agent-events captures or authorized fleet queries.

    81k GitHub stars~2.4k tokensUpdated today
    Auto-check: notes
  • Triage Codacy

    netdata/netdata

    Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers.

    81k GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • Triage Coverity

    netdata/netdata

    Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested.

    81k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Triage Sonarqube

    netdata/netdata

    Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.

    81k GitHub stars~2.8k tokensUpdated today
    Auto-check: notes

Questions about Triage Support Bundle

What does Triage Support Bundle do?

Investigate a Netdata support bundle offline - the archive netdata-support-bundle produces - to explain one host's alerts, missing data, collector failures, crashes, high CPU or memory, streaming…. Triage Support Bundle is an agent skill from netdata/netdata. Investigate a Netdata support bundle offline - the archive netdata-support-bundle produces - to explain one host's alerts, missing data, collector failures, crashes, high CPU or memory, streaming, cloud claiming, retention, dashboard reachability, permissions, install and update, container and Windows problems.

When should I use Triage Support Bundle?

Triage Support Bundle fits situations like: analyse this support bundle; A customer sent a bundle; what does this bundle say; why did this agent crash.

How do I install Triage Support Bundle in Claude Code?

Run `npx skills add netdata/netdata --skill triage-support-bundle -a claude-code`. Or copy the skill folder (.agents/skills/triage-support-bundle in netdata/netdata) into .claude/skills/triage-support-bundle in your project. Claude Code loads it when a task matches its description.

How do I install Triage Support Bundle in Codex?

Run `npx skills add netdata/netdata --skill triage-support-bundle -a codex`. Or copy the skill folder (.agents/skills/triage-support-bundle in netdata/netdata) into .agents/skills/triage-support-bundle in your project. Codex loads it when a task matches its description.

Can I use Triage Support Bundle in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add netdata/netdata --skill triage-support-bundle -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triage-support-bundle, .gemini/skills/triage-support-bundle, .github/skills/triage-support-bundle and .opencode/skills/triage-support-bundle in your project.

What does Triage Support Bundle need to run?

Going by SKILL.md and its folder, Triage Support Bundle needs a shell for the scripts in its folder. Our summary lists: A Bash shell; Docker.

Does Triage Support Bundle access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Triage Support Bundle safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Triage Support Bundle use?

Triage Support Bundle is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Triage Support Bundle use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Triage Support Bundle?

Skills that share tags, products or a category with Triage Support Bundle: Axiom Dashboard Builder (openclaw/clawhub, 9.5k stars), Axiom Cost Control (openclaw/clawhub, 9.5k stars), ML Pipeline Expert (Jeffallan/claude-skills, 12k stars) and Sf AI Agentforce Observability (Jaganpro/sf-skills, 424 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Triage Support Bundle?

netdata (a GitHub organization) maintains it in netdata/netdata, which has 80,820 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 7, 2026.

Source: netdata/netdata on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.