Agent skill

Root Cause Investigation

by nimrodfisher in nimrodfisher/data-analytics-skills

Systematic investigation of metric changes and anomalies. An agent skill from nimrodfisher/data-analytics-skills.

MITAuto-check passedData & Analytics

Install Root Cause Investigation

skills CLI
$ npx skills add nimrodfisher/data-analytics-skills --skill root-cause-investigation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nimrodfisher/data-analytics-skills root-cause-investigation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nimrodfisher/data-analytics-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/03-data-analysis-investigation/root-cause-investigation .claude/skills/root-cause-investigation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
root-cause-investigation
GitHub stars
470
Token cost
~764 tokens
SKILL.md length
363 words
Files
5 (incl. scripts, references, assets)
Skills in repo
31
Repo updated
First seen
Licence
MIT

At a glance

Systematic investigation of metric changes and anomalies. An agent skill from nimrodfisher/data-analytics-skills.

  • Works in 6 steps: Validate the change — confirm the metric… → Establish a timeline — plot the metric… → Decompose the metric — break the metric… → …
  • A metric unexpectedly changes
  • Runs Python scripts from its folder
  • Investigating business metric drops

What it does

Root Cause Investigation is an agent skill from nimrodfisher/data-analytics-skills. Systematic investigation of metric changes and anomalies. Use when a metric unexpectedly changes, investigating business metric drops, explaining performance variations, or drilling into aggregated metric drivers.

Its SKILL.md is about 760 tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/rca_report_template.md`, `references/hypothesis_testing_guide.md` and `references/rca_framework.md`).

It sits in Data & Analytics, covering Root cause analysis. The repository describes itself as: A comprehensive list of Claude & Codex skills for a wide range of data analytics tasks. The licence is MIT.

When your agent uses it

  • A metric unexpectedly changes
  • Investigating business metric drops
  • Explaining performance variations
  • Drilling into aggregated metric drivers

Example prompts

  • “/root-cause-investigation”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Validate the change — confirm the metric changed beyond normal variance using a z-score or simple comparison to the rolling average. If…
  2. Establish a timeline — plot the metric over time to pinpoint when the change started. A sudden step change suggests a specific event; a…
  3. Decompose the metric — break the metric into its constituent parts (e.g., revenue = volume × price × mix). Determine which component is…
  4. Drill down systematically — compare the metric before vs. after the change across available dimensions (geography, platform, channel…
  5. Test hypotheses — generate explicit hypotheses (volume drop, mix shift, per-unit quality change, data issue) and accept or reject each…
  6. Write the root cause report — document the primary driver (quantified share of impact), supporting evidence, rejected hypotheses, and…

What it can do on your machine

Read from SKILL.md and the folder at commit 9449d36. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Root Cause Investigation loads about 764 tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 60 tokens; SKILL.md has 363 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~764
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from nimrodfisher/data-analytics-skills at commit 9449d36, republished under its MIT licence (© nimrodfisher). 363 words, ~764 tokens.

Download SKILL.mdSave it as .claude/skills/root-cause-investigation/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
root-cause-investigation
description
Systematic investigation of metric changes and anomalies. Use when a metric unexpectedly changes, investigating business metric drops, explaining performance variations, or drilling into aggregated metric drivers.

Root Cause Investigation

When to use

  • A key metric dropped (or spiked) unexpectedly and the team needs an explanation
  • Stakeholders are asking "why did X happen?" and need an evidence-based answer
  • A metric change has been observed but the team is unsure whether it's noise or signal
  • Preparing a post-mortem after an incident that affected business metrics
  • A trend change happened weeks ago and needs retrospective investigation

Process

  1. Validate the change — confirm the metric changed beyond normal variance using a z-score or simple comparison to the rolling average. If the change is within ±1.5 standard deviations, document it as within normal range and close. Use scripts/drilldown_analyzer.py --validate.
  2. Establish a timeline — plot the metric over time to pinpoint when the change started. A sudden step change suggests a specific event; a gradual drift suggests a structural shift.
  3. Decompose the metric — break the metric into its constituent parts (e.g., revenue = volume × price × mix). Determine which component is driving the change before drilling into dimensions.
  4. Drill down systematically — compare the metric before vs. after the change across available dimensions (geography, platform, channel, product category, user segment). Sort by absolute contribution to identify the primary driver. Use scripts/drilldown_analyzer.py --drilldown. See references/rca_framework.md for the structured approach.
  5. Test hypotheses — generate explicit hypotheses (volume drop, mix shift, per-unit quality change, data issue) and accept or reject each with evidence. Correlate the timeline with known events from references/hypothesis_testing_guide.md.
  6. Write the root cause report — document the primary driver (quantified share of impact), supporting evidence, rejected hypotheses, and tiered recommendations (immediate / short-term / long-term). Use assets/rca_report_template.md.
Show full SKILL.md (102 more words)Show less

Inputs the skill needs

  • Metric name and historical values (at least 30 days before the change)
  • Granular data with dimensional breakdowns (geography, platform, segment, etc.)
  • The date or date range when the change was noticed
  • A change log or incident log for the same period (product releases, campaigns, outages)
  • The business context: what decisions depend on this metric

Output

  • scripts/drilldown_analyzer.py — validates the change, computes dimensional drill-downs, and ranks contributors by impact
  • references/rca_framework.md — structured five-step RCA method with decision rules
  • references/hypothesis_testing_guide.md — checklist of common root causes and how to test each
  • assets/rca_report_template.md — report template: what changed, when, primary driver, supporting evidence, timeline, recommendations

© nimrodfisher, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in 03-data-analysis-investigation/root-cause-investigation of nimrodfisher/data-analytics-skills.

  • SKILL.md
  • assets/rca_report_template.md
  • references/hypothesis_testing_guide.md
  • references/rca_framework.md
  • scripts/drilldown_analyzer.py

Open the folder on GitHubat commit 9449d36

Compare with similar skills

Root Cause Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Root Cause Investigation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Root Cause Investigation this skillnimrodfisher/data-analytics-skills470—~764Automated safety check: PassMIT
Monte Carlo Performance Diagnosissickn33/agentic-awesome-skills47k1 repos~2kAutomated safety check: PassApache-2.0
Anomaly Investigationgaasher/Agent-Loop-Skills174—~2.1kAutomated safety check: PassMIT
Pm Metricsserejaris/personal-corp-os229—~3kAutomated safety check: PassMIT
Amazon Opensearch Serviceaws/agent-toolkit-for-aws2.8k—~2.4kAutomated safety check: PassApache-2.0
Data Analysis Standardmohitagw15856/pm-claude-skills1.4k—~1.7kAutomated safety check: PassMIT

Similar skills

  • Monte Carlo Performance Diagnosis

    sickn33/agentic-awesome-skills

    Diagnoses pipeline performance issues -- slow jobs, expensive queries, latency trends -- using Monte Carlo's cross-platform observability.

    47k GitHub starsUsed in 1 repo~2k tokens
    Data & AnalyticsAuto-check passed
  • Anomaly Investigation

    gaasher/Agent-Loop-Skills

    A skill your agent uses when the user has a known, already-observed anomaly in their data — a metric spike or drop, an outlier, an unexpected number — and wants its root cause diagnosed, not guessed.

    174 GitHub stars~2.1k tokensUpdated 3 mo ago
    Data & AnalyticsAuto-check passed
  • Pm Metrics

    serejaris/personal-corp-os

    Делает ревью продуктовых метрик — тренды, аномалии, root causes и рекомендации к действиям.

    229 GitHub stars~3k tokensUpdated 3 days ago
    Data & AnalyticsAuto-check passed
  • Amazon Opensearch Service

    aws/agent-toolkit-for-aws

    Official

    Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…

    2.8k GitHub stars~2.4k tokensUpdated yesterday
    Data & AnalyticsAuto-check passed
  • Data Analysis Standard

    mohitagw15856/pm-claude-skills

    Structure a product data analysis, metric deep-dive, funnel analysis, or cohort study.

    1.4k GitHub stars~1.7k tokensUpdated yesterday
    Data & AnalyticsAuto-check passed
  • Troubleshooting Dbt Job Errors

    Kilo-Org/kilo-marketplace

    Diagnoses dbt Cloud/platform job failures by analyzing run logs, querying the Admin API, reviewing git history, and investigating data issues.

    190 GitHub stars~2.6k tokensUpdated 12 days ago
    Data & AnalyticsAuto-check passed

More from nimrodfisher/data-analytics-skills

All 31 skills in this repo
  • Ab Test Analysis

    nimrodfisher/data-analytics-skills

    Rigorous A/B test statistical analysis. An agent skill from nimrodfisher/data-analytics-skills.

    470 GitHub stars~708 tokensUpdated 16 days ago
    Auto-check passed
  • Analysis Assumptions Log

    nimrodfisher/data-analytics-skills

    Track and document analytical assumptions and decisions. An agent skill from nimrodfisher/data-analytics-skills.

    470 GitHub stars~578 tokensUpdated 16 days ago
    Auto-check passed
  • Analysis QA Checklist

    nimrodfisher/data-analytics-skills

    Pre-delivery quality assurance for analysis work. An agent skill from nimrodfisher/data-analytics-skills.

    470 GitHub stars~470 tokensUpdated 16 days ago
    Auto-check passed
  • Business Metrics Calculator

    nimrodfisher/data-analytics-skills

    Standard business metric calculation with industry benchmarks.

    470 GitHub stars~668 tokensUpdated 16 days ago
    Auto-check passed
  • Cohort Analysis

    nimrodfisher/data-analytics-skills

    Time-based cohort analysis with retention and behaviour tracking.

    470 GitHub stars~660 tokensUpdated 16 days ago
    Auto-check passed
  • Context Packager

    nimrodfisher/data-analytics-skills

    Efficiently package context for AI-assisted analysis. An agent skill from nimrodfisher/data-analytics-skills.

    470 GitHub stars~500 tokensUpdated 16 days ago
    Auto-check passed

Questions about Root Cause Investigation

What does Root Cause Investigation do?

Systematic investigation of metric changes and anomalies. An agent skill from nimrodfisher/data-analytics-skills. Root Cause Investigation is an agent skill from nimrodfisher/data-analytics-skills. Systematic investigation of metric changes and anomalies.

When should I use Root Cause Investigation?

Root Cause Investigation fits situations like: A metric unexpectedly changes; investigating business metric drops; explaining performance variations; drilling into aggregated metric drivers.

How do I install Root Cause Investigation in Claude Code?

Run `npx skills add nimrodfisher/data-analytics-skills --skill root-cause-investigation -a claude-code`. Or copy the skill folder (03-data-analysis-investigation/root-cause-investigation in nimrodfisher/data-analytics-skills) into .claude/skills/root-cause-investigation in your project. Claude Code loads it when a task matches its description.

How do I install Root Cause Investigation in Codex?

Run `npx skills add nimrodfisher/data-analytics-skills --skill root-cause-investigation -a codex`. Or copy the skill folder (03-data-analysis-investigation/root-cause-investigation in nimrodfisher/data-analytics-skills) into .agents/skills/root-cause-investigation in your project. Codex loads it when a task matches its description.

Can I use Root Cause Investigation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nimrodfisher/data-analytics-skills --skill root-cause-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/root-cause-investigation, .gemini/skills/root-cause-investigation, .github/skills/root-cause-investigation and .opencode/skills/root-cause-investigation in your project.

What does Root Cause Investigation need to run?

Going by SKILL.md and its folder, Root Cause Investigation needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Root Cause Investigation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Root Cause Investigation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Root Cause Investigation use?

Root Cause Investigation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Root Cause Investigation use?

About 764 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Root Cause Investigation?

Skills that share tags, products or a category with Root Cause Investigation: Monte Carlo Performance Diagnosis (sickn33/agentic-awesome-skills, 47k stars), Anomaly Investigation (gaasher/Agent-Loop-Skills, 174 stars), Pm Metrics (serejaris/personal-corp-os, 229 stars) and Amazon Opensearch Service (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Root Cause Investigation?

nimrodfisher (a GitHub user) maintains it in nimrodfisher/data-analytics-skills, which has 470 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on September 25, 2026.

Source: nimrodfisher/data-analytics-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.