Agent skill

Observal Admin

by Observal in Observal/Observal

Administers Observal users, settings, diagnostics, review queues, security events, audit logs, SAML, SCIM, the local Observal server, its upgrades and rollback, and its own PostgreSQL and ClickHouse…

Apache-2.0Auto-check passedDatabases

Install Observal Admin

skills CLI
$ npx skills add Observal/Observal --skill observal-admin -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Observal/Observal observal-admin --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Observal/Observal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/observal_cli/skills/observal-admin .claude/skills/observal-admin && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
observal-admin
GitHub stars
4.2k
Token cost
~774 tokens
SKILL.md length
313 words
Files
3 (incl. references)
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

Administers Observal users, settings, diagnostics, review queues, security events, audit logs, SAML, SCIM, the local Observal server, its upgrades and rollback, and its own PostgreSQL and ClickHouse…

  • Works in 9 steps: Execute commands with a 60 second… → Use machine output by default: add… → Run --help before acting when a path,… → …
  • The user needs privileged governance
  • SKILL.md covers Execution contract, Choose the workflow, Safety rules and Completion
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Observal Admin is an agent skill from Observal/Observal. Administers Observal users, settings, diagnostics, review queues, security events, audit logs, SAML, SCIM, the local Observal server, its upgrades and rollback, and its own PostgreSQL and ClickHouse schema migrations. Use when the user needs privileged governance, submission decisions, identity configuration, security investigation, or Observal server operations. Not for querying a database or any work outside Observal administration.

Its SKILL.md is about 770 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/governance-and-identity.md` and `references/server-operations.md`).

It sits in Databases, covering Database migrations and Data warehousing. It works with ClickHouse and PostgreSQL. The repository describes itself as: Observal is self-hosted registry for your coding agent extensions with a built in insight engine. Setup Observal, define the scope and share your Skills, MCPs and Agents with… The licence is Apache-2.0.

When your agent uses it

  • The user needs privileged governance
  • Submission decisions
  • Identity configuration
  • Security investigation

Example prompts

  • “Use the observal-admin skill to administer Observal users, settings, diagnostics, review queues, security events, audit logs, SAML, SCIM, the local…”
  • “/observal-admin”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Execute commands with a 60 second timeout, except documented long-running server and migration operations.
  2. Use machine output by default: add --output json whenever supported. Parse list results from items and pagination fields.
  3. Run --help before acting when a path, role requirement, confirmation flag, or destination option is uncertain.
  4. Read current state before privileged mutations. Use the smallest required authority.
  5. Supply --force or another documented confirmation flag for noninteractive destructive operations.
  6. Verify review decisions, role changes, identity settings, server upgrades, rollback, and imports.
  7. Never repeat generated passwords, SCIM tokens, certificates, submitted headers, database URLs, environment values, or sensitive audit…
  8. Fail openly. Do not bypass the CLI through direct database changes or hand-written migration SQL.
  9. Never blindly retry privileged mutations. Read resulting state after an uncertain failure.

What it can do on your machine

Read from SKILL.md and the folder at commit 30c39f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Observal Admin loads about 774 tokens when it runs, and up to ~2.3k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 313 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~774
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Observal/Observal at commit 30c39f0, republished under its Apache-2.0 licence (© Observal). 313 words, ~774 tokens.

Download SKILL.mdSave it as .claude/skills/observal-admin/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
observal-admin
description
Administers Observal users, settings, diagnostics, review queues, security events, audit logs, SAML, SCIM, the local Observal server, its upgrades and rollback, and its own PostgreSQL and ClickHouse schema migrations. Use when the user needs privileged governance, submission decisions, identity configuration, security investigation, or Observal server operations. Not for querying a database or any work outside Observal administration.
command
observal
version
2.2.1
owner
observal

Administering Observal

Core administration requires an admin role. Review actions also work for authorized global reviewers and teamspace owners or reviewers.

Execution contract

  1. Execute commands with a 60 second timeout, except documented long-running server and migration operations.
  2. Use machine output by default: add --output json whenever supported. Parse list results from items and pagination fields.
  3. Run --help before acting when a path, role requirement, confirmation flag, or destination option is uncertain.
  4. Read current state before privileged mutations. Use the smallest required authority.
  5. Supply --force or another documented confirmation flag for noninteractive destructive operations.
  6. Verify review decisions, role changes, identity settings, server upgrades, rollback, and imports.
  7. Never repeat generated passwords, SCIM tokens, certificates, submitted headers, database URLs, environment values, or sensitive audit content.
  8. Fail openly. Do not bypass the CLI through direct database changes or hand-written migration SQL.
  9. Never blindly retry privileged mutations. Read resulting state after an uncertain failure.

Choose the workflow

User intentRead
Users, settings, diagnostics, reviews, security, audit, SAML, or SCIMGovernance and identity
Local services, versions, upgrades, rollback, reset, or data migrationServer operations

Read the selected reference completely before executing.

Safety rules

  • Permission denial is a result, not a reason to escalate automatically. Report the required role.
  • Review only the returned UUID requested by the user. Never act on table position or an unrelated queue item.
  • Treat one-time password and token responses as secrets from the moment they are returned.
  • Export and import destinations must be explicit. Validate an archive before import.
  • Use the project's migration commands. Never replace them with ad hoc SQL.
  • A server command is successful only when the final status confirms the requested service or version state.

Completion

Report the affected resource by safe identifier, resulting state, request ID for failures, and any required follow-up. Redact secret values even when the command returned them successfully.

© Observal, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in observal_cli/skills/observal-admin of Observal/Observal.

  • SKILL.md
  • references/governance-and-identity.md
  • references/server-operations.md

Open the folder on GitHubat commit 30c39f0

Compare with similar skills

Observal Admin next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Observal Admin compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Observal Admin this skillObserval/Observal4.2k—~774Automated safety check: PassApache-2.0
Database MigrationRain-kl/OpenFlare288—~1.3kAutomated safety check: PassApache-2.0
Migration Patternschmonitor/chmonitor299—~4.4kAutomated safety check: PassGPL-3.0
Clickhouse Logs Queriessupabase/supabase111k—~2.4kAutomated safety check: PassApache-2.0
Chdb SQLvemetric/vemetric3941 repos~1.2kAutomated safety check: PassApache-2.0
Querying Tempotempoxyz/tidx107—~3.1kAutomated safety check: PassMIT

Similar skills

  • Database Migration

    Rain-kl/OpenFlare

    Wavelet 项目专用:当新增或修改数据库表结构、索引、初始化数据、系统配置 seed、模板 seed、默认管理员、goose SQL 迁移、internal/infra/persistence/migrator、ClickHouse 分析库 DDL 或数据库升级流程时必须使用。本技能指导在 internal/infra/persistence/migrator/goose 下编写…

    288 GitHub stars~1.3k tokensUpdated today
    DatabasesAuto-check passed
  • Migration Patterns

    chmonitor/chmonitor

    Schema migrations: ALTER patterns, engine changes, zero-downtime swaps, clickhouse-local offline migrations, lightweight UPDATE/DELETE strategies, and Postgres→ClickHouse migration planning (type…

    299 GitHub stars~4.4k tokensUpdated 2 days ago
    DatabasesAuto-check passed
  • Clickhouse Logs Queries

    supabase/supabase

    Official

    Write, review, and migrate Supabase logs queries against the ClickHouse-backed logs table (the logs.all.otel analytics endpoint).

    111k GitHub stars~2.4k tokensUpdated today
    DatabasesAuto-check passed
  • Chdb SQL

    vemetric/vemetric

    A skill your agent uses when the user wants to run SQL — especially analytical SQL — on local files (parquet/csv/json), URLs, S3 paths, or remote databases (Postgres, MySQL, MongoDB, ClickHouse…

    394 GitHub starsUsed in 1 repo~1.2k tokens
    DatabasesAuto-check passed
  • Querying Tempo

    tempoxyz/tidx

    Query indexed Tempo chain data via tidx HTTP API and CLI. An agent skill from tempoxyz/tidx.

    107 GitHub stars~3.1k tokensUpdated today
    DatabasesAuto-check passed
  • Local Platform E2E

    computesdk/benchmarks

    Stand up benchmarks-platform locally (Postgres + MinIO + ClickHouse in docker) and run a real @benchsdk/runner benchmark against it, with no cloud or provider credentials.

    126 GitHub stars~3k tokensUpdated today
    DatabasesAuto-check: notes

More from Observal/Observal

  • Release

    Observal/Observal

    Cut and maintain Observal release branches, prepare alpha, beta, RC, stable, and patch releases, backport merged main PRs, inspect release status, verify published artifacts, and recover failed…

    4.2k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Observal

    Observal/Observal

    A skill your agent uses when starting any task the organization may already have an approved skill, prompt, MCP server, or Agent for: reviewing code, a commit, a diff, or a pull request; writing…

    4.2k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Observal Advanced

    Observal/Observal

    Recovers Observal session ingestion, manages CLI upgrades, downgrades and rollback, and performs explicit local Agent fallback when the server is unavailable.

    4.2k GitHub stars~604 tokensUpdated yesterday
    Auto-check passed
  • Observal Agents

    Observal/Observal

    Creates, authors, validates, publishes, updates, versions, pulls, archives, restores, transfers, and manages co-authors for Observal Agents.

    4.2k GitHub stars~753 tokensUpdated yesterday
    Auto-check passed
  • Observal Ops

    Observal/Observal

    Inspects Observal traces, sessions, rankings, feedback, telemetry health, logs, and Agent insight reports.

    4.2k GitHub stars~654 tokensUpdated yesterday
    Auto-check passed
  • Observal Registry

    Observal/Observal

    Searches, recommends, bulk-submits, installs, edits, versions, archives, restores, transfers, and manages co-authors for Observal MCP servers, skills, hooks, prompts, sandboxes, and registered…

    4.2k GitHub stars~907 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Observal Admin

What does Observal Admin do?

Administers Observal users, settings, diagnostics, review queues, security events, audit logs, SAML, SCIM, the local Observal server, its upgrades and rollback, and its own PostgreSQL and ClickHouse…. Observal Admin is an agent skill from Observal/Observal. Administers Observal users, settings, diagnostics, review queues, security events, audit logs, SAML, SCIM, the local Observal server, its upgrades and rollback, and its own PostgreSQL and ClickHouse schema migrations.

When should I use Observal Admin?

Observal Admin fits situations like: the user needs privileged governance; submission decisions; identity configuration; security investigation.

How do I install Observal Admin in Claude Code?

Run `npx skills add Observal/Observal --skill observal-admin -a claude-code`. Or copy the skill folder (observal_cli/skills/observal-admin in Observal/Observal) into .claude/skills/observal-admin in your project. Claude Code loads it when a task matches its description.

How do I install Observal Admin in Codex?

Run `npx skills add Observal/Observal --skill observal-admin -a codex`. Or copy the skill folder (observal_cli/skills/observal-admin in Observal/Observal) into .agents/skills/observal-admin in your project. Codex loads it when a task matches its description.

Can I use Observal Admin in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Observal/Observal --skill observal-admin -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/observal-admin, .gemini/skills/observal-admin, .github/skills/observal-admin and .opencode/skills/observal-admin in your project.

What does Observal Admin need to run?

SKILL.md names no scripts, command-line tools or credentials: Observal Admin is instructions for the agent only.

Does Observal Admin access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Observal Admin safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Observal Admin use?

Observal Admin is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Observal Admin use?

About 774 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Observal Admin?

Skills that share tags, products or a category with Observal Admin: Database Migration (Rain-kl/OpenFlare, 288 stars), Migration Patterns (chmonitor/chmonitor, 299 stars), Clickhouse Logs Queries (supabase/supabase, 111k stars) and Chdb SQL (vemetric/vemetric, 394 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Observal Admin?

Observal (a GitHub organization) maintains it in Observal/Observal, which has 4,193 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 6, 2026.

Source: Observal/Observal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.