Agent skill

Axiom Alerting Management

by openclaw in openclaw/clawhub

Creates and manages Axiom monitors and notifiers end to end through the v2 API, with scripts for each CRUD operation and a recommended create-validate-tune workflow.

MITAuto-check passedDevOps & Cloud

Install Axiom Alerting Management

skills CLI
$ npx skills add openclaw/clawhub --skill axiom-alerting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/clawhub axiom-alerting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/clawhub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/axiom-alerting .claude/skills/axiom-alerting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
axiom-alerting
GitHub stars
9.5k
Token cost
~2.1k tokens
SKILL.md length
673 words
Files
16 (incl. scripts)
Skills in repo
55
Repo updated
First seen
Licence
MIT

At a glance

Creates and manages Axiom monitors and notifiers end to end through the v2 API, with scripts for each CRUD operation and a recommended create-validate-tune workflow.

  • Works in 2 steps: Run scripts/setup → Ensure .axiom.toml has a deployment
  • Setting up a new alert in Axiom with its routing notifier
  • SKILL.md covers API Overview, Prerequisites, Scripts and Recommended Workflow, plus 7 more sections
  • Reaches api.axiom.co and hooks.slack.com

What it does

The skill wraps the Axiom v2 API at api.axiom.co, authenticating with a bearer token read from .axiom.toml in the project root or home directory. It covers both resource types: monitors under /v2/monitors for detection, with list, get, history, create, update and delete operations, and notifiers under /v2/notifiers for routing alerts, with the same set minus history.

A setup script checks prerequisites, and a core axiom-api script issues the raw calls, backed by dedicated scripts per operation such as monitor-create, monitor-history and notifier-update, each taking a deployment name and, for create or update, a JSON file. The recommended workflow is to create or reuse a notifier first, create the monitor with its notifierIds attached, validate behavior with monitor-history, and then tune threshold, rangeMinutes, intervalMinutes and N-of-M trigger fields, re-checking history after each change. One notifier per channel is the stated best practice.

When your agent uses it

  • Setting up a new alert in Axiom with its routing notifier
  • Checking whether a monitor's threshold is too noisy or too quiet
  • Updating or deleting an existing Axiom monitor or notifier

Example prompts

  • “Create an Axiom notifier for the on-call Slack channel, then a monitor that uses it.”
  • “Check the history of monitor abc123 in prod for the last 24 hours.”
  • “Raise the threshold on our error-rate monitor because it's firing too often.”

Requirements

  • An Axiom API token in .axiom.toml
  • Bash, to run the bundled scripts

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Run scripts/setup
  2. Ensure .axiom.toml has a deployment

What it can do on your machine

Read from SKILL.md and the folder at commit d044664. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 13 files in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.axiom.co
    • hooks.slack.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Axiom Alerting Management loads about 2.1k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 673 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from openclaw/clawhub at commit d044664, republished under its MIT licence (© openclaw). 673 words, ~2,107 tokens.

Download SKILL.mdSave it as .claude/skills/axiom-alerting/SKILL.md (or your agent's skills folder). This skill also uses 15 other files; get the full folder from GitHub.
name
axiom-alerting
description
Create and manage Axiom monitors and notifiers via the v2 public API. Use when building alerting, routing notifications, validating monitor behavior, and maintaining alert configurations end-to-end.

Axiom Alerting

You manage alerting in Axiom end-to-end: notifiers for routing and monitors for detection.

API Overview

Base URL: https://api.axiom.co/v2/ with Bearer token auth from .axiom.toml (project root or ~/.axiom.toml).

Monitors (/v2/monitors)
OperationMethodPath
ListGET/v2/monitors
GetGET/v2/monitors/{id}
HistoryGET/v2/monitors/{id}/history
CreatePOST/v2/monitors
UpdatePUT/v2/monitors/{id}
DeleteDELETE/v2/monitors/{id}
Notifiers (/v2/notifiers)
OperationMethodPath
ListGET/v2/notifiers
GetGET/v2/notifiers/{id}
CreatePOST/v2/notifiers
UpdatePUT/v2/notifiers/{id}
DeleteDELETE/v2/notifiers/{id}

Prerequisites

  1. Run scripts/setup
  2. Ensure .axiom.toml has a deployment:
toml
[deployments.prod]
url = "https://api.axiom.co"
token = "xaat-your-token"
org_id = "your-org-id"

Scripts

Core:

  • scripts/axiom-api <deploy> <method> <path> [body]

Monitor scripts:

  • scripts/monitor-list <deployment> [--json]
  • scripts/monitor-get <deployment> <id>
  • scripts/monitor-history <deployment> <id> <startTime> <endTime>
  • scripts/monitor-create <deployment> <json-file>
  • scripts/monitor-update <deployment> <id> <json-file>
  • scripts/monitor-delete <deployment> <id>

Notifier scripts:

  • scripts/notifier-list <deployment> [--json]
  • scripts/notifier-get <deployment> <id>
  • scripts/notifier-create <deployment> <json-file>
  • scripts/notifier-update <deployment> <id> <json-file>
  • scripts/notifier-delete <deployment> <id>
  1. Create notifier first.
  2. Create monitor and set notifierIds.
  3. Validate monitor behavior with monitor-history.
  4. Iterate monitor thresholds and schedule.

Workflow: End-To-End Alerting

  1. Run scripts/setup.
  2. List existing notifiers with scripts/notifier-list <deployment> and reuse one if appropriate.
  3. If no suitable notifier exists, create one with scripts/notifier-create.
  4. Create or update the monitor with notifierIds attached.
  5. Validate with scripts/monitor-history <deployment> <id> <startTime> <endTime>.
  6. If behavior is noisy or silent, tune threshold, rangeMinutes, intervalMinutes, and N-of-M trigger fields.
  7. Re-check history after each change.

Best Practices

  • Configure one channel per notifier.
  • Use emails (not recipients) for email notifier payloads.
  • Prefer triggerAfterNPositiveResults/triggerFromNRuns for noisy signals.
  • Use explicit bin() in monitor queries; avoid bin_auto() for alert logic.
  • For metrics-backed monitors, prefer mplQuery for definitions; API responses may include both aplQuery and mplQuery.

Monitor Types And Operators

Monitor types:

  • Threshold
  • MatchEvent
  • AnomalyDetection

Operators:

  • Above
  • Below
  • AboveOrEqual
  • BelowOrEqual
  • AboveOrBelow

Monitor Field Reference

Core fields:

  • name: Human-readable monitor name.
  • type: Threshold, MatchEvent, or AnomalyDetection.
  • aplQuery / mplQuery: Query evaluated by the monitor.
  • notifierIds: Array of notifier IDs to notify.
  • disabled: Whether monitor is disabled.
  • disabledUntil: Optional timestamp for temporary disable/snooze.
  • description: Optional monitor description.

Threshold and evaluation fields:

  • operator: Threshold comparison operator.
  • threshold: Numeric threshold value.
  • rangeMinutes: Query evaluation window in minutes.
  • intervalMinutes: Evaluation cadence in minutes.
  • alertOnNoData: Whether no-data should trigger alerting.
  • triggerAfterNPositiveResults: Positive evaluations required before firing.
  • triggerFromNRuns: Total evaluation runs considered for N-of-M logic.

Advanced behavior fields:

  • resolvable: Whether alerts can resolve automatically.
  • notifyByGroup: Notify per group key/value result.
  • notifyEveryRun: Notify on every positive evaluation.
  • skipResolved: Skip sending resolved notifications.
  • secondDelay: Delay (seconds) to tolerate late-arriving data.

Type-specific fields:

  • columnName: Field used by some anomaly/value-anomaly monitors.
Show full SKILL.md (263 more words)Show less

Minimal Valid Monitor Examples

Threshold:

json
{
  "name": "High Error Count",
  "type": "Threshold",
  "aplQuery": "['logs'] | where status >= 500 | summarize count()",
  "operator": "Above",
  "threshold": 100,
  "rangeMinutes": 5,
  "intervalMinutes": 5,
  "notifierIds": ["notifier-id"],
  "triggerAfterNPositiveResults": 2,
  "triggerFromNRuns": 3,
  "disabled": false
}

MatchEvent:

json
{
  "name": "Error Event Match",
  "type": "MatchEvent",
  "aplQuery": "['logs'] | where level == 'error'",
  "rangeMinutes": 5,
  "intervalMinutes": 5,
  "notifierIds": ["notifier-id"],
  "disabled": false
}

AnomalyDetection:

json
{
  "name": "CPU Anomaly",
  "type": "AnomalyDetection",
  "aplQuery": "['metrics'] | summarize avg(cpu_usage)",
  "columnName": "cpu_usage",
  "operator": "AboveOrBelow",
  "rangeMinutes": 5,
  "intervalMinutes": 5,
  "notifierIds": ["notifier-id"],
  "disabled": false
}

Minimal Valid Notifier Examples

Email:

json
{
  "name": "Oncall Email",
  "properties": {
    "email": {
      "emails": ["oncall@example.com"]
    }
  }
}

Slack:

json
{
  "name": "Oncall Slack",
  "properties": {
    "slack": {
      "slackUrl": "https://hooks.slack.com/services/T.../B.../XXX"
    }
  }
}

Custom webhook:

json
{
  "name": "Oncall Custom Webhook",
  "properties": {
    "customWebhook": {
      "url": "https://api.example.com/alerts",
      "body": "{\"action\":\"{{.Action}}\",\"monitorID\":\"{{.MonitorID}}\"}"
    }
  }
}

Troubleshooting

401 Unauthorized:

  • Cause: invalid or expired token.
  • Fix:
    • Verify token in ~/.axiom.toml.
    • Re-run scripts/setup and retry:
      • scripts/notifier-list <deployment>

403 Forbidden:

  • Cause: token lacks required permissions.
  • Fix:
    • Create/assign token scopes for monitor/notifier management and dataset query access.
    • Retry:
      • scripts/monitor-list <deployment>

404 Not Found on get/update/delete:

  • Cause: wrong monitor/notifier ID or wrong deployment/org.
  • Fix:
    • Confirm deployment in .axiom.toml.
    • Re-list objects and use exact IDs:
      • scripts/monitor-list <deployment> --json
      • scripts/notifier-list <deployment> --json

400 Bad Request on notifier create/update:

  • Cause: invalid notifier payload shape.
  • Fix:
    • Use one notifier channel inside properties.
    • For email, use emails (not recipients).
    • Validate against a known-good example and retry:
      • scripts/notifier-create <deployment> <json-file>

400 Bad Request on monitor create/update:

  • Cause: invalid monitor schema, operator/type mismatch, or invalid query fields.
  • Fix:
    • Validate required fields: name, type, query field, schedule, and notifierIds.
    • Confirm operator matches monitor type and threshold logic.
    • Retry:
      • scripts/monitor-create <deployment> <json-file>
      • scripts/monitor-update <deployment> <id> <json-file>

Monitor created but never alerts:

  • Cause: threshold too strict, wrong query window, or not enough positive runs.
  • Fix:
    • Inspect history over a known active period:
      • scripts/monitor-history <deployment> <id> <startTime> <endTime>
    • Reduce threshold or widen rangeMinutes.
    • Tune triggerAfterNPositiveResults/triggerFromNRuns.

Too many alerts (noisy monitor):

  • Cause: threshold too low or interval too short.
  • Fix:
    • Increase threshold.
    • Increase triggerAfterNPositiveResults and/or triggerFromNRuns.
    • Increase intervalMinutes or narrow match conditions.

Notifier exists but no delivery:

  • Cause: destination config invalid (URL/key/channel/email list), or destination-side rejection.
  • Fix:
    • Fetch notifier and verify destination fields:
      • scripts/notifier-get <deployment> <id>
    • Recreate/update notifier with corrected properties:
      • scripts/notifier-update <deployment> <id> <json-file>
    • Confirm monitor references correct notifier IDs.

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 15 other files (scripts) in .agents/skills/axiom-alerting of openclaw/clawhub.

  • SKILL.md
  • .meta/.gitkeep
  • README.md
  • scripts/axiom-api
  • scripts/monitor-create
  • scripts/monitor-delete
  • scripts/monitor-get
  • scripts/monitor-history
  • scripts/monitor-list
  • scripts/monitor-update
  • scripts/notifier-create
  • scripts/notifier-delete
  • scripts/notifier-get
  • scripts/notifier-list
  • scripts/notifier-update
  • scripts/setup

Open the folder on GitHubat commit d044664

Compare with similar skills

Axiom Alerting Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Axiom Alerting Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Axiom Alerting Management this skillopenclaw/clawhub9.5k—~2.1kAutomated safety check: PassMIT
Mz Release SignoffMaterializeInc/materialize6.4k—~7.2kAutomated safety check: PassCustom licence
UI Architectopenobserve/openobserve22k—~16kAutomated safety check: NotesAGPL-3.0
KubeEye Cluster Inspectionkubesphere/kubesphere17k—~3.6kAutomated safety check: PassCustom licence
Docs Corpus Auditmicrosoft/apm4k—~2.6kAutomated safety check: PassMIT
SageMaker Production Defaultshuggingface/skills11k1 repos~6.9kAutomated safety check: PassApache-2.0

Similar skills

  • Mz Release Signoff

    MaterializeInc/materialize

    Verify a release candidate on the Grafana dashboards and sign off in release.

    6.4k GitHub stars~7.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • UI Architect

    openobserve/openobserve

    ALWAYS use this skill for ANY change to the OpenObserve web UI (web/) — even a single-line UI modification.

    22k GitHub stars~16k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • KubeEye Cluster Inspection

    kubesphere/kubesphere

    Deploys KubeEye on KubeSphere and writes InspectRule and InspectPlan resources to inspect cluster health, then retrieves the inspection reports.

    17k GitHub stars~3.6k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Docs Corpus Audit

    microsoft/apm

    Official

    A skill your agent uses to run a holistic regrounding pass on the entire microsoft/apm documentation corpus against current source code, page-by-page, and emit surgical fixes for stale claims.

    4k GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Deploys SageMaker endpoints with autoscaling, CloudWatch alarms and tags on by default, using scripts for real-time, scale-to-zero and async setups.

    11k GitHub starsUsed in 1 repo~6.9k tokens
    DevOps & CloudAuto-check passed
  • Queries live Prometheus metrics and manages Grafana dashboards as code for Happy's infrastructure, using the grafanactl CLI and the Grafana datasource proxy API.

    24k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from openclaw/clawhub

All 55 skills in this repo
  • Axiom Dashboard Builder

    openclaw/clawhub

    Designs and deploys Axiom dashboards through the API, choosing chart types and writing APL or metrics queries, with templates and migration notes for Splunk and Grafana.

    9.5k GitHub stars~4.9k tokensUpdated yesterday
    Auto-check passed
  • Axiom Cost Control

    openclaw/clawhub

    Finds unused data in Axiom by analyzing query patterns, then deploys a cost dashboard and ingest monitors to keep spend under the contract limit.

    9.5k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Axiom Metrics Query

    openclaw/clawhub

    Explores and queries OpenTelemetry metrics in Axiom MetricsDB, listing datasets, metrics and tags first and picking the right aggregation for each metric's type.

    9.5k GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Axiom SRE Investigator

    openclaw/clawhub

    Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.

    9.5k GitHub stars~7.1k tokensUpdated yesterday
    Auto-check passed
  • Axiom Eval Writer

    openclaw/clawhub

    Scaffolds evaluation suites for the Axiom AI SDK: eval files, scorers, flag schemas and axiom.config.ts, generated from plain descriptions of an AI capability.

    9.5k GitHub stars~4.1k tokensUpdated yesterday
    Auto-check: warnings
  • Drafts, previews, sends and records email for an existing ClawHub content rights case through the admin CLI, with a dry run and your sign-off before anything goes out.

    9.5k GitHub stars~984 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Axiom Alerting Management

What does Axiom Alerting Management do?

Creates and manages Axiom monitors and notifiers end to end through the v2 API, with scripts for each CRUD operation and a recommended create-validate-tune workflow. toml in the project root or home directory. It covers both resource types: monitors under /v2/monitors for detection, with list, get, history, create, update and delete operations, and notifiers under /v2/notifiers for routing alerts, with the same set minus history.

When should I use Axiom Alerting Management?

Axiom Alerting Management fits situations like: setting up a new alert in Axiom with its routing notifier; checking whether a monitor's threshold is too noisy or too quiet; updating or deleting an existing Axiom monitor or notifier.

How do I install Axiom Alerting Management in Claude Code?

Run `npx skills add openclaw/clawhub --skill axiom-alerting -a claude-code`. Or copy the skill folder (.agents/skills/axiom-alerting in openclaw/clawhub) into .claude/skills/axiom-alerting in your project. Claude Code loads it when a task matches its description.

How do I install Axiom Alerting Management in Codex?

Run `npx skills add openclaw/clawhub --skill axiom-alerting -a codex`. Or copy the skill folder (.agents/skills/axiom-alerting in openclaw/clawhub) into .agents/skills/axiom-alerting in your project. Codex loads it when a task matches its description.

Can I use Axiom Alerting Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/clawhub --skill axiom-alerting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/axiom-alerting, .gemini/skills/axiom-alerting, .github/skills/axiom-alerting and .opencode/skills/axiom-alerting in your project.

What does Axiom Alerting Management need to run?

SKILL.md names no scripts, command-line tools or credentials: Axiom Alerting Management is instructions for the agent only. Our summary lists: An Axiom API token in .axiom.toml; Bash, to run the bundled scripts.

Does Axiom Alerting Management access the network?

SKILL.md names 2 domains. In commands or code: api.axiom.co and hooks.slack.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Axiom Alerting Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Axiom Alerting Management use?

Axiom Alerting Management is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Axiom Alerting Management use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Axiom Alerting Management?

Skills that share tags, products or a category with Axiom Alerting Management: Mz Release Signoff (MaterializeInc/materialize, 6.4k stars), UI Architect (openobserve/openobserve, 22k stars), KubeEye Cluster Inspection (kubesphere/kubesphere, 17k stars) and Docs Corpus Audit (microsoft/apm, 4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Axiom Alerting Management?

openclaw (a GitHub organization) maintains it in openclaw/clawhub, which has 9,497 GitHub stars. The repository holds 55 skills in this directory. The repository was last updated on October 9, 2026.

Source: openclaw/clawhub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.