Agent skill

Datadog Analysis

by PackmindHub in PackmindHub/packmind

Analyze Datadog error logs for Packmind production services (api-proprietary, frontend-proprietary), group them into patterns, root-cause against the codebase, and produce a structured bug report.

Apache-2.0Auto-check passedDevelopment

Install Datadog Analysis

skills CLI
$ npx skills add PackmindHub/packmind --skill datadog-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PackmindHub/packmind datadog-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PackmindHub/packmind.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/datadog-analysis .claude/skills/datadog-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
datadog-analysis
GitHub stars
317
Token cost
~1.6k tokens
SKILL.md length
734 words
Files
4 (incl. references)
Skills in repo
35
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyze Datadog error logs for Packmind production services (api-proprietary, frontend-proprietary), group them into patterns, root-cause against the codebase, and produce a structured bug report.

  • Works in 4 steps: Discover Error Patterns (all services in… → Deep Dive Each Error Group → Codebase Root Cause Analysis → …
  • Production logs
  • SKILL.md covers Prerequisites, Services, Parameters and Exclusions, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Datadog Analysis is an agent skill from PackmindHub/packmind. Analyze Datadog error logs for Packmind production services (api-proprietary, frontend-proprietary), group them into patterns, root-cause against the codebase, and produce a structured bug report. Triggers on Datadog, production logs, prod errors, service health, or periodic error reviews.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/datadog_mcp.md`, `references/known_patterns.md` and `references/report-template.md`).

It sits in Development, covering Root cause analysis and QA and bug reports. It works with Datadog, Docker, NGINX and Model Context Protocol. The repository describes itself as: Packmind seamlessly captures your engineering playbook and turns it into AI context, guardrails, and governance. The licence is Apache-2.0.

When your agent uses it

  • Production logs
  • Periodic error reviews

Example prompts

  • “/datadog-analysis”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Discover Error Patterns (all services in parallel)
  2. Deep Dive Each Error Group
  3. Codebase Root Cause Analysis
  4. Generate Report

What it can do on your machine

Read from SKILL.md and the folder at commit 8a10541. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Datadog Analysis loads about 1.6k tokens when it runs, and up to ~4.3k if it reads all its reference files. Until then it costs about 77 tokens; SKILL.md has 734 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PackmindHub/packmind at commit 8a10541, republished under its Apache-2.0 licence (© PackmindHub). 734 words, ~1,562 tokens.

Download SKILL.mdSave it as .claude/skills/datadog-analysis/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
datadog-analysis
description
Analyze Datadog error logs for Packmind production services (api-proprietary, frontend-proprietary), group them into patterns, root-cause against the codebase, and produce a structured bug report. Triggers on Datadog, production logs, prod errors, service health, or periodic error reviews.

Datadog Analysis

Analyze production error logs from Packmind Datadog services, group them into patterns, cross-reference stack traces with the codebase, and produce a structured markdown report with root causes and Datadog search patterns.

Prerequisites

  • The Datadog MCP server must be connected. If not connected, prompt the user to run /mcp first.
  • Read references/datadog_mcp.md before making any MCP tool calls for guidance on tool usage, gotchas, and known pitfalls.

Services

The analysis covers two production services. Each maps to a Datadog service name, a codebase location, and a Dockerfile:

Datadog serviceAppCodebaseDockerfileRuntime
api-proprietaryAPIapps/api/ + all packages/dockerfile/Dockerfile.apiNode.js (NestJS, TypeORM, Redis/ioredis, BullMQ)
frontend-proprietaryFrontendapps/frontend/dockerfile/Dockerfile.frontendNginx (static SPA serving)

Root cause analysis should trace errors back to source files in the monorepo. For Nginx (frontend), also check the Nginx configs in dockerfile/nginx.*.conf and the entrypoint dockerfile/nginx-entrypoint.sh.

Parameters

ParameterDefaultDescription
Days to analyze7Number of past days to look at. Override by user request (e.g., "last 3 days")

Exclusions

The following log patterns should be discarded and not included in the report. Skip them during pattern discovery and do not count them as errors:

  • (node:1) [DEP0060] DeprecationWarning: The util._extend API is deprecated. Please use Object.assign() instead. -- Known Node.js deprecation from a transitive dependency. Noise, not actionable. Filter with -DEP0060.

  • Nginx stale asset 404s (open() "/usr/share/nginx/html/assets/..." failed (2: No such file or directory)) -- Expected SPA behavior after deployments. Browsers with a cached index.html request old hashed JS chunks that no longer exist. Not a bug. Filter with -"No such file or directory" -"/assets/" on frontend-proprietary.

When filtering in Phase 1, exclude these patterns from the analysis by appending the exclusion terms to Datadog queries, or remove them during report consolidation.

Workflow

Phase 1: Discover Error Patterns (all services in parallel)

For each of the two services, launch two parallel MCP calls (4 calls total, all in parallel). If rate-limited by the MCP server, fall back to batching 2 calls per service sequentially.

Every Datadog MCP call requires a telemetry object with an intent string describing the call's purpose (e.g., {"intent": "Discover error patterns for api-proprietary over last 7 days"}). Keep intents concise and avoid including PII or secrets.

  1. Pattern discovery -- Use mcp__datadog-mcp__search_datadog_logs with:

    • query: service:{service_name} status:(error OR critical OR emergency)
    • from: now-{N}d (where N = number of days, default 7)
    • use_log_patterns: true
    • max_tokens: 10000
  2. Error message counts -- Use mcp__datadog-mcp__analyze_datadog_logs with:

    • filter: service:{service_name} status:(error OR critical OR emergency)
    • sql_query: SELECT message, count(*) as cnt FROM logs GROUP BY message ORDER BY cnt DESC LIMIT 50
    • from: now-{N}d
    • max_tokens: 10000

From these results, identify the distinct error groups per service. If a service has zero errors in the period, mention "No issues found" in the report and skip Phases 2-3 for that service.

Show full SKILL.md (278 more words)Show less
Phase 2: Deep Dive Each Error Group

For each distinct error group identified in Phase 1:

  1. Fetch raw logs -- Use search_datadog_logs with a targeted query to get full stack traces and context. Use extra_fields: ["*"] for tag metadata when useful.

  2. Get daily distribution -- Use analyze_datadog_logs with:

    • sql_query: SELECT DATE_TRUNC('day', timestamp) as day, count(*) as cnt FROM logs WHERE message LIKE '%<pattern>%' GROUP BY DATE_TRUNC('day', timestamp) ORDER BY DATE_TRUNC('day', timestamp)
  3. Count occurrences -- Use analyze_datadog_logs to get total unique occurrences grouped by message.

Parallelize independent MCP calls wherever possible to save time.

Frontend-Specific Notes

For frontend-proprietary, Nginx writes all error_log output (including [notice]) to stderr. Datadog classifies stderr as status:error. Filter out Nginx lifecycle noise:

  • Ignore patterns containing [notice] (worker start/stop, SIGQUIT, SIGCHLD, SIGIO) -- these are normal Nginx operations misclassified as errors
  • Focus on [error] (404s for missing files) and [alert] (permission issues, config errors)
Phase 3: Codebase Root Cause Analysis

For each application-level error (not infra/external):

Before grepping, consult references/known_patterns.md — if the error matches a catalogued pattern, jump straight to its entry point and skip to step 2.

  1. Grep for the error class or message in the codebase using the Grep tool (e.g., SpaceMembershipRequiredError, Recipe.*not found)
  2. Read the source files where the error is thrown
  3. Trace the call chain: error class -> service/use case -> controller/adapter
  4. Identify the root cause: missing error handling, wrong HTTP status, race condition, missing validation, Dockerfile misconfiguration, etc.

For frontend Nginx errors, check:

  • dockerfile/Dockerfile.frontend for permission/ownership issues
  • dockerfile/nginx.k8s.conf, dockerfile/nginx.k8s.no-ingress.conf, dockerfile/nginx.compose.conf for config issues
  • dockerfile/nginx-entrypoint.sh for entrypoint issues
Phase 4: Generate Report

Read references/report-template.md before writing the report for the output path, scaffold, severity ordering, occurrence labels, and final summary table.

© PackmindHub, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in .agents/skills/datadog-analysis of PackmindHub/packmind.

  • SKILL.md
  • references/datadog_mcp.md
  • references/known_patterns.md
  • references/report-template.md

Open the folder on GitHubat commit 8a10541

Compare with similar skills

Datadog Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Datadog Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Datadog Analysis this skillPackmindHub/packmind317—~1.6kAutomated safety check: PassApache-2.0
Agent Observability Trace Rcadatadog-labs/agent-skills177—~10kAutomated safety check: PassMIT
DeerFlow Smoke Testbytedance/deer-flow83k—~2.5kAutomated safety check: NotesMIT
Product Diagnosisamplitude/builder-skills159—~4kAutomated safety check: PassNone
AI Operationsmajiayu000/claude-skill-registry6661 repos~1.4kAutomated safety check: PassApache-2.0
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone

Similar skills

  • Agent Observability Trace Rca

    datadog-labs/agent-skills

    Root cause analysis on production LLM traces. An agent skill from datadog-labs/agent-skills.

    177 GitHub stars~10k tokensUpdated today
    DevelopmentAuto-check passed
  • DeerFlow Smoke Test

    bytedance/deer-flow

    Walks through an end-to-end smoke test of a DeerFlow deployment: pull the latest code, deploy with Docker or locally, verify services, run health checks and write a report.

    83k GitHub stars~2.5k tokensUpdated today
    Testing & QAAuto-check: notes
  • Product Diagnosis

    amplitude/builder-skills

    Diagnoses product health by cross-referencing Amplitude analytics (dashboards, charts, funnels, feedback, AI agent analytics), optionally Datadog (errors, latency, stack traces), and optionally…

    159 GitHub stars~4k tokensUpdated 2 mo ago
    Testing & QAAuto-check passed
  • AI Operations

    majiayu000/claude-skill-registry

    Configure Harness AI-powered operations (AIDA) via MCP. An agent skill from majiayu000/claude-skill-registry.

    666 GitHub starsUsed in 1 repo~1.4k tokens
    DevOps & CloudAuto-check passed
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Create Epic Recap

    DataDog/datadog-agent

    Official

    A skill your agent uses when an engineer or manager asks to recap, summarize, or post an update on a Jira Epic — a progress update for an in-progress Epic (how far along it is, what's shipped so…

    3.8k GitHub stars~5k tokensUpdated today
    DevelopmentAuto-check: notes

More from PackmindHub/packmind

All 35 skills in this repo
  • Michel CLI Demo Recorder

    PackmindHub/packmind

    Produce proof-of-execution demos of the Packmind CLI (packmind-cli) as terminal-styled images (colors and formatting preserved exactly), for embedding in a GitHub PR.

    317 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Michel UI Demo Recorder

    PackmindHub/packmind

    Record polished UI demo videos and screenshots of a running web app using Playwright MCP — for client deliverables, release notes, feature walkthroughs, or bug repros.

    317 GitHub stars~6.4k tokensUpdated today
    Auto-check passed
  • Packmind Create Skill

    PackmindHub/packmind

    Guide for creating effective skills. An agent skill from PackmindHub/packmind.

    317 GitHub stars~3.5k tokensUpdated today
    Auto-check: notes
  • Doc Audit

    PackmindHub/packmind

    Audit Packmind end-user documentation (apps/doc/) for broken links, outdated CLI references, non-existent concepts, misleading information, and missing coverage.

    317 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Feature Sprint

    PackmindHub/packmind

    Execute the implementation plan produced by /feature-spec. An agent skill from PackmindHub/packmind.

    317 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Review an implemented GitHub issue the way a senior Packmind engineer would — the human-judgment checks that ESLint, the TypeScript compiler, and e2e tests cannot catch (authorization scoping…

    317 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Questions about Datadog Analysis

What does Datadog Analysis do?

Analyze Datadog error logs for Packmind production services (api-proprietary, frontend-proprietary), group them into patterns, root-cause against the codebase, and produce a structured bug report. Datadog Analysis is an agent skill from PackmindHub/packmind. Analyze Datadog error logs for Packmind production services (api-proprietary, frontend-proprietary), group them into patterns, root-cause against the codebase, and produce a structured bug report.

When should I use Datadog Analysis?

Datadog Analysis fits situations like: production logs; periodic error reviews.

How do I install Datadog Analysis in Claude Code?

Run `npx skills add PackmindHub/packmind --skill datadog-analysis -a claude-code`. Or copy the skill folder (.agents/skills/datadog-analysis in PackmindHub/packmind) into .claude/skills/datadog-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Datadog Analysis in Codex?

Run `npx skills add PackmindHub/packmind --skill datadog-analysis -a codex`. Or copy the skill folder (.agents/skills/datadog-analysis in PackmindHub/packmind) into .agents/skills/datadog-analysis in your project. Codex loads it when a task matches its description.

Can I use Datadog Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PackmindHub/packmind --skill datadog-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/datadog-analysis, .gemini/skills/datadog-analysis, .github/skills/datadog-analysis and .opencode/skills/datadog-analysis in your project.

What does Datadog Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Datadog Analysis is instructions for the agent only. Our summary lists: Node.js.

Does Datadog Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Datadog Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Datadog Analysis use?

Datadog Analysis is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Datadog Analysis use?

About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.8k tokens, read only when the agent opens those files.

What are the alternatives to Datadog Analysis?

Skills that share tags, products or a category with Datadog Analysis: Agent Observability Trace Rca (datadog-labs/agent-skills, 177 stars), DeerFlow Smoke Test (bytedance/deer-flow, 83k stars), Product Diagnosis (amplitude/builder-skills, 159 stars) and AI Operations (majiayu000/claude-skill-registry, 666 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Datadog Analysis?

PackmindHub (a GitHub organization) maintains it in PackmindHub/packmind, which has 317 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 8, 2026.

Source: PackmindHub/packmind on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.