When multiple hosts alert simultaneously (burst), create a master YouTrack issue, run per-host triage, link children, analyze correlation, and escalate the master to Claude Code.

No licenceAuto-check: notes

Install Correlated Triage

skills CLI
$ npx skills add papadopouloskyriakos/agentic-chatops --skill correlated-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install papadopouloskyriakos/agentic-chatops correlated-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/papadopouloskyriakos/agentic-chatops.git skills-src && mkdir -p .claude/skills && cp -r skills-src/openclaw/skills/correlated-triage .claude/skills/correlated-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
correlated-triage
GitHub stars
107
Token cost
~390 tokens
SKILL.md length
162 words
Files
2
Skills in repo
17
Repo updated
First seen
Licence
None found

At a glance

When multiple hosts alert simultaneously (burst), create a master YouTrack issue, run per-host triage, link children, analyze correlation, and escalate the master to Claude Code.

  • Works in 5 steps: Create a MASTER YouTrack issue… → Run per-host triage (reusing… → Link each child issue as a subtask of… → …
  • SKILL.md covers Execution and CRITICAL RULES
  • Runs Shell scripts from its folder

What it does

Correlated Triage is an agent skill from papadopouloskyriakos/agentic-chatops. When multiple hosts alert simultaneously (burst), create a master YouTrack issue, run per-host triage, link children, analyze correlation, and escalate the master to Claude Code.

Its SKILL.md is about 390 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `correlated-triage.sh`).

The repository describes itself as: 3-tier agentic ChatOps (n8n + GPT-4o + Claude Code) implementing all 21 patterns from "Agentic Design Patterns" — solo operator managing 137 devices.

Example prompts

  • “/correlated-triage”

Requirements

  • A Bash shell
  • Pre-approved tools (allowed-tools): Bash

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Create a MASTER YouTrack issue summarizing the burst
  2. Run per-host triage (reusing infra-triage.sh) without individual escalation
  3. Link each child issue as a subtask of the master
  4. Post a correlation analysis comment on the master issue
  5. Escalate the MASTER issue only to Claude Code (Level 3)

What it can do on your machine

Read from SKILL.md and the folder at commit 473f057. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Correlated Triage loads about 390 tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 162 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~390

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:20
    ource /home/app-user/.openclaw/workspace/.env && ./skills/correlated-triage/correlated-triage.sh "<comma-separated-hosts
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 162 words (~390 tokens).

“When you receive a message containing correlated-triage.sh in #infra-nl-prod or #infra-gr-prod, you MUST immediately execute the triage using the exec tool. Do NOT ask questions — just execute.”

— opening of SKILL.md by papadopouloskyriakos
name
correlated-triage
allowed-tools
Bash
user-invocable
true

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in openclaw/skills/correlated-triage of papadopouloskyriakos/agentic-chatops.

  • SKILL.md
  • correlated-triage.sh

Open the folder on GitHubat commit 473f057

Compare with similar skills

Correlated Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Correlated Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Correlated Triage this skillpapadopouloskyriakos/agentic-chatops107—~390Automated safety check: NotesNone
Triaging Security Alerts In Splunkmukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Triage Dependabot Alertsactivepieces/activepieces25k—~2.9kAutomated safety check: PassCustom licence
Performing Alert Triage With Elastic Siemmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Triaging Issuespytorch/pytorch104k—~4.2kAutomated safety check: PassCustom licence
Issue Triagepaperclipai/paperclip100k—~1kAutomated safety check: PassMIT

Similar skills

  • Triaging Security Alerts In Splunk

    mukul975/Anthropic-Cybersecurity-Skills

    Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL…

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Triage Dependabot Alerts

    activepieces/activepieces

    Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and…

    25k GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Performing Alert Triage With Elastic Siem

    mukul975/Anthropic-Cybersecurity-Skills

    Perform systematic alert triage in Elastic Security SIEM—classifying, prioritizing, and investigating alerts using Kibana, ES|QL queries, and ECS-normalized data—to drive SOC analyst workflows.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Triaging Issues

    pytorch/pytorch

    Triages GitHub issues by routing to oncall teams, applying labels, and closing questions.

    104k GitHub stars~4.2k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Issue Triage

    paperclipai/paperclip

    Triage Paperclip inbox issues that are stale, blocked, in-review, or assigned-but-not-progressing, and decide a single next action per issue (resume, reassign, unblock, escalate, or close).

    100k GitHub stars~1k tokensUpdated today
    DevelopmentAuto-check passed
  • Triage

    pnpm/pnpm

    Triage an incoming GitHub issue against the pnpm codebase and related open issues, then apply exactly one implementation-readiness label using pnpm's state: taxonomy.

    37k GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed

More from papadopouloskyriakos/agentic-chatops

All 17 skills in this repo
  • Escalate To Claude

    papadopouloskyriakos/agentic-chatops

    Escalate a YouTrack issue to Claude Code (Tier 2) for CODE IMPLEMENTATION ONLY.

    107 GitHub stars~672 tokensUpdated 5 days ago
    Auto-check: notes
  • Netbox Lookup

    papadopouloskyriakos/agentic-chatops

    Look up infrastructure devices, VMs, IPs, VLANs, and interfaces from NetBox CMDB.

    107 GitHub stars~618 tokensUpdated 5 days ago
    Auto-check: notes
  • Youtrack Lookup

    papadopouloskyriakos/agentic-chatops

    Look up YouTrack issues by ID or list open issues. An agent skill from papadopouloskyriakos/agentic-chatops.

    107 GitHub stars~550 tokensUpdated 5 days ago
    Auto-check: notes
  • Playbook Lookup

    papadopouloskyriakos/agentic-chatops

    Query past incident resolutions from the knowledge base. An agent skill from papadopouloskyriakos/agentic-chatops.

    107 GitHub stars~363 tokensUpdated 5 days ago
    Auto-check: notes
  • Bootstrap

    papadopouloskyriakos/agentic-chatops

    Meta-skill chaining /specify → /constitute → /plan → /tasks → spec-validation → dispatch-ready.

    107 GitHub stars~837 tokensUpdated 5 days ago
    Auto-check: notes
  • Cross Tier Review

    papadopouloskyriakos/agentic-chatops

    Cross-tier review protocol — chain of verification for REVIEW REQUEST messages from Claude Code (Tier 2).

    107 GitHub stars~691 tokensUpdated 5 days ago
    Auto-check: notes

Questions about Correlated Triage

What does Correlated Triage do?

When multiple hosts alert simultaneously (burst), create a master YouTrack issue, run per-host triage, link children, analyze correlation, and escalate the master to Claude Code. Correlated Triage is an agent skill from papadopouloskyriakos/agentic-chatops. When multiple hosts alert simultaneously (burst), create a master YouTrack issue, run per-host triage, link children, analyze correlation, and escalate the master to Claude Code.

How do I install Correlated Triage in Claude Code?

Run `npx skills add papadopouloskyriakos/agentic-chatops --skill correlated-triage -a claude-code`. Or copy the skill folder (openclaw/skills/correlated-triage in papadopouloskyriakos/agentic-chatops) into .claude/skills/correlated-triage in your project. Claude Code loads it when a task matches its description.

How do I install Correlated Triage in Codex?

Run `npx skills add papadopouloskyriakos/agentic-chatops --skill correlated-triage -a codex`. Or copy the skill folder (openclaw/skills/correlated-triage in papadopouloskyriakos/agentic-chatops) into .agents/skills/correlated-triage in your project. Codex loads it when a task matches its description.

Can I use Correlated Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add papadopouloskyriakos/agentic-chatops --skill correlated-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/correlated-triage, .gemini/skills/correlated-triage, .github/skills/correlated-triage and .opencode/skills/correlated-triage in your project.

What does Correlated Triage need to run?

Going by SKILL.md and its folder, Correlated Triage needs a shell for the scripts in its folder. Our summary lists: A Bash shell. Its frontmatter pre-approves these tools: Bash.

Does Correlated Triage access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Correlated Triage safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Correlated Triage use?

No licence was found for Correlated Triage or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Correlated Triage use?

About 390 tokens (SKILL.md is roughly 1.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Correlated Triage?

Skills that share tags, products or a category with Correlated Triage: Triaging Security Alerts In Splunk (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Triage Dependabot Alerts (activepieces/activepieces, 25k stars), Performing Alert Triage With Elastic Siem (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Triaging Issues (pytorch/pytorch, 104k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Correlated Triage?

papadopouloskyriakos (a GitHub user) maintains it in papadopouloskyriakos/agentic-chatops, which has 107 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 6, 2026.

Source: papadopouloskyriakos/agentic-chatops on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.