Official agent skill

Authoring Log Alerts

by PostHog in PostHog/posthog

Author useful, low-noise log alerts on services in a PostHog project.

OfficialCustom licenceAuto-check passed

Install Authoring Log Alerts

skills CLI
$ npx skills add PostHog/posthog --skill authoring-log-alerts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PostHog/posthog authoring-log-alerts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PostHog/posthog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/products/logs/skills/authoring-log-alerts .claude/skills/authoring-log-alerts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authoring-log-alerts
GitHub stars
40k
Token cost
~3k tokens
SKILL.md length
1,143 words
Files
5 (incl. scripts, references)
Skills in repo
252
Repo updated
First seen
Licence
Custom licence

At a glance

Author useful, low-noise log alerts on services in a PostHog project.

  • Works in 6 steps: Triage — pick candidate services → (Optional) Narrow the filter → Baseline — characterise the candidate… → …
  • The user asks to set up alerts for their logs
  • SKILL.md covers When to use this skill, When not to use this skill, Tools and Workflow, plus 4 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Authoring Log Alerts is an agent skill from PostHog/posthog, published by the product's own GitHub organization. Author useful, low-noise log alerts on services in a PostHog project. Use when the user asks to set up alerts for their logs, suggest alerts they should add, or evaluate whether a service is worth monitoring. Covers service triage, baseline characterisation, threshold drafting, back-testing via simulate, and shipping with a notification destination.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `references/threshold-defaults.md`, `references/volume-floor-alerts.md` and `scripts/baseline_stats.py`).

It works with PostHog. The repository describes itself as: :hedgehog: PostHog is the leading platform for building self-driving products. Our developer tools – AI observability, analytics, session replay, flags, experiments, error…

When your agent uses it

  • The user asks to set up alerts for their logs
  • Suggest alerts they should add
  • Evaluate whether a service is worth monitoring

Example prompts

  • “/authoring-log-alerts”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Triage — pick candidate services
  2. (Optional) Narrow the filter
  3. Baseline — characterise the candidate over 7 days
  4. Draft and simulate
  5. Iterate — three rounds, then ship or skip
  6. Ship — create + attach destination

What it can do on your machine

Read from SKILL.md and the folder at commit 10f9ad7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authoring Log Alerts loads about 3k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 1,143 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,143 words (~3,039 tokens).

“Authoring an alert is a measurement problem, not a guessing problem. You are not trying to be exhaustive — you are trying to land thresholds that fire 0–3 times per week on real production patterns, on services that matter.”

— opening of SKILL.md by PostHog, Custom licence
name
authoring-log-alerts

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (scripts, references) in products/logs/skills/authoring-log-alerts of PostHog/posthog.

  • SKILL.md
  • references/threshold-defaults.md
  • references/volume-floor-alerts.md
  • scripts/baseline_stats.py
  • tests/test_baseline_stats.py

Open the folder on GitHubat commit 10f9ad7

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in PostHog/posthog, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Authoring Log Alerts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authoring Log Alerts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authoring Log Alerts this skillPostHog/posthog40k—~3kAutomated safety check: PassCustom licence
Opik Analytics Instrumentationcomet-ml/opik22k—~4.4kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Define Feature Flagmacro-inc/macro4.6k—~780Automated safety check: PassAGPL-3.0
Soku CLIAbout-Intelligence/soku-cli304—~2.4kAutomated safety check: PassMIT
Compare Array Bundle SizePostHog/posthog-js613—~599Automated safety check: PassCustom licence

Similar skills

  • Shows how to add product analytics events to Opik's frontend, Java backend and Python SDK, all reporting through Segment to PostHog with an opik_ name prefix.

    22k GitHub stars~4.4k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Define Feature Flag

    macro-inc/macro

    Define a frontend feature flag with defineFlag and wire its readers.

    4.6k GitHub stars~780 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Soku CLI

    About-Intelligence/soku-cli

    Guides an agent through the soku command line tool for ads, GA4 and PostHog data reads, ads writes, SEO hosting, automations, files and skill management.

    304 GitHub stars~2.4k tokensUpdated today
    Marketing & SEOAuto-check passed
  • Compare Array Bundle Size

    PostHog/posthog-js

    Official

    Quickly compare the posthog-js array.js bundle size in the current working tree against a git baseline using the repository's esbuild proxy.

    613 GitHub stars~599 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Telemetry Analytics

    OpenHands/OpenHands

    This skill should be used when the user asks to "add tracking", "add a PostHog event", "change telemetry consent", "instrument onboarding", "debug analytics", or changes telemetry.ts…

    90k GitHub stars~305 tokensUpdated today
    DevOps & CloudAuto-check passed

More from PostHog/posthog

All 252 skills in this repo
  • Official

    Operating procedure for the conflict-autoresolver agent: sweep open PostHog/posthog PRs that conflict with master, resolve the trivial conflicts (generated artifacts deterministically, source…

    40k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Help users debug PostHog Error Tracking stack-trace symbolication for any supported platform — JavaScript/TypeScript web, React Native (Hermes), Android (Proguard / R8), or iOS / macOS (dSYM).

    40k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Exploring Apm Traces

    PostHog/posthog

    Official

    Investigates distributed application performance using PostHog APM (OpenTelemetry span) data via MCP.

    40k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Exploring LLM Traces

    PostHog/posthog

    Official

    Debug and inspect LLM/AI agent traces using PostHog's MCP tools.

    40k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Investigate Metric

    PostHog/posthog

    Official

    Diagnose why a product metric changed (dropped, spiked, or plateaued) by orchestrating breakdowns, actors, paths, lifecycle, retention, and annotations queries.

    40k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • QA Team

    PostHog/posthog

    Official

    Multi-agent QA review team for code changes. An agent skill from PostHog/posthog.

    40k GitHub stars~4.6k tokensUpdated today
    Auto-check passed

Works with

Questions about Authoring Log Alerts

What does Authoring Log Alerts do?

Author useful, low-noise log alerts on services in a PostHog project. Authoring Log Alerts is an agent skill from PostHog/posthog, published by the product's own GitHub organization. Author useful, low-noise log alerts on services in a PostHog project.

When should I use Authoring Log Alerts?

Authoring Log Alerts fits situations like: the user asks to set up alerts for their logs; suggest alerts they should add; evaluate whether a service is worth monitoring.

How do I install Authoring Log Alerts in Claude Code?

Run `npx skills add PostHog/posthog --skill authoring-log-alerts -a claude-code`. Or copy the skill folder (products/logs/skills/authoring-log-alerts in PostHog/posthog) into .claude/skills/authoring-log-alerts in your project. Claude Code loads it when a task matches its description.

How do I install Authoring Log Alerts in Codex?

Run `npx skills add PostHog/posthog --skill authoring-log-alerts -a codex`. Or copy the skill folder (products/logs/skills/authoring-log-alerts in PostHog/posthog) into .agents/skills/authoring-log-alerts in your project. Codex loads it when a task matches its description.

Can I use Authoring Log Alerts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PostHog/posthog --skill authoring-log-alerts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authoring-log-alerts, .gemini/skills/authoring-log-alerts, .github/skills/authoring-log-alerts and .opencode/skills/authoring-log-alerts in your project.

What does Authoring Log Alerts need to run?

Going by SKILL.md and its folder, Authoring Log Alerts needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Authoring Log Alerts access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Authoring Log Alerts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Authoring Log Alerts use?

Authoring Log Alerts has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Authoring Log Alerts use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Authoring Log Alerts?

Skills that share tags, products or a category with Authoring Log Alerts: Opik Analytics Instrumentation (comet-ml/opik, 22k stars), C15t (c15t/c15t, 1.9k stars), Define Feature Flag (macro-inc/macro, 4.6k stars) and Soku CLI (About-Intelligence/soku-cli, 304 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authoring Log Alerts?

PostHog (a GitHub organization, an official publisher) maintains it in PostHog/posthog, which has 40,182 GitHub stars. The repository holds 252 skills in this directory. The repository was last updated on October 8, 2026.

Source: PostHog/posthog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.