Official agent skill

Investigating Metric Anomalies

by PostHog in PostHog/posthog

Investigates server/infrastructure metric anomalies in PostHog Metrics — from "this metric is rising/dropping/spiking" or a fired alert to a probable cause with evidence.

OfficialCustom licenceAuto-check passedDevOps & Cloud

Install Investigating Metric Anomalies

skills CLI
$ npx skills add PostHog/posthog --skill investigating-metric-anomalies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PostHog/posthog investigating-metric-anomalies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PostHog/posthog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/products/metrics/skills/investigating-metric-anomalies .claude/skills/investigating-metric-anomalies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
investigating-metric-anomalies
GitHub stars
40k
Token cost
~1.5k tokens
SKILL.md length
750 words
Files
1
Skills in repo
254
Repo updated
First seen
Licence
Custom licence

At a glance

Investigates server/infrastructure metric anomalies in PostHog Metrics — from "this metric is rising/dropping/spiking" or a fired alert to a probable cause with evidence.

  • Works in 5 steps: Pin down the metric → Characterize first — one call, three… → Sharpen with targeted metric queries → …
  • Asked why a metric looks wrong (ingestion lag rising
  • SKILL.md covers The loop, Worked example: "ingestion lag… and Pitfalls
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Investigating Metric Anomalies is an agent skill from PostHog/posthog, published by the product's own GitHub organization. Investigates server/infrastructure metric anomalies in PostHog Metrics — from "this metric is rising/dropping/spiking" or a fired alert to a probable cause with evidence. Use when asked why a metric looks wrong (ingestion lag rising, error rate spiking, latency degrading, queue depth growing, throughput dropping), when an alert fires on an OTel/Prometheus metric, or for any incident triage that starts from a metric symptom. Composes characterize-metric-anomaly, query-metrics, and metric-names-list with logs…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Monitoring and alerting and Root cause analysis. It works with PostHog, OpenTelemetry and Prometheus. The repository describes itself as: :hedgehog: PostHog is the leading platform for building self-driving products. Our developer tools – AI observability, analytics, session replay, flags, experiments, error…

When your agent uses it

  • Asked why a metric looks wrong (ingestion lag rising
  • Error rate spiking
  • Latency degrading
  • Queue depth growing

Example prompts

  • “this metric is rising/dropping/spiking”
  • “Use the investigating-metric-anomalies skill to investigate server/infrastructure metric anomalies in PostHog Metrics — from "this metric is…”
  • “/investigating-metric-anomalies”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Pin down the metric
  2. Characterize first — one call, three answers
  3. Sharpen with targeted metric queries
  4. Correlate across signals at the onset
  5. Conclude with evidence, not vibes

What it can do on your machine

Read from SKILL.md and the folder at commit c012c8d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Investigating Metric Anomalies loads about 1.5k tokens when it runs. Until then it costs about 156 tokens; SKILL.md has 750 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~156
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 750 words (~1,483 tokens).

“The job: go from a metric symptom ("ingestion lag is rising") to a probable cause with evidence, fast. The metric tells you what and when; logs and traces tell you why. Follow the loop below — it front-loads the cheap…”

— opening of SKILL.md by PostHog, Custom licence
name
investigating-metric-anomalies

Read the full SKILL.md on GitHub

Files

Just SKILL.md in products/metrics/skills/investigating-metric-anomalies of PostHog/posthog.

Open the folder on GitHubat commit c012c8d

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in PostHog/posthog, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Investigating Metric Anomalies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Investigating Metric Anomalies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Investigating Metric Anomalies this skillPostHog/posthog40k—~1.5kAutomated safety check: PassCustom licence
UModel Root Cause Analysisalibaba/UnifiedModel415—~1.9kAutomated safety check: PassCustom licence
Signozqjoly/GitOps112—~6.1kAutomated safety check: PassWTFPL
Developing Funboost Mixinydf0509/funboost895—~2.1kAutomated safety check: PassNone
Archestra Dev Observabilityarchestra-ai/archestra4.4k—~1.2kAutomated safety check: PassCustom licence
Frontmcp Observabilityagentfront/frontmcp146—~4.6kAutomated safety check: PassApache-2.0

Similar skills

  • UModel Root Cause Analysis

    alibaba/UnifiedModel

    Investigates a service incident to its root cause by querying a UModel object graph alongside metrics, logs, topology and recent deployments.

    415 GitHub stars~1.9k tokensUpdated 17 days ago
    DevOps & CloudAuto-check passed
  • Signoz

    qjoly/GitOps

    Manage the self-hosted SigNoz observability stack in this GitOps repo.

    112 GitHub stars~6.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • 当需要为 funboost 创建 Consumer 或 Publisher 的 Mixin 扩展类时使用。触发场景:添加监控、熔断、限流、链路追踪等横切关注点,编写自定义前置/后置处理钩子。关键词:mixin, consumeroverridecls, publisheroverridecls, ConsumerMixin, 自定义消费者, hook, 拦截器, 熔断器, 监控…

    895 GitHub stars~2.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Archestra Dev Observability

    archestra-ai/archestra

    A skill your agent uses when changing Archestra tracing, metrics, OpenTelemetry, Tempo, Grafana, Prometheus, LLM/MCP spans, observability labels, or local observability setup.

    4.4k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Frontmcp Observability

    agentfront/frontmcp

    A skill your agent uses when adding tracing, structured logging, metrics, or monitoring to a FrontMCP server.

    146 GitHub stars~4.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Monitoring Observability

    ahmedasmar/devops-claude-skills

    Monitoring and observability strategy, implementation, and troubleshooting.

    203 GitHub stars~3.9k tokensUpdated 6 mo ago
    DevOps & CloudAuto-check passed

More from PostHog/posthog

All 254 skills in this repo
  • Authoring Log Alerts

    PostHog/posthog

    Official

    Author useful, low-noise log alerts on services in a PostHog project.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Official

    Operating procedure for the conflict-autoresolver agent: sweep open PostHog/posthog PRs that conflict with master, resolve the trivial conflicts (generated artifacts deterministically, source…

    40k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Help users debug PostHog Error Tracking stack-trace symbolication for any supported platform — JavaScript/TypeScript web, React Native (Hermes), Android (Proguard / R8), or iOS / macOS (dSYM).

    40k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Exploring Apm Traces

    PostHog/posthog

    Official

    Investigates distributed application performance using PostHog APM (OpenTelemetry span) data via MCP.

    40k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Exploring LLM Traces

    PostHog/posthog

    Official

    Debug and inspect LLM/AI agent traces using PostHog's MCP tools.

    40k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Investigate Metric

    PostHog/posthog

    Official

    Diagnose why a product metric changed (dropped, spiked, or plateaued) by orchestrating breakdowns, actors, paths, lifecycle, retention, and annotations queries.

    40k GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Categories

Questions about Investigating Metric Anomalies

What does Investigating Metric Anomalies do?

Investigates server/infrastructure metric anomalies in PostHog Metrics — from "this metric is rising/dropping/spiking" or a fired alert to a probable cause with evidence. Investigating Metric Anomalies is an agent skill from PostHog/posthog, published by the product's own GitHub organization. Investigates server/infrastructure metric anomalies in PostHog Metrics — from "this metric is rising/dropping/spiking" or a fired alert to a probable cause with evidence.

When should I use Investigating Metric Anomalies?

Investigating Metric Anomalies fits situations like: asked why a metric looks wrong (ingestion lag rising; error rate spiking; latency degrading; queue depth growing.

How do I install Investigating Metric Anomalies in Claude Code?

Run `npx skills add PostHog/posthog --skill investigating-metric-anomalies -a claude-code`. Or copy the skill folder (products/metrics/skills/investigating-metric-anomalies in PostHog/posthog) into .claude/skills/investigating-metric-anomalies in your project. Claude Code loads it when a task matches its description.

How do I install Investigating Metric Anomalies in Codex?

Run `npx skills add PostHog/posthog --skill investigating-metric-anomalies -a codex`. Or copy the skill folder (products/metrics/skills/investigating-metric-anomalies in PostHog/posthog) into .agents/skills/investigating-metric-anomalies in your project. Codex loads it when a task matches its description.

Can I use Investigating Metric Anomalies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PostHog/posthog --skill investigating-metric-anomalies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/investigating-metric-anomalies, .gemini/skills/investigating-metric-anomalies, .github/skills/investigating-metric-anomalies and .opencode/skills/investigating-metric-anomalies in your project.

What does Investigating Metric Anomalies need to run?

SKILL.md names no scripts, command-line tools or credentials: Investigating Metric Anomalies is instructions for the agent only.

Does Investigating Metric Anomalies access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Investigating Metric Anomalies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Investigating Metric Anomalies use?

Investigating Metric Anomalies has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Investigating Metric Anomalies use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Investigating Metric Anomalies?

Skills that share tags, products or a category with Investigating Metric Anomalies: UModel Root Cause Analysis (alibaba/UnifiedModel, 415 stars), Signoz (qjoly/GitOps, 112 stars), Developing Funboost Mixin (ydf0509/funboost, 895 stars) and Archestra Dev Observability (archestra-ai/archestra, 4.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Investigating Metric Anomalies?

PostHog (a GitHub organization, an official publisher) maintains it in PostHog/posthog, which has 40,209 GitHub stars. The repository holds 254 skills in this directory. The repository was last updated on October 10, 2026.

Source: PostHog/posthog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.