Agent skill

Elasticsearch

by RightNow-AI in RightNow-AI/openfang

Elasticsearch expert for queries, mappings, aggregations, index management, and cluster operations

Apache-2.0Auto-check passedBackend & APIs

Install Elasticsearch

skills CLI
$ npx skills add RightNow-AI/openfang --skill elasticsearch -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install RightNow-AI/openfang elasticsearch --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/RightNow-AI/openfang.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crates/openfang-skills/bundled/elasticsearch .claude/skills/elasticsearch && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
elasticsearch
GitHub stars
18k
Token cost
~803 tokens
SKILL.md length
394 words
Files
1
Skills in repo
68
Repo updated
First seen
Licence
Apache-2.0

At a glance

Elasticsearch expert for queries, mappings, aggregations, index management, and cluster operations

  • Tasks that involve Search implementation
  • SKILL.md covers Key Principles, Techniques, Common Patterns and Pitfalls to Avoid
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Container orchestration

What it does

Elasticsearch is an agent skill from RightNow-AI/openfang. Elasticsearch expert for queries, mappings, aggregations, index management, and cluster operations

Its SKILL.md is about 800 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Search implementation and Container orchestration. It works with Elasticsearch. The repository describes itself as: Open-source Agent Operating System. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Search implementation
  • Tasks that involve Container orchestration

Example prompts

  • “/elasticsearch”

What it can do on your machine

Read from SKILL.md and the folder at commit acf2587. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Elasticsearch loads about 803 tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 394 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~803

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from RightNow-AI/openfang at commit acf2587, republished under its Apache-2.0 licence (© RightNow-AI). 394 words, ~803 tokens.

Download SKILL.mdSave it as .claude/skills/elasticsearch/SKILL.md (or your agent's skills folder).
name
elasticsearch
description
Elasticsearch expert for queries, mappings, aggregations, index management, and cluster operations

Elasticsearch Expert

A search and analytics specialist with deep expertise in Elasticsearch cluster architecture, query DSL, mapping design, and performance optimization. This skill provides production-grade guidance for building search experiences, log analytics pipelines, and time-series data platforms using the Elastic stack.

Key Principles

  • Design mappings explicitly before indexing data; relying on dynamic mapping leads to field type conflicts and bloated indices
  • Understand the difference between keyword fields (exact match, aggregations, sorting) and text fields (full-text search with analyzers)
  • Use index aliases for zero-downtime reindexing, canary deployments, and time-based index rotation
  • Size shards between 10-50 GB for optimal performance; too many small shards waste overhead, too few large shards limit parallelism
  • Monitor cluster health (green/yellow/red) continuously and investigate yellow status immediately, as it indicates unassigned replica shards

Techniques

  • Construct bool queries with must (scored AND), filter (unscored AND), should (OR with minimum_should_match), and must_not (exclusion) clauses
  • Use match queries for full-text search with analyzer-aware tokenization, and term queries for exact keyword lookups without analysis
  • Build aggregations: terms for top-N cardinality, date_histogram for time bucketing, nested for sub-document analysis, and pipeline aggs like cumulative_sum
  • Apply Index Lifecycle Management (ILM) policies with hot/warm/cold/delete phases to automate rollover and data retention
  • Reindex with POST _reindex using source/dest, applying scripts for field transformations during migration
  • Check cluster allocation with GET _cluster/allocation/explain to diagnose why shards remain unassigned
  • Tune search performance with the search profiler API, request caching, and pre-warming for frequently used queries
Show full SKILL.md (156 more words)Show less

Common Patterns

  • Search-as-you-type: Use the search_as_you_type field type or edge_ngram tokenizer with a match_phrase_prefix query for autocomplete experiences
  • Parent-Child Relationships: Use join field types for one-to-many relationships where child documents update independently, avoiding costly nested reindexing
  • Cross-cluster Search: Configure remote clusters and use cluster:index syntax to query across multiple Elasticsearch deployments transparently
  • Snapshot and Restore: Register a snapshot repository (S3, GCS, or filesystem) and schedule regular snapshots for disaster recovery with SLM policies

Pitfalls to Avoid

  • Do not use wildcard queries on text fields with leading wildcards, as they bypass the inverted index and cause full field scans
  • Do not index large documents (over 100 MB) without splitting them; they cause memory pressure during indexing and merging
  • Do not set number_of_replicas to 0 in production; replicas provide both search throughput and data redundancy
  • Do not update mappings on existing indices for incompatible type changes; create a new index with the correct mapping and reindex the data

© RightNow-AI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in crates/openfang-skills/bundled/elasticsearch of RightNow-AI/openfang.

Open the folder on GitHubat commit acf2587

Compare with similar skills

Elasticsearch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Elasticsearch compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Elasticsearch this skillRightNow-AI/openfang18k—~803Automated safety check: PassApache-2.0
Product Full-Text Searchlobehub/lobehub83k—~4.1kAutomated safety check: PassCustom licence
Foundatio Repositoriesexceptionless/Exceptionless2.5k—~1.9kAutomated safety check: PassApache-2.0
Elasticsearch Authnaspectrr/deer405—~1.2kAutomated safety check: NotesMIT
Elasticsearch Authzaspectrr/deer405—~1.8kAutomated safety check: PassMIT
Elasticsearch File Ingestaspectrr/deer405—~684Automated safety check: PassMIT

Similar skills

  • Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.

    83k GitHub stars~4.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Foundatio Repositories

    exceptionless/Exceptionless

    Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.

    2.5k GitHub stars~1.9k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Elasticsearch Authn

    aspectrr/deer

    Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.

    405 GitHub stars~1.2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check: notes
  • Elasticsearch Authz

    aspectrr/deer

    Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    405 GitHub stars~684 tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.

    405 GitHub stars~4.9k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed

More from RightNow-AI/openfang

All 68 skills in this repo
  • Reference of CSS selectors, step-by-step web workflows and error recovery tactics for an agent that browses, fills forms and compares prices on live sites.

    18k GitHub stars~1k tokensUpdated 3 mo ago
    Auto-check passed
  • Reference knowledge for open-source intelligence collection: the collection cycle, source reliability tiers, search query patterns and entity extraction.

    18k GitHub stars~2.1k tokensUpdated 3 mo ago
    Auto-check passed
  • Lead Generation Research Guide

    RightNow-AI/openfang

    Reference knowledge for AI lead generation: building an ideal customer profile, researching prospects on the web, enriching lead records and finding email formats.

    18k GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • Video Clipping Reference

    RightNow-AI/openfang

    Command reference for cutting clips from online video: yt-dlp downloads, whisper transcription, SRT subtitle files and ffmpeg processing, with Windows, macOS and Linux differences.

    18k GitHub stars~4.1k tokensUpdated 3 mo ago
    Auto-check: warnings
  • Forecasting Expert Knowledge

    RightNow-AI/openfang

    Reference knowledge for AI forecasting: superforecasting principles, a signal taxonomy, confidence calibration rules and reasoning chains for making and tracking predictions.

    18k GitHub stars~2.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Deep Research Methodology

    RightNow-AI/openfang

    Reference knowledge for AI deep research: a five-phase process, strategies by question type, CRAAP source scoring, cross-referencing, synthesis and citation formats.

    18k GitHub stars~2.6k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Categories

Questions about Elasticsearch

What does Elasticsearch do?

Elasticsearch expert for queries, mappings, aggregations, index management, and cluster operations. Elasticsearch is an agent skill from RightNow-AI/openfang.

When should I use Elasticsearch?

Elasticsearch fits situations like: tasks that involve Search implementation; tasks that involve Container orchestration.

How do I install Elasticsearch in Claude Code?

Run `npx skills add RightNow-AI/openfang --skill elasticsearch -a claude-code`. Or copy the skill folder (crates/openfang-skills/bundled/elasticsearch in RightNow-AI/openfang) into .claude/skills/elasticsearch in your project. Claude Code loads it when a task matches its description.

How do I install Elasticsearch in Codex?

Run `npx skills add RightNow-AI/openfang --skill elasticsearch -a codex`. Or copy the skill folder (crates/openfang-skills/bundled/elasticsearch in RightNow-AI/openfang) into .agents/skills/elasticsearch in your project. Codex loads it when a task matches its description.

Can I use Elasticsearch in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add RightNow-AI/openfang --skill elasticsearch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch, .gemini/skills/elasticsearch, .github/skills/elasticsearch and .opencode/skills/elasticsearch in your project.

What does Elasticsearch need to run?

SKILL.md names no scripts, command-line tools or credentials: Elasticsearch is instructions for the agent only.

Does Elasticsearch access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Elasticsearch safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Elasticsearch use?

Elasticsearch is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Elasticsearch use?

About 803 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Elasticsearch?

Skills that share tags, products or a category with Elasticsearch: Product Full-Text Search (lobehub/lobehub, 83k stars), Foundatio Repositories (exceptionless/Exceptionless, 2.5k stars), Elasticsearch Authn (aspectrr/deer, 405 stars) and Elasticsearch Authz (aspectrr/deer, 405 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Elasticsearch?

RightNow-AI (a GitHub organization) maintains it in RightNow-AI/openfang, which has 18,214 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on July 2, 2026.

Source: RightNow-AI/openfang on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.