Agent skill

Cost Anomaly

by ruvnet in ruvnet/ruflo

MAD-based outlier detection on session spend. An agent skill from ruvnet/ruflo.

MITAuto-check: notesData & Analytics

Install Cost Anomaly

skills CLI
$ npx skills add ruvnet/ruflo --skill cost-anomaly -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ruvnet/ruflo cost-anomaly --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ruvnet/ruflo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ruflo-cost-tracker/skills/cost-anomaly .claude/skills/cost-anomaly && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cost-anomaly
GitHub stars
74k
Token cost
~935 tokens
SKILL.md length
303 words
Files
1
Skills in repo
265
Repo updated
First seen
Licence
MIT

At a glance

MAD-based outlier detection on session spend. An agent skill from ruvnet/ruflo.

  • Works in 5 steps: Read all session-* records from… → Filter to --since window (default:… → Compute median(total_cost_usd) and MAD =… → …
  • Tasks that involve Data cleaning
  • SKILL.md covers Algorithm, Why MAD and not mean + sigma?, Smoke transcript (5 baseline… and Exit codes, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cost Anomaly is an agent skill from ruvnet/ruflo. MAD-based outlier detection on session spend. Robust to the very outliers it hunts (unlike mean+sigma). Surfaces specific anomalous sessions with modified-z scores; optional --alert-on-outliers exit code for CI gates. Distinct from cost-burn (aggregate trend) — this answers "which INDIVIDUAL session is the outlier?".

Its SKILL.md is about 940 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Data & Analytics, covering Data cleaning. The repository describes itself as: 🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory…. The licence is MIT.

When your agent uses it

  • Tasks that involve Data cleaning

Example prompts

  • “which INDIVIDUAL session is the outlier?”
  • “/cost-anomaly”

Requirements

  • Pre-approved tools (allowed-tools): Bash

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read all session-* records from cost-tracking namespace.
  2. Filter to --since window (default: all-time).
  3. Compute median(total_cost_usd) and MAD = median(|x - median|).
  4. Per-session modified z-score (Iglewicz-Hoaglin 1993)
  5. Flag sessions with |z| > --threshold (default 3.5).

What it can do on your machine

Read from SKILL.md and the folder at commit 6c04654. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cost Anomaly loads about 935 tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 303 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~935

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ruvnet/ruflo at commit 6c04654, republished under its MIT licence (© ruvnet). 303 words, ~935 tokens.

Download SKILL.mdSave it as .claude/skills/cost-anomaly/SKILL.md (or your agent's skills folder).
name
cost-anomaly
description
MAD-based outlier detection on session spend. Robust to the very outliers it hunts (unlike mean+sigma). Surfaces specific anomalous sessions with modified-z scores; optional --alert-on-outliers exit code for CI gates. Distinct from cost-burn (aggregate trend) — this answers "which INDIVIDUAL session is the outlier?".
allowed-tools
Bash
argument-hint
[--since 7d] [--threshold 3.5] [--alert-on-outliers N] [--format table|json]

Per-session outlier detection — the diagnostic counterpart to cost-burn's aggregate-trend signal.

QuestionSkill
"Is the AGGREGATE rate accelerating?"cost-burn
"Which SPECIFIC sessions are anomalous outliers?"cost-anomaly ← this
"Could we have spent less in aggregate?"cost-counterfactual
"When will we hit budget?"cost-projection

Algorithm

Implementation: scripts/anomaly.mjs.

  1. Read all session-* records from cost-tracking namespace.
  2. Filter to --since window (default: all-time).
  3. Compute median(total_cost_usd) and MAD = median(|x - median|).
  4. Per-session modified z-score (Iglewicz-Hoaglin 1993): z = 0.6745 * (x - median) / MAD
  5. Flag sessions with |z| > --threshold (default 3.5).

Why MAD and not mean + sigma?

ApproachWhat breaks
mean + sigmaA single $50 session inflates BOTH mean and sigma so badly that subsequent outliers hide inside the new "normal" band. Catastrophic on small samples.
median + MADBoth estimators ignore up to 50% of the data — the outliers themselves can't shift them. Robust on n=10. The canonical cutoff |z| > 3.5 is from Iglewicz-Hoaglin (1993).

Smoke transcript (5 baseline sessions $0.08-$0.12 + 1 outlier $5.00)

| Sessions considered | 5 |
| Threshold (|modified z|) | 3.5 |
| Median spend | $0.100000 |
| MAD | $0.010000 |
| Min / Max | $0.080000 / $5.000000 |
| **Outliers found** | **1** |

## Outlier sessions
| Session | Spend | Deviation | Modified z | Direction |
| outlier- | $5.000000 | +$4.900000 | 330.505 | high |

Exit codes

$ cost anomaly --alert-on-outliers 1
⚠ ALERT: found 1 outlier session(s) (|modified z| > 3.5); threshold was ≥1
exit 1

$ cost anomaly --alert-on-outliers 5
✓ found 1 outlier session(s); under threshold ≥5 — OK
exit 0

CI integration

bash
# Fail the build if any session this week is a >3.5σ outlier
cost anomaly --since 7d --alert-on-outliers 1 || investigate-bad-session

Most useful when paired with cost-burn:

bash
cost burn  --alert-on-acceleration-pct 50  || page-oncall   # rate-of-change alert
cost anomaly --alert-on-outliers 1         || investigate   # point-anomaly alert

Together they cover "is the average shifting?" AND "is there a single rogue session?" — both can fire independently.

Edge cases

  • n < 3: emit "Insufficient data" message, exit 0. MAD on 1-2 samples is meaningless.
  • MAD = 0: ≥50% of sessions share the exact same spend, so z-scores collapse. Emit explainer instead of dividing by zero. Common cause: dry-run sessions all at $0.
  • Low-direction outliers: usually crashed or dropped sessions, not over-spending. The output table explicitly labels direction so operators interpret correctly.
  • Very small MAD: even tiny absolute deviations produce huge z-scores. The $5 outlier with MAD=$0.01 yields z=330 — that's correct, not a bug.

Direction column

DirectionLikely causeAction
highLong session, stuck in expensive tier, or runaway loopcost report + cost conversation to investigate
lowCrash, dropped session, or unfinished workVerify the session completed normally

© ruvnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/ruflo-cost-tracker/skills/cost-anomaly of ruvnet/ruflo.

Open the folder on GitHubat commit 6c04654

Compare with similar skills

Cost Anomaly next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cost Anomaly compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cost Anomaly this skillruvnet/ruflo74k—~935Automated safety check: NotesMIT
Question2reportrefraction-ray/xalpha2.7k—~3.2kAutomated safety check: PassMIT
Dingo VerifyMigoXLab/dingo757—~741Automated safety check: NotesApache-2.0
Data Validationplatonai/Browser41.2k—~896Automated safety check: PassApache-2.0
Pandas ProJeffallan/claude-skills12k1 repos~1.5kAutomated safety check: PassMIT
Issues DeduplicationJetBrains/ideavim10k—~1.3kAutomated safety check: PassMIT

Similar skills

  • Question2report

    refraction-ray/xalpha

    Turn a natural-language financial question into a polished, self-contained HTML report.

    2.7k GitHub stars~3.2k tokensUpdated 2 mo ago
    Data & AnalyticsAuto-check passed
  • Dingo Verify

    MigoXLab/dingo

    A skill your agent uses when the user wants to fact-check an article or verify factual claims in a document.

    757 GitHub stars~741 tokensUpdated yesterday
    Data & AnalyticsAuto-check: notes
  • Data Validation

    platonai/Browser4

    Validates data against common and custom rules (required fields, formats, ranges).

    1.2k GitHub stars~896 tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Pandas Pro

    Jeffallan/claude-skills

    Handles pandas DataFrame work: cleaning, merging, groupby aggregation, pivots, time-series resampling and memory tuning, with checks on dtypes, shapes and nulls.

    12k GitHub starsUsed in 1 repo~1.5k tokens
    Data & AnalyticsAuto-check passed
  • Issues Deduplication

    JetBrains/ideavim

    Official

    Handles deduplication of YouTrack issues. An agent skill from JetBrains/ideavim.

    10k GitHub stars~1.3k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Openbb Data Fetcher

    monarchjuno/vibe-investing

    Fetch financial, market, economic, fundamental, news, options, crypto, ETF, index, and macro data through the OpenBB Python interface instead of the OpenBB MCP server.

    299 GitHub stars~2.9k tokensUpdated 5 mo ago
    Data & AnalyticsAuto-check: notes

More from ruvnet/ruflo

All 265 skills in this repo
  • Stores, searches, and retrieves successful patterns with HNSW-indexed semantic search so agents can reuse past solutions instead of relearning them.

    74k GitHub starsUsed in 2 repos~830 tokens
    Auto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    Auto-check passed
  • Applies the SPARC method (specification, pseudocode, architecture, refinement, completion) with 17 specialized modes and multi-agent orchestration, from research to deployment.

    74k GitHub starsUsed in 2 repos~829 tokens
    Auto-check passed
  • Coordinates a hierarchical swarm of specialized agents through the claude-flow CLI for work that spans several files or modules at once.

    74k GitHub starsUsed in 2 repos~779 tokens
    Auto-check passed
  • Sets up and drives Ruflo, an npm-installed orchestration layer for multi-agent swarms, persistent memory, routing, hooks and its MCP tool catalog.

    74k GitHub starsUsed in 1 repo~975 tokens
    Auto-check passed
  • Agent Coordination

    ruvnet/ruflo

    Reference for spawning, listing, monitoring and stopping agents with claude-flow commands, with agent type families, routing codes and coordination tips.

    74k GitHub starsUsed in 2 repos~519 tokens
    Auto-check passed

Questions about Cost Anomaly

What does Cost Anomaly do?

MAD-based outlier detection on session spend. An agent skill from ruvnet/ruflo. Cost Anomaly is an agent skill from ruvnet/ruflo. MAD-based outlier detection on session spend.

When should I use Cost Anomaly?

Cost Anomaly fits situations like: tasks that involve Data cleaning.

How do I install Cost Anomaly in Claude Code?

Run `npx skills add ruvnet/ruflo --skill cost-anomaly -a claude-code`. Or copy the skill folder (plugins/ruflo-cost-tracker/skills/cost-anomaly in ruvnet/ruflo) into .claude/skills/cost-anomaly in your project. Claude Code loads it when a task matches its description.

How do I install Cost Anomaly in Codex?

Run `npx skills add ruvnet/ruflo --skill cost-anomaly -a codex`. Or copy the skill folder (plugins/ruflo-cost-tracker/skills/cost-anomaly in ruvnet/ruflo) into .agents/skills/cost-anomaly in your project. Codex loads it when a task matches its description.

Can I use Cost Anomaly in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ruvnet/ruflo --skill cost-anomaly -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cost-anomaly, .gemini/skills/cost-anomaly, .github/skills/cost-anomaly and .opencode/skills/cost-anomaly in your project.

What does Cost Anomaly need to run?

SKILL.md names no scripts, command-line tools or credentials: Cost Anomaly is instructions for the agent only. Its frontmatter pre-approves these tools: Bash.

Does Cost Anomaly access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cost Anomaly safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Cost Anomaly use?

Cost Anomaly is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cost Anomaly use?

About 935 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cost Anomaly?

Skills that share tags, products or a category with Cost Anomaly: Question2report (refraction-ray/xalpha, 2.7k stars), Dingo Verify (MigoXLab/dingo, 757 stars), Data Validation (platonai/Browser4, 1.2k stars) and Pandas Pro (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cost Anomaly?

ruvnet (a GitHub user) maintains it in ruvnet/ruflo, which has 74,222 GitHub stars. The repository holds 265 skills in this directory. The repository was last updated on October 10, 2026.

Source: ruvnet/ruflo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.