Analyze GitHub Action Logs
withastro/astro
Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.
Audit trail register: timestamp, user, module, record, action, field changed, old and new value, and the reason for the change.
$ npx skills add sickn33/agentic-awesome-skills --skill audit-log -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills audit-log --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-log .claude/skills/audit-log && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-log" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/audit-log into .claude/skills/audit-log/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-log", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/audit-logType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill audit-log -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills audit-log --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/audit-log .agents/skills/audit-log && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-log" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/audit-log into .agents/skills/audit-log/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-log", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill audit-log -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills audit-log --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/audit-log .cursor/skills/audit-log && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-log" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/audit-log into .cursor/skills/audit-log/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-log", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/audit-log--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill audit-log -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills audit-log --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/audit-log .gemini/skills/audit-log && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-log" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/audit-log into .gemini/skills/audit-log/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-log", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills audit-logInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill audit-log -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/audit-log .github/skills/audit-log && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-log" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/audit-log into .github/skills/audit-log/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-log", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill audit-log -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills audit-log --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/audit-log .opencode/skills/audit-log && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-log" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/audit-log into .opencode/skills/audit-log/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-log", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-logAudit trail register: timestamp, user, module, record, action, field changed, old and new value, and the reason for the change.
Audit Log is an agent skill from sickn33/agentic-awesome-skills. Audit trail register: timestamp, user, module, record, action, field changed, old and new value, and the reason for the change. Use for change history and control evidence.
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml, csv, sql, json and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
json-schema.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Audit Log loads about 3.6k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 1,598 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit ec02547, republished under its MIT licence (© sickn33). 1,598 words, ~3,560 tokens.
.claude/skills/audit-log/SKILL.md (or your agent's skills folder).What it is: Compliance trail.
Works out the smallest useful Audit Log setup for the business in front of it, then builds it only when asked. The default output is a short recommendation, not a spreadsheet. Artifacts - CSV, SQL DDL, JSON Schema, Notion mapping - are produced on request, from one field list so they cannot drift apart.
Layer: Layer 7: Protect. Fits: Scale stage. Table code: n/a.
Also use it when the user says "compliance trail", or describes the same process happening in a spreadsheet, a document or someone inboxes.
Do not use it for: payroll calculation, tax filing, or legal advice. This skill produces empty templates only - it never holds or processes real employee or customer data.
Follow the shared execution contract. The module-specific rules below define only domain fields, decisions, calculations, and safety constraints.
Read the request and pick the intent before asking anything.
Ask only if this is the highest-value missing fact; otherwise proceed without an opener:
Q: What do you need to be able to prove?
Skip anything the user already answered, in any earlier message. Ask the rest one at a time, and stop as soon as the remaining answers would not change the output.
Never invent an answer. If the user does not know, record it as unknown and carry on.
Hold the answers in this shape. It stays internal - it is not shown to the user unless they ask, and it never carries a value the user did not give.
module: audit-log
intent: null # setup | advice | review | fix | build | convert | export
scale: null # Starter | Growth | Scale, only if the answer changes it
areas:
"Purpose": null
"Events": null
"Evidence": null
"Current process": null
"Outcome": null
requested_outputs: [] # csv | sql | json | notion | xlsx - requested formats only
confirmed_facts: [] # only what the user actually said
open_questions: [] # the unanswered ones, in the order worth askingIf an artifact was requested, build it after resolving essential missing facts. Otherwise give a short recommendation and offer the relevant artifact.
Recommended approach: Define the small set of events worth keeping and record who did what and when. Depth follows the question you need to answer.
Why this one: Audit logs become useless when everything is captured. Start from the question you need to answer, then record only what answers it.
Workflow: Event recorded → Actor and time → Stored → Periodically reviewed → Evidence produced
Once the user asks for it, derive the fields from the confirmed context and emit the requested artifacts. For machine-readable text, keep prose outside the data; for files, provide a usable link. Report material validation failures or limitations separately.
A selected Notion output is rendered by notion-manual-import, so route the
Notion step there. When the user selects Notion, hand that step to
@notion-manual-import: it holds the CSV, the property
mapping, the import steps and the verification checklist, and it renders the Field
Reference below instead of defining a table of its own. Do not restate the mapping
here and do not improvise the import steps. Manual CSV and mapping outputs need no
connection. For requested workspace changes, follow the shared contract: verify actual
tool access and the target before writing. A user saying "connected" is not tool evidence.
Never ask for a Notion password or token.
For an Excel-compatible CSV, use UTF-8 with a byte order mark so Excel opens the
text correctly. A CSV is not an .xlsx workbook; create .xlsx only when the user
requests a workbook.
A CSV carries no types, so after it, name the columns
that need a number, date or currency format applied.
Log Entry,Date and Time,User,Module,Record,Action,Field Changed,Old Value,New Value,Reason,Log ID
Policy updated,2026-01-15 09:30,Example User,Invoices & Billing,INV-EXAMPLE-001,Update,Status,Draft,Sent,Correction made after a review query,CREATE TABLE audit_log (
log_entry VARCHAR(255),
date_and_time TIMESTAMP NOT NULL,
user_account VARCHAR(255),
module VARCHAR(255),
record VARCHAR(255),
action VARCHAR(255),
field_changed VARCHAR(255),
old_value VARCHAR(255),
new_value VARCHAR(255),
reason VARCHAR(255),
log_id SERIAL PRIMARY KEY,
created_at TIMESTAMP DEFAULT NOW(),
updated_at TIMESTAMP DEFAULT NOW()
);{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"title": "Audit Log",
"type": "object",
"additionalProperties": false,
"properties": {
"Log Entry": { "type": "string" },
"Date and Time": { "type": "string", "format": "date-time" },
"User": { "type": "string" },
"Module": { "type": "string" },
"Record": { "type": "string" },
"Action": { "type": "string" },
"Field Changed": { "type": "string" },
"Old Value": { "type": "string" },
"New Value": { "type": "string" },
"Reason": { "type": "string" },
"Log ID": { "type": "integer" }
},
"required": [
"Date and Time"
]
}| CSV column | Notion property | Set after import |
|---|---|---|
| Log Entry | Title | Use as the database title |
| Date and Time | Date (include time) | Convert to Date (include time) |
| User | Text | Leave as Text |
| Module | Text | Leave as Text |
| Record | Text | Leave as Text |
| Action | Text | Leave as Text |
| Field Changed | Text | Leave as Text |
| Old Value | Text | Leave as Text |
| New Value | Text | Leave as Text |
| Reason | Text | Leave as Text |
| Log ID | Text (preserve source ID) | Keep imported IDs as Text; optionally add a separate Unique ID property |The rows above are documentation examples only. Emit empty templates unless the user explicitly requests examples. Money stays currency, dates stay date,
and anything pointing at another table stays relation.
| # | Field | Type | SQL | JSON Schema | Notion | CSV example |
|---|---|---|---|---|---|---|
| 1 | Log Entry | text | VARCHAR(255) | string | Text | Policy updated |
| 2 | Date and Time | datetime | TIMESTAMP | string, format: date-time | Date (include time) | 2026-01-15 09:30 |
| 3 | User | text | VARCHAR(255) | string | Text | Example User |
| 4 | Module | text | VARCHAR(255) | string | Text | Invoices & Billing |
| 5 | Record | text | VARCHAR(255) | string | Text | INV-EXAMPLE-001 |
| 6 | Action | text | VARCHAR(255) | string | Text | Update |
| 7 | Field Changed | text | VARCHAR(255) | string | Text | Status |
| 8 | Old Value | text | VARCHAR(255) | string | Text | Draft |
| 9 | New Value | text | VARCHAR(255) | string | Text | Sent |
| 10 | Reason | text | VARCHAR(255) | string | Text | Correction made after a review query |
| 11 | Log ID | id | SERIAL PRIMARY KEY | integer | Text (preserve source ID) | (blank) |
No Select fields.
Link fields: none
Prompt
When a client questioned an approval we had nothing to show.Context first - one question per message, nothing already answered:
Q: Which process? A: Expense approvals.
Q: Who asks? A: Our accountant, at year end.
Q: How far back? A: Three years.
Recommended next step - offered, not built:
Define the small set of events worth keeping and record who did what and when. Depth follows the question you need to answer.
Workflow: Event recorded → Actor and time → Stored → Periodically reviewed → Evidence produced
Want the CSV, SQL, JSON Schema and Notion mapping for this?
relation for anything that points at another table, text only for free text.currency, never text. Dates are date, never free text.Before treating a change record as evidence, verify the event identity, actor, timestamp, target, action, result, and correlation reference as separate values. Preserve the original event text alongside any normalized fields, record the timezone and clock source, and mark missing values as Unknown. Group related events by a stable correlation ID, but do not merge distinct actions into one summary row.
For a review export, filter by the requested time window first, then check that the export is complete, ordered deterministically, and scoped to the authorized system. Redact secrets and personal data only after retaining a reversible reference to the source record; never rewrite the underlying audit event. Record retention, deletion, clock drift, failed writes, duplicate events, and any gap in sequence as review findings rather than silently filling them.
Use a fixed action vocabulary such as create, read, update, delete, export, approve, reject, login, permission-change, and retention-delete. Store the resource type and resource identifier separately from the human-readable label. For bulk jobs, record the job identifier, item count, start and finish, partial-failure count, and final status; one bulk event must not be mistaken for one successful change per item.
For investigations, preserve the sequence as observed, then derive a second view grouped by actor, resource, or correlation ID. Mark derived views as derived and keep the query definition with the export. A missing event is a finding only when the expected event boundary and source system are known.
I want to set up compliance trail for my company.
Ask me one short question at a time, and only about what I have not already told you.
Then recommend the smallest setup that fits, and wait for me to ask before you build it.
When I ask, output CSV, SQL DDL, JSON Schema, a Notion property mapping or an Excel workbook. Data only.© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/audit-log of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit ec02547
We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Audit Log next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Audit Log this skillsickn33/agentic-awesome-skills | 47k | 1 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Analyze GitHub Action Logswithastro/astro | 63k | 1 repos | ~1.3k | Automated safety check: Pass | Custom licence | |
| Implementing Cloud Trail Log Analysismukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Recordingcodewhale-hq/Codewhale | 41k | — | ~540 | Automated safety check: Pass | MIT | |
| ActionsJetBrains/intellij-community | 21k | — | ~341 | Automated safety check: Pass | Custom licence | |
| Browser Recordruvnet/ruflo | 74k | — | ~735 | Automated safety check: Notes | MIT |
withastro/astro
Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.
mukul975/Anthropic-Cybersecurity-Skills
Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized…
codewhale-hq/Codewhale
Capture screenshots on registered computers, record on macOS or HarmonyOS, and manage saved captures.
JetBrains/intellij-community
Implement or change IntelliJ AnAction actions and registrations.
ruvnet/ruflo
Open a named, traced browser session into an RVF cognitive container with a ruvector trajectory recording every action
affaan-m/ECC
Write growth log entries that extract reusable patterns from completed work — root cause, transferable rule, and a recognizable signal — instead of diary-style event narration, with a 4-8 sentence…
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
sickn33/agentic-awesome-skills
Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.
Audit trail register: timestamp, user, module, record, action, field changed, old and new value, and the reason for the change. Audit Log is an agent skill from sickn33/agentic-awesome-skills. Audit trail register: timestamp, user, module, record, action, field changed, old and new value, and the reason for the change.
Audit Log fits situations like: change history and control evidence.
Run `npx skills add sickn33/agentic-awesome-skills --skill audit-log -a claude-code`. Or copy the skill folder (skills/audit-log in sickn33/agentic-awesome-skills) into .claude/skills/audit-log in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill audit-log -a codex`. Or copy the skill folder (skills/audit-log in sickn33/agentic-awesome-skills) into .agents/skills/audit-log in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill audit-log -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-log, .gemini/skills/audit-log, .github/skills/audit-log and .opencode/skills/audit-log in your project.
SKILL.md names no scripts, command-line tools or credentials: Audit Log is instructions for the agent only.
SKILL.md names 1 domain. In commands or code: json-schema.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Audit Log is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Audit Log: Analyze GitHub Action Logs (withastro/astro, 63k stars), Implementing Cloud Trail Log Analysis (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Recording (codewhale-hq/Codewhale, 41k stars) and Actions (JetBrains/intellij-community, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.