Agent skill

Root Cause Investigator

by umputun in umputun/cc-thingz

Systematic root cause analysis for errors, bugs, and unexpected behaviors using 5-Why methodology.

MITAuto-check passedDevelopment

Install Root Cause Investigator

skills CLI
$ npx skills add umputun/cc-thingz --skill root-cause-investigator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install umputun/cc-thingz root-cause-investigator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/umputun/cc-thingz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/thinking-tools/skills/root-cause-investigator .claude/skills/root-cause-investigator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
root-cause-investigator
GitHub stars
485
Token cost
~879 tokens
SKILL.md length
277 words
Files
3 (incl. references)
Skills in repo
16
Repo updated
First seen
Licence
MIT

At a glance

Systematic root cause analysis for errors, bugs, and unexpected behaviors using 5-Why methodology.

  • Works in 3 steps: Gather Initial Context → Apply 5-Why Analysis → Identify Root Cause
  • User reports errors
  • SKILL.md covers Activation Triggers, The 5-Why Methodology, Investigation Workflow and Investigation Principles, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Root Cause Investigator is an agent skill from umputun/cc-thingz. Systematic root cause analysis for errors, bugs, and unexpected behaviors using 5-Why methodology. Use when user reports errors, build failures, test failures, performance issues, integration problems, or any "it's not working" scenarios.

Its SKILL.md is about 880 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/patterns.md` and `references/techniques.md`).

It sits in Development, covering Root cause analysis. The repository describes itself as: various things for claude code. The licence is MIT.

When your agent uses it

  • User reports errors
  • Performance issues
  • Integration problems
  • Any its not working scenarios

Example prompts

  • “s not working”
  • “/root-cause-investigator”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Gather Initial Context
  2. Apply 5-Why Analysis
  3. Identify Root Cause

What it can do on your machine

Read from SKILL.md and the folder at commit 99e1c8d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Root Cause Investigator loads about 879 tokens when it runs, and up to ~1.6k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 277 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~879
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from umputun/cc-thingz at commit 99e1c8d, republished under its MIT licence (© umputun). 277 words, ~879 tokens.

Download SKILL.mdSave it as .claude/skills/root-cause-investigator/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
root-cause-investigator
description
Systematic root cause analysis for errors, bugs, and unexpected behaviors using 5-Why methodology. Use when user reports errors, build failures, test failures, performance issues, integration problems, or any "it's not working" scenarios.

Root Cause Investigator

Apply systematic 5-Why methodology to identify fundamental root causes of issues rather than treating symptoms. Guide thorough investigation through structured evidence gathering and analysis.

Activation Triggers

  • errors, bugs, or unexpected behavior
  • build failures or test failures
  • performance issues or degradation
  • integration problems
  • any "it's not working" scenarios

The 5-Why Methodology

Systematically ask "why" five times to drill down to root cause:

  1. Why #1: identify immediate cause (symptoms)
  2. Why #2: uncover process/workflow issues
  3. Why #3: find system-level problems
  4. Why #4: discover design/architecture issues
  5. Why #5: reveal fundamental root cause

Investigation Workflow

1. Gather Initial Context

Collect information about the issue:

## Issue Summary
[brief description of reported problem]

## Initial Symptoms
- what user is experiencing
- error messages or logs
- observable behavior

## Context Gathering
- environment details
- recent changes
- related components
- steps to reproduce
2. Apply 5-Why Analysis

Structure the investigation with progressive depth:

## 5-Why Analysis

### Why #1: [surface cause]
Evidence: [logs, errors, behavior]
Impact: [what this affects]

### Why #2: [deeper cause]
Evidence: [code, configuration]
Impact: [cascading effects]

### Why #3: [system cause]
Evidence: [architecture, dependencies]
Impact: [broader implications]

### Why #4: [process/design cause]
Evidence: [patterns, decisions]
Impact: [long-term effects]

### Why #5: [root cause]
Evidence: [fundamental issue]
Impact: [core problem]
3. Identify Root Cause

Document the fundamental issue requiring attention:

## Root Cause Identified
[the fundamental issue that needs addressing]

## Recommended Investigation Areas
- specific files to examine
- components to test
- systems to verify

Investigation Principles

  1. Avoid solution bias - focus on understanding before fixing
  2. Gather evidence - don't assume, verify with data
  3. Consider multiple causes - issues often have multiple contributing factors
  4. Document findings - clear documentation prevents repeat issues
  5. Think systemically - consider broader implications
  6. Question assumptions - challenge "it should work" thinking
  7. Use version control - check when issue was introduced

Using Reference Materials

Load reference files as needed during investigation:

  • references/patterns.md - common root cause patterns by category (configuration, race conditions, resource exhaustion, integration failures, build/deployment issues)
  • references/techniques.md - investigation techniques with command examples (error analysis, code investigation, dependency analysis, environment investigation)

Best Practices

  • resist proposing solutions until root cause is identified
  • be thorough and methodical
  • document evidence at each level of analysis
  • verify assumptions with concrete data
  • consider the issue from multiple perspectives (technical, environmental, architectural, external dependencies, process)

The goal is to find the fundamental cause, not just fix symptoms.

© umputun, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/thinking-tools/skills/root-cause-investigator of umputun/cc-thingz.

  • SKILL.md
  • references/patterns.md
  • references/techniques.md

Open the folder on GitHubat commit 99e1c8d

Compare with similar skills

Root Cause Investigator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Root Cause Investigator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Root Cause Investigator this skillumputun/cc-thingz485—~879Automated safety check: PassMIT
OpenLogi macOS Permissions TriageAprilNEA/OpenLogi23k—~2.5kAutomated safety check: NotesApache-2.0
Bug Finder for daisyUIsaadeghi/daisyui43k—~2.3kAutomated safety check: PassMIT
Root Cause Debugginggarrytan/gstack136k—~1.4kAutomated safety check: PassMIT
Review PRapache/shardingsphere21k—~6.5kAutomated safety check: PassApache-2.0
Graph-Based Bug Tracingtirth8205/code-review-graph32k1 repos~287Automated safety check: PassMIT

Similar skills

  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Bug Finder for daisyUI

    saadeghi/daisyui

    Investigates suspected bugs in the daisyUI monorepo through read-only analysis, then writes a decision-ready fix plan in tmp/bugs without changing any product code.

    43k GitHub stars~2.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Root Cause Debugging

    garrytan/gstack

    Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.

    136k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Review PR

    apache/shardingsphere

    Review Apache ShardingSphere or user-authorized downstream pull requests and PR discussions from public or authorized repository evidence.

    21k GitHub stars~6.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Graph-Based Bug Tracing

    tirth8205/code-review-graph

    Traces a bug through a code knowledge graph, following callers, callees and execution flow before opening source files, within a small token budget.

    32k GitHub starsUsed in 1 repo~287 tokens
    DevelopmentAuto-check passed
  • Om Auto Fix Issue

    go-musicfox/go-musicfox

    Fix or implement a tracker issue end to end from a single command — takes an issue id or a plain problem description (filed first via om-prepare-issue), classifies, then drives the bug autofix chain…

    2.6k GitHub starsUsed in 1 repo~5k tokens
    DevelopmentAuto-check: notes

More from umputun/cc-thingz

All 16 skills in this repo
  • Exec

    umputun/cc-thingz

    Execute plan tasks sequentially using subagents. An agent skill from umputun/cc-thingz.

    485 GitHub stars~8k tokensUpdated 5 days ago
    Auto-check passed
  • New

    umputun/cc-thingz

    A skill your agent uses when user asks to create a release, cut a release, or publish a version.

    485 GitHub stars~1.9k tokensUpdated 5 days ago
    Auto-check: notes
  • Ask Codex

    umputun/cc-thingz

    Consult OpenAI Codex for investigation, debugging, or code review.

    485 GitHub stars~2.6k tokensUpdated 5 days ago
    Auto-check: notes
  • Backlog

    umputun/cc-thingz

    Read, work, and maintain a Git repo's deferred-work items in docs/backlog/, one file per item.

    485 GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check: notes
  • Brainstorm

    umputun/cc-thingz

    Use before any creative work or significant changes. An agent skill from umputun/cc-thingz.

    485 GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check: notes
  • Clarify

    umputun/cc-thingz

    This skill should be used when user appears confused, frustrated, or shows misalignment between expectations and reality.

    485 GitHub stars~2.1k tokensUpdated 5 days ago
    Auto-check passed

Categories

Questions about Root Cause Investigator

What does Root Cause Investigator do?

Systematic root cause analysis for errors, bugs, and unexpected behaviors using 5-Why methodology. Root Cause Investigator is an agent skill from umputun/cc-thingz. Systematic root cause analysis for errors, bugs, and unexpected behaviors using 5-Why methodology.

When should I use Root Cause Investigator?

Root Cause Investigator fits situations like: user reports errors; performance issues; integration problems; any its not working scenarios.

How do I install Root Cause Investigator in Claude Code?

Run `npx skills add umputun/cc-thingz --skill root-cause-investigator -a claude-code`. Or copy the skill folder (plugins/thinking-tools/skills/root-cause-investigator in umputun/cc-thingz) into .claude/skills/root-cause-investigator in your project. Claude Code loads it when a task matches its description.

How do I install Root Cause Investigator in Codex?

Run `npx skills add umputun/cc-thingz --skill root-cause-investigator -a codex`. Or copy the skill folder (plugins/thinking-tools/skills/root-cause-investigator in umputun/cc-thingz) into .agents/skills/root-cause-investigator in your project. Codex loads it when a task matches its description.

Can I use Root Cause Investigator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add umputun/cc-thingz --skill root-cause-investigator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/root-cause-investigator, .gemini/skills/root-cause-investigator, .github/skills/root-cause-investigator and .opencode/skills/root-cause-investigator in your project.

What does Root Cause Investigator need to run?

SKILL.md names no scripts, command-line tools or credentials: Root Cause Investigator is instructions for the agent only.

Does Root Cause Investigator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Root Cause Investigator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Root Cause Investigator use?

Root Cause Investigator is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Root Cause Investigator use?

About 879 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 748 tokens, read only when the agent opens those files.

What are the alternatives to Root Cause Investigator?

Skills that share tags, products or a category with Root Cause Investigator: OpenLogi macOS Permissions Triage (AprilNEA/OpenLogi, 23k stars), Bug Finder for daisyUI (saadeghi/daisyui, 43k stars), Root Cause Debugging (garrytan/gstack, 136k stars) and Review PR (apache/shardingsphere, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Root Cause Investigator?

umputun (a GitHub user) maintains it in umputun/cc-thingz, which has 485 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 5, 2026.

Source: umputun/cc-thingz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.