Agent skill

Audit Log

by WrongStack in WrongStack/WrongStack

A skill your agent uses when analyzing WrongStack session journals to explain what happened in a session — tool usage and failures, token spend and cache efficiency, compactions, delegations, loops…

MITAuto-check passed

Install Audit Log

skills CLI
$ npx skills add WrongStack/WrongStack --skill audit-log -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install WrongStack/WrongStack audit-log --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/audit-log .claude/skills/audit-log && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-log
GitHub stars
368
Token cost
~1.7k tokens
SKILL.md length
554 words
Files
2
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when analyzing WrongStack session journals to explain what happened in a session — tool usage and failures, token spend and cache efficiency, compactions, delegations, loops…

  • Works in 6 steps: Parse the journal; don't infer from… → Scope every figure: one session, or an… → Cite evidence — event type, timestamp,… → …
  • Analyzing WrongStack session journals to explain what happened in a session — tool usage and failures
  • SKILL.md covers Overview, Rules, Where journals live and Event reference, plus 6 more sections
  • Calls node

What it does

Audit Log is an agent skill from WrongStack/WrongStack. Use this skill when analyzing WrongStack session journals to explain what happened in a session — tool usage and failures, token spend and cache efficiency, compactions, delegations, loops, and errors. Triggers: user says "audit", "session analysis", "analyze the session", "log analysis", "why did this session cost so much", "token usage", "what went wrong in that run", "usage patterns".

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `SKILL.save.md`).

The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.

When your agent uses it

  • Analyzing WrongStack session journals to explain what happened in a session — tool usage and failures
  • Token spend and cache efficiency

Example prompts

  • “session analysis”
  • “analyze the session”
  • “log analysis”
  • “/audit-log”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Parse the journal; don't infer from memory, the UI, or the session title.
  2. Scope every figure: one session, or an aggregate labelled per session.
  3. Cite evidence — event type, timestamp, tool name, tool call id — for every
  4. Stream the file line by line; journals can be hundreds of megabytes. Skip
  5. Treat content as sensitive. user_input, tool inputs, and tool results can
  6. The analysis is read-only. Never edit, truncate, or rewrite a journal.

What it can do on your machine

Read from SKILL.md and the folder at commit ec76a20. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Log loads about 1.7k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 554 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from WrongStack/WrongStack at commit ec76a20, republished under its MIT licence (© WrongStack). 554 words, ~1,668 tokens.

Download SKILL.mdSave it as .claude/skills/audit-log/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
audit-log
description
Use this skill when analyzing WrongStack session journals to explain what happened in a session — tool usage and failures, token spend and cache efficiency, compactions, delegations, loops, and errors. Triggers: user says "audit", "session analysis", "analyze the session", "log analysis", "why did this session cost so much", "token usage", "what went wrong in that run", "usage patterns".
version
2.0.0
required-capabilities
filesystem.read
optional-capabilities
execution.shell, code.inspect

Audit Log — WrongStack session journals

Overview

Every WrongStack session is journaled as JSONL: one event per line, in order. The journal is the ground truth for what the agent did, what it cost, and where it went wrong. Analyze it from the file, report numbers that trace back to specific events, and never summarize a session you did not parse.

Rules

  1. Parse the journal; don't infer from memory, the UI, or the session title.
  2. Scope every figure: one session, or an aggregate labelled per session.
  3. Cite evidence — event type, timestamp, tool name, tool call id — for every finding.
  4. Stream the file line by line; journals can be hundreds of megabytes. Skip and count malformed lines instead of aborting.
  5. Treat content as sensitive. user_input, tool inputs, and tool results can hold secrets and personal data; quote only what a finding needs, redacted.
  6. The analysis is read-only. Never edit, truncate, or rewrite a journal.

Where journals live

  • Project sessions: ~/.wrongstack/projects/<project>/sessions/ (one JSONL per session).
  • Subagent transcripts are separate files; an agent_session_linked event in the parent journal carries the child's agentSessionId and transcriptPath.

Event reference

typeKey fieldsUse it for
session_start / session_resumedid, model, providerSession identity and starting model
user_inputcontentTurn boundaries; what was asked
llm_requestmodel, messageCount, estimatedInputTokens, toolCountContext growth per request
llm_responsestopReason, usage, model, providerTokens actually billed; stop reasons
tool_useid, name, inputTool call counts and repeated calls
tool_resultid, isError, contentFailures — join to tool_use on id
compactionbefore, after, level, reductionsContext pressure
errormessage, phaseRuntime failures
mode_changedfrom, toBehaviour shifts mid-session
delegate_started / delegate_completedtarget, ok, status, durationMs, toolCalls, costUsdDelegated work and its outcome
agent_spawned / agent_stopped / agent_erroragentId, role, reasonSubagent lifecycle
session_endusage, pendingToolUsesFinal usage; tool calls left unanswered

usage holds input, output, cacheRead, and cacheWrite (plus cacheWrite5m / cacheWrite1h when the provider reports them). Journals written by older versions may lack newer fields; tolerate their absence.

Show full SKILL.md (229 more words)Show less

What to compute

QuestionComputation
Which tools failed?tool_result.isError joined to tool_use.name by id; rate per tool
Did it loop?The same tool_use name and identical input repeated; long runs of calls with no user_input
Where did tokens go?Sum llm_response.usage per turn; growth in llm_request.estimatedInputTokens
Is caching working?cacheRead / (input + cacheRead + cacheWrite) per request; a sudden drop means the prompt prefix changed
Was context under pressure?compaction count, levels, and before → after
Did delegation pay off?delegate_completed ok/status, durationMs, costUsd per target
Did it end cleanly?session_end.pendingToolUses, final stopReason, trailing error events

Script

Save outside the repository (a temp dir) and run with node tool-stats.mjs <journal.jsonl>:

js
import { createReadStream } from 'node:fs';
import { createInterface } from 'node:readline';

const toolById = new Map();
const tools = {};
const tokens = { input: 0, output: 0, cacheRead: 0, cacheWrite: 0 };
const counts = { compaction: 0, error: 0, malformed: 0 };

for await (const line of createInterface({ input: createReadStream(process.argv[2]) })) {
  if (!line.trim()) continue;
  let event;
  try {
    event = JSON.parse(line);
  } catch {
    counts.malformed++;
    continue;
  }
  if (event.type === 'tool_use') {
    toolById.set(event.id, event.name);
    tools[event.name] ??= { calls: 0, errors: 0 };
    tools[event.name].calls++;
  } else if (event.type === 'tool_result' && event.isError) {
    const name = toolById.get(event.id);
    if (name) tools[name].errors++;
  } else if (event.type === 'llm_response' && event.usage) {
    for (const key of Object.keys(tokens)) tokens[key] += event.usage[key] ?? 0;
  } else if (event.type in counts) {
    counts[event.type]++;
  }
}

console.log(JSON.stringify({ tools, tokens, counts }, null, 2));

Report

text
## Session audit — <session id> (<model>, <start> → <end>)

### Summary
Turns 14 · tool calls 212 (9.4% failed) · tokens in 1.9M / out 48k · cache hit 81% · compactions 2

### Findings
1. The bash tool failed 17/60 calls; 12 are the same `pnpm test` timing out
   (tool_use ids …, 10:42–10:58). Cause: watch mode never exits.
2. Cache hit fell from 88% to 12% at 11:03 after mode_changed plan → default;
   the prefix changed, and the next 6 requests paid full input price.

### Coverage
Parsed 18,402 lines, 3 malformed and skipped. Subagent transcripts not included.

Anti-patterns

  • Reporting totals with no evidence — every number traces to events.
  • Mixing sessions without per-session labels.
  • Reading a huge journal whole into context instead of streaming it.
  • Pasting raw tool output with secrets into the report.
  • Guessing a cause the events don't support — say "unexplained" instead.

Before returning

  • Journal parsed from disk; malformed lines counted, not fatal
  • Every finding cites event types, times, and ids
  • Tool failures joined by id; token and cache figures from usage
  • Coverage stated (lines parsed, subagent transcripts included or not)
  • Nothing sensitive quoted unredacted; journal untouched

Skills in scope

  • observability — for turning recurring findings into better runtime signals
  • bug-hunter — for locating the code behind a recurring tool failure
  • output-standards — for the <nextsteps> shape in the report

© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in packages/core/skills/audit-log of WrongStack/WrongStack.

  • SKILL.md
  • SKILL.save.md

Open the folder on GitHubat commit ec76a20

Compare with similar skills

Audit Log next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Log compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Log this skillWrongStack/WrongStack368—~1.7kAutomated safety check: PassMIT
Analyzing DNS Logs For Exfiltrationmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
Analyzing Windows Event Logs In Splunkmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Analyzing Azure Activity Logs For Threatsmukul975/Anthropic-Cybersecurity-Skills34k—~609Automated safety check: PassApache-2.0
Analyzing Security Logs With Splunkmukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0

Similar skills

  • Analyzing DNS Logs For Exfiltration

    mukul975/Anthropic-Cybersecurity-Skills

    Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Analyzing Windows Event Logs In Splunk

    mukul975/Anthropic-Cybersecurity-Skills

    Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Azure Activity Logs For Threats

    mukul975/Anthropic-Cybersecurity-Skills

    Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications.

    34k GitHub stars~609 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Security Logs With Splunk

    mukul975/Anthropic-Cybersecurity-Skills

    Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection.

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Kubernetes Audit Logs

    mukul975/Anthropic-Cybersecurity-Skills

    Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules…

    34k GitHub stars~654 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from WrongStack/WrongStack

All 38 skills in this repo
  • Design Craft

    WrongStack/WrongStack

    Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.

    368 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Design Critique

    WrongStack/WrongStack

    A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…

    368 GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Mailbox Bridge

    WrongStack/WrongStack

    A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…

    368 GitHub stars~3.9k tokensUpdated yesterday
    Auto-check passed
  • Multi Agent

    WrongStack/WrongStack

    A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.

    368 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Web Platform Baseline

    WrongStack/WrongStack

    Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…

    368 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Wrongstack Mailbox

    WrongStack/WrongStack

    A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…

    368 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed

Questions about Audit Log

What does Audit Log do?

A skill your agent uses when analyzing WrongStack session journals to explain what happened in a session — tool usage and failures, token spend and cache efficiency, compactions, delegations, loops…. Audit Log is an agent skill from WrongStack/WrongStack. Use this skill when analyzing WrongStack session journals to explain what happened in a session — tool usage and failures, token spend and cache efficiency, compactions, delegations, loops, and errors.

When should I use Audit Log?

Audit Log fits situations like: analyzing WrongStack session journals to explain what happened in a session — tool usage and failures; token spend and cache efficiency.

How do I install Audit Log in Claude Code?

Run `npx skills add WrongStack/WrongStack --skill audit-log -a claude-code`. Or copy the skill folder (packages/core/skills/audit-log in WrongStack/WrongStack) into .claude/skills/audit-log in your project. Claude Code loads it when a task matches its description.

How do I install Audit Log in Codex?

Run `npx skills add WrongStack/WrongStack --skill audit-log -a codex`. Or copy the skill folder (packages/core/skills/audit-log in WrongStack/WrongStack) into .agents/skills/audit-log in your project. Codex loads it when a task matches its description.

Can I use Audit Log in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill audit-log -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-log, .gemini/skills/audit-log, .github/skills/audit-log and .opencode/skills/audit-log in your project.

What does Audit Log need to run?

Going by SKILL.md and its folder, Audit Log needs the command-line tools its instructions call (node).

Does Audit Log access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Log safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Log use?

Audit Log is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Log use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Log?

Skills that share tags, products or a category with Audit Log: Analyzing DNS Logs For Exfiltration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyze GitHub Action Logs (withastro/astro, 63k stars), Analyzing Windows Event Logs In Splunk (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Analyzing Azure Activity Logs For Threats (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Log?

WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 368 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 6, 2026.

Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.