Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Observability Pattern Detector

ASecurity

Automated pattern recognition in Claude Code telemetry. Use when detecting failures, slowness, anomalies, trends, inefficiencies, conversation patterns, or tool sequences.

3 stars
0 votes
0 copies
0 views
Added 2/8/2026
datagobashdebugging

Works with

claude code

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 2/12/2026

$npx -y skills add adaptationio/Skrillz --skill observability-pattern-detector --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Observability Pattern Detector?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Observability Pattern Detector
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/adaptationio-observability-pattern-detector/badge)](https://www.skillsdirectory.com/skills/adaptationio-observability-pattern-detector)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: observability-pattern-detector
description: Automated pattern recognition in Claude Code telemetry. Use when detecting failures, slowness, anomalies, trends, inefficiencies, conversation patterns, or tool sequences.
---

# Observability Pattern Detector

Automated pattern recognition and anomaly detection in Claude Code telemetry data from enhanced hooks.

## Data Source

Primary: `{job="claude_code_enhanced"}` in Loki

## Operations

### `detect-failures`
Group similar failures and identify patterns.
```logql
{job="claude_code_enhanced", event_type="tool_result", status="error"} | json
```
**Algorithm**: Group by error_type → Calculate frequency → Rank by impact.
**Output**: Failure patterns with occurrences, affected tools, first/last seen, trend.

### `detect-slowness`
Identify large response patterns (proxy for slowness).
```logql
{job="claude_code_enhanced", event_type="tool_result"} | json | response_length > 100000
```
**Algorithm**: Flag responses >100k chars → Group by tool → Identify patterns.
**Output**: Slow operations with response sizes, affected tools.

### `detect-anomalies`
Statistical anomaly detection in sessions.
```logql
{job="claude_code_enhanced", event_type="session_end"} | json | turn_count > 50
```
**Methods**: High turn count, long duration, many errors per session.
**Output**: Anomalous sessions with metrics, likely cause.

### `detect-trends`
Long-term trend analysis.
```logql
sum(count_over_time({job="claude_code_enhanced", event_type="tool_call"} [1d]))
```
**Metrics**: Tool usage trend, error rate trend, session frequency trend.
**Output**: Trends with direction (increasing/decreasing/stable), rate.

### `detect-waste`
Identify inefficiencies (redundant operations).
```logql
{job="claude_code_enhanced", event_type="tool_call"} | json | line_format "{{.tool_name}}:{{.previous_tool}}"
```
**Patterns**:
- Multiple reads of same file (Read→Read)
- Repeated failed operations
- Excessive Glob before Read
- Many small edits vs one large edit
**Output**: Waste patterns with occurrences, recommendations.

### `detect-conversation-patterns`
Analyze user prompt patterns.
```logql
sum by (pattern) (count_over_time({job="claude_code_enhanced", event_type="user_prompt"} | json [24h]))
```
**Patterns**:
- Question frequency (pattern="question")
- Debugging sessions (pattern="debugging")
- Creation tasks (pattern="creation")
- Ultrathink usage (pattern="ultrathink")
**Output**: Conversation style distribution, trends.

### `detect-tool-sequences`
Identify common tool call sequences.
```logql
{job="claude_code_enhanced", event_type="tool_call"} | json | line_format "{{.previous_tool}} → {{.tool_name}}"
```
**Common Patterns**:
- Glob → Read (file discovery)
- Read → Edit (modify after read)
- Grep → Read (search then open)
- Task → Task (parallel agents)
**Output**: Sequence frequencies, unusual patterns.

### `detect-subagent-patterns`
Analyze Task tool usage patterns.
```logql
{job="claude_code_enhanced", event_type="tool_call", tool="Task"} | json
```
**Patterns**:
- Subagent types distribution
- Parallel spawning patterns
- Subagent success rates
**Output**: Subagent usage analytics, recommendations.

### `detect-context-issues`
Identify context window problems.
```logql
{job="claude_code_enhanced", event_type="context_compact"} | json
```
**Patterns**:
- Frequent auto-compaction
- High context usage sessions
- Large response accumulation
**Output**: Context management issues, optimization suggestions.

### `detect-permission-patterns`
Analyze permission request patterns.
```logql
{job="claude_code_enhanced", event_type="permission_request"} | json
```
**Patterns**:
- Frequent permission requests
- Permission types distribution
- Permission denials
**Output**: Permission friction points, automation opportunities.

### `detect-repo-patterns`
Repository activity patterns.
```logql
sum by (repo) (count_over_time({job="claude_code_enhanced", event_type="tool_call"} | json [7d]))
```
**Patterns**:
- Most active repos
- Tool usage by repo
- Error rates by repo
**Output**: Project-level insights, cross-repo comparisons.

## Example Output

```json
{
  "failure_patterns": [
    {
      "pattern_id": "file_not_found",
      "signature": "File does not exist",
      "occurrences": 23,
      "affected_tools": ["Read", "Edit"],
      "trend": "stable",
      "recommendation": "Add file existence check before operations"
    }
  ],
  "tool_sequence_patterns": [
    {
      "sequence": "Glob → Read → Edit",
      "occurrences": 156,
      "context": "Standard file modification flow"
    }
  ],
  "conversation_patterns": [
    {
      "pattern": "debugging",
      "percentage": 35,
      "avg_turns": 12,
      "common_tools": ["Bash", "Read", "Grep"]
    }
  ],
  "context_issues": [
    {
      "issue": "auto_compaction_frequent",
      "sessions_affected": 5,
      "recommendation": "Use more focused queries, split large tasks"
    }
  ]
}
```

## Pattern Detection Queries

### Failure Patterns
```logql
# Group errors by type
sum by (error_type, tool) (count_over_time({job="claude_code_enhanced", event_type="tool_result", status="error"} | json [24h]))

# Error timeline
{job="claude_code_enhanced", event_type="tool_result", status="error"} | json | line_format "{{.timestamp}} {{.tool_name}}: {{.error_type}}"
```

### Tool Sequence Patterns
```logql
# Most common transitions
{job="claude_code_enhanced", event_type="tool_call"} | json | previous_tool != "" | line_format "{{.previous_tool}} → {{.tool_name}}"
```

### Session Anomalies
```logql
# Long sessions
{job="claude_code_enhanced", event_type="session_end"} | json | duration_seconds > 3600

# High error sessions
{job="claude_code_enhanced", event_type="session_end"} | json | error_count > 5

# High turn sessions
{job="claude_code_enhanced", event_type="session_end"} | json | turn_count > 30
```

### Context Patterns
```logql
# Auto compactions
{job="claude_code_enhanced", event_type="context_compact", trigger="auto"} | json

# High utilization
{job="claude_code_enhanced", event_type="context_utilization"} | json | context_percentage > 80
```

## Scripts

- `scripts/detect-failures.sh` - Failure pattern detection
- `scripts/detect-anomalies.sh` - Statistical anomaly detection
- `scripts/detect-trends.sh` - Trend analysis
- `scripts/detect-sequences.sh` - Tool sequence analysis
- `scripts/generate-pattern-report.sh` - Full pattern report

Attribution

adaptationioadaptationio
View sourceSee grades on GitHubMore from adaptationio →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Rank Tracker

This skill helps you track, analyze, and report on keyword ranking positions over time. It monitors both traditional SERP rankings and AI/GEO visibility to provide comprehensive search performance insights.

1821 votes

Youtube Competitor Analyzer

Find and analyze YouTube competitor channels using YouTube Data API v3. Discover competitors through keyword search, category matching, content similarity, and related channel discovery. Compare metrics, content strategies, and market positioning. Use when users want to (1) Find competitors for their YouTube channel, (2) Analyze competitor performance metrics, (3) Compare their channel against competitors, (4) Identify content gaps and opportunities, (5) Benchmark against similar creators, (6...

31 votes

Xlsx

Use this skill any time a spreadsheet file is the primary input or output. This means any task where the user wants to: open, read, edit, or fix an existing .xlsx, .xlsm, .xltx, .csv, or .tsv file (e.g., adding columns, computing formulas, formatting, charting, cleaning messy data); create a new spreadsheet from scratch or from other data sources; or convert between tabular file formats. Trigger especially when the user references a spreadsheet file by name or path — even casually (like \"the...

1798860 votes

Weather Fetcher

Instructions for fetching current weather temperature data for Karachi, Pakistan from wttr.in API

672240 votes

Weather

Get current weather and forecasts (no API key required).

486960 votes
View all in data →