Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills Aโ€“Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Agent Observability Spec

ASecurity

Specify the tracing, metrics, and alerting for an AI agent or LLM feature in production. Use when asked what to log for an LLM app, design agent tracing or spans, define quality and cost monitors, or answer 'how do we know if the agent is misbehaving?'. Produces an observability spec with a trace schema, metric definitions with owners and alert thresholds, sampling and retention policy, and a privacy note for logged content.

1,330 stars
0 votes
0 copies
0 views
Added 9/3/2026
ai-agentsgorailsdebugginggit

Works with

terminal

Security Analysis

A100/100

Scanned 9/3/2026

$npx -y skills add mohitagw15856/pm-claude-skills --skill agent-observability-spec --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Agent Observability Spec?

Add the live security badge to your README โ€” it updates automatically with every re-scan.

Security grade badge for Agent Observability Spec
[![Security: A โ€” Skills Directory](https://www.skillsdirectory.com/api/skills/mohitagw15856-agent-observability-spec/badge)](https://www.skillsdirectory.com/skills/mohitagw15856-agent-observability-spec)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: agent-observability-spec
description: "Specify the tracing, metrics, and alerting for an AI agent or LLM feature in production. Use when asked what to log for an LLM app, design agent tracing or spans, define quality and cost monitors, or answer 'how do we know if the agent is misbehaving?'. Produces an observability spec with a trace schema, metric definitions with owners and alert thresholds, sampling and retention policy, and a privacy note for logged content."
homepage: https://mohitagw15856.github.io/pm-claude-skills/skill/agent-observability-spec.html
metadata:
  {
    "openclaw": { "emoji": "๐Ÿฆพ" }
  }
---

# Agent Observability Spec Skill

You can't fix what you didn't record. For LLM systems the unit of observability is the *trace* โ€” everything the model saw and did โ€” because behaviour, not uptime, is what fails. This skill specifies what to capture, what to compute from it, and when to page someone.

## What This Skill Produces

- A **trace schema**: per-request spans and the fields each must carry
- **Metric definitions** across health, quality, cost, and behaviour โ€” each with a threshold and owner
- A **sampling and retention policy** that keeps cost sane and debugging possible
- A **privacy note**: what logged content contains, who can see it, and how long it lives

## Required Inputs

Ask for (if not already provided):
- **The system's shape** โ€” single LLM call, RAG pipeline, or multi-step tool-using agent
- **Traffic volume and cost sensitivity** โ€” full tracing at 10M req/day is a budget decision
- **What "misbehaving" means here** โ€” the two or three failure modes that matter most (wrong facts? wrong actions? cost? refusals?)
- **Existing observability stack** (Datadog, Langfuse, OTel, homegrown) โ€” spec into it, not around it

## Trace Schema

Every request produces one trace; every model call, retrieval, guardrail check, and tool execution is a span. Minimum fields:

| Span | Must capture |
|---|---|
| **Request root** | request id, user/session (pseudonymous), feature + prompt version, model id, total tokens, total cost, latency, terminal status |
| **Model call** | full input context (or content-addressed ref), output, finish reason, tokens in/out, cached-token share, temperature |
| **Retrieval** | query, top-k ids + scores, which chunks entered the context |
| **Tool call** | tool name, arguments, result (or ref), duration, error |
| **Guardrail** | check name, verdict, and *what it did* (blocked / rewrote / flagged) |
| **User signal** | edits, regenerates, thumbs, abandonment โ€” joined to the trace id |

The test of the schema: **an engineer can replay any incident from its trace alone** (see `agent-incident-postmortem`).

## Metrics and Alerts

Define four families; every metric gets a threshold, a window, and an owner.

- **Health** โ€” error rate, p50/p95 latency, timeout rate, provider 429/5xx rate. *Page* on these.
- **Cost** โ€” cost per request (p50, p99), tokens per request, cache hit rate, daily spend vs. budget (pair with `llm-cost-latency-budget`). *Alert* on p99 and daily-budget burn โ€” cost incidents are caused by the tail, not the mean.
- **Quality proxies** โ€” format/schema violation rate, refusal rate, groundedness-check failure rate, judge score on a sampled slice, regenerate/edit rate. *Alert on drift* vs. a rolling baseline: absolute thresholds go stale, deltas don't.
- **Behaviour (agents)** โ€” steps per task, tool-error rate, loop detection (same tool + same args N times), unauthorised-action attempts caught by guardrails. *Page* on the last one.

## Sampling & Retention

- **Metadata for 100%** of requests (ids, versions, tokens, cost, status) โ€” this is cheap and non-negotiable.
- **Full content traces:** 100% for errors, guardrail hits, and negative user signals; [1-10]% random sample for the rest, adjusted to volume.
- **Retention:** full content [30-90] days, metadata [12+] months for trend baselines; incident traces pinned indefinitely.
- **Privacy:** logged context contains user data โ€” state where it lives, who has access, how deletion requests reach it, and that traces are scrubbed or access-gated before wide sharing.

## Output Format

### Observability Spec: [feature/agent]

**System shape:** [calls/pipeline/agent] ยท **Volume:** [req/day] ยท **Stack:** [tooling]

**Trace schema:** [the span table, tailored]

**Metrics:**
| Metric | Family | Threshold / baseline | Window | Alert โ†’ owner |
|---|---|---|---|---|

**Sampling & retention:** [the policy]

**Privacy:** [content classification, access, deletion path]

**Dashboards:** [the 2-3 views: live health, quality drift, cost]

**First incident drill:** pick yesterday's worst trace and confirm it can be replayed end-to-end from the stored data.

## Quality Checks

- [ ] Any incident is replayable from its trace alone โ€” the schema was tested against that bar
- [ ] Every metric has a number, a window, and a named owner โ€” no orphan dashboards
- [ ] Quality alerts are drift-based against a rolling baseline, not absolute guesses
- [ ] Sampling keeps 100% of error/guardrail/negative-signal traces
- [ ] The privacy note exists and names retention and access โ€” logged prompts are user data

## Anti-Patterns

- [ ] Do not log only inputs and outputs โ€” without retrieval and tool spans, root cause analysis is guesswork
- [ ] Do not alert on mean cost or mean latency โ€” the tail is where both incidents live
- [ ] Do not run judge-based quality scoring on 100% of traffic โ€” sample; spend the budget on better baselines
- [ ] Do not treat observability as launch-week scaffolding โ€” drift metrics only work with months of baseline
- [ ] Do not ship an agent that can take actions without logging the guardrail verdicts alongside the actions

Attribution

mohitagw15856mohitagw15856
View sourceSee grades on GitHubMore from mohitagw15856 โ†’
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents โ†’