All skills
launchdarkly avatar

/investigate

@c3d4333 official

Analyzes observability data — logs, traces, errors, sessions, and metrics — to find root cause and actionable evidence. Use when the user reports a bug, an unexpected behavior, or asks about patterns across application data.

Use this Skill: https://skilld.dev/gh/launchdarkly/agent-skills/investigate

This session only. Nothing lands on disk.

logs.md

≈729 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Investigating with logs

Load this file when the investigation touches application logs — error messages, log-level filters, service log patterns.

When to reach for logs

  • The user mentions a specific error string, service name, or log level
  • You need to correlate a symptom with a specific moment in time
  • A trace span failed and you need the structured log output around it
  • You're looking for a pattern (repeated error, frequency change) before narrowing to specific records

Logs are your best tool for verbatim evidence. They're your worst tool for "what's the overall picture" — reach for query-aggregations instead.

Tool guidance (query-logs)

The query-logs tool returns paginated log entries with timestamp, level, message, and core attributes.

  • start_date is required; ISO format with timezone (e.g. 2026-01-24T15:25:19.000-08:00 or 2026-01-24T15:25:19Z).
  • end_date defaults to now.
  • query is a filter expression like message="error" AND level=error. Empty string returns all logs in range. See query syntax below.
  • limit defaults to 20, max 50. Do not request more.
  • direction is ASC or DESC. Defaults to DESC (newest first).

Session-scoped queries. To pull logs from a specific session, use secure_session_id=<id> in the query. Set start_date to the session's created_at and end_date to created_at + 3 hours. Narrower windows will miss tail events.

Typical patterns

  1. Error pattern search — query="level=error AND service_name=<svc>", 24h window, aggregate first with query-aggregations if volume is high.
  2. Specific error message — escape quotes in the query: query="message=\"Cannot use 'in' operator*\"". Wildcards work.
  3. Logs around a trace — pull the trace first, grab the timestamp and service, then query="trace_id=<id>" with a 1-minute window centered on the event.
  4. Service-wide health snapshot — query-aggregations with product_type="logs" and group_by="level" for a time window, then drill into high-count levels with query-logs.

Interpreting results

  • Don't paraphrase — cite the exact log line. "The database is slow" is not actionable; {"ts": "2026-04-20T14:23:11Z", "level": "error", "message": "pg_pool: connection timeout after 30s"} is.
  • If you see repeated errors, note the exact cadence — a burst suggests an incident onset; steady-state suggests a persistent bug.
  • Log level drift often correlates with deploys or flag flips — cross-reference with query-flag-evaluations when a regression appears.

Common mistakes

  • Asking for 100+ entries. Max is 50. Use query-aggregations for aggregates.
  • Forgetting to specify start_date. It's required.
  • Wildcarding too broadly (message="*") — returns everything, wastes token budget.
  • Assuming attribute names. Call get-keys(product_type="Logs") if you're unsure which field to filter on.

Source: SKILL.md on GitHub

1 warning2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    This skill provides a comprehensive suite for investigating application observability data via LaunchDarkly. It enables searching logs, traces, errors, and sessions. The skill includes instructions to use local shell tools like Bash, Python, and JQ for processing large data outputs. While these are standard developer workflows, they represent an execution surface that could be targeted via indirect prompt injection if the observability data contains malicious payloads.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: MEDIUM · 1 issue

Signed by skilld at c3d4333. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 3 months ago
compatibility
Requires the remotely hosted LaunchDarkly MCP server
metadata
{
  "author": "launchdarkly",
  "version": "0.1.0"
}

README badge

README badge for launchdarkly/agent-skills/investigate