All skills
launchdarkly avatar

/investigate

@c3d4333 official

Analyzes observability data — logs, traces, errors, sessions, and metrics — to find root cause and actionable evidence. Use when the user reports a bug, an unexpected behavior, or asks about patterns across application data.

Use this Skill: https://skilld.dev/gh/launchdarkly/agent-skills/investigate

This session only. Nothing lands on disk.

traces.md

≈708 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Investigating with traces

Load this file when the investigation concerns request flow, latency, or span-level behavior across service boundaries.

When to reach for traces

  • The user reports a slow or failed request and you have a trace ID
  • You need to understand which service in a chain is the bottleneck
  • An error has a trace ID in its context — follow the trace to find where the request went sideways
  • You're comparing "healthy" vs. "unhealthy" requests for the same operation

Traces are high-volume and unbounded queries are rarely useful. Always anchor to a trace ID, a narrow time window, or a specific service+operation.

Tool guidance (query-traces)

The query-traces tool returns paginated trace entries with timestamp, span details, and attributes.

  • start_date is required; ISO format.
  • end_date defaults to now. Never query more than 24 hours of traces. If you need a wider window, use query-aggregations to aggregate first.
  • query filters by span attributes — e.g. span_name="getUserData" AND service_name=auth.
  • limit defaults to 20, max 50.
  • direction is ASC or DESC. Defaults to DESC.

Duration is in nanoseconds. Convert before reporting — a latency of 2500000000 is 2.5 seconds.

Session-scoped traces. Use query="secure_session_id=<id>" with start_date = session created_at, end_date = +3 hours.

Typical patterns

  1. Latency investigation — find the slow operation via query-aggregations with product_type="traces" and group_by="span_name", then drill in with query-traces for specific slow instances.
  2. Critical-path analysis — pull one representative slow trace, identify the span that dominates total duration, then check if it's consistently slow across many traces (query-traces + query filter) or a one-off.
  3. Cross-service failure — when a trace shows an error span, look at the parent and child spans. The failure often cascades; the true root is usually a downstream service.
  4. Compare healthy vs. unhealthy — pull one trace of each for the same operation. Apples-to-apples — same span_name, same service version.

Interpreting results

  • Span hierarchy matters. Read the trace as a tree. A 5-second top-level span made up of a 4.9-second DB call tells a different story than ten 500ms calls.
  • If spans are missing or sampled out, say so. Don't infer timing from gaps.
  • Cite the trace ID and service name when making claims. "The auth service is slow" with no trace ID isn't actionable.

Common mistakes

  • Querying traces across 7-day windows. Max 24 hours; use query-aggregations for longer ranges.
  • Reporting duration in raw nanoseconds. Always convert to ms or s.
  • Treating a single slow trace as a systemic problem. Check frequency before recommending a fix.

Source: SKILL.md on GitHub

1 warning2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    This skill provides a comprehensive suite for investigating application observability data via LaunchDarkly. It enables searching logs, traces, errors, and sessions. The skill includes instructions to use local shell tools like Bash, Python, and JQ for processing large data outputs. While these are standard developer workflows, they represent an execution surface that could be targeted via indirect prompt injection if the observability data contains malicious payloads.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: MEDIUM · 1 issue

Signed by skilld at c3d4333. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 3 months ago
compatibility
Requires the remotely hosted LaunchDarkly MCP server
metadata
{
  "author": "launchdarkly",
  "version": "0.1.0"
}

README badge

README badge for launchdarkly/agent-skills/investigate