investigate — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited investigate (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Polymorphic on the input. Read-only, always. Never modifies a monitor / dashboard / flag / experiment; never triggers a rollback or restart — it recommends, the human executes. Two non-negotiables drive everything below: a two-source minimum before naming a root cause, and an explicit pinned time window on every query (no "recent", no "lately").
The full operating contract lives in this skill folder — read these as you need them:
| Aspect | File |
|---|---|
| How you investigate (voice, confidence, blast-radius ordering) | persona.md |
| The phased process + Workflow multi-source fan-out | workflow.md |
| Hard rules + refusals + safety | rules.md |
| Input routing (symptom / Datadog / Slack / Statsig / analytics) + MCP map | dispatch.md |
[T_start, T_end] from --window, the alert's fire time, or the symptom's first-seen. If none can be derived, ask — don't guess (rules.md).context-gatherer/investigator agent per data source with the Workflow tool — each blind to the others — then form a hypothesis that requires ≥2 agreeing signals, then have a skeptic try to refute it.rules.md."Always have a workflow." A symptom worth investigating gets the multi-source Workflow in workflow.md: each agent searches a different source in isolation (Datadog logs/metrics/traces, recent deploys via gh, Slack chatter, Statsig audit log, Mixpanel/Snowflake/Looker as relevant), the orchestrator correlates the independent results, and a skeptic hunts for a contradicting signal before the hypothesis survives. Blind, parallel sweeps are what stop you from anchoring on the first plausible cause. Skip the Workflow only for a trivial single-source lookup (e.g. "what's the p99 on service X right now"), and say so.
gh) + Slack, correlate, hypothesize.gh/git + optional Mixpanel user-impact.--window 6h, --window 2026-06-04T14:00Z..2026-06-04T15:30Z).~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.