[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"org-elastic":3,"repo-skills-v-0-3-0":232},{"org":4,"repos":57},{"slug":5,"name":6,"logoUrl":7,"githubOrg":5,"website":8,"skillCount":9,"repoCount":10,"topRepos":11,"topTags":27,"lastUpdatedAt":56},"elastic","Elastic","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Felastic.png","https:\u002F\u002Fwww.elastic.co",86,9,[12,15,18,21,24],{"name":13,"skillCount":14},"elastic\u002Fagent-skills",35,{"name":16,"skillCount":17},"elastic\u002Felastic-docs-skills",18,{"name":19,"skillCount":20},"elastic\u002Fintegration-skills",14,{"name":22,"skillCount":23},"elastic\u002Fexample-mcp-app-observability",6,{"name":25,"skillCount":26},"elastic\u002Fexample-mcp-app-security",5,[28,29,32,35,38,41,44,47,50,53],{"slug":5,"name":6},{"slug":30,"name":31},"elasticsearch","Elasticsearch",{"slug":33,"name":34},"observability","Observability",{"slug":36,"name":37},"documentation","Documentation",{"slug":39,"name":40},"kibana","Kibana",{"slug":42,"name":43},"security","Security",{"slug":45,"name":46},"technical-writing","Technical Writing",{"slug":48,"name":49},"monitoring","Monitoring",{"slug":51,"name":52},"integrations","Integrations",{"slug":54,"name":55},"dashboards","Dashboards","2026-07-18T05:13:04.420121",[58,76,99,116,136,160,180,202,218],{"name":59,"fullName":13,"repoUrl":60,"skillCount":14,"stars":61,"forks":62,"description":63,"topics":64,"topTags":65,"topTagCount":74,"lastUpdatedAt":75},"agent-skills","https:\u002F\u002Fgithub.com\u002Felastic\u002Fagent-skills",531,41,"Official Elastic Skills",[],[66,67,68,69,70,71],{"slug":5,"name":6},{"slug":30,"name":31},{"slug":39,"name":40},{"slug":33,"name":34},{"slug":42,"name":43},{"slug":72,"name":73},"opentelemetry","OpenTelemetry",45,"2026-07-12T07:49:33.582904",{"name":77,"fullName":16,"repoUrl":78,"skillCount":17,"stars":79,"forks":10,"description":80,"topics":81,"topTags":84,"topTagCount":97,"lastUpdatedAt":98},"elastic-docs-skills","https:\u002F\u002Fgithub.com\u002Felastic\u002Felastic-docs-skills",71,"Instructions for code agents on how to author Elastic docs",[82,5,83],"docs","skills",[85,86,87,88,91,94],{"slug":36,"name":37},{"slug":5,"name":6},{"slug":45,"name":46},{"slug":89,"name":90},"audit","Audit",{"slug":92,"name":93},"github","GitHub",{"slug":95,"name":96},"seo","SEO",12,"2026-07-12T07:50:44.050021",{"name":100,"fullName":19,"repoUrl":101,"skillCount":20,"stars":102,"forks":103,"description":104,"topics":105,"topTags":106,"topTagCount":115,"lastUpdatedAt":56},"integration-skills","https:\u002F\u002Fgithub.com\u002Felastic\u002Fintegration-skills",11,2,null,[],[107,108,109,110,111,114],{"slug":5,"name":6},{"slug":51,"name":52},{"slug":30,"name":31},{"slug":54,"name":55},{"slug":112,"name":113},"data-engineering","Data Engineering",{"slug":39,"name":40},31,{"name":117,"fullName":22,"repoUrl":118,"skillCount":23,"stars":119,"forks":120,"description":104,"topics":121,"topTags":122,"topTagCount":102,"lastUpdatedAt":135},"example-mcp-app-observability","https:\u002F\u002Fgithub.com\u002Felastic\u002Fexample-mcp-app-observability",10,7,[],[123,124,125,126,129,132],{"slug":5,"name":6},{"slug":33,"name":34},{"slug":48,"name":49},{"slug":127,"name":128},"apm","APM",{"slug":130,"name":131},"alerting","Alerting",{"slug":133,"name":134},"anomaly-detection","Anomaly Detection","2026-07-12T07:49:28.114697",{"name":137,"fullName":25,"repoUrl":138,"skillCount":26,"stars":17,"forks":119,"description":139,"topics":140,"topTags":147,"topTagCount":158,"lastUpdatedAt":159},"example-mcp-app-security","https:\u002F\u002Fgithub.com\u002Felastic\u002Fexample-mcp-app-security","Reference MCP App for Elastic Security — interactive SOC dashboards inside Claude, Cursor, and other MCP hosts.",[141,142,143,5,144,145,42,146],"ai","claude","cursor","mcp","model-context-protocol","soc",[148,149,150,153,154,155],{"slug":42,"name":43},{"slug":5,"name":6},{"slug":151,"name":152},"triage","Triage",{"slug":48,"name":49},{"slug":54,"name":55},{"slug":156,"name":157},"incident-response","Incident Response",8,"2026-07-12T07:48:29.539756",{"name":161,"fullName":162,"repoUrl":163,"skillCount":164,"stars":165,"forks":166,"description":104,"topics":167,"topTags":168,"topTagCount":120,"lastUpdatedAt":179},"elastic-ramen","elastic\u002Felastic-ramen","https:\u002F\u002Fgithub.com\u002Felastic\u002Felastic-ramen",3,16,4,[],[169,170,173,174,175,178],{"slug":5,"name":6},{"slug":171,"name":172},"debugging","Debugging",{"slug":39,"name":40},{"slug":33,"name":34},{"slug":176,"name":177},"cli","CLI",{"slug":30,"name":31},"2026-07-12T07:49:44.954024",{"name":181,"fullName":182,"repoUrl":183,"skillCount":164,"stars":184,"forks":185,"description":186,"topics":187,"topTags":188,"topTagCount":10,"lastUpdatedAt":201},"rally","elastic\u002Frally","https:\u002F\u002Fgithub.com\u002Felastic\u002Frally",2027,339,"Macrobenchmarking framework for Elasticsearch",[30],[189,190,193,196,199,200],{"slug":5,"name":6},{"slug":191,"name":192},"performance","Performance",{"slug":194,"name":195},"analytics","Analytics",{"slug":197,"name":198},"data-analysis","Data Analysis",{"slug":171,"name":172},{"slug":30,"name":31},"2026-07-12T07:46:38.54144",{"name":203,"fullName":204,"repoUrl":205,"skillCount":206,"stars":206,"forks":207,"description":208,"topics":209,"topTags":210,"topTagCount":103,"lastUpdatedAt":217},"clients-team-automations","elastic\u002Fclients-team-automations","https:\u002F\u002Fgithub.com\u002Felastic\u002Fclients-team-automations",1,0,"Contains shared reusable GitHub Actions workflows of the clients team.",[],[211,214],{"slug":212,"name":213},"engineering","Engineering",{"slug":215,"name":216},"qa","QA","2026-07-12T07:50:52.684493",{"name":219,"fullName":220,"repoUrl":221,"skillCount":206,"stars":222,"forks":23,"description":223,"topics":224,"topTags":225,"topTagCount":26,"lastUpdatedAt":231},"esdiag","elastic\u002Fesdiag","https:\u002F\u002Fgithub.com\u002Felastic\u002Fesdiag",28,"Elastic Stack Diagnostics",[],[226,227,228,229,230],{"slug":171,"name":172},{"slug":5,"name":6},{"slug":30,"name":31},{"slug":33,"name":34},{"slug":191,"name":192},"2026-07-12T07:50:27.992499",{"items":233,"total":23},[234,246,257,272,283,296],{"slug":235,"name":235,"fn":236,"description":237,"org":238,"tags":239,"stars":119,"repoUrl":118,"updatedAt":245},"apm-health-summary","summarize Elastic APM service health","Get a cluster-level rollup of service health from APM telemetry — the \"how's my environment right now?\" entry point for observability investigations. Use whenever the user asks about HEALTH, STATUS, or general wellbeing of an environment \u002F cluster \u002F namespace (\"how's my cluster\", \"status of the X env\", \"what's broken\", \"any issues\", \"show me the health of …\", \"give me a status report\", \"what should I look at\", \"things feel slow\"). This applies regardless of any time qualifier — \"show me the health of X over the past hour\" still routes here (with lookback=\"1h\"), NOT to observe. observe is for raw-metric queries; this tool is for the rollup. Gracefully degrades: layers in Kubernetes pod data and ML anomaly context when those backends are present, but still returns useful APM-only output if they aren't. Do not use for log-only or metrics-only customers — this tool requires Elastic APM.\n",{"slug":5,"name":6,"logoUrl":7,"githubOrg":5},[240,242,243,244],{"name":128,"slug":127,"type":241},"tag",{"name":6,"slug":5,"type":241},{"name":49,"slug":48,"type":241},{"name":34,"slug":33,"type":241},"2026-07-12T07:49:24.405551",{"slug":247,"name":247,"fn":248,"description":249,"org":250,"tags":251,"stars":119,"repoUrl":118,"updatedAt":256},"apm-service-dependencies","map application topology from APM telemetry","Map the application topology from APM telemetry — which services call which, over what protocols, with what call volume and latency. Use when the user asks \"what calls X\", \"what depends on X\", \"show me the topology\", \"what are the upstream\u002Fdownstream services\", \"where does this service fit\", or is doing root-cause investigation and needs to trace how a problem propagates through the call graph. Also trigger for \"service map\", \"dependency graph\", \"blast radius of service X\", or \"who's the dependency of Y\". Requires Elastic APM — do not trigger for log-only or metrics-only customers.\n",{"slug":5,"name":6,"logoUrl":7,"githubOrg":5},[252,253,254,255],{"name":128,"slug":127,"type":241},{"name":6,"slug":5,"type":241},{"name":49,"slug":48,"type":241},{"name":34,"slug":33,"type":241},"2026-07-12T07:49:23.167442",{"slug":258,"name":258,"fn":259,"description":260,"org":261,"tags":262,"stars":119,"repoUrl":118,"updatedAt":271},"k8s-blast-radius","assess Kubernetes node failure impact","Assess the impact of a Kubernetes node going offline — which deployments lose all replicas (full outage), which lose partial capacity (degraded), which are unaffected, and whether the cluster has enough spare capacity to reschedule the lost pods. Use when the user asks \"what happens if node X goes down\", \"what's the blast radius of draining this node\", \"can I safely maintain node Y\", \"what's running on this node\", \"if I evict this node what breaks\", or is planning node maintenance, a cluster upgrade, or investigating an actual node failure. Requires Kubernetes (kubeletstats metrics) and Elastic APM for downstream service impact — do not trigger for non-K8s deployments.\n",{"slug":5,"name":6,"logoUrl":7,"githubOrg":5},[263,264,267,268],{"name":6,"slug":5,"type":241},{"name":265,"slug":266,"type":241},"Kubernetes","kubernetes",{"name":34,"slug":33,"type":241},{"name":269,"slug":270,"type":241},"Risk Assessment","risk-assessment","2026-07-12T07:49:25.645103",{"slug":273,"name":273,"fn":274,"description":275,"org":276,"tags":277,"stars":119,"repoUrl":118,"updatedAt":282},"manage-alerts","manage Kibana alerting rules","CRUD for Kibana alerting rules — create, list, get, or delete custom-threshold rules. Use when the user says \"alert me when\", \"create a rule for\", \"page me if\", \"set up an alert\", \"show me my rules\", \"what alerts do I have\", \"delete that alert\", \"remove the rule\". Backend-agnostic — works on any metric field in any index pattern (metrics-*, logs-*, traces-apm*, custom). For transient session-scoped monitoring use `observe` instead. Requires Kibana with the Alerting feature enabled — the tool is auto-disabled when no Kibana URL is configured.\n",{"slug":5,"name":6,"logoUrl":7,"githubOrg":5},[278,279,280,281],{"name":131,"slug":130,"type":241},{"name":6,"slug":5,"type":241},{"name":40,"slug":39,"type":241},{"name":49,"slug":48,"type":241},"2026-07-12T07:49:21.846108",{"slug":284,"name":284,"fn":285,"description":286,"org":287,"tags":288,"stars":119,"repoUrl":118,"updatedAt":295},"ml-anomalies","query Elastic ML anomaly detection results","Query Elastic ML anomaly detection results to understand what's behaving unusually, why, and how badly. Use when the user asks \"what's anomalous\", \"is anything unusual happening\", \"why is X slow\u002Fspiking\", \"show me the weirdness\", or mentions memory growth, CPU spikes, restart patterns, unusual latency, unexpected error rates, or drift from typical behavior. Also trigger for \"ML anomalies\", \"anomaly detection\", \"Elastic ML\", \"what does ML think\", or when the user wants to understand behavior that deviates from baseline. The tool opens an inline explainer view with a severity gauge, plain-English narrative, and per-entity deviation breakdown — so the agent should USE the visualization, not just dump JSON.\n",{"slug":5,"name":6,"logoUrl":7,"githubOrg":5},[289,290,291,294],{"name":134,"slug":133,"type":241},{"name":6,"slug":5,"type":241},{"name":292,"slug":293,"type":241},"Machine Learning","machine-learning",{"name":34,"slug":33,"type":241},"2026-07-12T07:49:26.869446",{"slug":297,"name":297,"fn":298,"description":299,"org":300,"tags":301,"stars":119,"repoUrl":118,"updatedAt":135},"observe","monitor Elastic observability telemetry","The agent's Elastic-access primitive. Four modes: wait for an ML anomaly to fire, poll an ES|QL metric (live-sample or wait for a threshold), read a single-instance scalar value, or return a full ES|QL table. Use when the user says \"tell me when...\", \"let me know if...\", \"wait until X drops below Y\", \"watch for anything unusual\", \"monitor for the next N minutes\", \"poll until stable\", \"what is X right now\", \"list …\", \"which … are …\", or wants transient (session-scoped) monitoring or ad-hoc querying without creating a persistent Kibana rule. Also trigger for \"keep an eye on\" and post-remediation validation.\n",{"slug":5,"name":6,"logoUrl":7,"githubOrg":5},[302,303,306,307],{"name":6,"slug":5,"type":241},{"name":304,"slug":305,"type":241},"Metrics","metrics",{"name":49,"slug":48,"type":241},{"name":34,"slug":33,"type":241}]