[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-elastic-maintain-integration":3,"mdc-efs71h-key":34,"related-repo-elastic-maintain-integration":564,"related-org-elastic-maintain-integration":670},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":11,"stars":23,"repoUrl":24,"updatedAt":25,"license":26,"forks":27,"topics":28,"repo":29,"sourceUrl":32,"mdContent":33},"maintain-integration","maintain and improve Elastic integration packages","Use when reviewing, fixing, or improving an EXISTING Elastic integration package. Covers quality reviews, targeted fixes (pipelines, field mappings, CEL programs, manifests, changelogs), full improvement passes, and minor adjustments. Use create-integration instead when creating a new package or adding a new data stream from scratch.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},"elastic","Elastic","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Felastic.png",[12,16,19,20],{"name":13,"slug":14,"type":15},"Maintenance","maintenance","tag",{"name":17,"slug":18,"type":15},"Integrations","integrations",{"name":9,"slug":8,"type":15},{"name":21,"slug":22,"type":15},"Code Analysis","code-analysis",11,"https:\u002F\u002Fgithub.com\u002Felastic\u002Fintegration-skills","2026-07-12T07:46:58.876712","Apache-2.0",2,[],{"repoUrl":24,"stars":23,"forks":27,"topics":30,"description":31},[],null,"https:\u002F\u002Fgithub.com\u002Felastic\u002Fintegration-skills\u002Ftree\u002FHEAD\u002Fskills\u002Fmaintain-integration","---\nname: maintain-integration\ndescription: \"Use when reviewing, fixing, or improving an EXISTING Elastic integration package. Covers quality reviews, targeted fixes (pipelines, field mappings, CEL programs, manifests, changelogs), full improvement passes, and minor adjustments. Use create-integration instead when creating a new package or adding a new data stream from scratch.\"\nlicense: Apache-2.0\nmetadata:\n  author: elastic\n  version: \"1.0\"\n---\n\n# maintain-integration\n\n## When to use vs create-integration\n\nUse this skill when the **package already exists**:\n- reviewing quality, ECS compliance, or correctness of an existing package\n- fixing specific issues: pipeline errors, field mappings, ECS categorization, CEL programs, manifests\n- running a full quality improvement pass (review → fix → re-validate loop)\n- making minor adjustments to existing data streams\n\nUse `create-integration` instead when:\n- creating a new integration package from scratch\n- adding a new data stream to an existing package (`create-integration` → `references\u002Fadd-datastream-workflow.md`)\n\n## Modes\n\n### Review only (read-only, no edits)\n\n→ **Read `references\u002Freview-workflow.md` fully before starting.**\n\nRun automated validation, delegate inspection to a subagent (see Dispatch convention in `references\u002Freview-workflow.md`) pointing it at `review-integration\u002Freferences\u002Freviewer-subagent-guidance.md` as its operating manual, present findings with no file changes.\n\n### Full improvement pass (analyze → fix → re-validate)\n\n→ **Read `references\u002Fimprove-workflow.md` fully before starting.**\n\nAnalyze issues (from prior review or fresh reviewer run), prioritize by severity, fix directly or delegate to subagents, re-validate, and report.\n\n### Minor direct fix (no subagents needed)\n\nFor small targeted changes you can handle inline without loading a full workflow:\n- manifest field corrections (title, description, format_version, conditions, owner)\n- changelog entries and version bumps — see `package-spec` skill\n- documentation placeholder text in `_dev\u002Fbuild\u002Fdocs\u002FREADME.md`\n- `_dev\u002Fbuild\u002Fbuild.yml` creation or ECS reference bump\n- simple field file fixes (typos, missing entry, duplicate removal)\n- CEL formatting only — run `celfmt -s -agent -i cel.yml.hbs -o cel.yml.hbs` in the stream's `agent\u002Fstream\u002F` directory\n\nRun `elastic-package lint` and `elastic-package check` after any direct edits to confirm no regressions.\n\n## Skills to load for direct work\n\n- `elastic-package-cli` — validation and test commands\n- `package-spec` — manifest rules, version bumps, and changelog schema\n\nDo **not** load domain-specific skills (pipelines, CEL, ECS, field mappings) into your own context. Delegate to subagents that already have that knowledge.\n\n## Subagents\n\nAll specialised work is delegated to the platform's **generic \u002F general-purpose subagent** (Cursor: `generalPurpose` Task agent; Claude Code: `general-purpose` Task agent; or the equivalent on other platforms). Each task prompt must **point the subagent at the relevant `*-subagent-guidance.md` file by path** and instruct it to read that file (plus the skill SKILL.md it lists in \"First steps\") end-to-end before doing any other work. **Do NOT read the guidance file yourself or paste its contents into the task prompt** — that doubles its context cost. Pass only the path plus the task-specific context. The subagent will load the manual itself in its own fresh context. Full dispatch rules and per-workflow detail live in `references\u002Freview-workflow.md` and `references\u002Fimprove-workflow.md`.\n\n| Subagent guidance file | Use for |\n|----------|---------|\n| `review-integration\u002Freferences\u002Freviewer-subagent-guidance.md` | Thorough read-only quality inspection: classifies files by domain, loads all relevant domain skills and checklists via the `review-integration` skill, returns severity-ranked, domain-tagged findings |\n| `ingest-pipelines\u002Freferences\u002Fbuilder-subagent-guidance.md` | Pipeline fixes: JSE00001, error handling, processor tags, ECS categorization, field definitions, test fixtures |\n| `cel-programs\u002Freferences\u002Fbuilder-subagent-guidance.md` | CEL fixes: program logic, cursor management, error handling, mito validation, mock API, `cel.yml.hbs` template, manifest var cleanup |\n\nWhen delegating, provide the subagent with: package path, data stream path, specific issues to fix (paste findings), sample data if relevant, and any constraints.\n\n## Data anonymization\n\nAll data committed must be fully anonymized — no real IPs, hostnames, emails, tokens, or org identifiers in any committed file. When fixing or adding test fixtures, mock responses, sample events, or documentation examples, verify all values are synthetic. Anonymize any real data found as part of the improvement pass.\n\n## References\n\n- `references\u002Freview-workflow.md` — read-only review workflow (phases 1–4, mandatory checklists, output format)\n- `references\u002Fimprove-workflow.md` — full improvement workflow (analyze → prioritize → fix → re-validate → report)\n",{"data":35,"body":38},{"name":4,"description":6,"license":26,"metadata":36},{"author":8,"version":37},"1.0",{"type":39,"children":40},"root",[41,48,55,69,94,108,136,142,149,167,187,193,208,213,219,224,293,314,320,344,356,362,425,519,524,530,535,541],{"type":42,"tag":43,"props":44,"children":45},"element","h1",{"id":4},[46],{"type":47,"value":4},"text",{"type":42,"tag":49,"props":50,"children":52},"h2",{"id":51},"when-to-use-vs-create-integration",[53],{"type":47,"value":54},"When to use vs create-integration",{"type":42,"tag":56,"props":57,"children":58},"p",{},[59,61,67],{"type":47,"value":60},"Use this skill when the ",{"type":42,"tag":62,"props":63,"children":64},"strong",{},[65],{"type":47,"value":66},"package already exists",{"type":47,"value":68},":",{"type":42,"tag":70,"props":71,"children":72},"ul",{},[73,79,84,89],{"type":42,"tag":74,"props":75,"children":76},"li",{},[77],{"type":47,"value":78},"reviewing quality, ECS compliance, or correctness of an existing package",{"type":42,"tag":74,"props":80,"children":81},{},[82],{"type":47,"value":83},"fixing specific issues: pipeline errors, field mappings, ECS categorization, CEL programs, manifests",{"type":42,"tag":74,"props":85,"children":86},{},[87],{"type":47,"value":88},"running a full quality improvement pass (review → fix → re-validate loop)",{"type":42,"tag":74,"props":90,"children":91},{},[92],{"type":47,"value":93},"making minor adjustments to existing data streams",{"type":42,"tag":56,"props":95,"children":96},{},[97,99,106],{"type":47,"value":98},"Use ",{"type":42,"tag":100,"props":101,"children":103},"code",{"className":102},[],[104],{"type":47,"value":105},"create-integration",{"type":47,"value":107}," instead when:",{"type":42,"tag":70,"props":109,"children":110},{},[111,116],{"type":42,"tag":74,"props":112,"children":113},{},[114],{"type":47,"value":115},"creating a new integration package from scratch",{"type":42,"tag":74,"props":117,"children":118},{},[119,121,126,128,134],{"type":47,"value":120},"adding a new data stream to an existing package (",{"type":42,"tag":100,"props":122,"children":124},{"className":123},[],[125],{"type":47,"value":105},{"type":47,"value":127}," → ",{"type":42,"tag":100,"props":129,"children":131},{"className":130},[],[132],{"type":47,"value":133},"references\u002Fadd-datastream-workflow.md",{"type":47,"value":135},")",{"type":42,"tag":49,"props":137,"children":139},{"id":138},"modes",[140],{"type":47,"value":141},"Modes",{"type":42,"tag":143,"props":144,"children":146},"h3",{"id":145},"review-only-read-only-no-edits",[147],{"type":47,"value":148},"Review only (read-only, no edits)",{"type":42,"tag":56,"props":150,"children":151},{},[152,154],{"type":47,"value":153},"→ ",{"type":42,"tag":62,"props":155,"children":156},{},[157,159,165],{"type":47,"value":158},"Read ",{"type":42,"tag":100,"props":160,"children":162},{"className":161},[],[163],{"type":47,"value":164},"references\u002Freview-workflow.md",{"type":47,"value":166}," fully before starting.",{"type":42,"tag":56,"props":168,"children":169},{},[170,172,177,179,185],{"type":47,"value":171},"Run automated validation, delegate inspection to a subagent (see Dispatch convention in ",{"type":42,"tag":100,"props":173,"children":175},{"className":174},[],[176],{"type":47,"value":164},{"type":47,"value":178},") pointing it at ",{"type":42,"tag":100,"props":180,"children":182},{"className":181},[],[183],{"type":47,"value":184},"review-integration\u002Freferences\u002Freviewer-subagent-guidance.md",{"type":47,"value":186}," as its operating manual, present findings with no file changes.",{"type":42,"tag":143,"props":188,"children":190},{"id":189},"full-improvement-pass-analyze-fix-re-validate",[191],{"type":47,"value":192},"Full improvement pass (analyze → fix → re-validate)",{"type":42,"tag":56,"props":194,"children":195},{},[196,197],{"type":47,"value":153},{"type":42,"tag":62,"props":198,"children":199},{},[200,201,207],{"type":47,"value":158},{"type":42,"tag":100,"props":202,"children":204},{"className":203},[],[205],{"type":47,"value":206},"references\u002Fimprove-workflow.md",{"type":47,"value":166},{"type":42,"tag":56,"props":209,"children":210},{},[211],{"type":47,"value":212},"Analyze issues (from prior review or fresh reviewer run), prioritize by severity, fix directly or delegate to subagents, re-validate, and report.",{"type":42,"tag":143,"props":214,"children":216},{"id":215},"minor-direct-fix-no-subagents-needed",[217],{"type":47,"value":218},"Minor direct fix (no subagents needed)",{"type":42,"tag":56,"props":220,"children":221},{},[222],{"type":47,"value":223},"For small targeted changes you can handle inline without loading a full workflow:",{"type":42,"tag":70,"props":225,"children":226},{},[227,232,245,256,267,272],{"type":42,"tag":74,"props":228,"children":229},{},[230],{"type":47,"value":231},"manifest field corrections (title, description, format_version, conditions, owner)",{"type":42,"tag":74,"props":233,"children":234},{},[235,237,243],{"type":47,"value":236},"changelog entries and version bumps — see ",{"type":42,"tag":100,"props":238,"children":240},{"className":239},[],[241],{"type":47,"value":242},"package-spec",{"type":47,"value":244}," skill",{"type":42,"tag":74,"props":246,"children":247},{},[248,250],{"type":47,"value":249},"documentation placeholder text in ",{"type":42,"tag":100,"props":251,"children":253},{"className":252},[],[254],{"type":47,"value":255},"_dev\u002Fbuild\u002Fdocs\u002FREADME.md",{"type":42,"tag":74,"props":257,"children":258},{},[259,265],{"type":42,"tag":100,"props":260,"children":262},{"className":261},[],[263],{"type":47,"value":264},"_dev\u002Fbuild\u002Fbuild.yml",{"type":47,"value":266}," creation or ECS reference bump",{"type":42,"tag":74,"props":268,"children":269},{},[270],{"type":47,"value":271},"simple field file fixes (typos, missing entry, duplicate removal)",{"type":42,"tag":74,"props":273,"children":274},{},[275,277,283,285,291],{"type":47,"value":276},"CEL formatting only — run ",{"type":42,"tag":100,"props":278,"children":280},{"className":279},[],[281],{"type":47,"value":282},"celfmt -s -agent -i cel.yml.hbs -o cel.yml.hbs",{"type":47,"value":284}," in the stream's ",{"type":42,"tag":100,"props":286,"children":288},{"className":287},[],[289],{"type":47,"value":290},"agent\u002Fstream\u002F",{"type":47,"value":292}," directory",{"type":42,"tag":56,"props":294,"children":295},{},[296,298,304,306,312],{"type":47,"value":297},"Run ",{"type":42,"tag":100,"props":299,"children":301},{"className":300},[],[302],{"type":47,"value":303},"elastic-package lint",{"type":47,"value":305}," and ",{"type":42,"tag":100,"props":307,"children":309},{"className":308},[],[310],{"type":47,"value":311},"elastic-package check",{"type":47,"value":313}," after any direct edits to confirm no regressions.",{"type":42,"tag":49,"props":315,"children":317},{"id":316},"skills-to-load-for-direct-work",[318],{"type":47,"value":319},"Skills to load for direct work",{"type":42,"tag":70,"props":321,"children":322},{},[323,334],{"type":42,"tag":74,"props":324,"children":325},{},[326,332],{"type":42,"tag":100,"props":327,"children":329},{"className":328},[],[330],{"type":47,"value":331},"elastic-package-cli",{"type":47,"value":333}," — validation and test commands",{"type":42,"tag":74,"props":335,"children":336},{},[337,342],{"type":42,"tag":100,"props":338,"children":340},{"className":339},[],[341],{"type":47,"value":242},{"type":47,"value":343}," — manifest rules, version bumps, and changelog schema",{"type":42,"tag":56,"props":345,"children":346},{},[347,349,354],{"type":47,"value":348},"Do ",{"type":42,"tag":62,"props":350,"children":351},{},[352],{"type":47,"value":353},"not",{"type":47,"value":355}," load domain-specific skills (pipelines, CEL, ECS, field mappings) into your own context. Delegate to subagents that already have that knowledge.",{"type":42,"tag":49,"props":357,"children":359},{"id":358},"subagents",[360],{"type":47,"value":361},"Subagents",{"type":42,"tag":56,"props":363,"children":364},{},[365,367,372,374,380,382,388,390,403,405,410,412,417,418,423],{"type":47,"value":366},"All specialised work is delegated to the platform's ",{"type":42,"tag":62,"props":368,"children":369},{},[370],{"type":47,"value":371},"generic \u002F general-purpose subagent",{"type":47,"value":373}," (Cursor: ",{"type":42,"tag":100,"props":375,"children":377},{"className":376},[],[378],{"type":47,"value":379},"generalPurpose",{"type":47,"value":381}," Task agent; Claude Code: ",{"type":42,"tag":100,"props":383,"children":385},{"className":384},[],[386],{"type":47,"value":387},"general-purpose",{"type":47,"value":389}," Task agent; or the equivalent on other platforms). Each task prompt must ",{"type":42,"tag":62,"props":391,"children":392},{},[393,395,401],{"type":47,"value":394},"point the subagent at the relevant ",{"type":42,"tag":100,"props":396,"children":398},{"className":397},[],[399],{"type":47,"value":400},"*-subagent-guidance.md",{"type":47,"value":402}," file by path",{"type":47,"value":404}," and instruct it to read that file (plus the skill SKILL.md it lists in \"First steps\") end-to-end before doing any other work. ",{"type":42,"tag":62,"props":406,"children":407},{},[408],{"type":47,"value":409},"Do NOT read the guidance file yourself or paste its contents into the task prompt",{"type":47,"value":411}," — that doubles its context cost. Pass only the path plus the task-specific context. The subagent will load the manual itself in its own fresh context. Full dispatch rules and per-workflow detail live in ",{"type":42,"tag":100,"props":413,"children":415},{"className":414},[],[416],{"type":47,"value":164},{"type":47,"value":305},{"type":42,"tag":100,"props":419,"children":421},{"className":420},[],[422],{"type":47,"value":206},{"type":47,"value":424},".",{"type":42,"tag":426,"props":427,"children":428},"table",{},[429,448],{"type":42,"tag":430,"props":431,"children":432},"thead",{},[433],{"type":42,"tag":434,"props":435,"children":436},"tr",{},[437,443],{"type":42,"tag":438,"props":439,"children":440},"th",{},[441],{"type":47,"value":442},"Subagent guidance file",{"type":42,"tag":438,"props":444,"children":445},{},[446],{"type":47,"value":447},"Use for",{"type":42,"tag":449,"props":450,"children":451},"tbody",{},[452,477,494],{"type":42,"tag":434,"props":453,"children":454},{},[455,464],{"type":42,"tag":456,"props":457,"children":458},"td",{},[459],{"type":42,"tag":100,"props":460,"children":462},{"className":461},[],[463],{"type":47,"value":184},{"type":42,"tag":456,"props":465,"children":466},{},[467,469,475],{"type":47,"value":468},"Thorough read-only quality inspection: classifies files by domain, loads all relevant domain skills and checklists via the ",{"type":42,"tag":100,"props":470,"children":472},{"className":471},[],[473],{"type":47,"value":474},"review-integration",{"type":47,"value":476}," skill, returns severity-ranked, domain-tagged findings",{"type":42,"tag":434,"props":478,"children":479},{},[480,489],{"type":42,"tag":456,"props":481,"children":482},{},[483],{"type":42,"tag":100,"props":484,"children":486},{"className":485},[],[487],{"type":47,"value":488},"ingest-pipelines\u002Freferences\u002Fbuilder-subagent-guidance.md",{"type":42,"tag":456,"props":490,"children":491},{},[492],{"type":47,"value":493},"Pipeline fixes: JSE00001, error handling, processor tags, ECS categorization, field definitions, test fixtures",{"type":42,"tag":434,"props":495,"children":496},{},[497,506],{"type":42,"tag":456,"props":498,"children":499},{},[500],{"type":42,"tag":100,"props":501,"children":503},{"className":502},[],[504],{"type":47,"value":505},"cel-programs\u002Freferences\u002Fbuilder-subagent-guidance.md",{"type":42,"tag":456,"props":507,"children":508},{},[509,511,517],{"type":47,"value":510},"CEL fixes: program logic, cursor management, error handling, mito validation, mock API, ",{"type":42,"tag":100,"props":512,"children":514},{"className":513},[],[515],{"type":47,"value":516},"cel.yml.hbs",{"type":47,"value":518}," template, manifest var cleanup",{"type":42,"tag":56,"props":520,"children":521},{},[522],{"type":47,"value":523},"When delegating, provide the subagent with: package path, data stream path, specific issues to fix (paste findings), sample data if relevant, and any constraints.",{"type":42,"tag":49,"props":525,"children":527},{"id":526},"data-anonymization",[528],{"type":47,"value":529},"Data anonymization",{"type":42,"tag":56,"props":531,"children":532},{},[533],{"type":47,"value":534},"All data committed must be fully anonymized — no real IPs, hostnames, emails, tokens, or org identifiers in any committed file. When fixing or adding test fixtures, mock responses, sample events, or documentation examples, verify all values are synthetic. Anonymize any real data found as part of the improvement pass.",{"type":42,"tag":49,"props":536,"children":538},{"id":537},"references",[539],{"type":47,"value":540},"References",{"type":42,"tag":70,"props":542,"children":543},{},[544,554],{"type":42,"tag":74,"props":545,"children":546},{},[547,552],{"type":42,"tag":100,"props":548,"children":550},{"className":549},[],[551],{"type":47,"value":164},{"type":47,"value":553}," — read-only review workflow (phases 1–4, mandatory checklists, output format)",{"type":42,"tag":74,"props":555,"children":556},{},[557,562],{"type":42,"tag":100,"props":558,"children":560},{"className":559},[],[561],{"type":47,"value":206},{"type":47,"value":563}," — full improvement workflow (analyze → prioritize → fix → re-validate → report)",{"items":565,"total":669},[566,585,600,610,627,640,655],{"slug":567,"name":567,"fn":568,"description":569,"org":570,"tags":571,"stars":23,"repoUrl":24,"updatedAt":584},"anonymize-logs","anonymize sensitive log data","Anonymize and sanitize customer-provided log files before they are committed as pipeline test fixtures or sample events. Performs a line-by-line review and replaces all sensitive values inline, preserving log structure and format exactly — never reformats, re-indents, or restructures content. Invoke manually with \u002Fanonymize-logs.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[572,575,578,581],{"name":573,"slug":574,"type":15},"Data Cleaning","data-cleaning",{"name":576,"slug":577,"type":15},"Logs","logs",{"name":579,"slug":580,"type":15},"Privacy","privacy",{"name":582,"slug":583,"type":15},"Security","security","2026-07-18T05:13:04.420121",{"slug":586,"name":586,"fn":587,"description":588,"org":589,"tags":590,"stars":23,"repoUrl":24,"updatedAt":599},"cel-programs","write CEL programs for data collection","Use for all CEL and mito work on integrations that collect from APIs — writing CEL programs, cel.yml.hbs templates, manifest configuration, mock-first development with the mito CLI, system test mock setup, and answering CEL\u002Fmito questions. Load this skill whenever any data stream uses the cel input type.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[591,594,597,598],{"name":592,"slug":593,"type":15},"API Development","api-development",{"name":595,"slug":596,"type":15},"Data Engineering","data-engineering",{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},"2026-07-12T07:47:10.207064",{"slug":105,"name":105,"fn":601,"description":602,"org":603,"tags":604,"stars":23,"repoUrl":24,"updatedAt":609},"create Elastic integration packages","Use when creating a new Elastic integration package, scaffolding data streams, answering package layout or structure questions, or running the end-to-end integration build workflow. Covers package topology, scaffold commands, post-scaffold edits, and full orchestration of CEL\u002Fpipeline\u002Ftest subagents.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[605,608],{"name":606,"slug":607,"type":15},"Elasticsearch","elasticsearch",{"name":17,"slug":18,"type":15},"2026-07-12T07:46:56.318866",{"slug":611,"name":611,"fn":612,"description":613,"org":614,"tags":615,"stars":23,"repoUrl":24,"updatedAt":626},"dashboard-guidelines","create and review Kibana dashboard assets","Use when creating or reviewing Kibana assets in packages, including dashboard export structure, naming, and data stream alignment.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[616,619,620,623],{"name":617,"slug":618,"type":15},"Dashboards","dashboards",{"name":606,"slug":607,"type":15},{"name":621,"slug":622,"type":15},"Kibana","kibana",{"name":624,"slug":625,"type":15},"UI Components","ui-components","2026-07-12T07:47:07.702332",{"slug":628,"name":628,"fn":629,"description":630,"org":631,"tags":632,"stars":23,"repoUrl":24,"updatedAt":639},"dashboard-review","review Elastic dashboard JSON changes","Use when reviewing dashboard JSON changes in a PR or branch. Extracts structured descriptions with kbdash, compares before\u002Fafter, and checks guideline compliance.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[633,636,637,638],{"name":634,"slug":635,"type":15},"Code Review","code-review",{"name":617,"slug":618,"type":15},{"name":9,"slug":8,"type":15},{"name":621,"slug":622,"type":15},"2026-07-12T07:47:06.493988",{"slug":641,"name":641,"fn":642,"description":643,"org":644,"tags":645,"stars":23,"repoUrl":24,"updatedAt":654},"ecs-field-mappings","define ECS field mappings for integrations","Use when defining field mappings for data streams, populating ecs.yml with ECS field references, selecting ECS categorization values, choosing custom field types, or troubleshooting mapping validation failures.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[646,649,652,653],{"name":647,"slug":648,"type":15},"Data Modeling","data-modeling",{"name":650,"slug":651,"type":15},"Data Quality","data-quality",{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},"2026-07-12T07:47:13.472534",{"slug":331,"name":331,"fn":656,"description":657,"org":658,"tags":659,"stars":23,"repoUrl":24,"updatedAt":668},"develop and validate Elastic integrations","Use when developing or validating Elastic integrations with elastic-package commands such as build, check, lint, format, test, stack, service, install, profiles, and benchmark.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[660,663,664,665],{"name":661,"slug":662,"type":15},"CLI","cli",{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},{"name":666,"slug":667,"type":15},"Testing","testing","2026-07-12T07:46:57.647395",14,{"items":671,"total":835},[672,691,708,719,738,750,760,773,785,798,809,822],{"slug":673,"name":673,"fn":674,"description":675,"org":676,"tags":677,"stars":688,"repoUrl":689,"updatedAt":690},"accessing-benchmark-results","retrieve and analyze Rally benchmark results","Retrieve Rally benchmark results from an external Elasticsearch metrics store. Use to list past races, get a single race's overall (per-task) results, chart a metric's trend across multiple runs, compare two races, or check whether a run converged — e.g. \"show me recent geonames races\", \"what's the service_time trend for nyc_taxis over the last 30 days?\", \"compare these two race-ids\". Applies when datastore.type = elasticsearch is set in ~\u002F.rally\u002Frally.ini.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[678,681,684,685],{"name":679,"slug":680,"type":15},"Analytics","analytics",{"name":682,"slug":683,"type":15},"Data Analysis","data-analysis",{"name":9,"slug":8,"type":15},{"name":686,"slug":687,"type":15},"Performance","performance",2027,"https:\u002F\u002Fgithub.com\u002Felastic\u002Frally","2026-07-12T07:46:38.54144",{"slug":692,"name":692,"fn":693,"description":694,"org":695,"tags":696,"stars":688,"repoUrl":689,"updatedAt":707},"developing-rally","develop and debug Rally source code","Work on Rally's own codebase, not running benchmarks with it. Use when setting up the dev environment, running Rally's tests or linters, navigating its source, debugging Rally's own code, or making changes to Rally itself.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[697,700,701,704],{"name":698,"slug":699,"type":15},"Debugging","debugging",{"name":9,"slug":8,"type":15},{"name":702,"slug":703,"type":15},"Engineering","engineering",{"name":705,"slug":706,"type":15},"Local Development","local-development","2026-07-12T07:46:35.976807",{"slug":709,"name":709,"fn":710,"description":711,"org":712,"tags":713,"stars":688,"repoUrl":689,"updatedAt":718},"running-benchmarks","run Rally benchmarks against Elasticsearch","Run Rally benchmarks (races) against Elasticsearch — an existing\u002Fexternal cluster or a Rally-provisioned distribution — and read the summary report. Use when running a race (any pipeline, track, challenge, target-hosts, or auth) or when interpreting throughput, latency, and service_time results.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[714,715,716,717],{"name":9,"slug":8,"type":15},{"name":606,"slug":607,"type":15},{"name":686,"slug":687,"type":15},{"name":666,"slug":667,"type":15},"2026-07-12T07:46:37.277964",{"slug":720,"name":720,"fn":721,"description":722,"org":723,"tags":724,"stars":735,"repoUrl":736,"updatedAt":737},"cloud-access-management","manage Elastic Cloud organization access","Manage Elastic Cloud organization access: invite users, assign roles to Serverless projects, and create or revoke Cloud API keys. Use when granting, modifying, or auditing user access.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[725,728,729,732],{"name":726,"slug":727,"type":15},"Cloud","cloud",{"name":9,"slug":8,"type":15},{"name":730,"slug":731,"type":15},"Operations","operations",{"name":733,"slug":734,"type":15},"Permissions","permissions",531,"https:\u002F\u002Fgithub.com\u002Felastic\u002Fagent-skills","2026-07-12T07:46:44.946285",{"slug":739,"name":739,"fn":740,"description":741,"org":742,"tags":743,"stars":735,"repoUrl":736,"updatedAt":749},"cloud-create-project","create Elastic Cloud Serverless projects","Creates Elastic Cloud Serverless projects (Elasticsearch, Observability, or Security) via the REST API, saves credentials to file, and bootstraps a scoped Elasticsearch API key. Use when creating a new serverless project, provisioning a search or observability environment, or spinning up a new Elastic Cloud project.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[744,745,748],{"name":726,"slug":727,"type":15},{"name":746,"slug":747,"type":15},"Deployment","deployment",{"name":606,"slug":607,"type":15},"2026-07-12T07:46:42.353362",{"slug":751,"name":751,"fn":752,"description":753,"org":754,"tags":755,"stars":735,"repoUrl":736,"updatedAt":759},"cloud-manage-project","manage Elastic Cloud Serverless projects","Manages existing Elastic Cloud Serverless projects: list, get, update, delete, reset credentials, resume, and load saved credentials. Connects to existing projects by resolving endpoints and acquiring scoped Elasticsearch API keys. Use when performing day-2 operations on serverless projects, connecting to an existing project, loading or resetting project credentials, or looking up project details.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[756,757,758],{"name":726,"slug":727,"type":15},{"name":606,"slug":607,"type":15},{"name":730,"slug":731,"type":15},"2026-07-12T07:46:41.097412",{"slug":761,"name":761,"fn":762,"description":763,"org":764,"tags":765,"stars":735,"repoUrl":736,"updatedAt":772},"cloud-network-security","manage Elastic Cloud network security","Manage Serverless network security (traffic filters): create, update, and delete IP filters and AWS PrivateLink VPC filters. Use when restricting network access or configuring private connectivity.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[766,767,768,771],{"name":726,"slug":727,"type":15},{"name":606,"slug":607,"type":15},{"name":769,"slug":770,"type":15},"Networking","networking",{"name":582,"slug":583,"type":15},"2026-07-12T07:46:43.675992",{"slug":774,"name":774,"fn":775,"description":776,"org":777,"tags":778,"stars":735,"repoUrl":736,"updatedAt":784},"cloud-setup","configure Elastic Cloud authentication","Configures Elastic Cloud authentication and environment defaults. Use when setting up EC_API_KEY, configuring Cloud API access, or when another cloud skill requires credentials.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[779,782,783],{"name":780,"slug":781,"type":15},"Authentication","authentication",{"name":726,"slug":727,"type":15},{"name":606,"slug":607,"type":15},"2026-07-12T07:46:39.783105",{"slug":786,"name":786,"fn":787,"description":788,"org":789,"tags":790,"stars":735,"repoUrl":736,"updatedAt":797},"elasticsearch-audit","configure Elasticsearch security audit logs","Enable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[791,794,795,796],{"name":792,"slug":793,"type":15},"Audit","audit",{"name":606,"slug":607,"type":15},{"name":576,"slug":577,"type":15},{"name":582,"slug":583,"type":15},"2026-07-12T07:47:35.092599",{"slug":799,"name":799,"fn":800,"description":801,"org":802,"tags":803,"stars":735,"repoUrl":736,"updatedAt":808},"elasticsearch-authn","configure Elasticsearch authentication realms","Authenticate to Elasticsearch using native, file-based, LDAP\u002FAD, SAML, OIDC, Kerberos, JWT, or certificate realms. Use when connecting with credentials, choosing a realm, or managing API keys. Assumes the target realms are already configured.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[804,805,806,807],{"name":780,"slug":781,"type":15},{"name":9,"slug":8,"type":15},{"name":606,"slug":607,"type":15},{"name":582,"slug":583,"type":15},"2026-07-12T07:47:41.474547",{"slug":810,"name":810,"fn":811,"description":812,"org":813,"tags":814,"stars":735,"repoUrl":736,"updatedAt":821},"elasticsearch-authz","manage Elasticsearch RBAC and security roles","Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP\u002FSAML.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[815,816,817,820],{"name":9,"slug":8,"type":15},{"name":606,"slug":607,"type":15},{"name":818,"slug":819,"type":15},"RBAC","rbac",{"name":582,"slug":583,"type":15},"2026-07-12T07:47:36.394177",{"slug":823,"name":823,"fn":824,"description":825,"org":826,"tags":827,"stars":735,"repoUrl":736,"updatedAt":834},"elasticsearch-esql","query Elasticsearch data with ES|QL","Execute ES|QL (Elasticsearch Query Language) queries, use when the user wants to query Elasticsearch data, analyze logs, aggregate metrics, explore data, or create charts and dashboards from ES|QL results.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[828,829,830,831],{"name":679,"slug":680,"type":15},{"name":682,"slug":683,"type":15},{"name":606,"slug":607,"type":15},{"name":832,"slug":833,"type":15},"SQL","sql","2026-07-12T07:47:40.249533",86]