conducting-investigations

Analyze suspicious AT Protocol network activity through a six-phase investigation framework.

6|Updated Feb 21, 2026
One-click install
npx skills add https://github.com/skywatch-bsky/skywatch-agent-skills --skill conducting-investigations
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: conducting-investigations
Source: https://github.com/skywatch-bsky/skywatch-agent-skills/tree/main/claude-skills/plugins/skywatch-investigations/skills/conducting-investigations
Command: npx skills add https://github.com/skywatch-bsky/skywatch-agent-skills --skill conducting-investigations

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This skill provides a rigorous, six-phase framework for investigating suspicious activity on the AT Protocol, ensuring consistent, evidence-based analysis and reporting while minimizing context window fatigue.

Core Features & Use Cases

  • Structured Methodology: Guides the investigator through discovery, characterization, linkage, amplification mapping, rule validation, and reporting.
  • Subagent Delegation: Offloads rote ClickHouse querying to subagents, preserving the investigator's focus for high-level analysis.
  • Use Case: When a cluster of accounts exhibits coordinated bot-like behavior, use this skill to systematically map their infrastructure, identify amplification targets, and generate a formal investigation report for moderation action.

Quick Start

Initiate the conducting-investigations skill to begin a new six-phase analysis of the suspicious account activity identified in the recent security logs.

Frequently Asked Questions about conducting-investigations

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate coordinated bot-like behavior on the AT Protocol?

To investigate coordinated bot activity on the AT Protocol, apply a structured six-phase methodology covering discovery, characterization, linkage, amplification mapping, rule validation, and reporting to ensure consistent evidence-based analysis.

What is the best way to map infrastructure linkage for suspicious AT Protocol accounts?

The best way to map infrastructure linkage is through a structured investigation framework that systematically identifies bot-like behavior and infrastructure connections while maintaining consistent evidence documentation standards.

Can I use ClickHouse querying to identify amplification patterns on the AT Protocol?

Yes, you can identify amplification patterns by delegating ClickHouse querying to subagents, which offloads rote data collection and preserves the investigator's focus for high-level analysis of coordinated network activity.

How does subagent delegation help with AT Protocol moderation analysis?

Subagent delegation assists moderation analysis by offloading rote ClickHouse data collection tasks, which minimizes context window fatigue and preserves the investigator's focus for high-level analysis and evidence documentation.

Do I need a standardized reporting format for AT Protocol network investigations?

Yes, a standardized reporting format is needed for AT Protocol investigations to ensure consistent evidence documentation and generate formal reports that directly support moderation action and enforcement workflows.

What are the limitations of manual analysis when detecting coordination on the AT Protocol?

Manual analysis of AT Protocol coordination is limited by context window fatigue and inconsistent evidence documentation, which are mitigated by using a structured six-phase investigation framework with subagent-assisted querying.