forensics

Reconstruct pipeline incident timelines and detect anomalies from trajectory data.

1|Updated Mar 15, 2026
One-click install
npx skills add https://github.com/paulingham/.claude --skill forensics-paulingham
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: forensics
Source: https://github.com/paulingham/.claude/tree/main/skills/forensics
Command: npx skills add https://github.com/paulingham/.claude --skill forensics-paulingham

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Post-incident investigations of pipeline runs are often manual, fragmented, and time-consuming. This Skill reconstructs timelines from trajectory data, detects anomalies, verifies artifact integrity, and produces structured findings to accelerate root cause analysis.

Core Features & Use Cases

  • Timeline reconstruction: rebuilds agent trajectories from trajectory.jsonl and pipeline state files.
  • Anomaly detection: flags long phases, retries, gaps, and orphan agents to highlight failure modes.
  • Artifact integrity & reporting: cross-checks git history and pipeline state to generate evidence-backed findings.

Quick Start

Provide a post-incident dataset (trajectory.jsonl and pipeline.md) in the task state and run forensics to generate a findings report.

Frequently Asked Questions about forensics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I reconstruct event timelines for pipeline incident investigation?

Post-incident pipeline analysis works by reconstructing event timelines from trajectory data and cross-checking artifact integrity against git history. This structured approach accelerates root cause analysis for complex pipelines where the failure point is unclear.

How do I find the root cause of repeated pipeline failures?

Post-incident pipeline analysis works by reconstructing event timelines from trajectory data and cross-checking artifact integrity against git history. This structured approach accelerates root cause analysis for complex pipelines where the failure point is unclear.

What is the best way to detect anomalies in trajectory data after an incident?

Post-incident pipeline analysis works by reconstructing event timelines from trajectory data and cross-checking artifact integrity against git history. This structured approach accelerates root cause analysis for complex pipelines where the failure point is unclear.

Do I need a specific dataset format to generate an evidence report for a pipeline review?

Post-incident pipeline analysis works by reconstructing event timelines from trajectory data and cross-checking artifact integrity against git history. This structured approach accelerates root cause analysis for complex pipelines where the failure point is unclear.

When should I use scripted timeline parsing for post-incident reviews?

Post-incident pipeline analysis works by reconstructing event timelines from trajectory data and cross-checking artifact integrity against git history. This structured approach accelerates root cause analysis for complex pipelines where the failure point is unclear.