skywatch-conducting-investigations

Investigate suspicious AT Protocol accounts using a six-phase methodology.

6|Updated Feb 21, 2026
One-click install
npx skills add https://github.com/skywatch-bsky/skywatch-agent-skills --skill skywatch-conducting-investigations
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: skywatch-conducting-investigations
Source: https://github.com/skywatch-bsky/skywatch-agent-skills/tree/main/polytoken/skills/skywatch-conducting-investigations
Command: npx skills add https://github.com/skywatch-bsky/skywatch-agent-skills --skill skywatch-conducting-investigations

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This skill provides a rigorous, six-phase framework for investigating suspicious activity on the AT Protocol, ensuring consistent evidence gathering, coordination mapping, and reporting.

Core Features & Use Cases

  • Structured Investigation Workflow: Guides the user through discovery, characterization, linkage, amplification mapping, rule validation, and reporting.
  • Subagent Delegation: Standardizes the offloading of rote ClickHouse queries to specialized data-analyst subagents to preserve context.
  • Evidence-Based Decision Making: Provides clear standards for determining account linkage, coordination, and policy violations.

Quick Start

Initiate the investigation process for a suspicious DID by following the six-phase methodology outlined in this skill to gather evidence and generate a formal report.

Frequently Asked Questions about skywatch-conducting-investigations

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a network investigation of suspicious accounts on the AT Protocol?

Mapping amplification patterns involves tracing how content is distributed and boosted across linked accounts within the network. This process identifies coordinated behavior and validates detection rules to flag policy violations accurately.

How do I map coordination and amplification patterns in AT Protocol network analysis?

Mapping amplification patterns involves tracing how content is distributed across linked accounts within the network. The investigation methodology standardizes this process to identify coordinated behavior and validate detection rules against policy violations.

Do I need ClickHouse and Ozone moderation tools to investigate AT Protocol accounts?

The investigation methodology delegates rote ClickHouse queries to specialized data-analyst subagents. This standardizes data retrieval and preserves context for the primary investigation workflow.

Can I use subagents to handle ClickHouse queries during a moderation investigation?

Yes, the investigation methodology delegates rote ClickHouse queries to specialized data-analyst subagents. This standardizes data retrieval and preserves context for the primary investigation workflow.

What are the limitations of using a structured methodology for AT Protocol moderation?

Before starting an investigation, ensure access to ClickHouse for network data retrieval and Ozone moderation tools for evidence management. You must have a target suspicious DID to initiate the six-phase methodology and gather formal evidence.