skills/platform/observability/SKILL.md
Use when monitoring or diagnosing the wicked-garden plugin ecosystem — health probes, contract assertions, hook traces, error pattern detection, and APM/logging/metrics toolchain discovery. NOT for distributed tracing across services (use the platform domain skill's traces action) or audit evidence (use platform/audit). Use when: "plugin health", "health probe", "hook didn't fire", "hook traces", "contract assertions", "validate script outputs", "what monitoring tools are installed", "toolchain discovery", or any former /wicked-garden:platform:{plugin-health|assert|toolchain} invocation.
npx skillsauth add mikeparcewski/wicked-garden wicked-garden-platform-observabilityInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Monitor and diagnose the wicked-garden plugin ecosystem — health probes, contract assertions, and hook execution traces. All three pillars run inline (no agent delegation needed).
# Check plugin ecosystem health
sh "${CLAUDE_PLUGIN_ROOT}/scripts/_python.sh" "${CLAUDE_PLUGIN_ROOT}/scripts/_run.py" scripts/platform/observability/health_probe.py
# Query recent hook traces (operational log)
sh "${CLAUDE_PLUGIN_ROOT}/scripts/_python.sh" "${CLAUDE_PLUGIN_ROOT}/scripts/_run.py" scripts/platform/observability/ops_log_viewer.py --tail 20
# Validate script output contracts
sh "${CLAUDE_PLUGIN_ROOT}/scripts/_python.sh" "${CLAUDE_PLUGIN_ROOT}/scripts/_run.py" scripts/platform/observability/assert_contracts.py
Validate ecosystem integrity by checking plugin structure, hook bindings, and script availability.
Run the health probe script inline:
# All plugins
sh "${CLAUDE_PLUGIN_ROOT}/scripts/_python.sh" "${CLAUDE_PLUGIN_ROOT}/scripts/_run.py" scripts/platform/observability/health_probe.py
# Single plugin, machine-readable
sh "${CLAUDE_PLUGIN_ROOT}/scripts/_python.sh" "${CLAUDE_PLUGIN_ROOT}/scripts/_run.py" scripts/platform/observability/health_probe.py --plugin wicked-garden --json
0 = healthy, 1 = warnings, 2 = failures.latest.json for programmatic consumption.Auth retry (--retry-auth): after the user authenticates a CLI
mid-session, re-run the plugin readiness probes from bootstrap — see
refs/plugin-health.md for the probe invocation and
reporting steps.
Every hook execution is traced with timing, exit codes, and silent failure detection. Query the operational log to diagnose issues via scripts/platform/observability/ops_log_viewer.py:
# Last 10 entries
sh "${CLAUDE_PLUGIN_ROOT}/scripts/_python.sh" "${CLAUDE_PLUGIN_ROOT}/scripts/_run.py" scripts/platform/observability/ops_log_viewer.py --tail 10
# Filter by verbosity level (normal | verbose | debug)
sh "${CLAUDE_PLUGIN_ROOT}/scripts/_python.sh" "${CLAUDE_PLUGIN_ROOT}/scripts/_run.py" scripts/platform/observability/ops_log_viewer.py --level verbose
# Machine-readable, or a specific session's log
sh "${CLAUDE_PLUGIN_ROOT}/scripts/_python.sh" "${CLAUDE_PLUGIN_ROOT}/scripts/_run.py" scripts/platform/observability/ops_log_viewer.py --json --session {ID}
Note: hook-trace viewing is this script, not distributed tracing. For latency/dependency analysis of distributed traces across services, use the
tracesaction of the platform domain skill (skills/platform/SKILL.md).
Validate that plugin scripts return data matching their declared JSON schemas.
Run the assertion script inline:
# Run all assertions
sh "${CLAUDE_PLUGIN_ROOT}/scripts/_python.sh" "${CLAUDE_PLUGIN_ROOT}/scripts/_run.py" scripts/platform/observability/assert_contracts.py
# Single plugin, machine-readable
sh "${CLAUDE_PLUGIN_ROOT}/scripts/_python.sh" "${CLAUDE_PLUGIN_ROOT}/scripts/_run.py" scripts/platform/observability/assert_contracts.py --plugin wicked-garden --json
schemas/{plugin}/{script}.json before assertions can run.--tail 20 (pillar 2) — check if the hook was invoked--plugin {name} (pillar 3) — check contract complianceDiscover monitoring CLIs (APM, logging, metrics, cloud) available in the current environment and run queries against them — inline, no dispatch.
Semantics:
command -v and report what
was found, grouped by category with binary path and version.--query "...": route the query to the appropriate detected tool(s) —
logging tools search recent logs (last 1h default), metrics tools query
matching metrics, APM tools search traces/events, cloud tools query
CloudWatch/Stackdriver/Azure logs — and present results side-by-side with
tool attribution.--category apm|logging|metrics|cloud: limit both discovery and query
execution to that category.→ Read("${CLAUDE_PLUGIN_ROOT}/skills/platform/observability/refs/toolchain-discovery.md")
for the detection script, per-tool usage examples, query routing, display
format, and next-step suggestions.
| Category | Tools Detected |
|----------|---------------|
| APM | datadog-agent, newrelic, dt (Dynatrace) |
| Logging | splunk, elasticsearch, logcli (Loki) |
| Metrics | promtool (Prometheus), grafana-cli, influx |
| Cloud | aws (CloudWatch), gcloud (monitoring), az (Azure Monitor) |
Detection uses command -v — no external dependencies.
development
Pattern-conformance agent-half: evaluates a produced artifact or diff against a set of architectural/design pattern rules from the conformance-rule store (wicked_governance schema). Returns structured findings with rule ID, severity, and rationale — the deterministic half (mechanical rule recall) is done by the guard pipeline; this is the semantic evaluation step. Triggered by: the guard_pipeline `outgov_pattern` check (session-close), or explicitly by an engineering review when WICKED_OUTGOV_RULES_DIR is populated. NOT a replacement for the full `engineering` review skill — focuses only on conformance to stored Pattern rules; architecture and code-quality checks live in the `engineering` skill. Semantic evaluation reuses `wicked-garden-qe-semantic-reviewer` as the designated agent-half evaluator (per garden#983 spec). This skill is the orchestrating wrapper that loads applicable Pattern rules and delegates the per-rule semantic judgment to qe-semantic-reviewer.
tools
The FOUNDATIONAL domain-model capability: extract a codebase's domain — testable business rules (with confidence + provenance), entities, requirements — as a schema-conformant model on the estate graph. The workers annotate the store; wicked-core reads it and builds the requirements graph, coverage-gating fail-closed. Steers three fork workers. A shared substrate, not a modernization tool. The `modernize` archetype DERIVES from it; build / migrate / review / specify / explore consume the SAME domain model — none OWN it. Understanding a codebase's domain is upstream of almost everything else garden does. Use when: "extract the business rules / domain model from this codebase", "build a requirements graph from the code", "what does this system actually require", "reverse-engineer the domain before we build/port/migrate". Works on ANY codebase (modern or legacy) — the value is the domain model, not the porting. NOT the code transform itself (that is the archetype consuming this model). This skill produces the DOMAIN MODEL, not new code.
development
Domain-graph fork worker for the modernize archetype. Groups the estate's Louvain communities into business domains, attaches each requirement to its cluster (advisory cluster_id provenance), and invokes wicked-core's domain-graph build (which reads the annotated estate store, recomputes coverage fail-closed, and builds the requirements graph) — then validates core's output against the vendored schema. Use when: dispatched by wicked-garden-domain after rule extraction to turn a flat rule set into cluster-keyed domains; "group these into domains", "build the requirements graph", "translate clusters into a domain model". NOT for mining the rules themselves (that is domain-extractor) or threat-modeling (that is domain-coverage).
tools
Rule-extraction fork worker for the FOUNDATIONAL domain-model capability. Mines testable business rules from a codebase — each with a numeric confidence and a provenance{source, ref, source_kinds} — and annotates them into the estate store so wicked-core can build the domain-model requirements graph (coverage-gated). This is a substrate, not a modernization tool: the `modernize` archetype DERIVES from it, and build / migrate / review / specify / explore can consume the same domain model — none OWN it. Use when: dispatched by wicked-garden-domain to mine the business_rules of a codebase (or a module); "extract the domain rules", "what does this system require", building the requirements half of a domain model. NOT for grouping into domains (that is domain-modeler) or judging coverage (that is domain-coverage — a seat-distinct evaluator).