observability-aiops
Use this skill whenever the user needs to operate a self-hosted observability stack on Prometheus (HTTP API + PromQL), Alertmanager, Grafana, or Grafana Loki (logs) — a one-shot overview, PromQL instant/range queries, label + series metadata, scrape-target health (up/down + why) and dropped targets, recording/alerting rule health, firing/pending alerts, Alertmanager alerts + silences, Grafana dashboards/datasources/folders, bounded Loki LogQL log reads (labels, query, error-tail), five flagship analyses (firing-alert RCA, target-scrape-health, alert-noise/flap, log-error-burst RCA, log-volume/cardinality) plus an alert->log cross-signal, and guarded writes (create/expire silence, create annotation, update/delete dashboard, reload Prometheus config). Always use this skill for "Prometheus", "PromQL", "Alertmanager", "Grafana", "Loki", "LogQL", "logs", "which targets are down", "scrape failing", "why is this alert firing", "root cause this alert", "firing alerts", "silence this alert", "noisy alerts", "alert flapping", "recording rule", "alerting rule", "dashboard", "datasource health", "reload prometheus config", "TSDB cardinality", "error burst", "log volume", "log cardinality", "tail errors" when the context is a self-hosted metrics/logs/observability stack. Do NOT use when the target is something other than a Prometheus/Grafana observability stack (a hypervisor, storage appliance, backup product, container-orchestrator control plane, network device config, or OT/industrial equipment) — route those to the appropriate other AIops-tools skill. Hosted/SaaS monitoring suites (Datadog, New Relic, enterprise NMS) are out of scope. Governed observability operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). Beyond the mock suite, the Prometheus/Alertmanager/Grafana surfaces have been exercised against a live Prometheus 3.x + Alertmanager + Grafana 13 stack (RCAs, governed writes, undo); the Loki surface has not (see docs/VERIFICATION.md).
Rank
62
Safety
84
Downloads
1.5k
Updated
Oct 10, 2026
Version
0.10.4
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.5K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.10.4release · observed Sep 16, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:observability-aiops- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:observability-aiops` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/observability-aiops before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-observability-aiops/snapshot"
Documentation
CLAWHUB
150,253 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: observability-aiops
slug: observability-aiops
displayName: "Observability AIops"
summary: "Governed Prometheus + Grafana ops: PromQL, alerts, dashboards, RCA; 39 tools."
license: MIT
homepage: https://github.com/AIops-tools/Observability-AIops
tags: [aiops, mcp, governance, observability]
description: >
Use this skill whenever the user needs to operate a self-hosted observability stack on Prometheus (HTTP API + PromQL), Alertmanager, Grafana, or Grafana Loki (logs) — a one-shot overview, PromQL instant/range queries, label + series metadata, scrape-target health (up/down + why) and dropped targets, recording/alerting rule health, firing/pending alerts, Alertmanager alerts + silences, Grafana dashboards/datasources/folders, bounded Loki LogQL log reads (labels, query, error-tail), five flagship analyses (firing-alert RCA, target-scrape-health, alert-noise/flap, log-error-burst RCA, log-volume/cardinality) plus an alert->log cross-signal, and guarded writes (create/expire silence, create annotation, update/delete dashboard, reload Prometheus config).
Always use this skill for "Prometheus", "PromQL", "Alertmanager", "Grafana", "Loki", "LogQL", "logs", "which targets are down", "scrape failing", "why is this alert firing", "root cause this alert", "firing alerts", "silence this alert", "noisy alerts", "alert flapping", "recording rule", "alerting rule", "dashboard", "datasource health", "reload prometheus config", "TSDB cardinality", "error burst", "log volume", "log cardinality", "tail errors" when the context is a self-hosted metrics/logs/observability stack.
Do NOT use when the target is something other than a Prometheus/Grafana observability stack (a hypervisor, storage appliance, backup product, container-orchestrator control plane, network device config, or OT/industrial equipment) — route those to the appropriate other AIops-tools skill. Hosted/SaaS monitoring suites (Datadog, New Relic, enterprise NMS) are out of scope.
Governed observability operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). Beyond the mock suite, the Prometheus/Alertmanager/Grafana surfaces have been exercised against a live Prometheus 3.x + Alertmanager + Grafana 13 stack (RCAs, governed writes, undo); the Loki surface has not (see docs/VERIFICATION.md).
installer:
kind: uv
package: observability-aiops
argument-hint: "[a PromQL query, an alert/dashboard uid, or describe your observability task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["observability-aiops","uvx"]},"optional":{"env":["OBSERVABILITY_AIOPS_CONFIG","OBSERVABILITY_AIOPS_MASTER_PASSWORD"]},"homepage":"https://github.com/AIops-tools/Observability-AIops","emoji":"📈","os":["macos","linux"]}}
compatibility: >
Standalone, self-governed observability operations across Prometheus (HTTP API + PromQL, default port 9090, optional bearer token), a companion Alertmanager (/api/v2, default port 9093), Grafana (HTTP API, default_meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "observability-aiops",
"version": "0.10.4",
"publishedAt": 1789601183574
}references/agent-guardrails.md
# Agent guardrails — running observability-aiops with a smaller / local model
If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,
Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably
better results with a short system prompt. This page gives you one, and — more
importantly — tells you which guardrails you **no longer need to write**, because
the tool now enforces them itself.
The distinction matters. A guardrail in a prompt is a request. A guardrail in the
harness is a guarantee. Anything below that we could move into the harness, we did.
## What the tool now enforces — do not waste prompt budget on these
| You might be tempted to prompt | Why you don't need to |
|---|---|
| "Don't invent a value when a field is missing" | A field the API did not return comes back as `null`, never as `""`. An alert with no `severity` label, a scrape target that has never errored, a recording rule with no alert `state`, a silence with no `comment` — all report `null`, distinguishable from a genuinely empty value. |
| "Tell me if the output was cut off" | Bounded reads (`loki_query`, `loki_tail_errors`, `loki_labels`, `loki_label_values`, `instant_query`, `range_query`, `label_values`, `series_metadata`, `undo_list`) return `{"returned": N, "limit": L, "truncated": true/false}` alongside the rows. For the Loki reads truncation is **measured** — one line beyond the limit is requested — not guessed from a length coincidence. |
| "Preserve the ordering / tell me what's most urgent" | The analysis tools already return worst-first: `firing_alert_rca` ranks by severity, `target_scrape_health_analysis` puts down targets before slow ones, `alert_noise_and_flap_analysis` sorts by instance count. Priority is the list order, and each entry carries the measured number it was ranked on. |
| "Confirm before anything destructive" | Every write tool takes `dry_run` for a preview, and `delete_dashboard` is `risk=high`. ⚠️ **Apart from `undo apply`, no write tool here has a CLI command**, so the CLI double confirmation never applies to one: they are reachable only over MCP, where nothing prompts. Keep your own confirmation for them. |
| "Log what you did" | Every call is audited to `~/.observability-aiops/audit.db` regardless of what the model says it did, and reversible writes record an undo token (`undo_list` / `undo_apply`). |
| "Don't hammer the same call in a loop" | The runaway guard trips a circuit breaker on tight poll/retry loops — a safety backstop, not authorization. |
Authorization is not this tool's job. Whether a write is allowed to happen is
decided by the account you connect it with, or by your agent's own judgement —
not by this harness. See "Recommended setup for a local model" below for how to
enforce read-only at the account instead of in a prompt.
## What still needs a prompt
These are model-behaviour problems the harness cannot fix from the outside.
Copy this into your agent's system prompt:
```text
Yoreferences/capabilities.md
# observability-aiops capability matrix
> **39 MCP tools** (32 read, 7 write) across Prometheus
> (HTTP API + PromQL, default port 9090, optional bearer token), a companion
> Alertmanager (`/api/v2`, port 9093), Grafana (HTTP API, port 3000, required
> bearer token), and Grafana Loki (HTTP API, port 3100, optional bearer/basic
> auth, optional multi-tenant `X-Scope-OrgID`). Loki is **read-only**. The
> Prometheus/Alertmanager/Grafana surfaces have been exercised against a live Prometheus 3.x + Alertmanager + Grafana 13 stack; the Loki surface has not
> (see docs/VERIFICATION.md).
## Metrics — Prometheus (read)
| Tool | API path | Returns |
|------|----------|---------|
| `instant_query` | `/api/v1/query` | PromQL evaluated at one instant (samples: metric + value + timestamp) |
| `range_query` | `/api/v1/query_range` | PromQL over a time range (per-series point arrays) |
| `label_values` | `/api/v1/label/<name>/values` | distinct values of a label (default `__name__` = all metric names) |
| `series_metadata` | `/api/v1/series` | series (label-set) metadata for a selector |
## Targets & status — Prometheus (read)
| Tool | API path | Returns |
|------|----------|---------|
| `list_targets` | `/api/v1/targets` | active scrape targets (job, instance, health, lastError), optional up/down filter |
| `target_scrape_health` | `/api/v1/targets` | up/down summary + the unhealthy targets |
| `dropped_targets` | `/api/v1/targets` | targets discovered but dropped by relabeling |
| `prometheus_config_status` | `/api/v1/status/config` | running-config fingerprint (sha256) + size — never the raw YAML/secrets |
| `prometheus_tsdb_status` | `/api/v1/status/tsdb` | TSDB head cardinality + top metrics by series count |
## Rules — Prometheus (read)
| Tool | API path | Returns |
|------|----------|---------|
| `list_rules` | `/api/v1/rules` | recording + alerting rules (name, type, expr, health), optional type filter |
| `rule_health` | `/api/v1/rules` | rule-evaluation health summary + erroring rules |
## Alerts — Prometheus + Alertmanager (read)
| Tool | API path | Returns |
|------|----------|---------|
| `firing_alerts` | `/api/v1/alerts` | firing Prometheus rule alerts, grouped by severity |
| `pending_alerts` | `/api/v1/alerts` | pending (not-yet-firing) rule alerts |
| `alertmanager_alerts` | AM `/api/v2/alerts` | alerts as Alertmanager sees them (post grouping/silence/inhibit) |
| `list_silences` | AM `/api/v2/silences` | silences (active, pending, expired) with matchers |
## Grafana (read)
| Tool | API path | Returns |
|------|----------|---------|
| `list_dashboards` | `/api/search?type=dash-db` | dashboards (uid, title, folder, tags), optional title query |
| `get_dashboard` | `/api/dashboards/uid/{uid}` | one dashboard's summary (title, version, panel + tag counts) |
| `list_datasources` | `/api/datasources` | datasources (id, uid, name, type, default flag) |
| `datasource_health` | `/api/datasources/{id}/health` | one datasource's health (statusreferences/cli-reference.md
# observability-aiops CLI reference
> Covers Prometheus (HTTP API + PromQL), a companion Alertmanager, Grafana
> (HTTP API), and Grafana Loki (LogQL, read-only). The Prometheus/Alertmanager/
> Grafana surfaces have been exercised against a live Prometheus 3.x + Alertmanager + Grafana 13 stack;
> the Loki surface has not (see docs/VERIFICATION.md). The CLI is a convenience
> subset — the full 39-tool surface is via the MCP server
> (`observability-aiops mcp`).
## Setup & diagnostics
```bash
observability-aiops init # interactive wizard (asks for the platform: prometheus/grafana/loki)
observability-aiops doctor [--skip-auth] # config + secret store + connectivity
# Prometheus: /api/v1/status/buildinfo · Grafana: /api/health
# Loki: /ready + /loki/api/v1/status/buildinfo
observability-aiops mcp # start the MCP server (stdio transport)
```
## Secrets (encrypted store ~/.observability-aiops/secrets.enc)
```bash
observability-aiops secret set <target> [--value <token>] # store bearer token (hidden prompt if no --value)
observability-aiops secret list # names only — secrets never shown
observability-aiops secret rm <target>
observability-aiops secret migrate # import legacy plaintext env (OBSERVABILITY_<TARGET>_TOKEN)
observability-aiops secret rotate-password # re-encrypt under a new master password
```
## Overview
```bash
observability-aiops overview [--target <t>] # snapshot: firing alerts + targets up/down + rules erroring (Prometheus)
# or dashboard/datasource/folder counts (Grafana) / label-name count (Loki)
```
## Query (Prometheus PromQL)
```bash
observability-aiops query instant 'up' # PromQL instant query
observability-aiops query range 'rate(x[5m])' --start ... --end ... [--step 60s]
observability-aiops query labels [__name__] # distinct label values (default = all metric names)
```
## Logs (Grafana Loki, read-only, bounded)
```bash
observability-aiops logs labels [--hours 1] [--target <t>] # distinct Loki label names in the window
observability-aiops logs query '{app="api"} |= "error"' [--hours 1] [--limit 100] # bounded LogQL (stream selector required)
observability-aiops logs errors '{app="api"}' [--hours 1] [--limit 100] # canned error-level tail for a selector
```
## Alerts
```bash
observability-aiops alert firing [--target <t>] # firing Prometheus rule alerts, by severity
observability-aiops alert silences [--target <t>] # Alertmanager silences
observability-aiops alert rca [--target <t>] # root-cause firing alerts (join to rule expr → cause+action)
```
## Common options
- `--target, -t <name>` — target name from `config.yaml` (omit to use the
default/first target); each target dAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/observability-aiops",
"sourceUrl": "https://clawhub.ai/zw008/skills/observability-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T11:32:30.020Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-observability-aiops/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-observability-aiops/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T11:32:30.020Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.5K downloads",
"href": "https://clawhub.ai/zw008/observability-aiops",
"sourceUrl": "https://clawhub.ai/zw008/observability-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T11:32:30.020Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.10.4",
"href": "https://clawhub.ai/zw008/observability-aiops",
"sourceUrl": "https://clawhub.ai/zw008/observability-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-16T23:26:23.574Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-observability-aiops/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-observability-aiops/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.10.4",
"description": "## observability-aiops 0.10.4 - Updated documentation in `references/agent-guardrails.md`. - Removed the redundant `skill-card.md` file.",
"href": "https://clawhub.ai/zw008/observability-aiops",
"sourceUrl": "https://clawhub.ai/zw008/observability-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-16T23:26:23.574Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
