{"id":"dbd42bf6-1c46-40c4-adbf-ca496dff1462","entityType":"agent","slug":"clawhub-kwdb-kwdb-intelligent-inspection","name":"KWDB Intelligent Inspection","canonicalUrl":"https://www.xpersona.co/agent/clawhub-kwdb-kwdb-intelligent-inspection","canonicalPath":"/agent/clawhub-kwdb-kwdb-intelligent-inspection","generatedAt":"2026-10-11T01:48:16.912Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T23:38:39.294Z","emptyReason":null},"description":"Run KaiwuDB inspection and health-check tasks. Use this skill for database health checks, metrics collection, anomaly detection, and inspection report generation.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17e2f9k2hwm2p7q50y9wz03fs8445dh:kwdb-intelligent-inspection","sourceUrl":"https://clawhub.ai/kwdb/kwdb-intelligent-inspection","homepage":"https://clawhub.ai/kwdb/skills/kwdb-intelligent-inspection","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/kwdb/kwdb-intelligent-inspection","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/kwdb/skills/kwdb-intelligent-inspection","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"KWDB Intelligent Inspection technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T23:38:39.294Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T23:38:39.294Z","emptyReason":null},"stars":null,"forks":null,"downloads":1228,"packageName":null,"latestVersion":"1.2.1","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T23:38:39.234Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T23:38:39.294Z","lastCrawledAt":"2026-10-10T23:38:39.234Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T23:38:39.234Z","lastVerifiedAt":null,"highlights":[{"version":"1.2.1","createdAt":"2026-08-28T00:47:36.030Z","changelog":"- Removed the skill description file skill-card.md. - No changes to the skill logic or SKILL.md content.","fileCount":13,"zipByteSize":17701},{"version":"1.2.0","createdAt":"2026-07-23T05:52:29.658Z","changelog":"- Removed the skill documentation file (skill-card.md). - No changes to functionality or workflow.","fileCount":13,"zipByteSize":17666},{"version":"1.1.0","createdAt":"2026-06-22T09:01:07.262Z","changelog":"kwdb-intelligent-inspection 1.1.0 - Enforces strict step-by-step workflow for KaiwuDB health inspections, requiring explicit user confirmation of node addresses, ports, and inspection scope before metric collection. - Introduces critical constraints: all scripts must be run only after reading their specific usage documentation; parameters must not be guessed. - Alerting/anomaly detection is now 100% user-driven: apply default or custom rules only if the user explicitly requests alerting. - Updated and expanded supported trigger phrases, including Chinese language triggers. - Output for inspection reports is standardized per output rules; ensures all reports include required details and formatting. - Clarifies key limitations: Windows OS and KaiwuDB with TLS mode are not supported.","fileCount":13,"zipByteSize":17719},{"version":"1.0.0","createdAt":"2026-05-19T04:09:33.062Z","changelog":"kwdb-intelligent-inspection 1.0.0 - Initial release of KaiwuDB health-check and inspection automation skill. - Supports metric collection, anomaly detection, inspection report generation, and user-defined alerting rules for KaiwuDB clusters. - Enforces strict workflow: requires user confirmation of node addresses, ports, and inspection scope before any data collection begins. - Integrates scripted metric and statement collection; always checks script usage docs before execution. - Respects strict anomaly judgment and report output formats as defined in reference documents. - Supports both English and Chinese trigger phrases. - Does not support Windows OS or TLS-enabled KaiwuDB deployments.","fileCount":13,"zipByteSize":17692}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17e2f9k2hwm2p7q50y9wz03fs8445dh:kwdb-intelligent-inspection","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17e2f9k2hwm2p7q50y9wz03fs8445dh:kwdb-intelligent-inspection` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/kwdb/kwdb-intelligent-inspection before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kwdb-kwdb-intelligent-inspection/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kwdb-kwdb-intelligent-inspection/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kwdb-kwdb-intelligent-inspection/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kwdb-kwdb-intelligent-inspection/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kwdb-kwdb-intelligent-inspection/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kwdb-kwdb-intelligent-inspection/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T01:48:16.910Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kwdb-kwdb-intelligent-inspection/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kwdb-kwdb-intelligent-inspection/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kwdb-kwdb-intelligent-inspection/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kwdb-kwdb-intelligent-inspection/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T23:38:39.294Z","emptyReason":null},"readme":"Skill: KWDB Intelligent Inspection\n\nOwner: kwdb\n\nSummary: Run KaiwuDB inspection and health-check tasks. Use this skill for database health checks, metrics collection, anomaly detection, and inspection report generation.\n\nTags: kwdb:1.2.1, latest:1.2.1, ready:1.2.1\n\nVersion history:\n\nv1.2.1 | 2026-08-28T00:47:36.030Z | auto\n\n- Removed the skill description file skill-card.md.\n- No changes to the skill logic or SKILL.md content.\n\nv1.2.0 | 2026-07-23T05:52:29.658Z | auto\n\n- Removed the skill documentation file (skill-card.md).\n- No changes to functionality or workflow.\n\nv1.1.0 | 2026-06-22T09:01:07.262Z | auto\n\nkwdb-intelligent-inspection 1.1.0\n\n- Enforces strict step-by-step workflow for KaiwuDB health inspections, requiring explicit user confirmation of node addresses, ports, and inspection scope before metric collection.\n- Introduces critical constraints: all scripts must be run only after reading their specific usage documentation; parameters must not be guessed.\n- Alerting/anomaly detection is now 100% user-driven: apply default or custom rules only if the user explicitly requests alerting.\n- Updated and expanded supported trigger phrases, including Chinese language triggers.\n- Output for inspection reports is standardized per output rules; ensures all reports include required details and formatting.\n- Clarifies key limitations: Windows OS and KaiwuDB with TLS mode are not supported.\n\nv1.0.0 | 2026-05-19T04:09:33.062Z | auto\n\nkwdb-intelligent-inspection 1.0.0\n\n- Initial release of KaiwuDB health-check and inspection automation skill.\n- Supports metric collection, anomaly detection, inspection report generation, and user-defined alerting rules for KaiwuDB clusters.\n- Enforces strict workflow: requires user confirmation of node addresses, ports, and inspection scope before any data collection begins.\n- Integrates scripted metric and statement collection; always checks script usage docs before execution.\n- Respects strict anomaly judgment and report output formats as defined in reference documents.\n- Supports both English and Chinese trigger phrases.\n- Does not support Windows OS or TLS-enabled KaiwuDB deployments.\n\nArchive index:\n\nArchive v1.2.1: 13 files, 17701 bytes\n\nFiles: references/anomaly-rules.md (981b), references/inspection-port-listening-reference.md (2158b), references/inspection-requirements-confirmation.md (1741b), references/metric-types.md (1547b), references/output-rules.md (1388b), references/report-template.md (1859b), references/statements-script-usage.md (2496b), references/ts-metrics-script-usage.md (1068b), scripts/get_kwdb_statements.py (7393b), scripts/get_kwdb_ts_metrics.py (14612b), skill-card.md (2761b), SKILL.md (3308b), _meta.json (146b)\n\nFile v1.2.1:SKILL.md\n\n---\nname: kwdb-intelligent-inspection\ndescription: |\n  Run KaiwuDB inspection and health-check tasks. Use this skill for database health checks, metrics collection, anomaly detection, and inspection report generation.\ntriggers:\n  - show me all database metrics\n  - database metrics for my KWDB cluster\n  - kwdb cluster metrics\n  - check database health\n  - inspect KWDB cluster\n  - database health check\n  - collect database metrics\n  - kwdb inspection\n  - 巡检\n  - 数据库指标\n  - 查看数据库指标\n  - 检查数据库健康\n---\n\n## Critical Constraints (non-negotiable)\n\n❝ **Never skip Step 1.** Collecting metrics before confirming node addresses, ports, and inspection scope with the user is forbidden. The inspection must not proceed until the user explicitly confirms the node addresses, ports, and inspection scope. ❞\n\n❝ **Never call a script without reading its usage doc first.** Before running any script under `scripts/`, you MUST read the corresponding `references/*-script-usage.md` file. This is the only way to know the correct parameters, defaults, and required arguments. Guessing parameters is forbidden. ❞\n\n❝ **Anomaly rules are user-driven.** If user does not request alerting, skip alerting. If user requests alerting without specific thresholds, apply default rules from `references/anomaly-rules.md`. If user provides custom thresholds, use those instead. ❞\n\n## Workflow\n\n### Step 1: Confirm target and scope\n\n**Before collecting any metrics**, follow `references/inspection-requirements-confirmation.md` EXACTLY in order:\n1. Parse user intent → confirm target (host, ports)\n2. Probe connectivity → verify ports reachable (see `references/inspection-port-listening-reference.md`)\n3. TLS mode detection → determine if inspection supported\n4. Present scope menu → user confirms before proceeding\n\n### Step 2: Collect metrics\n\n**MANDATORY: Read the script usage doc BEFORE calling any script.**\n- `references/ts-metrics-script-usage.md` — for `get_kwdb_ts_metrics.py`\n- `references/statements-script-usage.md` — for `get_kwdb_statements.py`\n\nDo not call any script without first reading its usage doc. Verify the parameter names, required arguments, and defaults match what you are about to pass.\n\n- **Port listener status**: Use Step 1 connectivity probe results.\n- **Most metrics**: Use `scripts/get_kwdb_ts_metrics.py` per `references/ts-metrics-script-usage.md`.\n- **Slow queries**: Use `scripts/get_kwdb_statements.py` per `references/statements-script-usage.md`.\n\n### Step 3: Apply anomaly rules\n\nApply anomaly judgment rules only when user requests alerting. See `references/anomaly-rules.md` for default rules and configurable rules.\n\n### Step 4: Generate report\n\nProduce a Markdown inspection report with metric values, anomaly judgments, and data-source notes per `references/output-rules.md`.\n\n## Anomaly Rules\n\nSee `references/anomaly-rules.md` for default rules and configurable rules.\n\n## Output Rules\n\nSee `references/output-rules.md` — **do not deviate from these rules when producing any inspection report.**\n\n## Limitations\n\n- **Windows is not supported**: This skill does not support Windows operating systems.\n- **TLS mode inspection is not supported**: This skill does not support inspecting KaiwuDB deployed with TLS mode enabled.\n\nFile v1.2.1:_meta.json\n\n{\n  \"ownerId\": \"kn7fr8q8f22jd6gzb6f7prf9g183z64v\",\n  \"slug\": \"kwdb-intelligent-inspection\",\n  \"version\": \"1.2.1\",\n  \"publishedAt\": 1787878056030\n}\n\nFile v1.2.1:references/anomaly-rules.md\n\n## Anomaly Rules\n\nThese rules apply only when the user requests alerting. If no alerting is requested, skip all rules.\n\n### Default Rules (applied when user requests alerting without custom thresholds)\n\n1. **Database Down**: `cr.node.liveness.livenodes == 0` or port listener check failure\n2. **Port Anomaly**: Port 26257 or 8080 not listening\n3. **Frequent Restarts**: Database restarts > 1 time/day\n4. **Replica sync lag > 5s**: `cr.store.raft.replica.consistent.latency-p99` via `/ts/query` API\n5. **Unavailable Replicas > 0**: `cr.store.ranges.unavailable` via `/ts/query` API — ranges with fewer replicas than quorum requires\n\n### Configurable Rules (require explicit user threshold)\n\n- **CPU > threshold%**: `cr.node.sys.cpu.combined.percent-normalized`\n- **Memory > threshold%**: `cr.node.sys.rss`\n- **QPS anomaly**: requires sampling window, do not claim from single snapshot\n- **Write/Query latency anomaly**: requires sampling window, do not claim from single snapshot\n\nFile v1.2.1:references/inspection-port-listening-reference.md\n\n# Port Listening Detection Reference\n\nThis document describes how to check KaiwuDB port reachability status.\n\n## Critical Constraint (non-negotiable)\n\n**Do not SSH into the target server to run inspection commands there.** Always use local tools on the machine where the inspection is being performed. Only use remote port probing tools (`nc`, `telnet`, `curl`, `wget`) to check if KaiwuDB ports are reachable on target servers.\n\n## Default Ports\n\n| Service | Default Port | Description |\n|---------|-------------|-------------|\n| SQL Port | `26257` | KaiwuDB SQL/API port |\n| Admin Console | `8080` | Admin UI port |\n\n## Supported Detection Methods\n\nUse remote port probing tools to check if KaiwuDB ports are listening on target servers. Common tools:\n\n- **All platforms**: `nc` (netcat), `telnet`\n- **For HTTP ports**: `curl`, `wget`\n\n## Tool Installation\n\nIf the required port detection tool is not available on the local system:\n\n1. **Do NOT install tool automatically** — always request user permission first\n2. Explain to the user which tool is missing and why it is needed\n3. Ask for explicit confirmation before proceeding with installation\n4. Only after user approval, proceed with installation using system package manager\n\nExample prompt when tool is missing:\n```\n[TOOL_MISSING] The port probing tool 'nc' is not installed on this system.\nRequired for: Checking if KaiwuDB ports (26257, 8080) are reachable on target server.\nDo you want me to install it? (y/n)\n```\n\n## Example Commands\n\n### Using `nc` (netcat)\n```bash\nnc -zv <target_host> 26257 8080 -w 5\n```\n\n### Using `telnet`\n```bash\necho \"quit\" | telnet <target_host> 26257\n```\n\n### Using `curl` (for HTTP ports)\n```bash\ncurl -s -o /dev/null -w \"%{http_code}\" --connect-timeout 5 http://<target_host>:8080\n```\n\n### Using `wget` (for HTTP ports)\n```bash\nwget --spider --timeout=5 -q http://<target_host>:8080\n```\n\n## Expected Output\n\nThe inspection should verify:\n1. Whether each port is reachable (open/closed)\n2. Connection response time (if available)\n\n## Output Format\n\nReport the port reachability status:\n```json\n{\n  \"port\": 26257,\n  \"reachable\": true,\n  \"response_time_ms\": 12\n}\n```\n\nFile v1.2.1:references/inspection-requirements-confirmation.md\n\n## Inspection Requirements Confirmation\n\n⚠️ **These steps MUST be executed in the following order. Do not skip or reorder any step.**\n\n### Step 1: Parse User Intent\n\nWhen user provides a target (e.g., \"inspect 10.110.10.146 26257 8080\"), extract and confirm:\n- Node address(es)\n- Database port (default 26257)\n- Admin console port (default 8080)\n\n**Do NOT proceed to Step 2 until target info is confirmed with user.**\n\n---\n\n### Step 2: Probe Connectivity\n\nAfter confirming target info with user, verify reachability using appropriate tools (e.g., `nc`, `telnet`, `curl`, `ping`):\n- Check database port (26257) and admin console port (8080)\n- If ports unreachable: inform user and ask them to verify network/firewall/service\n- Only proceed if ports are reachable\n\n**Do NOT proceed to Step 3 until ports are confirmed reachable.**\n\n---\n\n### Step 3: TLS Mode Detection\n\nOnly after connectivity is confirmed, check TLS status:\n\n**Must strictly use this exact command format, only replace `<host>` and `<admin-port>` with actual values:**\n```\ncurl -k https://<host>:<admin-port>/health\n```\n- If output contains `error:0A00010B` or `wrong version number` → TLS not enforced, proceed\n- If returns JSON health data with no error → TLS enabled, **inspection not supported** (stop here)\n\n**Do NOT proceed to Step 4 until TLS mode is determined.**\n\n---\n\n### Step 4: Present Scope Menu\n\nRead `references/report-template.md` and `references/anomaly-rules.md`, then show user:\n- Full inspection scope (Sections 1-6)\n- Default rules and configurable rules (only applied if user requests alerting)\n- Ask user to confirm which metrics to inspect and whether to enable alerting\n\n**Do NOT proceed to metrics collection until user confirms the scope.**\n\nFile v1.2.1:references/metric-types.md\n\n## Metric Types\n\nThis document maps each inspectable metric to its `/ts/query` query params. Query params are read from this file when constructing API requests — do not infer or invent values.\n\n### Notation\n\n- `d` = downsampler\n- `sa` = source_aggregator\n- `der` = derivative\n\n### Gauge / Counter Metrics\n\nThese metrics use: `d:1, sa:2, der:0`\n\n| Metric Name |\n|-------------|\n| `cr.node.liveness.livenodes` |\n| `cr.node.sys.uptime` |\n| `cr.node.sys.cpu.user.percent` |\n| `cr.node.sys.cpu.sys.percent` |\n| `cr.node.sys.cpu.combined.percent-normalized` |\n| `cr.store.capacity` |\n| `cr.store.capacity.available` |\n| `cr.store.capacity.used` |\n| `cr.node.sys.rss` |\n| `cr.node.sys.go.allocbytes` |\n| `cr.node.sys.go.totalbytes` |\n| `cr.node.sql.insert.count` |\n| `cr.node.sql.update.count` |\n| `cr.node.sql.delete.count` |\n| `cr.store.rebalancing.writespersecond` |\n| `cr.node.sql.select.count` |\n| `cr.node.sql.query.count` |\n| `cr.store.rebalancing.queriespersecond` |\n| `cr.store.totalbytes` |\n| `cr.store.livebytes` |\n| `cr.store.replicas` |\n| `cr.store.replicas.leaders` |\n| `cr.store.replicas.leaseholders` |\n| `cr.store.ranges.unavailable` |\n| `cr.store.ranges.underreplicated` |\n| `cr.store.ranges.overreplicated` |\n| `cr.store.raftlog.behind` |\n\n### Latency Metrics\n\nThese metrics use: `d:1, sa:1, der:0`\n\n| Metric Name |\n|-------------|\n| `cr.node.exec.latency-p99` |\n| `cr.node.sql.service.latency-p99` |\n| `cr.node.sql.distsql.exec.latency-p99` |\n| `cr.store.raft.replica.consistent.latency-p99` |\n| `cr.node.clock-offset.meannanos` |\n\nFile v1.2.1:references/output-rules.md\n\n## Output Rules\n\n❝ **Never produce an inspection report unless it follows the format defined in `references/report-template.md`.** The report must use the Required Report Sections 1-6 structure, include all metrics listed under each section, and use the API Name column values for metric references. Deviating from this template is forbidden. ❞\n\n1. For every section, identify the data source as `API` (via `/ts/query`) or `OS` (via shell scripts under `scripts/`).\n2. If a metric is only partially supported, say so explicitly.\n3. If multi-node evidence is incomplete, say which part is inferred versus directly observed.\n4. Return inline Markdown report rather than claiming a saved file path unless a file tool actually created that artifact.\n5. If the task runs in cluster mode, the report must cover all nodes rather than only a single node snapshot.\n6. Scheduled inspection should recover thresholds and time-range hints from the task prompt; if missing, use defaults and document that assumption.\n7. HTML and PDF are optional; default to Markdown. When generating PDF, HTML, or Markdown files, use UTF-8 character encoding, use relevant PDF or HTML generation skills to produce reports in the corresponding format if available.\n8. If the user explicitly asks for charts, hand structured metrics to a visualization tool. Chart generation failure must not block the main report.\n\nFile v1.2.1:references/report-template.md\n\n## Required Report Sections\n\nThe default inspection report must cover these sections unless the user explicitly narrows scope.\n\n### Data Source Priority\n\n1. **Port listener status**: Use Workflow Step 1 connectivity probe results (no fixed script) in SKILL.md\n2. **Slow queries**: Use `scripts/get_kwdb_statements.py` (`/_status/statements` API)\n3. **All other metrics**: Use `scripts/get_kwdb_ts_metrics.py` (`/ts/query` API)\n\n### Report Sections\n\n#### 1. Basic Indicators\n\n- Database running state (`cr.node.liveness.livenodes`)\n- Uptime (`cr.node.sys.uptime`)\n\n#### 2. System Resources\n\n- CPU user % (`cr.node.sys.cpu.user.percent`)\n- CPU sys % (`cr.node.sys.cpu.sys.percent`)\n- CPU combined % normalized (`cr.node.sys.cpu.combined.percent-normalized`)\n- Disk total/available/used (`cr.store.capacity`, `cr.store.capacity.available`, `cr.store.capacity.used`)\n- Memory RSS (`cr.node.sys.rss`)\n- Go alloc/total bytes (`cr.node.sys.go.allocbytes`, `cr.node.sys.go.totalbytes`)\n\n#### 3. Database Performance\n\n- Write QPS: insert + update + delete + rebalancing writes\n- Query QPS: select + query + rebalancing queries\n- Exec latency: `cr.node.exec.latency-p99`, `cr.node.sql.service.latency-p99`, `cr.node.sql.distsql.exec.latency-p99`\n- Slow query information (via `/_status/statements` API)\n\n#### 4. Storage\n\n- Total data size (`cr.store.totalbytes`, `cr.store.livebytes`, `cr.store.capacity.used`)\n\n#### 5. Cluster\n\n- Replicas, Raft leaders, Lease holders (`cr.store.replicas`, `cr.store.replicas.leaders`, `cr.store.replicas.leaseholders`)\n- Unavailable/Under-replicated/Over-replicated ranges\n- Sync lag (`cr.store.raft.replica.consistent.latency-p99`, `cr.store.raftlog.behind`, `cr.store.raft.replica.consistent.latency-p99`)\n- Data distribution balance\n\n#### 6. Network\n\n- Node-to-node latency (`round-trip-latency`, `cr.node.clock-offset.meannanos`)\n\nFile v1.2.1:references/statements-script-usage.md\n\n## Slow Statements Script Usage\n\nUse `scripts/get_kwdb_statements.py` to collect slow SQL statement statistics from KaiwuDB.\n\n### Full Collection (all statements)\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> [--port <port>]\n```\n\n### Filter by Minimum Latency\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> --min-latency-ms <ms>\n```\n\nExample - get statements with service latency > 100ms:\n```bash\npython3 scripts/get_kwdb_statements.py --host 10.110.10.146 --min-latency-ms 100\n```\n\n### Sort by Different Metrics\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> --sort-by <field>\n```\n\nAvailable sort fields:\n- `service_lat` (default) - total service latency\n- `run_lat` - execution latency\n- `plan_lat` - planning latency\n- `count` - number of executions\n\n### Limit Results\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> --limit <N>\n```\n\n### Options\n\n| Option | Default | Description |\n|--------|---------|-------------|\n| `--host` | localhost | KaiwuDB admin host |\n| `--port` | 8080 | KaiwuDB admin port |\n| `--limit` | 10 | Number of statements to display |\n| `--min-latency-ms` | 0 | Minimum service latency filter (ms) |\n| `--sort-by` | service_lat | Sort field |\n| `--json` | false | Output raw JSON |\n\n### Output Format\n\nThe script outputs a formatted table with:\n- **Query** - SQL statement text (truncated at 200 chars)\n- **App** - Application name\n- **User** - Database user\n- **Database** - Database name\n- **Count** - Execution count\n- **Service/Run/Plan/Parse** - Latencies in ms\n- **DistSQL** - Whether distributed SQL was used\n- **Failed** - Whether any executions failed\n- **Last Error** - Error message if failed\n\n### Examples\n\n```bash\n# Get top 10 slowest statements (by service latency)\npython3 scripts/get_kwdb_statements.py --host localhost --port 8080\n\n# Filter statements with latency > 100ms\npython3 scripts/get_kwdb_statements.py --host localhost --min-latency-ms 100\n\n# Sort by run latency instead of service latency\npython3 scripts/get_kwdb_statements.py --host localhost --sort-by run_lat\n\n# Output raw JSON\npython3 scripts/get_kwdb_statements.py --host localhost --json\n\n# Limit to top 5\npython3 scripts/get_kwdb_statements.py --host localhost --limit 5\n```\n\n### Underlying API\n\nThis script wraps the KaiwuDB Statements API at `http://<host>:8080/_status/statements`.\n\n**Note:** TLS mode is not supported because the AdminUI login requires captcha verification that cannot be solved in non-interactive mode.\n\nFile v1.2.1:references/ts-metrics-script-usage.md\n\n## Time Series Metrics Script Usage\n\nUse `scripts/get_kwdb_ts_metrics.py` to collect time series metrics from KaiwuDB.\n\n### Full Collection (all metrics)\n\n```bash\npython3 scripts/get_kwdb_ts_metrics.py --host <host> [--port <port>]\n```\n\n### Partial Collection (specific metrics)\n\n```bash\npython3 scripts/get_kwdb_ts_metrics.py --host <host> --metric <metric_name> [--metric <metric_name> ...]\n```\n\nExample:\n```bash\npython3 scripts/get_kwdb_ts_metrics.py --host 10.110.10.146 --metric sys.cpu.user.percent --metric sql.insert.count\n```\n\n### Options\n\n| Option | Default | Description |\n|--------|---------|-------------|\n| `--host` | localhost | KaiwuDB admin host |\n| `--port` | 8080 | KaiwuDB admin port |\n| `--start` | 1 hour ago | Start time (unix timestamp in ns) |\n| `--end` | now | End time (unix timestamp in ns) |\n| `--sample` | 60 | Sample interval in seconds |\n| `--metric` | all | Filter by metric name (can repeat) |\n| `--json` | false | Output raw JSON |\n\n### Available Metrics\n\nSee `references/metric-types.md` for the complete list of available metrics.\n\nFile v1.2.1:skill-card.md\n\n## Description:\n\nRun KaiwuDB inspection and health-check tasks for database health checks, metrics collection, anomaly detection, and inspection report generation.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[kwdb](https://clawhub.ai/user/kwdb)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and database operators use this skill to inspect KaiwuDB clusters, collect time-series and slow-statement data, apply optional anomaly checks, and produce inspection reports.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Inspection reports and raw JSON may expose SQL text, usernames, database names, and error details.\n\nMitigation: Run against hosts you administer and handle generated reports and raw outputs as sensitive operational data.\n\nRisk: The skill probes network ports and collects data from KaiwuDB admin endpoints.\n\nMitigation: Use it only on authorized KaiwuDB clusters, preferably over trusted networks or tunnels, and confirm target hosts, ports, and scope before collection.\n\nRisk: TLS-enabled KaiwuDB deployments are not supported by the artifact workflow.\n\nMitigation: Stop inspection when TLS mode is detected and use an approved TLS-capable process instead.\n\nRisk: Single snapshots or incomplete multi-node evidence can lead to misleading anomaly judgments.\n\nMitigation: Document sampling windows, distinguish observed from inferred data, and require explicit thresholds for configurable anomaly checks.\n\n## Reference(s):\n\n- [Anomaly Rules](references/anomaly-rules.md)\n- [Port Listening Detection Reference](references/inspection-port-listening-reference.md)\n- [Inspection Requirements Confirmation](references/inspection-requirements-confirmation.md)\n- [Metric Types](references/metric-types.md)\n- [Output Rules](references/output-rules.md)\n- [Report Template](references/report-template.md)\n- [Slow Statements Script Usage](references/statements-script-usage.md)\n- [Time Series Metrics Script Usage](references/ts-metrics-script-usage.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, json, guidance]\n\n**Output Format:** [Markdown inspection report with optional JSON and tabular command output]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Reports should identify data sources and assumptions; raw JSON and report content may include SQL text, usernames, database names, and error details.]\n\n## Skill Version(s):\n\n1.2.1 (source: release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.2.0: 13 files, 17666 bytes\n\nFiles: references/anomaly-rules.md (981b), references/inspection-port-listening-reference.md (2158b), references/inspection-requirements-confirmation.md (1741b), references/metric-types.md (1547b), references/output-rules.md (1388b), references/report-template.md (1859b), references/statements-script-usage.md (2496b), references/ts-metrics-script-usage.md (1068b), scripts/get_kwdb_statements.py (7393b), scripts/get_kwdb_ts_metrics.py (14612b), skill-card.md (2741b), SKILL.md (3308b), _meta.json (146b)\n\nFile v1.2.0:SKILL.md\n\n---\nname: kwdb-intelligent-inspection\ndescription: |\n  Run KaiwuDB inspection and health-check tasks. Use this skill for database health checks, metrics collection, anomaly detection, and inspection report generation.\ntriggers:\n  - show me all database metrics\n  - database metrics for my KWDB cluster\n  - kwdb cluster metrics\n  - check database health\n  - inspect KWDB cluster\n  - database health check\n  - collect database metrics\n  - kwdb inspection\n  - 巡检\n  - 数据库指标\n  - 查看数据库指标\n  - 检查数据库健康\n---\n\n## Critical Constraints (non-negotiable)\n\n❝ **Never skip Step 1.** Collecting metrics before confirming node addresses, ports, and inspection scope with the user is forbidden. The inspection must not proceed until the user explicitly confirms the node addresses, ports, and inspection scope. ❞\n\n❝ **Never call a script without reading its usage doc first.** Before running any script under `scripts/`, you MUST read the corresponding `references/*-script-usage.md` file. This is the only way to know the correct parameters, defaults, and required arguments. Guessing parameters is forbidden. ❞\n\n❝ **Anomaly rules are user-driven.** If user does not request alerting, skip alerting. If user requests alerting without specific thresholds, apply default rules from `references/anomaly-rules.md`. If user provides custom thresholds, use those instead. ❞\n\n## Workflow\n\n### Step 1: Confirm target and scope\n\n**Before collecting any metrics**, follow `references/inspection-requirements-confirmation.md` EXACTLY in order:\n1. Parse user intent → confirm target (host, ports)\n2. Probe connectivity → verify ports reachable (see `references/inspection-port-listening-reference.md`)\n3. TLS mode detection → determine if inspection supported\n4. Present scope menu → user confirms before proceeding\n\n### Step 2: Collect metrics\n\n**MANDATORY: Read the script usage doc BEFORE calling any script.**\n- `references/ts-metrics-script-usage.md` — for `get_kwdb_ts_metrics.py`\n- `references/statements-script-usage.md` — for `get_kwdb_statements.py`\n\nDo not call any script without first reading its usage doc. Verify the parameter names, required arguments, and defaults match what you are about to pass.\n\n- **Port listener status**: Use Step 1 connectivity probe results.\n- **Most metrics**: Use `scripts/get_kwdb_ts_metrics.py` per `references/ts-metrics-script-usage.md`.\n- **Slow queries**: Use `scripts/get_kwdb_statements.py` per `references/statements-script-usage.md`.\n\n### Step 3: Apply anomaly rules\n\nApply anomaly judgment rules only when user requests alerting. See `references/anomaly-rules.md` for default rules and configurable rules.\n\n### Step 4: Generate report\n\nProduce a Markdown inspection report with metric values, anomaly judgments, and data-source notes per `references/output-rules.md`.\n\n## Anomaly Rules\n\nSee `references/anomaly-rules.md` for default rules and configurable rules.\n\n## Output Rules\n\nSee `references/output-rules.md` — **do not deviate from these rules when producing any inspection report.**\n\n## Limitations\n\n- **Windows is not supported**: This skill does not support Windows operating systems.\n- **TLS mode inspection is not supported**: This skill does not support inspecting KaiwuDB deployed with TLS mode enabled.\n\nFile v1.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn7fr8q8f22jd6gzb6f7prf9g183z64v\",\n  \"slug\": \"kwdb-intelligent-inspection\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1784785949658\n}\n\nFile v1.2.0:references/anomaly-rules.md\n\n## Anomaly Rules\n\nThese rules apply only when the user requests alerting. If no alerting is requested, skip all rules.\n\n### Default Rules (applied when user requests alerting without custom thresholds)\n\n1. **Database Down**: `cr.node.liveness.livenodes == 0` or port listener check failure\n2. **Port Anomaly**: Port 26257 or 8080 not listening\n3. **Frequent Restarts**: Database restarts > 1 time/day\n4. **Replica sync lag > 5s**: `cr.store.raft.replica.consistent.latency-p99` via `/ts/query` API\n5. **Unavailable Replicas > 0**: `cr.store.ranges.unavailable` via `/ts/query` API — ranges with fewer replicas than quorum requires\n\n### Configurable Rules (require explicit user threshold)\n\n- **CPU > threshold%**: `cr.node.sys.cpu.combined.percent-normalized`\n- **Memory > threshold%**: `cr.node.sys.rss`\n- **QPS anomaly**: requires sampling window, do not claim from single snapshot\n- **Write/Query latency anomaly**: requires sampling window, do not claim from single snapshot\n\nFile v1.2.0:references/inspection-port-listening-reference.md\n\n# Port Listening Detection Reference\n\nThis document describes how to check KaiwuDB port reachability status.\n\n## Critical Constraint (non-negotiable)\n\n**Do not SSH into the target server to run inspection commands there.** Always use local tools on the machine where the inspection is being performed. Only use remote port probing tools (`nc`, `telnet`, `curl`, `wget`) to check if KaiwuDB ports are reachable on target servers.\n\n## Default Ports\n\n| Service | Default Port | Description |\n|---------|-------------|-------------|\n| SQL Port | `26257` | KaiwuDB SQL/API port |\n| Admin Console | `8080` | Admin UI port |\n\n## Supported Detection Methods\n\nUse remote port probing tools to check if KaiwuDB ports are listening on target servers. Common tools:\n\n- **All platforms**: `nc` (netcat), `telnet`\n- **For HTTP ports**: `curl`, `wget`\n\n## Tool Installation\n\nIf the required port detection tool is not available on the local system:\n\n1. **Do NOT install tool automatically** — always request user permission first\n2. Explain to the user which tool is missing and why it is needed\n3. Ask for explicit confirmation before proceeding with installation\n4. Only after user approval, proceed with installation using system package manager\n\nExample prompt when tool is missing:\n```\n[TOOL_MISSING] The port probing tool 'nc' is not installed on this system.\nRequired for: Checking if KaiwuDB ports (26257, 8080) are reachable on target server.\nDo you want me to install it? (y/n)\n```\n\n## Example Commands\n\n### Using `nc` (netcat)\n```bash\nnc -zv <target_host> 26257 8080 -w 5\n```\n\n### Using `telnet`\n```bash\necho \"quit\" | telnet <target_host> 26257\n```\n\n### Using `curl` (for HTTP ports)\n```bash\ncurl -s -o /dev/null -w \"%{http_code}\" --connect-timeout 5 http://<target_host>:8080\n```\n\n### Using `wget` (for HTTP ports)\n```bash\nwget --spider --timeout=5 -q http://<target_host>:8080\n```\n\n## Expected Output\n\nThe inspection should verify:\n1. Whether each port is reachable (open/closed)\n2. Connection response time (if available)\n\n## Output Format\n\nReport the port reachability status:\n```json\n{\n  \"port\": 26257,\n  \"reachable\": true,\n  \"response_time_ms\": 12\n}\n```\n\nFile v1.2.0:references/inspection-requirements-confirmation.md\n\n## Inspection Requirements Confirmation\n\n⚠️ **These steps MUST be executed in the following order. Do not skip or reorder any step.**\n\n### Step 1: Parse User Intent\n\nWhen user provides a target (e.g., \"inspect 10.110.10.146 26257 8080\"), extract and confirm:\n- Node address(es)\n- Database port (default 26257)\n- Admin console port (default 8080)\n\n**Do NOT proceed to Step 2 until target info is confirmed with user.**\n\n---\n\n### Step 2: Probe Connectivity\n\nAfter confirming target info with user, verify reachability using appropriate tools (e.g., `nc`, `telnet`, `curl`, `ping`):\n- Check database port (26257) and admin console port (8080)\n- If ports unreachable: inform user and ask them to verify network/firewall/service\n- Only proceed if ports are reachable\n\n**Do NOT proceed to Step 3 until ports are confirmed reachable.**\n\n---\n\n### Step 3: TLS Mode Detection\n\nOnly after connectivity is confirmed, check TLS status:\n\n**Must strictly use this exact command format, only replace `<host>` and `<admin-port>` with actual values:**\n```\ncurl -k https://<host>:<admin-port>/health\n```\n- If output contains `error:0A00010B` or `wrong version number` → TLS not enforced, proceed\n- If returns JSON health data with no error → TLS enabled, **inspection not supported** (stop here)\n\n**Do NOT proceed to Step 4 until TLS mode is determined.**\n\n---\n\n### Step 4: Present Scope Menu\n\nRead `references/report-template.md` and `references/anomaly-rules.md`, then show user:\n- Full inspection scope (Sections 1-6)\n- Default rules and configurable rules (only applied if user requests alerting)\n- Ask user to confirm which metrics to inspect and whether to enable alerting\n\n**Do NOT proceed to metrics collection until user confirms the scope.**\n\nFile v1.2.0:references/metric-types.md\n\n## Metric Types\n\nThis document maps each inspectable metric to its `/ts/query` query params. Query params are read from this file when constructing API requests — do not infer or invent values.\n\n### Notation\n\n- `d` = downsampler\n- `sa` = source_aggregator\n- `der` = derivative\n\n### Gauge / Counter Metrics\n\nThese metrics use: `d:1, sa:2, der:0`\n\n| Metric Name |\n|-------------|\n| `cr.node.liveness.livenodes` |\n| `cr.node.sys.uptime` |\n| `cr.node.sys.cpu.user.percent` |\n| `cr.node.sys.cpu.sys.percent` |\n| `cr.node.sys.cpu.combined.percent-normalized` |\n| `cr.store.capacity` |\n| `cr.store.capacity.available` |\n| `cr.store.capacity.used` |\n| `cr.node.sys.rss` |\n| `cr.node.sys.go.allocbytes` |\n| `cr.node.sys.go.totalbytes` |\n| `cr.node.sql.insert.count` |\n| `cr.node.sql.update.count` |\n| `cr.node.sql.delete.count` |\n| `cr.store.rebalancing.writespersecond` |\n| `cr.node.sql.select.count` |\n| `cr.node.sql.query.count` |\n| `cr.store.rebalancing.queriespersecond` |\n| `cr.store.totalbytes` |\n| `cr.store.livebytes` |\n| `cr.store.replicas` |\n| `cr.store.replicas.leaders` |\n| `cr.store.replicas.leaseholders` |\n| `cr.store.ranges.unavailable` |\n| `cr.store.ranges.underreplicated` |\n| `cr.store.ranges.overreplicated` |\n| `cr.store.raftlog.behind` |\n\n### Latency Metrics\n\nThese metrics use: `d:1, sa:1, der:0`\n\n| Metric Name |\n|-------------|\n| `cr.node.exec.latency-p99` |\n| `cr.node.sql.service.latency-p99` |\n| `cr.node.sql.distsql.exec.latency-p99` |\n| `cr.store.raft.replica.consistent.latency-p99` |\n| `cr.node.clock-offset.meannanos` |\n\nFile v1.2.0:references/output-rules.md\n\n## Output Rules\n\n❝ **Never produce an inspection report unless it follows the format defined in `references/report-template.md`.** The report must use the Required Report Sections 1-6 structure, include all metrics listed under each section, and use the API Name column values for metric references. Deviating from this template is forbidden. ❞\n\n1. For every section, identify the data source as `API` (via `/ts/query`) or `OS` (via shell scripts under `scripts/`).\n2. If a metric is only partially supported, say so explicitly.\n3. If multi-node evidence is incomplete, say which part is inferred versus directly observed.\n4. Return inline Markdown report rather than claiming a saved file path unless a file tool actually created that artifact.\n5. If the task runs in cluster mode, the report must cover all nodes rather than only a single node snapshot.\n6. Scheduled inspection should recover thresholds and time-range hints from the task prompt; if missing, use defaults and document that assumption.\n7. HTML and PDF are optional; default to Markdown. When generating PDF, HTML, or Markdown files, use UTF-8 character encoding, use relevant PDF or HTML generation skills to produce reports in the corresponding format if available.\n8. If the user explicitly asks for charts, hand structured metrics to a visualization tool. Chart generation failure must not block the main report.\n\nFile v1.2.0:references/report-template.md\n\n## Required Report Sections\n\nThe default inspection report must cover these sections unless the user explicitly narrows scope.\n\n### Data Source Priority\n\n1. **Port listener status**: Use Workflow Step 1 connectivity probe results (no fixed script) in SKILL.md\n2. **Slow queries**: Use `scripts/get_kwdb_statements.py` (`/_status/statements` API)\n3. **All other metrics**: Use `scripts/get_kwdb_ts_metrics.py` (`/ts/query` API)\n\n### Report Sections\n\n#### 1. Basic Indicators\n\n- Database running state (`cr.node.liveness.livenodes`)\n- Uptime (`cr.node.sys.uptime`)\n\n#### 2. System Resources\n\n- CPU user % (`cr.node.sys.cpu.user.percent`)\n- CPU sys % (`cr.node.sys.cpu.sys.percent`)\n- CPU combined % normalized (`cr.node.sys.cpu.combined.percent-normalized`)\n- Disk total/available/used (`cr.store.capacity`, `cr.store.capacity.available`, `cr.store.capacity.used`)\n- Memory RSS (`cr.node.sys.rss`)\n- Go alloc/total bytes (`cr.node.sys.go.allocbytes`, `cr.node.sys.go.totalbytes`)\n\n#### 3. Database Performance\n\n- Write QPS: insert + update + delete + rebalancing writes\n- Query QPS: select + query + rebalancing queries\n- Exec latency: `cr.node.exec.latency-p99`, `cr.node.sql.service.latency-p99`, `cr.node.sql.distsql.exec.latency-p99`\n- Slow query information (via `/_status/statements` API)\n\n#### 4. Storage\n\n- Total data size (`cr.store.totalbytes`, `cr.store.livebytes`, `cr.store.capacity.used`)\n\n#### 5. Cluster\n\n- Replicas, Raft leaders, Lease holders (`cr.store.replicas`, `cr.store.replicas.leaders`, `cr.store.replicas.leaseholders`)\n- Unavailable/Under-replicated/Over-replicated ranges\n- Sync lag (`cr.store.raft.replica.consistent.latency-p99`, `cr.store.raftlog.behind`, `cr.store.raft.replica.consistent.latency-p99`)\n- Data distribution balance\n\n#### 6. Network\n\n- Node-to-node latency (`round-trip-latency`, `cr.node.clock-offset.meannanos`)\n\nFile v1.2.0:references/statements-script-usage.md\n\n## Slow Statements Script Usage\n\nUse `scripts/get_kwdb_statements.py` to collect slow SQL statement statistics from KaiwuDB.\n\n### Full Collection (all statements)\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> [--port <port>]\n```\n\n### Filter by Minimum Latency\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> --min-latency-ms <ms>\n```\n\nExample - get statements with service latency > 100ms:\n```bash\npython3 scripts/get_kwdb_statements.py --host 10.110.10.146 --min-latency-ms 100\n```\n\n### Sort by Different Metrics\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> --sort-by <field>\n```\n\nAvailable sort fields:\n- `service_lat` (default) - total service latency\n- `run_lat` - execution latency\n- `plan_lat` - planning latency\n- `count` - number of executions\n\n### Limit Results\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> --limit <N>\n```\n\n### Options\n\n| Option | Default | Description |\n|--------|---------|-------------|\n| `--host` | localhost | KaiwuDB admin host |\n| `--port` | 8080 | KaiwuDB admin port |\n| `--limit` | 10 | Number of statements to display |\n| `--min-latency-ms` | 0 | Minimum service latency filter (ms) |\n| `--sort-by` | service_lat | Sort field |\n| `--json` | false | Output raw JSON |\n\n### Output Format\n\nThe script outputs a formatted table with:\n- **Query** - SQL statement text (truncated at 200 chars)\n- **App** - Application name\n- **User** - Database user\n- **Database** - Database name\n- **Count** - Execution count\n- **Service/Run/Plan/Parse** - Latencies in ms\n- **DistSQL** - Whether distributed SQL was used\n- **Failed** - Whether any executions failed\n- **Last Error** - Error message if failed\n\n### Examples\n\n```bash\n# Get top 10 slowest statements (by service latency)\npython3 scripts/get_kwdb_statements.py --host localhost --port 8080\n\n# Filter statements with latency > 100ms\npython3 scripts/get_kwdb_statements.py --host localhost --min-latency-ms 100\n\n# Sort by run latency instead of service latency\npython3 scripts/get_kwdb_statements.py --host localhost --sort-by run_lat\n\n# Output raw JSON\npython3 scripts/get_kwdb_statements.py --host localhost --json\n\n# Limit to top 5\npython3 scripts/get_kwdb_statements.py --host localhost --limit 5\n```\n\n### Underlying API\n\nThis script wraps the KaiwuDB Statements API at `http://<host>:8080/_status/statements`.\n\n**Note:** TLS mode is not supported because the AdminUI login requires captcha verification that cannot be solved in non-interactive mode.\n\nFile v1.2.0:references/ts-metrics-script-usage.md\n\n## Time Series Metrics Script Usage\n\nUse `scripts/get_kwdb_ts_metrics.py` to collect time series metrics from KaiwuDB.\n\n### Full Collection (all metrics)\n\n```bash\npython3 scripts/get_kwdb_ts_metrics.py --host <host> [--port <port>]\n```\n\n### Partial Collection (specific metrics)\n\n```bash\npython3 scripts/get_kwdb_ts_metrics.py --host <host> --metric <metric_name> [--metric <metric_name> ...]\n```\n\nExample:\n```bash\npython3 scripts/get_kwdb_ts_metrics.py --host 10.110.10.146 --metric sys.cpu.user.percent --metric sql.insert.count\n```\n\n### Options\n\n| Option | Default | Description |\n|--------|---------|-------------|\n| `--host` | localhost | KaiwuDB admin host |\n| `--port` | 8080 | KaiwuDB admin port |\n| `--start` | 1 hour ago | Start time (unix timestamp in ns) |\n| `--end` | now | End time (unix timestamp in ns) |\n| `--sample` | 60 | Sample interval in seconds |\n| `--metric` | all | Filter by metric name (can repeat) |\n| `--json` | false | Output raw JSON |\n\n### Available Metrics\n\nSee `references/metric-types.md` for the complete list of available metrics.\n\nFile v1.2.0:skill-card.md\n\n## Description: <br>\nRun KaiwuDB inspection and health-check tasks for database health checks, metrics collection, anomaly detection, and inspection report generation. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[kwdb](https://clawhub.ai/user/kwdb) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, database operators, and support engineers use this skill to inspect KaiwuDB clusters, confirm target scope, collect time-series metrics and slow statement data, and generate Markdown health reports. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can collect and display sensitive database telemetry, including slow SQL statement text and error details. <br>\nMitigation: Use it only against KaiwuDB systems you administer and treat generated reports, script output, and raw JSON as confidential operational data. <br>\nRisk: Inspection traffic can use unencrypted HTTP to KaiwuDB admin endpoints. <br>\nMitigation: Prefer localhost, VPN, or SSH-tunneled access and avoid exposing collected telemetry over untrusted networks. <br>\nRisk: The skill probes target hosts and ports before collecting metrics. <br>\nMitigation: Confirm node addresses, ports, and inspection scope with the user before probing or running collection scripts. <br>\n\n\n## Reference(s): <br>\n- [Inspection Requirements Confirmation](references/inspection-requirements-confirmation.md) <br>\n- [Port Listening Detection Reference](references/inspection-port-listening-reference.md) <br>\n- [Time Series Metrics Script Usage](references/ts-metrics-script-usage.md) <br>\n- [Slow Statements Script Usage](references/statements-script-usage.md) <br>\n- [Metric Types](references/metric-types.md) <br>\n- [Anomaly Rules](references/anomaly-rules.md) <br>\n- [Output Rules](references/output-rules.md) <br>\n- [Required Report Sections](references/report-template.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, JSON, guidance] <br>\n**Output Format:** [Markdown inspection reports with inline command guidance and optional JSON or table output from helper scripts] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Reports must identify data sources, note incomplete evidence, and avoid claiming saved files unless the agent created them.] <br>\n\n## Skill Version(s): <br>\n1.2.0 (source: release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.1.0: 13 files, 17719 bytes\n\nFiles: references/anomaly-rules.md (981b), references/inspection-port-listening-reference.md (2158b), references/inspection-requirements-confirmation.md (1741b), references/metric-types.md (1547b), references/output-rules.md (1388b), references/report-template.md (1859b), references/statements-script-usage.md (2496b), references/ts-metrics-script-usage.md (1068b), scripts/get_kwdb_statements.py (7393b), scripts/get_kwdb_ts_metrics.py (14612b), skill-card.md (2966b), SKILL.md (3308b), _meta.json (146b)\n\nFile v1.1.0:SKILL.md\n\n---\nname: kwdb-intelligent-inspection\ndescription: |\n  Run KaiwuDB inspection and health-check tasks. Use this skill for database health checks, metrics collection, anomaly detection, and inspection report generation.\ntriggers:\n  - show me all database metrics\n  - database metrics for my KWDB cluster\n  - kwdb cluster metrics\n  - check database health\n  - inspect KWDB cluster\n  - database health check\n  - collect database metrics\n  - kwdb inspection\n  - 巡检\n  - 数据库指标\n  - 查看数据库指标\n  - 检查数据库健康\n---\n\n## Critical Constraints (non-negotiable)\n\n❝ **Never skip Step 1.** Collecting metrics before confirming node addresses, ports, and inspection scope with the user is forbidden. The inspection must not proceed until the user explicitly confirms the node addresses, ports, and inspection scope. ❞\n\n❝ **Never call a script without reading its usage doc first.** Before running any script under `scripts/`, you MUST read the corresponding `references/*-script-usage.md` file. This is the only way to know the correct parameters, defaults, and required arguments. Guessing parameters is forbidden. ❞\n\n❝ **Anomaly rules are user-driven.** If user does not request alerting, skip alerting. If user requests alerting without specific thresholds, apply default rules from `references/anomaly-rules.md`. If user provides custom thresholds, use those instead. ❞\n\n## Workflow\n\n### Step 1: Confirm target and scope\n\n**Before collecting any metrics**, follow `references/inspection-requirements-confirmation.md` EXACTLY in order:\n1. Parse user intent → confirm target (host, ports)\n2. Probe connectivity → verify ports reachable (see `references/inspection-port-listening-reference.md`)\n3. TLS mode detection → determine if inspection supported\n4. Present scope menu → user confirms before proceeding\n\n### Step 2: Collect metrics\n\n**MANDATORY: Read the script usage doc BEFORE calling any script.**\n- `references/ts-metrics-script-usage.md` — for `get_kwdb_ts_metrics.py`\n- `references/statements-script-usage.md` — for `get_kwdb_statements.py`\n\nDo not call any script without first reading its usage doc. Verify the parameter names, required arguments, and defaults match what you are about to pass.\n\n- **Port listener status**: Use Step 1 connectivity probe results.\n- **Most metrics**: Use `scripts/get_kwdb_ts_metrics.py` per `references/ts-metrics-script-usage.md`.\n- **Slow queries**: Use `scripts/get_kwdb_statements.py` per `references/statements-script-usage.md`.\n\n### Step 3: Apply anomaly rules\n\nApply anomaly judgment rules only when user requests alerting. See `references/anomaly-rules.md` for default rules and configurable rules.\n\n### Step 4: Generate report\n\nProduce a Markdown inspection report with metric values, anomaly judgments, and data-source notes per `references/output-rules.md`.\n\n## Anomaly Rules\n\nSee `references/anomaly-rules.md` for default rules and configurable rules.\n\n## Output Rules\n\nSee `references/output-rules.md` — **do not deviate from these rules when producing any inspection report.**\n\n## Limitations\n\n- **Windows is not supported**: This skill does not support Windows operating systems.\n- **TLS mode inspection is not supported**: This skill does not support inspecting KaiwuDB deployed with TLS mode enabled.\n\nFile v1.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn7fr8q8f22jd6gzb6f7prf9g183z64v\",\n  \"slug\": \"kwdb-intelligent-inspection\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1782118867262\n}\n\nFile v1.1.0:references/anomaly-rules.md\n\n## Anomaly Rules\n\nThese rules apply only when the user requests alerting. If no alerting is requested, skip all rules.\n\n### Default Rules (applied when user requests alerting without custom thresholds)\n\n1. **Database Down**: `cr.node.liveness.livenodes == 0` or port listener check failure\n2. **Port Anomaly**: Port 26257 or 8080 not listening\n3. **Frequent Restarts**: Database restarts > 1 time/day\n4. **Replica sync lag > 5s**: `cr.store.raft.replica.consistent.latency-p99` via `/ts/query` API\n5. **Unavailable Replicas > 0**: `cr.store.ranges.unavailable` via `/ts/query` API — ranges with fewer replicas than quorum requires\n\n### Configurable Rules (require explicit user threshold)\n\n- **CPU > threshold%**: `cr.node.sys.cpu.combined.percent-normalized`\n- **Memory > threshold%**: `cr.node.sys.rss`\n- **QPS anomaly**: requires sampling window, do not claim from single snapshot\n- **Write/Query latency anomaly**: requires sampling window, do not claim from single snapshot\n\nFile v1.1.0:references/inspection-port-listening-reference.md\n\n# Port Listening Detection Reference\n\nThis document describes how to check KaiwuDB port reachability status.\n\n## Critical Constraint (non-negotiable)\n\n**Do not SSH into the target server to run inspection commands there.** Always use local tools on the machine where the inspection is being performed. Only use remote port probing tools (`nc`, `telnet`, `curl`, `wget`) to check if KaiwuDB ports are reachable on target servers.\n\n## Default Ports\n\n| Service | Default Port | Description |\n|---------|-------------|-------------|\n| SQL Port | `26257` | KaiwuDB SQL/API port |\n| Admin Console | `8080` | Admin UI port |\n\n## Supported Detection Methods\n\nUse remote port probing tools to check if KaiwuDB ports are listening on target servers. Common tools:\n\n- **All platforms**: `nc` (netcat), `telnet`\n- **For HTTP ports**: `curl`, `wget`\n\n## Tool Installation\n\nIf the required port detection tool is not available on the local system:\n\n1. **Do NOT install tool automatically** — always request user permission first\n2. Explain to the user which tool is missing and why it is needed\n3. Ask for explicit confirmation before proceeding with installation\n4. Only after user approval, proceed with installation using system package manager\n\nExample prompt when tool is missing:\n```\n[TOOL_MISSING] The port probing tool 'nc' is not installed on this system.\nRequired for: Checking if KaiwuDB ports (26257, 8080) are reachable on target server.\nDo you want me to install it? (y/n)\n```\n\n## Example Commands\n\n### Using `nc` (netcat)\n```bash\nnc -zv <target_host> 26257 8080 -w 5\n```\n\n### Using `telnet`\n```bash\necho \"quit\" | telnet <target_host> 26257\n```\n\n### Using `curl` (for HTTP ports)\n```bash\ncurl -s -o /dev/null -w \"%{http_code}\" --connect-timeout 5 http://<target_host>:8080\n```\n\n### Using `wget` (for HTTP ports)\n```bash\nwget --spider --timeout=5 -q http://<target_host>:8080\n```\n\n## Expected Output\n\nThe inspection should verify:\n1. Whether each port is reachable (open/closed)\n2. Connection response time (if available)\n\n## Output Format\n\nReport the port reachability status:\n```json\n{\n  \"port\": 26257,\n  \"reachable\": true,\n  \"response_time_ms\": 12\n}\n```\n\nFile v1.1.0:references/inspection-requirements-confirmation.md\n\n## Inspection Requirements Confirmation\n\n⚠️ **These steps MUST be executed in the following order. Do not skip or reorder any step.**\n\n### Step 1: Parse User Intent\n\nWhen user provides a target (e.g., \"inspect 10.110.10.146 26257 8080\"), extract and confirm:\n- Node address(es)\n- Database port (default 26257)\n- Admin console port (default 8080)\n\n**Do NOT proceed to Step 2 until target info is confirmed with user.**\n\n---\n\n### Step 2: Probe Connectivity\n\nAfter confirming target info with user, verify reachability using appropriate tools (e.g., `nc`, `telnet`, `curl`, `ping`):\n- Check database port (26257) and admin console port (8080)\n- If ports unreachable: inform user and ask them to verify network/firewall/service\n- Only proceed if ports are reachable\n\n**Do NOT proceed to Step 3 until ports are confirmed reachable.**\n\n---\n\n### Step 3: TLS Mode Detection\n\nOnly after connectivity is confirmed, check TLS status:\n\n**Must strictly use this exact command format, only replace `<host>` and `<admin-port>` with actual values:**\n```\ncurl -k https://<host>:<admin-port>/health\n```\n- If output contains `error:0A00010B` or `wrong version number` → TLS not enforced, proceed\n- If returns JSON health data with no error → TLS enabled, **inspection not supported** (stop here)\n\n**Do NOT proceed to Step 4 until TLS mode is determined.**\n\n---\n\n### Step 4: Present Scope Menu\n\nRead `references/report-template.md` and `references/anomaly-rules.md`, then show user:\n- Full inspection scope (Sections 1-6)\n- Default rules and configurable rules (only applied if user requests alerting)\n- Ask user to confirm which metrics to inspect and whether to enable alerting\n\n**Do NOT proceed to metrics collection until user confirms the scope.**\n\nFile v1.1.0:references/metric-types.md\n\n## Metric Types\n\nThis document maps each inspectable metric to its `/ts/query` query params. Query params are read from this file when constructing API requests — do not infer or invent values.\n\n### Notation\n\n- `d` = downsampler\n- `sa` = source_aggregator\n- `der` = derivative\n\n### Gauge / Counter Metrics\n\nThese metrics use: `d:1, sa:2, der:0`\n\n| Metric Name |\n|-------------|\n| `cr.node.liveness.livenodes` |\n| `cr.node.sys.uptime` |\n| `cr.node.sys.cpu.user.percent` |\n| `cr.node.sys.cpu.sys.percent` |\n| `cr.node.sys.cpu.combined.percent-normalized` |\n| `cr.store.capacity` |\n| `cr.store.capacity.available` |\n| `cr.store.capacity.used` |\n| `cr.node.sys.rss` |\n| `cr.node.sys.go.allocbytes` |\n| `cr.node.sys.go.totalbytes` |\n| `cr.node.sql.insert.count` |\n| `cr.node.sql.update.count` |\n| `cr.node.sql.delete.count` |\n| `cr.store.rebalancing.writespersecond` |\n| `cr.node.sql.select.count` |\n| `cr.node.sql.query.count` |\n| `cr.store.rebalancing.queriespersecond` |\n| `cr.store.totalbytes` |\n| `cr.store.livebytes` |\n| `cr.store.replicas` |\n| `cr.store.replicas.leaders` |\n| `cr.store.replicas.leaseholders` |\n| `cr.store.ranges.unavailable` |\n| `cr.store.ranges.underreplicated` |\n| `cr.store.ranges.overreplicated` |\n| `cr.store.raftlog.behind` |\n\n### Latency Metrics\n\nThese metrics use: `d:1, sa:1, der:0`\n\n| Metric Name |\n|-------------|\n| `cr.node.exec.latency-p99` |\n| `cr.node.sql.service.latency-p99` |\n| `cr.node.sql.distsql.exec.latency-p99` |\n| `cr.store.raft.replica.consistent.latency-p99` |\n| `cr.node.clock-offset.meannanos` |\n\nFile v1.1.0:references/output-rules.md\n\n## Output Rules\n\n❝ **Never produce an inspection report unless it follows the format defined in `references/report-template.md`.** The report must use the Required Report Sections 1-6 structure, include all metrics listed under each section, and use the API Name column values for metric references. Deviating from this template is forbidden. ❞\n\n1. For every section, identify the data source as `API` (via `/ts/query`) or `OS` (via shell scripts under `scripts/`).\n2. If a metric is only partially supported, say so explicitly.\n3. If multi-node evidence is incomplete, say which part is inferred versus directly observed.\n4. Return inline Markdown report rather than claiming a saved file path unless a file tool actually created that artifact.\n5. If the task runs in cluster mode, the report must cover all nodes rather than only a single node snapshot.\n6. Scheduled inspection should recover thresholds and time-range hints from the task prompt; if missing, use defaults and document that assumption.\n7. HTML and PDF are optional; default to Markdown. When generating PDF, HTML, or Markdown files, use UTF-8 character encoding, use relevant PDF or HTML generation skills to produce reports in the corresponding format if available.\n8. If the user explicitly asks for charts, hand structured metrics to a visualization tool. Chart generation failure must not block the main report.\n\nFile v1.1.0:references/report-template.md\n\n## Required Report Sections\n\nThe default inspection report must cover these sections unless the user explicitly narrows scope.\n\n### Data Source Priority\n\n1. **Port listener status**: Use Workflow Step 1 connectivity probe results (no fixed script) in SKILL.md\n2. **Slow queries**: Use `scripts/get_kwdb_statements.py` (`/_status/statements` API)\n3. **All other metrics**: Use `scripts/get_kwdb_ts_metrics.py` (`/ts/query` API)\n\n### Report Sections\n\n#### 1. Basic Indicators\n\n- Database running state (`cr.node.liveness.livenodes`)\n- Uptime (`cr.node.sys.uptime`)\n\n#### 2. System Resources\n\n- CPU user % (`cr.node.sys.cpu.user.percent`)\n- CPU sys % (`cr.node.sys.cpu.sys.percent`)\n- CPU combined % normalized (`cr.node.sys.cpu.combined.percent-normalized`)\n- Disk total/available/used (`cr.store.capacity`, `cr.store.capacity.available`, `cr.store.capacity.used`)\n- Memory RSS (`cr.node.sys.rss`)\n- Go alloc/total bytes (`cr.node.sys.go.allocbytes`, `cr.node.sys.go.totalbytes`)\n\n#### 3. Database Performance\n\n- Write QPS: insert + update + delete + rebalancing writes\n- Query QPS: select + query + rebalancing queries\n- Exec latency: `cr.node.exec.latency-p99`, `cr.node.sql.service.latency-p99`, `cr.node.sql.distsql.exec.latency-p99`\n- Slow query information (via `/_status/statements` API)\n\n#### 4. Storage\n\n- Total data size (`cr.store.totalbytes`, `cr.store.livebytes`, `cr.store.capacity.used`)\n\n#### 5. Cluster\n\n- Replicas, Raft leaders, Lease holders (`cr.store.replicas`, `cr.store.replicas.leaders`, `cr.store.replicas.leaseholders`)\n- Unavailable/Under-replicated/Over-replicated ranges\n- Sync lag (`cr.store.raft.replica.consistent.latency-p99`, `cr.store.raftlog.behind`, `cr.store.raft.replica.consistent.latency-p99`)\n- Data distribution balance\n\n#### 6. Network\n\n- Node-to-node latency (`round-trip-latency`, `cr.node.clock-offset.meannanos`)\n\nFile v1.1.0:references/statements-script-usage.md\n\n## Slow Statements Script Usage\n\nUse `scripts/get_kwdb_statements.py` to collect slow SQL statement statistics from KaiwuDB.\n\n### Full Collection (all statements)\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> [--port <port>]\n```\n\n### Filter by Minimum Latency\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> --min-latency-ms <ms>\n```\n\nExample - get statements with service latency > 100ms:\n```bash\npython3 scripts/get_kwdb_statements.py --host 10.110.10.146 --min-latency-ms 100\n```\n\n### Sort by Different Metrics\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> --sort-by <field>\n```\n\nAvailable sort fields:\n- `service_lat` (default) - total service latency\n- `run_lat` - execution latency\n- `plan_lat` - planning latency\n- `count` - number of executions\n\n### Limit Results\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> --limit <N>\n```\n\n### Options\n\n| Option | Default | Description |\n|--------|---------|-------------|\n| `--host` | localhost | KaiwuDB admin host |\n| `--port` | 8080 | KaiwuDB admin port |\n| `--limit` | 10 | Number of statements to display |\n| `--min-latency-ms` | 0 | Minimum service latency filter (ms) |\n| `--sort-by` | service_lat | Sort field |\n| `--json` | false | Output raw JSON |\n\n### Output Format\n\nThe script outputs a formatted table with:\n- **Query** - SQL statement text (truncated at 200 chars)\n- **App** - Application name\n- **User** - Database user\n- **Database** - Database name\n- **Count** - Execution count\n- **Service/Run/Plan/Parse** - Latencies in ms\n- **DistSQL** - Whether distributed SQL was used\n- **Failed** - Whether any executions failed\n- **Last Error** - Error message if failed\n\n### Examples\n\n```bash\n# Get top 10 slowest statements (by service latency)\npython3 scripts/get_kwdb_statements.py --host localhost --port 8080\n\n# Filter statements with latency > 100ms\npython3 scripts/get_kwdb_statements.py --host localhost --min-latency-ms 100\n\n# Sort by run latency instead of service latency\npython3 scripts/get_kwdb_statements.py --host localhost --sort-by run_lat\n\n# Output raw JSON\npython3 scripts/get_kwdb_statements.py --host localhost --json\n\n# Limit to top 5\npython3 scripts/get_kwdb_statements.py --host localhost --limit 5\n```\n\n### Underlying API\n\nThis script wraps the KaiwuDB Statements API at `http://<host>:8080/_status/statements`.\n\n**Note:** TLS mode is not supported because the AdminUI login requires captcha verification that cannot be solved in non-interactive mode.\n\nFile v1.1.0:references/ts-metrics-script-usage.md\n\n## Time Series Metrics Script Usage\n\nUse `scripts/get_kwdb_ts_metrics.py` to collect time series metrics from KaiwuDB.\n\n### Full Collection (all metrics)\n\n```bash\npython3 scripts/get_kwdb_ts_metrics.py --host <host> [--port <port>]\n```\n\n### Partial Collection (specific metrics)\n\n```bash\npython3 scripts/get_kwdb_ts_metrics.py --host <host> --metric <metric_name> [--metric <metric_name> ...]\n```\n\nExample:\n```bash\npython3 scripts/get_kwdb_ts_metrics.py --host 10.110.10.146 --metric sys.cpu.user.percent --metric sql.insert.count\n```\n\n### Options\n\n| Option | Default | Description |\n|--------|---------|-------------|\n| `--host` | localhost | KaiwuDB admin host |\n| `--port` | 8080 | KaiwuDB admin port |\n| `--start` | 1 hour ago | Start time (unix timestamp in ns) |\n| `--end` | now | End time (unix timestamp in ns) |\n| `--sample` | 60 | Sample interval in seconds |\n| `--metric` | all | Filter by metric name (can repeat) |\n| `--json` | false | Output raw JSON |\n\n### Available Metrics\n\nSee `references/metric-types.md` for the complete list of available metrics.\n\nFile v1.1.0:skill-card.md\n\n## Description: <br>\nRun KaiwuDB inspection and health-check tasks for database health checks, metrics collection, anomaly detection, and inspection report generation. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[kwdb](https://clawhub.ai/user/kwdb) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDatabase administrators and support engineers use this skill to inspect KaiwuDB or KWDB clusters, collect metrics and slow statement telemetry, optionally apply user-requested anomaly rules, and produce a Markdown health-check report. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill fetches KaiwuDB admin telemetry over HTTP from user-specified hosts and ports. <br>\nMitigation: Run it only from a trusted admin environment, confirm the exact target hosts and ports before collection, and avoid untrusted networks. <br>\nRisk: Slow statement telemetry can expose SQL text, application names, users, database names, and error messages. <br>\nMitigation: Review and redact raw slow-query output before sharing it outside approved operational or support channels. <br>\nRisk: Inspection results may be misleading if run against the wrong cluster, unsupported TLS mode, or an incomplete scope. <br>\nMitigation: Follow the required confirmation workflow, stop when TLS mode is detected, and document partial or incomplete multi-node evidence in the report. <br>\n\n\n## Reference(s): <br>\n- [KWDB Intelligent Inspection on ClawHub](https://clawhub.ai/kwdb/kwdb-intelligent-inspection) <br>\n- [Inspection Requirements Confirmation](references/inspection-requirements-confirmation.md) <br>\n- [Port Listening Detection Reference](references/inspection-port-listening-reference.md) <br>\n- [Time Series Metrics Script Usage](references/ts-metrics-script-usage.md) <br>\n- [Slow Statements Script Usage](references/statements-script-usage.md) <br>\n- [Report Template](references/report-template.md) <br>\n- [Output Rules](references/output-rules.md) <br>\n- [Anomaly Rules](references/anomaly-rules.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, guidance] <br>\n**Output Format:** [Markdown inspection report with metric tables, anomaly notes when requested, and optional raw JSON from helper scripts.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires user-confirmed hosts, ports, inspection scope, and unsupported TLS status before collection; slow-query output may contain SQL text, user names, database names, and errors.] <br>\n\n## Skill Version(s): <br>\n1.1.0 (source: server evidence release.version) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.0: 13 files, 17692 bytes\n\nFiles: references/anomaly-rules.md (981b), references/inspection-port-listening-reference.md (2158b), references/inspection-requirements-confirmation.md (1741b), references/metric-types.md (1547b), references/output-rules.md (1284b), references/report-template.md (1859b), references/statements-script-usage.md (2496b), references/ts-metrics-script-usage.md (1068b), scripts/get_kwdb_statements.py (7393b), scripts/get_kwdb_ts_metrics.py (14612b), skill-card.md (3030b), SKILL.md (3308b), _meta.json (146b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: kwdb-intelligent-inspection\ndescription: |\n  Run KaiwuDB inspection and health-check tasks. Use this skill for database health checks, metrics collection, anomaly detection, and inspection report generation.\ntriggers:\n  - show me all database metrics\n  - database metrics for my KWDB cluster\n  - kwdb cluster metrics\n  - check database health\n  - inspect KWDB cluster\n  - database health check\n  - collect database metrics\n  - kwdb inspection\n  - 巡检\n  - 数据库指标\n  - 查看数据库指标\n  - 检查数据库健康\n---\n\n## Critical Constraints (non-negotiable)\n\n❝ **Never skip Step 1.** Collecting metrics before confirming node addresses, ports, and inspection scope with the user is forbidden. The inspection must not proceed until the user explicitly confirms the node addresses, ports, and inspection scope. ❞\n\n❝ **Never call a script without reading its usage doc first.** Before running any script under `scripts/`, you MUST read the corresponding `references/*-script-usage.md` file. This is the only way to know the correct parameters, defaults, and required arguments. Guessing parameters is forbidden. ❞\n\n❝ **Anomaly rules are user-driven.** If user does not request alerting, skip alerting. If user requests alerting without specific thresholds, apply default rules from `references/anomaly-rules.md`. If user provides custom thresholds, use those instead. ❞\n\n## Workflow\n\n### Step 1: Confirm target and scope\n\n**Before collecting any metrics**, follow `references/inspection-requirements-confirmation.md` EXACTLY in order:\n1. Parse user intent → confirm target (host, ports)\n2. Probe connectivity → verify ports reachable (see `references/inspection-port-listening-reference.md`)\n3. TLS mode detection → determine if inspection supported\n4. Present scope menu → user confirms before proceeding\n\n### Step 2: Collect metrics\n\n**MANDATORY: Read the script usage doc BEFORE calling any script.**\n- `references/ts-metrics-script-usage.md` — for `get_kwdb_ts_metrics.py`\n- `references/statements-script-usage.md` — for `get_kwdb_statements.py`\n\nDo not call any script without first reading its usage doc. Verify the parameter names, required arguments, and defaults match what you are about to pass.\n\n- **Port listener status**: Use Step 1 connectivity probe results.\n- **Most metrics**: Use `scripts/get_kwdb_ts_metrics.py` per `references/ts-metrics-script-usage.md`.\n- **Slow queries**: Use `scripts/get_kwdb_statements.py` per `references/statements-script-usage.md`.\n\n### Step 3: Apply anomaly rules\n\nApply anomaly judgment rules only when user requests alerting. See `references/anomaly-rules.md` for default rules and configurable rules.\n\n### Step 4: Generate report\n\nProduce a Markdown inspection report with metric values, anomaly judgments, and data-source notes per `references/output-rules.md`.\n\n## Anomaly Rules\n\nSee `references/anomaly-rules.md` for default rules and configurable rules.\n\n## Output Rules\n\nSee `references/output-rules.md` — **do not deviate from these rules when producing any inspection report.**\n\n## Limitations\n\n- **Windows is not supported**: This skill does not support Windows operating systems.\n- **TLS mode inspection is not supported**: This skill does not support inspecting KaiwuDB deployed with TLS mode enabled.\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7fr8q8f22jd6gzb6f7prf9g183z64v\",\n  \"slug\": \"kwdb-intelligent-inspection\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1779163773062\n}\n\nFile v1.0.0:references/anomaly-rules.md\n\n## Anomaly Rules\n\nThese rules apply only when the user requests alerting. If no alerting is requested, skip all rules.\n\n### Default Rules (applied when user requests alerting without custom thresholds)\n\n1. **Database Down**: `cr.node.liveness.livenodes == 0` or port listener check failure\n2. **Port Anomaly**: Port 26257 or 8080 not listening\n3. **Frequent Restarts**: Database restarts > 1 time/day\n4. **Replica sync lag > 5s**: `cr.store.raft.replica.consistent.latency-p99` via `/ts/query` API\n5. **Unavailable Replicas > 0**: `cr.store.ranges.unavailable` via `/ts/query` API — ranges with fewer replicas than quorum requires\n\n### Configurable Rules (require explicit user threshold)\n\n- **CPU > threshold%**: `cr.node.sys.cpu.combined.percent-normalized`\n- **Memory > threshold%**: `cr.node.sys.rss`\n- **QPS anomaly**: requires sampling window, do not claim from single snapshot\n- **Write/Query latency anomaly**: requires sampling window, do not claim from single snapshot\n\nFile v1.0.0:references/inspection-port-listening-reference.md\n\n# Port Listening Detection Reference\n\nThis document describes how to check KaiwuDB port reachability status.\n\n## Critical Constraint (non-negotiable)\n\n**Do not SSH into the target server to run inspection commands there.** Always use local tools on the machine where the inspection is being performed. Only use remote port probing tools (`nc`, `telnet`, `curl`, `wget`) to check if KaiwuDB ports are reachable on target servers.\n\n## Default Ports\n\n| Service | Default Port | Description |\n|---------|-------------|-------------|\n| SQL Port | `26257` | KaiwuDB SQL/API port |\n| Admin Console | `8080` | Admin UI port |\n\n## Supported Detection Methods\n\nUse remote port probing tools to check if KaiwuDB ports are listening on target servers. Common tools:\n\n- **All platforms**: `nc` (netcat), `telnet`\n- **For HTTP ports**: `curl`, `wget`\n\n## Tool Installation\n\nIf the required port detection tool is not available on the local system:\n\n1. **Do NOT install tool automatically** — always request user permission first\n2. Explain to the user which tool is missing and why it is needed\n3. Ask for explicit confirmation before proceeding with installation\n4. Only after user approval, proceed with installation using system package manager\n\nExample prompt when tool is missing:\n```\n[TOOL_MISSING] The port probing tool 'nc' is not installed on this system.\nRequired for: Checking if KaiwuDB ports (26257, 8080) are reachable on target server.\nDo you want me to install it? (y/n)\n```\n\n## Example Commands\n\n### Using `nc` (netcat)\n```bash\nnc -zv <target_host> 26257 8080 -w 5\n```\n\n### Using `telnet`\n```bash\necho \"quit\" | telnet <target_host> 26257\n```\n\n### Using `curl` (for HTTP ports)\n```bash\ncurl -s -o /dev/null -w \"%{http_code}\" --connect-timeout 5 http://<target_host>:8080\n```\n\n### Using `wget` (for HTTP ports)\n```bash\nwget --spider --timeout=5 -q http://<target_host>:8080\n```\n\n## Expected Output\n\nThe inspection should verify:\n1. Whether each port is reachable (open/closed)\n2. Connection response time (if available)\n\n## Output Format\n\nReport the port reachability status:\n```json\n{\n  \"port\": 26257,\n  \"reachable\": true,\n  \"response_time_ms\": 12\n}\n```\n\nFile v1.0.0:references/inspection-requirements-confirmation.md\n\n## Inspection Requirements Confirmation\n\n⚠️ **These steps MUST be executed in the following order. Do not skip or reorder any step.**\n\n### Step 1: Parse User Intent\n\nWhen user provides a target (e.g., \"inspect 10.110.10.146 26257 8080\"), extract and confirm:\n- Node address(es)\n- Database port (default 26257)\n- Admin console port (default 8080)\n\n**Do NOT proceed to Step 2 until target info is confirmed with user.**\n\n---\n\n### Step 2: Probe Connectivity\n\nAfter confirming target info with user, verify reachability using appropriate tools (e.g., `nc`, `telnet`, `curl`, `ping`):\n- Check database port (26257) and admin console port (8080)\n- If ports unreachable: inform user and ask them to verify network/firewall/service\n- Only proceed if ports are reachable\n\n**Do NOT proceed to Step 3 until ports are confirmed reachable.**\n\n---\n\n### Step 3: TLS Mode Detection\n\nOnly after connectivity is confirmed, check TLS status:\n\n**Must strictly use this exact command format, only replace `<host>` and `<admin-port>` with actual values:**\n```\ncurl -k https://<host>:<admin-port>/health\n```\n- If output contains `error:0A00010B` or `wrong version number` → TLS not enforced, proceed\n- If returns JSON health data with no error → TLS enabled, **inspection not supported** (stop here)\n\n**Do NOT proceed to Step 4 until TLS mode is determined.**\n\n---\n\n### Step 4: Present Scope Menu\n\nRead `references/report-template.md` and `references/anomaly-rules.md`, then show user:\n- Full inspection scope (Sections 1-6)\n- Default rules and configurable rules (only applied if user requests alerting)\n- Ask user to confirm which metrics to inspect and whether to enable alerting\n\n**Do NOT proceed to metrics collection until user confirms the scope.**\n\nFile v1.0.0:references/metric-types.md\n\n## Metric Types\n\nThis document maps each inspectable metric to its `/ts/query` query params. Query params are read from this file when constructing API requests — do not infer or invent values.\n\n### Notation\n\n- `d` = downsampler\n- `sa` = source_aggregator\n- `der` = derivative\n\n### Gauge / Counter Metrics\n\nThese metrics use: `d:1, sa:2, der:0`\n\n| Metric Name |\n|-------------|\n| `cr.node.liveness.livenodes` |\n| `cr.node.sys.uptime` |\n| `cr.node.sys.cpu.user.percent` |\n| `cr.node.sys.cpu.sys.percent` |\n| `cr.node.sys.cpu.combined.percent-normalized` |\n| `cr.store.capacity` |\n| `cr.store.capacity.available` |\n| `cr.store.capacity.used` |\n| `cr.node.sys.rss` |\n| `cr.node.sys.go.allocbytes` |\n| `cr.node.sys.go.totalbytes` |\n| `cr.node.sql.insert.count` |\n| `cr.node.sql.update.count` |\n| `cr.node.sql.delete.count` |\n| `cr.store.rebalancing.writespersecond` |\n| `cr.node.sql.select.count` |\n| `cr.node.sql.query.count` |\n| `cr.store.rebalancing.queriespersecond` |\n| `cr.store.totalbytes` |\n| `cr.store.livebytes` |\n| `cr.store.replicas` |\n| `cr.store.replicas.leaders` |\n| `cr.store.replicas.leaseholders` |\n| `cr.store.ranges.unavailable` |\n| `cr.store.ranges.underreplicated` |\n| `cr.store.ranges.overreplicated` |\n| `cr.store.raftlog.behind` |\n\n### Latency Metrics\n\nThese metrics use: `d:1, sa:1, der:0`\n\n| Metric Name |\n|-------------|\n| `cr.node.exec.latency-p99` |\n| `cr.node.sql.service.latency-p99` |\n| `cr.node.sql.distsql.exec.latency-p99` |\n| `cr.store.raft.replica.consistent.latency-p99` |\n| `cr.node.clock-offset.meannanos` |\n\nFile v1.0.0:references/output-rules.md\n\n## Output Rules\n\n❝ **Never produce an inspection report unless it follows the format defined in `references/report-template.md`.** The report must use the Required Report Sections 1-6 structure, include all metrics listed under each section, and use the API Name column values for metric references. Deviating from this template is forbidden. ❞\n\n1. For every section, identify the data source as `API` (via `/ts/query`) or `OS` (via shell scripts under `scripts/`).\n2. If a metric is only partially supported, say so explicitly.\n3. If multi-node evidence is incomplete, say which part is inferred versus directly observed.\n4. Return inline Markdown report rather than claiming a saved file path unless a file tool actually created that artifact.\n5. If the task runs in cluster mode, the report must cover all nodes rather than only a single node snapshot.\n6. Scheduled inspection should recover thresholds and time-range hints from the task prompt; if missing, use defaults and document that assumption.\n7. HTML and PDF are optional; default to Markdown. When generating PDF, HTML, or Markdown files, use UTF-8 character encoding.\n8. If the user explicitly asks for charts, hand structured metrics to a visualization tool. Chart generation failure must not block the main report.\n\nFile v1.0.0:references/report-template.md\n\n## Required Report Sections\n\nThe default inspection report must cover these sections unless the user explicitly narrows scope.\n\n### Data Source Priority\n\n1. **Port listener status**: Use Workflow Step 1 connectivity probe results (no fixed script) in SKILL.md\n2. **Slow queries**: Use `scripts/get_kwdb_statements.py` (`/_status/statements` API)\n3. **All other metrics**: Use `scripts/get_kwdb_ts_metrics.py` (`/ts/query` API)\n\n### Report Sections\n\n#### 1. Basic Indicators\n\n- Database running state (`cr.node.liveness.livenodes`)\n- Uptime (`cr.node.sys.uptime`)\n\n#### 2. System Resources\n\n- CPU user % (`cr.node.sys.cpu.user.percent`)\n- CPU sys % (`cr.node.sys.cpu.sys.percent`)\n- CPU combined % normalized (`cr.node.sys.cpu.combined.percent-normalized`)\n- Disk total/available/used (`cr.store.capacity`, `cr.store.capacity.available`, `cr.store.capacity.used`)\n- Memory RSS (`cr.node.sys.rss`)\n- Go alloc/total bytes (`cr.node.sys.go.allocbytes`, `cr.node.sys.go.totalbytes`)\n\n#### 3. Database Performance\n\n- Write QPS: insert + update + delete + rebalancing writes\n- Query QPS: select + query + rebalancing queries\n- Exec latency: `cr.node.exec.latency-p99`, `cr.node.sql.service.latency-p99`, `cr.node.sql.distsql.exec.latency-p99`\n- Slow query information (via `/_status/statements` API)\n\n#### 4. Storage\n\n- Total data size (`cr.store.totalbytes`, `cr.store.livebytes`, `cr.store.capacity.used`)\n\n#### 5. Cluster\n\n- Replicas, Raft leaders, Lease holders (`cr.store.replicas`, `cr.store.replicas.leaders`, `cr.store.replicas.leaseholders`)\n- Unavailable/Under-replicated/Over-replicated ranges\n- Sync lag (`cr.store.raft.replica.consistent.latency-p99`, `cr.store.raftlog.behind`, `cr.store.raft.replica.consistent.latency-p99`)\n- Data distribution balance\n\n#### 6. Network\n\n- Node-to-node latency (`round-trip-latency`, `cr.node.clock-offset.meannanos`)\n\nFile v1.0.0:references/statements-script-usage.md\n\n## Slow Statements Script Usage\n\nUse `scripts/get_kwdb_statements.py` to collect slow SQL statement statistics from KaiwuDB.\n\n### Full Collection (all statements)\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> [--port <port>]\n```\n\n### Filter by Minimum Latency\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> --min-latency-ms <ms>\n```\n\nExample - get statements with service latency > 100ms:\n```bash\npython3 scripts/get_kwdb_statements.py --host 10.110.10.146 --min-latency-ms 100\n```\n\n### Sort by Different Metrics\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> --sort-by <field>\n```\n\nAvailable sort fields:\n- `service_lat` (default) - total service latency\n- `run_lat` - execution latency\n- `plan_lat` - planning latency\n- `count` - number of executions\n\n### Limit Results\n\n```bash\npython3 scripts/get_kwdb_statements.py --host <host> --limit <N>\n```\n\n### Options\n\n| Option | Default | Description |\n|--------|---------|-------------|\n| `--host` | localhost | KaiwuDB admin host |\n| `--port` | 8080 | KaiwuDB admin port |\n| `--limit` | 10 | Number of statements to display |\n| `--min-latency-ms` | 0 | Minimum service latency filter (ms) |\n| `--sort-by` | service_lat | Sort field |\n| `--json` | false | Output raw JSON |\n\n### Output Format\n\nThe script outputs a formatted table with:\n- **Query** - SQL statement text (truncated at 200 chars)\n- **App** - Application name\n- **User** - Database user\n- **Database** - Database name\n- **Count** - Execution count\n- **Service/Run/Plan/Parse** - Latencies in ms\n- **DistSQL** - Whether distributed SQL was used\n- **Failed** - Whether any executions failed\n- **Last Error** - Error message if failed\n\n### Examples\n\n```bash\n# Get top 10 slowest statements (by service latency)\npython3 scripts/get_kwdb_statements.py --host localhost --port 8080\n\n# Filter statements with latency > 100ms\npython3 scripts/get_kwdb_statements.py --host localhost --min-latency-ms 100\n\n# Sort by run latency instead of service latency\npython3 scripts/get_kwdb_statements.py --host localhost --sort-by run_lat\n\n# Output raw JSON\npython3 scripts/get_kwdb_statements.py --host localhost --json\n\n# Limit to top 5\npython3 scripts/get_kwdb_statements.py --host localhost --limit 5\n```\n\n### Underlying API\n\nThis script wraps the KaiwuDB Statements API at `http://<host>:8080/_status/statements`.\n\n**Note:** TLS mode is not supported because the AdminUI login requires captcha verification that cannot be solved in non-interactive mode.\n\nFile v1.0.0:references/ts-metrics-script-usage.md\n\n## Time Series Metrics Script Usage\n\nUse `scripts/get_kwdb_ts_metrics.py` to collect time series metrics from KaiwuDB.\n\n### Full Collection (all metrics)\n\n```bash\npython3 scripts/get_kwdb_ts_metrics.py --host <host> [--port <port>]\n```\n\n### Partial Collection (specific metrics)\n\n```bash\npython3 scripts/get_kwdb_ts_metrics.py --host <host> --metric <metric_name> [--metric <metric_name> ...]\n```\n\nExample:\n```bash\npython3 scripts/get_kwdb_ts_metrics.py --host 10.110.10.146 --metric sys.cpu.user.percent --metric sql.insert.count\n```\n\n### Options\n\n| Option | Default | Description |\n|--------|---------|-------------|\n| `--host` | localhost | KaiwuDB admin host |\n| `--port` | 8080 | KaiwuDB admin port |\n| `--start` | 1 hour ago | Start time (unix timestamp in ns) |\n| `--end` | now | End time (unix timestamp in ns) |\n| `--sample` | 60 | Sample interval in seconds |\n| `--metric` | all | Filter by metric name (can repeat) |\n| `--json` | false | Output raw JSON |\n\n### Available Metrics\n\nSee `references/metric-types.md` for the complete list of available metrics.\n\nFile v1.0.0:skill-card.md\n\n## Description: <br>\nRun KaiwuDB inspection and health-check tasks for database health checks, metrics collection, anomaly detection, and inspection report generation. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[kwdb](https://clawhub.ai/user/kwdb) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDatabase administrators and operations engineers use this skill to inspect KaiwuDB clusters, collect metrics and slow-statement data, apply requested anomaly rules, and produce inspection reports. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Inspection reports and JSON output may include sensitive workload details such as SQL text, usernames, database names, error messages, topology, and capacity data. <br>\nMitigation: Share reports only with authorized operators and redact sensitive fields before storing or forwarding results. <br>\nRisk: Running inspection against the wrong host, ports, or scope could expose or collect data from an unintended KaiwuDB cluster. <br>\nMitigation: Confirm node addresses, ports, and inspection scope with the user before any connectivity checks or metric collection. <br>\nRisk: Network inspection of database endpoints can be inappropriate outside trusted administrative contexts. <br>\nMitigation: Use the skill only when administering the target KaiwuDB cluster and run it from trusted networks. <br>\nRisk: TLS-enabled KaiwuDB deployments are not supported by this skill. <br>\nMitigation: Stop inspection when TLS mode is detected and use a supported manual or authenticated workflow instead. <br>\n\n\n## Reference(s): <br>\n- [ClawHub release page](https://clawhub.ai/kwdb/kwdb-intelligent-inspection) <br>\n- [Inspection requirements confirmation](references/inspection-requirements-confirmation.md) <br>\n- [Port listening detection reference](references/inspection-port-listening-reference.md) <br>\n- [Time series metrics script usage](references/ts-metrics-script-usage.md) <br>\n- [Slow statements script usage](references/statements-script-usage.md) <br>\n- [Metric types](references/metric-types.md) <br>\n- [Anomaly rules](references/anomaly-rules.md) <br>\n- [Report template](references/report-template.md) <br>\n- [Output rules](references/output-rules.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, json, guidance] <br>\n**Output Format:** [Markdown reports with optional JSON data and shell command snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires confirmed target host, ports, inspection scope, and TLS support before collection.] <br>\n\n## Skill Version(s): <br>\n1.0.0 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: KWDB Intelligent Inspection Owner: kwdb Summary: Run KaiwuDB inspection and health-check tasks. Use this skill for database health checks, metrics collection, anomaly detection, and inspection report generation. Tags: kwdb:1.2.1, latest:1.2.1, ready:1.2.1 Version history: v1.2.1 | 2026-08-28T00:47:36.030Z | auto - Removed the skill description file skill-card.md. - No changes to the skill logic or SKILL.md con","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"[TOOL_MISSING] The port probing tool 'nc' is not installed on this system.\nRequired for: Checking if KaiwuDB ports (26257, 8080) are reachable on target server.\nDo you want me to install it? (y/n)"},{"language":"bash","snippet":"nc -zv <target_host> 26257 8080 -w 5"},{"language":"bash","snippet":"echo \"quit\" | telnet <target_host> 26257"},{"language":"bash","snippet":"curl -s -o /dev/null -w \"%{http_code}\" --connect-timeout 5 http://<target_host>:8080"},{"language":"bash","snippet":"curl -s -o /dev/null -w \"%{http_code}\" --connect-timeout 5 http://<target_host>:8080"},{"language":"bash","snippet":"wget --spider --timeout=5 -q http://<target_host>:8080"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: kwdb-intelligent-inspection\ndescription: |\n  Run KaiwuDB inspection and health-check tasks. Use this skill for database health checks, metrics collection, anomaly detection, and inspection report generation.\ntriggers:\n  - show me all database metrics\n  - database metrics for my KWDB cluster\n  - kwdb cluster metrics\n  - check database health\n  - inspect KWDB cluster\n  - database health check\n  - collect database metrics\n  - kwdb inspection\n  - 巡检\n  - 数据库指标\n  - 查看数据库指标\n  - 检查数据库健康\n---\n\n## Critical Constraints (non-negotiable)\n\n❝ **Never skip Step 1.** Collecting metrics before confirming node addresses, ports, and inspection scope with the user is forbidden. The inspection must not proceed until the user explicitly confirms the node addresses, ports, and inspection scope. ❞\n\n❝ **Never call a script without reading its usage doc first.** Before running any script under `scripts/`, you MUST read the corresponding `references/*-script-usage.md` file. This is the only way to know the correct parameters, defaults, and required arguments. Guessing parameters is forbidden. ❞\n\n❝ **Anomaly rules are user-driven.** If user does not request alerting, skip alerting. If user requests alerting without specific thresholds, apply default rules from `references/anomaly-rules.md`. If user provides custom thresholds, use those instead. ❞\n\n## Workflow\n\n### Step 1: Confirm target and scope\n\n**Before collecting any metrics**, follow `references/inspection-requirements-confirmation.md` EXACTLY in order:\n1. Parse user intent → confirm target (host, ports)\n2. Probe connectivity → verify ports reachable (see `references/inspection-port-listening-reference.md`)\n3. TLS mode detection → determine if inspection supported\n4. Present scope menu → user confirms before proceeding\n\n### Step 2: Collect metrics\n\n**MANDATORY: Read the script usage doc BEFORE calling any script.**\n- `references/ts-metrics-script-usage.md` — for `get_kwdb_ts_metrics.py`\n- `references/statements-script-usage.md` — for `get_kwdb_statements.py`\n\nDo not call any script without first reading its usage doc. Verify the parameter names, required arguments, and defaults match what you are about to pass.\n\n- **Port listener status**: Use Step 1 connectivity probe results.\n- **Most metrics**: Use `scripts/get_kwdb_ts_metrics.py` per `references/ts-metrics-script-usage.md`.\n- **Slow queries**: Use `scripts/get_kwdb_statements.py` per `references/statements-script-usage.md`.\n\n### Step 3: Apply anomaly rules\n\nApply anomaly judgment rules only when user requests alerting. See `references/anomaly-rules.md` for default rules and configurable rules.\n\n### Step 4: Generate report\n\nProduce a Markdown inspection report with metric values, anomaly judgments, and data-source notes per `references/output-rules.md`.\n\n## Anomaly Rules\n\nSee `references/anomaly-rules.md` for default rules and configurable rules.\n\n## Output Rules\n\nSee `references/output-rules.md` — **do not deviate from these rules when producing any inspect"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7fr8q8f22jd6gzb6f7prf9g183z64v\",\n  \"slug\": \"kwdb-intelligent-inspection\",\n  \"version\": \"1.2.1\",\n  \"publishedAt\": 1787878056030\n}"},{"path":"references/anomaly-rules.md","content":"## Anomaly Rules\n\nThese rules apply only when the user requests alerting. If no alerting is requested, skip all rules.\n\n### Default Rules (applied when user requests alerting without custom thresholds)\n\n1. **Database Down**: `cr.node.liveness.livenodes == 0` or port listener check failure\n2. **Port Anomaly**: Port 26257 or 8080 not listening\n3. **Frequent Restarts**: Database restarts > 1 time/day\n4. **Replica sync lag > 5s**: `cr.store.raft.replica.consistent.latency-p99` via `/ts/query` API\n5. **Unavailable Replicas > 0**: `cr.store.ranges.unavailable` via `/ts/query` API — ranges with fewer replicas than quorum requires\n\n### Configurable Rules (require explicit user threshold)\n\n- **CPU > threshold%**: `cr.node.sys.cpu.combined.percent-normalized`\n- **Memory > threshold%**: `cr.node.sys.rss`\n- **QPS anomaly**: requires sampling window, do not claim from single snapshot\n- **Write/Query latency anomaly**: requires sampling window, do not claim from single snapshot"},{"path":"references/inspection-port-listening-reference.md","content":"# Port Listening Detection Reference\n\nThis document describes how to check KaiwuDB port reachability status.\n\n## Critical Constraint (non-negotiable)\n\n**Do not SSH into the target server to run inspection commands there.** Always use local tools on the machine where the inspection is being performed. Only use remote port probing tools (`nc`, `telnet`, `curl`, `wget`) to check if KaiwuDB ports are reachable on target servers.\n\n## Default Ports\n\n| Service | Default Port | Description |\n|---------|-------------|-------------|\n| SQL Port | `26257` | KaiwuDB SQL/API port |\n| Admin Console | `8080` | Admin UI port |\n\n## Supported Detection Methods\n\nUse remote port probing tools to check if KaiwuDB ports are listening on target servers. Common tools:\n\n- **All platforms**: `nc` (netcat), `telnet`\n- **For HTTP ports**: `curl`, `wget`\n\n## Tool Installation\n\nIf the required port detection tool is not available on the local system:\n\n1. **Do NOT install tool automatically** — always request user permission first\n2. Explain to the user which tool is missing and why it is needed\n3. Ask for explicit confirmation before proceeding with installation\n4. Only after user approval, proceed with installation using system package manager\n\nExample prompt when tool is missing:\n```\n[TOOL_MISSING] The port probing tool 'nc' is not installed on this system.\nRequired for: Checking if KaiwuDB ports (26257, 8080) are reachable on target server.\nDo you want me to install it? (y/n)\n```\n\n## Example Commands\n\n### Using `nc` (netcat)\n```bash\nnc -zv <target_host> 26257 8080 -w 5\n```\n\n### Using `telnet`\n```bash\necho \"quit\" | telnet <target_host> 26257\n```\n\n### Using `curl` (for HTTP ports)\n```bash\ncurl -s -o /dev/null -w \"%{http_code}\" --connect-timeout 5 http://<target_host>:8080\n```\n\n### Using `wget` (for HTTP ports)\n```bash\nwget --spider --timeout=5 -q http://<target_host>:8080\n```\n\n## Expected Output\n\nThe inspection should verify:\n1. Whether each port is reachable (open/closed)\n2. Connection response time (if available)\n\n## Output Format\n\nReport the port reachability status:\n```json\n{\n  \"port\": 26257,\n  \"reachable\": true,\n  \"response_time_ms\": 12\n}\n```"},{"path":"references/inspection-requirements-confirmation.md","content":"## Inspection Requirements Confirmation\n\n⚠️ **These steps MUST be executed in the following order. Do not skip or reorder any step.**\n\n### Step 1: Parse User Intent\n\nWhen user provides a target (e.g., \"inspect 10.110.10.146 26257 8080\"), extract and confirm:\n- Node address(es)\n- Database port (default 26257)\n- Admin console port (default 8080)\n\n**Do NOT proceed to Step 2 until target info is confirmed with user.**\n\n---\n\n### Step 2: Probe Connectivity\n\nAfter confirming target info with user, verify reachability using appropriate tools (e.g., `nc`, `telnet`, `curl`, `ping`):\n- Check database port (26257) and admin console port (8080)\n- If ports unreachable: inform user and ask them to verify network/firewall/service\n- Only proceed if ports are reachable\n\n**Do NOT proceed to Step 3 until ports are confirmed reachable.**\n\n---\n\n### Step 3: TLS Mode Detection\n\nOnly after connectivity is confirmed, check TLS status:\n\n**Must strictly use this exact command format, only replace `<host>` and `<admin-port>` with actual values:**\n```\ncurl -k https://<host>:<admin-port>/health\n```\n- If output contains `error:0A00010B` or `wrong version number` → TLS not enforced, proceed\n- If returns JSON health data with no error → TLS enabled, **inspection not supported** (stop here)\n\n**Do NOT proceed to Step 4 until TLS mode is determined.**\n\n---\n\n### Step 4: Present Scope Menu\n\nRead `references/report-template.md` and `references/anomaly-rules.md`, then show user:\n- Full inspection scope (Sections 1-6)\n- Default rules and configurable rules (only applied if user requests alerting)\n- Ask user to confirm which metrics to inspect and whether to enable alerting\n\n**Do NOT proceed to metrics collection until user confirms the scope.**"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1623,"uniquenessScore":38,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T23:38:39.294Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T23:38:39.294Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T01:48:16.912Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}