Token导航 LogoToken导航TokenDH.com
研究检索需要联网clawhub未标认证来源可访问clear审计通过

incident-replay事件重播

Agent Skill

incident-replay 用于查找、检索和筛选相关信息,适合在 OpenClaw 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

10,336

周安装

435

GitHub Stars

公开资料未说明

下载量

3,619
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:incident-replay(事件重播)
来源仓库:https://github.com/theshadowrose/incident-replay
安装命令:
openclaw skills install incident-replay
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install incident-replay

简介

incident-replay 对 AI 代理崩溃事件进行事后回放,重建执行过程与失败节点。

  • 适合在 OpenClaw 中诊断代理行为异常、定位逻辑错误或优化容错机制时使用。
  • 捕获完整状态序列与调用栈信息,辅助开发者理解故障传播路径。
  • 安装命令:openclaw skills install incident-replay,需提供崩溃时的日志与内存快照。
  • 注意部分敏感操作记录可能被加密,需提前配置调试符号与日志级别。

SKILL.md

name
Incident Replay Agent Failure Forensics
description
Post-mortem analysis for AI agent failures. Capture state, reconstruct timelines, identify root causes. When your agent breaks, know what happened, why, and how to prevent it.
author
@TheShadowRose
version
1.0.5
tags
["forensics", "debugging", "post-mortem", "failure-analysis", "incident", "recovery"]
license
MIT

Incident Replay Agent Failure Forensics

Post-mortem analysis for AI agent failures. Capture state, reconstruct timelines, identify root causes. When your agent breaks, know what happened, why, and how to prevent it.


Post-mortem analysis for AI agent failures. Capture state, reconstruct timelines, identify root causes.

When your agent breaks, you need to know what happened, why, and how to prevent it next time. Incident Replay captures workspace state at points in time, detects when things go wrong, reconstructs the sequence of events, and classifies root causes with actionable remediation steps.


The Problem

Your agent crashed overnight. Files are missing. The config looks wrong. The logs are a wall of text. What happened? When? Why?

Without forensics tooling, post-mortem analysis is manual detective work: diffing files by hand, grepping logs, guessing at causation. Incident Replay automates the mechanics so you can focus on understanding.

What It Does

1. Capture (incident_capture.py)

  • Take point-in-time snapshots of your workspace (files, sizes, hashes, content)
  • Configurable include/exclude patterns (track what matters, ignore noise)
  • Automatic snapshot pruning (keep last N)
  • Compare any two snapshots to see exactly what changed
  • Trigger detection — automatically flag incidents based on:

- Log patterns (tracebacks, errors, fatal messages) - File changes (unexpected deletions, config modifications) - Content patterns (secrets in output, constraint violations) - Empty output files

2. Replay (incident_replay.py)

  • Build chronological timelines from snapshots, file changes, and triggers
  • Extract decision chains from agent logs and memory files
  • Heuristic root cause classification:

- Config error — misconfiguration caused the failure - Data corruption — input data was malformed or missing - Drift — gradual workspace state degradation - External failure — API/network/filesystem dependency failed - Logic error — bug in agent logic or prompt - Resource exhaustion — ran out of memory, disk, tokens, or time

  • Remediation suggestions tailored to each root cause category
  • Incident database with persistent storage and pattern tracking

3. Report (incident_report.py)

  • Full incident reports with timeline, changes, triggers, and remediation
  • Summary reports across all incidents with severity and root cause breakdowns
  • Decision chain visualisation (what the agent decided and why)
  • Export markdown or JSON

Quick Start

# 1. Configure
cp config_example.json incident_config.json
# Edit workspace root, triggers, log patterns

# 2. Take a baseline snapshot
python3 incident_capture.py --config incident_config.json --snapshot --label baseline

# 3. ... agent does work, something breaks ...

# 4. Take a post-incident snapshot
python3 incident_capture.py --config incident_config.json --snapshot --label post-incident

# 5. See what changed
python3 incident_capture.py --config incident_config.json \
  --diff incident_data/snapshots/SNAP1.json incident_data/snapshots/SNAP2.json

# 6. Check triggers
python3 incident_capture.py --config incident_config.json \
  --triggers incident_data/snapshots/SNAP1.json incident_data/snapshots/SNAP2.json

# 7. Full analysis — creates an incident with timeline, root cause, remediation
python3 incident_replay.py --config incident_config.json \
  --analyze incident_data/snapshots/SNAP1.json incident_data/snapshots/SNAP2.json \
  --title "Agent crashed during deployment"

# 8. Generate incident report
python3 incident_report.py --config incident_config.json --incident INC-0001

# 9. View all incidents and patterns
python3 incident_replay.py --config incident_config.json --incidents
python3 incident_replay.py --config incident_config.json --patterns
python3 incident_report.py --config incident_config.json --summary

Programmatic Usage

from incident_capture import Capturer, Snapshot, _load_config
from incident_replay import Analyzer

cfg = _load_config("incident_config.json")
cap = Capturer(cfg)
analyzer = Analyzer(cfg)

# Take snapshots
before = cap.take_snapshot(label="before")
# ... agent runs ...
after = cap.take_snapshot(label="after")

# Analyse
changes = cap.diff_snapshots(before, after)
triggers = cap.check_triggers(before, after)
decisions = analyzer.extract_decisions(after)
timeline = analyzer.build_timeline(
    [before, after],
    triggers=[t.to_dict() for t in triggers],
    changes=changes,
)

# Create incident
incident = analyzer.create_incident(
    title="Agent failed during task X",
    timeline=timeline,
    triggers=[t.to_dict() for t in triggers],
    file_changes=changes,
    decisions=decisions,
)
print(f"Created {incident.id}: {incident.root_cause}")

Use Cases

  • Overnight failure analysis: Agent ran unattended and broke — what happened?
  • Config change impact: Track exactly what changed after a config update
  • Drift detection: Compare weekly snapshots to catch gradual degradation
  • Secret leak detection: Catch credentials or sensitive data in agent outputs
  • Regression forensics: Agent used to work, now it doesn't — find the divergence point
  • Team incident management: Track incidents over time, find recurring patterns

What's Included

FilePurpose
incident_capture.pyState snapshot and change detection
incident_replay.pyTimeline reconstruction, analysis, incident management
incident_report.pyReport generation (markdown, JSON)
config_example.jsonFull configuration template
LIMITATIONS.mdWhat this tool doesn't do
LICENSEMIT License

Requirements

  • Python 3.8+
  • No external dependencies (stdlib only)
  • Works on any OS
  • Platform-agnostic (works with any file-based AI agent workspace)

Configuration

See config_example.json for the complete reference. Key areas:

  • WORKSPACE_ROOT — Directory to monitor
  • INCLUDE/EXCLUDE_PATTERNS — What files to capture
  • TRIGGERS — Conditions that flag incidents (log patterns, file changes, content scans)
  • ROOT_CAUSE_CATEGORIES — Classification categories with descriptions and remediation
  • DECISION_MARKERS — Regex patterns to extract agent decisions from logs
  • LOG_FILES — Which files to scan for decision chains

quality-verified

License

MIT — See LICENSE file.


⚠️ Security Note — Config File

Configuration is loaded from a JSON file. This is safe to share — no code execution.

  • Config path is validated for existence and size (1MB cap) before loading
  • Must be a .json file — raises ValueError if given a non-JSON path
  • Keep your config under version control; it defines what triggers are watched and what's protected

⚠️ Disclaimer

This software is provided "AS IS", without warranty of any kind, express or implied.

USE AT YOUR OWN RISK.

  • The author(s) are NOT liable for any damages, losses, or consequences arising from

the use or misuse of this software — including but not limited to financial loss, data loss, security breaches, business interruption, or any indirect/consequential damages.

  • This software does NOT constitute financial, legal, trading, or professional advice.
  • Users are solely responsible for evaluating whether this software is suitable for

their use case, environment, and risk tolerance.

  • No guarantee is made regarding accuracy, reliability, completeness, or fitness

for any particular purpose.

  • The author(s) are not responsible for how third parties use, modify, or distribute

this software after purchase.

By downloading, installing, or using this software, you acknowledge that you have read this disclaimer and agree to use the software entirely at your own risk.

DATA DISCLAIMER: This software processes and stores data locally on your system. The author(s) are not responsible for data loss, corruption, or unauthorized access resulting from software bugs, system failures, or user error. Always maintain independent backups of important data. This software does not transmit data externally unless explicitly configured by the user.


Support & Links

🐛 Bug ReportsTheShadowyRose@proton.me
Ko-fiko-fi.com/theshadowrose
🛒 Gumroadshadowyrose.gumroad.com
🐦 Twitter@TheShadowyRose
🐙 GitHubgithub.com/TheShadowRose
🧠 PromptBasepromptbase.com/profile/shadowrose

*Built with OpenClaw — thank you for making this possible.*


🛠️ Need something custom? Custom OpenClaw agents & skills starting at $500. If you can describe it, I can build it. → Hire me on Fiverr

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

73.28%
按下载量换算2,652

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills