Install
$ agentstack add skill-byerlikaya-claude-starter-kit-observability ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Observability
Goal: to be able to answer "what happened, where, why" during a production incident by looking at the logs. It is stack-agnostic; when you need a framework-specific library/format, do a web search.
Three signals
- Log — event record (structured/JSON, leveled).
- Metric — numeric time series (request count, latency, error rate, resource usage).
- Trace — a request's journey across services (spans + correlation id).
Checklist
- [ ] Logs are structured (JSON/key-value), not string interpolation
- [ ] Every log line carries a correlation id (request/trace id)
- [ ] Levels are correct: the DEBUG/INFO/WARN/ERROR distinction is meaningful
- [ ] No PII/secret is logged (password, token, card, national/ID number, email body)
- [ ] Error logs carry context (input summary, user/resource id — not PII); the stack trace does not leak to the user
- [ ] Critical business metric + infrastructure metric are emitted (where applicable)
- [ ] The correlation id is propagated across service-to-service calls (header/propagation)
How
- Structured logger — set up/use one whose output is machine-readable (JSON). Search for the library the framework recommends.
- Correlation id: generate it at the entry point (HTTP middleware / message consumer) or take it from the incoming
X-Request-Id/trace header; put it in the log context; propagate it to downstream calls. - Level discipline: INFO = business event, WARN = expected-but-noteworthy, ERROR = needs intervention. DEBUG is off/sampled in production.
- Context fields:
event,correlation_id,user_id(not PII, an opaque id),duration_ms,outcome. Do not embed them in free text. - Metrics: at minimum RED (Rate, Errors, Duration) or USE; plus business-critical counters. Search for the framework's metrics library.
- Trace (in a distributed system): start/end spans, bind the correlation id to the trace id.
PII / secret leakage (critical)
Never to the log: password, token, API key, card number, national/ID number, full email/phone body, raw request body.
- Mask:
user@***, card**** 1234, tokensk-p…789. - When needed, log an opaque id (hash/uuid), not the raw value.
- This axis overlaps with
security-scan(sensitive data in logs) andprivacy-compliance(KVKK/GDPR) — if personal data is involved, trigger those too.
Invariant rules
- Structured > free text — greppable, parseable.
- Correlation id on every line — without it, a distributed error is untraceable.
- No PII/secret is logged — mask it or use an opaque id.
- Do not make noise — every line must answer a question; do not add meaningless spam logs.
- Match the existing format — if the repo has a logger, follow its pattern; do not impose a new one.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: byerlikaya
- Source: byerlikaya/claude-starter-kit
- License: MIT
- Homepage: https://www.npmjs.com/package/@byerlikaya/claude-starter-kit
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.