AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Agent Session Forensics

skill-yeaight7-agent-powerups-agent-session-forensics · by yeaight7

Use when diagnosing agent session history, interrupted tool loops, missing tool results, timing bottlenecks, or subagent trace correlation.

No reviews yet
0 installs
36 views
0.0% view→install

Install

$ agentstack add skill-yeaight7-agent-powerups-agent-session-forensics

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-yeaight7-agent-powerups-agent-session-forensics)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Agent Session Forensics? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Agent Session Forensics

When To Use

  • Agent session ended mid-tool-call or cannot resume.
  • Tool call appears in assistant turn but no corresponding result turn follows.
  • Need to correlate tool calls, tool results, and timing metadata.
  • Diagnosing slow LLM calls, duplicate user turns, or malformed results.
  • Debugging experimental MCP data-layer sessions.

Requirements / Checks

  • Locate session directory and history files before editing anything.
  • Prefer read-only inspection first.
  • Have jq or equivalent JSON tooling available.
  • Ask before modifying, truncating, or deleting any session or history file.

Workflow

  1. Inventory session files — find metadata, current history, rotated previous history, and related subagent histories.
  1. Count and list last turns:

``sh jq 'length' history.json # total messages jq '.[-10:] | .[] | {role, stop_reason}' history.json # last 10 turns jq '.[] | select(.role=="assistant") | .tool_calls[].id' history.json # tool call IDs jq '.[] | select(.role=="user") | .tool_results[]?.tool_call_id' history.json # results ``

  1. Correlate tool call IDs — every tool_call in an assistant turn must have a matching tool_result in the immediately following user turn. Find the first gap.
  1. Check timing for slow calls:

``sh jq '.[] | select(.timing) | {role, duration_ms: .timing.duration_ms}' history.json ``

  1. Identify failure pattern — see table below.
  1. Repair (if approved) — write a backup first (cp history.json history.json.bak), then make the smallest possible fix at the last valid correlation boundary.

Common Failure Patterns

| Symptom | Likely cause | Repair | |---|---|---| | Tool call with no result turn | Session interrupted mid-tool | Truncate after last matched pair | | Two consecutive user turns | Duplicate message insertion | Remove the duplicate | | tool_result with no prior tool_call | Corrupted or manually edited history | Remove orphan result | | Empty content on assistant turn | Model returned no text + no tools | Usually safe to truncate | | Session loops without progress | Missing result causes re-prompt | Inject minimal synthetic result |

Safety Constraints

  • Do not edit session JSON without backing up the original first.
  • Treat history files as sensitive: prompts, tool arguments, credentials, and file contents may appear.
  • Do not infer user intent from stale history when current user instructions conflict.
  • Do not repair by deleting broad ranges — find the last valid tool-call/result correlation boundary.

Validation / Done Criteria

  • Report the names of every session file inspected.
  • Every tool-call ID is accounted for (matched or flagged as unmatched).
  • Any proposed repair names the backup path and truncation boundary.
  • No session file is mutated without explicit user approval.

References

  • references/history-diagnostics.md

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.