一键导入
alerting
Use when creating structured incident alerts from SysGuard findings, health reports, log analysis, remediation failures, or operational events.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Use when creating structured incident alerts from SysGuard findings, health reports, log analysis, remediation failures, or operational events.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Use when checking database connectivity, running read-only diagnostic SQL, validating DSNs, or collecting small database health evidence through SysGuard.
Use when reading, statting, listing, or tailing local files for SysGuard diagnostics without modifying filesystem contents.
Use when checking host health, service health, CPU, memory, disk, network status, or determining whether SysGuard should treat a system as unhealthy.
Use when analyzing operational logs, filtering errors or warnings, summarizing incidents from log files, or finding relevant lines in SysGuard-managed logs.
Use when collecting structured CPU, memory, disk, network, service, or health-score metrics from SysGuard for dashboards or reports.
Use when diagnosing DNS, TCP connectivity, ping reachability, network interfaces, service ports, or network-related SysGuard incidents.
| name | alerting |
| description | Use when creating structured incident alerts from SysGuard findings, health reports, log analysis, remediation failures, or operational events. |
Use this skill to turn operational findings into structured alerts that downstream notification or audit systems can consume.
The Go implementation is registered by RegisterCoreSkills and invoked as "alerting":
registry.Execute(ctx, "alerting", &skills.SkillInput{Params: map[string]interface{}{
"severity": "critical",
"title": "Service down",
"message": "nginx is inactive",
"source": "sysguard",
}})
The result is an Alert with ID, severity, title, message, source, metadata, and timestamp.
critical for down services, unreachable networks, or failed remediation.warning for degraded CPU, memory, disk, or suspicious logs.notification when the alert needs to leave the process.Alerts should describe facts observed by SysGuard. Do not invent root causes when the evidence only supports symptoms.