Find the skill for your next task.

Browse reusable Agent Skills, each with a clear purpose and practical guidance.

bug-reproduce

Use when the user mentions a bug number or asks to reproduce, investigate, or debug anything in Kibana Security Solution — even just "look into #NNN", "can you reproduce this", or "something's wrong with X".

21.18k repo starsObserved in 1 repos
Testing & Quality

bug-validator

Validates whether open Security Solution GitHub bugs are still valid through static code analysis, git history, and PR cross-referencing — without running the application. Use when the user shares a GitHub issue URL, an issue list URL, an issue number (#NNN), or asks to triage, validate, or check if a Security Solution bug is still reproducible.

21.18k repo starsObserved in 1 repos
Testing & Quality

elasticsearch-onboarding

Primary guided playbook for Elasticsearch search in Kibana Agent Builder: intent → data → mapping → Dev Tools API snippets (SENSE), with one question at a time. Load this skill whenever the user wants to learn Elasticsearch search, get started, begin building, take first steps, onboard, follow a walkthrough or tutorial, go from zero to a working query, or get structured help setting up indices and search — including casual openers like hi, help, getting started, new to Elasticsearch, how do I build search, or I want to try search. Use when they need end-to-end onboarding, not a single narrow API answer. If they only ask what they can build with Elastic (exploration without the full playbook), prefer invoking /use-case-library first; you can still load this skill afterward for the guided build.

21.18k repo starsObserved in 1 repos
Research

elasticsearch-tutorial

Topic-driven, hands-on Elasticsearch tutorial flow that runs in Kibana Dev Console. Use whenever the user says "walk me through", "give me a tutorial for", "teach me", "show me how X works", "tutorial on", or similar topical learning intent — and they are NOT asking you to build their real, specific use case. Topics are open-ended: any Elasticsearch / Kibana search concept the user names (e.g. mappings, analyzers, bool queries, semantic_text, kNN, RRF, aggregations, ingest pipelines, reranking, data streams, ES|QL). Tutorials use sample data on isolated resources, present every step as a SENSE snippet to run in Dev Tools, and end with cleanup plus pointers to docs and the onboarding / pattern skills.

21.18k repo starsObserved in 1 repos
Research

evals-write-spec

Write LLM evaluation spec files with datasets, tasks, and evaluators using the @kbn/evals Playwright fixture. Use when authoring new eval specs, adding datasets or evaluators, or debugging evaluation test failures.

21.18k repo starsObserved in 1 repos
Agent Building

flaky-test-investigator

Investigate Scout and FTR flaky test failures in Kibana. Use when triaging a failed-test issue, a Buildkite-reported failure, a test path that has been failing intermittently, or any time the user asks to look at a flaky test, deflake a test, or stabilize a test.

21.18k repo starsObserved in 1 repos
Testing & Quality

fleet-flaky-test-doctor

Fleet-specific. Analyzes failing, flaky, or skipped Fleet tests to determine root cause and recommend the right action. Three modes: (1) triage a single GitHub issue, (2) audit the full Team:Fleet failed-test backlog, (3) fix a cluster of related issues together. Use when: (1) a user shares a failing or skipped Fleet test, (2) asked to triage or fix a flaky test, (3) asked to audit or clear the Fleet failed-test backlog, (4) asked to find the shared cause across a group of related test failures.

21.18k repo starsObserved in 1 repos
Testing & Quality

ftr-testing

Deep reference for the Kibana Functional Test Runner (FTR). Use when reading, analyzing, debugging, or reviewing FTR tests, including config anatomy, services, page objects, loadTestFile patterns, data loading, tags, CI wiring, and common FTR idioms.

21.18k repo starsObserved in 1 repos
Testing & Quality

generate-security-data

Use when an agent needs high-fidelity Elastic Security development data while working in Kibana: endpoint events, endpoint alerts, Security detection alerts, Attack Discoveries, or generated cases. This is for local engineering development, testing, and debugging only, not cloud deployments or customer-facing demos.

21.18k repo starsObserved in 1 repos
Testing & Quality

gh-create-issue

Create a new GitHub issue (feature request or bug report) by gathering an unstructured description from the user, classifying it, filling out the appropriate Kibana template, interviewing the user to improve any weak sections, and filing the issue via the GitHub CLI.

21.18k repo starsObserved in 1 repos
Productivity