datadog-labs agent-skills
COMMUNITYLABSCO SUMMARY
The skills sort into families rather than standing alone. Five walk Linux APM onboarding start to finish — agent-install, enable-ssi, verify-ssi, troubleshoot-ssi, and onboarding-summary. Four cover the Browser SDK: dd-browser-sdk for general RUM, Logs, and Session Replay setup, plus one dedicated upgrade guide apiece for the v5, v6, and v7 major version jumps. Five answer Audit Trail questions — security investigations, API key compromise, cost-spike root cause, SOC 2 and PCI compliance evidence, and Bits AI activity auditing. Six form an Agent Observability pipeline of their own, from session classification through root-cause analysis to evaluator generation and experiment comparison. The rest are one skill apiece: dd-monitors, dd-logs, dd-apm, dd-docs, service-remapping, datadog-app for scaffolding a Datadog App, and the unblock-pr / triage-flaky-test pair for CI.
This is for teams already running Datadog who want an agent to drive onboarding, audits, or SDK upgrades from a conversation instead of the docs or the UI. Almost none of it does anything for someone without a Datadog org and the credentials to act inside it.
READ THE FULL ANALYSIS
Twenty-five need a Datadog account key up front — an API key and application key pair set as DD_API_KEY / DD_APP_KEY / DD_SITE for direct REST calls, or pup auth login for the CLI path. Three more (k9-ownership-byod-setup and the v6 and v7 browser-SDK upgrade guides) are unverified in our check. Only dd-browser-sdk and the v5 upgrade skill are ready with nothing to configure, and dd-docs is the one exception that needs no account at all — it looks up Datadog's own public documentation site.
The observability family layers an MCP server on top of the account key. All six agent-observability skills additionally require a separate datadog-llmo-mcp MCP server before they produce anything beyond a code template, and agent-observability-eval-pipeline is pure orchestration over the other five rather than doing its own analysis.
Our index carries 32 of the 39 skills the repository has shipped. The README's own table groups them into ten named families; seven skill directories that exist in the repository no longer pass our liveness check and are excluded from the 32 counted here.
None of this reaches past Datadog itself. If you don't already have a Datadog org, nothing in the package is useful as written, dd-docs included — even the one skill with no account requirement is a lookup tool for Datadog's own docs, not general observability advice.
WHAT'S INSIDE
31 showing · 31 totalNothing else to set up — install it and go.
agent-install
Sets up Datadog's monitoring software on Linux servers you reach over SSH, so the applications running on them start reporting how they are performing without anyone touching their code.
agent-observability-eval-bootstrap
Works out what a good answer means for your particular AI app by reading a sample of the real conversations it has had, then writes automatic checks for it — created switched off until you turn them on.
agent-observability-eval-pipeline
Six steps, in order and with a pause between each: see what your AI app actually did in production, work out why it failed, build the checks, collect the test cases, run the test, read the results.
agent-observability-experiment-analyzer
You ran the experiment; this is the part that tells you what the numbers mean — what changed, where it broke, and what to try next — with a link into Datadog behind each point.
agent-observability-session-classify
Did the person actually get what they came for? This reads back a conversation with your AI app and answers yes or no, with the failure named when the answer is no.
agent-observability-trace-rca
When an AI app gives bad answers, the thing that actually broke is usually several steps back from where you noticed; this walks the failure back through everything the app did and names the real cause.
agent-skills
The front door to Datadog's other skills: what each one covers — logs, alerts, performance tracing, cloud accounts, CI checks — and the command that installs the ones you want.
datadog-app
Datadog lets you build your own page that lives inside its interface; this covers making one — from the first empty project through to the published app — and points at the right reference for whichever step you are on.
dd-apm
Datadog's request tracing, start to finish: getting it running on Kubernetes or a plain Linux server, fixing a service that shows up under the wrong name, and digging out the slow and failing requests.
dd-audit
Datadog keeps a record of every change anyone makes to it, and this is the way into that record — which investigation fits your question, how to search it by hand, and how far back it actually goes.
dd-audit-ai-activity
If your team lets Datadog's AI assistant act on the account, this shows exactly what it did — who asked it, what it touched, what it deleted — and flags the ones worth a second look.
dd-audit-compliance-report
An auditor asks for proof that only the right people can change things — this pulls that proof out of Datadog's own records and files each piece under the SOC 2 or PCI clause it answers.
dd-audit-cost-spike-investigation
An investigation into a sudden jump in a Datadog bill: what the extra usage was, when it started, and whose change set it off.
dd-audit-key-compromise
One of your Datadog access keys may have leaked, and the first question is what it has already been used for — this answers that from the last ninety days of records.
dd-audit-security-investigation
Somebody deleted a dashboard, or signed in from a country you do not recognise, and you need to know who and when — this answers that kind of question from Datadog's own records.
dd-browser-sdk
Datadog's browser code drops old settings every time it goes up a major version; this works out which of the ones you use are gone and sends you to the guide for that particular jump.
dd-docs
Looks things up in Datadog's own documentation rather than guessing or searching the open web — there is a machine-readable index of every page, and this uses it.
dd-logs
Searching your logs, plus the part that actually costs money: deciding which lines are worth keeping, which get thrown away before you are billed for them, and where the rest get stored.
dd-monitors
Setting up the alerts that wake somebody when things break — and, just as much, keeping them from going off so often that people stop reading them.
dd-pup
Datadog's command-line tool, and what to type into it: one signed-in command for logs, alerts, dashboards, incidents, on-call rotas and the rest, without opening the website.
enable-ssi
Switches on automatic tracing for everything running in a Kubernetes cluster: the applications start reporting how they are performing the next time their pods restart, and nobody edits any code.
k9-ownership-byod-setup
When Datadog flags a security problem on a cloud resource it has to guess who owns it; this builds the spreadsheet that tells it the answer, from your own tags and naming rules.
onboarding-summary
The last step after setting tracing up on a Linux server: rather than assuming it worked, it goes and checks every link in the chain, right through to traces actually landing in Datadog.
service-remapping
Datadog names some of your services for you, and it often gets them wrong; this rewrites the name as the data arrives, so nothing has to be re-instrumented or redeployed.
triage-flaky-test
A test that passes sometimes and fails sometimes for no reason anyone can see — this digs up its history, works out what kind of flakiness it is, and says whether to fix it, silence it, or hand it to its owners.
troubleshoot-ssi
Everything is installed and nothing is arriving: this works through the reasons a Linux service can look properly set up and still send no data, starting from Datadog's own side before anyone logs into the server.
unblock-pr
Sorts out why the automated checks on a code change are failing: a real bug in the change, a test that fails at random, or the build machines having a bad day. Each one comes back with the action to take.
upgrade-browser-sdk-v5
A step-by-step move of Datadog's browser code from version 4 to version 5, going through every setting that was renamed and every method that was dropped along the way.
upgrade-browser-sdk-v6
Version 6 of Datadog's browser code changed enough defaults that upgrading is not just a version bump; this goes through an app and finds what actually has to change.
upgrade-browser-sdk-v7
Moving an app from version 6 to version 7 of Datadog's browser code, which now arrives as a modern JavaScript module and needs the page set up differently to load it.
verify-ssi
After switching automatic tracing on, this is the part that proves it took — because an install that looks healthy and data that actually arrives are two different things.
HOW TO GET IT
npx skills add datadog-labs/agent-skillsnpx skills add datadog-labs/agent-skills --skill <name> --full-depthPick the skill name from the Skills tab — each entry there installs independently.