When To Use
Trigger when user says: "check my system", "what's wrong", "health check", "diagnose", "audit", "why is X slow", "something feels off"
This is NOT generic data analysis. This is system self-diagnosis — examining the agent's own workspace, configuration, and operational health.
Analysis Modes
| Mode |
Scope |
When |
| Quick |
Security + critical operational |
"Quick check", default if unspecified |
| Full |
All categories, all checks |
"Full audit", "deep check" |
| Targeted |
Single category |
"Check my memory", "audit cron" |
Priority Order (Always This Sequence)
- SECURITY — Exposed secrets, leaked credentials, permission issues
- OPERATIONAL — Broken crons, dead sessions, unreachable APIs
- HYGIENE — Memory bloat, orphan files, stale entries, inefficiencies
Stop and report critical security findings immediately. Don't bury them in a long list.
Detection Strategy
Cheap first, expensive only when needed:
- File checks (free) — existence, size, age, syntax
- Local commands (cheap) — process lists, disk usage, git status
- API calls (expensive) — only when file-level signals warrant
Never hit external APIs speculatively. Validate need from local evidence first.
Findings Format
[CRITICAL|WARNING|INFO] category/subcategory: description
→ Action: specific remediation step
→ Auto-fixable: yes/no
Group by severity, not by category. User sees worst problems first.
Load Detailed Checks
| Category |
Reference |
| All check definitions by category |
checks.md |
| Remediation actions and auto-fix scripts |
remediation.md |
| Tracking analysis runs, improvement over time |
tracking.md |
1---2name: analysis3description: Run deep system health checks across workspace, config, skills, and integrations with prioritized findings and remediation.4---56## When To Use78Trigger when user says: "check my system", "what's wrong", "health check", "diagnose", "audit", "why is X slow", "something feels off"910This is NOT generic data analysis. This is **system self-diagnosis** — examining the agent's own workspace, configuration, and operational health.1112---1314## Analysis Modes1516| Mode | Scope | When |17|------|-------|------|18| **Quick** | Security + critical operational | "Quick check", default if unspecified |19| **Full** | All categories, all checks | "Full audit", "deep check" |20| **Targeted** | Single category | "Check my memory", "audit cron" |2122---2324## Priority Order (Always This Sequence)25261. **SECURITY** — Exposed secrets, leaked credentials, permission issues272. **OPERATIONAL** — Broken crons, dead sessions, unreachable APIs283. **HYGIENE** — Memory bloat, orphan files, stale entries, inefficiencies2930Stop and report critical security findings immediately. Don't bury them in a long list.3132---3334## Detection Strategy3536**Cheap first, expensive only when needed:**371. File checks (free) — existence, size, age, syntax382. Local commands (cheap) — process lists, disk usage, git status393. API calls (expensive) — only when file-level signals warrant4041Never hit external APIs speculatively. Validate need from local evidence first.4243---4445## Findings Format4647```48[CRITICAL|WARNING|INFO] category/subcategory: description49 → Action: specific remediation step50 → Auto-fixable: yes/no51```5253Group by severity, not by category. User sees worst problems first.5455---5657## Load Detailed Checks5859| Category | Reference |60|----------|-----------|61| All check definitions by category | `checks.md` |62| Remediation actions and auto-fix scripts | `remediation.md` |63| Tracking analysis runs, improvement over time | `tracking.md` |