When To Use
Trigger when user says: "check my system", "what's wrong", "health check", "diagnose", "audit", "why is X slow", "something feels off"
This is NOT generic data analysis. This is system self-diagnosis — examining the agent's own workspace, configuration, and operational health.
Analysis Modes
| Mode |
Scope |
When |
| Quick |
Security + critical operational |
"Quick check", default if unspecified |
| Full |
All categories, all checks |
"Full audit", "deep check" |
| Targeted |
Single category |
"Check my memory", "audit cron" |
Priority Order (Always This Sequence)
- SECURITY — Exposed secrets, leaked credentials, permission issues
- OPERATIONAL — Broken crons, dead sessions, unreachable APIs
- HYGIENE — Memory bloat, orphan files, stale entries, inefficiencies
Stop and report critical security findings immediately. Don't bury them in a long list.
Detection Strategy
Cheap first, expensive only when needed:
- File checks (free) — existence, size, age, syntax
- Local commands (cheap) — process lists, disk usage, git status
- API calls (expensive) — only when file-level signals warrant
Never hit external APIs speculatively. Validate need from local evidence first.
Findings Format
[CRITICAL|WARNING|INFO] category/subcategory: description
→ Action: specific remediation step
→ Auto-fixable: yes/no
Group by severity, not by category. User sees worst problems first.
Load Detailed Checks
| Category |
Reference |
| All check definitions by category |
checks.md |
| Remediation actions and auto-fix scripts |
remediation.md |
| Tracking analysis runs, improvement over time |
tracking.md |
1---2name: analysis3description: Run deep system health checks across workspace, config, skills, and integrations with prioritized findings and remediation.4---5
6## When To Use
7
8Trigger when user says: "check my system", "what's wrong", "health check", "diagnose", "audit", "why is X slow", "something feels off"
9
10This is NOT generic data analysis. This is **system self-diagnosis** — examining the agent's own workspace, configuration, and operational health.
11
12---
13
14## Analysis Modes
15
16| Mode | Scope | When |
17|------|-------|------|
18| **Quick** | Security + critical operational | "Quick check", default if unspecified |
19| **Full** | All categories, all checks | "Full audit", "deep check" |
20| **Targeted** | Single category | "Check my memory", "audit cron" |
21
22---
23
24## Priority Order (Always This Sequence)
25
261. **SECURITY** — Exposed secrets, leaked credentials, permission issues
272. **OPERATIONAL** — Broken crons, dead sessions, unreachable APIs
283. **HYGIENE** — Memory bloat, orphan files, stale entries, inefficiencies
29
30Stop and report critical security findings immediately. Don't bury them in a long list.
31
32---
33
34## Detection Strategy
35
36**Cheap first, expensive only when needed:**
371. File checks (free) — existence, size, age, syntax
382. Local commands (cheap) — process lists, disk usage, git status
393. API calls (expensive) — only when file-level signals warrant
40
41Never hit external APIs speculatively. Validate need from local evidence first.
42
43---
44
45## Findings Format
46
47```
48[CRITICAL|WARNING|INFO] category/subcategory: description
49 → Action: specific remediation step
50 → Auto-fixable: yes/no
51```
52
53Group by severity, not by category. User sees worst problems first.
54
55---
56
57## Load Detailed Checks
58
59| Category | Reference |
60|----------|-----------|
61| All check definitions by category | `checks.md` |
62| Remediation actions and auto-fix scripts | `remediation.md` |
63| Tracking analysis runs, improvement over time | `tracking.md` |