SkillVaultskills Browse all 500 skills

Code Quality · Version 1.6.0 · Reviewed 2026-08-02

Logging Quality Reviewer

Make a defensible decision about log event design and sensitive-data review with evidence, explicit trade-offs, and a verification plan.

4 method steps 6 documented failure modes 5 diagnostic checks 7 quality gates

Reviews application logging for event usefulness, levels, structure, cardinality, duplication, sensitive data, and incident usability.

₹99 one-time

Get this skill archive

What this skill helps you do

  • Log event design
  • Sensitive-data review
  • Noise reduction

How Logging Quality Reviewer works

You provide

Current signals, alert rules, and recent incidents

It inspects

Symptom-versus-cause coverage for log event design

It decides

A sensitive-data review design with bounded label cardinality

You verify

Each page has a documented action and a real trigger

What it checks first

Logging Quality Reviewer reviews application logging for event usefulness, levels, structure, cardinality, duplication, sensitive data, and incident usability. Use it when the work involves Log event design, Sensitive-data review, Noise reduction.

  1. Whether alerts are symptom-based (user impact) or cause-based (component state); cause-based alerts generate the most noise.
  2. Cardinality of labels, since unbounded dimensions like user ID or URL destroy a metrics backend.
  3. Whether traces propagate context across async boundaries, because a broken chain hides the slow hop.
  4. The ratio of actionable to total alerts, which predicts whether alerts will be ignored.
  5. Whether the SLO reflects a user journey or an internal component that users never observe.

Failure modes it recognizes

  • Alert fatigue where a noisy alert trains responders to ignore the channel that later carries a real outage.
  • Metric cardinality explosion from a label containing a request ID, causing ingestion cost and query failure.
  • Sampled traces dropping exactly the slow requests that needed investigation.
  • Logs without correlation IDs, making a multi-service request impossible to reconstruct.
  • A dashboard averaging latency, which hides the tail where user pain actually lives.
  • An alert on a threshold that only fires after the error budget is already exhausted.

Answers it will reject

  • Alerting on CPU utilization, which is a resource state rather than user impact and fires without consequence.
  • Adding a dashboard instead of an alert, which requires a human to be watching to be useful.
  • Logging at debug level in production to "have the data", which costs more than the incidents it solves.
  • Reporting availability as a mean, which allows a total regional outage to disappear into the average.

Decision rules it applies

  • Alert on symptoms that users feel; use cause metrics for diagnosis, not for paging.
  • Every page must have a documented action; if the action is "look at it", it is not a page.
  • Measure latency with percentiles and always include p99, since averages hide the tail.
  • Keep label cardinality bounded and known; treat an unbounded dimension as a defect.

Evidence it asks for

  • Define an SLI as a ratio of good events to valid events, with both terms explicitly specified.
  • Use tail-based sampling so slow and failed traces are retained preferentially.
  • Propagate a correlation ID from edge to database and include it in every log line.

The method inside

  1. Map the artifact, actors, boundaries, and invariants relevant to log event design.
  2. Trace concrete failure or abuse paths for sensitive-data review; do not report checklist items without a mechanism.
  3. Prioritize noise reduction findings by impact, likelihood, confidence, and cost of correction.
  4. Recommend the smallest defensible change, then define how an independent reviewer can verify it.

Deliverables

  • Log event design assessment
  • Sensitive-data review decision and action plan
  • Noise reduction verification checklist

Evidence requirements

  • Functional and quality requirements
  • Scale, latency, consistency, cost, and compliance constraints
  • Current topology and alternatives considered

Quality gates

  • Every material claim traces to supplied evidence or is labeled as a hypothesis.
  • The response follows the declared deliverable contract.
  • No execution, access, measurement, or verification is invented.
  • Secrets and personal data are redacted rather than repeated.
  • The user receives a concrete independent verification step.
  • The relevant failure modes in this domain were considered rather than only the reported symptom.
  • No listed anti-pattern was recommended as a solution.

Example task

Input

Our service emits millions of logs but incident responders still cannot follow one failed request. Review the logging strategy.

Expected output

The logs narrate internal steps without stable event names or correlation context. Define a small event taxonomy, log boundary outcomes once, attach trace and tenant identifiers, and remove duplicate exception logging...

Boundaries and compatibility

Ideal for

  • Log event design: produce a decision or artifact grounded in supplied evidence.
  • Sensitive-data review: produce a decision or artifact grounded in supplied evidence.
  • Noise reduction: produce a decision or artifact grounded in supplied evidence.

Out of scope

  • Producing a generic reference architecture without requirements
  • Hiding material trade-offs behind best-practice language

Agent compatibility

  • GitHub Copilot custom agents
  • Claude Agent Skills / SKILL.md
  • Any instruction-following chat model

Tool policy: Advisory by default. No tools are assumed. If the host provides tools, use read-only evidence gathering unless the user explicitly approves a scoped write or execution action.