luckystrker

Agentic Usage Analysis — Security skill for Claude Code

Security community

Skill + toolkit: audit how AI coding agents (Codex, Claude Code, OpenCode, OMP, ZCode.

How to install Agentic Usage Analysis

This entry records only its repository, not the path inside it, so there is no exact command to give. Open luckystrker/agentic-usage-analysis and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Agentic Usage Analysis does

Skill + toolkit: audit how AI coding agents (Codex, Claude Code, OpenCode, OMP, ZCode, ...) worked on a repo — from their local session logs. Stats, digests, escaped-defects cross-check, report.md + report.html dashboard.

Alternatives in Security

  • ThinkWatch — Self-hosted AI API and MCP gateway for organizations: SSO and RBAC, per-user identity for MCP tool calls, PII 817 ★
  • OpenTag — Open-source, channel-native agent gateway for Slack 499 ★
  • Memory Self Review — Mine recent agent history (claude-mem + usage stats) for recurring failures and repeated patterns, audit MEMOR 297 ★

README

agentic-usage-analysis

[![npm version](https://img.shields.io/npm/v/agentic-usage-analysis?color=cb3837&label=npm)](https://www.npmjs.com/package/agentic-usage-analysis) [![License: MIT](https://img.shields.io/badge/License-MIT-informational)](LICENSE) [![Installer](https://img.shields.io/badge/installer-Node_18%2B-339933?logo=nodedotjs&logoColor=white)](https://nodejs.org) [![Scripts](https://img.shields.io/badge/scripts-Python_3.10%2B-3776AB?logo=python&logoColor=white)](https://www.python.org) [![Platform](https://img.shields.io/badge/platform-Windows%20%7C%20Linux%20%7C%20macOS-lightgrey)](#quick-start)

A skill (and standalone toolkit) that reconstructs **how AI coding agents actually worked on a repository** — from their local session logs. Built and battle-tested on a real month-long, four-tool game project.

npx agentic-usage-analysis

_Installs the skill into your agent's skills dir (ZCode, Claude Code, OpenCode, Codex, Cursor — auto-detected). Works standalone too._

What it does

Reconstructs per-tool session history and turns it into an evidence-backed audit:

  • 8 tools supported: Codex CLI, Claude Code, OpenCode, OMP, ZCode have dedicated extractors; Qoder, Antigravity, Pi and other unknown layouts go through a best-effort generic extractor + storage inspection helpers.
  • Quantitative: sessions per tool per day, tool-call profiles, error counts, retry loops (≥2 identical commands), token/cost totals, user-request classification (RU+EN defaults, per-project overrides).
  • Qualitative: per-session digests for reading, subagent prompts for deep analysis, an escaped-defects cross-check against the repo's own validation history and git log.
  • Two final reports: report.md (full analysis) and report.html — a standalone dashboard (KPIs, era timeline, charts) built by scripts/make_report_page.py, no JS dependencies.
  • Correctness care that matters: codex resumed threads are merged by real session_id (not filenames), n