Token导航 LogoToken导航TokenDH.com
研究检索只读github未标认证来源可访问许可证需确认审计通过

apple-logarchiveApple logarchive 搜索

Agent Skill

apple-logarchive 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

235

周安装

10

GitHub Stars

公开资料未说明

下载量

82
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:apple-logarchive(Apple logarchive 搜索)
来源仓库:https://github.com/benwaffle/skills
仓库路径:skills/apple-logarchive
安装命令:
npx skills add https://github.com/benwaffle/skills --skill apple-logarchive
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/benwaffle/skills --skill apple-logarchive

简介

用于查找、检索和筛选 macOS/iOS 系统日志分析相关信息。

  • 适用于 Codex、Claude、Cursor、Gemini CLI,支持 .logarchive 文件的搜索与过滤。
  • 通过 npx skills add 命令安装,需用户提供日志路径并按时间范围进行查询。
  • 安装前建议核实是否会执行系统命令或读取敏感日志,避免权限越界。
  • apple-logarchive 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Apple Log Archive Skill

You are an expert at analyzing macOS/iOS unified log archives (.logarchive bundles) using the /usr/bin/log command.

When to Use

Activate when the user wants to:

  • Search, filter, or analyze a .logarchive file
  • Find errors, faults, or crashes in system logs
  • Investigate a specific process, subsystem, or category in logs
  • Understand what happened during a time window
  • Count or summarize log activity

Step 1 — Locate the Archive

Ask the user for the path to their .logarchive if not already provided. Verify it exists:

ls <path>.logarchive/Info.plist

Step 2 — Determine Time Range

Get the first and last timestamps to understand the archive's span:

/usr/bin/log show --style ndjson --no-pager <archive> | head -1
/usr/bin/log show --style ndjson --no-pager <archive> | tail -1

Step 3 — Query the Archive

Use /usr/bin/log show with appropriate filters. Always pass --no-pager to prevent interactive mode.

Command Structure

/usr/bin/log show [options] <archive>

Key Options

OptionDescription
--predicate '<filter>'Filter using NSPredicate or shorthand syntax
--style <format>Output format: default, syslog, json, ndjson, compact
--start 'Y-M-D H:m:s'Show events from this time
--end 'Y-M-D H:m:s'Show events up to this time
`--last <N>m\h\d`Show last N minutes/hours/days
--infoInclude Info-level messages (excluded by default)
--debugInclude Debug-level messages (excluded by default)
--sourceAnnotate with source file and line number
`--process <name\pid>`Filter by process name or PID
--no-pagerAlways use this — prevents interactive less

Predicate Fields

FieldTypeDescription
process (shorthand: p)stringProcess name
processIdentifier (shorthand: pid)integerProcess ID
subsystem (shorthand: s)stringSubsystem (e.g. com.apple.xpc)
category (shorthand: c, cat)stringCategory within subsystem
composedMessage (shorthand: m)stringLog message text
sender (shorthand: l, lib)stringLibrary/sender name
logTypelog typedefault, info, debug, error, fault
type (shorthand only)event typedefault, info, debug, error, fault, loss, signpost
senderImagePathstringFull path to sender library
processImagePathstringFull path to process binary
threadIdentifier (shorthand: tid)integerThread ID
eventTypestringlogEvent, signpostEvent, stateEvent, activityCreateEvent, timesyncEvent, lossEvent

Predicate Syntax — Shorthand (preferred for simple queries)

# By process
'p=Safari'
'p=foo|bar'                    # multiple processes (OR)

# By message content
'"error loading"'              # message contains (field omitted = message)
'm:"timeout"'                  # explicit message contains
'm~/"regex pattern"'           # regex match

# By subsystem/category
's=com.apple.xpc'
'c=connection'

# By log level
'type=error'
'type>=error'                  # error + fault

# Combined
'p=CommCenter AND type>=error'
'pid=100 AND "connection"'
's=com.apple.xpc AND c=connection AND type=error'

Predicate Syntax — NSPredicate (for complex queries)

'process == "Safari"'
'composedMessage CONTAINS "error"'
'subsystem == "com.apple.xpc" AND category == "connection"'
'logType == "fault" OR logType == "error"'
'composedMessage MATCHES ".*timeout.*"'
'processImagePath ENDSWITH "CommCenter"'
'eventType == "signpostEvent"'

Comparison Operators

OperatorDescription
==, =Equality
!=, <>Inequality
CONTAINS, :Contains substring
BEGINSWITH, :^Starts with
ENDSWITHEnds with
LIKEWildcard match (? = 1 char, * = 0+ chars)
MATCHES, ~/Regex match
AND, OR, NOTLogical operators

Output Guidelines

  • Use --style ndjson when you need to parse or count results programmatically (pipe to wc -l, head, tail, etc.)
  • Use --style default (or omit) for human-readable output to show the user
  • Use --style compact for a denser human-readable view
  • Always pipe through head -N for initial exploration to avoid overwhelming output — logarchives can contain millions of entries
  • For counting: /usr/bin/log show --no-pager --style ndjson --predicate '...' <archive> | wc -l

Common Workflows

Find all errors and faults

/usr/bin/log show --no-pager --predicate 'type>=error' <archive> | head -50

Investigate a specific process

/usr/bin/log show --no-pager --predicate 'p=SpringBoard' --info --debug <archive> | head -100

Search for a keyword in messages

/usr/bin/log show --no-pager --predicate '"crash"' <archive> | head -50

Logs from a specific subsystem during a time window

/usr/bin/log show --no-pager --start '2026-03-01 10:00:00' --end '2026-03-01 10:05:00' --predicate 's=com.apple.xpc' <archive>

Count events by type

/usr/bin/log show --no-pager --style ndjson --predicate 'type=error' <archive> | wc -l
/usr/bin/log show --no-pager --style ndjson --predicate 'type=fault' <archive> | wc -l

List unique processes in the archive

/usr/bin/log show --no-pager --style ndjson <archive> | head -1000 | python3 -c "import sys,json; procs=set(); [procs.add(json.loads(l).get('processImagePath','')) for l in sys.stdin]; print('\n'.join(sorted(procs)))"

Important Notes

  • Always use --no-pager — interactive pagers hang in non-interactive shells
  • Always pipe through head on first query — archives can be enormous
  • By default only Default and Error/Fault level messages are shown; pass --info and/or --debug to include lower-severity messages
  • Time format for --start/--end: 'Y-M-D H:m:s' or 'Y-M-D'
  • Use shorthand predicates for simple queries; use NSPredicate syntax when you need MATCHES, ENDSWITH, LIKE, or complex nesting
  • The eventMessage field in JSON output corresponds to composedMessage in predicates

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

32.69%
按下载量换算27

Claude

30.58%
按下载量换算25

Cursor

19.98%
按下载量换算16

Gemini CLI

8.59%
按下载量换算7

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

只读

该 Skill 主要提供规则、说明或参考内容,本身偏只读;真正读写文件、联网或执行命令仍取决于宿主 Agent 的任务。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills