/forensics
Post-mortem investigation for failed THRUNT workflows — analyzes git history, artifacts, and state to diagnose what went wrong
$ npx -y skills add backbay-labs/thrunt-god --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/forensics
Context preview
What this command does when you run it.
Post-mortem investigation for failed THRUNT workflows — analyzes git history, artifacts, and state to diagnose what went wrong
Command definition
forensics.mdtype: prompt
name: thrunt:forensics
description: Post-mortem investigation for failed THRUNT workflows — analyzes git history, artifacts, and state to diagnose what went wrong
argument-hint: "[problem description]"
allowed-tools:
- Read
- Write
- Bash
- Grep
- Glob
<objective> Investigate what went wrong during a THRUNT workflow execution. Analyzes git history, `.planning/` artifacts, and file system state to detect anomalies and generate a structured diagnostic report.
Purpose: Diagnose failed or stuck workflows so the user can understand root cause and take corrective action. Output: Forensic report saved to `.planning/forensics/`, presented inline, with optional issue creation. </objective>
<execution_context> @~/.claude/thrunt-god/workflows/forensics.md </execution_context>
<context> **Data sources:**
- `git log` (recent commits, patterns, time gaps)
- `git status` / `git diff` (uncommitted work, conflicts)
- `.planning/STATE.md` (current position, session history)
- `.planning/HUNTMAP.md` (phase scope and progress)
- `.planning/phases/*/` (PLAN.md, SUMMARY.md, FINDINGS.md, CONTEXT.md)
- `.planning/reports/SESSION_REPORT.md` (last session outcomes)
**User input:**
- Problem description: $ARGUMENTS (optional — will ask if not provided)
</context>
<process> Read and execute the forensics workflow from @~/.claude/thrunt-god/workflows/forensics.md end-to-end. </process>
<success_criteria>
- Evidence gathered from all available data sources
- At least 4 anomaly types checked (stuck loop, missing artifacts, abandoned work, crash/interruption)
- Structured forensic report written to `.planning/forensics/report-{timestamp}.md`
- Report presented inline with findings, anomalies, and recommendations
- Interactive investigation offered for deeper analysis
- GitHub issue creation offered if actionable findings exist
</success_criteria>
<critical_rules>
- **Read-only investigation:** Do not modify project source files during forensics. Only write the forensic report and update STATE.md session tracking.
- **Redact sensitive data:** Strip absolute paths, API keys, tokens from reports and issues.
- **Ground findings in evidence:** Every anomaly must cite specific commits, files, or state data.
- **No speculation without evidence:** If data is insufficient, say so — do not fabricate root causes.
</critical_rules>
Read more
type: prompt name: thrunt:forensics description: Post-mortem investigation for failed THRUNT workflows — analyzes git history, artifacts, and state to diagnose what went wrong argument-hint: "[problem description]" allowed-tools: - Read - Write - Bash - Grep - Glob
<objective> Investigate what went wrong during a THRUNT workflow execution. Analyzes git history, `.planning/` artifacts, and file system state to detect anomalies and generate a structured diagnostic report.
Purpose: Diagnose failed or stuck workflows so the user can understand root cause and take corrective action. Output: Forensic report saved to `.planning/forensics/`, presented inline, with optional issue creation. </objective>
<execution_context> @~/.claude/thrunt-god/workflows/forensics.md </execution_context>
<context> **Data sources:**
- `git log` (recent commits, patterns, time gaps)
- `git status` / `git diff` (uncommitted work, conflicts)
- `.planning/STATE.md` (current position, session history)
- `.planning/HUNTMAP.md` (phase scope and progress)
- `.planning/phases/*/` (PLAN.md, SUMMARY.md, FINDINGS.md, CONTEXT.md)
- `.planning/reports/SESSION_REPORT.md` (last session outcomes)
**User input:**
- Problem description: $ARGUMENTS (optional — will ask if not provided)
</context>
<process> Read and execute the forensics workflow from @~/.claude/thrunt-god/workflows/forensics.md end-to-end. </process>
<success_criteria>
- Evidence gathered from all available data sources
- At least 4 anomaly types checked (stuck loop, missing artifacts, abandoned work, crash/interruption)
- Structured forensic report written to `.planning/forensics/report-{timestamp}.md`
- Report presented inline with findings, anomalies, and recommendations
- Interactive investigation offered for deeper analysis
- GitHub issue creation offered if actionable findings exist
</success_criteria>
<critical_rules>
- **Read-only investigation:** Do not modify project source files during forensics. Only write the forensic report and update STATE.md session tracking.
- **Redact sensitive data:** Strip absolute paths, API keys, tokens from reports and issues.
- **Ground findings in evidence:** Every anomaly must cite specific commits, files, or state data.
- **No speculation without evidence:** If data is insufficient, say so — do not fabricate root causes.
</critical_rules>
Threat hunting command system for agentic IDEs
Repo: backbay-labs/thrunt-god
Other commands on thrunt-god.
- /help
Show available THRUNT threat hunting commands and artifact layout
Open command - /map-environment
Map available telemetry, query surfaces, tenants, retention windows, and investigation blind spots
Open command - /new-case
Initialize a threat hunting case from a signal, detection, intel lead, or analyst suspicion
Open command - /new-program
Initialize a threat hunting program with an environment map, tool inventory, huntmap, and empty execution directories
Open command - /plan
Create phase plans for a threat hunt with exact telemetry tasks, receipts, and query outputs
Open command - /publish
Publish a hunt as a case report, escalation, detection promotion, or leadership summary
Open command

