Audit Log Investigation with Claude Code: SKILL.md Template
A production playbook for audit log investigation in cross-industry operations using Claude Code: skill.md template, run-scoped inputs, logs, typed results, and artifacts.
Audience: Security operations teams
The problem
Security operations teams need audit log investigation to run repeatedly against audit logs, entity metadata, and escalation policy. In cross-industry operations, the pain is not one good answer; it is repeatability, auditability, exception handling, and evidence that survives handoff.
Implementation path
Put the operating procedure in SKILL.md, keep examples beside the skill, attach audit logs, entity metadata, and escalation policy per run, and let Argo turn the folder into a repeatable Claude Code execution.
Tradeoffs and failure modes
A skill folder is less flexible than an open chat, but it gives the product a versioned workflow that can be tested and rolled back. For audit log investigation, the practical test is whether a second run can be debugged, retried, and consumed by a product without reading the raw agent transcript.
SKILL.md starter
# SKILL.md
You run audit log investigation using Claude Code.
Read only /skill/.argo/inputs.
Write artifacts to /skill/output/artifacts.
Return argo.result.v1 with body.type = "audit_log_investigation".
Run this on Argo