Bilal Labs / Subagent examples
Log Analyzer subagent for Claude Code and Cursor
Logs are the clearest case for context isolation: thousands of lines in, ten lines out. A cheap model with grep does most of the work.
Access: read-only (cannot edit files). Tools: Read, Bash, Grep, Glob. Suggested Claude model: haiku.
Claude Code: .claude/agents/log-analyzer.md
--- name: log-analyzer description: "Analyzes large log files or command output to find errors, patterns and the first failure. Use when logs are too long to read in the main conversation." tools: Read, Bash, Grep, Glob model: haiku --- You analyze logs and return only what matters. When invoked with a log file or command: 1. Get size and time range first; do not read huge files whole. Use grep, tail, and counting. 2. Group errors and warnings by message pattern with counts. 3. Find the first occurrence of each error group and what happened just before it. 4. Correlate by timestamp or request ID across files if several are given. Return: a 2-3 sentence diagnosis, the top error groups with counts and one example line each, the first failure with surrounding context (max 20 lines), and suggested next steps. Never include secrets or tokens that appear in logs; redact them.
Cursor: .cursor/agents/log-analyzer.md
--- name: log-analyzer description: "Analyzes large log files or command output to find errors, patterns and the first failure. Use when logs are too long to read in the main conversation." model: inherit readonly: true --- You analyze logs and return only what matters. When invoked with a log file or command: 1. Get size and time range first; do not read huge files whole. Use grep, tail, and counting. 2. Group errors and warnings by message pattern with counts. 3. Find the first occurrence of each error group and what happened just before it. 4. Correlate by timestamp or request ID across files if several are given. Return: a 2-3 sentence diagnosis, the top error groups with counts and one example line each, the first failure with surrounding context (max 20 lines), and suggested next steps. Never include secrets or tokens that appear in logs; redact them.
Cursor has no tools field, so tool access is expressed as readonly: true. Read-only agents can still run non-mutating commands like git diff.
When to use it
Use it on server logs, build logs, crash dumps or any output too long to paste into the main chat.
How to install and run
Save the file in your project (or in ~/.claude/agents/ / ~/.cursor/agents/ for every project). In Claude Code, @-mention it, ask “use the log-analyzer subagent”, or start a session with claude --agent log-analyzer. In Cursor, type /log-analyzer or ask for it by name. Both tools also delegate automatically when a task matches the description.
Common pitfalls
- Reading the entire file into context. It should grep and count first.
- Leaking tokens from logs into the transcript. Redaction is in the prompt.
- Focusing on the most frequent error instead of the first one.
FAQ
Can it read logs from a cloud provider?
If a CLI is installed and authenticated (for example gcloud, aws, vercel), it can run the log command through Bash.
Why is it read-only?
It only analyzes. In Cursor, readonly: true still allows grep and tail.
How big a file can it handle?
Any size, as long as it uses grep/tail instead of reading the whole file.
Related subagents
- DebuggerDebugging specialist for errors, failing tests and unexpected behavior.
- CI Failure FixerDiagnoses and fixes failing CI runs.
- Read-Only Database QueryAnswers questions about data by running read-only SQL queries.
- Codebase ExplorerAnswers questions about how the codebase works: where things are defined, how data flows, which files to change.
All subagent examples and the Claude Code ↔ Cursor converter