Root cause
Skill VoDaiLocz/kilo-kit-mcp/skills/kilo-kit/debugging/root-cause
An MCP server for safer coding agents: skill routing, C4 workflow gates, memory checks, and verification before completion.
npx -y skills add VoDaiLocz/kilo-kit-mcp --skill root-causeAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 24 stars24 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Deep root cause analysis using the 5 Whys and Fishbone techniques. Use when systematic debugging hasn't found the cause, or for complex systemic issues. Keywords: root cause, why, underlying, fundamental, systemic, deep, origin
SKILL.md
9.4 KB, as published. Nobody here has run it
π¬ Root Cause Analysis Skill
Philosophy: Don't stop at the first "why" β dig until you hit bedrock.
When to Use
Use this skill when:
- Systematic debugging found the bug but not WHY it exists
- Issue keeps recurring despite fixes
- Bug seems to have multiple contributing factors
- You need to prevent similar bugs in the future
- There's a systemic/architectural issue suspected
Do NOT use this skill when:
- Bug is simple and obvious
- Time is extremely limited (use quick-fix)
- Just need to patch, not understand
Prerequisites
Before starting:
- Bug has been identified (what is happening)
- Have access to relevant code and history
- Understand the system architecture (high level)
- Have time for thorough analysis (~30-60 mins)
Process
Phase 1: PROBLEM DEFINITION π
Goal: Clearly define what we're analyzing.
Steps:
-
State the Problem Precisely
Template: "When [condition], the system [actual behavior] instead of [expected behavior]." Example: "When a user submits a login form with special characters, the system returns a 500 error instead of validating input." -
Gather Impact Data
- How often does it occur?
- Who/what is affected?
- What's the business impact?
- How long has it been happening?
-
Document Timeline
- When did it first appear?
- Any recent changes before first occurrence?
- Has it gotten better/worse?
Output: Clear problem statement with context.
Phase 2: THE 5 WHYS ANALYSIS π
Goal: Drill down to fundamental causes.
Method:
Start: Problem Statement
β
ββ Why? β First-level cause
β β
β ββ Why? β Second-level cause
β β β
β β ββ Why? β Third-level cause
β β β β
β β β ββ Why? β Fourth-level cause
β β β β β
β β β β ββ Why? β ROOT CAUSE
Rules:
- Each answer must be factual, not speculative
- If multiple answers possible at a level, branch and explore all
- Stop when you reach something actionable
- "Human error" is NEVER a root cause β dig deeper
Example:
Problem: Login fails with special characters
Why #1: Server returns 500 error
β Because: Unhandled exception in auth.service.ts
Why #2: Why is there an unhandled exception?
β Because: SQL query fails with syntax error
Why #3: Why does SQL have syntax error?
β Because: User input is concatenated directly into query
Why #4: Why is input concatenated directly?
β Because: Developer didn't use parameterized queries
Why #5: Why didn't developer use parameterized queries?
β Because: No code review caught it, and no security guidelines exist
ROOT CAUSE: Missing security coding standards and review process
Phase 3: FISHBONE DIAGRAM (ISHIKAWA) π
Goal: Explore contributing factors systematically.
Categories to Examine:
ββββββββββββ
ββββββββββββββββββββΊβ β
β Environment β β
β β β
βββββββββββ΄ββββ β PROBLEM β
β Methods ββββββββββββββββΊβ β
βββββββββββββββ β β
β β
βββββββββββββββ β β
β Machines ββββββββββββββββΊβ β
β (Systems) β β β
βββββββββββββββ βββββββ¬βββββ
β
βββββββββββββββββββββββββββββ
β
ββββββ΄βββββ ββββββββββββ ββββββββββββ
β People β βMaterials β βMeasurementβ
β(Process)β β (Data) β β (Metrics)β
βββββββββββ ββββββββββββ ββββββββββββ
For Each Category, Ask:
| Category | Questions to Ask |
|---|---|
| Methods | Is the process correct? Is it followed? Is it documented? |
| Machines | Is the system configured correctly? Dependencies up to date? |
| Environment | Dev vs Prod differences? External factors? |
| People/Process | Training adequate? Communication clear? Handoffs smooth? |
| Materials/Data | Data quality? Input validation? Edge cases? |
| Measurement | Are we monitoring correctly? Are we measuring the right things? |
Phase 4: CONTRIBUTING FACTOR ANALYSIS π§©
Goal: Weight and prioritize contributing factors.
Steps:
-
List All Contributing Factors Combine findings from 5 Whys and Fishbone
-
Score Each Factor
scoring: frequency: 1-5 (how often does this contribute?) detectability: 1-5 (how hard to detect? 5=very hidden) severity: 1-5 (how much impact when it contributes?) risk_score: frequency Γ detectability Γ severity -
Create Priority Matrix
High Frequency + High Severity β Address immediately High Frequency + Low Severity β Address soon Low Frequency + High Severity β Create safeguards Low Frequency + Low Severity β Monitor only
Phase 5: ROOT CAUSE VALIDATION β
Goal: Confirm the root cause is correct.
Validation Questions:
-
Causation Test
- If we fix this, will the problem definitely not recur?
- Can we prove cause β effect relationship?
-
Completeness Test
- Are there other causes we might have missed?
- Would fixing this alone be sufficient?
-
Actionability Test
- Can we actually address this cause?
- Is it within our control?
-
Proportionality Test
- Is the root cause proportional to the problem?
- (Big problems usually have big root causes)
Phase 6: PREVENTION RECOMMENDATIONS π‘οΈ
Goal: Prevent recurrence.
Recommendation Types:
-
Immediate Fix
- Direct fix for the symptom
- Buys time for proper solution
-
Root Cause Fix
- Addresses the fundamental cause
- Prevents this exact issue
-
Systemic Improvement
- Prevents entire class of similar issues
- Usually involves process/tooling changes
-
Detection Improvement
- Catch similar issues earlier next time
- Monitoring, testing, review improvements
Example Recommendations:
for_the_sql_injection_example:
immediate:
- Fix the specific query to use parameters
- Add input sanitization
root_cause:
- Establish secure coding guidelines
- Require security review for auth code
systemic:
- Enable SQL injection detection in SAST tooling
- Add security-focused code review checklist
- Security training for developers
detection:
- Add SQL injection tests to CI pipeline
- Monitor for unusual database queries
Output Template
# Root Cause Analysis Report
## Problem Statement
[Clear statement of the problem]
## Timeline
- First observed: [date]
- Recent changes: [list]
- Frequency: [how often]
## 5 Whys Analysis
1. Why? β [answer]
2. Why? β [answer]
3. Why? β [answer]
4. Why? β [answer]
5. Why? β [answer]
## Contributing Factors
| Factor | Category | Risk Score | Priority |
|--------|----------|------------|----------|
| [factor] | [cat] | [score] | [priority] |
## Root Cause
[Clear statement of root cause]
## Validation
- [ ] Causation confirmed
- [ ] Complete (no other causes)
- [ ] Actionable
- [ ] Proportional
## Recommendations
### Immediate
- [action]
### Root Cause Fix
- [action]
### Systemic
- [action]
### Detection
- [action]
Guidelines
DO β
- Follow the evidence, not assumptions
- Keep asking "why" until you can't anymore
- Document everything for future reference
- Involve domain experts when needed
- Look for patterns across similar issues
DON'T β
- Blame individuals (focus on systems)
- Stop at the first plausible answer
- Skip validation steps
- Propose fixes before understanding cause
- Ignore contributing factors
Success Criteria
Before claiming analysis complete:
- Problem clearly defined with impact
- 5 Whys completed to true root cause
- Contributing factors identified and scored
- Root cause validated against all tests
- Prevention recommendations at all levels
- Report documented for future reference
Related Skills
skills/kilo-kit/debugging/systematic/- For initial bug identificationskills/kilo-kit/debugging/verification/- For validating fixesskills/kilo-kit/quality/code-review/- For review improvements
Root Cause Analysis Skill v1.0.0 β Dig until you hit bedrock