npx skills add ...
npx skills add posthog/skills --skill investigating-replay
npx skills add posthog/skills --skill investigating-replay
Investigates a session recording by gathering metadata, person profile, same-session events, and linked error tracking issues in one pass. Use when a user provides a recording or session ID and wants to understand what happened — who the user was, what they did, what errors occurred, and whether there are related error tracking issues. Replaces the manual chain of session-recording-get, persons-retrieve, execute-sql, and query-error-tracking-issues-list.
When a user asks "what happened in this session?" or provides a recording/session ID to investigate, gather all relevant context in parallel rather than making them ask for each piece.
| Tool | Purpose |
|---|---|
posthog:session-recording-get | Recording metadata (duration, counts, status) |
posthog:persons-retrieve | Person profile (properties, distinct IDs) |
posthog:execute-sql | Query events, errors, and page views in session |
posthog:query-error-tracking-issues-list | Find error tracking issues linked to the session |
posthog:vision-observations-list | Check for an existing Replay Vision AI summary |
posthog:vision-scanners-list | Find summarizer scanners (scanner_type=summarizer) |
posthog:vision-scanners-scan-session | Run a summarizer scanner on the session (slow, optional) |
posthog:vision-scanners-create | Create a temporary summarizer scanner (ask first) |
posthog:vision-scanners-delete | Delete a temporary scanner after summarizing |
Start with the recording to get metadata and the person's distinct ID:
The response includes distinct_id, person, duration, interaction counts,
console error counts, and viewing status. Use the distinct_id to fetch
the full person profile:
Get the timeline of what the user did during the session:
For sessions with many events, focus on the most informative ones:
If the recording has console errors or exceptions, find related error tracking issues:
If fingerprints are found, search for the corresponding error tracking issues to provide links and status:
Present the findings as a coherent narrative:
If the user wants a deeper analysis without reading through events manually, offer a Replay Vision summary. Follow "check-then-scan" — don't scan blindly, a scanner can only observe a given session once.
Check for an existing summary. A scheduled scanner may already have one:
Look for an observation where scanner_snapshot.scanner_type is summarizer
and status is succeeded. If found, read scanner_result.model_output
(title, summary, intent, outcome, friction_points, keywords) — done,
no new scan needed.
Find a summarizer scanner if none exists yet:
Scan the session with the chosen scanner. Warn this is async and takes several minutes (rasterize + LLM):
Retrieve the result by polling vision-observations-list (step 1) until
the new observation reaches succeeded.
If the project has no summarizer scanner, you can still produce a one-off summary with a throwaway scanner — but ask the user's permission before creating anything.
Ask permission to create a temporary summarizer scanner just to summarize this one session.
Create it disabled so it never sweeps on a schedule — a disabled scanner only runs when you trigger it on demand, so it won't touch other sessions or burn quota in the background:
Scan this session on demand with the new scanner, then poll for the result:
Poll vision-observations-list until the observation reaches succeeded and
read scanner_result.model_output.
Ask whether to keep or delete the scanner. Once you have the observation,
ask the user if they want to keep the temporary scanner or delete it with
vision-scanners-delete. Deleting is safe: the summary you just read is also
emitted as an event that persists after the scanner is gone, so cleaning up the
temporary scanner does not lose the result.
start_url from the recording tells you where the user's journey began —
use this to frame the narrative.person is null on the recording, the user was anonymous.
Person properties won't be available, but events still are.posthog:execute-sql
SELECT
timestamp,
event,
properties.$current_url AS url,
if(event = '$exception', properties.$exception_message, null) AS exception_message,
if(event = '$exception', properties.$exception_type, null) AS exception_type
FROM events
WHERE $session_id = '<session_id>'
AND event IN ('$pageview', '$pageleave', '$autocapture', '$exception', '$rageclick')
ORDER BY timestamp ASC
LIMIT 100posthog:execute-sql
SELECT DISTINCT
properties.$exception_fingerprint AS fingerprint,
properties.$exception_type AS type,
properties.$exception_message AS message,
count() AS occurrences
FROM events
WHERE $session_id = '<session_id>'
AND event = '$exception'
GROUP BY fingerprint, type, message
ORDER BY occurrences DESC
LIMIT 10posthog:query-error-tracking-issues-list
{
"searchQuery": "<exception_type or message>"
}