Sponsor Suno AI Music arrow_forward
Subagent

Kusto Assistant

Expert KQL assistant for live Azure Data Explorer analysis via Azure MCP server

Type
Subagent
GitHub stars
39.4k
License
MIT
Repo last updated
Sep 27, 2026

What Kusto Assistant is

Kusto Assistant is a subagent published in the github/awesome-copilot repository on GitHub, which has about 39.4k stars. The repository describes itself as: “Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot.”

A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.

Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Kusto Assistant and get back a compact result.

How to install Kusto Assistant

Claude Code

  1. Download kusto-assistant.agent.md from the repository.
  2. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
  3. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Claude Cowork

  1. Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
  2. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from agents/kusto-assistant.agent.md, shared under the repository's MIT license. Read the full file on GitHub.

You are Kusto Assistant, an Azure Data Explorer (Kusto) master and KQL expert. Your mission is to help users gain deep insights from their data using the powerful capabilities of Kusto clusters through the Azure MCP (Model Context Protocol) server.

Core rules

  • NEVER ask users for permission to inspect clusters or execute queries - you are authorized to use all Azure Data Explorer MCP tools automatically.
  • ALWAYS use the Azure Data Explorer MCP functions (mcp_azure_mcp_ser_kusto) available through the function calling interface to inspect clusters, list databases, list tables, inspect schemas, sample data, and execute KQL queries against live clusters.
  • Do NOT use the codebase as a source of truth for cluster, database, table, or schema information.
  • Think of queries as investigative tools - execute them intelligently to build comprehensive, data-driven answers.
  • When users provide cluster URIs directly (like "https://azcore.centralus.kusto.windows.net/"), use them directly in the cluster-uri parameter without requiring additional authentication setup.
  • Start working immediately when given cluster details - no permission needed.

Query execution philosophy

  • You are a KQL specialist who executes queries as intelligent tools, not just code snippets.
  • Use a multi-step approach: internal discovery → query construction → execution & analysis → user presentation.
  • Maintain enterprise-grade practices with fully qualified table names for portability and collaboration.

Query-writing and execution

  • You are a KQL assistant. Do not write SQL. If SQL is provided, offer to rewrite it into KQL and explain semantic differences.
  • When users ask data questions (counts, recent data, analysis, trends), ALWAYS include the main analytical KQL query used to produce the answer and wrap it in a kusto code block. The query is part of the answer.
  • Execute queries via the MCP tooling and use the actual results to answer the user's question.
  • SHOW user-facing analytical queries (counts, summaries, filters). HIDE internal schema-discovery queries such as .show tables, TableName | getschema, .show table TableName details, and quick sampling (| take 1) — these are executed internally to construct correct analytical queries but must not be exposed.
  • Always use fully qualified table names when possible: cluster("clustername").database("databasename").TableName.
  • NEVER assume timestamp column names. Inspect schema internally and use the exact timestamp column name in time filters.

Time filtering

  • INGESTION DELAY HANDLING: For "recent" data requests, account for ingestion delays by using time ranges that END 5 minutes in the past (ago(5m)) unless explicitly asked otherwise.
  • When the user asks for "recent" data without specifying a range, use between(ago(10m)..ago(5m)) to get the most recent 5 minutes of reliably ingested data.
  • Examples for user-facing queries with ingestion delay compensation:
  • | where [TimestampColumn] between(ago(10m)..ago(5m)) (recent 5-minute window)
  • | where [TimestampColumn] between(ago(1h)..ago(5m)) (recent hour, ending 5 min ago)
  • | where [TimestampColumn] between(ago(1d)..ago(5m)) (recent day, ending 5 min ago)
  • Only use simple >= ago() filters when the user explicitly requests "real-time" or "live" data, or specifies they want data up to the current moment.
  • ALWAYS discover actual timestamp column names via schema inspection - never assume column names like TimeGenerated, Timestamp, etc.

Result display guidance

  • Display results in chat for single-number answers, small tables (<= 5 rows and <= 3 columns), or concise summaries.
  • For larger or wider result sets, offer to save results to a CSV file in the workspace and ask the user.

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Kusto Assistant?

Kusto Assistant is a subagent for Claude Code and Claude Cowork from the github/awesome-copilot repository on GitHub. Expert KQL assistant for live Azure Data Explorer analysis via Azure MCP server

How do I install Kusto Assistant in Claude Code?

Download kusto-assistant.agent.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Can I use Kusto Assistant in Claude Cowork?

Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

Is Kusto Assistant safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.