Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
athola avatar

Bug Review

  • 100 installs
  • 325 repo stars
  • Updated August 2, 2026
  • athola/claude-night-market

Turn messy bug reports into structured defect docs with exact file:line references and severity tiers before you fix or triage.

About

Bug-review is a defect-documentation agent skill that forces systematic identification instead of vague “something broke” notes. It walks you through capturing precise locations—file path, line number, containing function, and a short context snippet—so fixes and handoffs stay reproducible. A fixed severity table ties each issue to business impact and expected response time, from immediate Critical (crash, data loss, security) through backlog Low edge cases. Root-cause categories group logic mistakes, API misuse, concurrency failures, and resource leaks so patterns show up across sprints. Progressive loading keeps token use reasonable while still pairing with proof-of-work style verification from its dependency chain. Solo builders shipping agents, CLIs, or SaaS backends use it during PR review, pre-release sweeps, and post-incident writeups when you need audit-ready bug lists—not brainstorming fixes.

  • Requires file path, line number, function scope, and a 3–5 line code snippet for every defect
  • Four-level severity matrix (Critical/High/Medium/Low) with impact and response-time guidance
  • Root-cause taxonomy: logic errors, API misuse, concurrency, and resource leaks
  • Progressive-loading parent workflow (pensive:bug-review) with imbue:proof-of-work dependency
  • Rust/Go-oriented examples (ownership, channels) for backend and systems code

Bug Review by the numbers

  • 100 all-time installs (skills.sh)
  • Ranked #444 of 1,352 Code Review & Quality skills by installs in the Skillselion catalog
  • Security screen: LOW risk (skills.sh audit)
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/athola/claude-night-market --skill bug-review

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs100
repo stars325
Security audit3 / 3 scanners passed
Last updatedAugust 2, 2026
Repositoryathola/claude-night-market

What it does

Turn messy bug reports into structured defect docs with exact file:line references and severity tiers before you fix or triage.

Files

SKILL.mdMarkdownGitHub ↗

Table of Contents

Bug Review Workflow

Systematic bug identification and fixing with language-specific expertise.

Quick Start

/bug-review

Verification: Run the command with --help flag to verify availability.

When To Use

  • Reviewing code for potential bugs
  • After receiving bug reports
  • Before major releases
  • During security audits
  • Investigating production issues

When NOT To Use

  • Test coverage audit - use test-review instead

Required TodoWrite Items

1. bug-review:language-detected 2. bug-review:repro-plan 3. bug-review:defects-documented 4. bug-review:fixes-prepared 5. bug-review:verification-plan 6. bug-review:findings-verified

Progressive Loading

Load additional context as needed:

  • Language Detection: @include modules/language-detection.md - Manifest heuristics, expertise framing, version constraints
  • Defect Documentation: @include modules/defect-documentation.md - Severity classification, root cause analysis, static analyzers
  • Fix Preparation: @include modules/fix-preparation.md - Minimal patches, idiomatic patterns, test coverage

Workflow

Step 1: Detect Languages (bug-review:language-detected)

Identify dominant languages using manifest files (Cargo.toml → Rust, package.json → Node, etc.).

State expertise persona appropriate for the language ecosystem.

Note version constraints (MSRV, Python versions, Node engines).

Progressive: Load modules/language-detection.md for detailed manifest heuristics.

Step 2: Plan Reproduction (bug-review:repro-plan)

Identify reproduction methods:

  • Unit/integration test suites
  • Fuzzing tools
  • Manual reproduction commands

Document exact commands:

cargo test -p core
pytest tests/test_api.py
npm test -- pkg

Verification: Run pytest -v tests/test_api.py to verify.

Capture blockers and propose mocks when dependencies unavailable.

Step 3: Document Defects (bug-review:defects-documented)

Review code line-by-line, logging each bug with:

  • File:line reference: Precise location
  • Severity: Critical, High, Medium, Low
  • Root cause: Logic error, API misuse, concurrency, resource leak
  • Impact: What breaks and how

Run static analyzers (cargo clippy, ruff check, golangci-lint, eslint).

Use imbue:proof-of-work for reproducible capture.

Progressive: Load modules/defect-documentation.md for classification details and analyzer commands.

Step 4: Prepare Fixes (bug-review:fixes-prepared)

Draft minimal, idiomatic patches using language best practices:

  • Guard clauses (Rust: pattern matching, Python: early returns)
  • Resource cleanup (Go: defer, Python: context managers)
  • Error propagation (Rust: ?, Go: wrapped errors)

Create tests following Red → Green pattern: 1. Write failing test 2. Apply minimal fix 3. Verify test passes

Progressive: Load modules/fix-preparation.md for language-specific patterns and test strategies.

Step 5: Verification Plan (bug-review:verification-plan)

Execute reproduction steps with fixes applied.

Capture evidence:

  • Test output logs
  • Benchmark comparisons
  • Coverage reports

Document remaining risks using imbue:diff-analysis/modules/risk-assessment-framework.

Assign owners and deadlines for follow-up items.

Step 6: Verify Findings Are Grounded (bug-review:findings-verified)

Every defect must cite a real file:line and a verbatim Anchor. Write findings to .review/findings.json and confirm each citation resolves:

python plugins/imbue/scripts/citation_verifier.py \
  --findings .review/findings.json --repo-root .

Drop or label UNVERIFIED any defect the verifier fails (exit 1); only verified defects enter the report. See Skill(imbue:review-core) Step 5 for the protocol and Skill(imbue:structured-output) for the schema.

Defect Classification (Condensed)

Severity: Critical (crash/data loss) → High (broken features) → Medium (degraded UX) → Low (edge cases)

Root Causes: Logic errors | API misuse | Concurrency issues | Resource leaks | Validation gaps

Output Format

## Summary
[Brief scope description]

## Defects Found
### [D1] file.rs:142 - Title
- Severity: High
- Anchor: `verbatim source text at file.rs:142`
- Root Cause: Logic error
- Impact: Data corruption possible
- Fix: [description]

## Proposed Fixes
### Fix for D1
[code diff with explanation]

## Test Updates
[new/updated tests with Red → Green verification]

## Evidence
- Commands executed
- Logs and outputs
- External references

Verification: Run pytest -v to verify tests pass.

Best Practices

1. Evidence-based: Every finding has file:line reference 2. Reproducible: Clear steps to reproduce each bug 3. Minimal fixes: Smallest change that fixes the issue 4. Test coverage: Every fix has corresponding test 5. Risk awareness: Document remaining risks with severity scoring

Exit Criteria

  • All defects documented with precise references
  • Every defect carries a file:line + verbatim Anchor, and citation_verifier.py confirmed all citations (exit 0) or unverified defects were dropped or labeled UNVERIFIED
  • Fixes prepared with test coverage verified
  • Verification plan includes commands and expected outputs
  • Remaining risks assessed and owners assigned

Related skills

FAQ

Is Bug Review safe to install?

skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Code Review & Qualitytestingbackend

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.