Agent skill

Semantic Szz Analyzer

by ArabelaTso in ArabelaTso/Skills-4-SE

Identify bug-introducing commits using semantic analysis that extends traditional SZZ algorithm.

Apache-2.0Auto-check passedDevelopment

Install Semantic Szz Analyzer

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill semantic-szz-analyzer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE semantic-szz-analyzer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/semantic-szz-analyzer .claude/skills/semantic-szz-analyzer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
semantic-szz-analyzer
GitHub stars
253
Token cost
~1.4k tokens
SKILL.md length
466 words
Files
9 (incl. scripts, references)
Skills in repo
170
Repo updated
First seen
Licence
Apache-2.0

At a glance

Identify bug-introducing commits using semantic analysis that extends traditional SZZ algorithm.

  • Works in 8 steps: Semantic Change Detection → Bug-Introducing Commit Identification → False Positive Reduction → …
  • Analyzing bug-fix commits to trace back to bug-introducing changes
  • SKILL.md covers Overview, Core Capabilities, Workflow and Usage Examples, plus 3 more sections
  • Runs Python scripts from its folder; calls python and git

What it does

Semantic Szz Analyzer is an agent skill from ArabelaTso/Skills-4-SE. Identify bug-introducing commits using semantic analysis that extends traditional SZZ algorithm. Distinguishes semantic changes from refactorings or code movements using control-flow and data-flow similarity analysis. Use when analyzing bug-fix commits to trace back to bug-introducing changes, investigating software evolution, conducting empirical studies on defect prediction, or reducing false positives in bug localization. Supports git repositories and provides explanations for why commits are identified as…

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `README.md`, `references/language_support.md` and `references/semantic_analysis.md`).

It sits in Development, covering Debugging, Refactoring and Internationalization. It works with Git. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Analyzing bug-fix commits to trace back to bug-introducing changes
  • Investigating software evolution
  • Conducting empirical studies on defect prediction
  • Reducing false positives in bug localization

Example prompts

  • “/semantic-szz-analyzer”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Semantic Change Detection
  2. Bug-Introducing Commit Identification
  3. False Positive Reduction
  4. Analyze Bug-Fix Commit
  5. Identify Candidate Commits
  6. Apply Semantic Analysis
  7. Filter and Rank Results
  8. Generate Explanation

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Semantic Szz Analyzer loads about 1.4k tokens when it runs, and up to ~6.6k if it reads all its reference files. Until then it costs about 138 tokens; SKILL.md has 466 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 466 words, ~1,407 tokens.

Download SKILL.mdSave it as .claude/skills/semantic-szz-analyzer/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
semantic-szz-analyzer
description
Identify bug-introducing commits using semantic analysis that extends traditional SZZ algorithm. Distinguishes semantic changes from refactorings or code movements using control-flow and data-flow similarity analysis. Use when analyzing bug-fix commits to trace back to bug-introducing changes, investigating software evolution, conducting empirical studies on defect prediction, or reducing false positives in bug localization. Supports git repositories and provides explanations for why commits are identified as bug-introducing.

Semantic SZZ Analyzer

Overview

Semantic SZZ Analyzer extends the traditional SZZ (Sliwerski-Zimmermann-Zeller) algorithm by incorporating semantic analysis to identify bug-introducing commits more accurately. It distinguishes actual semantic changes from refactorings or code movements by analyzing control-flow and data-flow similarity across versions.

Core Capabilities

1. Semantic Change Detection

Analyze commits to distinguish between:

  • Semantic changes: Modifications that alter program behavior
  • Refactorings: Code restructuring without behavior changes
  • Code movements: Relocations of code blocks without semantic impact

Use control-flow graphs (CFG) and data-flow analysis to compute similarity between code versions.

2. Bug-Introducing Commit Identification

Given a bug-fix commit, trace back through git history to identify the commit that introduced the bug:

  1. Extract changed lines from the bug-fix commit
  2. Use git blame to find commits that last modified those lines
  3. Apply semantic analysis to filter out false positives
  4. Rank candidates by semantic similarity and temporal proximity
3. False Positive Reduction

Traditional SZZ produces many false positives due to:

  • Whitespace changes
  • Comment modifications
  • Import reorganization
  • Variable renaming
  • Code formatting

Semantic SZZ filters these by analyzing AST (Abstract Syntax Tree) structure and semantic equivalence.

Workflow

Step 1: Analyze Bug-Fix Commit

Start by identifying the bug-fix commit. Look for:

  • Commits with keywords: "fix", "bug", "issue", "patch", "resolve"
  • Commits linked to issue trackers
  • Commits explicitly marked as fixes

Extract the changed lines and affected files.

Step 2: Identify Candidate Commits

Use git blame or git log -L to trace the history of changed lines:

bash
git blame -L <start>,<end> <file> <bug-fix-commit>^

This identifies commits that last modified the buggy lines before the fix.

Step 3: Apply Semantic Analysis

For each candidate commit, run semantic analysis using the provided script:

bash
python scripts/semantic_analyzer.py --repo <repo-path> --candidate <commit-hash> --fix <fix-commit-hash>

The script computes:

  • CFG similarity: Control-flow graph matching between versions
  • Data-flow similarity: Variable usage and dependency analysis
  • AST diff: Structural code changes vs. superficial changes
Show full SKILL.md (173 more words)Show less
Step 4: Filter and Rank Results

Filter candidates based on semantic similarity threshold (default: 0.7). Rank remaining candidates by:

  1. Semantic change magnitude
  2. Temporal proximity to bug-fix
  3. Code churn in the commit
Step 5: Generate Explanation

For each identified bug-introducing commit, generate an explanation including:

  • What semantic changes were made
  • Why the change is considered bug-introducing
  • Confidence score based on similarity metrics
  • Diff highlighting the problematic changes

Usage Examples

Example 1: Analyze a specific bug-fix

bash
python scripts/semantic_szz.py --repo /path/to/repo --fix-commit abc123

Example 2: Batch analysis of multiple fixes

bash
python scripts/batch_analyze.py --repo /path/to/repo --fixes-file bug_fixes.txt

Example 3: Generate detailed report

bash
python scripts/semantic_szz.py --repo /path/to/repo --fix-commit abc123 --output report.json --explain

Advanced Features

Custom Similarity Thresholds

Adjust sensitivity by modifying similarity thresholds:

python
# In scripts/semantic_analyzer.py
CFG_THRESHOLD = 0.7  # Control-flow similarity
DFG_THRESHOLD = 0.6  # Data-flow similarity
AST_THRESHOLD = 0.8  # AST structural similarity
Language-Specific Analysis

The analyzer supports multiple languages with language-specific parsers:

  • Python: Uses ast module
  • Java: Uses javalang or tree-sitter
  • C/C++: Uses pycparser or tree-sitter
  • JavaScript: Uses esprima or tree-sitter

See references/language_support.md for details.

Integration with Issue Trackers

Link bug-fixes to issue IDs for automated analysis:

bash
python scripts/semantic_szz.py --repo /path/to/repo --issue JIRA-123

References

Output Format

Results are provided in JSON format:

json
{
  "fix_commit": "abc123",
  "bug_introducing_commits": [
    {
      "commit": "def456",
      "confidence": 0.85,
      "semantic_change_type": "logic_modification",
      "explanation": "Modified conditional logic in function foo()",
      "changed_lines": [45, 46, 47],
      "similarity_scores": {
        "cfg": 0.72,
        "dfg": 0.68,
        "ast": 0.81
      }
    }
  ]
}

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts, references) in skills/semantic-szz-analyzer of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • README.md
  • bug_fixes.txt.example
  • references/language_support.md
  • references/semantic_analysis.md
  • references/szz_algorithm.md
  • scripts/batch_analyze.py
  • scripts/semantic_analyzer.py
  • scripts/semantic_szz.py

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Semantic Szz Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Semantic Szz Analyzer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Semantic Szz Analyzer this skillArabelaTso/Skills-4-SE253—~1.4kAutomated safety check: PassApache-2.0
Nemo Rl Auto ResearchNVIDIA/skills3.5k—~2.3kAutomated safety check: PassApache-2.0
Git History Bug Auditben-manes/caffeine18k—~3.3kAutomated safety check: PassApache-2.0
Stax Devcesarferreira/stax130—~987Automated safety check: PassMIT
Odoo Workflowunclecatvn/agent-skills143—~4.7kAutomated safety check: PassMIT
Anchor Vetlynxlangya/techne105—~1.3kAutomated safety check: PassMIT

Similar skills

  • Official

    Autonomous NeMo-RL research agent workflow for directed hypothesis testing and open-ended discovery.

    3.5k GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Git History Bug Audit

    ben-manes/caffeine

    Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

    18k GitHub stars~3.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Stax Dev

    cesarferreira/stax

    Development harness for the stax Rust CLI project. An agent skill from cesarferreira/stax.

    130 GitHub stars~987 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Odoo Workflow

    unclecatvn/agent-skills

    Mandatory pre-code gate and definition-of-done for ANY Odoo change (add field, override method, inherit view/xpath, OWL/JS patch, wizard, cron, controller, report, security, migration, bug fix…

    143 GitHub stars~4.7k tokensUpdated 15 days ago
    DevelopmentAuto-check passed
  • Anchor Vet

    lynxlangya/techne

    Evidence-gated diff review for PRs, branches, commit ranges, staged code changes, and merge readiness checks.

    105 GitHub stars~1.3k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Merge Master

    keybase/client

    A skill your agent uses when periodically merging upstream master commits into a long-running refactor branch where code has moved, been renamed, or restructured — guiding careful per-commit…

    9.3k GitHub stars~1.3k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from ArabelaTso/Skills-4-SE

All 170 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Semantic Szz Analyzer

What does Semantic Szz Analyzer do?

Identify bug-introducing commits using semantic analysis that extends traditional SZZ algorithm. Semantic Szz Analyzer is an agent skill from ArabelaTso/Skills-4-SE. Identify bug-introducing commits using semantic analysis that extends traditional SZZ algorithm.

When should I use Semantic Szz Analyzer?

Semantic Szz Analyzer fits situations like: analyzing bug-fix commits to trace back to bug-introducing changes; investigating software evolution; conducting empirical studies on defect prediction; reducing false positives in bug localization.

How do I install Semantic Szz Analyzer in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill semantic-szz-analyzer -a claude-code`. Or copy the skill folder (skills/semantic-szz-analyzer in ArabelaTso/Skills-4-SE) into .claude/skills/semantic-szz-analyzer in your project. Claude Code loads it when a task matches its description.

How do I install Semantic Szz Analyzer in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill semantic-szz-analyzer -a codex`. Or copy the skill folder (skills/semantic-szz-analyzer in ArabelaTso/Skills-4-SE) into .agents/skills/semantic-szz-analyzer in your project. Codex loads it when a task matches its description.

Can I use Semantic Szz Analyzer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill semantic-szz-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/semantic-szz-analyzer, .gemini/skills/semantic-szz-analyzer, .github/skills/semantic-szz-analyzer and .opencode/skills/semantic-szz-analyzer in your project.

What does Semantic Szz Analyzer need to run?

Going by SKILL.md and its folder, Semantic Szz Analyzer needs Python for the scripts in its folder and the command-line tools its instructions call (python and git). Our summary lists: Python 3.

Does Semantic Szz Analyzer access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Semantic Szz Analyzer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Semantic Szz Analyzer use?

Semantic Szz Analyzer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Semantic Szz Analyzer use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.2k tokens, read only when the agent opens those files.

What are the alternatives to Semantic Szz Analyzer?

Skills that share tags, products or a category with Semantic Szz Analyzer: Nemo Rl Auto Research (NVIDIA/skills, 3.5k stars), Git History Bug Audit (ben-manes/caffeine, 18k stars), Stax Dev (cesarferreira/stax, 130 stars) and Odoo Workflow (unclecatvn/agent-skills, 143 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Semantic Szz Analyzer?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 170 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.