Agent skill

Static Bug Detector

by ArabelaTso in ArabelaTso/Skills-4-SE

Analyze source code statically to detect potential functional bugs including null dereferences, incorrect condition checks, unreachable code, inconsistent state updates, logic errors, resource…

Apache-2.0Auto-check passedDevelopment

Install Static Bug Detector

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill static-bug-detector -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE static-bug-detector --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/static-bug-detector .claude/skills/static-bug-detector && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
static-bug-detector
GitHub stars
253
Token cost
~3.4k tokens
SKILL.md length
514 words
Files
2 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyze source code statically to detect potential functional bugs including null dereferences, incorrect condition checks, unreachable code, inconsistent state updates, logic errors, resource…

  • Works in 5 steps: Understand the Code → Detect Bug Patterns → Analyze Severity → …
  • Reviewing code for bugs
  • SKILL.md covers Overview, Bug Detection Workflow, Bug Categories and Examples
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Static Bug Detector is an agent skill from ArabelaTso/Skills-4-SE. Analyze source code statically to detect potential functional bugs including null dereferences, incorrect condition checks, unreachable code, inconsistent state updates, logic errors, resource leaks, and type mismatches. Report suspicious code locations with detailed explanations, severity levels, and confidence assessments. Use when reviewing code for bugs, performing code audits, or when the user asks to find bugs, detect issues, analyze code for problems, or perform static analysis.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/detection_patterns.md`).

It sits in Development, covering Static analysis and SAST and Debugging. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Reviewing code for bugs
  • Performing code audits
  • The user asks to find bugs
  • Analyze code for problems

Example prompts

  • “/static-bug-detector”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Understand the Code
  2. Detect Bug Patterns
  3. Analyze Severity
  4. Assess Confidence
  5. Generate Report

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown, java, python, javascript and language).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Static Bug Detector loads about 3.4k tokens when it runs, and up to ~7.6k if it reads all its reference files. Until then it costs about 128 tokens; SKILL.md has 514 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~128
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 514 words, ~3,446 tokens.

Download SKILL.mdSave it as .claude/skills/static-bug-detector/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
static-bug-detector
description
Analyze source code statically to detect potential functional bugs including null dereferences, incorrect condition checks, unreachable code, inconsistent state updates, logic errors, resource leaks, and type mismatches. Report suspicious code locations with detailed explanations, severity levels, and confidence assessments. Use when reviewing code for bugs, performing code audits, or when the user asks to find bugs, detect issues, analyze code for problems, or perform static analysis.

Static Bug Detector

Overview

Perform static analysis on source code to identify potential functional bugs. Detect common bug patterns, analyze control flow and data flow, and report suspicious locations with explanations, severity levels, and confidence assessments.

Bug Detection Workflow

Step 1: Understand the Code

Analyze the code structure and semantics:

  1. Identify language:

    • Determine programming language
    • Understand language-specific semantics
    • Note language idioms and conventions
  2. Parse code structure:

    • Functions/methods
    • Classes/types
    • Control flow (if, loops, etc.)
    • Data flow (assignments, returns)
  3. Build context:

    • Variable declarations and types
    • Function signatures
    • Class hierarchies
    • Dependencies
  4. Identify scope:

    • What code to analyze
    • Entry points
    • Critical paths
Step 2: Detect Bug Patterns

Scan for common bug patterns:

  1. Null dereference bugs:

    • Variables from nullable sources
    • Dereferences without null checks
    • Null checks after use
    • Undocumented null returns
  2. Incorrect conditions:

    • Always true/false conditions
    • Assignment in condition (= vs ==)
    • Redundant conditions
    • Inverted logic
    • Wrong operators
  3. Unreachable code:

    • Code after return/throw
    • Always-false branches
    • Dead code paths
  4. Inconsistent state:

    • Partial state updates
    • Updates without validation
    • Non-atomic operations
    • Broken invariants
  5. Logic errors:

    • Off-by-one errors
    • Wrong operator precedence
    • Infinite loops
    • Incorrect boolean logic
  6. Resource issues:

    • Resource leaks
    • Double free/close
    • Use after free/close
  7. Type issues:

    • Type mismatches
    • Implicit coercion
    • Invalid casts
Step 3: Analyze Severity

Assess the impact of each bug:

High Severity:

  • Causes crashes or exceptions
  • Data corruption
  • Security vulnerabilities
  • Guaranteed runtime errors

Medium Severity:

  • Incorrect behavior
  • Potential errors (context-dependent)
  • Performance issues
  • Maintainability problems

Low Severity:

  • Code smells
  • Redundant code
  • Minor inefficiencies
  • Style issues that might hide bugs
Step 4: Assess Confidence

Determine confidence in the bug report:

High Confidence (90-100%):

  • Clear violation of language semantics
  • Guaranteed to cause error
  • Well-known bug pattern
  • No ambiguity

Medium Confidence (60-89%):

  • Likely bug but context-dependent
  • May be intentional in rare cases
  • Suspicious pattern
  • Needs verification

Low Confidence (30-59%):

  • Unusual but possibly valid
  • Could be intentional design
  • Needs more context
  • Style issue that might hide bug

Factors:

  • Code context available
  • Language semantics clarity
  • Pattern recognition
  • Documentation consistency
Show full SKILL.md (188 more words)Show less
Step 5: Generate Report

Produce structured bug report:

  1. For each bug:

    • Bug type/category
    • Location (file, line, range)
    • Severity level
    • Confidence level
    • Description
    • Why it's a bug
    • Potential impact
    • Recommendation/fix
  2. Organize by:

    • Severity (high first)
    • Confidence (high first)
    • Location (file order)
    • Bug type (grouped)
  3. Include:

    • Code context
    • Example fixes
    • Related bugs
    • Summary statistics

Bug Categories

For detailed patterns and examples, see detection_patterns.md.

Quick Reference
Bug CategoryCommon PatternsSeverityDetection Difficulty
Null DereferenceNo null check, null after useHighEasy
Incorrect Conditions= vs ==, always true/falseHigh-MediumEasy
Unreachable CodeAfter return, dead branchLowEasy
Inconsistent StatePartial update, no validationHigh-MediumMedium
Logic ErrorsOff-by-one, wrong precedenceHigh-MediumMedium
Resource IssuesLeaks, double closeMediumMedium
Type IssuesMismatch, implicit coercionMedium-LowEasy

Examples

Example 1: Null Dereference

Input Code (Java):

java
public String getUserName(int userId) {
    User user = userRepository.findById(userId);
    return user.getName();
}

Analysis Output:

markdown
## Bug: Potential null dereference

**Location:** line 3
**Severity:** High
**Confidence:** High (95%)

### Description
Variable 'user' may be null but is dereferenced without null check.

### Why This Is a Bug
Method 'findById' may return null if user not found. Calling 'getName()'
on null will throw NullPointerException.

### Potential Impact
- Runtime NullPointerException
- Application crash
- Poor user experience

### Recommendation
Add null check before dereferencing:

```java
public String getUserName(int userId) {
    User user = userRepository.findById(userId);
    if (user == null) {
        return null;  // or throw exception
    }
    return user.getName();
}

Or use Optional:

java
public Optional<String> getUserName(int userId) {
    return Optional.ofNullable(userRepository.findById(userId))
                   .map(User::getName);
}

### Example 2: Incorrect Condition

**Input Code (C):**
```c
int status = getStatus();
if (status = SUCCESS) {
    printf("Operation successful\n");
}

Analysis Output:

markdown
## Bug: Assignment in condition

**Location:** line 2
**Severity:** High
**Confidence:** High (98%)

### Description
Using assignment operator '=' instead of comparison operator '==' in condition.

### Why This Is a Bug
Expression 'status = SUCCESS' assigns SUCCESS to status and evaluates to
SUCCESS value. This is almost always a typo for 'status == SUCCESS'.

### Potential Impact
- Condition always evaluates to true (if SUCCESS is non-zero)
- Original status value lost
- Logic error in program flow

### Recommendation
Change to comparison operator:

```c
if (status == SUCCESS) {
    printf("Operation successful\n");
}

Most compilers warn about this. Enable warnings: -Wall -Wextra


### Example 3: Off-by-One Error

**Input Code (Python):**
```python
def process_array(arr):
    for i in range(len(arr) + 1):
        print(arr[i])

Analysis Output:

markdown
## Bug: Off-by-one error (array index out of bounds)

**Location:** line 2-3
**Severity:** High
**Confidence:** High (100%)

### Description
Loop iterates one past the end of array, causing IndexError.

### Why This Is a Bug
range(len(arr) + 1) produces indices 0 to len(arr) inclusive. Array
indices are 0 to len(arr)-1, so arr[len(arr)] is out of bounds.

### Potential Impact
- IndexError exception
- Program crash
- Incorrect behavior

### Recommendation
Remove the +1:

```python
def process_array(arr):
    for i in range(len(arr)):
        print(arr[i])

Or use idiomatic iteration:

python
def process_array(arr):
    for item in arr:
        print(item)

### Example 4: Resource Leak

**Input Code (Python):**
```python
def read_config(path):
    f = open(path)
    config = json.load(f)
    return config

Analysis Output:

markdown
## Bug: Resource leak

**Location:** line 2
**Severity:** Medium
**Confidence:** High (90%)

### Description
File opened but never closed, causing resource leak.

### Why This Is a Bug
File handle opened on line 2 is never closed. If exception occurs during
json.load or in normal execution, file remains open.

### Potential Impact
- File descriptor leak
- Resource exhaustion with many calls
- File locking issues on Windows

### Recommendation
Use context manager to ensure cleanup:

```python
def read_config(path):
    with open(path) as f:
        config = json.load(f)
        return config

Or ensure close in finally:

python
def read_config(path):
    f = open(path)
    try:
        config = json.load(f)
        return config
    finally:
        f.close()

### Example 5: Inconsistent State Update

**Input Code (Java):**
```java
public class BankAccount {
    private double balance;

    public void transfer(BankAccount target, double amount) {
        this.balance -= amount;
        // Missing: target.balance += amount
    }
}

Analysis Output:

markdown
## Bug: Incomplete state update

**Location:** line 5
**Severity:** High
**Confidence:** Medium (75%)

### Description
Transfer method deducts from source but doesn't add to target, leaving
system in inconsistent state.

### Why This Is a Bug
Money is removed from source account but never added to target account.
This violates the invariant that total money in system is constant.

### Potential Impact
- Money disappears from system
- Data corruption
- Accounting errors
- Loss of funds

### Recommendation
Complete the transfer operation:

```java
public void transfer(BankAccount target, double amount) {
    if (this.balance < amount) {
        throw new InsufficientFundsException();
    }
    this.balance -= amount;
    target.balance += amount;
}

Consider making atomic with synchronization or transactions.


### Example 6: Unreachable Code

**Input Code (JavaScript):**
```javascript
function calculate(x) {
    if (x < 0) {
        return -x;
    }
    return x;
    console.log("Calculated");  // Unreachable
}

Analysis Output:

markdown
## Bug: Unreachable code

**Location:** line 6
**Severity:** Low
**Confidence:** High (100%)

### Description
Statement is unreachable because function returns unconditionally on line 5.

### Why This Is a Bug
All code paths return before line 6. The console.log statement can never
execute, indicating dead code or logic error.

### Potential Impact
- Dead code clutters codebase
- May indicate incomplete refactoring
- Confusing for maintainers

### Recommendation
Remove unreachable code:

```javascript
function calculate(x) {
    if (x < 0) {
        return -x;
    }
    return x;
}

Or if logging was intended, move before return:

javascript
function calculate(x) {
    let result = x < 0 ? -x : x;
    console.log("Calculated");
    return result;
}

## Report Format

### Summary Section

```markdown
# Static Analysis Report

**Files Analyzed:** X
**Bugs Found:** Y
**High Severity:** A
**Medium Severity:** B
**Low Severity:** C

## Summary by Category
- Null Dereference: X bugs
- Incorrect Conditions: Y bugs
- Unreachable Code: Z bugs
- Inconsistent State: A bugs
- Logic Errors: B bugs
- Resource Issues: C bugs
- Type Issues: D bugs
Individual Bug Reports
markdown
## Bug #N: [Bug Type]

**Location:** [File]:[Line] or [Line Range]
**Severity:** [High/Medium/Low]
**Confidence:** [High/Medium/Low] ([Percentage]%)

### Description
[What the bug is]

### Why This Is a Bug
[Explanation of the problem]

### Potential Impact
[What could go wrong]

### Recommendation
[How to fix it]

### Code Context
```[language]
[Code snippet with line numbers]
Example Fix
language
[Corrected code]

## Best Practices

### Analysis Guidelines

1. **Be thorough:** Check all common bug patterns
2. **Be precise:** Provide exact locations
3. **Be clear:** Explain why it's a bug
4. **Be helpful:** Suggest concrete fixes
5. **Be honest:** Indicate confidence levels
6. **Be practical:** Prioritize by severity
7. **Be respectful:** Avoid judgmental language

### Reporting Guidelines

1. **Prioritize:** High severity and confidence first
2. **Group:** Related bugs together
3. **Contextualize:** Show relevant code
4. **Explain:** Why it's a bug, not just what
5. **Suggest:** Concrete fixes, not just problems
6. **Quantify:** Confidence and severity levels
7. **Summarize:** Overall statistics

### Confidence Calibration

**Report High Confidence when:**
- Clear language violation
- Guaranteed runtime error
- Well-documented bug pattern
- No reasonable alternative interpretation

**Report Medium Confidence when:**
- Suspicious but context-dependent
- Likely bug but could be intentional
- Requires domain knowledge
- Multiple interpretations possible

**Report Low Confidence when:**
- Unusual but possibly valid
- Style issue that might hide bug
- Insufficient context
- Language-specific idiom

## Limitations

### What This Skill Can Detect

✅ Null dereferences
✅ Incorrect conditions
✅ Unreachable code
✅ Logic errors
✅ Resource leaks
✅ Type mismatches
✅ Off-by-one errors
✅ Inconsistent state updates

### What This Skill Cannot Detect

❌ Concurrency bugs (race conditions, deadlocks)
❌ Performance issues (without profiling)
❌ Security vulnerabilities (requires specialized analysis)
❌ Design flaws (architectural issues)
❌ Business logic errors (requires domain knowledge)
❌ Integration issues (requires runtime context)

### False Positives

Some reported bugs may be intentional:
- Defensive programming patterns
- Language-specific idioms
- Framework conventions
- Performance optimizations

Always verify bugs in context before fixing.

## Resources

- **Detection patterns:** See [detection_patterns.md](references/detection_patterns.md) for comprehensive bug patterns and examples
- **Static analysis tools:** Compare with automated tools (ESLint, PyLint, FindBugs, etc.)
- **Code review best practices:** Guidelines for manual code review

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/static-bug-detector of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • references/detection_patterns.md

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Static Bug Detector next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Static Bug Detector compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Static Bug Detector this skillArabelaTso/Skills-4-SE253—~3.4kAutomated safety check: PassApache-2.0
Codexqa Rootcause Analyzeropenqa-cn/codexqa152—~2.6kAutomated safety check: PassApache-2.0
New Rule for sonar-javaSonarSource/sonar-java1.2k—~833Automated safety check: PassCustom licence
Golang Continuous Integrationsamber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT
Arandu Doctor Findingsarandu-io/arandu281—~1.2kAutomated safety check: PassMIT
Golang Continuous Integrationcontext-labs/whip1.1k—~3.5kAutomated safety check: PassMIT

Similar skills

  • Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.

    152 GitHub stars~2.6k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • New Rule for sonar-java

    SonarSource/sonar-java

    Official

    Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

    1.2k GitHub stars~833 tokensUpdated today
    DevelopmentAuto-check passed
  • Golang Continuous Integration

    samber/cc-skills-golang

    GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

    3.4k GitHub stars~3.7k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Arandu Doctor Findings

    arandu-io/arandu

    Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to.

    281 GitHub stars~1.2k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

    1.1k GitHub stars~3.5k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Fix

    BUZZARDGTA/Session-Sniffer

    Diagnose and fix Session Sniffer bugs, errors, tracebacks, logs, lint failures, static-analysis findings, test failures, and IDE-reported problems.

    104 GitHub stars~2.7k tokensUpdated today
    DevelopmentAuto-check passed

More from ArabelaTso/Skills-4-SE

All 150 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Static Bug Detector

What does Static Bug Detector do?

Analyze source code statically to detect potential functional bugs including null dereferences, incorrect condition checks, unreachable code, inconsistent state updates, logic errors, resource…. Static Bug Detector is an agent skill from ArabelaTso/Skills-4-SE. Analyze source code statically to detect potential functional bugs including null dereferences, incorrect condition checks, unreachable code, inconsistent state updates, logic errors, resource leaks, and type mismatches.

When should I use Static Bug Detector?

Static Bug Detector fits situations like: reviewing code for bugs; performing code audits; the user asks to find bugs; analyze code for problems.

How do I install Static Bug Detector in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill static-bug-detector -a claude-code`. Or copy the skill folder (skills/static-bug-detector in ArabelaTso/Skills-4-SE) into .claude/skills/static-bug-detector in your project. Claude Code loads it when a task matches its description.

How do I install Static Bug Detector in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill static-bug-detector -a codex`. Or copy the skill folder (skills/static-bug-detector in ArabelaTso/Skills-4-SE) into .agents/skills/static-bug-detector in your project. Codex loads it when a task matches its description.

Can I use Static Bug Detector in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill static-bug-detector -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/static-bug-detector, .gemini/skills/static-bug-detector, .github/skills/static-bug-detector and .opencode/skills/static-bug-detector in your project.

What does Static Bug Detector need to run?

SKILL.md names no scripts, command-line tools or credentials: Static Bug Detector is instructions for the agent only. Our summary lists: Python 3.

Does Static Bug Detector access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Static Bug Detector safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Static Bug Detector use?

Static Bug Detector is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Static Bug Detector use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.

What are the alternatives to Static Bug Detector?

Skills that share tags, products or a category with Static Bug Detector: Codexqa Rootcause Analyzer (openqa-cn/codexqa, 152 stars), New Rule for sonar-java (SonarSource/sonar-java, 1.2k stars), Golang Continuous Integration (samber/cc-skills-golang, 3.4k stars) and Arandu Doctor Findings (arandu-io/arandu, 281 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Static Bug Detector?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.