Agent skill

Szz Bug Introducing Commit Identifier

by ArabelaTso in ArabelaTso/Skills-4-SE

Identifies bug-introducing commits using SZZ-style analysis based on bug-fixing commits, commit history, and code blame information.

Apache-2.0Auto-check passedDevelopment

Install Szz Bug Introducing Commit Identifier

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill szz-bug-introducing-commit-identifier -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE szz-bug-introducing-commit-identifier --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/szz-bug-identifier .claude/skills/szz-bug-introducing-commit-identifier && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
szz-bug-introducing-commit-identifier
GitHub stars
253
Token cost
~1.5k tokens
SKILL.md length
547 words
Files
3 (incl. scripts, references)
Skills in repo
170
Repo updated
First seen
Licence
Apache-2.0

At a glance

Identifies bug-introducing commits using SZZ-style analysis based on bug-fixing commits, commit history, and code blame information.

  • Works in 4 steps: Identify the Bug-Fixing Commit → Run the SZZ Analysis → Interpret Results → …
  • You need to trace bugs back to their origin
  • SKILL.md covers Overview, Workflow, Understanding Confidence Scores and False Positive Filtering, plus 4 more sections
  • Runs Python scripts from its folder; calls python and git

What it does

Szz Bug Introducing Commit Identifier is an agent skill from ArabelaTso/Skills-4-SE. Identifies bug-introducing commits using SZZ-style analysis based on bug-fixing commits, commit history, and code blame information. Use this skill when you need to trace bugs back to their origin, identify which commits introduced bugs, analyze bug-fix commits to find root causes, perform software repository mining for bug analysis, or conduct empirical studies on software defects. Triggers when users ask to find bug-introducing commits, identify when a bug was introduced, trace bug origins, perform SZZ…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/szz_algorithm.md` and `scripts/szz_analyzer.py`).

It sits in Development, covering Debugging and Root cause analysis. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • You need to trace bugs back to their origin
  • Identify which commits introduced bugs
  • Analyze bug-fix commits to find root causes
  • Perform software repository mining for bug analysis

Example prompts

  • “Use the szz-bug-introducing-commit-identifier skill to identify bug-introducing commits using SZZ-style analysis based on bug-fixing commits, commit…”
  • “/szz-bug-introducing-commit-identifier”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Identify the Bug-Fixing Commit
  2. Run the SZZ Analysis
  3. Interpret Results
  4. Manual Verification

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Szz Bug Introducing Commit Identifier loads about 1.5k tokens when it runs, and up to ~2.6k if it reads all its reference files. Until then it costs about 147 tokens; SKILL.md has 547 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~147
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 547 words, ~1,527 tokens.

Download SKILL.mdSave it as .claude/skills/szz-bug-introducing-commit-identifier/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
szz-bug-introducing-commit-identifier
description
Identifies bug-introducing commits using SZZ-style analysis based on bug-fixing commits, commit history, and code blame information. Use this skill when you need to trace bugs back to their origin, identify which commits introduced bugs, analyze bug-fix commits to find root causes, perform software repository mining for bug analysis, or conduct empirical studies on software defects. Triggers when users ask to find bug-introducing commits, identify when a bug was introduced, trace bug origins, perform SZZ analysis, or analyze bug-fixing commits.

SZZ Bug-Introducing Commit Identifier

Overview

This skill performs SZZ (Śliwerski-Zimmermann-Zeller) algorithm analysis to identify bug-introducing commits in git repositories. Given a bug-fixing commit, it traces modified lines back through version history using git blame to find candidate commits that originally introduced the buggy code.

Workflow

1. Identify the Bug-Fixing Commit

Start by identifying the commit that fixes the bug. This can be obtained from:

  • Commit hash provided by the user
  • Issue tracker references (e.g., "fixes #123")
  • Commit message analysis (e.g., "fix:", "bug:")
  • Manual identification by the user
2. Run the SZZ Analysis

Use the provided script to perform the analysis:

bash
python scripts/szz_analyzer.py <fix-commit-hash>

Options:

  • --repo <path>: Specify repository path (default: current directory)
  • --json: Output results in JSON format for programmatic processing
  • --top <n>: Number of top candidates to show (default: 10)

Example:

bash
python scripts/szz_analyzer.py abc123def --repo /path/to/repo --top 5
3. Interpret Results

The script outputs a ranked list of candidate bug-introducing commits with:

  • Commit hash: The candidate commit identifier
  • Author: Who made the commit
  • Date: When the commit was made
  • Message: The commit message
  • Confidence score: Likelihood this commit introduced the bug (0.0-1.0)
  • Reasons: Explanation for why this commit is a candidate
4. Manual Verification

Always manually review the top candidates:

  1. Examine the actual code changes in the candidate commit
  2. Check if the changes are functionally related to the bug
  3. Consider the context and purpose of the changes
  4. Verify against issue tracker history if available

Understanding Confidence Scores

High Confidence (0.8-1.0):

  • Multiple lines from the commit were fixed
  • Commit message doesn't suggest refactoring
  • Functional code changes (not just formatting)

Medium Confidence (0.5-0.8):

  • Single line modified, or
  • Some indicators of refactoring but functional changes present

Low Confidence (0.0-0.5):

  • Commit message suggests refactoring/formatting
  • Only structural changes (imports, comments, whitespace)
  • Likely a false positive

False Positive Filtering

The script automatically filters common false positives:

Automatically Filtered Lines:

  • Empty lines and whitespace-only changes
  • Comment additions/modifications
  • Import/include statements
  • Braces and structural elements

Reduced Confidence for:

  • Commits with refactoring keywords in messages
  • Single-line changes
  • Formatting-related commits

Common Use Cases

Show full SKILL.md (220 more words)Show less
Use Case 1: Bug Root Cause Analysis
User: "Find which commit introduced the bug fixed in commit abc123"
→ Run: python scripts/szz_analyzer.py abc123
→ Review top candidates and examine their changes
Use Case 2: Developer Accountability
User: "Who introduced the authentication bug?"
→ First identify the fix commit
→ Run SZZ analysis
→ Check the author field of top candidates
Use Case 3: Bug Pattern Analysis
User: "Analyze all bug-introducing commits from the last release"
→ Identify all bug-fix commits
→ Run SZZ analysis on each
→ Aggregate results to find patterns
Use Case 4: Empirical Software Engineering Research
User: "Generate dataset of bug-introducing commits for analysis"
→ Run SZZ analysis with --json flag
→ Process JSON output for statistical analysis

Limitations and Considerations

  1. Tangled Changes: If a commit mixes bug-introducing code with unrelated changes, the entire commit is flagged

  2. Refactoring Breaks Chains: Heavy refactoring can make it difficult to trace back to the original introduction

  3. Indirect Bugs: Bugs caused by missing code or incorrect assumptions may not be detected

  4. Multi-Commit Bugs: Bugs introduced across multiple commits may only identify the most recent contributor

  5. False Fixes: If the "fix" commit doesn't actually fix the bug, the analysis will be incorrect

Advanced Usage

Programmatic Integration

Use JSON output for integration with other tools:

python
import subprocess
import json

result = subprocess.run(
    ['python', 'scripts/szz_analyzer.py', 'abc123', '--json'],
    capture_output=True,
    text=True
)
candidates = json.loads(result.stdout)

for candidate in candidates:
    print(f"{candidate['commit_hash']}: {candidate['confidence_score']}")
Batch Analysis

Analyze multiple bug fixes:

bash
for commit in $(git log --grep="fix:" --format="%H"); do
    echo "Analyzing fix: $commit"
    python scripts/szz_analyzer.py $commit --top 3
done

Resources

scripts/szz_analyzer.py

The main analysis script that performs SZZ algorithm implementation. It:

  • Extracts modified lines from bug-fixing commits
  • Uses git blame to trace lines back through history
  • Applies filtering heuristics to reduce false positives
  • Ranks candidates by confidence score
references/szz_algorithm.md

Comprehensive documentation on the SZZ algorithm including:

  • Detailed algorithm steps and theory
  • False positive patterns and filtering strategies
  • Confidence scoring methodology
  • Limitations and best practices
  • Algorithm variants and extensions

Read this reference when you need deeper understanding of the algorithm, want to customize filtering heuristics, or need to explain the methodology to users.

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in skills/szz-bug-identifier of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • references/szz_algorithm.md
  • scripts/szz_analyzer.py

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Szz Bug Introducing Commit Identifier next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Szz Bug Introducing Commit Identifier compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Szz Bug Introducing Commit Identifier this skillArabelaTso/Skills-4-SE253—~1.5kAutomated safety check: PassApache-2.0
OpenLogi macOS Permissions TriageAprilNEA/OpenLogi23k—~2.5kAutomated safety check: NotesApache-2.0
Bug Finder for daisyUIsaadeghi/daisyui43k—~2.3kAutomated safety check: PassMIT
Root Cause Debugginggarrytan/gstack136k—~1.4kAutomated safety check: PassMIT
Graph-Based Bug Tracingtirth8205/code-review-graph32k1 repos~287Automated safety check: PassMIT
Systematic DebuggingChrisWiles/claude-code-showcase6.1k3 repos~1.2kAutomated safety check: PassNone

Similar skills

  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Bug Finder for daisyUI

    saadeghi/daisyui

    Investigates suspected bugs in the daisyUI monorepo through read-only analysis, then writes a decision-ready fix plan in tmp/bugs without changing any product code.

    43k GitHub stars~2.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Root Cause Debugging

    garrytan/gstack

    Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.

    136k GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Graph-Based Bug Tracing

    tirth8205/code-review-graph

    Traces a bug through a code knowledge graph, following callers, callees and execution flow before opening source files, within a small token budget.

    32k GitHub starsUsed in 1 repo~287 tokens
    DevelopmentAuto-check passed
  • Systematic Debugging

    ChrisWiles/claude-code-showcase

    Applies a four-phase debugging routine that finds the root cause of a bug or failing test before any fix is written.

    6.1k GitHub starsUsed in 3 repos~1.2k tokens
    DevelopmentAuto-check passed
  • Debugging and Error Recovery

    addyosmani/agent-skills

    Applies a stop-the-line rule and a step-by-step triage when tests fail, builds break or something stops working, aiming at the root cause instead of guesses.

    103k GitHub starsUsed in 1 repo~2.6k tokens
    DevelopmentAuto-check passed

More from ArabelaTso/Skills-4-SE

All 170 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Szz Bug Introducing Commit Identifier

What does Szz Bug Introducing Commit Identifier do?

Identifies bug-introducing commits using SZZ-style analysis based on bug-fixing commits, commit history, and code blame information. Szz Bug Introducing Commit Identifier is an agent skill from ArabelaTso/Skills-4-SE. Identifies bug-introducing commits using SZZ-style analysis based on bug-fixing commits, commit history, and code blame information.

When should I use Szz Bug Introducing Commit Identifier?

Szz Bug Introducing Commit Identifier fits situations like: you need to trace bugs back to their origin; identify which commits introduced bugs; analyze bug-fix commits to find root causes; perform software repository mining for bug analysis.

How do I install Szz Bug Introducing Commit Identifier in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill szz-bug-introducing-commit-identifier -a claude-code`. Or copy the skill folder (skills/szz-bug-identifier in ArabelaTso/Skills-4-SE) into .claude/skills/szz-bug-introducing-commit-identifier in your project. Claude Code loads it when a task matches its description.

How do I install Szz Bug Introducing Commit Identifier in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill szz-bug-introducing-commit-identifier -a codex`. Or copy the skill folder (skills/szz-bug-identifier in ArabelaTso/Skills-4-SE) into .agents/skills/szz-bug-introducing-commit-identifier in your project. Codex loads it when a task matches its description.

Can I use Szz Bug Introducing Commit Identifier in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill szz-bug-introducing-commit-identifier -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/szz-bug-introducing-commit-identifier, .gemini/skills/szz-bug-introducing-commit-identifier, .github/skills/szz-bug-introducing-commit-identifier and .opencode/skills/szz-bug-introducing-commit-identifier in your project.

What does Szz Bug Introducing Commit Identifier need to run?

Going by SKILL.md and its folder, Szz Bug Introducing Commit Identifier needs Python for the scripts in its folder and the command-line tools its instructions call (python and git). Our summary lists: Python 3.

Does Szz Bug Introducing Commit Identifier access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Szz Bug Introducing Commit Identifier safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Szz Bug Introducing Commit Identifier use?

Szz Bug Introducing Commit Identifier is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Szz Bug Introducing Commit Identifier use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Szz Bug Introducing Commit Identifier?

Skills that share tags, products or a category with Szz Bug Introducing Commit Identifier: OpenLogi macOS Permissions Triage (AprilNEA/OpenLogi, 23k stars), Bug Finder for daisyUI (saadeghi/daisyui, 43k stars), Root Cause Debugging (garrytan/gstack, 136k stars) and Graph-Based Bug Tracing (tirth8205/code-review-graph, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Szz Bug Introducing Commit Identifier?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 170 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.