Agent skill

Bug Review

by athola in athola/claude-night-market

Hunts bugs with evidence trails. An agent skill from athola/claude-night-market.

MITAuto-check passedDevelopment

Install Bug Review

skills CLI
$ npx skills add athola/claude-night-market --skill bug-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install athola/claude-night-market bug-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/pensive/skills/bug-review .claude/skills/bug-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bug-review
GitHub stars
341
Token cost
~1.4k tokens
SKILL.md length
489 words
Files
4
Skills in repo
154
Repo updated
First seen
Licence
MIT

At a glance

Hunts bugs with evidence trails. An agent skill from athola/claude-night-market.

  • Works in 6 steps: Detect Languages… → Plan Reproduction (bug-review:repro-plan) → Document Defects… → …
  • Investigating unexpected behavior
  • SKILL.md covers Quick Start, When To Use, When NOT To Use and Required TodoWrite Items, plus 6 more sections
  • Calls pytest, cargo and npm

What it does

Bug Review is an agent skill from athola/claude-night-market. Hunts bugs with evidence trails. Use when investigating unexpected behavior or before merging code with potential hidden defects.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `modules/defect-documentation.md`, `modules/fix-preparation.md` and `modules/language-detection.md`).

It sits in Development, covering Code review. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.

When your agent uses it

  • Investigating unexpected behavior
  • Before merging code with potential hidden defects

Example prompts

  • “Use the bug-review skill to hunt bugs with evidence trails. An agent skill from athola/claude-night-market”
  • “/bug-review”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Detect Languages (bug-review:language-detected)
  2. Plan Reproduction (bug-review:repro-plan)
  3. Document Defects (bug-review:defects-documented)
  4. Prepare Fixes (bug-review:fixes-prepared)
  5. Verification Plan (bug-review:verification-plan)
  6. Verify Findings Are Grounded (bug-review:findings-verified)

What it can do on your machine

Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pytest
    • cargo
    • npm
    • ruff

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bug Review loads about 1.4k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 489 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 489 words, ~1,439 tokens.

Download SKILL.mdSave it as .claude/skills/bug-review/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
bug-review
description
Hunts bugs with evidence trails. Use when investigating unexpected behavior or before merging code with potential hidden defects.
role
library
alwaysApply
false
category
code-review
tags
bugs, defects, debugging, code-quality, fixes, verification
usage_patterns
bug-hunting, defect-documentation, fix-preparation, verification-planning
complexity
intermediate
model_hint
standard
estimated_tokens
450
progressive_loading
true
dependencies
imbue:proof-of-work, imbue:diff-analysis/modules/risk-assessment-framework, imbue:review-core, imbue:structured-output

Bug Review Workflow

Systematic bug identification and fixing with language-specific expertise.

Quick Start

bash
/bug-review

Verification: Run the command with --help flag to verify availability.

When To Use

  • Reviewing code for potential bugs
  • After receiving bug reports
  • Before major releases
  • During security audits
  • Investigating production issues

When NOT To Use

  • Test coverage audit - use test-review instead

Required TodoWrite Items

  1. bug-review:language-detected
  2. bug-review:repro-plan
  3. bug-review:defects-documented
  4. bug-review:fixes-prepared
  5. bug-review:verification-plan
  6. bug-review:findings-verified

Progressive Loading

Load additional context as needed:

  • Language Detection: @include modules/language-detection.md - Manifest heuristics, expertise framing, version constraints
  • Defect Documentation: @include modules/defect-documentation.md - Severity classification, root cause analysis, static analyzers
  • Fix Preparation: @include modules/fix-preparation.md - Minimal patches, idiomatic patterns, test coverage

Workflow

Step 1: Detect Languages (bug-review:language-detected)

Identify dominant languages using manifest files (Cargo.toml → Rust, package.json → Node, etc.).

State expertise persona appropriate for the language ecosystem.

Note version constraints (MSRV, Python versions, Node engines).

Progressive: Load modules/language-detection.md for detailed manifest heuristics.

Step 2: Plan Reproduction (bug-review:repro-plan)

Identify reproduction methods:

  • Unit/integration test suites
  • Fuzzing tools
  • Manual reproduction commands

Document exact commands:

bash
cargo test -p core
pytest tests/test_api.py
npm test -- pkg

Verification: Run pytest -v tests/test_api.py to verify.

Capture blockers and propose mocks when dependencies unavailable.

Step 3: Document Defects (bug-review:defects-documented)

Review code line-by-line, logging each bug with:

  • File:line reference: Precise location
  • Severity: Critical, High, Medium, Low
  • Root cause: Logic error, API misuse, concurrency, resource leak
  • Impact: What breaks and how

Run static analyzers (cargo clippy, ruff check, golangci-lint, eslint).

Use imbue:proof-of-work for reproducible capture.

Progressive: Load modules/defect-documentation.md for classification details and analyzer commands.

Step 4: Prepare Fixes (bug-review:fixes-prepared)

Draft minimal, idiomatic patches using language best practices:

  • Guard clauses (Rust: pattern matching, Python: early returns)
  • Resource cleanup (Go: defer, Python: context managers)
  • Error propagation (Rust: ?, Go: wrapped errors)

Create tests following Red → Green pattern:

  1. Write failing test
  2. Apply minimal fix
  3. Verify test passes

Progressive: Load modules/fix-preparation.md for language-specific patterns and test strategies.

Show full SKILL.md (189 more words)Show less
Step 5: Verification Plan (bug-review:verification-plan)

Execute reproduction steps with fixes applied.

Capture evidence:

  • Test output logs
  • Benchmark comparisons
  • Coverage reports

Document remaining risks using imbue:diff-analysis/modules/risk-assessment-framework.

Assign owners and deadlines for follow-up items.

Step 6: Verify Findings Are Grounded (bug-review:findings-verified)

Write defects to .review/findings.json, run the citation verifier (Skill(imbue:review-core) Step 5), and drop or label UNVERIFIED any the verifier rejects.

Defect Classification (Condensed)

Severity: Critical (crash/data loss) → High (broken features) → Medium (degraded UX) → Low (edge cases)

Root Causes: Logic errors | API misuse | Concurrency issues | Resource leaks | Validation gaps

Output Format

markdown
## Summary
[Brief scope description]

## Defects Found
### [D1] file.rs:142 - Title
- Severity: High
- Anchor: `verbatim source text at file.rs:142`
- Root Cause: Logic error
- Impact: Data corruption possible
- Fix: [description]

## Proposed Fixes
### Fix for D1
[code diff with explanation]

## Test Updates
[new/updated tests with Red → Green verification]

## Evidence
- Commands executed
- Logs and outputs
- External references

Verification: Run pytest -v to verify tests pass.

Best Practices

  1. Evidence-based: Every finding has file:line reference
  2. Reproducible: Clear steps to reproduce each bug
  3. Minimal fixes: Smallest change that fixes the issue
  4. Test coverage: Every fix has corresponding test
  5. Risk awareness: Document remaining risks with severity scoring

Exit Criteria

  • All defects documented with precise references
  • Every defect carries a file:line + verbatim Anchor, and citation_verifier.py confirmed all citations (exit 0) or unverified defects were dropped or labeled UNVERIFIED
  • Fixes prepared with test coverage verified
  • Verification plan includes commands and expected outputs
  • Remaining risks assessed and owners assigned

© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in plugins/pensive/skills/bug-review of athola/claude-night-market.

  • SKILL.md
  • modules/defect-documentation.md
  • modules/fix-preparation.md
  • modules/language-detection.md

Open the folder on GitHubat commit 9f3eb00

Compare with similar skills

Bug Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bug Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bug Review this skillathola/claude-night-market341—~1.4kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Tabularis Local PR ReviewTabularisDB/tabularis5.1k—~1.4kAutomated safety check: PassApache-2.0
MAUI PR Performance Analysisdotnet/maui23k—~2.4kAutomated safety check: PassMIT
Requesting Code ReviewHezaoHezao/poirot2495 repos~1.6kAutomated safety check: PassMIT
Pre-Merge Checkjsmastery-pro/skills1.5k—~1.1kAutomated safety check: NotesMIT

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Tabularis Local PR Review

    TabularisDB/tabularis

    Reviews a Tabularis pull request locally, judging the diff against the repo's rule files, verifying every claim in its description against the code, and running its tests on the real branch.

    5.1k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Interprets pinned managed benchmark evidence for a dotnet/maui pull request and writes a narrative for the performance review workflow, without running or publishing anything.

    23k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Requesting Code Review

    HezaoHezao/poirot

    Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.

    249 GitHub starsUsed in 5 repos~1.6k tokens
    DevelopmentAuto-check passed
  • Pre-Merge Check

    jsmastery-pro/skills

    A gate before merge: verify runs the real app against the spec, and review has a different model do a senior code review, without editing code.

    1.5k GitHub stars~1.1k tokensUpdated 2 mo ago
    DevelopmentAuto-check: notes
  • Verify Candidate PR Fix

    stickerdaniel/linkedin-mcp-server

    Reviews a candidate pull request's diff and tests against its linked issue, with an optional live comparison against a previously captured baseline, without editing, merging or pushing.

    3.8k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed

More from athola/claude-night-market

All 154 skills in this repo
  • Night Market Diagnostics Toolkit

    athola/claude-night-market

    Run and interpret repo diagnostic scripts (ratchets, validators, token stats).

    341 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • Skills Eval

    athola/claude-night-market

    Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.

    341 GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed
  • Agent Teams

    athola/claude-night-market

    Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.

    341 GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check passed
  • Delegation Core

    athola/claude-night-market

    Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).

    341 GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check passed
  • Elegant Code

    athola/claude-night-market

    Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.

    341 GitHub stars~2.1k tokensUpdated 3 days ago
    Auto-check passed
  • Skill Library Mission

    athola/claude-night-market

    Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.

    341 GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed

Questions about Bug Review

What does Bug Review do?

Hunts bugs with evidence trails. An agent skill from athola/claude-night-market. Bug Review is an agent skill from athola/claude-night-market. Hunts bugs with evidence trails.

When should I use Bug Review?

Bug Review fits situations like: investigating unexpected behavior; before merging code with potential hidden defects.

How do I install Bug Review in Claude Code?

Run `npx skills add athola/claude-night-market --skill bug-review -a claude-code`. Or copy the skill folder (plugins/pensive/skills/bug-review in athola/claude-night-market) into .claude/skills/bug-review in your project. Claude Code loads it when a task matches its description.

How do I install Bug Review in Codex?

Run `npx skills add athola/claude-night-market --skill bug-review -a codex`. Or copy the skill folder (plugins/pensive/skills/bug-review in athola/claude-night-market) into .agents/skills/bug-review in your project. Codex loads it when a task matches its description.

Can I use Bug Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill bug-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bug-review, .gemini/skills/bug-review, .github/skills/bug-review and .opencode/skills/bug-review in your project.

What does Bug Review need to run?

Going by SKILL.md and its folder, Bug Review needs the command-line tools its instructions call (pytest, cargo, npm and ruff). Our summary lists: Python 3.

Does Bug Review access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Bug Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bug Review use?

Bug Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bug Review use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bug Review?

Skills that share tags, products or a category with Bug Review: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Tabularis Local PR Review (TabularisDB/tabularis, 5.1k stars), MAUI PR Performance Analysis (dotnet/maui, 23k stars) and Requesting Code Review (HezaoHezao/poirot, 249 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bug Review?

athola (a GitHub user) maintains it in athola/claude-night-market, which has 341 GitHub stars. The repository holds 154 skills in this directory. The repository was last updated on October 6, 2026.

Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.