Agent skill

Bugbash

by av in av/mi

Systematically explores a CLI, API, backend or library to find bugs and edge cases, then writes a report with reproduction evidence for each issue.

No licenceAuto-check passedTesting & QA

Install Bugbash

skills CLI
$ npx skills add av/mi --skill bugbash -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install av/mi bugbash --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/av/mi.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/bugbash .claude/skills/bugbash && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bugbash
GitHub stars
102
Token cost
~1.4k tokens
SKILL.md length
692 words
Files
2
Skills in repo
20
Repo updated
First seen
Licence
None found

At a glance

Systematically explores a CLI, API, backend or library to find bugs and edge cases, then writes a report with reproduction evidence for each issue.

  • Works in 5 steps: Initialize → Orient → Explore → …
  • Testing a new CLI tool before release
  • SKILL.md covers Setup, Workflow and Guidance
  • Calls npm, docker-compose and cargo

What it does

The agent picks a target, such as a CLI binary, an API base URL or a Python package, along with an output directory and an optional scope, then works through initialize, orient, explore and document steps. Initialization creates log and evidence folders and a `report.md` holding the target, date, environment and summary counts by severity, and it builds or starts the software if needed.

Orient maps the surface area into a file: help output for CLIs, OpenAPI specs or routes for APIs, exported modules for libraries. Explore covers happy paths, invalid inputs, missing context such as absent environment variables or config files, and boundary conditions like permission errors and ports already in use, capturing output, errors, exit codes and HTTP status codes at each step. Issues are documented repro-first, with exact commands, inputs, logs and tracebacks. The skill is aimed at non-web interfaces.

When your agent uses it

  • Testing a new CLI tool before release
  • Probing an HTTP API for bad-input handling and error responses
  • Auditing a library's public methods for edge cases
  • Getting a structured bug report with reproduction steps for maintainers

Example prompts

  • “Bugbash ./my-cli and put the report in ./qa-reports.”
  • “Run a bug bash against the API at http://localhost:8080, focusing on the auth middleware.”
  • “Explore this Python package's public functions for crashes and unhelpful error messages.”

Requirements

  • A runnable target such as a CLI binary, API or library

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Initialize
  2. Orient
  3. Explore
  4. Document Issues (Repro-First)
  5. Wrap Up

What it can do on your machine

Read from SKILL.md and the folder at commit 2bf50c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • docker-compose
    • cargo
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bugbash loads about 1.4k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 692 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 692 words (~1,387 tokens).

“Systematically explore a software project, find issues, and produce a report with full reproduction evidence for every finding. This skill applies to CLIs, APIs, Backends, Libraries, and other non-web interfaces.”

— opening of SKILL.md by av
name
bugbash

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in .agents/skills/bugbash of av/mi.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit 2bf50c9

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in av/mi, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Bugbash next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bugbash compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bugbash this skillav/mi102—~1.4kAutomated safety check: PassNone
OpenWork Desktop CDP Driverdifferent-ai/openwork24k—~465Automated safety check: PassCustom licence
Structured Bug ReportsDonchitos/Claude-Code-Game-Studios26k—~2.5kAutomated safety check: NotesMIT
Pipensx Bug Report Triagei3sey/pipensx218—~1.5kAutomated safety check: NotesGPL-3.0
Diff-Driven QASkyvern-AI/skyvern23k—~4.7kAutomated safety check: WarnAGPL-3.0
Bug ReproducerAnastasiyaW/codex-claude-code-config154—~4.1kAutomated safety check: PassMIT

Similar skills

  • OpenWork Desktop CDP Driver

    different-ai/openwork

    Drives a running OpenWork desktop window over CDP from the shell to evaluate JS, take screenshots, start sessions and send prompts for hand checks.

    24k GitHub stars~465 tokensUpdated today
    Testing & QAAuto-check passed
  • Structured Bug Reports

    Donchitos/Claude-Code-Game-Studios

    Turns a description into a structured bug report, or scans code for likely bugs, then verifies and closes reports through four modes.

    26k GitHub stars~2.5k tokensUpdated 8 days ago
    Testing & QAAuto-check: notes
  • Decodes QR-code bug report photos and screenshots from the pipensx app into a log, then triages crashes and update, download or install failures.

    218 GitHub stars~1.5k tokensUpdated 5 days ago
    Testing & QAAuto-check: notes
  • Diff-Driven QA

    Skyvern-AI/skyvern

    Reads your git diff, decides whether the change needs browser QA, API checks or repo tests, runs that validation and reports pass or fail with evidence.

    23k GitHub stars~4.7k tokensUpdated today
    Testing & QAAuto-check: warnings
  • Bug Reproducer

    AnastasiyaW/codex-claude-code-config

    Find likely software bugs in a codebase, rank concrete bug candidates, and prove or reject them with focused regression tests before proposing a fix.

    154 GitHub stars~4.1k tokensUpdated 5 days ago
    Testing & QAAuto-check passed
  • Dough Bug Fixing

    terryyin/lizard

    Resolves a reported discrepancy, defect, or regression by gathering expected versus actual behavior and passing the report into bounded shared execution, or by placing known larger or inconclusive…

    2.5k GitHub stars~3.7k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Writes plain-English integration test specs with verifiable steps and expectations, then runs each one through a subagent that reports pass or fail with logs.

    102 GitHub stars~908 tokensUpdated 11 days ago
    Auto-check passed
  • Anneal

    av/mi

    A skill your agent uses when the user wants to systematically fix AI code slop — duplicated logic, over-engineering, silent error swallowing, convention drift, cargo-cult patterns, and other…

    102 GitHub stars~3.8k tokensUpdated 11 days ago
    Auto-check passed
  • Scans a codebase to tag every fact as draft, spec or implemented based on what the code actually shows, adding missing facts and fixing or removing wrong ones.

    102 GitHub stars~2.8k tokensUpdated 11 days ago
    Auto-check passed
  • Implements every @spec fact from a project's fact sheet in code, tags each one @implemented once done, and reports exactly what is left if it cannot finish.

    102 GitHub stars~1.3k tokensUpdated 11 days ago
    Auto-check passed
  • Works with you to turn draft behavioral facts into precise, implementable spec facts, resolving vague labels, gaps and contradictions one at a time through discussion.

    102 GitHub stars~1.5k tokensUpdated 11 days ago
    Auto-check passed
  • Ideate

    av/mi

    Timeboxed ideation on a topic using propose-and-critique subagent pairs.

    102 GitHub stars~2.8k tokensUpdated 11 days ago
    Auto-check passed

Questions about Bugbash

What does Bugbash do?

Systematically explores a CLI, API, backend or library to find bugs and edge cases, then writes a report with reproduction evidence for each issue. The agent picks a target, such as a CLI binary, an API base URL or a Python package, along with an output directory and an optional scope, then works through initialize, orient, explore and document steps.md` holding the target, date, environment and summary counts by severity, and it builds or starts the software if needed.

When should I use Bugbash?

Bugbash fits situations like: testing a new CLI tool before release; probing an HTTP API for bad-input handling and error responses; auditing a library's public methods for edge cases; getting a structured bug report with reproduction steps for maintainers.

How do I install Bugbash in Claude Code?

Run `npx skills add av/mi --skill bugbash -a claude-code`. Or copy the skill folder (.agents/skills/bugbash in av/mi) into .claude/skills/bugbash in your project. Claude Code loads it when a task matches its description.

How do I install Bugbash in Codex?

Run `npx skills add av/mi --skill bugbash -a codex`. Or copy the skill folder (.agents/skills/bugbash in av/mi) into .agents/skills/bugbash in your project. Codex loads it when a task matches its description.

Can I use Bugbash in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add av/mi --skill bugbash -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bugbash, .gemini/skills/bugbash, .github/skills/bugbash and .opencode/skills/bugbash in your project.

What does Bugbash need to run?

Going by SKILL.md and its folder, Bugbash needs the command-line tools its instructions call (npm, docker-compose, cargo and curl). Our summary lists: A runnable target such as a CLI binary, API or library.

Does Bugbash access the network?

SKILL.md contains no URLs. Its commands use npm and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Bugbash safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bugbash use?

No licence was found for Bugbash or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Bugbash use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bugbash?

Skills that share tags, products or a category with Bugbash: OpenWork Desktop CDP Driver (different-ai/openwork, 24k stars), Structured Bug Reports (Donchitos/Claude-Code-Game-Studios, 26k stars), Pipensx Bug Report Triage (i3sey/pipensx, 218 stars) and Diff-Driven QA (Skyvern-AI/skyvern, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bugbash?

av (a GitHub user) maintains it in av/mi, which has 102 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on September 26, 2026.

Source: av/mi on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.