Agent skill

Audit Exception Safety

by ben-manes in ben-manes/caffeine

Audit exception safety and failure atomicity across all throw sites

Apache-2.0Auto-check passed

Install Audit Exception Safety

skills CLI
$ npx skills add ben-manes/caffeine --skill audit-exception-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ben-manes/caffeine audit-exception-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-exception-safety .claude/skills/audit-exception-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-exception-safety
GitHub stars
18k
Token cost
~633 tokens
SKILL.md length
274 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit exception safety and failure atomicity across all throw sites

  • Works in 5 steps: CacheLoader.load / loadAll / reload → Weigher.weigh → Expiry.expireAfterCreate /… → …
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Exception Safety is an agent skill from ben-manes/caffeine. Audit exception safety and failure atomicity across all throw sites

Its SKILL.md is about 630 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: A high performance caching library for Java. The licence is Apache-2.0.

Example prompts

  • “/audit-exception-safety”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. CacheLoader.load / loadAll / reload
  2. Weigher.weigh
  3. Expiry.expireAfterCreate / expireAfterUpdate / expireAfterRead
  4. Mapping functions passed to compute, computeIfAbsent, merge
  5. RemovalListener.onRemoval / EvictionListener

What it can do on your machine

Read from SKILL.md and the folder at commit e972fb0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Exception Safety loads about 633 tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 274 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~633

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ben-manes/caffeine at commit e972fb0, republished under its Apache-2.0 licence (© ben-manes). 274 words, ~633 tokens.

Download SKILL.mdSave it as .claude/skills/audit-exception-safety/SKILL.md (or your agent's skills folder).
name
audit-exception-safety
description
Audit exception safety and failure atomicity across all throw sites
context
fork
agent
auditor
disable-model-invocation
true

Audit the cache for exception safety defects. For every code path where exceptions can be thrown, determine whether the cache is left consistent.

Assume at least one exception safety bug exists. If your analysis yields zero findings, re-examine catch-commit-rethrow paths — explain specifically why no exception scenario leaves inconsistent state.

Priority #1: catch-commit-rethrow in doComputeIfAbsent and remap. This is the most commonly misunderstood pattern and historically the most fragile. Trace the EXACT sequence of committed mutations, notification delivery, and exception propagation for every exception type.

User-provided code that can throw:

  1. CacheLoader.load / loadAll / reload
  2. Weigher.weigh
  3. Expiry.expireAfterCreate / expireAfterUpdate / expireAfterRead
  4. Mapping functions passed to compute, computeIfAbsent, merge
  5. RemovalListener.onRemoval / EvictionListener

Runtime exceptions: 6. OutOfMemoryError during node/reference allocation 7. StackOverflowError from deep re-entrancy 8. RejectedExecutionException from executor

In the jcache adapter, also trace: CacheWriter.write/writeAll/delete/deleteAll (the spec requires partial-failure bookkeeping), EntryProcessor.process, ExpiryPolicy methods, and Copier/serialization failures in store-by-value mode.

For each throw site:

  1. List every mutation already committed before the throw point.

  2. Determine whether the catch block rolls back or commits.

  3. Check for:

    • Phantom entries: Node in CHM but invisible to eviction/expiration
    • Orphaned references: WeakReference created but node rolled back
    • Counter drift: weightedSize out of sync with actual entries
    • Lost notifications: notifyEviction without notifyRemoval, or vice versa
    • Leaked futures: CompletableFuture never completed
    • Stuck refresh: refresh flag set but never cleared
  4. For catch-commit-rethrow (doComputeIfAbsent, remap), verify:

    • Catches Throwable, not just RuntimeException
    • Committed state is fully consistent
    • Original exception is preserved
  5. For OutOfMemoryError specifically:

    • Can AddTask/UpdateTask OOME orphan a CHM entry?
    • Can WeakKeyReference/WeakValueReference OOME leave half-constructed node?

For each defect: state the throw site, mutations committed, inconsistent state, and a concrete triggering scenario.

© ben-manes, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/audit-exception-safety of ben-manes/caffeine.

Open the folder on GitHubat commit e972fb0

Compare with similar skills

Audit Exception Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Exception Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Exception Safety this skillben-manes/caffeine18k—~633Automated safety check: PassApache-2.0
Compose Atomslobehub/lobehub83k—~2.6kAutomated safety check: PassCustom licence
Python Type Safetywshobson/agents40k—~1.4kAutomated safety check: PassMIT
Logistics Exception Managementaffaan-m/ECC276k4 repos~4.2kAutomated safety check: PassApache-2.0
Factor Of Safety Failure Marginhashgraph-online/awesome-codex-plugins1.3k—~1.9kAutomated safety check: PassApache-2.0
Safety Guardaffaan-m/ECC276k2 repos~554Automated safety check: NotesMIT

Similar skills

  • Compose Atoms

    lobehub/lobehub

    Splits a heavy front-end domain into capability atoms that each host imports separately, sinking state into each atom instead of adding mode or readOnly flags.

    83k GitHub stars~2.6k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Python Type Safety

    wshobson/agents

    Python type safety with type hints, generics, protocols, and strict type checking.

    40k GitHub stars~1.4k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Codified freight-exception handling expertise for shipment delays, damages, losses, shortages, and carrier disputes, with escalation protocols, carrier-specific behaviors by mode, claims procedures…

    276k GitHub starsUsed in 4 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Factor Of Safety Failure Margin

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when planning capacity, redundancy, graceful degradation, or recovery for systems that must keep working under stress — performance budgets, dependency failure handling…

    1.3k GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Safety Guard

    affaan-m/ECC

    Guard against destructive operations with three modes: Careful intercepts dangerous commands (rm -rf, git push --force, DROP TABLE) for confirmation, Freeze locks writes to one directory, and Guard…

    276k GitHub starsUsed in 2 repos~554 tokens
    DevelopmentAuto-check: notes
  • Safety Guard

    affaan-m/ECC

    本番システムでの作業時や、エージェントを自律的に実行する際に破壊的な操作を防ぐためにこのスキルを使用してください. An agent skill from affaan-m/ECC.

    276k GitHub stars~323 tokensUpdated today
    Auto-check: notes

More from ben-manes/caffeine

All 33 skills in this repo
  • Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.

    18k GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Git History Bug Audit

    ben-manes/caffeine

    Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

    18k GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Adversarial Codebase Audit

    ben-manes/caffeine

    Runs a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings.

    18k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check: notes
  • Caffeine Performance Audit

    ben-manes/caffeine

    Audits the Caffeine cache source for hot-path costs such as allocations, contention and memory layout, reporting only findings tied to specific lines.

    18k GitHub stars~559 tokensUpdated yesterday
    Auto-check passed
  • Audit Sibling Divergence

    ben-manes/caffeine

    Compares code paths that should behave the same, such as sync and async cache methods, and requires a concrete scenario where the two observably disagree.

    18k GitHub stars~4.3k tokensUpdated yesterday
    Auto-check: notes
  • Climber Step Minimization

    ben-manes/caffeine

    Prices each step of the window climber algorithm by disabling it in turn, to find steps that no longer earn their keep and branches that no longer fire.

    18k GitHub stars~3k tokensUpdated yesterday
    Auto-check: notes

Questions about Audit Exception Safety

What does Audit Exception Safety do?

Audit exception safety and failure atomicity across all throw sites. Audit Exception Safety is an agent skill from ben-manes/caffeine.

How do I install Audit Exception Safety in Claude Code?

Run `npx skills add ben-manes/caffeine --skill audit-exception-safety -a claude-code`. Or copy the skill folder (.claude/skills/audit-exception-safety in ben-manes/caffeine) into .claude/skills/audit-exception-safety in your project. Claude Code loads it when a task matches its description.

How do I install Audit Exception Safety in Codex?

Run `npx skills add ben-manes/caffeine --skill audit-exception-safety -a codex`. Or copy the skill folder (.claude/skills/audit-exception-safety in ben-manes/caffeine) into .agents/skills/audit-exception-safety in your project. Codex loads it when a task matches its description.

Can I use Audit Exception Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ben-manes/caffeine --skill audit-exception-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-exception-safety, .gemini/skills/audit-exception-safety, .github/skills/audit-exception-safety and .opencode/skills/audit-exception-safety in your project.

What does Audit Exception Safety need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Exception Safety is instructions for the agent only.

Does Audit Exception Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Exception Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Exception Safety use?

Audit Exception Safety is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Exception Safety use?

About 633 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Exception Safety?

Skills that share tags, products or a category with Audit Exception Safety: Compose Atoms (lobehub/lobehub, 83k stars), Python Type Safety (wshobson/agents, 40k stars), Logistics Exception Management (affaan-m/ECC, 276k stars) and Factor Of Safety Failure Margin (hashgraph-online/awesome-codex-plugins, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Exception Safety?

ben-manes (a GitHub user) maintains it in ben-manes/caffeine, which has 17,882 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 9, 2026.

Source: ben-manes/caffeine on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.