Agent skill

Git History Bug Audit

by ben-manes in ben-manes/caffeine

Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

Apache-2.0Auto-check passedDevelopment

Install Git History Bug Audit

skills CLI
$ npx skills add ben-manes/caffeine --skill audit-temporal-walk -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ben-manes/caffeine audit-temporal-walk --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-temporal-walk .claude/skills/audit-temporal-walk && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-temporal-walk
GitHub stars
18k
Token cost
~3.3k tokens
SKILL.md length
1,290 words
Files
14
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

  • Works in 4 steps: Run python3… → Create one tracked task per selected… → Launch run.py --variants (or --all)… → …
  • Running a final-pass bug audit before a major release
  • SKILL.md covers When invoked interactively, When to run, How to run and Variant walks, plus 5 more sections
  • Runs Python scripts from its folder; calls python3 and claude

What it does

This is a long-running, rarely used audit for the caffeine module. A walker script visits every commit from the project's start to HEAD, asking Claude at each one to flag, resolve or modify entries in a forward-tracked issue database, then verifies surviving issues against current code and writes them as findings. It aims at bugs that snapshot reviews miss: half-fixes, latent bugs paired with a later trigger, and partial refactors.

Run time depends on model and effort and can span many hours, so the walk is resumable from a checkpoint. When invoked interactively, the agent lists the available variants with `run.py --list`, lets you pick any combination, creates a task for each, launches the orchestrator under nohup or tmux and points you to the logs and a combined findings file. Prompt files for per-commit review, deletion, intent and sibling lenses, fix auditing, an invariant ledger and verification sit alongside the Python scripts. It is meant for pre-release or occasional baseline audits, not routine pre-commit review.

When your agent uses it

  • Running a final-pass bug audit before a major release
  • Catching half-fixes after a long run of refactors
  • Taking a baseline audit of a module's history every few months

Example prompts

  • “Start the temporal walk audit and let me pick which variants to run.”
  • “Resume the history audit from its last checkpoint.”
  • “Show me the combined findings from the finished audit run.”

Requirements

  • Python 3
  • The `claude` CLI
  • tmux or nohup so the multi-hour run survives the session

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Run python3 .claude/skills/audit-temporal-walk/run.py --list and show the
  2. Create one tracked task per selected variant so progress is visible.
  3. Launch run.py --variants (or --all) under nohup/tmux — the
  4. Point the user at the live logs and the combined findings-ALL.md.

What it can do on your machine

Read from SKILL.md and the folder at commit e972fb0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Git History Bug Audit loads about 3.3k tokens when it runs. Until then it costs about 133 tokens; SKILL.md has 1,290 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~133
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ben-manes/caffeine at commit e972fb0, republished under its Apache-2.0 licence (© ben-manes). 1,290 words, ~3,347 tokens.

Download SKILL.mdSave it as .claude/skills/audit-temporal-walk/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
audit-temporal-walk
description
Heavyweight history-mining bug audit. Walks the caffeine module's git history chronologically (oldest to HEAD), maintains a forward-tracked issue database, and surfaces concerns introduced by past commits that were never resolved. Catches bugs that snapshot mining cannot — half-fixes invisible from current state, latent+trigger pairs across multi-commit interactions, and partial refactors. Slow (model/effort-dependent; ~24h on Opus + max effort) and rare-run (every several months or before a major release).
disable-model-invocation
true

Audit: Temporal Walk

This is a long-running CLI tool. It walks every commit affecting the caffeine module from project inception to HEAD, asking Claude per commit to flag/resolve/modify a forward-tracked issue database. Issues that survive to HEAD are verified against current code and emitted as detail.dev-format findings.

The default walk is one of several variants (see "Variant walks" below). The variants are not run automatically by the default walk — so they are easy to forget. The orchestrator (run.py) exists to make that impossible.

When invoked interactively

When the user runs /audit-temporal-walk, do NOT silently start the default walk. Instead, present the full battery so nothing is forgotten, then launch the orchestrator:

  1. Run python3 .claude/skills/audit-temporal-walk/run.py --list and show the variants with AskUserQuestion (multi-select; default to all). This menu is the reminder — the user consciously picks the battery each time.
  2. Create one tracked task per selected variant so progress is visible.
  3. Launch run.py --variants <chosen> (or --all) under nohup/tmux — the battery is multi-hour and must survive the session. Suggest the strongest model and --effort max for a quality-critical run.
  4. Point the user at the live logs and the combined findings-ALL.md.

When to run

  • Before a major release, as a final-pass audit
  • After a long sequence of refactors, to catch half-fixes
  • Once per several months as a baseline audit
  • Not for routine pre-commit review (use /review-change for that)

How to run

The walker uses the claude CLI's default model (the session's current model) unless --model is passed. For a heavyweight rare-run audit, prefer running it in a session on the strongest model available.

bash
# Walk (long-running; safe to interrupt — resumable):
python3 .claude/skills/audit-temporal-walk/walker.py

# In tmux/nohup for multi-hour reliability (the redirect needs the dir to exist):
mkdir -p .local/audits/$AUDIT_MODEL/audit-temporal-walk-<module>
nohup python3 .claude/skills/audit-temporal-walk/walker.py \
  > .local/audits/$AUDIT_MODEL/audit-temporal-walk-<module>/walk.log 2>&1 &

# Process N commits then stop cleanly (useful for chunked runs):
python3 .claude/skills/audit-temporal-walk/walker.py --max-commits 200

# Disable inner-model tool access (faster, less accurate — see Design notes):
python3 .claude/skills/audit-temporal-walk/walker.py --no-tools

# Inspect state without running:
python3 .claude/skills/audit-temporal-walk/walker.py --summary

# After the walk completes, verify surviving issues against HEAD
# (default --min-confidence=low verifies every survivor):
python3 .claude/skills/audit-temporal-walk/verify.py

# Read the verified findings:
cat .local/audits/$AUDIT_MODEL/audit-temporal-walk-<module>/findings.md

Wall clock depends on model and effort and is dominated by model latency: roughly 8-14 hours on a mid-tier config, and ~24 hours on Opus + max effort (the recommended quality-critical config) for the full caffeine module (~760 commits). Tool-enabled mode (default) adds modest overhead from per-commit Read/Grep round-trips. Resumable from checkpoint after quota exhaustion or interruption.

Variant walks

The default run is a broad bug hunt over caffeine/src/main. The same engine drives several focused variants — each is a separate full (or filtered) walk with its own multi-hour cost, not an addition to the main run. --run-name gives each one a disjoint state-<name>.json / log-<name>/ / worktree-<name>/ so they don't clobber the main walk and can run concurrently. Verify a variant with the matching --run-name (and WALKER_SCOPE for the test walk).

run.py runs a selected set of variants sequentially (walk + verify each), then aggregates every findings-<name>.md into one findings-ALL.md with a summary table. It is resumable: each variant is checkpointed independently, so re-running picks up where it stopped and skips finished variants cheaply. This is the entry point to prefer — one command runs everything and reports on it.

bash
R=.claude/skills/audit-temporal-walk/run.py
python3 $R --list                       # show the battery
mkdir -p .local/audits/$AUDIT_MODEL/audit-temporal-walk-caffeine
nohup python3 $R --all --effort max \   # whole battery, quality config, in tmux/nohup
  > .local/audits/$AUDIT_MODEL/audit-temporal-walk-caffeine/battery.log 2>&1 &
python3 $R --variants fix-audit,lens-sibling   # a chosen subset
python3 $R --all --report-only          # just rebuild findings-ALL.md

Sequential is deliberate: the variants are independent and --run-name makes them parallel-safe, but running one at a time matches the one-active-script discipline and avoids hammering quota — there is no quality gain from parallelism (sharpness is per-prompt, not per-schedule).

Individual variants (focused one-offs)

To run or resume a single variant directly:

bash
W=.claude/skills/audit-temporal-walk
SCOPE_TEST=caffeine/src/test/java/com/github/benmanes/caffeine/cache/

# (#2) Diff-shape lenses — main scope, one concentrated question each.
#      Run individually; sharpness is the point. Three separate walks.
python3 $W/walker.py --prompt $W/lens-deletion.txt --run-name lens-deletion
python3 $W/walker.py --prompt $W/lens-sibling.txt  --run-name lens-sibling
python3 $W/walker.py --prompt $W/lens-intent.txt   --run-name lens-intent
python3 $W/verify.py --run-name lens-deletion        # etc. per lens

# (#4) Fix-commit walk — only commits whose message looks like a fix
#      (~39% of history). Pass the SAME --grep on every resume.
python3 $W/walker.py --prompt $W/fix-audit.txt --run-name fix-audit \
  --grep 'fix|bug|regression|NPE|race|leak|incorrect|wrong|revert'
python3 $W/verify.py --run-name fix-audit

# (#1) Test-history walk — coverage-regression hunt over the TEST tree.
#      The test scope routes to a disjoint  ...-caffeine-test/  reports dir.
#      Pass WALKER_SCOPE to verify.py too.
WALKER_SCOPE=$SCOPE_TEST python3 $W/walker.py \
  --prompt $W/test-walk.txt --run-name coverage
WALKER_SCOPE=$SCOPE_TEST python3 $W/verify.py --run-name coverage

# (#3) Invariant ledger — carries load-bearing assumptions forward and flags a
#      distant commit that violates one. Violations materialize as issues, so
#      verify/findings work unchanged. Full re-walk (the ledger builds from
#      genesis; it can't be backfilled onto the main run).
python3 $W/walker.py --prompt $W/invariant-ledger.txt --run-name invariants
python3 $W/verify.py --run-name invariants

All variants share the resolved/modified/new finding schema and emit findings-<name>.md. The invariant ledger additionally tracks establish/violate/retire in state-<name>.json (see --summary's "Invariants by status" line); a violation is also written as a normal issue so it flows through verification like any other finding.

What the walker does

For each substantive commit (skipping doc/style/dep-bump only), the walker:

  1. Checks out the commit into a managed detached worktree under .local/audits/<model>/audit-temporal-walk-<module>/worktree/
  2. Invokes claude -p with cwd=worktree and --tools "Read,Glob,Grep", so the inner model can verify hypotheses against the codebase at that commit's state, not HEAD
  3. Shows the commit's diff (scoped to the configured module) and the currently-open tracked issues whose files this commit touches

Claude returns deltas: which open issues this commit resolves, which it modifies (e.g., a contract change makes the issue more dangerous), and any new concerns the commit introduces. Each new concern requires a concrete bug witness — the input or scenario that exposes the failure, expressed strongly enough that a developer could write a failing unit test directly from it.

The pattern catalog and design-priors in per-commit.txt are tuned to caffeine's bug history (operator-order in halving formulas, sibling divergence between sync/async paths, missing lifecycle guards, etc.) and caffeine's documented intentional patterns (lossy buffers, best-effort refresh, async-listener semantics).

Show full SKILL.md (577 more words)Show less

What the verifier does

After the walk, verify.py reads each surviving open issue, grounds it against current HEAD code (file-grep ranks files by symbol-match-count to find code that has moved/renamed since introduction), and asks Claude whether the bug witness still applies. Verdicts: still_exists, implicitly_resolved, false_positive. The verifier prompt includes .claude/docs/design-decisions.md and cross_model_audit_results.md as filter sources.

An interrupted verify (quota/CLI error) records the unreached issues as error and retries them on the next resume — verify.py skips non-error verdicts but re-attempts errored ones. When any error remains, verify.py prints an "INCOMPLETE VERIFY" warning, marks the finding count PROVISIONAL in findings-<name>.md (and ⚠️+N? in findings-ALL.md), and exits 3 so a partial verify isn't mistaken for a complete one. A verify is only truly done when its verified-<name>.json has zero error verdicts.

Output is a detail.dev-format markdown report with full commit lineage already attached to each finding.

Output

The output directory is .local/audits/<model>/audit-temporal-walk-<module>/ (see .claude/docs/audit-output.md) — export AUDIT_MODEL with your own short model id before launching, since a shell-run walk cannot know it. audit_paths.reports_dir prefers an existing tree for the module, so a walk resumed the next day still finds its state.json. The <module> suffix is auto-derived from WALKER_SCOPE: the first path segment (the module name) plus a -test discriminator when the scope is a test tree. So caffeine/src/main/... writes to …/audit-temporal-walk-caffeine/, caffeine/src/test/... to audit-temporal-walk-caffeine-test/, jcache to audit-temporal-walk-jcache/, etc. All outputs are gitignored via .local/:

  • state.json — walker's issue database (and the invariant ledger, when used)
  • verified.json — per-issue verdicts
  • findings.md — detail.dev-format report
  • worktree/ — managed detached worktree used for per-commit snapshots (deleting it is safe; the next walk re-creates it)
  • log/<sha>.raw.json — per-commit raw responses
  • verify-log/<id>.raw.json — per-issue verifier responses

A --run-name <name> variant writes the same set under <name>-suffixed paths in the same module dir: state-<name>.json, verified-<name>.json, findings-<name>.md, log-<name>/, verify-log-<name>/, worktree-<name>/.

After running, the walker's findings should still be reviewed by hand — expect ~30-40% true-positive rate among surviving findings, with the rest being subtle design-intent matches that the priors don't quite cover.

What to do with a finding

For each still_exists finding in findings.md:

  1. Read the lineage to understand why the bug exists
  2. Cross-check against .claude/docs/design-decisions.md and .claude/docs/ruled-out.md (the standing rulings, by module)
  3. Write a failing test that exposes the bug witness
  4. If the test confirms, fix and commit. If the test passes (false positive), add the pattern to ruled-out.md so future audits don't re-raise it.

Design notes

  • Forward-tracked, not snapshot-mined. Catches half-fixes and latent+trigger pairs invisible from current state. See README.md for the design rationale and how this differs from /audit-* snapshot-style audits.
  • Resumable. State is persisted after every commit. Quota exhaustion or interruption leaves the next-commit pointer at the last successful commit; re-running picks up from there.
  • Tools scoped to the commit snapshot. The inner claude -p runs with cwd set to a detached worktree checked out at the commit being analyzed, and tools restricted to Read,Glob,Grep. This lets the model verify hypotheses against surrounding code (callers, sibling implementations, full method bodies outside the diff hunk) without seeing HEAD code from future commits — which would collapse the forward-tracking premise (every "issue" would look already fixed by some later commit). --no-tools falls back to diff-only analysis. --disable-slash-commands is always on.
  • Self-grounding. The verifier prompt requires that quoted code be copied verbatim from the shown HEAD code; verdicts that reference symbols not present in HEAD must return implicitly_resolved. This was load-bearing in early validation: the first verifier run hallucinated a finding citing a nonexistent file, fixed by hardening the grounding rules.

© ben-manes, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files in .claude/skills/audit-temporal-walk of ben-manes/caffeine.

  • SKILL.md
  • README.md
  • audit_paths.py
  • fix-audit.txt
  • invariant-ledger.txt
  • lens-deletion.txt
  • lens-intent.txt
  • lens-sibling.txt
  • per-commit.txt
  • run.py
  • test-walk.txt
  • verify.py
  • verify.txt
  • walker.py

Open the folder on GitHubat commit e972fb0

Compare with similar skills

Git History Bug Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Git History Bug Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Git History Bug Audit this skillben-manes/caffeine18k—~3.3kAutomated safety check: PassApache-2.0
Pypi ReleasealchemiststudiosDOTai/tunacode125—~2.2kAutomated safety check: PassMIT
Build Deploy TroubleshootParesh-Maheshwari/morphe-ai178—~1.1kAutomated safety check: PassGPL-3.0
Targeted Emergency Bug FixVeryGoodOpenSource/vgv-wingspan109—~1.9kAutomated safety check: PassMIT
Debug ProCraftOS-dev/CraftBot392—~931Automated safety check: NotesMIT
Sap Btp Business Application Studiosecondsky/sap-skills462—~2.7kAutomated safety check: PassGPL-3.0

Similar skills

  • Pypi Release

    alchemiststudiosDOTai/tunacode

    This skill should be used when releasing tunacode-cli to PyPI.

    125 GitHub stars~2.2k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Build Deploy Troubleshoot

    Paresh-Maheshwari/morphe-ai

    Build, test, deploy, and troubleshoot Morphe patches — gradle commands, CLI usage, git workflow, common errors and fixes.

    178 GitHub stars~1.1k tokensUpdated 11 days ago
    DevelopmentAuto-check passed
  • Targeted Emergency Bug Fix

    VeryGoodOpenSource/vgv-wingspan

    Applies a minimal fix to an emergency bug through triage, root-cause location, a hotfix branch and a blast-radius check, with tests and review still required.

    109 GitHub stars~1.9k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Debug Pro

    CraftOS-dev/CraftBot

    Advanced debugging assistance and error analysis. An agent skill from CraftOS-dev/CraftBot.

    392 GitHub stars~931 tokensUpdated today
    DevelopmentAuto-check: notes
  • This skill provides comprehensive guidance for SAP Business Application Studio (BAS), the cloud-based IDE on SAP BTP built on Code-OSS.

    462 GitHub stars~2.7k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed

More from ben-manes/caffeine

All 33 skills in this repo
  • Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.

    18k GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Adversarial Codebase Audit

    ben-manes/caffeine

    Runs a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings.

    18k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check: notes
  • Caffeine Performance Audit

    ben-manes/caffeine

    Audits the Caffeine cache source for hot-path costs such as allocations, contention and memory layout, reporting only findings tied to specific lines.

    18k GitHub stars~559 tokensUpdated yesterday
    Auto-check passed
  • Audit Sibling Divergence

    ben-manes/caffeine

    Compares code paths that should behave the same, such as sync and async cache methods, and requires a concrete scenario where the two observably disagree.

    18k GitHub stars~4.3k tokensUpdated yesterday
    Auto-check: notes
  • Climber Step Minimization

    ben-manes/caffeine

    Prices each step of the window climber algorithm by disabling it in turn, to find steps that no longer earn their keep and branches that no longer fire.

    18k GitHub stars~3k tokensUpdated yesterday
    Auto-check: notes
  • Runs three parallel reviewers on a diff or branch, one blind, one design-aware and one matching past bug patterns, then triages their findings.

    18k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check: notes

Categories

Questions about Git History Bug Audit

What does Git History Bug Audit do?

Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings. This is a long-running, rarely used audit for the caffeine module. A walker script visits every commit from the project's start to HEAD, asking Claude at each one to flag, resolve or modify entries in a forward-tracked issue database, then verifies surviving issues against current code and writes them as findings.

When should I use Git History Bug Audit?

Git History Bug Audit fits situations like: running a final-pass bug audit before a major release; catching half-fixes after a long run of refactors; taking a baseline audit of a module's history every few months.

How do I install Git History Bug Audit in Claude Code?

Run `npx skills add ben-manes/caffeine --skill audit-temporal-walk -a claude-code`. Or copy the skill folder (.claude/skills/audit-temporal-walk in ben-manes/caffeine) into .claude/skills/audit-temporal-walk in your project. Claude Code loads it when a task matches its description.

How do I install Git History Bug Audit in Codex?

Run `npx skills add ben-manes/caffeine --skill audit-temporal-walk -a codex`. Or copy the skill folder (.claude/skills/audit-temporal-walk in ben-manes/caffeine) into .agents/skills/audit-temporal-walk in your project. Codex loads it when a task matches its description.

Can I use Git History Bug Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ben-manes/caffeine --skill audit-temporal-walk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-temporal-walk, .gemini/skills/audit-temporal-walk, .github/skills/audit-temporal-walk and .opencode/skills/audit-temporal-walk in your project.

What does Git History Bug Audit need to run?

Going by SKILL.md and its folder, Git History Bug Audit needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and claude). Our summary lists: Python 3; The `claude` CLI; tmux or nohup so the multi-hour run survives the session.

Does Git History Bug Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Git History Bug Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Git History Bug Audit use?

Git History Bug Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Git History Bug Audit use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Git History Bug Audit?

Skills that share tags, products or a category with Git History Bug Audit: Pypi Release (alchemiststudiosDOTai/tunacode, 125 stars), Build Deploy Troubleshoot (Paresh-Maheshwari/morphe-ai, 178 stars), Targeted Emergency Bug Fix (VeryGoodOpenSource/vgv-wingspan, 109 stars) and Debug Pro (CraftOS-dev/CraftBot, 392 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Git History Bug Audit?

ben-manes (a GitHub user) maintains it in ben-manes/caffeine, which has 17,882 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 9, 2026.

Source: ben-manes/caffeine on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.