Agent skill

QA Find Bugs CLI

by bex-co in bex-co/beancount-io

Hunt bugs in the Beancount.io bea CLI by running real commands against isolated synthetic ledgers, checking output and file effects, reproducing failures, tracing root causes, and deduplicating…

MITAuto-check: notesDevelopment

Install QA Find Bugs CLI

skills CLI
$ npx skills add bex-co/beancount-io --skill qa-find-bugs-cli -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bex-co/beancount-io qa-find-bugs-cli --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bex-co/beancount-io.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/qa-find-bugs-cli .claude/skills/qa-find-bugs-cli && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
qa-find-bugs-cli
GitHub stars
295
Token cost
~2.2k tokens
SKILL.md length
1,156 words
Files
2
Skills in repo
27
Repo updated
First seen
Licence
MIT

At a glance

Hunt bugs in the Beancount.io bea CLI by running real commands against isolated synthetic ledgers, checking output and file effects, reproducing failures, tracing root causes, and deduplicating…

  • A terminal bug hunt
  • SKILL.md covers Prepare an isolated command…, Sweep whole journeys, Hosted journeys and credentials and Reproduce, research, and hand…
  • Calls uv and make; needs BEA_TOKEN and QA_PASSWORD
  • Tasks that involve Accounting and bookkeeping

What it does

QA Find Bugs CLI is an agent skill from bex-co/beancount-io. Hunt bugs in the Beancount.io bea CLI by running real commands against isolated synthetic ledgers, checking output and file effects, reproducing failures, tracing root causes, and deduplicating findings. Use for CLI QA or a terminal bug hunt. Skip ordinary code review, bug implementation, ledger bookkeeping, and browser or native-mobile QA.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `evals/evals.json`).

It sits in Development, covering Accounting and bookkeeping, Debugging and Root cause analysis. The repository describes itself as: 💰 Double-entry bookkeeping made easy — plain-text accounting for humans and AI agents. Polished iOS & Android app built with React Native + Expo. The licence is MIT.

When your agent uses it

  • A terminal bug hunt
  • Tasks that involve Accounting and bookkeeping
  • Tasks that involve Debugging

Example prompts

  • “/qa-find-bugs-cli”

Requirements

  • Python 3
  • A credential in BEA_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 2103ca1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BEA_TOKEN
    • QA_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

QA Find Bugs CLI loads about 2.2k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 1,156 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:82
    Do not assume `cli/.env` exists or load another package's credentials. Browser

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bex-co/beancount-io at commit 2103ca1, republished under its MIT licence (© bex-co). 1,156 words, ~2,236 tokens.

Download SKILL.mdSave it as .claude/skills/qa-find-bugs-cli/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
qa-find-bugs-cli
description
Hunt bugs in the Beancount.io bea CLI by running real commands against isolated synthetic ledgers, checking output and file effects, reproducing failures, tracing root causes, and deduplicating findings. Use for CLI QA or a terminal bug hunt. Skip ordinary code review, bug implementation, ledger bookkeeping, and browser or native-mobile QA.

CLI QA bug hunt

Read the shared QA contract first, then cli/AGENTS.md and the relevant sections of cli/README.md and cli/docs/USAGE.md. Exercise the real bea executable through subprocesses; unit tests and source inspection support a finding but do not replace a CLI journey.

Arguments: optional executable path, journey names, ledger path, server URL, wN, SHIP=1, DRY_RUN=1. Default to this checkout's uv run bea, local synthetic ledgers, and report mode. A server argument selects a hosted target; it does not turn every local journey into a cloud test. DRY_RUN=1 still allows disposable local fixture writes needed to reproduce bugs.

Prepare an isolated command environment

  • Work inside cli/; use uv sync --all-groups if existing dependencies are missing. Record HEAD, dirty files, OS, Python version, executable path and bea --version. For a supplied installed binary, keep its results separate from checkout reproduction: an older release is not evidence HEAD is broken.
  • Discover commands and flags from bea --help and subcommand help before scripting them. Global options precede the command, for example uv run bea --json --file /absolute/path/main.bean list transaction.
  • Create a unique run directory under the gitignored repo-root .tmp/qa-<date>/ and run every command with that as the cwd, so no fixture, export, or import artifact lands in cli/ or the repo root. Set absolute BEA_CONFIG_DIR and XDG_CACHE_HOME paths inside it in the child process environment and set BEA_NO_UPDATE_NOTIFIER=1. Remove inherited BEA_FILE and BEA_TOKEN from local-test children. Do not repurpose HOME or alter the user's shell, credential store, importer memory, or global CLI installation.
  • Use explicit absolute --file paths except when testing discovery. Build small synthetic fixtures with fixed dates, known balances and separate includes; retain a pristine copy for resets. Local disposable writes are part of this QA request. Treat a supplied real ledger as read-only and reproduce mutations in synthetic data. Plugins and importer configs execute Python; inspect them before running, and prefer controlled local fixtures.
  • Capture argument arrays, cwd, non-secret environment overrides, stdin mode, stdout, stderr, exit code, duration, and before/after file contents or hashes. Use bounded subprocess timeouts, closing stdin for unattended cases. Use a PTY for actual interactive journeys; lack of a PTY is a coverage limit. Do not pipe through a command that hides bea's exit status.

Sweep whole journeys

Use selected journey names to narrow this table; otherwise survey the available commands and deepen failures. Report skipped groups and why.

JourneyObservable promise
discovery/initHelp, version, target precedence (--file, BEA_FILE, cwd), paths with spaces/Unicode, missing files, and split-ledger includes work as documented. Init succeeds in a fresh directory; rerunning against an existing target preserves its contents.
directivesAdd then list each relevant directive; check the whole ledger and query the result in a fresh process. Cover balanced/inferred postings, metadata, escaping, date boundaries, --into, and invalid input. Rejected atomic writes leave files unchanged.
batch/importPreview leaves the ledger unchanged; apply persists the expected rows. Repeat import checks deduplication. Cover duplicate policy, malformed rows, and documented partial acceptance. Inspect the result and file diff before retrying any failed write. Use an inspected importer and synthetic bank export.
check/formatValid and deliberately invalid ledgers produce documented diagnostics and exit codes. Formatting preserves meaning and is idempotent; --check and --dry-run do not write. Recursive formatting's partial failures identify affected files.
list/queryFilters compose; limits, ordering and truncation agree with fixture rows. BQL results, empty results, malformed queries, decimal/date serialization and supported exports are correct. Exercise the interactive query shell only with a PTY.
reportsOverview, income statement, balance sheet and trial balance honor periods, intervals and conversion. Compare against fixed-date fixture expectations and independent BQL/Beancount inventories; preserve commodity units, cost/price distinctions and documented sign conventions.
automationHuman and JSON output convey the same supported result. Parse JSON and check stdout/stderr separation, envelope, target and exit category. Compare terminal, redirected stdin, --no-input, and CI behavior; unattended commands must not hang waiting for prompts.
cloudOn the selected server and authorized QA account, exercise status, listing, inspection and applicable auth recovery. Create/clone/delete only scoped disposable resources when authorized, inspect partial or uncertain outcomes before retrying, and verify persistence in another process.
ask/upgradeCheck help and missing-dependency/auth diagnostics locally. Live Ask sends ledger context and may use quota; use synthetic data within existing authorization. upgrade --check uses the network; actual upgrade changes the installation and requires that scope. Never upgrade the user's CLI as a routine QA step.

Use cli/docs/USAGE.md's current JSON exceptions and exit-code table as the contract. For example, ask rejects JSON, login requires interaction, and successful logout/clone need not emit JSON. A nonzero exit can accompany partial batch writes, recursive formatting, or successful remote creation followed by clone failure. Do not classify these documented behaviors as bugs.

Show full SKILL.md (381 more words)Show less

Hosted journeys and credentials

Local journeys need no login. Inspect BEA_API_URL and BEA_DASHBOARD_URL independently; the browser sign-in origin is not the REST origin. Use a user-designated QA token via the child environment or the CLI's real bea cloud login device flow with the isolated configuration directory. Do not assume cli/.env exists or load another package's credentials. Browser cookies from the shared dashboard helper are not CLI tokens. If browser login needs QA_EMAIL/QA_PASSWORD, use the shared credential rules and a verified field, then complete the device flow and check cloud status.

Keep tokens and device authorization codes out of captured transcripts. Never log an entire environment, credential file, authentication response, or raw debug transport. Without credentials, continue local and signed-out cases; mark authenticated cloud and live Ask unverified. Mock HTTP failures may prove local error handling but must be labeled simulations, not server defects.

Reproduce, research, and hand off

Repeat a candidate from pristine fixtures in a fresh process using the same executable and child environment. Check a nearby working control. Distinguish documented usage errors, invalid fixtures, missing optional extras and upstream Beancount semantics from CLI bugs. A hang needs a bounded capture and a check for an intended prompt; a data-loss claim needs before/after evidence.

Trace command registration in src/cli/main.py, behavior in src/cli/commands/, output/errors in src/cli/output.py and errors.py, and the relevant directive, report, auth or config helpers. Read nested guidance before following vendored src/fava/. Hosted commands use the generated REST client and cloud adapters: generated files are evidence, not manual fix targets. Trace server causes under backend package guidance and retain eligible REST/GraphQL/MCP parity in a proposed server fix.

Apply shared root-cause, caller search, board/history dedupe and optional pm/ship steps. In the finding record, replace route/device evidence with executable/version, OS, cwd, exact command and fixture setup, stdin/TTY mode, exit code, separate output streams and file diff. State expected behavior and its documented or independently calculated basis. Include a minimal synthetic reproducer in public filing text so ignored evidence files are not required.

Finish with findings by severity, coverage/skips, dedupe/filing status, and cleanup. Retain sanitized reproducible evidence; remove disposable credentials and stop only processes started by this run. Report remaining test resources. Do not implement fixes unless requested; if requested, add meaningful regression coverage and run make check-all inside cli/ before handoff.

© bex-co, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/qa-find-bugs-cli of bex-co/beancount-io.

  • SKILL.md
  • evals/evals.json

Open the folder on GitHubat commit 2103ca1

Compare with similar skills

QA Find Bugs CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

QA Find Bugs CLI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
QA Find Bugs CLI this skillbex-co/beancount-io295—~2.2kAutomated safety check: NotesMIT
Claudeceptiondivinevideo/divine-mobile266—~1.1kAutomated safety check: PassMIT
OpenLogi macOS Permissions TriageAprilNEA/OpenLogi23k—~2.5kAutomated safety check: NotesApache-2.0
Bug Finder for daisyUIsaadeghi/daisyui43k—~2.3kAutomated safety check: PassMIT
Root Cause Debugginggarrytan/gstack136k—~1.4kAutomated safety check: PassMIT
Graph-Based Bug Tracingtirth8205/code-review-graph32k1 repos~287Automated safety check: PassMIT

Similar skills

  • Claudeception

    divinevideo/divine-mobile

    A skill your agent uses when reviewing what was learned after debugging, workaround discovery, or trial-and-error investigation, and capture it as a dated journal entry under ~/.codex/journal

    266 GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated 4 days ago
    DevelopmentAuto-check: notes
  • Bug Finder for daisyUI

    saadeghi/daisyui

    Investigates suspected bugs in the daisyUI monorepo through read-only analysis, then writes a decision-ready fix plan in tmp/bugs without changing any product code.

    43k GitHub stars~2.3k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Root Cause Debugging

    garrytan/gstack

    Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.

    136k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Graph-Based Bug Tracing

    tirth8205/code-review-graph

    Traces a bug through a code knowledge graph, following callers, callees and execution flow before opening source files, within a small token budget.

    32k GitHub starsUsed in 1 repo~287 tokens
    DevelopmentAuto-check passed
  • Systematic Debugging

    ChrisWiles/claude-code-showcase

    Applies a four-phase debugging routine that finds the root cause of a bug or failing test before any fix is written.

    6.1k GitHub starsUsed in 3 repos~1.2k tokens
    DevelopmentAuto-check passed

More from bex-co/beancount-io

All 27 skills in this repo
  • Beancount Close

    bex-co/beancount-io

    Close an accounting period in a Beancount ledger by reconciling each active account through beancount-reconcile, checking assertions and recurring gaps, reviewing flags, then proposing a commit with…

    295 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Beancount Import

    bex-co/beancount-io

    Import a bank or card CSV, OFX/QFX, or QIF export into an existing Beancount ledger.

    295 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Beancount Importer Author

    bex-co/beancount-io

    Write or repair a reusable Beangulp importer from a sample bank export, with reviewed golden files and a passing test harness.

    295 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Beancount Init

    bex-co/beancount-io

    Scaffold a new Beancount ledger with bea init and validation, with optional Fava browser setup when requested.

    295 GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Beancount Options

    bex-co/beancount-io

    Record a described options trade or lifecycle event as validated Beancount transactions through bea, after review and confirmation.

    295 GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Beancount Reconcile

    bex-co/beancount-io

    Reconcile one Beancount account against a CSV statement or pasted PDF text.

    295 GitHub stars~4.1k tokensUpdated today
    Auto-check passed

Questions about QA Find Bugs CLI

What does QA Find Bugs CLI do?

Hunt bugs in the Beancount.io bea CLI by running real commands against isolated synthetic ledgers, checking output and file effects, reproducing failures, tracing root causes, and deduplicating…. QA Find Bugs CLI is an agent skill from bex-co/beancount-io.io bea CLI by running real commands against isolated synthetic ledgers, checking output and file effects, reproducing failures, tracing root causes, and deduplicating findings.

When should I use QA Find Bugs CLI?

QA Find Bugs CLI fits situations like: A terminal bug hunt; tasks that involve Accounting and bookkeeping; tasks that involve Debugging.

How do I install QA Find Bugs CLI in Claude Code?

Run `npx skills add bex-co/beancount-io --skill qa-find-bugs-cli -a claude-code`. Or copy the skill folder (.agents/skills/qa-find-bugs-cli in bex-co/beancount-io) into .claude/skills/qa-find-bugs-cli in your project. Claude Code loads it when a task matches its description.

How do I install QA Find Bugs CLI in Codex?

Run `npx skills add bex-co/beancount-io --skill qa-find-bugs-cli -a codex`. Or copy the skill folder (.agents/skills/qa-find-bugs-cli in bex-co/beancount-io) into .agents/skills/qa-find-bugs-cli in your project. Codex loads it when a task matches its description.

Can I use QA Find Bugs CLI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bex-co/beancount-io --skill qa-find-bugs-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/qa-find-bugs-cli, .gemini/skills/qa-find-bugs-cli, .github/skills/qa-find-bugs-cli and .opencode/skills/qa-find-bugs-cli in your project.

What does QA Find Bugs CLI need to run?

Going by SKILL.md and its folder, QA Find Bugs CLI needs the command-line tools its instructions call (uv and make) and credentials named BEA_TOKEN and QA_PASSWORD. Our summary lists: Python 3; A credential in BEA_TOKEN.

Does QA Find Bugs CLI access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is QA Find Bugs CLI safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does QA Find Bugs CLI use?

QA Find Bugs CLI is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does QA Find Bugs CLI use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to QA Find Bugs CLI?

Skills that share tags, products or a category with QA Find Bugs CLI: Claudeception (divinevideo/divine-mobile, 266 stars), OpenLogi macOS Permissions Triage (AprilNEA/OpenLogi, 23k stars), Bug Finder for daisyUI (saadeghi/daisyui, 43k stars) and Root Cause Debugging (garrytan/gstack, 136k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains QA Find Bugs CLI?

bex-co (a GitHub organization) maintains it in bex-co/beancount-io, which has 295 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 7, 2026.

Source: bex-co/beancount-io on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.