Agent skill

Bug Bash Campaign

by boardsesh in boardsesh/boardsesh

Run a multi-agent bug bash — pick a batch of open bugs by priority label, claim them, investigate then implement via subagents, pair adversarial reviews, and shepherd every PR to ready-for-review…

Apache-2.0Auto-check passedAgent Workflows

Install Bug Bash Campaign

skills CLI
$ npx skills add boardsesh/boardsesh --skill bug-bash-campaign -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install boardsesh/boardsesh bug-bash-campaign --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/boardsesh/boardsesh.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/bug-bash-campaign .claude/skills/bug-bash-campaign && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bug-bash-campaign
GitHub stars
163
Token cost
~2.4k tokens
SKILL.md length
1,362 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run a multi-agent bug bash — pick a batch of open bugs by priority label, claim them, investigate then implement via subagents, pair adversarial reviews, and shepherd every PR to ready-for-review…

  • Works in 10 steps: Pick → Claim → Investigate → …
  • Asked to do a bug bash
  • SKILL.md covers 1. Pick, 2. Claim, 3. Investigate and 4. Judge the plan, plus 6 more sections
  • Calls gh, git and claude

What it does

Bug Bash Campaign is an agent skill from boardsesh/boardsesh. Run a multi-agent bug bash — pick a batch of open bugs by priority label, claim them, investigate then implement via subagents, pair adversarial reviews, and shepherd every PR to ready-for-review for Marco to merge. Use when asked to "do a bug bash", "pick up N bugs", "run a batch of P1s", "continue the bug loop", or to adopt stale in-flight fix PRs. For from-sentry issues, also follow sentry-issue-campaign. Repo boardsesh/boardsesh.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows. It works with Bash. The licence is Apache-2.0.

When your agent uses it

  • Asked to do a bug bash
  • Run a batch of P1s
  • Continue the bug loop
  • Adopt stale in-flight fix PRs

Example prompts

  • “do a bug bash”
  • “pick up N bugs”
  • “run a batch of P1s”
  • “/bug-bash-campaign”

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Pick
  2. Claim
  3. Investigate
  4. Judge the plan
  5. Implement
  6. PR lifecycle
  7. Review gates
  8. Hand back, never merge
  9. Hazards
  10. Close out

What it can do on your machine

Read from SKILL.md and the folder at commit 93cf9a7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git
    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bug Bash Campaign loads about 2.4k tokens when it runs. Until then it costs about 115 tokens; SKILL.md has 1,362 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~115
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from boardsesh/boardsesh at commit 93cf9a7, republished under its Apache-2.0 licence (© boardsesh). 1,362 words, ~2,426 tokens.

Download SKILL.mdSave it as .claude/skills/bug-bash-campaign/SKILL.md (or your agent's skills folder).
name
bug-bash-campaign
description
Run a multi-agent bug bash — pick a batch of open bugs by priority label, claim them, investigate then implement via subagents, pair adversarial reviews, and shepherd every PR to ready-for-review for Marco to merge. Use when asked to "do a bug bash", "pick up N bugs", "run a batch of P1s", "continue the bug loop", or to adopt stale in-flight fix PRs. For `from-sentry` issues, also follow `sentry-issue-campaign`. Repo boardsesh/boardsesh.

Bug-bash campaign

Turn a batch of open bugs into ready-for-review PRs. The work is orchestration: you pick, claim, delegate, judge, and shepherd. You rarely write the fix yourself, and you never merge.

Name the loop at the start (e.g. bugbash42). The name goes in claim comments, scratch directories and the closing campaign memory.

1. Pick

gh issue list --label bug --state open --limit 200 \
  --json number,title,labels,assignees,createdAt

Order: priority:P0 → P1 → P2 → P3, then newest first within a label, and from-sentry ahead of the rest on ties. Take the batch size the user asked for (default 10). Skip issues assigned to someone else, and skip admin-only work (secret rotation, GitHub settings) since it has to go back to Marco anyway.

Prior-art scan before claiming. A matching fix often exists under a branch name with no issue number in it.

  • gh pr list --state all --limit 200 --json number,title,body and grep the bodies for the issue number. Grepping titles or branch names alone has missed real fixes.
  • gh issue view <n>: a closed event about 1 s after a PR merge is an auto-close, which means the fix already landed.
  • find /tmp ~/projects/boardsesh -maxdepth 1 \( -name 'boardsesh-*' -o -name 'wt-*' \): another loop checked out on this issue has effectively taken it. (find, not ls with globs: zsh aborts on a glob that matches nothing.) Adjust ~/projects/boardsesh to wherever your checkouts live.

If a PR already exists but is unmerged, the job is to get that PR ready, not start over.

2. Claim

gh issue edit <n> --add-assignee @me
gh issue comment <n> --body "🤖 Claimed by bug-batch loop \`<loop>\` (batch <N>, session <id>)"

A claim with no PR after about 10 days has lapsed. Reclaim it with a note. Some parallel loops ignore claims entirely, so commit and push early: a pushed commit survives another loop rewriting your worktree.

3. Investigate

One read-only investigator per issue. Scope the prompt as two-phase up front: "investigate now; implement only after coordinator approval". Never write "PLAN ONLY — do not modify files": the permission classifier binds the agent's whole session to that boundary, and neither a later message nor a fresh implementer spawn can lift it cleanly.

Tell the investigator that these are good answers: already fixed on main, duplicate, cannot reproduce, the ticket misdiagnoses the cause. In one 30-issue campaign, 6 were stale, duplicated or overstated. Require it to check the issue's claims against the code.

Keep prod-DB reads out of subagent prompts. A local dev-DB EXPLAIN is fine. Put prod queries in the PR body as a read-only checklist for Marco.

4. Judge the plan

Read every plan yourself.

  • Solid → spawn the implementer with the plan embedded.
  • Unsure, large, or reframes its own issue → run an adversarial review of the plan first. In moarbugs10000 this found a blocker the author had missed in 4 plans out of 4: an advisory lock that cannot work on a pooled client, a root cause that telemetry contradicted, a cache lock that does not exist, and a rollout step that could not run.

Model by risk: Sonnet for bounded or mechanical work (copy, i18n, tests, small UI). Opus for concurrency, data correctness, security, sync and native code. Pair every implementer with a reviewer.

5. Implement

Worktree per issue, as a sibling of the repo checkout (~/projects/boardsesh/ on the dev box; adjust to wherever your checkouts live), off fresh origin/main:

git fetch origin main
git worktree add -b fix/<issue>-<slug> ~/projects/boardsesh/wt-<issue> origin/main

Never under /tmp or .claude/worktrees/ (the mobile bundle check needs a sibling worktree).

Paste this block into every implementer prompt, replacing <scratchpad> with the absolute path of your session's scratchpad directory (Claude Code names it in the system prompt; subagents share it; with none, use ${TMPDIR:-/tmp}/<loop>) and <issue>/<loop> with real values:

  • Prove each guard fires: revert the fix, watch the test go red, restore, and paste the real red output. A new lint rule or checker needs a deliberately broken fixture.
  • Report any unverified step as unverified. "CI is authoritative for X" is fine; claiming green you did not see is not.
  • Commit before mutating code to test a guard. git checkout -- <file> also throws away uncommitted real work.
  • Scratch files go in <scratchpad>/<issue>-<loop>/ with unique names. The shell has noclobber on, so write files with the Write tool or >|, never bare >. Read the file back right before --body-file, and re-read the published PR body with gh pr view.
  • Run tests in the FOREGROUND with generous timeouts. Do not start background tasks or monitors and wait on them.
  • Local checks are scoped only: vp check on touched files, vp run typecheck:backend|shared|db|mobile, one targeted test file. No full backend suite and no typecheck:web (it runs a Next build); several of those at once exhaust the box's memory. Push a draft and let CI run the full sweep.
  • Read upstream behaviour out of node_modules, not memory. Resolve fingerprint impact with vp exec expo-updates runtimeversion:resolve or the PR's OTA check; never assert it.

Read the diff and the red output yourself before believing a report. If an agent stalls twice, stop resuming it: check git status, validate its edits, and land them from the main session.

Show full SKILL.md (551 more words)Show less

6. PR lifecycle

  • Open as draft; mark ready once CI is green and no review threads are open. A PR stacked on another stays draft until its base lands.
  • The body carries the template's ## Release Notes, ## Test plan (what a tester taps and sees, 1–5 steps) and a ## Risk heading with a separate Risk: N/5 — why line.
  • Title scope must be an allowed conventional-commit scope. commit-lint reads the webhook payload, so a rerun keeps the stale title: fix the title (and amend if needed), then push.
  • Native-fingerprint changes target release/next with a [native-train] title, not main.
  • Conflicts: rebase and git push --force-with-lease without asking. Check with git merge-tree --write-tree origin/main <branch> | grep CONFLICT, since GitHub's mergeable often reads UNKNOWN. A conflicted PR dispatches no CI at all.
  • When many stacked branches fan out CI, cancel every run except Claude Code Review after each push. One PR alone can run CI normally.
  • Codex reviews (from the chatgpt-codex-connector[bot] GitHub App) fire when a draft is marked ready. Work through them.

7. Review gates

  • Fable review for any diff touching BLE (packages/shared/ble-protocol/, packages/mobile/src/lib/ble/, packages/mobile/modules/live-activity/ios/) or any PR that moves the native fingerprint. That means a read-only reviewer subagent with model: "fable" that posts its review on the PR. It is not a person.
  • Visual or rendering changes (board art, hold colours, contrast) need before/after screenshots and a comment tagging @marcodejongh for sign-off.
  • Post review findings onto the PR as soon as they arrive. Marco can merge while a review is still running, and findings batched to the end land against main.
  • A reviewer can be right about the bug and wrong about the mechanism or the fix. Have the implementer verify each finding before acting on it.

8. Hand back, never merge

Marco reviews and merges. A merged PR showing mergedBy=marcodejongh with reviewDecision=REVIEW_REQUIRED is normal here (an author cannot approve their own PR). It does not mean a loop self-merged.

Surface these rather than deciding them:

  • anything that moves the native fingerprint;
  • anything needing a secret, env var or operator action to take effect;
  • anything that mutates stored user data (backfills, dedup migrations), including prod counts it needs first;
  • genuine product forks: post options plus a recommendation on the issue;
  • fixes that are inert until someone acts. Say so plainly.

A follow-up you find at P2 or worse gets a fix PR in the same turn, not just an issue.

9. Hazards

The Sentry skill's "Hazards that cost real time" section covers the backend test-DB lock, load-induced shifting failures, disk and inode exhaustion, squash-merge retargets and parallel PRs in one file. The bug-bash additions:

  • One heavy job at a time on the box. vp check leaves a ~2 GB tsgolint behind (pkill -f tsgolint || true). Don't pair a background job with a separate waiter.
  • vp output cross-contaminates worktrees. Read the paths in a failing log before trusting a red.
  • Resumed worktrees: origin may be ahead of your local branch. Diff both directions before any force-push.
  • Other loops' /tmp checkouts can exhaust inodes (df -i, not df -h). Never delete a checkout you did not create.

10. Close out

Write one campaign memory named after the loop: PRs opened and their state, issues resolved without a PR (already fixed, duplicate, handed back), issues filed on the way, and exactly what is still owed to Marco.

© boardsesh, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/bug-bash-campaign of boardsesh/boardsesh.

Open the folder on GitHubat commit 93cf9a7

Compare with similar skills

Bug Bash Campaign next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bug Bash Campaign compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bug Bash Campaign this skillboardsesh/boardsesh163—~2.4kAutomated safety check: PassApache-2.0
Hook Development for Claude Code Pluginsanthropics/claude-plugins-official38k11 repos~4.1kAutomated safety check: NotesApache-2.0
Plugin Settings Patternanthropics/claude-plugins-official38k7 repos~3kAutomated safety check: PassApache-2.0
Neat-Freak Knowledge CloseoutKKKKhazix/khazix-skills21k—~1.9kAutomated safety check: PassMIT
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Kimi Code DelegationCherryHQ/cherry-studio52k1 repos~504Automated safety check: PassAGPL-3.0

Similar skills

  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 11 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes
  • Plugin Settings Pattern

    anthropics/claude-plugins-official

    Official

    Shows how Claude Code plugins keep per-project settings and state in .claude/plugin-name.local.md files with YAML frontmatter and a markdown body.

    38k GitHub starsUsed in 7 repos~3k tokens
    Agent WorkflowsAuto-check passed
  • Neat-Freak Knowledge Closeout

    KKKKhazix/khazix-skills

    Brings project docs, agent rule files, authorized memory and leftover workspace files back in line with what the code and runtime actually do at the end of a work session.

    21k GitHub stars~1.9k tokensUpdated 6 days ago
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Kimi Code Delegation

    CherryHQ/cherry-studio

    Delegates one bounded repository task to Kimi Code in non-interactive prompt mode and reads back the final result from its JSON event stream.

    52k GitHub starsUsed in 1 repo~504 tokens
    Agent WorkflowsAuto-check passed
  • Official

    Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.

    5.4k GitHub stars~6.8k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from boardsesh/boardsesh

  • Discord Feedback Triage

    boardsesh/boardsesh

    Classify collected Boardsesh Discord messages into GitHub issue decisions — bug, feature, question, noise, or duplicate — deduplicating against the existing tracker.

    163 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Posthog Product Health Audit

    boardsesh/boardsesh

    Mine Boardsesh's PostHog telemetry (error tracking, session recordings, product analytics) with a multi-agent workflow, then file verified, deduplicated, severity-labelled GitHub issues.

    163 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Sentry Issue Campaign

    boardsesh/boardsesh

    Drive Sentry-derived GitHub issues to merged PRs at scale — pick by priority label, self-assign, plan then implement via subagents, pair adversarial reviews, and shepherd every PR to ready-for-review.

    163 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Android Screenshots

    boardsesh/boardsesh

    Capture screenshots of the Boardsesh React Native app (packages/mobile/) running on an Android emulator, driven against Metro with a cached dev-client APK.

    163 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Bug Bash Campaign

What does Bug Bash Campaign do?

Run a multi-agent bug bash — pick a batch of open bugs by priority label, claim them, investigate then implement via subagents, pair adversarial reviews, and shepherd every PR to ready-for-review…. Bug Bash Campaign is an agent skill from boardsesh/boardsesh. Run a multi-agent bug bash — pick a batch of open bugs by priority label, claim them, investigate then implement via subagents, pair adversarial reviews, and shepherd every PR to ready-for-review for Marco to merge.

When should I use Bug Bash Campaign?

Bug Bash Campaign fits situations like: asked to do a bug bash; run a batch of P1s; continue the bug loop; adopt stale in-flight fix PRs.

How do I install Bug Bash Campaign in Claude Code?

Run `npx skills add boardsesh/boardsesh --skill bug-bash-campaign -a claude-code`. Or copy the skill folder (.claude/skills/bug-bash-campaign in boardsesh/boardsesh) into .claude/skills/bug-bash-campaign in your project. Claude Code loads it when a task matches its description.

How do I install Bug Bash Campaign in Codex?

Run `npx skills add boardsesh/boardsesh --skill bug-bash-campaign -a codex`. Or copy the skill folder (.claude/skills/bug-bash-campaign in boardsesh/boardsesh) into .agents/skills/bug-bash-campaign in your project. Codex loads it when a task matches its description.

Can I use Bug Bash Campaign in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add boardsesh/boardsesh --skill bug-bash-campaign -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bug-bash-campaign, .gemini/skills/bug-bash-campaign, .github/skills/bug-bash-campaign and .opencode/skills/bug-bash-campaign in your project.

What does Bug Bash Campaign need to run?

Going by SKILL.md and its folder, Bug Bash Campaign needs the command-line tools its instructions call (gh, git and claude).

Does Bug Bash Campaign access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Bug Bash Campaign safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bug Bash Campaign use?

Bug Bash Campaign is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bug Bash Campaign use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bug Bash Campaign?

Skills that share tags, products or a category with Bug Bash Campaign: Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Plugin Settings Pattern (anthropics/claude-plugins-official, 38k stars), Neat-Freak Knowledge Closeout (KKKKhazix/khazix-skills, 21k stars) and Crush Configuration (charmbracelet/crush, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bug Bash Campaign?

boardsesh (a GitHub organization) maintains it in boardsesh/boardsesh, which has 163 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 8, 2026.

Source: boardsesh/boardsesh on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.