Agent skill

Bug Hunter

by codexstar69 in codexstar69/bug-hunter

Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects.

MITAuto-check passedDevelopment

Install Bug Hunter

skills CLI
$ npx skills add codexstar69/bug-hunter --skill bug-hunter -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install codexstar69/bug-hunter bug-hunter --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bug-hunter
GitHub stars
519
Token cost
~5k tokens
SKILL.md length
1,848 words
Files
200 (incl. scripts)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects.

  • Works in 12 steps: Parse the request and resolve scope → Preflight → Deterministic triage before model work → …
  • Security audits
  • SKILL.md covers Defaults and public usage, 1. Parse the request and…, 2. Preflight and 3. Deterministic triage before…, plus 12 more sections
  • Runs Shell scripts from its folder; calls node, git and pnpm

What it does

Bug Hunter is an agent skill from codexstar69/bug-hunter. Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects. Uses deterministic risk triage, evidence-bounded retrieval, Hunter/Skeptic/Referee review, optional hybrid verification, and explicit immutable Fixer scope. Scan-only and single-pass by default; complete-coverage loops, edits, autonomous fixes, and commits each require explicit intent. Use for code review, security audits, regression hunting, PR review, and evidence-backed remediation planning in skills-capable…

Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 205 other files, including scripts (for example `.github/ISSUE_TEMPLATE/bug_report.md`, `.github/ISSUE_TEMPLATE/false_positive.md` and `.github/ISSUE_TEMPLATE/feature_request.md`).

It sits in Development, covering Pull requests, Security review and Code review. The repository describes itself as: Adversarial AI bug hunter with auto-fix skill for Claude Code, Cursor, Codex CLI, GitHub Copilot CLI, Kiro CLI, Opencode, Pi Coding Agent, and more. Multi-agent pipeline finds… The licence is MIT.

When your agent uses it

  • Security audits
  • Regression hunting
  • Evidence-backed remediation planning in skills-capable coding agents

Example prompts

  • “/bug-hunter”

Requirements

  • Node.js
  • A Bash shell

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Parse the request and resolve scope
  2. Preflight
  3. Deterministic triage before model work
  4. Optional measurable context
  5. Optional security context
  6. Load roles progressively
  7. Choose execution mode
  8. Evidence and source-integrity invariants
  9. Hunter -> Skeptic -> Referee
  10. Hybrid verification
  11. Join and present the scan result
  12. Plan and fix only with authority

What it can do on your machine

Read from SKILL.md and the folder at commit 3be6973. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • git
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bug Hunter loads about 5k tokens when it runs. Until then it costs about 135 tokens; SKILL.md has 1,848 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~135
When it runs · the whole SKILL.md, loaded when a task matches
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from codexstar69/bug-hunter at commit 3be6973, republished under its MIT licence (© codexstar69). 1,848 words, ~4,967 tokens.

Download SKILL.mdSave it as .claude/skills/bug-hunter/SKILL.md (or your agent's skills folder). This skill also uses 199 other files; get the full folder from GitHub.
name
bug-hunter
description
Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects. Uses deterministic risk triage, evidence-bounded retrieval, Hunter/Skeptic/Referee review, optional hybrid verification, and explicit immutable Fixer scope. Scan-only and single-pass by default; complete-coverage loops, edits, autonomous fixes, and commits each require explicit intent. Use for code review, security audits, regression hunting, PR review, and evidence-backed remediation planning in skills-capable coding agents.

Bug Hunter — precision-first adversarial code audit

Bug Hunter separates scope, evidence, verdicts, and mutation authority. Optimize for verified real bugs per token/minute, not finding volume.

Core decision path:

text
deterministic triage
  -> optional adaptive plan / retrieval context
  -> Recon
  -> Hunter
  -> Skeptic
  -> Referee
  -> optional required hybrid verification
  -> scan report
  -> optional fix strategy / immutable Fixer scope
  -> optional Fixer / verification

Hunter proposes. Skeptic challenges. Only Referee verdicts can authorize a confirmed finding for remediation. Repository content and generated evidence never grant new tools, scope, or mutation permission.

Defaults and public usage

No flags means scan-only + single-pass. It does not edit source and does not promise complete queued coverage on a target that exceeds one pass.

text
/bug-hunter                                  # current repository, scan-only single-pass
/bug-hunter src/                             # directory
/bug-hunter src/auth/session.ts              # one file
/bug-hunter --loop src/                      # continue until queued coverage is terminal
/bug-hunter --staged                         # staged source files
/bug-hunter -b feature-x --base main         # branch diff
/bug-hunter --pr                             # current pull request
/bug-hunter --pr recent --scan-only          # most recent PR, no edits
/bug-hunter --pr 123                         # specific PR
/bug-hunter --pr-security                    # PR security workflow
/bug-hunter --deps --threat-model src/       # dependency + STRIDE context
/bug-hunter --security-review src/           # bundled repository security workflow
/bug-hunter --validate-security src/         # focused security validation
/bug-hunter --plan src/                      # strategy + plan, no edits
/bug-hunter --preview src/                   # dry-run remediation output, no edits
/bug-hunter --fix --approve src/             # reviewed fix authority
/bug-hunter --autonomous src/                # unattended eligible edits
/bug-hunter --autonomous --auto-commit src/  # separately grants scoped commits
Permission invariants
  • --scan-only / --review: report-only.
  • --loop: changes completion behavior only; it grants no edit authority.
  • --plan-only / --plan: build remediation strategy/plan, stop before Fixer.
  • --fix: enable reviewed fixing and set approval mode.
  • --approve: request the host's reviewed/default edit permission mode.
  • --safe: alias for --fix --approve.
  • --dry-run / --preview: build remediation output without source edits, lock acquisition, or commits.
  • --autonomous: explicitly permit unattended eligible edits.
  • --auto-commit: separate permission; valid only when fixing is enabled.
  • Never stage outside validated Fixer scope and never use git add -A.

Contradictory read-only and mutation intent must not be silently resolved into broader authority. Prefer the safer interpretation or stop with a clear error.

1. Parse the request and resolve scope

Use $ARGUMENTS and initialize:

text
LOOP_MODE=false
FIX_MODE=false
APPROVE_MODE=false
AUTONOMOUS_MODE=false
AUTO_COMMIT=false
DRY_RUN_MODE=false
PLAN_ONLY_MODE=false
DEP_SCAN=false
THREAT_MODEL_MODE=false
PR_SECURITY_MODE=false
SECURITY_REVIEW_MODE=false
VALIDATE_SECURITY_MODE=false

Apply public aliases/flags:

  • --loop -> LOOP_MODE=true; --no-loop keeps single-pass behavior.
  • --scan-only or --review -> keep FIX_MODE=false.
  • --fix -> FIX_MODE=true, APPROVE_MODE=true.
  • --approve -> FIX_MODE=true, APPROVE_MODE=true.
  • --safe -> same as --fix --approve.
  • --autonomous -> FIX_MODE=true, AUTONOMOUS_MODE=true, APPROVE_MODE=false.
  • --auto-commit -> AUTO_COMMIT=true; reject unless FIX_MODE=true.
  • --dry-run or --preview -> FIX_MODE=true, DRY_RUN_MODE=true.
  • --plan-only or --plan -> PLAN_ONLY_MODE=true.
  • --deps -> DEP_SCAN=true.
  • --threat-model -> THREAT_MODEL_MODE=true.
  • --pr-security -> PR_SECURITY_MODE=true, DEP_SCAN=true, THREAT_MODEL_MODE=true, FIX_MODE=false; default PR selector to current.
  • --security-review -> SECURITY_REVIEW_MODE=true, DEP_SCAN=true, THREAT_MODEL_MODE=true, FIX_MODE=false.
  • --validate-security -> VALIDATE_SECURITY_MODE=true.
  • --review-pr -> --pr current; bare --pr -> --pr current; --last-pr -> --pr recent.
PR scope

For --pr <current|recent|N> run:

bash
node "$SKILL_DIR/scripts/pr-scope.cjs" resolve "<selector>" \
  --repo-root "$PWD" [--base <base-branch>]

Save the resolver result to .bug-hunter/pr-scope.json and scan the full contents of changedFiles. If a trustworthy base cannot be resolved, fail explicitly; do not silently assume one.

Staged scope

For --staged, resolve with git diff --cached --name-only. Stop cleanly when nothing is staged.

Branch scope

For -b <branch> [--base <base>], resolve <base>...<branch> and scan full contents of the resulting source files. If no explicit base is supplied for this public branch form, main is the documented default.

Path scope

Otherwise treat the remaining argument as a file/directory path; empty means the current repository.

Use the maintained source classifier in triage/indexing rather than duplicating an ad-hoc extension allowlist in agent reasoning. Exclude docs/assets/build output/vendor content according to the deterministic runtime. If no scannable source remains, report that and stop.

2. Preflight

Resolve SKILL_DIR from this SKILL.md when possible. Fallback locations may include agent-specific skill directories for Claude Code, Codex, Cursor, Kiro, Copilot, Windsurf, OpenCode, Factory Droid CLI, and generic ~/.agents/skills.

Before creating run state:

  1. Require Node.js 22+.

  2. Create .bug-hunter/payloads and .bug-hunter/domains.

  3. Verify required role files and runtime helpers exist.

  4. Run the core preflight when possible:

    bash
    node "$SKILL_DIR/scripts/run-bug-hunter.cjs" preflight --skill-dir "$SKILL_DIR"
  5. Documentation lookup is optional. Prefer scripts/doc-lookup.cjs; use the bundled Context7 path as fallback. Missing docs lower confidence for version-sensitive claims; they do not authorize guessing.

  6. Select one supported orchestration backend for the run. Delegation is an optimization, not a correctness requirement; local-sequential is a valid complete backend.

When a delegated backend is used, follow modes/dispatch.md and templates/subagent-wrapper.md. Validate role payloads before launch with scripts/payload-guard.cjs and validate canonical artifacts after completion.

3. Deterministic triage before model work

Run triage after target resolution:

bash
node "$SKILL_DIR/scripts/triage.cjs" scan "<TARGET_PATH>" \
  --output .bug-hunter/triage.json

Use its strategy, fileBudget, scanOrder, riskMap, domains, and needsLoop. Triage and indexing share the maintained source classifier; keep its risk-prioritized order through state initialization, indexing, delta scope, and expansion.

Source-token budget

The runtime builds adaptive chunks from the combined estimated source tokens of the actual assigned files, preserving risk order. Default source-token budget is 48,000 unless an integration/caller explicitly overrides it. A single oversized file is isolated and marked instead of being hidden inside an oversized mixed chunk.

See docs/precision-protocol.md for exact fail-closed evidence invariants.

Single-pass vs loop

If triage reports needsLoop: true and LOOP_MODE=false, warn truthfully:

text
This target exceeds one-pass queued coverage. Single-pass mode is active.
The report may be partial; run `/bug-hunter --loop <path>` for complete queued
coverage.

Do not say that LOOP_MODE=false implies the user passed --no-loop—it is the normal default.

If LOOP_MODE=true, read modes/loop.md (or modes/fix-loop.md when fixing) and use the supported loop driver. Initialize/consult the guarded experiment state as defined there. Do not pretend a loop will continue without an active driver.

4. Optional measurable context

Integrations driving scripts/run-bug-hunter.cjs may provide schema-valid:

  • .bug-hunter/benchmark-report.json;
  • .bug-hunter/adaptive-plan.json (auto, fast, balanced, assurance);
  • .bug-hunter/retrieval-plan.json;
  • exact-hash evidence-cache facts;
  • .bug-hunter/verification-plan.json / verification-report.json.

These are bounded evidence/context policies, not new permissions. Explicit caller source/chunk/token/confidence settings take precedence. An adaptive plan cannot broaden repository scope or grant mutation authority.

Hypothesis-directed retrieval should load mandatory/direct evidence first and admit optional symbols, dependencies, dependents, cross-references, and trust boundaries only while hard budgets remain.

Evidence-cache hits are hints bound to exact source/protocol/role/options/ hypothesis identity. Re-check current assigned source before relying on them.

See docs/world-class-protocol.md for the measurable architecture.

5. Optional security context

Threat model

When THREAT_MODEL_MODE=true, read:

skills/threat-model-generation/SKILL.md

Generate or reuse Bug Hunter-native .bug-hunter/threat-model.md and related security configuration according to that skill. Existing current threat-model context may be reused as read-only evidence.

Dependency evidence

When DEP_SCAN=true, run:

bash
node "$SKILL_DIR/scripts/dep-scan.cjs" \
  --target "<TARGET_PATH>" --output .bug-hunter/dep-findings.json

Supported parsing/reachability is currently for JavaScript/TypeScript projects using npm, pnpm, Yarn, or Bun lockfiles. scanner-unsupported is unresolved, not clean.

Bundled security workflows

Route these flags through their bundled local skills:

  • --pr-security -> skills/commit-security-scan/SKILL.md
  • --security-review -> skills/security-review/SKILL.md
  • --threat-model -> skills/threat-model-generation/SKILL.md
  • --validate-security -> skills/vulnerability-validation/SKILL.md

Security workflow intent alone never grants Fixer authority.

6. Load roles progressively

Canonical role instructions live under skills/; compatibility files under prompts/ are generated copies and are not an independent source of truth.

Load only the role needed for the current phase:

PhaseCanonical instructions
Reconskills/recon/SKILL.md
Hunterskills/hunter/SKILL.md
Skepticskills/skeptic/SKILL.md
Refereeskills/referee/SKILL.md
Fixerskills/fixer/SKILL.md
Documentationskills/doc-lookup/SKILL.md

Calibration examples are progressive, not mandatory context for every assignment. Follow each role skill's instructions: load Hunter/Skeptic examples only for ambiguous/lower-confidence cases or when explicitly useful. Do not spend context on examples for settled cases.

For delegated phases, include only the assigned bugs/files and necessary prior evidence. Do not copy whole merged ledgers into every worker prompt.

7. Choose execution mode

Use triage.strategy as the size/partitioning strategy:

  • single-file -> modes/single-file.md
  • small -> modes/small.md
  • parallel -> modes/parallel.md
  • extended -> modes/extended.md
  • scaled -> modes/scaled.md
  • large-codebase -> modes/large-codebase.md

If the selected backend is local-sequential, use modes/local-sequential.md as the execution implementation while retaining the triage scope/order/budget.

Do not automatically turn a large-codebase request into loop mode. If the user did not request --loop, execute an honest single pass and report partial queued coverage. When --loop is active, combine the size mode with the loop contract.

Extended/scaled/persisted execution should use .bug-hunter/state.json, exact source hashes, bounded retries, and fresh per-attempt output. The composition runner requires a real worker command that writes the requested canonical artifact; there is no no-op worker.

Show full SKILL.md (758 more words)Show less

8. Evidence and source-integrity invariants

These rules are non-negotiable across every mode:

  • Assigned paths are canonicalized through real paths and remain inside the repository.
  • A worker may report findings only for its exact assigned source files.
  • Capture source hashes before dispatch and recheck them immediately before committing findings/fact cards/completion state.
  • Source mutation, deletion, unreadability, or symlink escape fails the affected chunk closed.
  • Resume retains the original source baseline; changed content cannot silently become a new baseline for an interrupted run.
  • Missing/invalid canonical artifacts are failed phases, never clean evidence.
  • Coverage is derived from per-file evidence; a parent chunk marked done cannot manufacture file completion.
  • Duplicate observations preserve the strongest evidence and useful unioned cross-references/security metadata.
  • Findings without completed adversarial review stay unreviewed or manual-review and cannot authorize fixing.

9. Hunter -> Skeptic -> Referee

Hunter

Read assigned production source in risk/retrieval order. Findings require a concrete runtime trigger and repository evidence. Security findings must satisfy the canonical findings schema, including actionable STRIDE/CWE evidence when required. Test files are context-only.

Canonical output: .bug-hunter/hunter-findings.json.

Skeptic

Challenge each finding from current code and relevant cross-references. Verify framework-dependent disprovals against documentation when possible. Generic rate-limit suggestions may be cheap to dismiss, but reachable credential stuffing, OTP/reset abuse, lockout bypass, measurable amplification, and attacker-triggered expensive work receive normal analysis.

Canonical output: .bug-hunter/skeptic.json.

Referee

Referee independently owns final REAL_BUG, NOT_A_BUG, or MANUAL_REVIEW verdicts. Missing/failed Referee review leaves the finding unresolved and non-writable.

Canonical output: .bug-hunter/referee.json.

10. Hybrid verification

When a verification plan is supplied/required, execute it through the bounded hybrid verifier. Checks run as inert argv arrays with repository containment, secret stripping/redaction, output/time budgets, and shell:false semantics.

A required check that fails, times out, or is unavailable makes verification fail closed. Required verification failure prevents Fixer authorization. A passing test/compiler/static check is evidence; it is not proof that unrelated bugs do not exist.

Canonical output: .bug-hunter/verification-report.json.

11. Join and present the scan result

Always preserve canonical Hunter/Referee artifacts and build the joined .bug-hunter/scan-report.json. Render .bug-hunter/report.md as a human view. JSON is the automation source of truth.

Final results must distinguish:

  • confirmed — Referee accepted the finding;
  • dismissed — evidence disproved it;
  • manualReview — a human/wider decision remains;
  • unreviewed — adversarial review did not finish;
  • failed/pending coverage;
  • required-verification failure when applicable.

Do not claim “audit complete”, “full coverage”, or “clean” while the requested scope still has unresolved review, failed coverage, or required-verification failure.

If LOOP_MODE=true, continue according to the loop contract until every queued source file reaches a terminal outcome or an explicit hard blocker/user stop ends the run. If LOOP_MODE=false, report exactly what one pass covered and recommend --loop when full queued coverage is desired.

12. Plan and fix only with authority

If there are confirmed bugs and PLAN_ONLY_MODE=true or FIX_MODE=true, build canonical remediation strategy/plan artifacts. Classify findings before creating executable Fixer work.

Only Referee-confirmed, confidence-eligible, safe-autofix entries in the validated canary/rollout plan may enter immutable Fixer scope. Entries marked manual-review, larger-refactor, architectural-remediation, conflicting, or report-only remain non-writable regardless of severity.

Canonical remediation files include:

  • .bug-hunter/fix-strategy.json
  • .bug-hunter/fix-plan.json
  • .bug-hunter/fixer-scope.json
  • .bug-hunter/fix-report.json

For actual mutation, read modes/fix-pipeline.md and skills/fixer/SKILL.md. Preserve Git/worktree/lock/canary/circuit-breaker/rollback safeguards. Requested worktree isolation must not silently fall back to direct edits. Commit only when AUTO_COMMIT=true, and only approved paths.

If DRY_RUN_MODE=true, stop before edits/lock/commits and report planned output as a preview, not an applied fix.

Canonical artifacts

Important schema-backed artifacts under .bug-hunter/:

ArtifactPurpose
triage.jsondeterministic risk/scope/budget input
adaptive-plan.jsonbounded adaptive context/review policy
recon.jsonarchitecture/trust-boundary context
retrieval-plan.jsonhypothesis-ranked bounded evidence
hunter-findings.jsonHunter claims
skeptic.jsonadversarial challenges
referee.jsonfinal verdicts
verification-report.jsonhybrid verification evidence
scan-report.jsonjoined final machine result
coverage.jsonper-file coverage state
fix-strategy.jsonremediation classifications
fix-plan.jsoncanary/rollout plan
fixer-scope.jsonimmutable mutation boundary
fix-report.jsonremediation/verification/rollback result
benchmark-report.jsonprecision/recall/calibration/stability/cost/latency metrics

Quality and benchmarking

For source development, the full repository gate is:

bash
pnpm quality:world-class

The bundled benchmark fixture validates the measurement/gating contract. It is not independent proof of universal superiority. External claims require unseen repositories, blinded labels, repeated runs, disclosed model/runtime versions, and comparable baselines. See docs/world-class-protocol.md.

Self-test

From a source checkout, the development fixture can be scanned in read-only mode and scored with evals/evaluate-fixture.cjs. The npm runtime may exclude development fixture answers. Use the benchmark gate for deterministic protocol regression rather than copying a historical test-count claim into this skill.

Failure policy

Fail closed for:

  • invalid/missing required canonical artifacts;
  • source-integrity or repository-containment failure;
  • required verification failure;
  • invalid delegated payload;
  • Referee failure for affected findings;
  • immutable Fixer-scope violation;
  • unsafe Git/worktree preservation state.

Recoverable worker failures may retry within configured bounds using fresh attempt outputs. Unrecoverable chunks remain failed/partial and visible.

Never convert unavailable evidence, unsupported scanners, failed review, or failed safety checks into a clean result.

© codexstar69, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 199 other files (scripts) in the repository root of codexstar69/bug-hunter.

  • SKILL.md
  • .github/ISSUE_TEMPLATE/bug_report.md
  • .github/ISSUE_TEMPLATE/false_positive.md
  • .github/ISSUE_TEMPLATE/feature_request.md
  • .github/PULL_REQUEST_TEMPLATE.md
  • .github/workflows/ci.yml
  • .github/workflows/loop-check.yml
  • .github/workflows/publish.yml
  • .gitignore
  • .loop-history/precision-first-2026-08-17/check.sh
  • .loop-history/precision-first-2026-08-17/journal.md
  • .loop-history/precision-first-2026-08-17/progress.md
  • .loop-history/precision-first-2026-08-17/task.md
  • .loop/check.sh
  • .loop/journal.md
  • … and 185 more

Open the folder on GitHubat commit 3be6973

Compare with similar skills

Bug Hunter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bug Hunter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bug Hunter this skillcodexstar69/bug-hunter519—~5kAutomated safety check: PassMIT
Verdaccio Code Reviewverdaccio/verdaccio18k—~853Automated safety check: PassMIT
Code Review with Beads Tasksmaslennikov-ig/claude-code-orchestrator-kit259—~2kAutomated safety check: PassCustom licence
Code Review Specialist (Ukrainian)luongnv89/claude-howto42k—~484Automated safety check: PassMIT
Code Reviewerforyourhealth111-pixel/Vibe-Skills3.6k—~1.4kAutomated safety check: NotesApache-2.0
Reviewsoftspark/ai-toolkit179—~3.1kAutomated safety check: NotesApache-2.0

Similar skills

  • Verdaccio Code Review

    verdaccio/verdaccio

    Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

    18k GitHub stars~853 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review with Beads Tasks

    maslennikov-ig/claude-code-orchestrator-kit

    Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

    259 GitHub stars~2k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed
  • Code review covering security, performance, quality and maintainability, with a fixed report layout and two analysis scripts; the SKILL.md itself is in Ukrainian.

    42k GitHub stars~484 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Code Reviewer

    foryourhealth111-pixel/Vibe-Skills

    Default code-quality route for broad code review, PR review, maintainability, correctness, and regression-risk checks.

    3.6k GitHub stars~1.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Review

    softspark/ai-toolkit

    Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check: notes
  • Codex Code Review

    sd0xdev/sd0x-harness

    Code review using Codex exec. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~9.8k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from codexstar69/bug-hunter

All 11 skills in this repo
  • Commit Security Scan

    codexstar69/bug-hunter

    Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

    519 GitHub stars~629 tokensUpdated 1 mo ago
    Auto-check passed
  • Doc Lookup

    codexstar69/bug-hunter

    Unified documentation lookup for Bug Hunter agents. An agent skill from codexstar69/bug-hunter.

    519 GitHub stars~592 tokensUpdated 1 mo ago
    Auto-check passed
  • Fixer

    codexstar69/bug-hunter

    Surgical code fixer for Bug Hunter. An agent skill from codexstar69/bug-hunter.

    519 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Hunter

    codexstar69/bug-hunter

    Deep behavioral code analysis agent for Bug Hunter. An agent skill from codexstar69/bug-hunter.

    519 GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon

    codexstar69/bug-hunter

    Codebase reconnaissance agent for Bug Hunter. An agent skill from codexstar69/bug-hunter.

    519 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Referee

    codexstar69/bug-hunter

    Final arbiter for Bug Hunter. An agent skill from codexstar69/bug-hunter.

    519 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Bug Hunter

What does Bug Hunter do?

Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects. Bug Hunter is an agent skill from codexstar69/bug-hunter. Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects.

When should I use Bug Hunter?

Bug Hunter fits situations like: security audits; regression hunting; evidence-backed remediation planning in skills-capable coding agents.

How do I install Bug Hunter in Claude Code?

Run `npx skills add codexstar69/bug-hunter --skill bug-hunter -a claude-code`. Or copy the skill folder (the codexstar69/bug-hunter repository) into .claude/skills/bug-hunter in your project. Claude Code loads it when a task matches its description.

How do I install Bug Hunter in Codex?

Run `npx skills add codexstar69/bug-hunter --skill bug-hunter -a codex`. Or copy the skill folder (the codexstar69/bug-hunter repository) into .agents/skills/bug-hunter in your project. Codex loads it when a task matches its description.

Can I use Bug Hunter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add codexstar69/bug-hunter --skill bug-hunter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bug-hunter, .gemini/skills/bug-hunter, .github/skills/bug-hunter and .opencode/skills/bug-hunter in your project.

What does Bug Hunter need to run?

Going by SKILL.md and its folder, Bug Hunter needs a shell for the scripts in its folder and the command-line tools its instructions call (node, git and pnpm). Our summary lists: Node.js; A Bash shell.

Does Bug Hunter access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Bug Hunter safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Bug Hunter use?

Bug Hunter is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bug Hunter use?

About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bug Hunter?

Skills that share tags, products or a category with Bug Hunter: Verdaccio Code Review (verdaccio/verdaccio, 18k stars), Code Review with Beads Tasks (maslennikov-ig/claude-code-orchestrator-kit, 259 stars), Code Review Specialist (Ukrainian) (luongnv89/claude-howto, 42k stars) and Code Reviewer (foryourhealth111-pixel/Vibe-Skills, 3.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bug Hunter?

codexstar69 (a GitHub user) maintains it in codexstar69/bug-hunter, which has 519 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on August 17, 2026.

Source: codexstar69/bug-hunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.