Agent skill

World Bug Opportunity Finder

by digoal in digoal/blog

Search current hot social or industry news, identify visible "world bugs" such as incentive failures, regulatory gaps, information asymmetry, safety risks, and unreasonable value-chain behavior…

GPL-2.0Auto-check passedDevelopment

Install World Bug Opportunity Finder

skills CLI
$ npx skills add digoal/blog --skill world-bug-opportunity-finder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install digoal/blog world-bug-opportunity-finder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/digoal/blog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/world-bug-opportunity-finder .claude/skills/world-bug-opportunity-finder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
world-bug-opportunity-finder
GitHub stars
8.6k
Token cost
~1.9k tokens
SKILL.md length
799 words
Files
2
Skills in repo
98
Repo updated
First seen
Licence
GPL-2.0

At a glance

Search current hot social or industry news, identify visible "world bugs" such as incentive failures, regulatory gaps, information asymmetry, safety risks, and unreasonable value-chain behavior…

  • Works in 6 steps: Define the search scope. → Search current evidence. → Select the strongest "bug". → …
  • The user gives an industry name and asks to find bugs/opportunities from industry news
  • SKILL.md covers Overview, Inputs And Defaults, Workflow and Report Structure, plus 1 more section
  • Reaches w3.org

What it does

World Bug Opportunity Finder is an agent skill from digoal/blog. Search current hot social or industry news, identify visible "world bugs" such as incentive failures, regulatory gaps, information asymmetry, safety risks, and unreasonable value-chain behavior, then propose root-cause fixes and business opportunities in a sourced, diagram-rich Chinese Markdown report saved under the current project's markdown directory. Use when the user gives an industry name and asks to find bugs/opportunities from industry news, or gives no industry and wants hot social-news bug analysis.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Debugging and Root cause analysis. The repository describes itself as: AI,Opensource,Database,Business,Finance,Minds. git clone --depth 1 https://github.com/digoal/blog. The licence is GPL-2.0.

When your agent uses it

  • The user gives an industry name and asks to find bugs/opportunities from industry news
  • Gives no industry and wants hot social-news bug analysis

Example prompts

  • “world bugs”
  • “/world-bug-opportunity-finder”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Define the search scope.
  2. Search current evidence.
  3. Select the strongest "bug".
  4. Analyze the mechanism.
  5. Design solutions.
  6. Write and save the Markdown report.

What it can do on your machine

Read from SKILL.md and the folder at commit ad6fcb7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • w3.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

World Bug Opportunity Finder loads about 1.9k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 799 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from digoal/blog at commit ad6fcb7, republished under its GPL-2.0 licence (© digoal). 799 words, ~1,881 tokens.

Download SKILL.mdSave it as .claude/skills/world-bug-opportunity-finder/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
world-bug-opportunity-finder
description
Search current hot social or industry news, identify visible "world bugs" such as incentive failures, regulatory gaps, information asymmetry, safety risks, and unreasonable value-chain behavior, then propose root-cause fixes and business opportunities in a sourced, diagram-rich Chinese Markdown report saved under the current project's markdown directory. Use when the user gives an industry name and asks to find bugs/opportunities from industry news, or gives no industry and wants hot social-news bug analysis.

World Bug Opportunity Finder

Overview

Use this skill to turn current hot news into a rigorous "找世界 bug" report. The goal is not to moralize after the fact, but to identify why an obviously unreasonable phenomenon can keep happening, who is constrained by which incentives, what can stop it earlier, and whether there is a legitimate business opportunity in solving it.

Default to Chinese output unless the user explicitly asks for another language.

Inputs And Defaults

  • If the user provides an industry, sector, product category, or scenario, search hot news for that scope.
  • If the user provides no scope, default to recent hot social news, especially民生消费、食品安全、教育医疗、住房养老、交通出行、平台治理、公共服务、就业劳动、未成年人保护、环境安全.
  • Use the most recent 7 days for broad social hotspots and the most recent 30 days for industry hotspots unless the user gives another window.
  • If the user gives a specific event, use it as the anchor event and still search adjacent evidence to understand whether it is isolated or structural.

Workflow

  1. Define the search scope.

    • State the scope and date window in working notes or the final response.
    • If the user's industry name is broad, keep it broad unless a narrower sub-sector is necessary to find concrete news; state any narrowing as an assumption.
    • Do not ask for clarification unless the missing detail would materially change the search.
  2. Search current evidence.

    • Browse current web/news sources. Current news is required; if browsing or network access is unavailable, say the report cannot be responsibly produced from current hotspots.
    • For industry scope, search the industry name plus terms such as 热点, 投诉, 监管, 处罚, 曝光, 事故, 乱象, 价格, 质量, 安全, 召回, 供应链, 平台, 维权, policy, regulation, recall, fraud, safety, complaint, enforcement.
    • For social scope, search terms such as 社会热点, 民生热点, 消费曝光, 食品安全, 监管通报, 315, 舆情, 执法, 处罚, 维权.
    • Prefer primary and high-signal sources: regulator notices, official investigations, court/police announcements, government data, company announcements, exchange filings, industry associations, reputable mainstream media, credible consumer-protection platforms, and first-party product/service documents.
    • Avoid basing accusations on short videos, anonymous screenshots, reposts, or single-source rumors. Use them only as leads unless corroborated.
  3. Select the strongest "bug".

    • Treat a bug as a structural unreasonable mechanism, not merely a bad person or one bad company.
    • Look for one or more of these patterns: incentive misalignment, information asymmetry, externalized cost, regulation lag, enforcement blind spot, measurement gaming, supply-chain opacity, captive users, high switching cost, weak accountability, false safety signal, trusted intermediary failure, or market design failure.
    • Rank candidates by evidence strength, public relevance, timeliness, root-cause clarity, preventability, solution feasibility, and whether a normal participant has a rational reason to keep the bad behavior going.
    • If no candidate has enough evidence, report that the evidence is too weak instead of forcing a sensational conclusion.
  4. Analyze the mechanism.

    • Separate facts, inferences, assumptions, and unknowns.
    • Use a five-whys style chain, but stop when the cause is actionable rather than philosophical.
    • Map stakeholders: consumers/users, suppliers, merchants, platforms, regulators, inspectors, local governments, media, insurers, certification bodies, and potential solution providers.
    • Explain why each actor's current incentive can produce the unreasonable outcome.
    • Identify the earliest practical intervention point before public exposure or harm occurs.
  5. Design solutions.

    • Give layered fixes:
      • 0-7 days: immediate containment, disclosure, sampling, consumer guidance, reporting channels, platform takedowns, refunds/recalls, or targeted enforcement.
      • 30-90 days: process changes, third-party testing, traceability, deposits, insurance, procurement rules, rating systems, auditing, data sharing, whistleblower protection, or platform governance.
      • 6-24 months: legal standards, licensing, certification, infrastructure, market mechanism redesign, industry self-discipline, or technology adoption.
    • For business opportunities, include the buyer, payment reason, MVP, first validation metric, distribution channel, regulatory dependency, and risks.
    • Prioritize public-good and legality. Do not propose doxxing, harassment, vigilante enforcement, fake reviews, illegal surveillance, evading regulation, or exploiting victims.
  6. Write and save the Markdown report.

    • Create or reuse markdown/ under the current project.
    • Save as markdown/<YYYYMMDD>-<scope-slug>-world-bug-opportunity.md.
    • Include text plus functional visuals: at least one Mermaid diagram, one inline SVG diagram, and one compact ASCII text map or table when useful.
    • Keep visuals explanatory, mobile-readable, and text-light; do not add decorative graphics.
    • Include a 参考来源 section with source names, publication dates, and links.
    • In the final response, provide the saved absolute path, selected bug, and brief evidence summary.
Show full SKILL.md (107 more words)Show less

Report Structure

Use this structure unless the user requests another shape:

markdown
# <行业/社会热点>: 我看到的一个世界 bug

> 一句话判断: <不合理现象不是偶然,而是某个机制让坏结果变得划算或更容易发生。>

## 这几天发生了什么

<用事实交代热点,不写长篇新闻复述。>

## 打眼一看哪里不合理

<定义 bug: 谁受损,谁获益,为什么正常机制没有及时阻止。>

```text
消费者/用户 -> 看到的表象 -> 真实风险
商家/平台   -> 当前收益   -> 转嫁成本
监管/市场   -> 应该阻止   -> 实际漏点
```

## 这个 bug 为什么会存在

```mermaid
flowchart TD
  A["上游约束/成本压力"] --> B["参与者的理性选择"]
  B --> C["短期收益"]
  C --> D["风险被转嫁给用户/公共系统"]
  D --> E["监管或市场反馈滞后"]
  E --> B
```

<解释利益链、信息链、监管链、证据链。>

## 根因拆解

<区分事实、推断、假设、未知。>

<svg role="img" aria-label="bug root cause map" viewBox="0 0 800 360" xmlns="http://www.w3.org/2000/svg">
  <!-- Use simple labeled boxes/arrows relevant to the actual case. -->
</svg>

## 怎么更快解决

| 层级 | 动作 | 责任方 | 验证指标 |
| --- | --- | --- | --- |
| 0-7天 | <应急措施> | <谁做> | <怎么知道有效> |
| 30-90天 | <机制修复> | <谁做> | <怎么知道有效> |
| 6-24个月 | <制度/基础设施> | <谁做> | <怎么知道有效> |

## 这里有没有商机

<提出1-3个合法、可验证、能从源头降低问题发生率的机会。每个机会写清买单方、MVP、渠道、风险。>

## 还要盯什么

<列出后续验证信号和反证信号。>

## 参考来源

- [来源标题](https://...), 发布日期/访问日期

Quality Bar

  • Use current sources for all news and changeable facts.
  • Cite every specific event, number, accusation, official action, or company-specific claim.
  • Do not fabricate quotes, data, company names, regulatory actions, or consumer cases.
  • Avoid turning the report into outrage content. The value is the mechanism and intervention design.
  • Avoid naming private individuals unless they are public officials, executives, or named in authoritative public sources and the name is necessary.
  • When a claim is not fully verified, label it as "待验证" or "基于现有报道的推断".
  • Do not present investment advice. Business opportunities are product/service hypotheses, not buy/sell recommendations.

© digoal, GPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/world-bug-opportunity-finder of digoal/blog.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit ad6fcb7

Compare with similar skills

World Bug Opportunity Finder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

World Bug Opportunity Finder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
World Bug Opportunity Finder this skilldigoal/blog8.6k—~1.9kAutomated safety check: PassGPL-2.0
OpenLogi macOS Permissions TriageAprilNEA/OpenLogi23k—~2.5kAutomated safety check: NotesApache-2.0
Bug Finder for daisyUIsaadeghi/daisyui43k—~2.3kAutomated safety check: PassMIT
Root Cause Debugginggarrytan/gstack136k—~1.4kAutomated safety check: PassMIT
Graph-Based Bug Tracingtirth8205/code-review-graph32k1 repos~287Automated safety check: PassMIT
Systematic DebuggingChrisWiles/claude-code-showcase6.1k3 repos~1.2kAutomated safety check: PassNone

Similar skills

  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Bug Finder for daisyUI

    saadeghi/daisyui

    Investigates suspected bugs in the daisyUI monorepo through read-only analysis, then writes a decision-ready fix plan in tmp/bugs without changing any product code.

    43k GitHub stars~2.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Root Cause Debugging

    garrytan/gstack

    Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.

    136k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Graph-Based Bug Tracing

    tirth8205/code-review-graph

    Traces a bug through a code knowledge graph, following callers, callees and execution flow before opening source files, within a small token budget.

    32k GitHub starsUsed in 1 repo~287 tokens
    DevelopmentAuto-check passed
  • Systematic Debugging

    ChrisWiles/claude-code-showcase

    Applies a four-phase debugging routine that finds the root cause of a bug or failing test before any fix is written.

    6.1k GitHub starsUsed in 3 repos~1.2k tokens
    DevelopmentAuto-check passed
  • Debugging and Error Recovery

    addyosmani/agent-skills

    Applies a stop-the-line rule and a step-by-step triage when tests fail, builds break or something stops working, aiming at the root cause instead of guesses.

    105k GitHub starsUsed in 1 repo~2.6k tokens
    DevelopmentAuto-check passed

More from digoal/blog

All 98 skills in this repo
  • 三层审查模型,逐段逐句验证文章真伪、证据链与逻辑结构。Use when the user asks to fact-check, verify, audit, or evaluate the credibility of an article, essay, report, opinion piece, social-media post, or any written claim —…

    8.6k GitHub stars~939 tokensUpdated 2 days ago
    Auto-check passed
  • Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core…

    8.6k GitHub stars~4k tokensUpdated 2 days ago
    Auto-check passed
  • Digoal

    digoal/blog

    Portable digital employee distilled from digoal's personal blog for PostgreSQL, PolarDB, DuckDB, AI+database, vector/RAG, database operations, source-code reading, technical content creation…

    8.6k GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • 从论文 PDF 文件或论文 PDF URL 生成通俗易懂、图文并茂、带批判性评估的中文 Markdown 解读,并保存到当前项目的 markdown 目录。Use when the user asks to interpret,精读,解读,summarize,explain,analyze, or write an article from an academic paper PDF…

    8.6k GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Analyze a product from documentation, websites, PDFs, articles, release notes, pricing pages, app listings, reviews, filings, or related links; save separate intermediate analyses from seven roles…

    8.6k GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • Turn a blog post, article, notes, or any source material into a set of vertical poster images — one cover plus several coherent content slides that explain the core points.

    8.6k GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about World Bug Opportunity Finder

What does World Bug Opportunity Finder do?

Search current hot social or industry news, identify visible "world bugs" such as incentive failures, regulatory gaps, information asymmetry, safety risks, and unreasonable value-chain behavior…. World Bug Opportunity Finder is an agent skill from digoal/blog. Search current hot social or industry news, identify visible "world bugs" such as incentive failures, regulatory gaps, information asymmetry, safety risks, and unreasonable value-chain behavior, then propose root-cause fixes and business opportunities in a sourced, diagram-rich Chinese Markdown report saved under the current project's markdown directory.

When should I use World Bug Opportunity Finder?

World Bug Opportunity Finder fits situations like: the user gives an industry name and asks to find bugs/opportunities from industry news; gives no industry and wants hot social-news bug analysis.

How do I install World Bug Opportunity Finder in Claude Code?

Run `npx skills add digoal/blog --skill world-bug-opportunity-finder -a claude-code`. Or copy the skill folder (skills/world-bug-opportunity-finder in digoal/blog) into .claude/skills/world-bug-opportunity-finder in your project. Claude Code loads it when a task matches its description.

How do I install World Bug Opportunity Finder in Codex?

Run `npx skills add digoal/blog --skill world-bug-opportunity-finder -a codex`. Or copy the skill folder (skills/world-bug-opportunity-finder in digoal/blog) into .agents/skills/world-bug-opportunity-finder in your project. Codex loads it when a task matches its description.

Can I use World Bug Opportunity Finder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add digoal/blog --skill world-bug-opportunity-finder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/world-bug-opportunity-finder, .gemini/skills/world-bug-opportunity-finder, .github/skills/world-bug-opportunity-finder and .opencode/skills/world-bug-opportunity-finder in your project.

What does World Bug Opportunity Finder need to run?

SKILL.md names no scripts, command-line tools or credentials: World Bug Opportunity Finder is instructions for the agent only.

Does World Bug Opportunity Finder access the network?

SKILL.md names 1 domain. In commands or code: w3.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is World Bug Opportunity Finder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does World Bug Opportunity Finder use?

World Bug Opportunity Finder is published under the GPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does World Bug Opportunity Finder use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to World Bug Opportunity Finder?

Skills that share tags, products or a category with World Bug Opportunity Finder: OpenLogi macOS Permissions Triage (AprilNEA/OpenLogi, 23k stars), Bug Finder for daisyUI (saadeghi/daisyui, 43k stars), Root Cause Debugging (garrytan/gstack, 136k stars) and Graph-Based Bug Tracing (tirth8205/code-review-graph, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains World Bug Opportunity Finder?

digoal (a GitHub user) maintains it in digoal/blog, which has 8,588 GitHub stars. The repository holds 98 skills in this directory. The repository was last updated on October 9, 2026.

Source: digoal/blog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.