Agent skill

Tau Papercut Triage

by dpc in dpc/tau

A skill your agent uses when asked to "triage papercuts", review clanker-reported problems, or analyze and clear tau dev papercut reports.

MPL-2.0Auto-check passed

Install Tau Papercut Triage

skills CLI
$ npx skills add dpc/tau --skill tau-papercut-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dpc/tau tau-papercut-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dpc/tau.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/tau-papercut-triage .claude/skills/tau-papercut-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tau-papercut-triage
GitHub stars
105
Token cost
~2.4k tokens
SKILL.md length
1,149 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MPL-2.0

At a glance

A skill your agent uses when asked to "triage papercuts", review clanker-reported problems, or analyze and clear tau dev papercut reports.

  • Works in 4 steps: Load dpc, tau-self-knowledge-debugging,… → Verify the installed interface and build… → Capture one complete authoritative CLI… → …
  • Asked to triage papercuts
  • SKILL.md covers Capture the complete inventory…, Classify evidence, not…, Report and queue before clear and Clear only through supported…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Tau Papercut Triage is an agent skill from dpc/tau. Use when asked to "triage papercuts", review clanker-reported problems, or analyze and clear tau dev papercut reports. Distinguish agent mistakes, recurring environment issues, and Tau defects; queue actionable follow-ups for approval before clearing analyzed reports safely.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Tau Coding Agent - like Pi, but twice as much. The licence is MPL-2.0.

When your agent uses it

  • Asked to triage papercuts
  • Review clanker-reported problems
  • Analyze and clear tau dev papercut reports

Example prompts

  • “triage papercuts”
  • “/tau-papercut-triage”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Load dpc, tau-self-knowledge-debugging, and applicable project instructions.
  2. Verify the installed interface and build rather than assuming flags
  3. Capture one complete authoritative CLI snapshot in an owner-private
  4. Give every report a stable ordinal within that snapshot and preserve its

What it can do on your machine

Read from SKILL.md and the folder at commit d2e1955. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tau Papercut Triage loads about 2.4k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 1,149 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dpc/tau at commit d2e1955, republished under its MPL-2.0 licence (© dpc). 1,149 words, ~2,390 tokens.

Download SKILL.mdSave it as .claude/skills/tau-papercut-triage/SKILL.md (or your agent's skills folder).
name
tau-papercut-triage
description
Use when asked to "triage papercuts", review clanker-reported problems, or analyze and clear tau dev papercut reports. Distinguish agent mistakes, recurring environment issues, and Tau defects; queue actionable follow-ups for approval before clearing analyzed reports safely.
advertise
true

Triage papercuts

Use a senior researcher for this task. Triage is investigation and reporting, not permission to fix code, change configuration, restart sessions, or bypass isolation. Respect any concurrent project update owner.

Capture the complete inventory privately

  1. Load dpc, tau-self-knowledge-debugging, and applicable project instructions. Read the papercut and relevant trust-boundary sections of SECURITY.md. Load dpc-rustgrep before structural Rust lookups, and linked-specs before investigating governed behavior through its specs.

  2. Verify the installed interface and build rather than assuming flags:

    sh
    tau --version
    tau dev papercut --help
    tau dev papercut list --help
    tau dev papercut clear --help
  3. Capture one complete authoritative CLI snapshot in an owner-private directory. Reports contain unredacted model text and may contain secrets. Do not dump raw reports into shared /tmp/public, tickets, or the conversation.

    sh
    umask 077
    private_dir=$(mktemp -d /tmp/tau-papercut-triage-XXXXXXXX)
    tau dev papercut list --markdown > "$private_dir/snapshot.md" &&
      sha256sum "$private_dir/snapshot.md" > "$private_dir/snapshot.sha256"

    Stop if listing fails; do not clear malformed/unreadable data. --state-dir <STATE_DIR> is supported on both list and clear; use the same explicitly selected root for both when overriding the default. This CLI covers the standard std-utils instance, not arbitrary reporter instances.

  4. Give every report a stable ordinal within that snapshot and preserve its timestamp and attribution privately. Count actual report records, not arbitrary Markdown heading matches inside report bodies. If taking plain and Markdown snapshots separately, verify their record sequences agree: each list call takes its own snapshot and reports may arrive between them. Plain output escapes controls but is not a general structured interchange format. Record capture time, first/last report timestamp, count, snapshot hash, CLI build, and inspected source revision.

Classify evidence, not reporter conclusions

Account for every report, including duplicates and multi-symptom reports. Group repeated symptoms into findings but retain an ordinal-to-finding ledger. Repeated reports from one incident are not independent reproductions.

For each finding record category, priority, confidence, recurrence, concrete evidence, disposition, and the smallest useful follow-up:

  • Agent mistake / expected behavior: usually low priority; ignore once explained. Record useful prevention improvements when mistakes recur or have meaningful consequences. A quoting mistake that runs a command or an overly broad cleanup is not harmless merely because the harness behaved correctly.
  • External environment / configured integration: medium priority by default. Distinguish one-off recovery, recurring contention, stale paths/builds, missing tools, configured policy denials, and a fixable integration mismatch. Identify the responsible project or configuration rather than automatically filing a Tau core defect.
  • Tau harness/product defect or suspected defect: highest investigative attention, with impact-based severity. Separate proven defects from observations still needing a minimal reproduction. Include misleading tool schemas/docs, inspection failures, and visibility defects, not only crashes.
  • Already fixed / stale / unresolved: use these as dispositions, not as a substitute for a category. A source commit is not proof every live daemon runs the fix. State which target you actually rechecked.

Check exact submitted arguments and canonical tool results before attributing a problem to Tau. Particularly useful counterchecks:

  • Backticks in double-quoted shell prose execute substitutions. Check quoting before alleging command/result mixups. Use literal heredocs/files for prose.
  • Look for earlier successful unlocks before concluding a manual lock vanished.
  • Check human UI and peer-message ingress before calling a child's work unsolicited.
  • Automatic tool backgrounding does not remove the command's explicit/default timeout. A completion notification is not necessarily a consumed result.
  • A deduplication pointer means identical output, not skipped command execution.
  • jj reads may snapshot/import mutable working-copy state. Pin immutable Git objects or use documented jj --ignore-working-copy when appropriate.
  • Directory-scoped wrappers and direnv may write before a nominally read-only command. Avoid inspecting through a mutating wrapper when a neutral workdir and explicit target path suffice.
  • Hidden runtime mounts can make discovery empty by design. Distinguish that from mixed-version exact-admission failure and real discovery bugs.
  • Provider-hosted web.run failures are not automatically Tau registered-tool failures. Keep the documented provider/native boundary clear.

Use bounded local source/history and diagnostic inspection. Durable agent logs are canonical replay evidence; session debug JSONL is incomplete, so a missing debug row does not prove an event never happened. Raw provider captures, tool arguments, and logs stay private. Do not run mutating probes, broad tests, or restoration operations without separate authority. Consult the relevant persistence/interface gates before proposing semantic changes; do not expand this task into hostile local-IPC hardening.

Show full SKILL.md (496 more words)Show less

Report and queue before clear

Produce a sanitized report with:

  1. Main findings and category/priority counts, with the scope of uncertainty.
  2. Deduplicated findings and actionable scopes, including stale fixes and harmless explanations.
  3. A complete per-report coverage ledger and the exact reviewed snapshot cut.
  4. Reproduction/evidence references without raw secrets.
  5. Clear status and any late-arrival or access blocker.

Write actionable follow-ups as discrete project task/ticket entries on the active work queue, initially blocked pending the user's review and approval. State proposed scope, evidence/confidence, priority, and approval gate in each entry. Use the project's actual ticket/queue workflow; when delegated, send entries to the coordinator who owns those writes rather than duplicating them. Record useful agent-prevention and environment work too, not only suspected harness bugs.

Only under an explicit user delegation may the coordinator approve an obvious Tau bug with an obvious narrow fix. Record the delegation, exact scope, and reason it qualifies; retain normal engineering review and CI. Non-obvious, uncertain, environmental, or meaningful semantic work stays user-gated. This exception is not blanket permission to auto-implement or dispatch triage findings. Ask the coordinator to acknowledge durable recording before clearing.

Shared reports may use an unpredictable mktemp /tmp/public/papercut-triage-XXXXXXXX.md path, but /tmp alone is not durable tracking: preserve the sanitized findings and coverage in the project's ticket/report workflow before removal of the source reports.

Clear only through supported archival semantics

Recheck the installed clear behavior before acting. In the current CLI, list is lock-consistent and clear takes the same cross-process append lock, validates the active file, then atomically renames it to a non-overwriting numbered archive. It reports the cleared record count and archive path. Reports admitted before the serialized clear boundary are recoverable from that archive; appends admitted after it create a fresh active file and remain visible to list. Archives retain the original private bytes indefinitely and are not listed, expired, or deleted automatically. The interface has no ID selection, snapshot token, --before, --dry-run, or compare-and-clear option.

  1. Confirm clearing is authorized and the report/queue entries are durable. If the original user request already authorized clear after triage, do not ask for duplicate approval; coordinate the execution boundary with the parent/coordinator.

  2. Capture and compare the final complete active sequence, then run:

    sh
    tau dev papercut clear &&
      tau dev papercut list --markdown > "$private_dir/post-clear.md" &&
      sha256sum "$private_dir/post-clear.md" > "$private_dir/post-clear.sha256"

    Add the same --state-dir <STATE_DIR> to both if a non-default root was used. Record the exact clear count, archive path, and a sanitized post-clear status. Compare the archived record sequence with the reviewed snapshot and analyze/report/queue any additions that arrived before the clear boundary. Keep archive contents, remaining report text, and attribution private. New post-clear reports are not evidence that clearing failed; do not blindly clear again. Do not manipulate the reporter store directly or delete the archive.

Finish with a concise summary of what was analyzed, what deserves user review, which reports were cleared (or why none were), and where the durable report and approval-gated or explicitly delegated follow-ups live.

© dpc, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/tau-papercut-triage of dpc/tau.

Open the folder on GitHubat commit d2e1955

Compare with similar skills

Tau Papercut Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tau Papercut Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tau Papercut Triage this skilldpc/tau105—~2.4kAutomated safety check: PassMPL-2.0
Web3 Triage and Report Examplestradecatlabs/vibe-coding-cn17k2 repos~7.7kAutomated safety check: PassMIT
Triage Issue Reportscursor/plugins11k1 repos~2.6kAutomated safety check: PassNone
Windows App SDK Issue Triage Reportmicrosoft/WindowsAppSDK4.7k—~3.4kAutomated safety check: PassApache-2.0
Reportmicrosoft/data-formulator18k—~1.5kAutomated safety check: PassMIT
Bug Report TriageOrchestratorInc/agent-orchestrator13k—~1.8kAutomated safety check: PassApache-2.0

Similar skills

  • Web3 Triage and Report Examples

    tradecatlabs/vibe-coding-cn

    Seven-question triage gate, Immunefi report format and dissected paid bounty examples for deciding whether a smart contract finding is worth submitting.

    17k GitHub starsUsed in 2 repos~7.7k tokens
    SecurityAuto-check passed
  • Triage Issue Reports

    cursor/plugins

    Official

    Triage Slack issue reports with one thread-only verdict, evidence review, cause-aware routing, tracker dedupe, and fail-closed ticket creation.

    11k GitHub starsUsed in 1 repo~2.6k tokens
    DevelopmentAuto-check passed
  • Official

    Generates GitHub Feature Area Status reports for the Windows App SDK repository, scoring issues so teams can see what needs attention in each area.

    4.7k GitHub stars~3.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Report

    microsoft/data-formulator

    Official

    Turn an exploration (threads, findings, charts) into a single Markdown report — note, blog post, executive summary, KPI dashboard, slide brief, or multi-section analytical report, with embedded…

    18k GitHub stars~1.5k tokensUpdated 2 days ago
    Writing & ContentAuto-check passed
  • Bug Report Triage

    OrchestratorInc/agent-orchestrator

    Helps a reporter describe a bug, searches for duplicates and gathers diagnostic evidence kept separate from a short, human-worded issue draft.

    13k GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Security Triage

    openclaw/openclaw

    Triage OpenClaw security advisories, drafts, and GHSA reports with shipped-tag and trust-model proof.

    392k GitHub stars~1.7k tokensUpdated today
    DevelopmentAuto-check passed
  • A skill your agent uses when selfci, Nix CI, coverage, cargo-crap, CRAP-score, crapAbsolute, or crapReport checks fail in Tau, or before changing the cargo-crap gates, thresholds, or flagged complex…

    105 GitHub stars~1.2k tokensUpdated 5 days ago
    Auto-check passed
  • A skill your agent uses when asked to verify Tau harness tools or tool output behavior, especially read, edit, shell/shellcommand, line-oriented output, truncation, metadata headers, UTF-8 handling…

    105 GitHub stars~4.8k tokensUpdated 5 days ago
    Auto-check passed
  • A skill your agent uses when verifying Tau file and command tools: read, edit, replace, applypatch, shell, or shellcommand, including ranges, UTF-8, truncation, diffs, timeouts, mutation safety, and…

    105 GitHub stars~4k tokensUpdated 5 days ago
    Auto-check passed
  • A skill your agent uses when changing or reviewing Tau's static site under site/ and needing visual verification of layout, spacing, colors, alignment, desktop rendering, mobile rendering, or…

    105 GitHub stars~308 tokensUpdated 5 days ago
    Auto-check passed
  • A skill your agent uses when tracing or auditing Tau agent execution, including provider and cache cost, tool/background/wait latency, outer turns, compaction, delegated workflows, or performance…

    105 GitHub stars~658 tokensUpdated 5 days ago
    Auto-check passed
  • A skill your agent uses when verifying Tau agentstart, message, or agentwatch coordination, including routing, validation, interruption, notification formatting, watch lifecycle, and deduplication.

    105 GitHub stars~6.3k tokensUpdated 5 days ago
    Auto-check passed

Questions about Tau Papercut Triage

What does Tau Papercut Triage do?

A skill your agent uses when asked to "triage papercuts", review clanker-reported problems, or analyze and clear tau dev papercut reports. Tau Papercut Triage is an agent skill from dpc/tau. Use when asked to "triage papercuts", review clanker-reported problems, or analyze and clear tau dev papercut reports.

When should I use Tau Papercut Triage?

Tau Papercut Triage fits situations like: asked to triage papercuts; review clanker-reported problems; analyze and clear tau dev papercut reports.

How do I install Tau Papercut Triage in Claude Code?

Run `npx skills add dpc/tau --skill tau-papercut-triage -a claude-code`. Or copy the skill folder (.agents/skills/tau-papercut-triage in dpc/tau) into .claude/skills/tau-papercut-triage in your project. Claude Code loads it when a task matches its description.

How do I install Tau Papercut Triage in Codex?

Run `npx skills add dpc/tau --skill tau-papercut-triage -a codex`. Or copy the skill folder (.agents/skills/tau-papercut-triage in dpc/tau) into .agents/skills/tau-papercut-triage in your project. Codex loads it when a task matches its description.

Can I use Tau Papercut Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dpc/tau --skill tau-papercut-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tau-papercut-triage, .gemini/skills/tau-papercut-triage, .github/skills/tau-papercut-triage and .opencode/skills/tau-papercut-triage in your project.

What does Tau Papercut Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Tau Papercut Triage is instructions for the agent only.

Does Tau Papercut Triage access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Tau Papercut Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Tau Papercut Triage use?

Tau Papercut Triage is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tau Papercut Triage use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tau Papercut Triage?

Skills that share tags, products or a category with Tau Papercut Triage: Web3 Triage and Report Examples (tradecatlabs/vibe-coding-cn, 17k stars), Triage Issue Reports (cursor/plugins, 11k stars), Windows App SDK Issue Triage Report (microsoft/WindowsAppSDK, 4.7k stars) and Report (microsoft/data-formulator, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tau Papercut Triage?

dpc (a GitHub user) maintains it in dpc/tau, which has 105 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 5, 2026.

Source: dpc/tau on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.