Web3 Triage and Report Examples
tradecatlabs/vibe-coding-cn
Seven-question triage gate, Immunefi report format and dissected paid bounty examples for deciding whether a smart contract finding is worth submitting.
A skill your agent uses when asked to "triage papercuts", review clanker-reported problems, or analyze and clear tau dev papercut reports.
$ npx skills add dpc/tau --skill tau-papercut-triage -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dpc/tau tau-papercut-triage --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dpc/tau.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/tau-papercut-triage .claude/skills/tau-papercut-triage && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "tau-papercut-triage" agent skill from https://github.com/dpc/tau/tree/master/.agents/skills/tau-papercut-triage into .claude/skills/tau-papercut-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tau-papercut-triage", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dpc/tau/tree/master/.agents/skills/tau-papercut-triageType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dpc/tau --skill tau-papercut-triage -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dpc/tau tau-papercut-triage --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dpc/tau.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/tau-papercut-triage .agents/skills/tau-papercut-triage && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "tau-papercut-triage" agent skill from https://github.com/dpc/tau/tree/master/.agents/skills/tau-papercut-triage into .agents/skills/tau-papercut-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tau-papercut-triage", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dpc/tau --skill tau-papercut-triage -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dpc/tau tau-papercut-triage --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dpc/tau.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/tau-papercut-triage .cursor/skills/tau-papercut-triage && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "tau-papercut-triage" agent skill from https://github.com/dpc/tau/tree/master/.agents/skills/tau-papercut-triage into .cursor/skills/tau-papercut-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tau-papercut-triage", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dpc/tau.git --path .agents/skills/tau-papercut-triage--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dpc/tau --skill tau-papercut-triage -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dpc/tau tau-papercut-triage --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dpc/tau.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/tau-papercut-triage .gemini/skills/tau-papercut-triage && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "tau-papercut-triage" agent skill from https://github.com/dpc/tau/tree/master/.agents/skills/tau-papercut-triage into .gemini/skills/tau-papercut-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tau-papercut-triage", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dpc/tau tau-papercut-triageInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dpc/tau --skill tau-papercut-triage -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dpc/tau.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/tau-papercut-triage .github/skills/tau-papercut-triage && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "tau-papercut-triage" agent skill from https://github.com/dpc/tau/tree/master/.agents/skills/tau-papercut-triage into .github/skills/tau-papercut-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tau-papercut-triage", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dpc/tau --skill tau-papercut-triage -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dpc/tau tau-papercut-triage --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dpc/tau.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/tau-papercut-triage .opencode/skills/tau-papercut-triage && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "tau-papercut-triage" agent skill from https://github.com/dpc/tau/tree/master/.agents/skills/tau-papercut-triage into .opencode/skills/tau-papercut-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tau-papercut-triage", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
tau-papercut-triageA skill your agent uses when asked to "triage papercuts", review clanker-reported problems, or analyze and clear tau dev papercut reports.
Tau Papercut Triage is an agent skill from dpc/tau. Use when asked to "triage papercuts", review clanker-reported problems, or analyze and clear tau dev papercut reports. Distinguish agent mistakes, recurring environment issues, and Tau defects; queue actionable follow-ups for approval before clearing analyzed reports safely.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Tau Coding Agent - like Pi, but twice as much. The licence is MPL-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d2e1955. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Tau Papercut Triage loads about 2.4k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 1,149 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dpc/tau at commit d2e1955, republished under its MPL-2.0 licence (© dpc). 1,149 words, ~2,390 tokens.
.claude/skills/tau-papercut-triage/SKILL.md (or your agent's skills folder).Use a senior researcher for this task. Triage is investigation and reporting, not permission to fix code, change configuration, restart sessions, or bypass isolation. Respect any concurrent project update owner.
Load dpc, tau-self-knowledge-debugging, and applicable project instructions.
Read the papercut and relevant trust-boundary sections of SECURITY.md.
Load dpc-rustgrep before structural Rust lookups, and linked-specs before
investigating governed behavior through its specs.
Verify the installed interface and build rather than assuming flags:
tau --version
tau dev papercut --help
tau dev papercut list --help
tau dev papercut clear --helpCapture one complete authoritative CLI snapshot in an owner-private
directory. Reports contain unredacted model text and may contain secrets.
Do not dump raw reports into shared /tmp/public, tickets, or the conversation.
umask 077
private_dir=$(mktemp -d /tmp/tau-papercut-triage-XXXXXXXX)
tau dev papercut list --markdown > "$private_dir/snapshot.md" &&
sha256sum "$private_dir/snapshot.md" > "$private_dir/snapshot.sha256"Stop if listing fails; do not clear malformed/unreadable data. --state-dir <STATE_DIR> is supported on both list and clear; use the same explicitly
selected root for both when overriding the default. This CLI covers the
standard std-utils instance, not arbitrary reporter instances.
Give every report a stable ordinal within that snapshot and preserve its timestamp and attribution privately. Count actual report records, not arbitrary Markdown heading matches inside report bodies. If taking plain and Markdown snapshots separately, verify their record sequences agree: each list call takes its own snapshot and reports may arrive between them. Plain output escapes controls but is not a general structured interchange format. Record capture time, first/last report timestamp, count, snapshot hash, CLI build, and inspected source revision.
Account for every report, including duplicates and multi-symptom reports. Group repeated symptoms into findings but retain an ordinal-to-finding ledger. Repeated reports from one incident are not independent reproductions.
For each finding record category, priority, confidence, recurrence, concrete evidence, disposition, and the smallest useful follow-up:
Check exact submitted arguments and canonical tool results before attributing a problem to Tau. Particularly useful counterchecks:
jj reads may snapshot/import mutable working-copy state. Pin immutable Git
objects or use documented jj --ignore-working-copy when appropriate.web.run failures are not automatically Tau registered-tool
failures. Keep the documented provider/native boundary clear.Use bounded local source/history and diagnostic inspection. Durable agent logs are canonical replay evidence; session debug JSONL is incomplete, so a missing debug row does not prove an event never happened. Raw provider captures, tool arguments, and logs stay private. Do not run mutating probes, broad tests, or restoration operations without separate authority. Consult the relevant persistence/interface gates before proposing semantic changes; do not expand this task into hostile local-IPC hardening.
Produce a sanitized report with:
Write actionable follow-ups as discrete project task/ticket entries on the active work queue, initially blocked pending the user's review and approval. State proposed scope, evidence/confidence, priority, and approval gate in each entry. Use the project's actual ticket/queue workflow; when delegated, send entries to the coordinator who owns those writes rather than duplicating them. Record useful agent-prevention and environment work too, not only suspected harness bugs.
Only under an explicit user delegation may the coordinator approve an obvious Tau bug with an obvious narrow fix. Record the delegation, exact scope, and reason it qualifies; retain normal engineering review and CI. Non-obvious, uncertain, environmental, or meaningful semantic work stays user-gated. This exception is not blanket permission to auto-implement or dispatch triage findings. Ask the coordinator to acknowledge durable recording before clearing.
Shared reports may use an unpredictable mktemp /tmp/public/papercut-triage-XXXXXXXX.md path, but /tmp alone is not durable
tracking: preserve the sanitized findings and coverage in the project's
ticket/report workflow before removal of the source reports.
Recheck the installed clear behavior before acting. In the current CLI, list
is lock-consistent and clear takes the same cross-process append lock, validates
the active file, then atomically renames it to a non-overwriting numbered archive.
It reports the cleared record count and archive path. Reports admitted before
the serialized clear boundary are recoverable from that archive; appends admitted
after it create a fresh active file and remain visible to list. Archives retain
the original private bytes indefinitely and are not listed, expired, or deleted
automatically. The interface has no ID selection, snapshot token, --before,
--dry-run, or compare-and-clear option.
Confirm clearing is authorized and the report/queue entries are durable. If the original user request already authorized clear after triage, do not ask for duplicate approval; coordinate the execution boundary with the parent/coordinator.
Capture and compare the final complete active sequence, then run:
tau dev papercut clear &&
tau dev papercut list --markdown > "$private_dir/post-clear.md" &&
sha256sum "$private_dir/post-clear.md" > "$private_dir/post-clear.sha256"Add the same --state-dir <STATE_DIR> to both if a non-default root was used.
Record the exact clear count, archive path, and a sanitized post-clear status.
Compare the archived record sequence with the reviewed snapshot and
analyze/report/queue any additions that arrived before the clear boundary.
Keep archive contents, remaining report text, and attribution private. New
post-clear reports are not evidence that clearing failed; do not blindly clear
again. Do not manipulate the reporter store directly or delete the archive.
Finish with a concise summary of what was analyzed, what deserves user review, which reports were cleared (or why none were), and where the durable report and approval-gated or explicitly delegated follow-ups live.
© dpc, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/tau-papercut-triage of dpc/tau.
Open the folder on GitHubat commit d2e1955
Tau Papercut Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Tau Papercut Triage this skilldpc/tau | 105 | — | ~2.4k | Automated safety check: Pass | MPL-2.0 | |
| Web3 Triage and Report Examplestradecatlabs/vibe-coding-cn | 17k | 2 repos | ~7.7k | Automated safety check: Pass | MIT | |
| Triage Issue Reportscursor/plugins | 11k | 1 repos | ~2.6k | Automated safety check: Pass | None | |
| Windows App SDK Issue Triage Reportmicrosoft/WindowsAppSDK | 4.7k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Reportmicrosoft/data-formulator | 18k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Bug Report TriageOrchestratorInc/agent-orchestrator | 13k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 |
tradecatlabs/vibe-coding-cn
Seven-question triage gate, Immunefi report format and dissected paid bounty examples for deciding whether a smart contract finding is worth submitting.
cursor/plugins
Triage Slack issue reports with one thread-only verdict, evidence review, cause-aware routing, tracker dedupe, and fail-closed ticket creation.
microsoft/WindowsAppSDK
Generates GitHub Feature Area Status reports for the Windows App SDK repository, scoring issues so teams can see what needs attention in each area.
microsoft/data-formulator
Turn an exploration (threads, findings, charts) into a single Markdown report — note, blog post, executive summary, KPI dashboard, slide brief, or multi-section analytical report, with embedded…
OrchestratorInc/agent-orchestrator
Helps a reporter describe a bug, searches for duplicates and gathers diagnostic evidence kept separate from a short, human-worded issue draft.
openclaw/openclaw
Triage OpenClaw security advisories, drafts, and GHSA reports with shipped-tag and trust-model proof.
dpc/tau
A skill your agent uses when selfci, Nix CI, coverage, cargo-crap, CRAP-score, crapAbsolute, or crapReport checks fail in Tau, or before changing the cargo-crap gates, thresholds, or flagged complex…
dpc/tau
A skill your agent uses when asked to verify Tau harness tools or tool output behavior, especially read, edit, shell/shellcommand, line-oriented output, truncation, metadata headers, UTF-8 handling…
A skill your agent uses when verifying Tau file and command tools: read, edit, replace, applypatch, shell, or shellcommand, including ranges, UTF-8, truncation, diffs, timeouts, mutation safety, and…
dpc/tau
A skill your agent uses when changing or reviewing Tau's static site under site/ and needing visual verification of layout, spacing, colors, alignment, desktop rendering, mobile rendering, or…
dpc/tau
A skill your agent uses when tracing or auditing Tau agent execution, including provider and cache cost, tool/background/wait latency, outer turns, compaction, delegated workflows, or performance…
A skill your agent uses when verifying Tau agentstart, message, or agentwatch coordination, including routing, validation, interruption, notification formatting, watch lifecycle, and deduplication.
A skill your agent uses when asked to "triage papercuts", review clanker-reported problems, or analyze and clear tau dev papercut reports. Tau Papercut Triage is an agent skill from dpc/tau. Use when asked to "triage papercuts", review clanker-reported problems, or analyze and clear tau dev papercut reports.
Tau Papercut Triage fits situations like: asked to triage papercuts; review clanker-reported problems; analyze and clear tau dev papercut reports.
Run `npx skills add dpc/tau --skill tau-papercut-triage -a claude-code`. Or copy the skill folder (.agents/skills/tau-papercut-triage in dpc/tau) into .claude/skills/tau-papercut-triage in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dpc/tau --skill tau-papercut-triage -a codex`. Or copy the skill folder (.agents/skills/tau-papercut-triage in dpc/tau) into .agents/skills/tau-papercut-triage in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dpc/tau --skill tau-papercut-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tau-papercut-triage, .gemini/skills/tau-papercut-triage, .github/skills/tau-papercut-triage and .opencode/skills/tau-papercut-triage in your project.
SKILL.md names no scripts, command-line tools or credentials: Tau Papercut Triage is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Tau Papercut Triage is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Tau Papercut Triage: Web3 Triage and Report Examples (tradecatlabs/vibe-coding-cn, 17k stars), Triage Issue Reports (cursor/plugins, 11k stars), Windows App SDK Issue Triage Report (microsoft/WindowsAppSDK, 4.7k stars) and Report (microsoft/data-formulator, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dpc (a GitHub user) maintains it in dpc/tau, which has 105 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 5, 2026.
Source: dpc/tau on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.