Official agent skill

Find Bugs

by getsentry in getsentry/skills

Find bugs, security vulnerabilities, and code quality issues in local branch changes.

OfficialApache-2.0Auto-check passedDevelopment

Install Find Bugs

skills CLI
$ npx skills add getsentry/skills --skill find-bugs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install getsentry/skills find-bugs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/getsentry/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/find-bugs .claude/skills/find-bugs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
find-bugs
GitHub stars
1k
Used in
9 other repos
Token cost
~708 tokens
SKILL.md length
336 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
Apache-2.0

At a glance

Find bugs, security vulnerabilities, and code quality issues in local branch changes.

  • Works in 5 steps: Complete Input Gathering → Attack Surface Mapping → Security Checklist (check EVERY item for… → …
  • Asked to review changes
  • SKILL.md covers Phase 1: Complete Input…, Phase 2: Attack Surface Mapping, Phase 3: Security Checklist… and Phase 4: Verification, plus 2 more sections
  • Calls git and gh

What it does

Find Bugs is an agent skill from getsentry/skills, published by the product's own GitHub organization. Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.

Its SKILL.md is about 710 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Debugging, Security review and Code quality. The repository describes itself as: Agent Skills used by the Sentry team for development. The licence is Apache-2.0.

When your agent uses it

  • Asked to review changes
  • Security review
  • Audit code on the current branch

Example prompts

  • “/find-bugs”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Complete Input Gathering
  2. Attack Surface Mapping
  3. Security Checklist (check EVERY item for EVERY file)
  4. Verification
  5. Pre-Conclusion Audit

What it can do on your machine

Read from SKILL.md and the folder at commit d18b7aa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Find Bugs loads about 708 tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 336 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~708

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from getsentry/skills at commit d18b7aa, republished under its Apache-2.0 licence (© getsentry). 336 words, ~708 tokens.

Download SKILL.mdSave it as .claude/skills/find-bugs/SKILL.md (or your agent's skills folder).
name
find-bugs
description
Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.

Find Bugs

Review changes on this branch for bugs, security vulnerabilities, and code quality issues.

Phase 1: Complete Input Gathering

  1. Get the FULL diff: git diff $(gh repo view --json defaultBranchRef --jq '.defaultBranchRef.name')...HEAD
  2. If output is truncated, read each changed file individually until you have seen every changed line
  3. List all files modified in this branch before proceeding

Phase 2: Attack Surface Mapping

For each changed file, identify and list:

  • All user inputs (request params, headers, body, URL components)
  • All database queries
  • All authentication/authorization checks
  • All session/state operations
  • All external calls
  • All cryptographic operations

Phase 3: Security Checklist (check EVERY item for EVERY file)

  • Injection: SQL, command, template, header injection
  • XSS: All outputs in templates properly escaped?
  • Authentication: Auth checks on all protected operations?
  • Authorization/IDOR: Access control verified, not just auth?
  • CSRF: State-changing operations protected?
  • Race conditions: TOCTOU in any read-then-write patterns?
  • Session: Fixation, expiration, secure flags?
  • Cryptography: Secure random, proper algorithms, no secrets in logs?
  • Information disclosure: Error messages, logs, timing attacks?
  • DoS: Unbounded operations, missing rate limits, resource exhaustion?
  • Business logic: Edge cases, state machine violations, numeric overflow?

Phase 4: Verification

For each potential issue:

  • Check if it's already handled elsewhere in the changed code
  • Search for existing tests covering the scenario
  • Read surrounding context to verify the issue is real

Phase 5: Pre-Conclusion Audit

Before finalizing, you MUST:

  1. List every file you reviewed and confirm you read it completely
  2. List every checklist item and note whether you found issues or confirmed it's clean
  3. List any areas you could NOT fully verify and why
  4. Only then provide your final findings

Output Format

Prioritize: security vulnerabilities > bugs > code quality

Skip: stylistic/formatting issues

For each issue:

  • File:Line - Brief description
  • Severity: Critical/High/Medium/Low
  • Problem: What's wrong
  • Evidence: Why this is real (not already fixed, no existing test, etc.)
  • Fix: Concrete suggestion
  • References: OWASP, RFCs, or other standards if applicable

If you find nothing significant, say so - don't invent issues.

Do not make changes - just report findings. I'll decide what to address.

© getsentry, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/find-bugs of getsentry/skills.

Open the folder on GitHubat commit d18b7aa

Used in 9 other repositories

We found 20 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 9 other GitHub owners. This page covers the copy in getsentry/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Find Bugs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Find Bugs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Find Bugs this skillgetsentry/skills1k9 repos~708Automated safety check: PassApache-2.0
Secure Codingtechygarg/lattice198—~1.5kAutomated safety check: PassMIT
Code Review Specialistluongnv89/claude-howto42k—~764Automated safety check: PassMIT
Best Practicesmidudev/100cosas.dev1143 repos~3kAutomated safety check: PassMIT
Read-Only Code AuditHarnessMD/munder-difflin8.5k—~350Automated safety check: NotesMIT
Codebase Review SwarmZaxbyHub/opencode-swarm488—~2.8kAutomated safety check: PassMIT

Similar skills

  • Secure Coding

    techygarg/lattice

    Apply security-conscious thinking when generating or modifying code.

    198 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Code Review Specialist

    luongnv89/claude-howto

    Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

    42k GitHub stars~764 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Best Practices

    midudev/100cosas.dev

    Apply modern web development best practices for security, compatibility, and code quality.

    114 GitHub starsUsed in 3 repos~3k tokens
    DevelopmentAuto-check passed
  • Read-Only Code Audit

    HarnessMD/munder-difflin

    Scans the working directory for ignored errors, hard-coded secrets, debt comments, dead exports and type gaps, and reports findings by severity without editing files.

    8.5k GitHub stars~350 tokensUpdated today
    DevelopmentAuto-check: notes
  • Codebase Review Swarm

    ZaxbyHub/opencode-swarm

    Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.

    488 GitHub stars~2.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review with Beads Tasks

    maslennikov-ig/claude-code-orchestrator-kit

    Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

    259 GitHub stars~2k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed

More from getsentry/skills

All 27 skills in this repo
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    Auto-check: warnings
  • Gh Review Requests

    getsentry/skills

    Official

    Fetch unread GitHub notifications for open PRs where review is requested from a specified team or opened by a team member.

    1k GitHub starsUsed in 3 repos~621 tokens
    Auto-check: notes
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    Auto-check: notes
  • Skill Writer

    getsentry/skills

    Official

    Create, synthesize, and iteratively improve agent skills following the Agent Skills specification.

    1k GitHub stars~2.5k tokensUpdated 4 days ago
    Auto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Auto-check: notes
  • Gha Security Review

    getsentry/skills

    Official

    GitHub Actions security review for workflow exploitation vulnerabilities.

    1k GitHub starsUsed in 3 repos~2.2k tokens
    Auto-check: notes

Questions about Find Bugs

What does Find Bugs do?

Find bugs, security vulnerabilities, and code quality issues in local branch changes. Find Bugs is an agent skill from getsentry/skills, published by the product's own GitHub organization. Find bugs, security vulnerabilities, and code quality issues in local branch changes.

When should I use Find Bugs?

Find Bugs fits situations like: asked to review changes; security review; audit code on the current branch.

How do I install Find Bugs in Claude Code?

Run `npx skills add getsentry/skills --skill find-bugs -a claude-code`. Or copy the skill folder (skills/find-bugs in getsentry/skills) into .claude/skills/find-bugs in your project. Claude Code loads it when a task matches its description.

How do I install Find Bugs in Codex?

Run `npx skills add getsentry/skills --skill find-bugs -a codex`. Or copy the skill folder (skills/find-bugs in getsentry/skills) into .agents/skills/find-bugs in your project. Codex loads it when a task matches its description.

Can I use Find Bugs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add getsentry/skills --skill find-bugs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/find-bugs, .gemini/skills/find-bugs, .github/skills/find-bugs and .opencode/skills/find-bugs in your project.

What does Find Bugs need to run?

Going by SKILL.md and its folder, Find Bugs needs the command-line tools its instructions call (git and gh).

Does Find Bugs access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Find Bugs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Find Bugs use?

Find Bugs is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Find Bugs use?

About 708 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Find Bugs?

Skills that share tags, products or a category with Find Bugs: Secure Coding (techygarg/lattice, 198 stars), Code Review Specialist (luongnv89/claude-howto, 42k stars), Best Practices (midudev/100cosas.dev, 114 stars) and Read-Only Code Audit (HarnessMD/munder-difflin, 8.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Find Bugs?

getsentry (a GitHub organization, an official publisher) maintains it in getsentry/skills, which has 1,037 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 2, 2026.

Source: getsentry/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.