Official agent skill

Error Pattern Safety

by github in github/gh-aw

Apply safe error-pattern matching rules for agentic engines.

OfficialMITAuto-check passed

Install Error Pattern Safety

skills CLI
$ npx skills add github/gh-aw --skill error-pattern-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/gh-aw error-pattern-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/error-pattern-safety .claude/skills/error-pattern-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
error-pattern-safety
GitHub stars
5.3k
Token cost
~1.3k tokens
SKILL.md length
415 words
Files
1
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Apply safe error-pattern matching rules for agentic engines.

  • Works in 3 steps: JavaScript's regex.exec() with the g… → When a pattern matches zero-width,… → The same position is matched repeatedly,…
  • SKILL.md covers The Problem, Dangerous Pattern Examples, Safe Pattern Examples and Pattern Safety Rules, plus 7 more sections
  • Calls make

What it does

Error Pattern Safety is an agent skill from github/gh-aw, published by the product's own GitHub organization. Apply safe error-pattern matching rules for agentic engines.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with JavaScript. The repository describes itself as: GitHub Agentic Workflows. The licence is MIT.

Example prompts

  • “/error-pattern-safety”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. JavaScript's regex.exec() with the g flag uses lastIndex to track position
  2. When a pattern matches zero-width, lastIndex doesn't advance
  3. The same position is matched repeatedly, causing an infinite loop

What it can do on your machine

Read from SKILL.md and the folder at commit eb63040. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • pkg.go.dev
    • developer.mozilla.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Error Pattern Safety loads about 1.3k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 415 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/gh-aw at commit eb63040, republished under its MIT licence (© github). 415 words, ~1,344 tokens.

Download SKILL.mdSave it as .claude/skills/error-pattern-safety/SKILL.md (or your agent's skills folder).
name
error-pattern-safety
description
Apply safe error-pattern matching rules for agentic engines.

Error Pattern Safety Guidelines

Use these regex safety rules in agentic engines to prevent JavaScript infinite loops.

The Problem

With the JavaScript global flag (/pattern/g), zero-width matches can cause infinite loops because:

  1. JavaScript's regex.exec() with the g flag uses lastIndex to track position
  2. When a pattern matches zero-width, lastIndex doesn't advance
  3. The same position is matched repeatedly, causing an infinite loop

Dangerous Pattern Examples

❌ NEVER USE THESE PATTERNS:

javascript
// Pure .* - matches everything including empty string at end
/.*/g

// Single character with * - matches zero or more (including zero)
/a*/g

// Patterns that can match empty string
/(x|y)*/g

Safe Pattern Examples

✅ ALWAYS USE PATTERNS LIKE THESE:

javascript
// Required prefix before .*
/error.*/gi
/error.*permission.*denied/gi

// Specific structure with required content
/\[(\d{4}-\d{2}-\d{2})\]\s+(ERROR):\s+(.+)/g

// Required characters throughout
/access denied.*user.*not authorized/gi

Pattern Safety Rules

  1. Always require at least one character match

    • Use .+ instead of .* when you need "something"
    • Ensure pattern has required prefix/suffix
  2. Never use bare .* as the entire pattern

    • Always combine with required text: error.*
    • Never just .* or .*?
  3. Test patterns against empty string

    javascript
    const regex = /your-pattern/g;
    if (regex.test("")) {
      throw new Error("Pattern matches empty string - DANGEROUS!");
    }
  4. Use specific anchors when possible

    • Start: ^error.*
    • End: .*error$
    • Word boundaries: \berror\b

Validation Tests

All error patterns must pass the same safety checks used by the repo’s unit suite:

Go tests
go
// Test that pattern doesn't match empty string
func TestPatternSafety(t *testing.T) {
    pattern := "your-pattern"
    regex := regexp.MustCompile(pattern)

    if regex.MatchString("") {
        t.Error("Pattern matches empty string!")
    }
}

Run the relevant package tests with make test-unit.

JavaScript tests
javascript
test("should not match empty string", () => {
  const regex = new RegExp("your-pattern", "g");
  expect(regex.test("")).toBe(false);
});

Use the relevant *.test.cjs suite under actions/setup/js/ or pkg/workflow/js/ for the area you changed, or run the repo’s JavaScript checks via make test-js.

Safety Mechanisms in the validation layer

The repo’s validation helpers include built-in protections for dangerous regex patterns:

  1. Zero-width detection: Checks whether a regex stops advancing across iterations
  2. Iteration warning: Warns when repeated runs approach a hang threshold
  3. Hard limit: Stops execution before runaway loops can lock the process
javascript
if (regex.lastIndex === lastIndex) {
  core.error(`Infinite loop detected! Pattern: ${pattern.pattern}`);
  break;
}
Show full SKILL.md (185 more words)Show less

Adding New Error Patterns

When adding new error patterns to engines:

  1. Write the pattern with required content

    go
    {
        Pattern:      `(?i)error.*permission.*denied`,
        LevelGroup:   0,
        MessageGroup: 0,
        Description:  "Permission denied error",
    }
  2. Test against empty string

    • Run: make test-unit
    • Checks: TestAllEnginePatternsSafe
  3. Test with actual log samples

    • Ensure it matches real errors
    • Ensure it doesn't match informational text
  4. Document the pattern

    • Add clear description
    • Note what it's designed to catch

Pattern Conversion: Go to JavaScript

Patterns are converted from Go to JavaScript:

go
// Go pattern (case-insensitive flag)
Pattern: `(?i)error.*permission.*denied`

// Converted to JavaScript
new RegExp("error.*permission.*denied", "gi")

The (?i) prefix is removed because JavaScript uses the i flag instead.

Examples from Current Codebase

✅ Safe Patterns
go
// Requires "error" prefix
Pattern: `(?i)error.*permission.*denied`

// Requires specific timestamp format
Pattern: `(\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z)\s+\[(ERROR)\]\s+(.+)`

// Requires "access denied" prefix
Pattern: `(?i)access denied.*user.*not authorized`
How to Fix Unsafe Patterns

If you find a pattern that matches empty string:

Before (unsafe):

go
Pattern: `.*error.*`  // Can match empty at start/end

After (safe):

go
Pattern: `error.*`     // Requires "error" at start
// OR
Pattern: `.*error.+`   // Requires "error" and at least one char after
// OR
Pattern: `\berror\b.*` // Requires word "error"

Testing Checklist

Before committing pattern changes:

  • Run make test-unit
  • Verify the relevant engine error-pattern tests still pass
  • Run the JavaScript checks for the changed area with make test-js or the targeted Vitest suite
  • Verify the pattern matches intended error messages
  • Verify the pattern does not match informational text or empty-string edge cases

References

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/error-pattern-safety of github/gh-aw.

Open the folder on GitHubat commit eb63040

Compare with similar skills

Error Pattern Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Error Pattern Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Error Pattern Safety this skillgithub/gh-aw5.3k—~1.3kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Tailwindcss Developmentanonaddy/anonaddy4.9k10 repos~865Automated safety check: PassMIT
Figma use_figma Plugin API Ruleswarpdotdev/warp65k4 repos~4.4kAutomated safety check: PassAGPL-3.0
GSAP Core Animationgreensock/gsap-skills16k4 repos~3.7kAutomated safety check: PassMIT
JavaScript Concept Fact Checkerleonardomso/33-js-concepts67k1 repos~5kAutomated safety check: PassMIT

Similar skills

  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Tailwindcss Development

    anonaddy/anonaddy

    Always invoke when the user's message includes 'tailwind' in any form.

    4.9k GitHub starsUsed in 10 repos~865 tokens
    Frontend & DesignAuto-check passed
  • Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.

    65k GitHub starsUsed in 4 repos~4.4k tokens
    Frontend & DesignAuto-check passed
  • GSAP Core Animation

    greensock/gsap-skills

    Covers the GSAP core API for tweens, easing, staggers, defaults and matchMedia, and when to choose GSAP over CSS animations or other JavaScript animation libraries.

    16k GitHub starsUsed in 4 repos~3.7k tokens
    Frontend & DesignAuto-check passed
  • JavaScript Concept Fact Checker

    leonardomso/33-js-concepts

    Verifies the technical accuracy of JavaScript concept pages by checking code examples, MDN and ECMAScript claims and external links through a five-phase method.

    67k GitHub starsUsed in 1 repo~5k tokens
    Writing & ContentAuto-check passed
  • Scroll World Landing Page

    oso95/scroll-world

    Builds a scroll-driven landing page where a pre-rendered camera flies through connected AI-generated scenes, using Higgsfield for stills and video clips.

    9.7k GitHub starsUsed in 1 repo~12k tokens
    Frontend & DesignAuto-check: notes

More from github/gh-aw

All 52 skills in this repo
  • Official

    Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.

    5.3k GitHub starsUsed in 23 repos~2.8k tokens
    Auto-check passed
  • Official

    Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.

    5.3k GitHub stars~6.8k tokensUpdated today
    Auto-check passed
  • Official

    Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.

    5.3k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Official

    Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.

    5.3k GitHub stars~3.8k tokensUpdated today
    Auto-check: warnings
  • Official

    Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.

    5.3k GitHub stars~899 tokensUpdated today
    Auto-check passed
  • Official

    Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.

    5.3k GitHub stars~736 tokensUpdated today
    Auto-check passed

Works with

Questions about Error Pattern Safety

What does Error Pattern Safety do?

Apply safe error-pattern matching rules for agentic engines. Error Pattern Safety is an agent skill from github/gh-aw, published by the product's own GitHub organization. Apply safe error-pattern matching rules for agentic engines.

How do I install Error Pattern Safety in Claude Code?

Run `npx skills add github/gh-aw --skill error-pattern-safety -a claude-code`. Or copy the skill folder (.github/skills/error-pattern-safety in github/gh-aw) into .claude/skills/error-pattern-safety in your project. Claude Code loads it when a task matches its description.

How do I install Error Pattern Safety in Codex?

Run `npx skills add github/gh-aw --skill error-pattern-safety -a codex`. Or copy the skill folder (.github/skills/error-pattern-safety in github/gh-aw) into .agents/skills/error-pattern-safety in your project. Codex loads it when a task matches its description.

Can I use Error Pattern Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill error-pattern-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/error-pattern-safety, .gemini/skills/error-pattern-safety, .github/skills/error-pattern-safety and .opencode/skills/error-pattern-safety in your project.

What does Error Pattern Safety need to run?

Going by SKILL.md and its folder, Error Pattern Safety needs the command-line tools its instructions call (make).

Does Error Pattern Safety access the network?

SKILL.md names 2 domains. As links in the text: pkg.go.dev and developer.mozilla.org. This is read from the text; nothing was executed.

Is Error Pattern Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Error Pattern Safety use?

Error Pattern Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Error Pattern Safety use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Error Pattern Safety?

Skills that share tags, products or a category with Error Pattern Safety: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Tailwindcss Development (anonaddy/anonaddy, 4.9k stars), Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars) and GSAP Core Animation (greensock/gsap-skills, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Error Pattern Safety?

github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,350 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.