Agent skill

Debug

by kdlbs in kdlbs/kandev

Diagnose Kandev bugs, running-instance issues, UI/browser failures, and runtime behavior.

AGPL-3.0Auto-check passedDevelopment

Install Debug

skills CLI
$ npx skills add kdlbs/kandev --skill debug -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kdlbs/kandev debug --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kdlbs/kandev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/debug .claude/skills/debug && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
debug
GitHub stars
903
Token cost
~2.2k tokens
SKILL.md length
1,029 words
Files
5 (incl. references)
Skills in repo
45
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Diagnose Kandev bugs, running-instance issues, UI/browser failures, and runtime behavior.

  • Works in 5 steps: Triage - classify the bug and choose the… → Gather evidence - targeted test,… → Diagnose - trace the failure to root cause → …
  • The user reports unexpected behavior
  • SKILL.md covers Planner Entry, First: Create The Pipeline, Triage Gate and Evidence Strategy, plus 4 more sections
  • Calls rg and pnpm; needs GITHUB_TOKEN and KANDEV_API_TOKEN

What it does

Debug is an agent skill from kdlbs/kandev. Diagnose Kandev bugs, running-instance issues, UI/browser failures, and runtime behavior. Use when the user reports unexpected behavior, asks to investigate, asks to add logs/instrumentation, or when a fix needs root-cause evidence before implementing. Triage first, gather evidence safely, then hand off to /fix for code changes.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/backend-repro.md`, `references/browser.md` and `references/instance.md`).

It sits in Development, covering Root cause analysis. The repository describes itself as: AI Kanban & Development Environment. Orchestrate multiple agents, review changes, open PRs. Multi-provider, self-hostable, no telemetry. The licence is AGPL-3.0.

When your agent uses it

  • The user reports unexpected behavior
  • Asks to investigate
  • Asks to add logs/instrumentation
  • A fix needs root-cause evidence before implementing

Example prompts

  • “/debug”

Requirements

  • A credential in KANDEV_API_TOKEN
  • A credential in GITHUB_TOKEN
  • Pre-approved tools (allowed-tools): Bash(curl:*), Bash(jq:*), Bash(mktemp:*), Bash(unzip:*), Bash(pnpm:*), Bash(scripts/kandev-instances:*), Bash(scripts/kandev-logs:*), Bash(scripts/dev-isolated:*), Bash(scripts/kandev-kill:*), Bash(go:*), Bash(rg:*), Bash(grep:*)

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Triage - classify the bug and choose the cheapest faithful path
  2. Gather evidence - targeted test, source-selectable diagnostic bundle, browser state, or instrumentation
  3. Diagnose - trace the failure to root cause
  4. Report - summarize evidence and choose /fix when code changes are needed
  5. Clean up - remove temporary logs, throwaway repro tests, isolated instances, and browser sessions

What it can do on your machine

Read from SKILL.md and the folder at commit dabc68f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(curl:*)
    • Bash(jq:*)
    • Bash(mktemp:*)
    • Bash(unzip:*)
    • Bash(pnpm:*)
    • Bash(scripts/kandev-instances:*)
    • Bash(scripts/kandev-logs:*)
    • Bash(scripts/dev-isolated:*)
    • Bash(scripts/kandev-kill:*)
    • Bash(go:*)

    …and 2 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • KANDEV_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Debug loads about 2.2k tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 84 tokens; SKILL.md has 1,029 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kdlbs/kandev at commit dabc68f, republished under its AGPL-3.0 licence (© kdlbs). 1,029 words, ~2,152 tokens.

Download SKILL.mdSave it as .claude/skills/debug/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
debug
description
Diagnose Kandev bugs, running-instance issues, UI/browser failures, and runtime behavior. Use when the user reports unexpected behavior, asks to investigate, asks to add logs/instrumentation, or when a fix needs root-cause evidence before implementing. Triage first, gather evidence safely, then hand off to /fix for code changes.
allowed-tools
Bash(curl:*), Bash(jq:*), Bash(mktemp:*), Bash(unzip:*), Bash(pnpm:*), Bash(scripts/kandev-instances:*), Bash(scripts/kandev-logs:*), Bash(scripts/dev-isolated:*), Bash(scripts/kandev-kill:*), Bash(go:*), Bash(rg:*), Bash(grep:*)

Debug

Diagnose efficiently and safely. Debugging produces evidence and a root-cause hypothesis; /fix turns that into a regression-tested patch.

Planner Entry

Perform triage, evidence gathering, and diagnosis directly in the primary conversation. Keep production edits out of the diagnostic phase, then proceed through /fix when code changes are needed.

First: Create The Pipeline

Create a visible task list:

  1. Triage - classify the bug and choose the cheapest faithful path
  2. Gather evidence - targeted test, source-selectable diagnostic bundle, browser state, or instrumentation
  3. Diagnose - trace the failure to root cause
  4. Report - summarize evidence and choose /fix when code changes are needed
  5. Clean up - remove temporary logs, throwaway repro tests, isolated instances, and browser sessions

Triage Gate

Pick one path before launching anything:

ClassSignalsReference
Backend logicvalidation, dedup, data shaping, workflow routing, API/service behaviorreferences/backend-repro.md
Live instanceuser has a running instance already misbehaving and you need read-only state/logsreferences/instance.md
UI/browserlayout, focus, click flow, WS-driven UI, console/network behaviorreferences/browser.md plus references/instance.md
Needs logscurrent evidence is insufficient and instrumentation is neededreferences/instrumentation.md

Rules:

  • Triage before launching anything.
  • Use logs and targeted tests before browser automation.
  • Never mutate the user's live instance. Creating or downloading an owned diagnostic bundle is read-only; browser interaction must use your isolated instance.
  • Tear down only what you started. Never pkill kandev.

Evidence Strategy

Start with the cheapest faithful reproduction:

  1. Backend logic: write a throwaway focused Go repro test against the real service path. If it reproduces, convert it via /fix.
  2. Live instance in a task session: call get_diagnostic_bundle_kandev with backend, frontend, or all; inspect manifest.json before assuming a source is complete.
  3. Host-side instance: use scripts/kandev-logs <port> --source backend|frontend|all; do not relaunch. Set KANDEV_API_TOKEN only when authentication is enabled.
  4. UI/browser: launch scripts/dev-isolated --web, drive pnpm --dir apps exec playwright-cli, and correlate console/network state with a fresh all-source bundle.
  5. Unknown: trace from the symptom backward through code and add temporary instrumentation only where it will split the search space.

When logs show repeated calls to the same endpoint or action, classify each request by transport, method/action, query or body cursor, caller, and cadence before diagnosing a loop. A periodic newest-window refresh and cursor pagination can share a route while serving different purposes. Verify pagination by capturing the directional cursor request and its response. If no such request exists, investigate the UI trigger or lifecycle; repeated uncursored refreshes do not prove that the server failed to advance a cursor.

Before any restart or mutating reproduction, capture the baseline diagnostic bundle and record the exact database and log pointers. Treat the live database as latest state, not historical evidence; preserve the baseline and reconstruct the lifecycle from timestamped logs, events, and transition tables before comparing later state.

For a GitHub merge-queue ejection, a timeline removal event is not the cause. Inspect the ruleset's check_response_timeout_minutes, the current mergeQueueEntry, and merge_group runs. Record the synthetic run/job IDs, head_sha, start/end timestamps, configured workflow/job timeout, and logs before classifying the failure as CI capacity or changing product code. Use the PR-fixup merge-queue and CI-troubleshooting references for the query details.

For workflow-routing failures, inspect the workflow's on activity types, job-level if gates, permissions, exact PR and head SHA, and the actor that added a label. Verify token-trigger behavior against GitHub's GITHUB_TOKEN documentation: events created with GITHUB_TOKEN generally do not create another workflow run, and a label-only trigger does not cover a later synchronize update. Confirm the observed run and event rather than inferring that a missing run means the workflow logic was skipped.

Show full SKILL.md (442 more words)Show less
File-first log triage

Start with the retained backend files before asking for a broad export. Each Kandev home has logs/backend-logs.log plus the two preceding UTC daily files (backend-logs-YYYY-MM-DD.log). The active file appends across same-day restarts and each daily file is bounded, so search the exact files rather than loading an entire log into memory:

bash
rg --fixed-strings '<task-id>' '<home>/logs' -g 'backend-logs*.log'
rg --fixed-strings '<session-id>' '<home>/logs' -g 'backend-logs*.log'

Prefer a task ID, session ID, or exact route/error string. Add a bounded time window only after the exact search; do not use a broad rg over the whole home directory because task workspaces and ACP files can contain unrelated private content. A zero-match task search is inconclusive when the event is an install-wide startup/API event.

Request only the needed bundle sources. Standard bundles contain backend and frontend diagnostic events; a custom bundle can add the allow-listed runtime index. These sources do not read stored chat transcripts, session messages, or agent messages. If the maintainer explicitly needs agent protocol evidence, use the debug-only ACP source and select the exact authorized sessions; ACP raw/normalized frames may contain prompts, responses, tool calls, file/MCP data, environment-derived values, and secrets. Always inspect manifest.json and its warnings before assuming a source is complete, and grep task/session IDs inside the extracted ZIP before broadening to route text or timestamps.

Cancellation intent is separate from event serialization: A generic per-session event-serialization mutex only orders work; it is not evidence that cancellation was requested. Model cancellation intent with separate state or a refcount, and mark it only around real cancellation operations. During concurrency debugging, inspect that state independently before attributing a queued or dropped event to cancellation.

Provider diagnostics: Raw agent stderr may contain URLs, IDs, subscription details, or other sensitive runtime data. Inspect it only in memory, sanitize it before writing to generic logs, ring buffers, process-exit errors, persistence, or the UI, and ensure bounded diagnostic consumers cannot block subprocess stderr draining.

Reference Files

Load only the reference needed for the selected path:

  • references/backend-repro.md - targeted Go repro tests and backend-first debugging.
  • references/instance.md - instance discovery, isolated launch, logs/export, and teardown.
  • references/browser.md - workspace-pinned playwright-cli browser debugging against isolated instances.
  • references/instrumentation.md - temporary vs persistent frontend/backend logging rules.

When To Use Instrumentation

Use references/instrumentation.md before adding:

  • console.log
  • logger.Warn("[DEBUG] ...")
  • createDebugLogger(...)
  • backend logger.Debug / logger.Info for persistent diagnosis

Temporary logs must be stripped before /commit or /pr. Persistent instrumentation stays only when it has ongoing diagnostic value.

Hand Off To Fix

When you can state:

  • what fails,
  • where it fails,
  • why it fails,
  • how to reproduce it,

then stop debugging and proceed through /fix in the same primary conversation.

Final Report

Report:

  • Bug class selected
  • Evidence gathered
  • Root cause or strongest hypothesis
  • Suggested fix path and files
  • Cleanup performed
  • Any remaining unknowns

© kdlbs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in .agents/skills/debug of kdlbs/kandev.

  • SKILL.md
  • references/backend-repro.md
  • references/browser.md
  • references/instance.md
  • references/instrumentation.md

Open the folder on GitHubat commit dabc68f

Compare with similar skills

Debug next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Debug compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Debug this skillkdlbs/kandev903—~2.2kAutomated safety check: PassAGPL-3.0
Req Analyzesd0xdev/sd0x-harness192—~4.1kAutomated safety check: PassMIT
Uipath InsightsUiPath/skills166—~6.4kAutomated safety check: NotesMIT
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone
OpenLogi macOS Permissions TriageAprilNEA/OpenLogi23k—~2.5kAutomated safety check: NotesApache-2.0
Bug Finder for daisyUIsaadeghi/daisyui43k—~2.3kAutomated safety check: PassMIT

Similar skills

  • Req Analyze

    sd0xdev/sd0x-harness

    Requirements analysis — problem decomposition, stakeholder scan, requirement structuring.

    192 GitHub stars~4.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Uipath Insights

    UiPath/skills

    UiPath Insights monitoring via uip insights: job metrics, failure analysis, and process performance; queue totals, SLA risk, timelines, and failure drill-down; machine availability, fault ranking…

    166 GitHub stars~6.4k tokensUpdated today
    DevelopmentAuto-check: notes
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated 4 days ago
    DevelopmentAuto-check: notes
  • Bug Finder for daisyUI

    saadeghi/daisyui

    Investigates suspected bugs in the daisyUI monorepo through read-only analysis, then writes a decision-ready fix plan in tmp/bugs without changing any product code.

    43k GitHub stars~2.3k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Root Cause Debugging

    garrytan/gstack

    Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.

    136k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed

More from kdlbs/kandev

All 45 skills in this repo
  • PR Walkthrough

    kdlbs/kandev

    Generate a single-file HTML walkthrough that explains a PR's purpose, user impact, interface changes, compatibility risks, and implementation.

    903 GitHub stars~6.2k tokensUpdated today
    Auto-check passed
  • Improve Kandev's AI harness from session learnings or explicit requests.

    903 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Diagram Design

    kdlbs/kandev

    Create branded architecture, IT current-state, flowchart, sequence, state machine, ER/data model, timeline, swimlane, quadrant, radar/spider, polar chart (polar/radial lollipop), loop/flywheel…

    903 GitHub starsUsed in 1 repo~8k tokens
    Auto-check passed
  • TDD

    kdlbs/kandev

    Implement changes using Test-Driven Development (Red-Green-Refactor).

    903 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Verify

    kdlbs/kandev

    Run a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it.

    903 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Acp Debug

    kdlbs/kandev

    Debug an ACP agent CLI by spawning it, speaking raw JSON-RPC, and capturing every frame to a JSONL file.

    903 GitHub stars~2.1k tokensUpdated today
    Auto-check passed

Questions about Debug

What does Debug do?

Diagnose Kandev bugs, running-instance issues, UI/browser failures, and runtime behavior. Debug is an agent skill from kdlbs/kandev. Diagnose Kandev bugs, running-instance issues, UI/browser failures, and runtime behavior.

When should I use Debug?

Debug fits situations like: the user reports unexpected behavior; asks to investigate; asks to add logs/instrumentation; A fix needs root-cause evidence before implementing.

How do I install Debug in Claude Code?

Run `npx skills add kdlbs/kandev --skill debug -a claude-code`. Or copy the skill folder (.agents/skills/debug in kdlbs/kandev) into .claude/skills/debug in your project. Claude Code loads it when a task matches its description.

How do I install Debug in Codex?

Run `npx skills add kdlbs/kandev --skill debug -a codex`. Or copy the skill folder (.agents/skills/debug in kdlbs/kandev) into .agents/skills/debug in your project. Codex loads it when a task matches its description.

Can I use Debug in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kdlbs/kandev --skill debug -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/debug, .gemini/skills/debug, .github/skills/debug and .opencode/skills/debug in your project.

What does Debug need to run?

Going by SKILL.md and its folder, Debug needs the command-line tools its instructions call (rg and pnpm) and credentials named GITHUB_TOKEN and KANDEV_API_TOKEN. Our summary lists: A credential in KANDEV_API_TOKEN; A credential in GITHUB_TOKEN. Its frontmatter pre-approves these tools: Bash(curl:*), Bash(jq:*), Bash(mktemp:*), Bash(unzip:*), Bash(pnpm:*), Bash(scripts/kandev-instances:*), Bash(scripts/kandev-logs:*), Bash(scripts/dev-isolated:*), Bash(scripts/kandev-kill:*), Bash(go:*), Bash(rg:*), Bash(grep:*).

Does Debug access the network?

SKILL.md names 1 domain. As links in the text: docs.github.com. This is read from the text; nothing was executed.

Is Debug safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Debug use?

Debug is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Debug use?

About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.

What are the alternatives to Debug?

Skills that share tags, products or a category with Debug: Req Analyze (sd0xdev/sd0x-harness, 192 stars), Uipath Insights (UiPath/skills, 166 stars), Code Design Rationale Investigator (cursor/plugins, 10k stars) and OpenLogi macOS Permissions Triage (AprilNEA/OpenLogi, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Debug?

kdlbs (a GitHub organization) maintains it in kdlbs/kandev, which has 903 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 7, 2026.

Source: kdlbs/kandev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.