Adversarial bug finding using 3 isolated agents (Hunter, Skeptic, Referee) to find and verify real bugs with high fidelity.

MITAuto-check passed

Install Nit

skills CLI
$ npx skills add koolamusic/claudefiles --skill nit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install koolamusic/claudefiles nit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/koolamusic/claudefiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/nit .claude/skills/nit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nit
GitHub stars
130
Token cost
~941 tokens
SKILL.md length
498 words
Files
5 (incl. references)
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Adversarial bug finding using 3 isolated agents (Hunter, Skeptic, Referee) to find and verify real bugs with high fidelity.

  • Works in 6 steps: Read the prompt files and check for… → Run the Hunter Agent → Run the Skeptic Agent → …
  • SKILL.md covers Target, Triage (Nit Ignore) and Execution Steps
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nit is an agent skill from koolamusic/claudefiles. Adversarial bug finding using 3 isolated agents (Hunter, Skeptic, Referee) to find and verify real bugs with high fidelity. Based on bug-hunt by danpeg (https://github.com/danpeg/bug-hunt).

Its SKILL.md is about 940 tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `prompts/hunter.md`, `prompts/referee.md` and `prompts/skeptic.md`).

It works with GitHub. The repository describes itself as: A minimal catalog of my favourite skills for working with claude. The licence is MIT.

Example prompts

  • “/nit”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Read the prompt files and check for ignore list
  2. Run the Hunter Agent
  3. Run the Skeptic Agent
  4. Run the Referee Agent
  5. Present the Nit Report
  6. Offer Triage

What it can do on your machine

Read from SKILL.md and the folder at commit 297c432. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nit loads about 941 tokens when it runs, and up to ~1.2k if it reads all its reference files. Until then it costs about 48 tokens; SKILL.md has 498 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~941
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from koolamusic/claudefiles at commit 297c432, republished under its MIT licence (© koolamusic). 498 words, ~941 tokens.

Download SKILL.mdSave it as .claude/skills/nit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
nit
description
Adversarial bug finding using 3 isolated agents (Hunter, Skeptic, Referee) to find and verify real bugs with high fidelity. Based on bug-hunt by danpeg (https://github.com/danpeg/bug-hunt).
argument-hint
[path/to/scan]
disable-model-invocation
true

Nit - Adversarial Bug Finding

Run a 3-agent adversarial nit hunt on your codebase. Each agent runs in isolation.

Target

The scan target is: $ARGUMENTS

If no target was specified, scan the current working directory.

Triage (Nit Ignore)

Nit respects a project-level ignore file at .claude/nitignore.md. This file tracks:

  • intentional — findings that are by design (won't fix)
  • remediated — findings that have already been fixed

Entries use a rule field formatted as category::description (e.g. security::hardcoded-token). Nit matches on file + rule to skip known findings.

A template is available at ${CLAUDE_SKILL_DIR}/references/nitignore-template.md.

Execution Steps

You MUST follow these steps in exact order. Each agent runs as a separate subagent via the Agent tool to ensure context isolation.

Step 1: Read the prompt files and check for ignore list

Read these files using the skill directory variable:

  • ${CLAUDE_SKILL_DIR}/prompts/hunter.md
  • ${CLAUDE_SKILL_DIR}/prompts/skeptic.md
  • ${CLAUDE_SKILL_DIR}/prompts/referee.md

Also check if .claude/nitignore.md exists in the project root. If it does, read it and pass the ignore entries to each agent so they can skip already-triaged findings.

Step 2: Run the Hunter Agent

Launch a general-purpose subagent with the hunter prompt. Include the scan target in the agent's task. The Hunter must use tools (Read, Glob, Grep) to examine the actual code.

Wait for the Hunter to complete and capture its full output.

Step 2b: Check for findings

If the Hunter reported TOTAL FINDINGS: 0, skip Steps 3-4 and go directly to Step 5 with a clean report. No need to run Skeptic and Referee on zero findings.

Step 3: Run the Skeptic Agent

Launch a NEW general-purpose subagent with the skeptic prompt. Inject the Hunter's structured bug list (BUG-IDs, files, lines, claims, evidence, severity, points). Do NOT include any narrative or methodology text outside the structured findings.

The Skeptic must independently read the code to verify each claim.

Wait for the Skeptic to complete and capture its full output.

Show full SKILL.md (192 more words)Show less
Step 4: Run the Referee Agent

Launch a NEW general-purpose subagent with the referee prompt. Inject BOTH:

  • The Hunter's full bug report
  • The Skeptic's full challenge report

The Referee must independently read the code to make final judgments.

Wait for the Referee to complete and capture its full output.

Step 5: Present the Nit Report

Display the Referee's final verified nit report to the user. Include:

  1. The summary stats
  2. The confirmed bugs table (sorted by severity)
  3. Low-confidence items flagged for manual review
  4. A collapsed section with dismissed bugs (for transparency)
  5. Triage-ready entries (see below)

If zero bugs were confirmed, say so clearly — a clean report is a good result.

Step 6: Offer Triage

After presenting findings, offer the user the option to triage. For each confirmed bug, output a pre-formatted ignore entry the user can approve:

| intentional | category::description | file/path | line(s) | [user adds rationale] |

Ask: "Would you like to dismiss any of these as intentional, or mark any as remediated? I can update .claude/nitignore.md for you."

If the user selects entries to triage:

  1. If .claude/nitignore.md doesn't exist, create it from ${CLAUDE_SKILL_DIR}/references/nitignore-template.md
  2. Append the selected entries to the table
  3. Confirm what was added

© koolamusic, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/nit of koolamusic/claudefiles.

  • SKILL.md
  • prompts/hunter.md
  • prompts/referee.md
  • prompts/skeptic.md
  • references/nitignore-template.md

Open the folder on GitHubat commit 297c432

Compare with similar skills

Nit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nit this skillkoolamusic/claudefiles130—~941Automated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Diagnosing Superpowers Sessionsobra/superpowers296k3 repos~1.7kAutomated safety check: PassMIT
GitHub Deep Researchbytedance/deer-flow83k5 repos~1.3kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.

    296k GitHub starsUsed in 3 repos~1.7k tokens
    Agent WorkflowsAuto-check passed
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    83k GitHub starsUsed in 5 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Last30days

    mvanhorn/last30days-skill

    Research what people actually say about any topic in the last 30 days.

    64k GitHub stars~7.8k tokensUpdated today
    Research & ScienceAuto-check: notes

More from koolamusic/claudefiles

All 13 skills in this repo
  • Explainer Formats

    koolamusic/claudefiles

    A skill your agent uses when asked to explain a topic, codebase, process, or document in a specific output format — plain language or Simplified Technical English (STE, in the style of ASD-STE100…

    130 GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Breadboarding

    koolamusic/claudefiles

    Transform a workflow description into affordance tables showing UI and Code affordances with their wiring.

    130 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Orchestrator

    koolamusic/claudefiles

    Turn the current session into a chief-of-staff thread that runs a war room of three role slots — surveyor, executor, auditor — and routes per-branch work to durable, reusable child agents.

    130 GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Retro

    koolamusic/claudefiles

    A skill your agent uses when a user completes a phase, sprint, milestone, or meaningful unit of work and needs a retrospective.

    130 GitHub stars~2.8k tokensUpdated 2 days ago
    Auto-check passed
  • Skill Creator

    koolamusic/claudefiles

    Guide for creating effective skills. An agent skill from koolamusic/claudefiles.

    130 GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Debug

    koolamusic/claudefiles

    A skill your agent uses when encountering any bug, test failure, or unexpected behavior, before proposing fixes - four-phase framework with built-in backward tracing for deep-stack failures…

    130 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Nit

What does Nit do?

Adversarial bug finding using 3 isolated agents (Hunter, Skeptic, Referee) to find and verify real bugs with high fidelity. Nit is an agent skill from koolamusic/claudefiles. Adversarial bug finding using 3 isolated agents (Hunter, Skeptic, Referee) to find and verify real bugs with high fidelity.

How do I install Nit in Claude Code?

Run `npx skills add koolamusic/claudefiles --skill nit -a claude-code`. Or copy the skill folder (skills/nit in koolamusic/claudefiles) into .claude/skills/nit in your project. Claude Code loads it when a task matches its description.

How do I install Nit in Codex?

Run `npx skills add koolamusic/claudefiles --skill nit -a codex`. Or copy the skill folder (skills/nit in koolamusic/claudefiles) into .agents/skills/nit in your project. Codex loads it when a task matches its description.

Can I use Nit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add koolamusic/claudefiles --skill nit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nit, .gemini/skills/nit, .github/skills/nit and .opencode/skills/nit in your project.

What does Nit need to run?

SKILL.md names no scripts, command-line tools or credentials: Nit is instructions for the agent only.

Does Nit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nit use?

Nit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nit use?

About 941 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 214 tokens, read only when the agent opens those files.

What are the alternatives to Nit?

Skills that share tags, products or a category with Nit: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Diagnosing Superpowers Sessions (obra/superpowers, 296k stars), GitHub Deep Research (bytedance/deer-flow, 83k stars) and Greploop (onyx-dot-app/onyx, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nit?

koolamusic (a GitHub user) maintains it in koolamusic/claudefiles, which has 130 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 5, 2026.

Source: koolamusic/claudefiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.