Agent skill

Code Bug Investigation

by macalbert in macalbert/envilder

Investigate a reported defect, gather reproduction evidence, confirm root cause, and recommend a focused verification strategy without editing artifacts.

MITAuto-check passedDevelopment

Install Code Bug Investigation

skills CLI
$ npx skills add macalbert/envilder --skill code-bug-investigation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install macalbert/envilder code-bug-investigation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/code-bug-investigation .claude/skills/code-bug-investigation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-bug-investigation
GitHub stars
138
Token cost
~1.3k tokens
SKILL.md length
598 words
Files
1
Skills in repo
30
Repo updated
First seen
Licence
MIT

At a glance

Investigate a reported defect, gather reproduction evidence, confirm root cause, and recommend a focused verification strategy without editing artifacts.

  • Works in 4 steps: Build the Fastest Feedback Loop → Gather Evidence → Locate the Root Cause → …
  • Tasks that involve Root cause analysis
  • SKILL.md covers When to Use, 1. Build the Fastest Feedback…, 2. Gather Evidence and 3. Locate the Root Cause, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Bug Investigation is an agent skill from macalbert/envilder. Investigate a reported defect, gather reproduction evidence, confirm root cause, and recommend a focused verification strategy without editing artifacts. Production defects require focused regression evidence; test-infrastructure defects start with consumer or direct-workflow evidence.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Root cause analysis. The repository describes itself as: One secret mapping for local dev, CI/CD, and runtime. Envilder resolves cloud secrets from your own vaults without SaaS middlemen, duplicated config, or .env drift. The licence is MIT.

When your agent uses it

  • Tasks that involve Root cause analysis

Example prompts

  • “/code-bug-investigation”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Build the Fastest Feedback Loop
  2. Gather Evidence
  3. Locate the Root Cause
  4. Select the Proposed Verification Strategy

What it can do on your machine

Read from SKILL.md and the folder at commit b6a0327. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Bug Investigation loads about 1.3k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 598 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from macalbert/envilder at commit b6a0327, republished under its MIT licence (© macalbert). 598 words, ~1,310 tokens.

Download SKILL.mdSave it as .claude/skills/code-bug-investigation/SKILL.md (or your agent's skills folder).
name
code-bug-investigation
description
Investigate a reported defect, gather reproduction evidence, confirm root cause, and recommend a focused verification strategy without editing artifacts. Production defects require focused regression evidence; test-infrastructure defects start with consumer or direct-workflow evidence.

Bug Investigation

Turn a bug report into a confirmed root-cause analysis and a ready-to-establish verification plan. This skill investigates; it does not fix code or edit verification.

Use common-verification-first as the governing policy. The intent is BUG_FIX; infrastructure, configuration, and test infrastructure do not create separate intents.

When to Use

  • A user or reviewer reports incorrect behavior.
  • A GitHub issue describes a defect.
  • A failing check suggests a regression.
  • A patch seems obvious but the root cause has not been demonstrated.

1. Build the Fastest Feedback Loop

  1. Restate observed behavior, expected behavior, trigger, and environment.
  2. Find the narrowest existing way to trigger the symptom: test selector, API request, CLI command, build, validator, browser flow, or direct workflow.
  3. Reproduce before proposing a fix. If the defect cannot be reproduced, stop and report the missing conditions or evidence.
  4. Use temporary read-only diagnostics when the failure is otherwise invisible. Do not leave instrumentation or edit tracked artifacts during investigation.
Production Behavior

Find whether existing behavioral verification can reproduce the defect accurately. Recommend reusing or updating it when possible; otherwise recommend one focused regression at the lowest level that crosses the failing boundary. The Contract Verifier will establish and prove that regression before implementation.

Test Infrastructure

Start with a production-behavior consumer test or direct reproduction of the affected test workflow. Shared, public, reusable, or independently versioned support code does not justify direct tests.

Recommend the smallest focused test of a stable support contract only when consumer or workflow evidence cannot localize the fault precisely enough, and state the diagnostic precision gap.

2. Gather Evidence

From an issue, collect its title, description, reproduction steps, expected and actual results, environment, labels, and relevant recent comments. From a user report, resolve material ambiguity before continuing.

Capture command, input, output, and whether the evidence is repeatable. Separate:

  • confirmed observation;
  • inference supported by code or runtime evidence; and
  • unverified assumption.

3. Locate the Root Cause

  1. Identify the affected domain, application, adapter, SDK, UI, workflow, or support layer.
  2. Read the execution path and stable external boundary.
  3. Inspect existing verification and explain why it missed the defect.
  4. Trace the exact condition and code path that produce the wrong result.
  5. Confirm the root cause with the reproduction; do not confuse it with the symptom.
  6. Identify invariants and neighboring behavior that the fix must preserve.
Show full SKILL.md (206 more words)Show less

4. Select the Proposed Verification Strategy

For production behavior, choose one focused regression plan:

  • reuse an existing behavioral test unchanged;
  • update an existing test whose expectation is wrong or incomplete; or
  • add one focused regression because the behavior is absent.

Do not keep contradictory expectations or add redundant tests. Choose the lowest level that proves the real defect without mocking away its cause:

Defect boundaryTypical level
Pure domain ruleUnit
Application decision with stable portsUnit or focused integration
File, HTTP, cloud provider, or external adapterIntegration
DI, command dispatch, or cross-layer wiringIntegration
CLI or GitHub Action contractIntegration or e2e
UI rendering or interactionComponent or browser test
Critical user journeyE2E

For test infrastructure, use consumer or direct-workflow evidence instead of this table unless the documented diagnostic exception applies.

Output

text
BugAnalysis

Observed behavior:
Expected behavior:
Trigger and environment:
Reproduction command and result:
Confirmed root cause:
Affected code and scope:
Preserved invariants:
Existing coverage and why it missed the defect:
Proposed strategy: reuse | update | add one focused regression | consumer/direct workflow
Proposed behavior and level:
Diagnostic precision gap: none | explanation
Assumptions and unresolved evidence:
Status: READY_TO_ESTABLISH_CONTRACT | NOT_REPRODUCED | BLOCKED

At an interactive checkpoint, present this analysis before implementation. Calling workflows may fold it into their single specification checkpoint.

Rules

  • One defect per investigation.
  • Never propose a production fix without confirmed reproduction evidence.
  • Never edit production, verification, documentation, configuration, or test support.
  • Never claim a planned regression has failed until the Contract Verifier actually runs it.
  • Never add direct support tests for coverage or methodology.
  • Surface inability to reproduce instead of guessing.

© macalbert, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/code-bug-investigation of macalbert/envilder.

Open the folder on GitHubat commit b6a0327

Compare with similar skills

Code Bug Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Bug Investigation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Bug Investigation this skillmacalbert/envilder138—~1.3kAutomated safety check: PassMIT
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone
Evlog Log Analyzerevloghq/evlog1.9k—~2.4kAutomated safety check: PassMIT
Close Case Artifactdandye/ai-runbooks127—~615Automated safety check: PassApache-2.0
Dt AlertingDynatrace/dynatrace-for-ai161—~3.3kAutomated safety check: PassApache-2.0
CI Fixwarpdotdev/oz-skills825—~790Automated safety check: PassMIT

Similar skills

  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Evlog Log Analyzer

    evloghq/evlog

    Reads the structured wide-event logs that evlog writes to .evlog/logs/ so the agent can debug errors, find slow requests and explain what the app did.

    1.9k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Close Case Artifact

    dandye/ai-runbooks

    Close a case or alert with proper reason and documentation. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~615 tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Dt Alerting

    Dynatrace/dynatrace-for-ai

    End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and…

    161 GitHub stars~3.3k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • CI Fix

    warpdotdev/oz-skills

    Diagnose and fix GitHub Actions CI failures. An agent skill from warpdotdev/oz-skills.

    825 GitHub stars~790 tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Maiden Skill

    Xircth/VibeX

    Project-wide engineering principles for VibeX. An agent skill from Xircth/VibeX.

    136 GitHub stars~597 tokensUpdated 8 days ago
    DevelopmentAuto-check passed

More from macalbert/envilder

All 30 skills in this repo
  • Code Review Perspectives

    macalbert/envilder

    Five independent analysis perspectives for code review: correctness, architecture, security, conventions, and complexity.

    138 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Index of Architecture Decision Records (ADRs) for cross-cutting technical decisions.

    138 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Common Git

    macalbert/envilder

    Git commit messages, PR workflow, and branching strategy using Conventional Commits and Semantic Versioning.

    138 GitHub stars~991 tokensUpdated 2 days ago
    Auto-check passed
  • Common Testing Conventions

    macalbert/envilder

    Mandatory testing conventions including the narrow diagnostic exception for testing test-only code, AAA pattern, test naming, and assertions across all stacks (.NET, TypeScript, Python).

    138 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Doc Maintenance

    macalbert/envilder

    Workflow for maintaining changelogs, READMEs, and documentation files.

    138 GitHub stars~904 tokensUpdated 2 days ago
    Auto-check passed
  • Doc Sync

    macalbert/envilder

    Audit and synchronize documentation across website, READMEs, and docs/.

    138 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed

Questions about Code Bug Investigation

What does Code Bug Investigation do?

Investigate a reported defect, gather reproduction evidence, confirm root cause, and recommend a focused verification strategy without editing artifacts. Code Bug Investigation is an agent skill from macalbert/envilder. Investigate a reported defect, gather reproduction evidence, confirm root cause, and recommend a focused verification strategy without editing artifacts.

When should I use Code Bug Investigation?

Code Bug Investigation fits situations like: tasks that involve Root cause analysis.

How do I install Code Bug Investigation in Claude Code?

Run `npx skills add macalbert/envilder --skill code-bug-investigation -a claude-code`. Or copy the skill folder (.github/skills/code-bug-investigation in macalbert/envilder) into .claude/skills/code-bug-investigation in your project. Claude Code loads it when a task matches its description.

How do I install Code Bug Investigation in Codex?

Run `npx skills add macalbert/envilder --skill code-bug-investigation -a codex`. Or copy the skill folder (.github/skills/code-bug-investigation in macalbert/envilder) into .agents/skills/code-bug-investigation in your project. Codex loads it when a task matches its description.

Can I use Code Bug Investigation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add macalbert/envilder --skill code-bug-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-bug-investigation, .gemini/skills/code-bug-investigation, .github/skills/code-bug-investigation and .opencode/skills/code-bug-investigation in your project.

What does Code Bug Investigation need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Bug Investigation is instructions for the agent only.

Does Code Bug Investigation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Bug Investigation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Bug Investigation use?

Code Bug Investigation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Bug Investigation use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Bug Investigation?

Skills that share tags, products or a category with Code Bug Investigation: Code Design Rationale Investigator (cursor/plugins, 10k stars), Evlog Log Analyzer (evloghq/evlog, 1.9k stars), Close Case Artifact (dandye/ai-runbooks, 127 stars) and Dt Alerting (Dynatrace/dynatrace-for-ai, 161 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Bug Investigation?

macalbert (a GitHub user) maintains it in macalbert/envilder, which has 138 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 5, 2026.

Source: macalbert/envilder on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.