Find Postgres Bug
digoal/blog
Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core…
Finds state inconsistency bugs where an operation mutates one piece of coupled state without updating its dependent counterpart, causing silent data corruption or reverts in subsequent operations.
$ npx skills add 0xiehnnkta/nemesis-auditor --skill state-inconsistency-auditor -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install 0xiehnnkta/nemesis-auditor state-inconsistency-auditor --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/0xiehnnkta/nemesis-auditor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/state-inconsistency-auditor .claude/skills/state-inconsistency-auditor && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "state-inconsistency-auditor" agent skill from https://github.com/0xiehnnkta/nemesis-auditor/tree/main/.claude/skills/state-inconsistency-auditor into .claude/skills/state-inconsistency-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "state-inconsistency-auditor", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/0xiehnnkta/nemesis-auditor/tree/main/.claude/skills/state-inconsistency-auditorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add 0xiehnnkta/nemesis-auditor --skill state-inconsistency-auditor -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install 0xiehnnkta/nemesis-auditor state-inconsistency-auditor --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/0xiehnnkta/nemesis-auditor.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/state-inconsistency-auditor .agents/skills/state-inconsistency-auditor && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "state-inconsistency-auditor" agent skill from https://github.com/0xiehnnkta/nemesis-auditor/tree/main/.claude/skills/state-inconsistency-auditor into .agents/skills/state-inconsistency-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "state-inconsistency-auditor", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add 0xiehnnkta/nemesis-auditor --skill state-inconsistency-auditor -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install 0xiehnnkta/nemesis-auditor state-inconsistency-auditor --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/0xiehnnkta/nemesis-auditor.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/state-inconsistency-auditor .cursor/skills/state-inconsistency-auditor && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "state-inconsistency-auditor" agent skill from https://github.com/0xiehnnkta/nemesis-auditor/tree/main/.claude/skills/state-inconsistency-auditor into .cursor/skills/state-inconsistency-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "state-inconsistency-auditor", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/0xiehnnkta/nemesis-auditor.git --path .claude/skills/state-inconsistency-auditor--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add 0xiehnnkta/nemesis-auditor --skill state-inconsistency-auditor -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install 0xiehnnkta/nemesis-auditor state-inconsistency-auditor --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/0xiehnnkta/nemesis-auditor.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/state-inconsistency-auditor .gemini/skills/state-inconsistency-auditor && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "state-inconsistency-auditor" agent skill from https://github.com/0xiehnnkta/nemesis-auditor/tree/main/.claude/skills/state-inconsistency-auditor into .gemini/skills/state-inconsistency-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "state-inconsistency-auditor", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install 0xiehnnkta/nemesis-auditor state-inconsistency-auditorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add 0xiehnnkta/nemesis-auditor --skill state-inconsistency-auditor -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/0xiehnnkta/nemesis-auditor.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/state-inconsistency-auditor .github/skills/state-inconsistency-auditor && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "state-inconsistency-auditor" agent skill from https://github.com/0xiehnnkta/nemesis-auditor/tree/main/.claude/skills/state-inconsistency-auditor into .github/skills/state-inconsistency-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "state-inconsistency-auditor", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add 0xiehnnkta/nemesis-auditor --skill state-inconsistency-auditor -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install 0xiehnnkta/nemesis-auditor state-inconsistency-auditor --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/0xiehnnkta/nemesis-auditor.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/state-inconsistency-auditor .opencode/skills/state-inconsistency-auditor && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "state-inconsistency-auditor" agent skill from https://github.com/0xiehnnkta/nemesis-auditor/tree/main/.claude/skills/state-inconsistency-auditor into .opencode/skills/state-inconsistency-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "state-inconsistency-auditor", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
state-inconsistency-auditorFinds state inconsistency bugs where an operation mutates one piece of coupled state without updating its dependent counterpart, causing silent data corruption or reverts in subsequent operations.
State Inconsistency Auditor is an agent skill from 0xiehnnkta/nemesis-auditor. Finds state inconsistency bugs where an operation mutates one piece of coupled state without updating its dependent counterpart, causing silent data corruption or reverts in subsequent operations. Triggers on /state-audit, state inconsistency audit, or coupled state audit.
Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: The Inescapable Auditor -- iterative deep-logic security audit agent for Claude Code. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 75cecc6. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and language).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
State Inconsistency Auditor loads about 5.4k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 1,493 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from 0xiehnnkta/nemesis-auditor at commit 75cecc6, republished under its MIT licence (© 0xiehnnkta). 1,493 words, ~5,382 tokens.
.claude/skills/state-inconsistency-auditor/SKILL.md (or your agent's skills folder).Finds bugs where an operation mutates one piece of coupled state without updating its dependent counterpart, causing silent data corruption or reverts in subsequent operations.
Language-agnostic by design. Coupled state bugs exist in any system that maintains related storage values — Solidity, Move, Rust, Go, C++, or anything else.
This agent performs structural invariant analysis — systematically mapping every coupled state pair, every mutation path, and every gap where one side updates without the other. It complements first-principles reasoning (Feynman) and pattern-matching tools by finding structural state desync bugs that other methodologies miss.
/feynman instead)Every system has COUPLED STATE PAIRS — two or more storage values that must maintain a relationship (an invariant) with each other. When any operation changes one side of the pair without adjusting the other, the invariant breaks. Future operations that read both values produce incorrect results.
Examples of coupled state:
The bug class: Operation X correctly updates State A, but fails to proportionally adjust the coupled State B. State B is now stale relative to State A.
When you start, detect the language and adapt terminology:
| Concept | Solidity | Move | Rust | Go | C++ |
|---|---|---|---|---|---|
| Storage | state variables | global storage / resources | struct fields / state | struct fields / DB | member variables |
| Mapping | mapping(k => v) | Table<K, V> / SmartTable | HashMap / BTreeMap | map[K]V | std::map / unordered_map |
| Delete | delete mapping[key] | table::remove | map.remove(&key) | delete(map, key) | map.erase(key) |
| Event | emit Event() | event::emit() | emit! / log | EventEmit() | signal / callback |
| Internal call | internal function | friend function | pub(crate) fn | unexported func | private method |
RULE 0: MAP BEFORE YOU HUNT
Never start checking functions until you have the complete coupled state
dependency map. You cannot find a missing update if you don't know what
updates are required.
RULE 1: EVERY MUTATION PATH MATTERS
A state variable might be modified by 5 different functions. ALL 5 must
update the coupled state. If 4 do and 1 doesn't — that's the bug.
RULE 2: PARTIAL OPERATIONS ARE THE #1 SOURCE
Full removals (delete everything) usually reset all state correctly.
Partial operations (reduce by X) frequently forget to proportionally
reduce the coupled state.
RULE 3: COMPARE PARALLEL PATHS
If transfer() and burn() both reduce a balance, they MUST both update
the same set of coupled state. If one does and the other doesn't — finding.
RULE 4: DEFENSIVE CODE MASKS BUGS
Code like `x > y ? x - y : 0` or `min(computed, available)` silently
hides broken invariants. These are red flags, not safety nets.
RULE 5: EVIDENCE-BASED FINDINGS ONLY
Every finding must include: the coupled pair, the breaking operation,
a concrete trigger sequence, and the downstream consequence.For every storage variable, ask: "What other storage values must change when this one changes?"
Build a dependency map:
State A changes → State B MUST also change (and vice versa)
State C changes → State D and State E MUST also changeLook for:
Output of Phase 1: A Coupled State Dependency Map.
┌─────────────────────────────────────────────────────────────┐
│ COUPLED STATE DEPENDENCY MAP │
├─────────────────────────────────────────────────────────────┤
│ │
│ PAIR 1: userBalance[user] ↔ checkpoint[user] │
│ Invariant: checkpoint must reflect balance at last update │
│ Mutation points: deposit(), withdraw(), transfer(), burn() │
│ │
│ PAIR 2: totalStaked ↔ rewardPerTokenStored │
│ Invariant: rewardPerToken must be updated before │
│ totalStaked changes │
│ Mutation points: stake(), unstake(), emergencyWithdraw() │
│ │
│ PAIR 3: position.collateral ↔ position.debtShares │
│ Invariant: health factor derived from both must stay valid │
│ Mutation points: addCollateral(), borrow(), repay(), │
│ liquidate(), withdrawCollateral() │
│ │
│ ... │
└─────────────────────────────────────────────────────────────┘For EACH state variable identified in Phase 1, list every function and code path that modifies it. Include:
state = newValuestate += delta, state -= deltadelete state, state = 0, state = default_mint(), _burn(), _transfer())_burn, rebasing changes effective balance without explicit writeOutput of Phase 2: A Mutation Matrix.
┌──────────────────────────────────────────────────────────────────┐
│ MUTATION MATRIX │
├──────────────────┬───────────────────┬───────────────────────────┤
│ State Variable │ Mutating Function │ Type of Mutation │
├──────────────────┼───────────────────┼───────────────────────────┤
│ userBalance[u] │ deposit() │ increment (+= amount) │
│ userBalance[u] │ withdraw() │ decrement (-= amount) │
│ userBalance[u] │ transfer() │ decrement sender, inc recv │
│ userBalance[u] │ _burn() │ decrement (-= amount) │
│ userBalance[u] │ liquidate() │ decrement (-= seized) │
│ checkpoint[u] │ deposit() │ full reset │
│ checkpoint[u] │ withdraw() │ full reset │
│ checkpoint[u] │ transfer() │ ??? — CHECK THIS │
│ checkpoint[u] │ _burn() │ ??? — CHECK THIS │
│ checkpoint[u] │ liquidate() │ ??? — CHECK THIS │
└──────────────────┴───────────────────┴───────────────────────────┘The ??? entries are your primary audit targets — mutations of State A where you haven't confirmed State B is also updated.
For EVERY (operation, state variable) pair from Phase 2:
"This operation modifies State A. Does it ALSO update every coupled state that depends on A?"
Check specifically:
□ Full removal (A → 0): Is every coupled state reset/cleared?
□ Partial removal (A decreases): Is every coupled state proportionally reduced?
□ Increase (A grows): Is every coupled state proportionally increased?
□ Transfer (A moves between entities): Is coupled state moved too?
□ Deletion (mapping entry removed): Is the paired mapping entry also removed?
□ Batch modification: Is coupled state updated per-iteration or only once?If ANY path updates A without updating its coupled state → FINDING.
For each potential finding, trace the FULL code path:
Many functions perform multiple state changes sequentially. Trace the exact order:
function doSomething() {
step1: reads State A and State B → computes result
step2: modifies State B based on result
step3: modifies State A
// State B is now stale relative to new State A
}Ask at each step:
Common ordering bugs:
Find operations that achieve similar outcomes through different paths:
transfer() vs burn() — both reduce sender balancewithdraw() vs liquidate() — both reduce positionpartial vs full removal — both decrease, different amountsFor each group, compare: do ALL paths update the same coupled state?
┌────────────────────────────────────────────────────────────┐
│ PARALLEL PATH COMPARISON │
├─────────────────┬──────────────┬──────────────┬────────────┤
│ Coupled State │ withdraw() │ liquidate() │ emergencyW │
├─────────────────┼──────────────┼──────────────┼────────────┤
│ balance │ ✓ updated │ ✓ updated │ ✓ updated │
│ checkpoint │ ✓ updated │ ✗ MISSING │ ✗ MISSING │
│ totalSupply │ ✓ updated │ ✓ updated │ ✗ MISSING │
│ rewardDebt │ ✓ updated │ ✗ MISSING │ ✗ MISSING │
└─────────────────┴──────────────┴──────────────┴────────────┘
FINDINGS: liquidate() and emergencyWithdraw() don't update checkpoint
or rewardDebt when reducing balance.If Path A adjusts the coupled state but Path B doesn't → FINDING.
Simulate sequences where a user interacts multiple times:
1. User enters a position (state initialized)
2. Time passes / external state evolves (index grows, prices change)
3. User does PARTIAL modification (coupled state may break here)
4. More time passes / external state evolves
5. User does another operation reading the coupled stateAt step 5, ask:
Key sequences to test:
Look for defensive code that HIDES broken invariants:
MASKING PATTERN 1: Ternary clamp
x > y ? x - y : 0
→ WHY would x ever be less than y? If the invariant held, it wouldn't.
This silently returns 0 instead of reverting on the broken state.
MASKING PATTERN 2: Try/catch swallowing
try target.call() {} catch {}
→ The revert from broken state is caught and ignored.
MASKING PATTERN 3: Early exit on zero
if (value == 0) return;
→ Skips the computation entirely when the broken state produces zero.
MASKING PATTERN 4: Min cap
min(computed, available)
→ Caps the result when broken state over-counts. The over-counting
is the bug; the min() just prevents the revert.
MASKING PATTERN 5: SafeMath without root cause fix
→ Prevents underflow revert but doesn't fix WHY the subtraction
would underflow. The state is still inconsistent.
MASKING PATTERN 6: Fallback to default
value = mapping[key] // returns 0 for non-existent key
→ If the key SHOULD exist but was deleted without cleaning its
coupled entry, the zero default masks the missing data.These patterns convert what SHOULD be a loud failure into a silent one. The invariant is still broken — the symptom is just suppressed. Flag every instance and trace whether the defensive code is hiding a real state inconsistency.
- [ ] A function modifies a base value but has no writes to its coupled state
- [ ] Two similar operations (e.g., transfer vs burn) handle coupled state differently
- [ ] A "claim/collect" step runs before a "reduce/remove" step, and
nothing reconciles afterward
- [ ] Partial operations exist alongside full operations, but only the full
operation resets/clears the coupled state
- [ ] A defensive ternary or min() exists in a computation involving two
coupled values (asks: WHY would this ever underflow?)
- [ ] delete or reset of one mapping but not its paired mapping
- [ ] A loop processes multiple sub-positions but accumulates into a
shared coupled value without per-iteration adjustment
- [ ] An emergency/admin function bypasses the normal state update path
- [ ] A migration or upgrade function copies State A but not State B
- [ ] A callback or hook modifies State A but the caller doesn't know
to update State B afterwardEvery CRITICAL, HIGH, and MEDIUM finding MUST be verified before final report.
Method A: Code Trace Verification
Method B: PoC Test Verification
Method C: Hybrid (trace + PoC) For complex multi-contract findings spanning multiple modules.
_beforeTokenTransfer hook)._updateReward() modifier runs before every function).| Severity | Criteria |
|---|---|
| CRITICAL | Coupled state desync causes direct value loss (wrong payouts, stolen funds, permanent lock) |
| HIGH | Coupled state desync causes conditional value loss or broken core functionality |
| MEDIUM | Coupled state desync causes incorrect accounting, griefing, or degraded functionality |
| LOW | Coupled state desync causes cosmetic issues, event inaccuracy, or edge-case-only errors |
Save raw findings to: .audit/findings/state-inconsistency-raw.md
Save verified findings to: .audit/findings/state-inconsistency-verified.md
# State Inconsistency Audit — Verified Findings
## Coupled State Dependency Map
[The map from Phase 1]
## Mutation Matrix
[The matrix from Phase 2]
## Parallel Path Comparison
[The comparison table from Phase 5]
## Verification Summary
| ID | Coupled Pair | Breaking Op | Original Severity | Verdict | Final Severity |
|----|-------------|-------------|-------------------|---------|----------------|
## Verified Findings
### Finding SI-001: [Title]
**Severity:** CRITICAL | HIGH | MEDIUM | LOW
**Verification:** [Code trace / PoC / Hybrid]
**Coupled Pair:** State A ↔ State B
**Invariant:** [What relationship must hold between them]
**Breaking Operation:** `functionName()` in `Contract.sol:L123`
- Modifies State A: [how]
- Does NOT update State B: [what's missing]
**Trigger Sequence:**
1. [Step-by-step minimal sequence to break the invariant]
**Consequence:**
- [What goes wrong when a later operation reads both A and B]
- [Concrete impact: wrong payout amount, locked funds, etc.]
**Masking Code** (if present):
```[language]
// This defensive code hides the broken invariant:
[the masking pattern]Fix:
// Add the missing state synchronization:
[minimal fix][Findings that failed verification, with explanation]
---
## Post-Audit Actions
| Scenario | Action |
|----------|--------|
| Need deeper context on a function | Re-read the function and its callers line-by-line |
| Finding confirmed as true positive | Write up with severity, trigger sequence, PoC, and fix |
| Need first-principles reasoning on a pair | Run `/feynman` on the specific functions involved |
| Need exploit validation | Write a Foundry/Hardhat PoC test to confirm |
| Uncertain about design intent | Check NatSpec, comments, and project documentation |
---
## Anti-Hallucination Protocol
NEVER:
ALWAYS:
---
## Quick-Start Checklist
- [ ] **Phase 1:** Map all storage variables and their coupled dependencies
- [ ] **Phase 1:** Build the Coupled State Dependency Map
- [ ] **Phase 2:** For each state variable, list every mutating function
- [ ] **Phase 2:** Build the Mutation Matrix (mark `???` for unconfirmed updates)
- [ ] **Phase 3:** Cross-check every mutation — does it update all coupled state?
- [ ] **Phase 4:** Check operation ordering within each function
- [ ] **Phase 5:** Compare parallel code paths (transfer/burn, withdraw/liquidate, etc.)
- [ ] **Phase 6:** Trace multi-step user journeys for stale state accumulation
- [ ] **Phase 7:** Flag all defensive/masking code and trace whether it hides broken invariants
- [ ] **Phase 8:** Verify ALL C/H/M findings (code trace + PoC)
- [ ] **Phase 8:** Eliminate false positives (hidden reconciliation, lazy eval, designed asymmetry)
- [ ] **Phase 8:** Save verified findings to `.audit/findings/state-inconsistency-verified.md`
- [ ] **Phase 8:** Present ONLY verified report to the user© 0xiehnnkta, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/state-inconsistency-auditor of 0xiehnnkta/nemesis-auditor.
Open the folder on GitHubat commit 75cecc6
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in 0xiehnnkta/nemesis-auditor, which our catalogue first saw on October 7, 2026.
State Inconsistency Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| State Inconsistency Auditor this skill0xiehnnkta/nemesis-auditor | 243 | 1 repos | ~5.4k | Automated safety check: Pass | MIT | |
| Find Postgres Bugdigoal/blog | 8.6k | — | ~4k | Automated safety check: Pass | GPL-2.0 | |
| Bug Finder for daisyUIsaadeghi/daisyui | 43k | — | ~2.3k | Automated safety check: Pass | MIT | |
| Find Bugsgetsentry/skills | 1k | 9 repos | ~708 | Automated safety check: Pass | Apache-2.0 | |
| Bug Huntersickn33/agentic-awesome-skills | 47k | 2 repos | ~2k | Automated safety check: Pass | MIT | |
| Bugs Are Annoyingsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.6k | Automated safety check: Pass | MIT |
digoal/blog
Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core…
saadeghi/daisyui
Investigates suspected bugs in the daisyUI monorepo through read-only analysis, then writes a decision-ready fix plan in tmp/bugs without changing any product code.
getsentry/skills
Find bugs, security vulnerabilities, and code quality issues in local branch changes.
sickn33/agentic-awesome-skills
Systematically finds and fixes bugs using proven debugging techniques.
sickn33/agentic-awesome-skills
Adversarial code auditor that hunts down bugs, logic errors, and security flaws.
flutter/flutter
A skill to find the lowest Dart and Flutter release containing a given commit.
0xiehnnkta/nemesis-auditor
Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.
0xiehnnkta/nemesis-auditor
The Inescapable Auditor. An agent skill from 0xiehnnkta/nemesis-auditor.
Finds state inconsistency bugs where an operation mutates one piece of coupled state without updating its dependent counterpart, causing silent data corruption or reverts in subsequent operations. State Inconsistency Auditor is an agent skill from 0xiehnnkta/nemesis-auditor. Finds state inconsistency bugs where an operation mutates one piece of coupled state without updating its dependent counterpart, causing silent data corruption or reverts in subsequent operations.
State Inconsistency Auditor fits situations like: state inconsistency audit; coupled state audit.
Run `npx skills add 0xiehnnkta/nemesis-auditor --skill state-inconsistency-auditor -a claude-code`. Or copy the skill folder (.claude/skills/state-inconsistency-auditor in 0xiehnnkta/nemesis-auditor) into .claude/skills/state-inconsistency-auditor in your project. Claude Code loads it when a task matches its description.
Run `npx skills add 0xiehnnkta/nemesis-auditor --skill state-inconsistency-auditor -a codex`. Or copy the skill folder (.claude/skills/state-inconsistency-auditor in 0xiehnnkta/nemesis-auditor) into .agents/skills/state-inconsistency-auditor in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 0xiehnnkta/nemesis-auditor --skill state-inconsistency-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/state-inconsistency-auditor, .gemini/skills/state-inconsistency-auditor, .github/skills/state-inconsistency-auditor and .opencode/skills/state-inconsistency-auditor in your project.
SKILL.md names no scripts, command-line tools or credentials: State Inconsistency Auditor is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
State Inconsistency Auditor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with State Inconsistency Auditor: Find Postgres Bug (digoal/blog, 8.6k stars), Bug Finder for daisyUI (saadeghi/daisyui, 43k stars), Find Bugs (getsentry/skills, 1k stars) and Bug Hunter (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
0xiehnnkta (a GitHub user) maintains it in 0xiehnnkta/nemesis-auditor, which has 243 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on March 16, 2026.
Source: 0xiehnnkta/nemesis-auditor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.