Agent skill

Bug Review

by pproenca in pproenca/dot-skills

A skill your agent uses when a user asks to review a pull request for bugs, wants AI code review focused on correctness issues, or runs /bug-review.

MITAuto-check passedDevelopment

Install Bug Review

skills CLI
$ npx skills add pproenca/dot-skills --skill bug-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pproenca/dot-skills bug-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pproenca/dot-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/bug-review .claude/skills/bug-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bug-review
GitHub stars
214
Token cost
~2.2k tokens
SKILL.md length
928 words
Files
17 (incl. scripts, references)
Skills in repo
182
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when a user asks to review a pull request for bugs, wants AI code review focused on correctness issues, or runs /bug-review.

  • Works in 6 steps: Parse Input & Fetch Context → Run 5 Parallel Review Passes → Aggregate & Vote → …
  • A user asks to review a pull request for bugs
  • SKILL.md covers When to Apply, Setup, Workflow Overview and Command: /bug-review, plus 5 more sections
  • Runs Shell scripts from its folder; calls git, gh and npm

What it does

Bug Review is an agent skill from pproenca/dot-skills. Use this skill when a user asks to review a pull request for bugs, wants AI code review focused on correctness issues, or runs /bug-review. Trigger on PR review, bug finding, code review, "review this PR", "check for bugs", "find issues in this PR". This is a multi-pass review workflow with 5 parallel passes, majority voting, independent Opus validation, and resolution rate tracking. Also trigger on /bug-review:resolve to classify whether findings were fixed at merge time, and /bug-review:report for resolution…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including scripts and reference files (for example `config.json`, `gotchas.md` and `hooks/hooks.json`).

It sits in Development, covering Pull requests. The repository describes itself as: A collection of AI agent skills following the Agent Skills open format. The licence is MIT.

When your agent uses it

  • A user asks to review a pull request for bugs
  • Wants AI code review focused on correctness issues
  • Runs /bug-review
  • Find issues in this PR

Example prompts

  • “review this PR”
  • “check for bugs”
  • “find issues in this PR”
  • “/bug-review”

Requirements

  • A Bash shell

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Parse Input & Fetch Context
  2. Run 5 Parallel Review Passes
  3. Aggregate & Vote
  4. Independent Validation (Opus)
  5. Dedup Against Prior Reviews
  6. Present Findings to User

What it can do on your machine

Read from SKILL.md and the folder at commit cf93c57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 10 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • gh
    • npm
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, gh and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bug Review loads about 2.2k tokens when it runs, and up to ~7.9k if it reads all its reference files. Until then it costs about 155 tokens; SKILL.md has 928 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~155
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from pproenca/dot-skills at commit cf93c57, republished under its MIT licence (© pproenca). 928 words, ~2,186 tokens.

Download SKILL.mdSave it as .claude/skills/bug-review/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.
name
bug-review
description
Use this skill when a user asks to review a pull request for bugs, wants AI code review focused on correctness issues, or runs /bug-review. Trigger on PR review, bug finding, code review, "review this PR", "check for bugs", "find issues in this PR". This is a multi-pass review workflow with 5 parallel passes, majority voting, independent Opus validation, and resolution rate tracking. Also trigger on /bug-review:resolve to classify whether findings were fixed at merge time, and /bug-review:report for resolution rate stats. Even if the user just says "review this" while on a PR branch, trigger this skill.
metadata.internal
true

Bug Review v2

Multi-pass PR review agent with 5 parallel review passes, majority voting, independent Opus validation, and resolution rate learning. Posts inline PR comments and optionally generates autofix commits. Tracks whether findings get resolved at merge time and uses that signal to improve future reviews.

When to Apply

  • User asks to review a pull request for bugs or correctness issues
  • User runs /bug-review <PR-number-or-URL>
  • User runs /bug-review:resolve <PR> to classify resolutions after merge
  • User runs /bug-review:report for resolution rate statistics
  • User asks for code review focused on logic errors, edge cases, or security
  • User wants to find bugs in a diff or set of changes

Setup

On first run, verify:

  • gh CLI is installed and authenticated (gh auth status)
  • Current directory is a git repo with a GitHub remote
  • jq is installed (for JSON processing)
  • bc is installed (for resolution rate calculations; pre-installed on most systems)

Read config.json for configuration (passes, vote threshold, models, category weights).

Workflow Overview

/bug-review <PR>
  |
  v
Fetch PR context + gather-context.sh
  |
  v
5 parallel passes (shuffled diffs, Sonnet) --> Aggregate & vote (3/5 majority)
  |
  v
Independent Opus validator --> Dedup --> Present findings --> Post + store
  |
  (later, after merge)
  v
/bug-review:resolve <PR> --> Classify resolutions --> Update category weights

Command: /bug-review <PR>

Step 1: Parse Input & Fetch Context
  1. Parse the PR identifier (number, URL, or branch name)
  2. Check cache: Look for ${CLAUDE_PLUGIN_DATA}/bug-review/cache/pr-{N}/ — if cache exists for the same head commit, offer to resume from the last checkpoint
  3. Run scripts/fetch-pr.sh <pr-identifier> to get PR diff + metadata as JSON
  4. Save the diff to a temp file for shuffling
  5. Run scripts/gather-context.sh <changed-files-json> to get prioritized context (callers, types, tests, repo rules)
  6. Read .bug-review.md from repo root if it exists
  7. Save checkpoint: Write context to ${CLAUDE_PLUGIN_DATA}/bug-review/cache/pr-{N}/context.json
Step 2: Run 5 Parallel Review Passes

For each pass (1-5), prepare a shuffled diff:

bash
scripts/shuffle-diff.sh <pass-number> < pr.diff > pass-<N>.diff

Launch 5 Agent subprocesses in parallel. Read review-passes.md for the exact prompt for each pass.

  • Pass 1: Logic & Edge Cases (seed 1)
  • Pass 2: Security & Data Integrity (seed 2)
  • Pass 3: Error Handling & API Contracts (seed 3)
  • Pass 4: Concurrency & State (seed 4)
  • Pass 5: Data Flow & Contracts (seed 5)

Use model from config.json agent_model (default: "sonnet").

Each agent returns a JSON array of findings.

Save checkpoint: Write all pass results to ${CLAUDE_PLUGIN_DATA}/bug-review/cache/pr-{N}/pass-results.json

Step 3: Aggregate & Vote
  1. Collect findings from all 5 passes
  2. Group findings by similarity: same file + line within +/-5 + same or related category
  3. Count votes per group
  4. Keep only findings with 3+ votes (majority of 5, configurable via vote_threshold)
  5. Apply category weights from config.json: final_score = votes × severity_weight × category_weight
  6. Categories with weight < 0.1 are suppressed entirely
  7. Rank by final_score descending

If only 1-2 passes found bugs and the others found none, present findings but note they lack consensus.

Save checkpoint: Write voted findings to cache.

Step 4: Independent Validation (Opus)

Launch a separate Agent using validator_model from config.json (default: "opus").

This agent has NOT seen the review passes. It receives only the voted findings and the original code. Read the Validator section in review-passes.md for the prompt.

For each finding, the validator outputs: {id, verdict: "KEEP"|"DISCARD", confidence, reasoning}

Remove DISCARDed findings. Multiply each finding's score by the validator's confidence.

Compute each finding's final confidence field:

confidence = (votes / total_passes) × validator_confidence

Findings with confidence < 0.5 are shown with a "low confidence" warning.

Save checkpoint: Write validated findings to cache.

Step 5: Dedup Against Prior Reviews

Run scripts/dedup.sh <pr-number> to get existing [bug-review] comments. Match by location proximity (file + line within +/-10) and category — not text similarity.

Show full SKILL.md (385 more words)Show less
Step 6: Present Findings to User

Display a table:

#SeverityConfidenceFileLineTitleVotes

For each finding, show full description, trigger scenario, suggested fix, and validator reasoning.

Ask the user (using AskUserQuestion with multiSelect):

  • Which findings to post as PR comments (default: all)
  • Which findings to autofix (default: none)

If no findings survived voting + validation: "No bugs found across 5 review passes. The changes look clean."

Step 7a: Post PR Review

Write approved findings to a temporary JSON file, then run:

bash
scripts/post-review.sh <pr-number> <findings-json-file>

Then persist findings for resolution tracking:

bash
scripts/store-findings.sh <pr-number> <findings-json-file> <head-commit-sha>
Step 7b: Autofix (User-Selected Findings)

For each finding selected for autofix:

  1. Read the file and understand surrounding context
  2. Generate a minimal fix (smallest possible change)
  3. Apply the fix using the Edit tool
  4. Scope check: Run git diff --stat — verify only the finding's file was modified and diff is under 20 lines. If exceeded, revert and warn.
  5. Run existing tests if available (npm test, go test ./..., pytest, etc.)
  6. If tests pass: commit with fix: {title} [bug-review]
  7. If tests fail: revert the fix (git checkout -- <file>) and report to user
  8. After all fixes: push to the PR branch

Safety: one commit per fix, run tests between fixes, never force-push, scope-validate every fix.

Command: /bug-review:resolve <PR>

Run after a PR is merged to classify whether findings were resolved.

  1. Run scripts/classify-resolutions.sh <pr-number>
    • Loads stored findings from ${CLAUDE_PLUGIN_DATA}/bug-review/findings/pr-{N}.json
    • Checks if PR is merged
    • For each finding: diffs code between review commit and merge commit
    • Classifies each as RESOLVED, UNRESOLVED, or INCONCLUSIVE
    • Updates the stored findings file with resolution data
  2. Display resolution summary to user
  3. If enough data accumulated (10+ findings, 3+ PRs): run scripts/update-weights.sh to adjust category weights

Command: /bug-review:report

Display resolution rate statistics across all tracked PRs.

Run scripts/resolution-report.sh which outputs:

  • Overall resolution rate
  • Resolution rate by severity
  • Resolution rate by category (sorted worst-first to highlight noisy categories)
  • Suppressed categories (weight < 0.1)

Repo-Specific Rules (.bug-review.md)

Teams can create .bug-review.md at their repo root:

markdown
## Focus Areas
- Pay special attention to authentication flows
- Check all database queries for SQL injection

## Ignore
- Don't flag issues in generated files (*.generated.ts)
- Ignore style-only concerns

## Invariants
- All API endpoints must check req.user before accessing user data
- Database migrations must be reversible

## Severity Overrides
- Treat any auth bypass as CRITICAL regardless of category default

How to Use

Read workflow.md for detailed step-by-step with error handling. Read review-passes.md for all 5 review pass prompts and the validator. Read categories.md for bug categories and learned weights.

  • Consider creating a Runbook skill for investigating bugs found by this review
  • Consider creating a CI/CD skill to run this review automatically on PR open

© pproenca, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 16 other files (scripts, references) in .agents/skills/bug-review of pproenca/dot-skills.

  • SKILL.md
  • config.json
  • gotchas.md
  • hooks/hooks.json
  • references/categories.md
  • references/review-passes.md
  • references/workflow.md
  • scripts/classify-resolutions.sh
  • scripts/dedup.sh
  • scripts/fetch-pr.sh
  • scripts/gather-context.sh
  • scripts/post-review.sh
  • scripts/resolution-report.sh
  • scripts/shuffle-diff.sh
  • scripts/store-findings.sh
  • scripts/update-weights.sh
  • scripts/verify.sh

Open the folder on GitHubat commit cf93c57

Compare with similar skills

Bug Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bug Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bug Review this skillpproenca/dot-skills214—~2.2kAutomated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
PR Design DocOpenHands/OpenHands90k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • PR Design Doc

    OpenHands/OpenHands

    For a non-trivial pull request, write a self-contained HTML design doc under the temporary .pr/ directory and link a visibility-appropriate preview in the PR description, so maintainers grasp the…

    90k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

More from pproenca/dot-skills

All 182 skills in this repo
  • Audio Voice Recovery

    pproenca/dot-skills

    Audio forensics and voice recovery guidelines for CSI-level audio analysis.

    214 GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Codemod React Pipeline

    pproenca/dot-skills

    Guided, scripted pipeline for running JSX/TSX/React codemods safely across large legacy codebases.

    214 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Dev Rfc

    pproenca/dot-skills

    Create well-structured RFCs and technical proposals for software projects.

    214 GitHub stars~3.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Dx Harness

    pproenca/dot-skills

    Developer-experience friction auditing and fixing — slow onboarding, repeated manual setup steps, missing bootstrap/reset/seed scripts, undiscoverable conventions.

    214 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Language Spec Author

    pproenca/dot-skills

    Turn a rough idea for a language into a complete, implementable specification — a DSL, query, config/data, template, or protocol language — by interviewing the author dimension by dimension until…

    214 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Python Pep Author

    pproenca/dot-skills

    Drafting Python Enhancement Proposals (PEPs) — proposing a Python language feature, a standard library change, an interoperability standard, or an informational/process document for the Python…

    214 GitHub stars~2.1k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Bug Review

What does Bug Review do?

A skill your agent uses when a user asks to review a pull request for bugs, wants AI code review focused on correctness issues, or runs /bug-review. Bug Review is an agent skill from pproenca/dot-skills. Use this skill when a user asks to review a pull request for bugs, wants AI code review focused on correctness issues, or runs /bug-review.

When should I use Bug Review?

Bug Review fits situations like: A user asks to review a pull request for bugs; wants AI code review focused on correctness issues; runs /bug-review; find issues in this PR.

How do I install Bug Review in Claude Code?

Run `npx skills add pproenca/dot-skills --skill bug-review -a claude-code`. Or copy the skill folder (.agents/skills/bug-review in pproenca/dot-skills) into .claude/skills/bug-review in your project. Claude Code loads it when a task matches its description.

How do I install Bug Review in Codex?

Run `npx skills add pproenca/dot-skills --skill bug-review -a codex`. Or copy the skill folder (.agents/skills/bug-review in pproenca/dot-skills) into .agents/skills/bug-review in your project. Codex loads it when a task matches its description.

Can I use Bug Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pproenca/dot-skills --skill bug-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bug-review, .gemini/skills/bug-review, .github/skills/bug-review and .opencode/skills/bug-review in your project.

What does Bug Review need to run?

Going by SKILL.md and its folder, Bug Review needs a shell for the scripts in its folder and the command-line tools its instructions call (git, gh, npm and go). Our summary lists: A Bash shell.

Does Bug Review access the network?

SKILL.md contains no URLs. Its commands use git, gh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Bug Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Bug Review use?

Bug Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bug Review use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.7k tokens, read only when the agent opens those files.

What are the alternatives to Bug Review?

Skills that share tags, products or a category with Bug Review: Finishing a Development Branch (obra/superpowers, 296k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bug Review?

pproenca (a GitHub user) maintains it in pproenca/dot-skills, which has 214 GitHub stars. The repository holds 182 skills in this directory. The repository was last updated on August 15, 2026.

Source: pproenca/dot-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.