Agent skill

Ripwire Find Bug

by redhat-et in redhat-et/ripwire

You have a SYMPTOM — crash, exception, wrong output, failing test, error string — and don't know which code is responsible.

Apache-2.0Auto-check: notesDevelopment

Install Ripwire Find Bug

skills CLI
$ npx skills add redhat-et/ripwire --skill ripwire-find-bug -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install redhat-et/ripwire ripwire-find-bug --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ripwire-find-bug .claude/skills/ripwire-find-bug && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ripwire-find-bug
GitHub stars
2.4k
Token cost
~2.2k tokens
SKILL.md length
1,161 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

You have a SYMPTOM — crash, exception, wrong output, failing test, error string — and don't know which code is responsible.

  • Works in 4 steps: Symptom search — ripwire --for="" → If several candidates remain,… → If the symptom is broad, blast radius of… → …
  • Tasks that involve Debugging
  • SKILL.md covers Branch A — "I have a symptom,…, Branch B — "I suspect a…, Branch C — "I changed X and… and Branch D — "I have a stack…, plus 1 more section
  • Calls git, pytest and sh

What it does

Ripwire Find Bug is an agent skill from redhat-et/ripwire. You have a SYMPTOM — crash, exception, wrong output, failing test, error string — and don't know which code is responsible. Ranks candidates; a stack trace or sanitizer output maps onto frames innermost-first; 'it worked yesterday' / 'my last edit broke it' → --situ. One clear hit plus one focused read is enough.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Debugging and Failing and flaky tests. The repository describes itself as: The ripgrep of AI context: a zero-dependency C++23 CLI + MCP server for coding agents. Find what you want without reading the repo, then check you built what you meant — blast… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Debugging
  • Tasks that involve Failing and flaky tests

Example prompts

  • “it worked yesterday”
  • “my last edit broke it”
  • “/ripwire-find-bug”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Bash, Read

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Symptom search — ripwire --for=""
  2. If several candidates remain, maintenance hotspots — ripwire --hotspots --legend=compact
  3. If the symptom is broad, blast radius of each remaining candidate — ripwire --impact=SYM --legend=compact
  4. Read narrowly — start with the top symbol/body or the smallest source range that can confirm or

What it can do on your machine

Read from SKILL.md and the folder at commit 255dc19. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • pytest
    • sh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ripwire Find Bug loads about 2.2k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 1,161 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from redhat-et/ripwire at commit 255dc19, republished under its Apache-2.0 licence (© redhat-et). 1,161 words, ~2,178 tokens.

Download SKILL.mdSave it as .claude/skills/ripwire-find-bug/SKILL.md (or your agent's skills folder).
name
ripwire-find-bug
description
You have a SYMPTOM — crash, exception, wrong output, failing test, error string — and don't know which code is responsible. Ranks candidates; a stack trace or sanitizer output maps onto frames innermost-first; 'it worked yesterday' / 'my last edit broke it' → --situ. One clear hit plus one focused read is enough.
allowed-tools
Bash, Read

Find the bug with ripwire

Nearest neighbours: • You already know the symbol and just want to understand it → ripwire-navigate. • You want the blast radius / tests for a change (not to find a bug) → ripwire-change-check. • Repo-wide quality once-over, no specific symptom → ripwire-fresh-eyes. • "Why don't I see feature X?" and nothing looks broken — the code may be built but compiled/flagged OFF, not buggy: ripwire <dir> --flags[=SUBSTR] --legend=compact (--flip=NAME for the blast radius of turning one ON) — lives in ripwire-fresh-eyes, worth a look before you go hunting for a bug that isn't one.

<dir> = repo root. Calls are warm after the first parse — chain freely. Pick the branch that matches what you already know; each converges on the same evidence trail (relevance × maintenance pain × blast radius), so you can escalate between them.

Evidence-sufficiency stop: escalate only while the responsible code is still ambiguous. If --for ranks one file/symbol clearly and a focused source read explains the symptom with a minimal fix, stop retrieval and implement/validate it. Do not automatically add --hotspots, --impact, another skill, or a whole-file read after the defect is already proven; those answer different questions and can cost more than the original localization. Resume the ladder only when the source contradicts the candidate, several candidates remain plausible, or the change's blast radius is itself part of the task.

Branch A — "I have a symptom, no idea where it lives"

  1. Symptom search — ripwire <dir> --for="<symptom in plain words>" <sigs> ranked by relevance — signatures + doc-comments closest to the symptom. The in= reuse count and cx= complexity are inline; prefer high-cx, high-in matches — complex, widely-called code fails in more ways. If the bundle says weak="1", reformulate — split camelCase terms, add synonyms from the domain, or quote an exact path/symbol from the issue — before trusting the ranking below it.
  2. If several candidates remain, maintenance hotspots — ripwire <dir> --hotspots --legend=compact <hotspots> ranked by score = churn × ccx; top= names the worst function per file. Bugs cluster in high-score files — cross with step 1: a symbol in both lists is your prime suspect.
  3. If the symptom is broad, blast radius of each remaining candidate — ripwire <dir> --impact=SYM --legend=compact for the top 2–3 from step 1. <impact of="SYM" defs="D" reaches="N"> lists everything that reaches SYM. A large reaches count is consistent with a symptom that appears in many places — that's the root, not a downstream effect.
  4. Read narrowly — start with the top symbol/body or the smallest source range that can confirm or reject it. Use the hotspot intersection only when step 1 did not already isolate a defensible candidate.

Branch B — "I suspect a subsystem — narrow it"

  1. Symptom-to-code — ripwire <dir> --for="<symptom>" → note the p= (file paths) of the top 5. Which directories recur? That's your first narrowing.
  2. Hotspots in those directories — ripwire <dir> --hotspots --legend=compact → files that are relevant to the symptom AND high churn+complexity are the most likely bug homes.
  3. Find the exact emit site — ripwire <dir> --grep="ERROR_STRING" --legend=compact (literal + enclosing symbol) or --regex="pattern". Add --grep-context=N (or --grep-before=N/--grep-after=N) for ripgrep-style lines of source around each hit — often enough to confirm the bug without a follow-up --expand. The enclosing symbol (in=) is ground truth — now --callers=SYM to trace up one level to the true root.

Branch C — "I changed X and now something's broken" (regression)

  1. Situational awareness on the change — ripwire <dir> --situ=fileA.cpp,fileB.h (or bare --situ to read from git diff). Emits, in one pass:
    • blast radius — everything that transitively reaches the changed symbols
    • tests to run now (--affected under the hood)
    • co-change partners NOT in your diff — files that historically move together (hidden coupling). This is the Shotgun Surgery check: did the change land everywhere it usually has to?
  2. Who calls the broken symbol — ripwire <dir> --callers=SYM --legend=compact → each recorded caller (a floor — counts_floor=) is a candidate for an unexpected side-effect.
  3. Co-change history — ripwire <dir> --cochange=fileA.cpp --legend=compact → partners ranked by deg (fraction of commits). A surprising="1" partner has no #include link — pure behavioural coupling, the non-obvious suspect.
  4. Read the functions that appear in BOTH the blast radius and the co-change list first.
Show full SKILL.md (485 more words)Show less

Branch D — "I have a stack trace / sanitizer report / compiler error"

You have the failing artifact's TEXT (a Python traceback, an ASan/UBSan report, a node/js stack, a clang/gcc diagnostic) — don't hand-translate its frames into queries one by one. Pipe it straight in:

  1. Map the trace onto symbols — ripwire <dir> --from-trace=FILE --legend=compact (or --from-trace=- to read the trace from stdin, e.g. pytest ... 2>&1 | ripwire <dir> --from-trace=- --legend=compact). Table-driven frame extraction (python / asan / node / compiler / generic), ranked innermost-first over the frames that resolve to your indexed code. Out-of-corpus frames (stdlib, vendored deps) are listed and counted, never ranked.
  2. Read rank 1 first — the innermost="1" suspect is the crash/throw site; its FULL body is emitted inline, the other suspects as signatures. skipped= tells you how many frames fell outside every root.
  3. Compose the budget — --from-trace=FILE --token-budget=N fits the bundle to N tokens for a tight context window. Unparseable input refuses loudly (never a misleading empty map).
  4. Or skip the run-read-paste loop entirely — ripwire <dir> --run-trace="make -j" --legend=compact RUNS the build/test command itself (sh -c, your user, your environment — the make trust model, no sandbox) and, on a non-zero exit, serves the SAME from-trace bundle for the captured output plus a token-frugal <lines view="relevant"> cut of the error/frame-shaped output lines. Exit 0 gets a minimal success record and no bundle — nothing failed, nothing to map. The command's own exit code is always disclosed (<run exit=>), and --run-timeout=SECONDS caps a hanging command (default 600 s, reported timed_out="1" honestly, never as an empty success).

Output

Report the branch you took, then: ranked candidate symbol(s) with name, file:line, and why (from --for); their hotspot score if present; their blast-radius count (--impact reaches=); the error site's enclosing symbol if --grep found it; and any surprising="1" co-change partner (branch C). Recommend the top 1–2 to inspect first, with the evidence trail.

Honesty: the call graph gives structure; --slice=SYM:VAR (add --slice-flow=back|fwd|both for the transitive reaching-definition walk) gives intra-procedural, name-based data flow — reach for it on a wrong-value symptom instead of re-reading the whole function by eye. Its own legend discloses the limits that matter here, so trust that over this line: statement/line-granular, flow-sensitive reaching definitions inside one function for C-family/Python and source-ordered for JS/Go/Java/Rust (the root's reach= says which; each use row's rd= lists its reaching def lines), no alias analysis, block scopes separated (a shadowed name's rows carry b=, the declaration each binds to; pp="1" marks a build-dependent #ifdef row), and it stops at the function boundary (chain --callers/--impact for the inter-procedural half). For use-after-move / taint / null / type bugs that cross that boundary you still need the compiler — use these results to focus where to look, not as proof. A high-amb symbol can be a dispatch hub, not the bug.

Found it? Pin the gotcha with ripwire <dir> --note-add="SYM_or_path: what actually went wrong" — the next agent (or you, next session) gets it automatically the next time --for/--expand surfaces that symbol.

© redhat-et, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ripwire-find-bug of redhat-et/ripwire.

Open the folder on GitHubat commit 255dc19

Compare with similar skills

Ripwire Find Bug next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ripwire Find Bug compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ripwire Find Bug this skillredhat-et/ripwire2.4k—~2.2kAutomated safety check: NotesApache-2.0
Systematic Debuggingultralisp/ultralisp25851 repos~2.4kAutomated safety check: PassNone
Exposed Bug Fix WorkflowJetBrains/Exposed9.3k—~3.8kAutomated safety check: PassApache-2.0
React Router Bug Fix Workflowremix-run/react-router57k—~1.3kAutomated safety check: PassMIT
Systematic DebuggingChrisWiles/claude-code-showcase6.1k3 repos~1.2kAutomated safety check: PassNone
Debugging and Error Recoveryaddyosmani/agent-skills102k1 repos~2.6kAutomated safety check: PassMIT

Similar skills

  • Systematic Debugging

    ultralisp/ultralisp

    A skill your agent uses when encountering any bug, test failure, or unexpected behavior, before proposing fixes

    258 GitHub starsUsed in 51 repos~2.4k tokens
    DevelopmentAuto-check passed
  • Exposed Bug Fix Workflow

    JetBrains/Exposed

    Official

    Takes a GitHub or YouTrack issue for the Exposed project through reproduction, a failing test, a fix, validation and a pull request.

    9.3k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • React Router Bug Fix Workflow

    remix-run/react-router

    Fixes a React Router bug reported in a GitHub issue end to end: fetching the issue, validating the reproduction, writing a failing test and implementing the fix on a new branch.

    57k GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Systematic Debugging

    ChrisWiles/claude-code-showcase

    Applies a four-phase debugging routine that finds the root cause of a bug or failing test before any fix is written.

    6.1k GitHub starsUsed in 3 repos~1.2k tokens
    DevelopmentAuto-check passed
  • Debugging and Error Recovery

    addyosmani/agent-skills

    Applies a stop-the-line rule and a step-by-step triage when tests fail, builds break or something stops working, aiming at the root cause instead of guesses.

    102k GitHub starsUsed in 1 repo~2.6k tokens
    DevelopmentAuto-check passed
  • Systematic Debugging

    ed3dai/ed3d-plugins

    A skill your agent uses when encountering any bug, test failure, or unexpected behavior, before proposing fixes - four-phase framework (root cause investigation, pattern analysis, hypothesis…

    250 GitHub starsUsed in 3 repos~2.4k tokens
    DevelopmentAuto-check passed

More from redhat-et/ripwire

All 19 skills in this repo
  • Ripwire Output Emission

    redhat-et/ripwire

    Rules for writing and converting formatted output in ripwire's C++ source with its emit helpers, keeping every printed byte identical to the old printf output.

    2.4k GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Ripwire Change Check

    redhat-et/ripwire

    Checks whether a working-tree diff or a pull request is safe to merge: blast radius, tests to run, contract breaks, branch conflicts and stranded work.

    2.4k GitHub stars~4.3k tokensUpdated 2 days ago
    Auto-check: notes
  • Ripwire Graph Query

    redhat-et/ripwire

    Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.

    2.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check: notes
  • Ripwire Subsystem Handoff

    redhat-et/ripwire

    Produces a short brief for handing a code subsystem to a teammate or fresh session, using ripwire to rank symbols, expand bodies and surface design docs.

    2.4k GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check: notes
  • Ripwire Code Navigation

    redhat-et/ripwire

    Answers questions about a named symbol, such as its callers, what it calls, the path between two symbols or the downstream impact of changing it, using the ripwire CLI.

    2.4k GitHub stars~4.8k tokensUpdated 2 days ago
    Auto-check: notes
  • Contributor guide for reading clang optimization remarks while editing ripwire's own C++, deciding between a source change and a build change such as LTO or PGO.

    2.4k GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check: notes

Categories

Questions about Ripwire Find Bug

What does Ripwire Find Bug do?

You have a SYMPTOM — crash, exception, wrong output, failing test, error string — and don't know which code is responsible. Ripwire Find Bug is an agent skill from redhat-et/ripwire. You have a SYMPTOM — crash, exception, wrong output, failing test, error string — and don't know which code is responsible.

When should I use Ripwire Find Bug?

Ripwire Find Bug fits situations like: tasks that involve Debugging; tasks that involve Failing and flaky tests.

How do I install Ripwire Find Bug in Claude Code?

Run `npx skills add redhat-et/ripwire --skill ripwire-find-bug -a claude-code`. Or copy the skill folder (skills/ripwire-find-bug in redhat-et/ripwire) into .claude/skills/ripwire-find-bug in your project. Claude Code loads it when a task matches its description.

How do I install Ripwire Find Bug in Codex?

Run `npx skills add redhat-et/ripwire --skill ripwire-find-bug -a codex`. Or copy the skill folder (skills/ripwire-find-bug in redhat-et/ripwire) into .agents/skills/ripwire-find-bug in your project. Codex loads it when a task matches its description.

Can I use Ripwire Find Bug in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add redhat-et/ripwire --skill ripwire-find-bug -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ripwire-find-bug, .gemini/skills/ripwire-find-bug, .github/skills/ripwire-find-bug and .opencode/skills/ripwire-find-bug in your project.

What does Ripwire Find Bug need to run?

Going by SKILL.md and its folder, Ripwire Find Bug needs the command-line tools its instructions call (git, pytest and sh). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash, Read.

Does Ripwire Find Bug access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ripwire Find Bug safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ripwire Find Bug use?

Ripwire Find Bug is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ripwire Find Bug use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ripwire Find Bug?

Skills that share tags, products or a category with Ripwire Find Bug: Systematic Debugging (ultralisp/ultralisp, 258 stars), Exposed Bug Fix Workflow (JetBrains/Exposed, 9.3k stars), React Router Bug Fix Workflow (remix-run/react-router, 57k stars) and Systematic Debugging (ChrisWiles/claude-code-showcase, 6.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ripwire Find Bug?

redhat-et (a GitHub organization) maintains it in redhat-et/ripwire, which has 2,412 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 4, 2026.

Source: redhat-et/ripwire on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.