Agent skill

What Could Break

by sickn33 in sickn33/agentic-awesome-skills

Find what a change breaks outside its own diff, then prove the one fact that makes it safe by running real code.

MITAuto-check passed

Install What Could Break

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill what-could-break -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills what-could-break --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/what-could-break .claude/skills/what-could-break && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
what-could-break
GitHub stars
47k
Token cost
~1.8k tokens
SKILL.md length
1,137 words
Files
2 (incl. references)
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Find what a change breaks outside its own diff, then prove the one fact that makes it safe by running real code.

  • Works in 5 steps: Do not trust your own writeup → Read the change → Find the one fact it is safe because of → …
  • SKILL.md covers Overview, When to Use, How It Works and Examples, plus 4 more sections
  • Calls git

What it does

What Could Break is an agent skill from sickn33/agentic-awesome-skills. Find what a change breaks outside its own diff, then prove the one fact that makes it safe by running real code. Use before any multi-file edit or an edit to a shared path.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files.

The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

Example prompts

  • “/what-could-break”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Do not trust your own writeup
  2. Read the change
  3. Find the one fact it is safe because of
  4. Look where grep stops
  5. Prove the one fact

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

What Could Break loads about 1.8k tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 47 tokens; SKILL.md has 1,137 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 1,137 words, ~1,847 tokens.

Download SKILL.mdSave it as .claude/skills/what-could-break/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
what-could-break
description
Find what a change breaks outside its own diff, then prove the one fact that makes it safe by running real code. Use before any multi-file edit or an edit to a shared path.
category
development
risk
safe
source
community
source_repo
stas4000/what-could-break
source_type
community
date_added
2026-10-08
author
stas4000
tags
code-review, refactoring, testing, blast-radius, verification
tools
claude, cursor, gemini
license
MIT

What Could Break

Overview

Listing callers is not the job. Grep does that in a second. This skill finds the breakage grep will not show you, and produces one proof that the change is safe.

Run it before design, not only before merge. Whenever a task asserts something about existing code ("X already handles Y", "just make X public"), that assertion is a hypothesis, and the census of real consumers decides the design.

When to Use

  • Use before any multi-file edit, or an edit to a shared path: API payload, config, stored data, a client other apps read, a prompt or policy file
  • Use when the user asks "what could this break" or "blast radius of X"
  • Use for a small diff you do not trust
  • Use when a brief asserts something about existing code, before you design against that assertion

How It Works

Step 1: Do not trust your own writeup

A risk analysis that sounds right is worthless: it reads as convincing whether or not it is true. Find the one or two facts the whole change depends on, and get each one as far down this ladder as is cheap. Say where it stopped.

  1. You said so. Worth nothing on its own.
  2. You pointed at it. A real file:line, or the library's own source at the pinned version.
  3. You walked it. You traced the bad case step by step and it does not reach.
  4. You ran it. A script or test calls the real code and fails loud if you are wrong.
  5. You saw it live. Reproduced in the running app, service or device.

Rung 4 is usually one small script that imports the same module production runs and calls the exact function you are worried about, with the input you are worried about.

Step 2: Read the change

The diff, the symbols it adds, changes and deletes, and what it now does differently, including what the diff does not spell out. git log -S '<symbol>' and git log -L :<function>:<file> show why the old shape exists; a guard that looks pointless often has a commit explaining the incident it stopped.

Step 3: Find the one fact it is safe because of

Most risky-looking changes are safe because of one fact ("this only drops cache entries that are already expired", "no client reads this field"). If it holds, most risks clear at once. If you cannot find one, the change is not understood yet.

Step 4: Look where grep stops

Search for the literal value, the field name, the error text and the old behavior, not only the symbol you renamed. Then check each of these by hand:

  • The same rule living twice. A second config file, a fallback path that hardcodes the old default, a copy synced into another repo, a constant duplicated in a migration or test fixture, a feature flag default.
  • Prompts and agent files that restate the rule. System prompts, agent and skill files, AGENTS.md, CLAUDE.md, runbooks. An agent obeys the stale sentence, not your code.
  • Every other client. Web, iOS, Android, desktop, CLI, extensions, partner integrations. Mobile clients in users' hands stay on the old version for weeks: what does an old client do with the new shape, and a new client with the old server?
  • Wire formats. JSON field names and types, enum values, null versus missing, date formats, pagination shape, error codes, webhook payloads, queue schemas, GraphQL and protobuf contracts.
  • Stored state. Columns and their defaults, rows written under the old shape, cache entries, files on disk, append-only logs, session and cookie contents, search indexes. Old data outlives the deploy.
  • Environment and secrets. An env var renamed in code but not in the deploy config, CI, the image, or the second service that reads it.
  • Processes that restart separately. Web server, workers, cron jobs, serverless functions, the mobile app, a sidecar. During a rollout one runs new code while another runs old code against the same data. Can both coexist for an hour?
  • Timing and concurrency. Two writers on the same row or key, a retry that now fires twice, ordering that only held because one step was slow.
  • Library source at its pinned version. Read the dependency's code at the lockfile version, not your memory of its docs.
  • Generated and vendored code. Clients generated from a schema, vendored copies, committed build artifacts, bundles whose cache-busting key did not change.
  • Tests and fixtures that encode the old behavior. A test that passes because its fixture still has the old shape proves nothing about the new one.
  • Observability. Dashboards, alerts and log parsers matching a message or metric name you changed.
Show full SKILL.md (362 more words)Show less
Step 5: Prove the one fact

Write the script or test that runs the real code, run it, and paste what happened. If you cannot run it, write "unproven" next to the fact. For a wide change, repeat steps 3 to 5 per subsystem instead of stretching one writeup across everything.

Examples

Example 1: A field removed from an API response

The one fact: no client reads legacy_total. Rung 2 is a search across every client repo. Rung 4 is a script that replays yesterday's real requests against the new serializer and asserts no response shrinks a field a stored client build still parses. The report names the iOS build still in users' hands and the cleared web and admin clients.

Example 2: "Just make this helper public"

The brief asserts the helper is already side-effect free. Treat that as a hypothesis: read it, then run it twice in one process and compare state. If it caches, the assertion is false and the design changes before any code is written.

Best Practices

  • ✅ State the rung each fact reached, and the command that proved it
  • ✅ List cleared risks separately from confirmed ones, with the search you ran
  • ✅ Cite a real file:line for every risk
  • ❌ Don't invent a caller, an API or a config key
  • ❌ Don't ship a convincing essay in place of one run script

Limitations

  • A risk needs a real chance and a real cost, or it does not belong on the list.
  • A search that found nothing is still an answer: write the search down rather than claiming the risk does not exist.
  • This skill does not replace environment-specific testing or expert review.
  • Keep secrets and private data out of the report and out of any script left behind.

Security & Safety Notes

  • The proof scripts this skill writes run real production code paths. Run them in a local or authorized test environment, never against production data stores.
  • Read-only by design: it inspects a diff and runs checks. It does not mutate state, and it should not be used to apply fixes.

Credits

Adapted from stas4000/what-could-break (MIT). Includes material adapted from pstack by Lauren Tan (MIT); its notice ships here in references/LICENSE-pstack.txt.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/what-could-break of sickn33/agentic-awesome-skills.

  • SKILL.md
  • references/LICENSE-pstack.txt

Open the folder on GitHubat commit b84d35a

Compare with similar skills

What Could Break next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

What Could Break compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
What Could Break this skillsickn33/agentic-awesome-skills47k—~1.8kAutomated safety check: PassMIT
Diffsopenclaw/openclaw392k4 repos~461Automated safety check: PassMIT
Diff Reviewnexu-io/open-design100k—~508Automated safety check: PassApache-2.0
Diff Analyzeruvnet/ruflo74k—~450Automated safety check: NotesMIT
Browser Screenshot Diffruvnet/ruflo74k—~623Automated safety check: NotesMIT
V5 Breaking Changesremotion-dev/remotion63k—~879Automated safety check: PassCustom licence

Similar skills

  • Diffs

    openclaw/openclaw

    Use the diffs tool to produce real, shareable diffs (viewer URL, file artifact, or both) instead of manual edit summaries.

    392k GitHub starsUsed in 4 repos~461 tokens
    Auto-check passed
  • Diff Review

    nexu-io/open-design

    Render the patch-edit run's accumulated changes as a reviewable diff, surface it through a GenUI choice surface, and persist the user's accept / reject decision into the artifact manifest.

    100k GitHub stars~508 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Diff Analyze

    ruvnet/ruflo

    Analyze git diffs for risk scoring, reviewer recommendations, and change classification.

    74k GitHub stars~450 tokensUpdated today
    DevelopmentAuto-check: notes
  • Visual + DOM diff between two recorded sessions at matching trajectory step ids; used for visual regression and replay verification

    74k GitHub stars~623 tokensUpdated today
    Testing & QAAuto-check: notes
  • V5 Breaking Changes

    remotion-dev/remotion

    Official

    Implement or review a Remotion 5 breaking change while the v4 and v5 release lines still share code.

    63k GitHub stars~879 tokensUpdated today
    Media & CreativeAuto-check passed
  • @pierre/diffs Code Rendering

    pierrecomputer/pierre

    Guides an agent through using @pierre/diffs to render syntax-highlighted files and diffs, and to build editing and review surfaces in React or plain JavaScript.

    6.3k GitHub starsUsed in 2 repos~803 tokens
    DevelopmentAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about What Could Break

What does What Could Break do?

Find what a change breaks outside its own diff, then prove the one fact that makes it safe by running real code. What Could Break is an agent skill from sickn33/agentic-awesome-skills. Find what a change breaks outside its own diff, then prove the one fact that makes it safe by running real code.

How do I install What Could Break in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill what-could-break -a claude-code`. Or copy the skill folder (skills/what-could-break in sickn33/agentic-awesome-skills) into .claude/skills/what-could-break in your project. Claude Code loads it when a task matches its description.

How do I install What Could Break in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill what-could-break -a codex`. Or copy the skill folder (skills/what-could-break in sickn33/agentic-awesome-skills) into .agents/skills/what-could-break in your project. Codex loads it when a task matches its description.

Can I use What Could Break in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill what-could-break -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/what-could-break, .gemini/skills/what-could-break, .github/skills/what-could-break and .opencode/skills/what-could-break in your project.

What does What Could Break need to run?

Going by SKILL.md and its folder, What Could Break needs the command-line tools its instructions call (git).

Does What Could Break access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is What Could Break safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does What Could Break use?

What Could Break is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does What Could Break use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 267 tokens, read only when the agent opens those files.

What are the alternatives to What Could Break?

Skills that share tags, products or a category with What Could Break: Diffs (openclaw/openclaw, 392k stars), Diff Review (nexu-io/open-design, 100k stars), Diff Analyze (ruvnet/ruflo, 74k stars) and Browser Screenshot Diff (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains What Could Break?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.