Agent skill

Bug Triage

by symfony in symfony/symfony

Decide whether open Bug PRs target the correct branch. An agent skill from symfony/symfony.

MITAuto-check passedDevelopment

Install Bug Triage

skills CLI
$ npx skills add symfony/symfony --skill bug-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install symfony/symfony bug-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/bug-triage .claude/skills/bug-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bug-triage
GitHub stars
31k
Token cost
~1.9k tokens
SKILL.md length
637 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Decide whether open Bug PRs target the correct branch. An agent skill from symfony/symfony.

  • Works in 5 steps: Scope → Investigate each PR (one subagent per… → Decision tree (first match wins) → …
  • The user says triage bug PRs
  • SKILL.md covers Steps and Quick reference table
  • Calls git, gh and curl; reaches symfony.com

What it does

Bug Triage is an agent skill from symfony/symfony. Decide whether open Bug PRs target the correct branch. A bug must be fixed on the lowest maintained branch where it exists, then merged up. Use when the user says "triage bug PRs", "which PRs need retargeting", or "retarget triage".

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Issue triage. It works with Symfony and PHP. The repository describes itself as: The Symfony PHP framework. The licence is MIT.

When your agent uses it

  • The user says triage bug PRs
  • Which PRs need retargeting
  • Retarget triage

Example prompts

  • “triage bug PRs”
  • “which PRs need retargeting”
  • “retarget triage”
  • “/bug-triage”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Scope
  2. Investigate each PR (one subagent per PR, run concurrently, batches of 8-10)
  3. Decision tree (first match wins)
  4. Aggregate report
  5. Execute (only on explicit user authorization)

What it can do on your machine

Read from SKILL.md and the folder at commit 42be462. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • symfony.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bug Triage loads about 1.9k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 637 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from symfony/symfony at commit 42be462, republished under its MIT licence (© symfony). 637 words, ~1,902 tokens.

Download SKILL.mdSave it as .claude/skills/bug-triage/SKILL.md (or your agent's skills folder).
name
bug-triage
description
Decide whether open Bug PRs target the correct branch. A bug must be fixed on the lowest maintained branch where it exists, then merged up. Use when the user says "triage bug PRs", "which PRs need retargeting", or "retarget triage".

Symfony Bug-PR Retarget Triage

Symfony fixes bugs on the lowest maintained branch where the bug exists, then merges up. This skill produces a retarget recommendation per PR. The final call belongs to a maintainer; never act without explicit confirmation.


Steps

Step 0 — Scope

Maintained branches:

bash
curl -s https://symfony.com/releases.json
# maintained_versions, e.g. ["6.4","7.4","8.0","8.1","8.2"]; LOWEST = first entry.
# DEV (new-feature target) = first entry AFTER latest_stable_version, not the last
# entry: when X.4 and Y.0 are developed in parallel both are dev, and features go to
# the lower one (they merge up).

Resolve the upstream remote (not always origin):

bash
REMOTE=$(git remote -v | awk '/[:\/]symfony\/symfony(\.git)?[[:space:]]+\(fetch\)/{print $1; exit}')
# Stop and ask the user if empty

Fetch all maintained branches, then collect open Bug PRs:

bash
git fetch "$REMOTE" <each maintained branch>

gh pr list --repo symfony/symfony --label Bug --state open --limit 300 \
  --json number,title,baseRefName,milestone,isDraft
# Skip drafts unless asked. A milestone/base mismatch is itself a signal.

Step 1 — Investigate each PR (one subagent per PR, run concurrently, batches of 8-10)

Each subagent is read-only and returns a structured verdict.

1a. Fetch PR data:

bash
gh pr view <N> --repo symfony/symfony \
  --json number,title,baseRefName,milestone,body,files,labels,closingIssuesReferences,url
gh pr diff <N> --repo symfony/symfony
gh pr view <N> --repo symfony/symfony --comments

From the body Q&A table, read Branch?, Bug fix?, New feature?, Deprecations?.

1b. Bug fix or feature? (objective check)

The Bug fix? field is self-declared and can be wrong. The real check: does the production diff add public/protected API surface?

bash
# Scan only non-Tests/ files for added API
gh pr diff <N> --repo symfony/symfony \
  | awk '/^diff --git /{skip=($0 ~ /\/Tests\//)} !skip' \
  | grep -nE '^\+\s*(public|protected)\s+(function|const|readonly|static|\??[A-Za-z\\]+\s+\$)|^\+\s*(final\s+)?(class|interface|trait|enum)\s'

If the diff grows the surface → treat as feature (target DEV, never retarget down). Two false positives to discount: code merely moved also shows as + lines, and adding to an @internal/@experimental class is not a BC extension. Exception: implementing a marker interface (e.g. ResetInterface) to fix a state leak is still a bug fix; weigh intent in those cases.

1c. Read linked issues:

bash
# Also parse the body for "Fix #", "Closes #", "Resolves #"
gh issue view <ISSUE> --repo symfony/symfony --json title,body,labels,comments
# The reported Symfony version is the strongest signal for how far back the bug reaches.

1d. Probe lower branches (for each branch below the PR's base, oldest first):

bash
# 1. Does the file exist?
git cat-file -e "$REMOTE/<branch>:<path>" && echo present || echo absent

# 2. Does the buggy code exist there?
git show "$REMOTE/<branch>:<path>"

# 3. When did the code arrive? (determines the regression floor)
git log -S'<symbol>' --oneline "$REMOTE/<branch>" -- <path>

1e. (Optional) Reproduce on the candidate branch:

bash
git worktree add --detach ../symfony-sf-triage-<N> "$REMOTE/<branch>"
cd ../symfony-sf-triage-<N> && ./phpunit src/Symfony/Component/<Name>
cd - && git worktree remove --force ../symfony-sf-triage-<N>

Subagent verdict: PR number, component, current base, recommended base, confidence (high/medium/low), deciding evidence, whether the fix needs adaptation.


Step 2 — Decision tree (first match wins)

Keep on current base if any hold:

  • Not a bug fix (feature, deprecation, or grows the public/protected API surface).
  • The touched code does not exist on any lower branch.
  • The regression was introduced on the current base or later (lower branches never had it).
  • Fixing lower would change frozen/contractual behaviour (flag for maintainer).

Retarget DOWN to branch T if all hold:

  1. It is a bug fix (fixes wrong behaviour, doesn't add capability).
  2. T is the oldest maintained branch where the bug exists, bounded by the regression floor and never below LOWEST.
  3. The fix applies on T (directly or with a documented adaptation).

Raise the base (rare): the PR targets a branch where the code doesn't exist yet, or an unmaintained branch → recommend the lowest maintained branch that has the code.


Show full SKILL.md (268 more words)Show less
Step 3 — Aggregate report

Collect verdicts into a table ordered by action then component:

PR      Component     Base  →  Recommend  Conf   Why
#64613  Validator     7.4      6.4        high   issue reports 6.4; method present & broken on 6.4
#64589  ObjectMapper  8.1      8.1 (keep) high   component added in 8.1; absent below
#64576  Serializer    8.1      7.4        med    regression introduced in 7.4 (commit abc123)

Routing (each is outward, so wait for confirmation before doing anything):

  • Retarget: draft a short factual comment citing the evidence.
  • Keep: record the reason so the PR is not re-triaged.
  • Needs human judgement: low-confidence or behaviour-change cases → state the open question.

Step 4 — Execute (only on explicit user authorization)

When to comment-only vs. rebase+push:

  • Comment-only when: maintainerCanModify is false; the fix needs real code adaptation; or the PR is already approved (a force-push dismisses reviews).
  • Rebase+push when commits cherry-pick cleanly onto the target.

Rebase mechanics:

bash
# Cherry-pick PR commits onto a fresh branch off the target (do NOT rebase the whole branch)
git fetch <fork-url> <headRef>; OLD=$(git rev-parse FETCH_HEAD)
git checkout -B retarget-<N> $REMOTE/<target>
git cherry-pick <oid>...

# Run tests before pushing
./phpunit src/Symfony/Component/<Name>

# Push with lease, then change base
git push <fork-url> HEAD:<headRef> --force-with-lease=<headRef>:$OLD
gh pr edit <N> --repo <repo> --base <target> --milestone <target>

# Clean up
git checkout <dev-branch> && git branch -D retarget-<N>

After retargeting, also update the body's | Branch? | value and remove any labels that contradict the new disposition (e.g. Feature on a confirmed bug fix).


Quick reference table

PR shapeRecommendationDeciding factor
Bug on 8.1; issue reproduced on 6.4; method present & broken on 6.4Retarget to 6.4bug reaches the floor
Bug on 8.2; offending line introduced in a commit first shipped in 8.0Retarget to 8.0regression floor is 8.0
Bug on 8.1 in a component that didn't exist before 8.1Keep on 8.1code absent on lower branches
New feature? yes opened on 8.1Raise to DEVfeatures target the dev branch
Maintainer commented "please rebase on 7.4"Retarget to 7.4 (high)explicit instruction overrides inference
Early "rebase on 6.4", later "this is a feature"Follow the latest: keep on DEVmost recent instruction wins
PR already approved; bug reaches lower branchesComment-only, ask authorforce-push dismisses reviews
Fix uses 8.x-only API but bug exists on 6.4Retarget to 6.4, adapt the fixdon't leave 6.4 broken

© symfony, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/bug-triage of symfony/symfony.

Open the folder on GitHubat commit 42be462

Compare with similar skills

Bug Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bug Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bug Triage this skillsymfony/symfony31k—~1.9kAutomated safety check: PassMIT
Clean Architecturegiuseppe-trisciuoglio/developer-kit355—~4.2kAutomated safety check: NotesMIT
PHP ProJeffallan/claude-skills12k—~1.6kAutomated safety check: NotesMIT
Shopware CLI Dockershopware/shopware-cli123—~1.8kAutomated safety check: PassMIT
Sentry Php SDKgetsentry/sentry-for-ai268—~3.7kAutomated safety check: NotesApache-2.0
Php ProAratKruglik/claude-laravel155—~984Automated safety check: NotesNone

Similar skills

  • Clean Architecture

    giuseppe-trisciuoglio/developer-kit

    Provides implementation patterns for Clean Architecture, Hexagonal Architecture (Ports & Adapters), and Domain-Driven Design in PHP 8.3+ with Symfony 7.x.

    355 GitHub stars~4.2k tokensUpdated 28 days ago
    DevelopmentAuto-check: notes
  • PHP Pro

    Jeffallan/claude-skills

    Writes strictly typed modern PHP 8.3+ for Laravel, Symfony and plain projects, with PHPStan level 9, PHPUnit or Pest tests, typed DTOs and secure defaults.

    12k GitHub stars~1.6k tokensUpdated 5 days ago
    Backend & APIsAuto-check: notes
  • Shopware CLI Docker

    shopware/shopware-cli

    A skill your agent uses when working on Docker-backed Shopware projects and needing to run Shopware or Symfony CLI commands, interact with project services or databases, start or stop the…

    123 GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Sentry Php SDK

    getsentry/sentry-for-ai

    Official

    Full Sentry SDK setup for PHP. An agent skill from getsentry/sentry-for-ai.

    268 GitHub stars~3.7k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Php Pro

    AratKruglik/claude-laravel

    A skill your agent uses when building PHP applications with modern PHP 8.3+ features, Laravel, or Symfony frameworks.

    155 GitHub stars~984 tokensUpdated 5 mo ago
    Backend & APIsAuto-check: notes
  • Php Symfony Audit

    0xShe/PHP-Code-Audit-Skill

    Symfony 框架特效安全审计工具。针对 Symfony 常见 security.yaml、CSRF、Twig/Twig raw、表达式与访问控制等框架机制做白盒静态审计,并将风险映射到通用漏洞类型体系(AUTH/CSRF/CFG/XSS/TPL/LOGIC 等)。

    402 GitHub starsUsed in 1 repo~599 tokens
    SecurityAuto-check passed

More from symfony/symfony

All 9 skills in this repo
  • Sync Translations

    symfony/symfony

    Synchronize translation catalogs across maintained Symfony branches: find messages that newer branches added to the English catalogs but that are still missing from the oldest maintained branch…

    31k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Merge Up

    symfony/symfony

    Cascade-merge maintained Symfony branches from oldest to newest (e.g.

    31k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • PR Merge

    symfony/symfony

    Merge a reviewed pull request the way the Symfony core team does: one --no-ff merge commit per PR, whose message archives the whole discussion, with the review gates checked first.

    31k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Security Triage

    symfony/symfony

    Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter).

    31k GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.

    31k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Hardening Rule

    symfony/symfony

    Decide whether a recurring hardening invariant is worth a CI gate, and add it without hitting the traps.

    31k GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Bug Triage

What does Bug Triage do?

Decide whether open Bug PRs target the correct branch. An agent skill from symfony/symfony. Bug Triage is an agent skill from symfony/symfony. Decide whether open Bug PRs target the correct branch.

When should I use Bug Triage?

Bug Triage fits situations like: the user says triage bug PRs; which PRs need retargeting; retarget triage.

How do I install Bug Triage in Claude Code?

Run `npx skills add symfony/symfony --skill bug-triage -a claude-code`. Or copy the skill folder (.agents/skills/bug-triage in symfony/symfony) into .claude/skills/bug-triage in your project. Claude Code loads it when a task matches its description.

How do I install Bug Triage in Codex?

Run `npx skills add symfony/symfony --skill bug-triage -a codex`. Or copy the skill folder (.agents/skills/bug-triage in symfony/symfony) into .agents/skills/bug-triage in your project. Codex loads it when a task matches its description.

Can I use Bug Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add symfony/symfony --skill bug-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bug-triage, .gemini/skills/bug-triage, .github/skills/bug-triage and .opencode/skills/bug-triage in your project.

What does Bug Triage need to run?

Going by SKILL.md and its folder, Bug Triage needs the command-line tools its instructions call (git, gh and curl).

Does Bug Triage access the network?

SKILL.md names 1 domain. In commands or code: symfony.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Bug Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bug Triage use?

Bug Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bug Triage use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bug Triage?

Skills that share tags, products or a category with Bug Triage: Clean Architecture (giuseppe-trisciuoglio/developer-kit, 355 stars), PHP Pro (Jeffallan/claude-skills, 12k stars), Shopware CLI Docker (shopware/shopware-cli, 123 stars) and Sentry Php SDK (getsentry/sentry-for-ai, 268 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bug Triage?

symfony (a GitHub organization) maintains it in symfony/symfony, which has 31,183 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: symfony/symfony on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.