Agent skill

Mole Bug Patterns

by tw93 in tw93/Mole

A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

GPL-3.0Auto-check passedDevelopment

Install Mole Bug Patterns

skills CLI
$ npx skills add tw93/Mole --skill bugs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tw93/Mole bugs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tw93/Mole.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/bugs .claude/skills/bugs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bugs
GitHub stars
69k
Token cost
~2k tokens
SKILL.md length
938 words
Files
6 (incl. references)
Skills in repo
4
Repo updated
First seen
Licence
GPL-3.0

At a glance

A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

  • Reviewing a Mole diff that touches cleanup or deletion logic
  • SKILL.md covers Route before loading details, Trace the complete mutation…, Working contract and Verification bar
  • Calls go
  • Checking that dry-run and real code paths apply the same safety guards

What it does

This is a project-specific review aid for Mole, an open-source command-line tool for cleaning and optimizing a Mac. It routes the agent to reference notes instead of loading everything at once. A table lists recurring bug shapes, each with a first probe to run and a reference to read, and the agent should open only the reference families that the evidence touches. A whole-project audit should classify surfaces first before reading any incident narratives.

The shapes include deletion candidates built from a weak name signal, existence or idleness decided by a single probe, a guard present on only one branch such as the dry-run path versus the real one, unbounded external commands, Bash 3.2, errexit and pipefail traps, stdin or TTY theft by background workers, system output parsed as if it were a stable API, persisted derived data that outlives its algorithm, two code paths computing one number differently, slow work that looks frozen, and regression tests that cannot fail.

Four reference files cover deletion evidence, shell and test pitfalls, state and progress accounting, and test validity, and an evals file is included. The skill is scoped to safety-sensitive Mole changes, not docs, release notes or generic review. Generic review and root-cause work on a live failure are handed to other skills named check and hunt.

When your agent uses it

  • Reviewing a Mole diff that touches cleanup or deletion logic
  • Checking that dry-run and real code paths apply the same safety guards
  • Auditing shell scripts for unbounded commands and errexit traps
  • Checking whether a new regression test could ever fail

Example prompts

  • “Review this diff to Mole's cleanup code for deletion-safety problems.”
  • “Does the dry-run path in this change apply the same guards as the real delete path?”
  • “Check whether the new regression test actually fails without the fix.”

What it can do on your machine

Read from SKILL.md and the folder at commit a68741b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mole Bug Patterns loads about 2k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 50 tokens; SKILL.md has 938 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tw93/Mole at commit a68741b, republished under its GPL-3.0 licence (© tw93). 938 words, ~2,027 tokens.

Download SKILL.mdSave it as .claude/skills/bugs/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
bugs
description
Mole incident catalog for cleanup safety, bounded probes, cancellation, dry-run parity, and actionable gates. Use for a Mole safety-sensitive diff; not for docs, release notes, or generic review.

Mole bug patterns

Generic review belongs to Waza check; root-cause investigation of a live failure belongs to hunt.

Route before loading details

Choose only the reference families touched by the evidence. A whole-project audit should classify surfaces first instead of loading every incident narrative.

#Recurring shapeFirst probeRead
1Deletion candidate built from a weak name signalInspect name, bundle-id, fallback globs, and failed-owner shortcutsDeletion evidence and final sink
2Existence or idleness decided by one probeEnumerate every legitimate location and unknown outcomeDeletion evidence and final sink
3Guard present on only one branchDiff dry-run, real, direct, fallback, and final-sink pathsDeletion evidence and final sink
4Unbounded external commandCount producer, consumer, inner-loop, and action boundsBounds, Shell, TTY, and parsing
5Bash 3.2, errexit, or pipefail trapCheck empty arrays, `fn
6TTY, stdin, or process-group theftInspect background workers and commands that may promptBounds, Shell, TTY, and parsing
7System output parsed as a stable APIForce locale, validate shape, and join on identifiers not headingsBounds, Shell, TTY, and parsing
8Persisted derived data outlives its algorithmTrace schema, TTL, evidence fingerprint, and mutationsState, accounting, and progress
9Two paths compute one number differentlyFind every producer and choose one definitionState, accounting, and progress
10Slow work looks frozenFind operations over roughly one second outside feedbackState, accounting, and progress
11Regression test cannot failProve positive control and pre-fix red stateTest validity and refusal diagnostics
12Gate cannot explain why it refusedMap each reason to one cause and a next action that fails on the broken stateTest validity and refusal diagnostics
13Mutation target is also accepted as a discovery containerCompare the recursive scan-root namespace with every purge target basenameDeletion evidence and final sink
14Owner metadata is treated as a complete, atomic inventoryIdentify who writes it, whether absence is authoritative, and what locks mutationDeletion evidence and final sink
15Cancellation stops one helper but later work continuesClassify each 124 as skip, section budget, or sticky cancel before tracing callersBounds, Shell, TTY, and parsing
16Async or cached data has no generation or freshness contractBind results to a request epoch and keep each sample's time, stale, and completeness fields togetherState, accounting, and progress
17Publication gate trusts ambiguous or pre-existing stateRequire exact source/tag equality, one generated target, and an expected-absence ref leaseTest validity and refusal diagnostics
18A sandbox well-known path is treated as app-private leftoversResolve Data/Downloads, Desktop, Pictures, Music, and Movies physically against $HOMEDeletion evidence and final sink

AGENTS.md keeps each rule stated fully enough to obey plus its test anchor; the incident story lives in these references or in release-flow, and the AGENTS.md bullet points to the section that holds it. Moving a story here is a merge, never the deletion of a rule that still constrains behavior.

Show full SKILL.md (440 more words)Show less

Trace the complete mutation lifecycle

For cleanup, purge, optimize, analyze deletion, or uninstall work, review the complete chain rather than the reported branch:

text
discover or plan
  -> cheap irreversible filters
  -> owner and open-handle probes
  -> size or metadata work
  -> final owner re-probe
  -> parent and target identity rebind
  -> deletion or Trash sink
  -> accounting, cancellation, and user output

At every transition, answer:

  • Does live or unknown state fail closed?
  • Are timeouts classified by probe, sizing, removal, or section scope, with unknown evidence refusing deletion and cancellation stopping later mutation?
  • Are probe and sink bound to the same physical parent and target?
  • Do dry-run and real mode start from the same eligible plan without reusing stale authorization?
  • Are cheap missing, protected, whitelisted, and compiled-model filters ahead of recursive probes?
  • Does one cumulative deadline cover the dynamic scan scope, with checkpoints in nested loops?
  • Do refused, filtered, timed-out, or failed items stay out of cleaned counts and reclaimed bytes?
  • Can large candidates avoid per-item size work without making the reported total false?

Do not trade final-sink rebinding or fail-closed owner checks for speed. Optimize absent targets, duplicated discovery probes, report-only work, and wrong-scope scans first.

Working contract

  • Before proposing a remedy, apply the Product Decision Filter in AGENTS.md: a new flag, environment variable, or visible retry message is a product change, even when the underlying fix is a safety improvement. Use the existing state/accounting reference when deciding what belongs in the normal summary.
  • A sandbox well-known directory is user data until physical resolution proves otherwise. Data/Downloads is usually ~/Downloads under another name.
  • A refusal next step that succeeds on the broken state is not a next step. Do not relax the gate to make the message nicer.
  • Sweep siblings by call-site shape, not filename or helper name. Report checked N / defective M / not applicable K.
  • A recurring fix ships with a regression or source invariant that fails against the pre-fix code.
  • Treat tests as production consumers only after proving the production helper ran. Negative assertions require a positive trace.
  • A cancellation regression makes the next candidate otherwise eligible, then proves its probe and sink never run. Making every candidate fail for the same reason is a false sticky-cancellation test.
  • Absence-sensitive tests use an isolated HOME or fixture root; a shared setup_file home is not isolation.
  • Reproduce CI through MOLE_TEST_NO_AUTH=1 ./scripts/test.sh when possible. If invoking Bats directly with jobs, preserve --no-parallelize-within-files; files share state and raw bats --jobs 6 file.bats changes semantics.
  • Treat specialist or AI reports as leads. Read the implementation, callers, fallback branches, and final sink yourself.

Verification bar

Use the hotspot commands in AGENTS.md; do not guess a narrower verifier. A typical Shell safety change finishes with:

bash
./scripts/check.sh --format
MOLE_TEST_NO_AUTH=1 bats tests/<area>.bats
MOLE_TEST_NO_AUTH=1 ./scripts/test.sh
go test ./...
MOLE_TEST_NO_AUTH=1 MOLE_DRY_RUN=1 ./mole clean --dry-run

Never infer a production defect from a function name, comment, string, fixture, or _test.go match. Confirm the live call path and verify red-green before reporting the class fixed.

© tw93, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in .claude/skills/bugs of tw93/Mole.

  • SKILL.md
  • evals/evals.json
  • references/deletion-evidence-and-final-sink.md
  • references/shell-and-test-pitfalls.md
  • references/state-accounting-and-progress.md
  • references/test-validity-and-refusal-diagnostics.md

Open the folder on GitHubat commit a68741b

Compare with similar skills

Mole Bug Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mole Bug Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mole Bug Patterns this skilltw93/Mole69k—~2kAutomated safety check: PassGPL-3.0
Swpm Code Reviewdeinsoftware/swpm125—~1.1kAutomated safety check: PassMIT
Batch Filesgithub/awesome-copilot40k1 repos~4.3kAutomated safety check: PassMIT
Os Scriptingaiskillstore/marketplace4303 repos~2.2kAutomated safety check: NotesNone
Shell ScripterFerroxLabs/wayland608—~3.3kAutomated safety check: PassApache-2.0
New Mac Setupswyxio/skills172—~4.3kAutomated safety check: PassMIT

Similar skills

  • Swpm Code Review

    deinsoftware/swpm

    Automated code review bash script for SWPM. An agent skill from deinsoftware/swpm.

    125 GitHub stars~1.1k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Batch Files

    github/awesome-copilot

    Official

    Expert-level Windows batch file (.bat/.cmd) skill for writing, debugging, and maintaining CMD scripts.

    40k GitHub starsUsed in 1 repo~4.3k tokens
    DevelopmentAuto-check passed
  • Os Scripting

    aiskillstore/marketplace

    Operating system and shell scripting troubleshooting workflow for Linux, macOS, and Windows.

    430 GitHub starsUsed in 3 repos~2.2k tokens
    DevelopmentAuto-check: notes
  • Shell Scripter

    FerroxLabs/wayland

    Shell scripting mastery. An agent skill from FerroxLabs/wayland.

    608 GitHub stars~3.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • New Mac Setup

    swyxio/skills

    Fully automated new Mac setup for fullstack web developers and AI engineers.

    172 GitHub stars~4.3k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • CLI Developer

    Jeffallan/claude-skills

    Walks through designing, building and polishing a command-line tool: user workflow and command hierarchy, implementation in commander, click, typer or cobra, completions and cross-platform testing.

    12k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed

More from tw93/Mole

  • Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.

    69k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Publishes curated, bilingual release notes for an existing Mole version tag with gh release edit, including contributor thanks and reactions, after the release workflow finishes.

    69k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Teaches an agent to drive the Mole (mo) Mac cleaning CLI safely: preview first, use JSON output, and leave destructive runs to the user.

    69k GitHub stars~1.8k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Mole Bug Patterns

What does Mole Bug Patterns do?

A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests. This is a project-specific review aid for Mole, an open-source command-line tool for cleaning and optimizing a Mac. It routes the agent to reference notes instead of loading everything at once.

When should I use Mole Bug Patterns?

Mole Bug Patterns fits situations like: reviewing a Mole diff that touches cleanup or deletion logic; checking that dry-run and real code paths apply the same safety guards; auditing shell scripts for unbounded commands and errexit traps; checking whether a new regression test could ever fail.

How do I install Mole Bug Patterns in Claude Code?

Run `npx skills add tw93/Mole --skill bugs -a claude-code`. Or copy the skill folder (.claude/skills/bugs in tw93/Mole) into .claude/skills/bugs in your project. Claude Code loads it when a task matches its description.

How do I install Mole Bug Patterns in Codex?

Run `npx skills add tw93/Mole --skill bugs -a codex`. Or copy the skill folder (.claude/skills/bugs in tw93/Mole) into .agents/skills/bugs in your project. Codex loads it when a task matches its description.

Can I use Mole Bug Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tw93/Mole --skill bugs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bugs, .gemini/skills/bugs, .github/skills/bugs and .opencode/skills/bugs in your project.

What does Mole Bug Patterns need to run?

Going by SKILL.md and its folder, Mole Bug Patterns needs the command-line tools its instructions call (go).

Does Mole Bug Patterns access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mole Bug Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mole Bug Patterns use?

Mole Bug Patterns is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mole Bug Patterns use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Mole Bug Patterns?

Skills that share tags, products or a category with Mole Bug Patterns: Swpm Code Review (deinsoftware/swpm, 125 stars), Batch Files (github/awesome-copilot, 40k stars), Os Scripting (aiskillstore/marketplace, 430 stars) and Shell Scripter (FerroxLabs/wayland, 608 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mole Bug Patterns?

tw93 (a GitHub user) maintains it in tw93/Mole, which has 69,469 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.

Source: tw93/Mole on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.