Swpm Code Review
deinsoftware/swpm
Automated code review bash script for SWPM. An agent skill from deinsoftware/swpm.
A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.
$ npx skills add tw93/Mole --skill bugs -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tw93/Mole bugs --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tw93/Mole.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/bugs .claude/skills/bugs && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "bugs" agent skill from https://github.com/tw93/Mole/tree/main/.claude/skills/bugs into .claude/skills/bugs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bugs", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tw93/Mole/tree/main/.claude/skills/bugsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tw93/Mole --skill bugs -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tw93/Mole bugs --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tw93/Mole.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/bugs .agents/skills/bugs && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "bugs" agent skill from https://github.com/tw93/Mole/tree/main/.claude/skills/bugs into .agents/skills/bugs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bugs", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tw93/Mole --skill bugs -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tw93/Mole bugs --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tw93/Mole.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/bugs .cursor/skills/bugs && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "bugs" agent skill from https://github.com/tw93/Mole/tree/main/.claude/skills/bugs into .cursor/skills/bugs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bugs", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tw93/Mole.git --path .claude/skills/bugs--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tw93/Mole --skill bugs -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tw93/Mole bugs --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tw93/Mole.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/bugs .gemini/skills/bugs && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "bugs" agent skill from https://github.com/tw93/Mole/tree/main/.claude/skills/bugs into .gemini/skills/bugs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bugs", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tw93/Mole bugsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tw93/Mole --skill bugs -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tw93/Mole.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/bugs .github/skills/bugs && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "bugs" agent skill from https://github.com/tw93/Mole/tree/main/.claude/skills/bugs into .github/skills/bugs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bugs", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tw93/Mole --skill bugs -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tw93/Mole bugs --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tw93/Mole.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/bugs .opencode/skills/bugs && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "bugs" agent skill from https://github.com/tw93/Mole/tree/main/.claude/skills/bugs into .opencode/skills/bugs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bugs", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
bugsA catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.
This is a project-specific review aid for Mole, an open-source command-line tool for cleaning and optimizing a Mac. It routes the agent to reference notes instead of loading everything at once. A table lists recurring bug shapes, each with a first probe to run and a reference to read, and the agent should open only the reference families that the evidence touches. A whole-project audit should classify surfaces first before reading any incident narratives.
The shapes include deletion candidates built from a weak name signal, existence or idleness decided by a single probe, a guard present on only one branch such as the dry-run path versus the real one, unbounded external commands, Bash 3.2, errexit and pipefail traps, stdin or TTY theft by background workers, system output parsed as if it were a stable API, persisted derived data that outlives its algorithm, two code paths computing one number differently, slow work that looks frozen, and regression tests that cannot fail.
Four reference files cover deletion evidence, shell and test pitfalls, state and progress accounting, and test validity, and an evals file is included. The skill is scoped to safety-sensitive Mole changes, not docs, release notes or generic review. Generic review and root-cause work on a live failure are handed to other skills named check and hunt.
Read from SKILL.md and the folder at commit a68741b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
goFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Mole Bug Patterns loads about 2k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 50 tokens; SKILL.md has 938 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from tw93/Mole at commit a68741b, republished under its GPL-3.0 licence (© tw93). 938 words, ~2,027 tokens.
.claude/skills/bugs/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Generic review belongs to Waza check; root-cause investigation of a live failure belongs to hunt.
Choose only the reference families touched by the evidence. A whole-project audit should classify surfaces first instead of loading every incident narrative.
| # | Recurring shape | First probe | Read |
|---|---|---|---|
| 1 | Deletion candidate built from a weak name signal | Inspect name, bundle-id, fallback globs, and failed-owner shortcuts | Deletion evidence and final sink |
| 2 | Existence or idleness decided by one probe | Enumerate every legitimate location and unknown outcome | Deletion evidence and final sink |
| 3 | Guard present on only one branch | Diff dry-run, real, direct, fallback, and final-sink paths | Deletion evidence and final sink |
| 4 | Unbounded external command | Count producer, consumer, inner-loop, and action bounds | Bounds, Shell, TTY, and parsing |
| 5 | Bash 3.2, errexit, or pipefail trap | Check empty arrays, `fn | |
| 6 | TTY, stdin, or process-group theft | Inspect background workers and commands that may prompt | Bounds, Shell, TTY, and parsing |
| 7 | System output parsed as a stable API | Force locale, validate shape, and join on identifiers not headings | Bounds, Shell, TTY, and parsing |
| 8 | Persisted derived data outlives its algorithm | Trace schema, TTL, evidence fingerprint, and mutations | State, accounting, and progress |
| 9 | Two paths compute one number differently | Find every producer and choose one definition | State, accounting, and progress |
| 10 | Slow work looks frozen | Find operations over roughly one second outside feedback | State, accounting, and progress |
| 11 | Regression test cannot fail | Prove positive control and pre-fix red state | Test validity and refusal diagnostics |
| 12 | Gate cannot explain why it refused | Map each reason to one cause and a next action that fails on the broken state | Test validity and refusal diagnostics |
| 13 | Mutation target is also accepted as a discovery container | Compare the recursive scan-root namespace with every purge target basename | Deletion evidence and final sink |
| 14 | Owner metadata is treated as a complete, atomic inventory | Identify who writes it, whether absence is authoritative, and what locks mutation | Deletion evidence and final sink |
| 15 | Cancellation stops one helper but later work continues | Classify each 124 as skip, section budget, or sticky cancel before tracing callers | Bounds, Shell, TTY, and parsing |
| 16 | Async or cached data has no generation or freshness contract | Bind results to a request epoch and keep each sample's time, stale, and completeness fields together | State, accounting, and progress |
| 17 | Publication gate trusts ambiguous or pre-existing state | Require exact source/tag equality, one generated target, and an expected-absence ref lease | Test validity and refusal diagnostics |
| 18 | A sandbox well-known path is treated as app-private leftovers | Resolve Data/Downloads, Desktop, Pictures, Music, and Movies physically against $HOME | Deletion evidence and final sink |
AGENTS.md keeps each rule stated fully enough to obey plus its test anchor; the incident story lives in these references or in release-flow, and the AGENTS.md bullet points to the section that holds it. Moving a story here is a merge, never the deletion of a rule that still constrains behavior.
For cleanup, purge, optimize, analyze deletion, or uninstall work, review the complete chain rather than the reported branch:
discover or plan
-> cheap irreversible filters
-> owner and open-handle probes
-> size or metadata work
-> final owner re-probe
-> parent and target identity rebind
-> deletion or Trash sink
-> accounting, cancellation, and user outputAt every transition, answer:
Do not trade final-sink rebinding or fail-closed owner checks for speed. Optimize absent targets, duplicated discovery probes, report-only work, and wrong-scope scans first.
AGENTS.md: a new flag, environment variable, or visible retry message is a product change, even when the underlying fix is a safety improvement. Use the existing state/accounting reference when deciding what belongs in the normal summary.Data/Downloads is usually ~/Downloads under another name.checked N / defective M / not applicable K.HOME or fixture root; a shared setup_file home is not isolation.MOLE_TEST_NO_AUTH=1 ./scripts/test.sh when possible. If invoking Bats directly with jobs, preserve --no-parallelize-within-files; files share state and raw bats --jobs 6 file.bats changes semantics.Use the hotspot commands in AGENTS.md; do not guess a narrower verifier. A typical Shell safety change finishes with:
./scripts/check.sh --format
MOLE_TEST_NO_AUTH=1 bats tests/<area>.bats
MOLE_TEST_NO_AUTH=1 ./scripts/test.sh
go test ./...
MOLE_TEST_NO_AUTH=1 MOLE_DRY_RUN=1 ./mole clean --dry-runNever infer a production defect from a function name, comment, string, fixture, or _test.go match. Confirm the live call path and verify red-green before reporting the class fixed.
© tw93, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in .claude/skills/bugs of tw93/Mole.
Open the folder on GitHubat commit a68741b
Mole Bug Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Mole Bug Patterns this skilltw93/Mole | 69k | — | ~2k | Automated safety check: Pass | GPL-3.0 | |
| Swpm Code Reviewdeinsoftware/swpm | 125 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Batch Filesgithub/awesome-copilot | 40k | 1 repos | ~4.3k | Automated safety check: Pass | MIT | |
| Os Scriptingaiskillstore/marketplace | 430 | 3 repos | ~2.2k | Automated safety check: Notes | None | |
| Shell ScripterFerroxLabs/wayland | 608 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| New Mac Setupswyxio/skills | 172 | — | ~4.3k | Automated safety check: Pass | MIT |
deinsoftware/swpm
Automated code review bash script for SWPM. An agent skill from deinsoftware/swpm.
github/awesome-copilot
Expert-level Windows batch file (.bat/.cmd) skill for writing, debugging, and maintaining CMD scripts.
aiskillstore/marketplace
Operating system and shell scripting troubleshooting workflow for Linux, macOS, and Windows.
FerroxLabs/wayland
Shell scripting mastery. An agent skill from FerroxLabs/wayland.
swyxio/skills
Fully automated new Mac setup for fullstack web developers and AI engineers.
Jeffallan/claude-skills
Walks through designing, building and polishing a command-line tool: user workflow and command hierarchy, implementation in commander, click, typer or cobra, completions and cross-platform testing.
tw93/Mole
Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.
tw93/Mole
Publishes curated, bilingual release notes for an existing Mole version tag with gh release edit, including contributor thanks and reactions, after the release workflow finishes.
tw93/Mole
Teaches an agent to drive the Mole (mo) Mac cleaning CLI safely: preview first, use JSON output, and leave destructive runs to the user.
Categories
A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests. This is a project-specific review aid for Mole, an open-source command-line tool for cleaning and optimizing a Mac. It routes the agent to reference notes instead of loading everything at once.
Mole Bug Patterns fits situations like: reviewing a Mole diff that touches cleanup or deletion logic; checking that dry-run and real code paths apply the same safety guards; auditing shell scripts for unbounded commands and errexit traps; checking whether a new regression test could ever fail.
Run `npx skills add tw93/Mole --skill bugs -a claude-code`. Or copy the skill folder (.claude/skills/bugs in tw93/Mole) into .claude/skills/bugs in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tw93/Mole --skill bugs -a codex`. Or copy the skill folder (.claude/skills/bugs in tw93/Mole) into .agents/skills/bugs in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tw93/Mole --skill bugs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bugs, .gemini/skills/bugs, .github/skills/bugs and .opencode/skills/bugs in your project.
Going by SKILL.md and its folder, Mole Bug Patterns needs the command-line tools its instructions call (go).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Mole Bug Patterns is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Mole Bug Patterns: Swpm Code Review (deinsoftware/swpm, 125 stars), Batch Files (github/awesome-copilot, 40k stars), Os Scripting (aiskillstore/marketplace, 430 stars) and Shell Scripter (FerroxLabs/wayland, 608 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tw93 (a GitHub user) maintains it in tw93/Mole, which has 69,469 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.
Source: tw93/Mole on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.