Agent skill

Bug Audit

by VasiHemanth in VasiHemanth/tokentelemetry

Weekly multi-agent audit for serious bugs (data integrity, silent caps, staleness, timestamp math, trust boundaries).

MITAuto-check passedAgent Workflows

Install Bug Audit

skills CLI
$ npx skills add VasiHemanth/tokentelemetry --skill bug-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install VasiHemanth/tokentelemetry bug-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/VasiHemanth/tokentelemetry.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/bug-audit .claude/skills/bug-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bug-audit
GitHub stars
376
Token cost
~1k tokens
SKILL.md length
472 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Weekly multi-agent audit for serious bugs (data integrity, silent caps, staleness, timestamp math, trust boundaries).

  • Works in 3 steps: Find the last audit marker: the most… → Primary scope = git diff ..HEAD plus any… → Always include the standing hot-spots…
  • Tasks that involve LLM cost and token optimization
  • SKILL.md covers Scope selection (do this first), Fan-out (Agent tool; run each…, Output and Weekly cadence
  • Calls gh, claude and git

What it does

Bug Audit is an agent skill from VasiHemanth/tokentelemetry. Weekly multi-agent audit for serious bugs (data integrity, silent caps, staleness, timestamp math, trust boundaries). Fans out Sonnet scanners + Opus deep auditors, adversarially verifies every finding, files GitHub issues for confirmed critical/high bugs. Trigger: /bug-audit

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering LLM cost and token optimization. It works with GitHub and TypeScript. The repository describes itself as: Token telemetry dashboard for AI autonomous and coding agents — tracks tokens, sessions, tool calls & reasoning across Hermes agent, Claude Code, Antigravity CLI, Codex & more… The licence is MIT.

When your agent uses it

  • Tasks that involve LLM cost and token optimization

Example prompts

  • “/bug-audit”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Find the last audit marker: the most recent GitHub issue labeled
  2. Primary scope = git diff ..HEAD plus any file those
  3. Always include the standing hot-spots regardless of diff

What it can do on your machine

Read from SKILL.md and the folder at commit d693bda. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • claude
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bug Audit loads about 1k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 472 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from VasiHemanth/tokentelemetry at commit d693bda, republished under its MIT licence (© VasiHemanth). 472 words, ~1,007 tokens.

Download SKILL.mdSave it as .claude/skills/bug-audit/SKILL.md (or your agent's skills folder).
name
bug-audit
description
Weekly multi-agent audit for serious bugs (data integrity, silent caps, staleness, timestamp math, trust boundaries). Fans out Sonnet scanners + Opus deep auditors, adversarially verifies every finding, files GitHub issues for confirmed critical/high bugs. Trigger: /bug-audit

bug-audit — weekly serious-bug sweep

Multi-agent audit of the TokenTelemetry backend/frontend for the bug class that motivated it (PR #131: a silent 100-session cap plus stub rows crushing real persisted data). Optimized for bugs that corrupt data, lose data, or silently report wrong numbers — not style or hypotheticals.

Scope selection (do this first)

  1. Find the last audit marker: the most recent GitHub issue labeled bug-audit (gh issue list --label bug-audit --state all --limit 1), whose body records the commit it audited up to.
  2. Primary scope = git diff <last-audited-commit>..HEAD plus any file those diffs touch. If no marker exists (first run), scope = backend/*.py and frontend/src/lib + frontend/src/app.
  3. Always include the standing hot-spots regardless of diff: backend/main.py scan loops, backend/history_store.py, backend/scan_cache.py (if present), anything matching backend/*cache*/backend/*store*.

Fan-out (Agent tool; run each wave's spawns in parallel)

Wave 1 — breadth, audit-scanner (Sonnet), one per dimension:

  • silent caps & truncation (slices, LIMIT, early breaks, [:N])
  • persisted-state integrity (upserts that overwrite, absent-vs-zero confusion, stub/partial rows)
  • cache & staleness (mtime keys, missing version fields, invalidation gaps)
  • timestamp/timezone math (naive datetimes, mtime-as-date, day bucketing)
  • trust boundaries (on-disk ids/paths/cwd used in paths, SQL, shell)
  • token/cost arithmetic (double counting, high-water-mark vs sum, unit slips)

Give each scanner the scope file list and its dimension. Prompt them to return the FINDING-block format their agent definition specifies.

Wave 2 — depth, audit-deep (Opus), in the same parallel batch as wave 1: one per risky subsystem actually present in scope, typically 2-4 of:

  • scan → cache → history-upsert pipeline (the PR #131 path)
  • one agent-store parser that changed recently (Claude, Codex, Copilot…)
  • any new persisted format introduced since the last audit
  • the analytics aggregation path (/analytics, ecosystem rollups)

Wave 3 — verification, audit-verifier (Opus), one per candidate: Dedupe wave 1+2 candidates by (file, defect) first. Send each survivor to a verifier with the full finding block. Only VERDICT: CONFIRMED findings survive; keep the verifier's own severity, not the scanner's.

Show full SKILL.md (161 more words)Show less

Output

  1. Write the report to docs/audits/<YYYY-MM-DD>-bug-audit.md: audited range (<from>..<to> commits), confirmed findings (severity, file:line, scenario, verifier's reason), refuted-candidate count, dimensions that came back clean.
  2. File one GitHub issue per confirmed critical or high finding: gh issue create --label bug,bug-audit — title is the one-sentence defect, body is the finding block + verifier reason + audited commit. Medium findings go only in the report.
  3. Always file/update the audit-marker issue: a single issue titled bug-audit marker labeled bug-audit whose body's last line is audited-through: <HEAD sha> (edit it if it exists, create otherwise).
  4. Commit the report on a branch audit/<YYYY-MM-DD> and open a draft PR (report only — never commit fixes from this skill; fixes are separate, human-initiated work).

Weekly cadence

Run manually with /bug-audit, or schedule headless:

bash
# launchd/cron, weekly:
cd /path/to/tokentelemetry && claude -p "/bug-audit" --permission-mode acceptEdits

Budget note: one run spawns roughly 6 Sonnet scanners + 2-4 Opus deep auditors + one Opus verifier per candidate. If candidates exceed ~15, verify only critical/high candidates and list the rest as unverified in the report.

© VasiHemanth, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/bug-audit of VasiHemanth/tokentelemetry.

Open the folder on GitHubat commit d693bda

Compare with similar skills

Bug Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bug Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bug Audit this skillVasiHemanth/tokentelemetry376—~1kAutomated safety check: PassMIT
Project Releaseswimmwatch/cloakbrowser-mcp161—~1.9kAutomated safety check: PassMIT
Spec Driven Developzhu1090093659/deepseek-pp1.9k—~6.9kAutomated safety check: PassApache-2.0
Levyra Context EfficiencyLUC4N3X/Levyra-deepsound531—~1.3kAutomated safety check: NotesGPL-3.0
GitHub Commentingjuspay/neurolink143—~698Automated safety check: PassMIT
Copilot SDKgithub/awesome-copilot40k5 repos~6.3kAutomated safety check: PassMIT

Similar skills

  • Project Release

    swimmwatch/cloakbrowser-mcp

    Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work.

    161 GitHub stars~1.9k tokensUpdated 6 days ago
    Agent WorkflowsAuto-check passed
  • Spec Driven Develop

    zhu1090093659/deepseek-pp

    Automates pre-development workflow for large-scale complex tasks.

    1.9k GitHub stars~6.9k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • Levyra Context Efficiency

    LUC4N3X/Levyra-deepsound

    A skill your agent uses for genuinely high-volume Levyra work such as builds, tests, lint, logs, broad searches, dependency output, Git/GitHub or CodeRabbit inspection, CI diagnostics, agent setup…

    531 GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • GitHub Commenting

    juspay/neurolink

    How to post clean, rich, deduplicated GitHub PR review comments — suggestion blocks, multi-line anchors, markers, formatting rules.

    143 GitHub stars~698 tokensUpdated today
    DevelopmentAuto-check passed
  • Copilot SDK

    github/awesome-copilot

    Official

    Build agentic applications with GitHub Copilot SDK. An agent skill from github/awesome-copilot.

    40k GitHub starsUsed in 5 repos~6.3k tokens
    AI & LLM EngineeringAuto-check passed
  • Deepseek Automation

    zhu1090093659/deepseek-pp

    A skill your agent uses when implementing, resuming, reviewing, or verifying the DeepSeek++ Codex-style automation feature in this repository.

    1.9k GitHub stars~2.1k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes

More from VasiHemanth/tokentelemetry

  • Issue Brief

    VasiHemanth/tokentelemetry

    Explain a GitHub issue, discussion, or feature request in plain language before deciding whether to build it.

    376 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed

Questions about Bug Audit

What does Bug Audit do?

Weekly multi-agent audit for serious bugs (data integrity, silent caps, staleness, timestamp math, trust boundaries). Bug Audit is an agent skill from VasiHemanth/tokentelemetry. Weekly multi-agent audit for serious bugs (data integrity, silent caps, staleness, timestamp math, trust boundaries).

When should I use Bug Audit?

Bug Audit fits situations like: tasks that involve LLM cost and token optimization.

How do I install Bug Audit in Claude Code?

Run `npx skills add VasiHemanth/tokentelemetry --skill bug-audit -a claude-code`. Or copy the skill folder (.claude/skills/bug-audit in VasiHemanth/tokentelemetry) into .claude/skills/bug-audit in your project. Claude Code loads it when a task matches its description.

How do I install Bug Audit in Codex?

Run `npx skills add VasiHemanth/tokentelemetry --skill bug-audit -a codex`. Or copy the skill folder (.claude/skills/bug-audit in VasiHemanth/tokentelemetry) into .agents/skills/bug-audit in your project. Codex loads it when a task matches its description.

Can I use Bug Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add VasiHemanth/tokentelemetry --skill bug-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bug-audit, .gemini/skills/bug-audit, .github/skills/bug-audit and .opencode/skills/bug-audit in your project.

What does Bug Audit need to run?

Going by SKILL.md and its folder, Bug Audit needs the command-line tools its instructions call (gh, claude and git).

Does Bug Audit access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Bug Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bug Audit use?

Bug Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bug Audit use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bug Audit?

Skills that share tags, products or a category with Bug Audit: Project Release (swimmwatch/cloakbrowser-mcp, 161 stars), Spec Driven Develop (zhu1090093659/deepseek-pp, 1.9k stars), Levyra Context Efficiency (LUC4N3X/Levyra-deepsound, 531 stars) and GitHub Commenting (juspay/neurolink, 143 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bug Audit?

VasiHemanth (a GitHub user) maintains it in VasiHemanth/tokentelemetry, which has 376 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 6, 2026.

Source: VasiHemanth/tokentelemetry on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.