Git History Bug Audit
ben-manes/caffeine
Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.
Applies a minimal fix to an emergency bug through triage, root-cause location, a hotfix branch and a blast-radius check, with tests and review still required.
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill hotfix -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install VeryGoodOpenSource/vgv-wingspan hotfix --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hotfix .claude/skills/hotfix && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hotfix" agent skill from https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/hotfix into .claude/skills/hotfix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hotfix", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/hotfixType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill hotfix -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install VeryGoodOpenSource/vgv-wingspan hotfix --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/hotfix .agents/skills/hotfix && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hotfix" agent skill from https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/hotfix into .agents/skills/hotfix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hotfix", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill hotfix -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install VeryGoodOpenSource/vgv-wingspan hotfix --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/hotfix .cursor/skills/hotfix && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hotfix" agent skill from https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/hotfix into .cursor/skills/hotfix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hotfix", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/VeryGoodOpenSource/vgv-wingspan.git --path skills/hotfix--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill hotfix -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install VeryGoodOpenSource/vgv-wingspan hotfix --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/hotfix .gemini/skills/hotfix && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hotfix" agent skill from https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/hotfix into .gemini/skills/hotfix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hotfix", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install VeryGoodOpenSource/vgv-wingspan hotfixInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill hotfix -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/hotfix .github/skills/hotfix && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hotfix" agent skill from https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/hotfix into .github/skills/hotfix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hotfix", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add VeryGoodOpenSource/vgv-wingspan --skill hotfix -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install VeryGoodOpenSource/vgv-wingspan hotfix --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-wingspan.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/hotfix .opencode/skills/hotfix && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hotfix" agent skill from https://github.com/VeryGoodOpenSource/vgv-wingspan/tree/main/skills/hotfix into .opencode/skills/hotfix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hotfix", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hotfixApplies a minimal fix to an emergency bug through triage, root-cause location, a hotfix branch and a blast-radius check, with tests and review still required.
This workflow skips brainstorm and plan documents but keeps tests and review mandatory. It needs a bug description, whether a symptom, an issue link or an error message, and asks for one if it is missing. The agent triages the bug in one sentence with symptom and suspected area, then uses a codebase-review agent to locate the responsible code narrowly and summarizes the root cause in two to three sentences, asking you for more context if the cause stays unclear.
It proposes a `hotfix/` branch named from the bug description unless you are already on one, then runs a blast-radius check before any code is written. If the fix would touch more than five files, several layers or new abstractions, it warns you and offers to switch to planning. Changes must be minimal with no drive-by refactors, and out-of-scope issues get a TODO(hotfix) comment. Reference files cover driving the build to green, a PR template, review agent instructions, consolidating review findings and a review report template. The only shell command it declares permission for is removing `docs/hotfix-review/`.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 19e0695. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(rm -rf docs/hotfix-review/)From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code (or similar products with agent support)
From compatibility in the SKILL.md frontmatter.
Targeted Emergency Bug Fix loads about 1.9k tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 32 tokens; SKILL.md has 1,003 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from VeryGoodOpenSource/vgv-wingspan at commit 19e0695, republished under its MIT licence (© VeryGoodOpenSource). 1,003 words, ~1,919 tokens.
.claude/skills/hotfix/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Apply a minimal, targeted fix fast. No brainstorm document, no plan document — but tests and review are still non-negotiable.
<bug_description>$ARGUMENTS</bug_description>
If the bug description above is empty, ask the user: "What's the bug? Paste a description, issue link, or error message."
DO NOT proceed until you have a bug description.
Summarize the bug in one sentence. Identify:
Run a focused codebase exploration to find the problem area:
After the agent returns:
If the root cause is unclear after exploration, use AskUserQuestion to ask the user for additional context before proceeding.
Set up a hotfix branch. Unlike normal feature branches, hotfix branches use the hotfix/ prefix.
Run:
git rev-parse --abbrev-ref HEADIf already on a hotfix/ branch: skip silently.
Otherwise: infer a branch name in the format hotfix/<kebab-slug> where the slug is derived from the bug description (max 60 characters total). Use AskUserQuestion to confirm:
git checkout -b hotfix/<slug>Before writing any code, outline which files and layers the fix touches.
If >5 files, multiple layers, or new abstractions needed: warn the user and use AskUserQuestion: (1) Proceed with hotfix, (2) Switch to /plan.
If contained (≤5 files, single layer): proceed directly.
Write the minimal change that addresses the root cause. Change only what is necessary — no drive-by refactors. If you touch unrelated code, stop and flag scope creep. Leave // TODO(hotfix): <description> comments for out-of-scope issues. Match surrounding code style.
Tests are non-negotiable, even for hotfixes:
Follow the validation and fix procedure.
// TODO(hotfix): <description of known limitation and its severity> comment in the code and note it in the PR description. The goal is to stop the bleeding, not achieve perfection.Run review agents in parallel to validate the fix. Use a reduced set — speed matters, but quality is non-negotiable.
Run pwd and let <PWD> be the result — subagents may change directories, making relative paths unreliable.
Each agent prompt must include the review agent instructions with <RAW_DIR> set to <PWD>/docs/hotfix-review/raw and <name> set to the agent's report name below (a bare stem — the agent writes <RAW_DIR>/<name>.md). Substitute <PWD> with the absolute path.
The reduced agent set and their report names (<name>):
| Agent | Report name |
|---|---|
| @vgv-review-agent | vgv-review |
| @test-quality-review-agent | test-quality-review |
If an agent fails, note it, continue with the other, and record the failure in the report header so the reduced review isn't silently halved.
Follow the review consolidation procedure: deduplicate the agents' structured findings, order them deterministically, assign stable FINDING-NN ids, and write one consolidated file to <PWD>/docs/hotfix-review/review.md using the report template. Print the aligned chat summary (same ids, order, and titles as the file). Then fix Critical findings by id and present Important findings to the user. The report is deleted at Cleanup, so the fix commit does not cite FINDING-NN ids.
Remove review reports after findings are addressed:
rm -rf docs/hotfix-review/A hotfix has no plan, so there is no success-criteria block. Follow the drive to green procedure with the detected project suite (formatter, linter, test runner) as both the gate set and the authoritative command run once. It loops until green by real output, delegates to a matching installed verification skill when one exists, and escalates only on un-runnable or self-contradictory failures — never on an ordinary, fixable one. Do not proceed until it is green.
Create a single, cherry-pick-friendly commit. Stage only fix-related files (no unrelated changes). Use this commit format:
fix: <concise description of what was fixed>
<Root cause explanation in 1-2 sentences>
Bug: <original bug description or issue link, truncated if long>Push the branch and create a PR. Title: fix: <concise description> (under 70 chars). Body: Use the PR template.
Use AskUserQuestion to present options:
/plan → /build.hotfix/ prefix, not fix/. Other skills use fix/ — do not mix them.docs/hotfix-review/ already exists from a previous interrupted hotfix, delete it before running Phase 4 to avoid stale reports contaminating the review./plan → /build.© VeryGoodOpenSource, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in skills/hotfix of VeryGoodOpenSource/vgv-wingspan.
Open the folder on GitHubat commit 19e0695
Targeted Emergency Bug Fix next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Targeted Emergency Bug Fix this skillVeryGoodOpenSource/vgv-wingspan | 108 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Git History Bug Auditben-manes/caffeine | 18k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Codexqa Rootcause Analyzeropenqa-cn/codexqa | 152 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| TiDB Test Diff Triagepingcap/tidb | 41k | — | ~498 | Automated safety check: Pass | Apache-2.0 | |
| Code Design Rationale Investigatorcursor/plugins | 10k | 9 repos | ~2.6k | Automated safety check: Pass | None | |
| Debugging and Error Recoveryaddyosmani/agent-skills | 102k | 1 repos | ~2.6k | Automated safety check: Pass | MIT |
ben-manes/caffeine
Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.
openqa-cn/codexqa
Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.
pingcap/tidb
Investigates TiDB plan or test-result diffs that the change does not explain, ruling out failpoint setup and merge effects before expected outputs are updated.
cursor/plugins
Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.
addyosmani/agent-skills
Applies a stop-the-line rule and a step-by-step triage when tests fail, builds break or something stops working, aiming at the root cause instead of guesses.
ruby-git/ruby-git
Addresses unresolved pull request review threads and suppressed (low-confidence) Copilot review comments on the current branch, folds each fix into the…
VeryGoodOpenSource/vgv-wingspan
Runs parallel review agents over a branch, chosen paths or a whole project and merges their findings into one numbered report you can act on by id.
VeryGoodOpenSource/vgv-wingspan
Rebases the current feature branch onto the latest main, master or develop, stashing uncommitted work first and aborting cleanly if conflicts appear.
VeryGoodOpenSource/vgv-wingspan
Clarifies what to build before how, by asking one question at a time about a feature idea and then handing the result on to planning.
VeryGoodOpenSource/vgv-wingspan
Stages, commits, pushes and opens a pull request with a Conventional Commits message, after running the project's checks unless told to skip them.
VeryGoodOpenSource/vgv-wingspan
Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh.
VeryGoodOpenSource/vgv-wingspan
Turns high-level brainstorming and ideas into well-structured, actionable implementation plans.
Works with
Categories
Applies a minimal fix to an emergency bug through triage, root-cause location, a hotfix branch and a blast-radius check, with tests and review still required. This workflow skips brainstorm and plan documents but keeps tests and review mandatory. It needs a bug description, whether a symptom, an issue link or an error message, and asks for one if it is missing.
Targeted Emergency Bug Fix fits situations like: shipping a small, targeted fix for a production bug without a full planning cycle; keeping an urgent fix to a minimal, reviewed and tested change; deciding whether an urgent bug is contained enough to skip planning.
Run `npx skills add VeryGoodOpenSource/vgv-wingspan --skill hotfix -a claude-code`. Or copy the skill folder (skills/hotfix in VeryGoodOpenSource/vgv-wingspan) into .claude/skills/hotfix in your project. Claude Code loads it when a task matches its description.
Run `npx skills add VeryGoodOpenSource/vgv-wingspan --skill hotfix -a codex`. Or copy the skill folder (skills/hotfix in VeryGoodOpenSource/vgv-wingspan) into .agents/skills/hotfix in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add VeryGoodOpenSource/vgv-wingspan --skill hotfix -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hotfix, .gemini/skills/hotfix, .github/skills/hotfix and .opencode/skills/hotfix in your project.
Going by SKILL.md and its folder, Targeted Emergency Bug Fix needs the command-line tools its instructions call (git). Our summary lists: A git repository; An agent environment that supports subagents, such as Claude Code. Its frontmatter pre-approves these tools: Bash(rm -rf docs/hotfix-review/). Compatibility (from SKILL.md): Designed for Claude Code (or similar products with agent support).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Targeted Emergency Bug Fix is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 145 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Targeted Emergency Bug Fix: Git History Bug Audit (ben-manes/caffeine, 18k stars), Codexqa Rootcause Analyzer (openqa-cn/codexqa, 152 stars), TiDB Test Diff Triage (pingcap/tidb, 41k stars) and Code Design Rationale Investigator (cursor/plugins, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
VeryGoodOpenSource (a GitHub organization) maintains it in VeryGoodOpenSource/vgv-wingspan, which has 108 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on September 30, 2026.
Source: VeryGoodOpenSource/vgv-wingspan on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.