ast-grep Structural Search
code-yeongyu/oh-my-openagent
Searches and rewrites code by syntax-tree shape across 25 languages with ast-grep, for codemods, structural queries and YAML lint rules, using a Python wrapper script.
A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…
$ npx skills add WrongStack/WrongStack --skill bug-hunter -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install WrongStack/WrongStack bug-hunter --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/bug-hunter .claude/skills/bug-hunter && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "bug-hunter" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/bug-hunter into .claude/skills/bug-hunter/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bug-hunter", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/bug-hunterType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add WrongStack/WrongStack --skill bug-hunter -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install WrongStack/WrongStack bug-hunter --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/core/skills/bug-hunter .agents/skills/bug-hunter && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "bug-hunter" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/bug-hunter into .agents/skills/bug-hunter/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bug-hunter", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill bug-hunter -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install WrongStack/WrongStack bug-hunter --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/core/skills/bug-hunter .cursor/skills/bug-hunter && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "bug-hunter" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/bug-hunter into .cursor/skills/bug-hunter/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bug-hunter", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/WrongStack/WrongStack.git --path packages/core/skills/bug-hunter--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add WrongStack/WrongStack --skill bug-hunter -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install WrongStack/WrongStack bug-hunter --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/core/skills/bug-hunter .gemini/skills/bug-hunter && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "bug-hunter" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/bug-hunter into .gemini/skills/bug-hunter/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bug-hunter", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install WrongStack/WrongStack bug-hunterInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add WrongStack/WrongStack --skill bug-hunter -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/core/skills/bug-hunter .github/skills/bug-hunter && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "bug-hunter" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/bug-hunter into .github/skills/bug-hunter/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bug-hunter", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill bug-hunter -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install WrongStack/WrongStack bug-hunter --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/core/skills/bug-hunter .opencode/skills/bug-hunter && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "bug-hunter" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/bug-hunter into .opencode/skills/bug-hunter/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bug-hunter", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
bug-hunterA skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…
Bug Hunter is an agent skill from WrongStack/WrongStack. Use this skill when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and verify one real defect. Trigger on the explicit vocabulary — "bug", "bug hunt", "/bughunt", "scan for issues", "find problems", "anti-pattern", "code smell", "static analysis" — and on the task shape, which is how it usually arrives: "audit these files", "scan this module", "check for leaks", "something's wrong in X", "look for…
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `SKILL.save.md`).
It sits in Development, covering Refactoring and Static analysis and SAST. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 57f6018. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Bug Hunter loads about 3.7k tokens when it runs. Until then it costs about 191 tokens; SKILL.md has 1,897 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from WrongStack/WrongStack at commit 57f6018, republished under its MIT licence (© WrongStack). 1,897 words, ~3,718 tokens.
.claude/skills/bug-hunter/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Finds real defects in code. In a scan it outputs a prioritized hit list with file:line references; in a proof-driven round it selects the one candidate it can prove, and hands it to the proof, fix, and verification discipline.
file:line you have actually read — verify the line exists;
never invent, guess, or extrapolate a reference. No line reference = can't be
fixed.node_modules, build output, or generated code.1. Scope: Accept file/dir globs, explicit paths, a feature, or a symptom
2. Map: Entry points, callers, and the contract the code must honour
3. Scan: grep/read across target files, lifecycle and async paths first
4. Confirm: Open each hit and answer the three questions below
5. Classify: Categorize by type and severity
6. Deliver: Report (scan modes) or select one candidate (proof-driven mode)A regex hit is a place to look, never a finding. Before any hit becomes a line in the report, open it and answer three questions:
element.innerHTML = "<b>Loading</b>" is not XSS..catch() chained further down, a
validated input, an outer try/catch, a cleanup in the owner's teardown —
read enough surrounding lines to know.Also establish what correct behaviour is and why: a documented contract, a caller's requirement, or an established test. A deliberate tradeoff or a stylistic preference is not a bug, however it looks.
When the codebase index and quality tools are available, let them narrow the search and grep for the rest:
Tool output is a candidate list like any grep hit: every finding is read before it ships.
node_modules, dist, build, .next, out, coverage, lockfiles,
*.min.*, generated clients and protobufs, snapshots (__snapshots__),
vendored third-party directories, and .git.
Test files and fixtures are a special case. Do not scan them for secrets — mock credentials are expected there. Do still scan them for leaks and unawaited promises, since those cause real flakiness. When a finding lands in a test file, say so in the finding.
| Level | Meaning | Action |
|---|---|---|
| Critical | Security breach, data loss, crash | Fix immediately |
| High | Logic bug, race condition, memory leak | Fix before release |
| Medium | Error handling gap, type unsafety | Fix soon |
| Low | Minor code smell with a real consequence | Consider fixing |
as any is Medium at a network
boundary and Low in an internal helper that only ever receives typed input.When torn between two levels, pick the lower one. Over-calling costs the reader's trust in every other line.
Regex column = where to start grepping. Confirm column = what must be true in the actual code before it becomes a finding.
| Pattern | Regex hint | Confirm by reading | Severity |
|---|---|---|---|
| Uncaught promise | \.then\( without .catch | No .catch on the chain and no enclosing try/catch on an awaited call | high |
| Missing await | async call as a bare statement | The call has side effects whose ordering or failure matters | high |
| Listener / timer leak | \.on\(, addEventListener, setInterval, setTimeout, subscribe | No matching removal or clear in teardown, on abort, or on the error path, and the owner outlives the handler | high |
| Abort not honoured | AbortSignal, signal parameters | Signal accepted but not passed down, not checked between steps, or its listener is never removed after completion | high |
| Stateful regex | /g or /y flag on a shared or module-level regex | Reused with .test()/.exec() across calls, so lastIndex makes alternate calls miss | high |
| Ignored option | option or config field in a type or signature | Accepted but never read on some path, or overwritten by a default | medium |
| Unsafe fallback | || or ?? defaults, catch returning a default | A valid falsy value (0, '', false) is replaced, or a failure is turned into a plausible success | medium |
| Stale state | caches, memos, module-level maps, let captured by closures | The key omits an input that changes the result, or nothing invalidates it | high |
| Race / check-then-act | an await between a check and the act it guards | Another caller can change the checked state in between; a second call can start before the first finishes | high |
| Path / name normalization | path.join, split('/'), endsWith('., toLowerCase | Separators, drive-letter case, trailing slashes, or extension case differ between producer and consumer | medium |
| Boundary / off-by-one | <=, length - 1, slice(, pagination, limits | Empty, single-element, exact-limit, or last-page input breaks the contract | medium |
| Unreachable branch | conditions over narrowed types, duplicate case | The branch can never run, so the handling it promises never happens | medium |
| Swallowed error | catch {}, catch (e) {}, .catch(() => {}) | The failure it hides is meaningful rather than genuinely ignorable | medium |
| Unbounded resource | while (true), recursion, unpaginated fetch-all, unbounded arrays or maps | No break condition, timeout, eviction, or limit on a path that can grow | high |
| Hardcoded secret | sk-, AKIA, -----BEGIN, api[_-]?key\s*= | It's a live credential, not a hash, digest, or test fixture | critical |
| Injection | exec( or execSync( with ${; SQL built with + or ${; innerHTML = | The interpolated value can carry caller-controlled input and is not escaped or parameterized | critical |
| Unsafe any | :\s*any\b or as any | Sits at a trust boundary (parsed JSON, network, DB, user input) rather than internal glue | medium |
Extend this table when a hunt turns up a pattern worth watching for — but only with rows that pass the same test: a grep that narrows the search plus a condition that decides it.
## Bug Hunt Report — <scope>
### Critical (must fix)
1. [SHELL-INJ] `tools/shell.ts:42` — template literal in exec()
`exec(\`echo ${userInput}\`)` → use execFile with args array
### High
2. [LEAK] `tools/pool.ts:89` — listener never removed on abort
### Summary
| Severity | Count |
|----------|-------|
| Critical | 1 |
| High | 1 |
Total: 2 findings in 2 files
<nextsteps>
1. Fix the shell injection in tools/shell.ts:42
2. Fix the listener leak in tools/pool.ts:89
</nextsteps>When more than 30% of hits were noise, add one line under Summary:
False positive rate: ~N% — <one-line cause>. If a scan turns up nothing, say
so plainly with the scope and file count.
As documented above. Report only; suggest fixes, don't apply them, unless the user asked for fixes.
Dispatched by a leader across a chunk of files (typically 5–10 per worker).
file:line, one-line fix — so findings deduplicate cleanly.When verified chimera findings meet the cascadeOn threshold
(high or critical; default high), the runtime spawns bug-hunter for
findings at or above that severity. You receive the review report and the changed files; you investigate
each finding and apply fixes. Results go directly to the session
transcript. NEVER send mailbox messages to the leader. You take part in the
re-review loop, up to maxCascadeDepth cycles.
One round = at most one proven, fixed, verified root cause. The round's own instructions are the protocol; this mode governs how the candidate is chosen. It overrides the out-of-scope list below: in this mode you do fix the bug and do write its regression test, and you never fan out, however large the target.
debugging and testing
before touching production code.Finish with verify-before-done: the same proof green, the regression test in
the normal suite, related checks, and an honest outcome label.
chimera's read-only lane; style is the linter's job. Multi-file
restructuring is refactor-planner's.security-scanner's lane.testing's lane outside proof-driven rounds.multi-agent fan-out on your own. For a target larger than
roughly 10–15 files, report its size and let the leader dispatch.debugging — for the reproduction and root cause once a candidate is chosentesting — for the proof and the durable regression testverify-before-done — for the final evidence and reportcode-review — for reviewing a specific change setsecurity-scanner — for hardcoded secrets and injection vectorsrefactor-planner — for fixing findings across multiple filestypescript-strict — for TypeScript type safety rulesoutput-standards — for standardized <nextsteps> formattingmulti-agent — for fanning out scans across large targets (never in a
proof-driven round)file:line opened and confirmed — none from grep output alone<nextsteps> mirrors them in order© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in packages/core/skills/bug-hunter of WrongStack/WrongStack.
Open the folder on GitHubat commit 57f6018
Bug Hunter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Bug Hunter this skillWrongStack/WrongStack | 370 | — | ~3.7k | Automated safety check: Pass | MIT | |
| ast-grep Structural Searchcode-yeongyu/oh-my-openagent | 70k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Gograph Go Repository Intelligenceozgurcd/gograph | 227 | — | ~4.8k | Automated safety check: Notes | MIT | |
| jscpd Duplicate Code Detectorkucherenko/jscpd | 6.4k | — | ~4.5k | Automated safety check: Pass | MIT | |
| Ripwire Graph Queryredhat-et/ripwire | 2.4k | — | ~1.1k | Automated safety check: Notes | Apache-2.0 | |
| Refactorabilitymeain/dotfiles | 285 | — | ~2k | Automated safety check: Pass | MIT |
code-yeongyu/oh-my-openagent
Searches and rewrites code by syntax-tree shape across 25 languages with ast-grep, for codemods, structural queries and YAML lint rules, using a Python wrapper script.
ozgurcd/gograph
Gives an agent working in a Go codebase a structural view through a local MCP server: call graphs, blast-radius and impact analysis, and bounded first-call exploration.
kucherenko/jscpd
Finds duplicated code in 220+ languages with jscpd, reports exact, renamed and near-miss clones in a compact agent-friendly format and measures duplication.
redhat-et/ripwire
Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.
meain/dotfiles
Review code for refactorability — surface concrete, prioritized refactoring opportunities grounded in Martin Fowler's smell catalog and SOLID, augmented with static analysis tools (gocyclo…
affaan-m/ECC
Verification loop for Quarkus projects: build, static analysis (Checkstyle, PMD, SpotBugs), tests with JaCoCo coverage, OWASP dependency and container security scans, GraalVM native compilation…
WrongStack/WrongStack
Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.
WrongStack/WrongStack
A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…
WrongStack/WrongStack
A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…
WrongStack/WrongStack
A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.
WrongStack/WrongStack
Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…
WrongStack/WrongStack
A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…
Categories
A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…. Bug Hunter is an agent skill from WrongStack/WrongStack. Use this skill when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and verify one real defect.
Bug Hunter fits situations like: scanning source code for bugs; quality issues in a codebase; running a proof-driven bug hunt that must find; verify one real defect.
Run `npx skills add WrongStack/WrongStack --skill bug-hunter -a claude-code`. Or copy the skill folder (packages/core/skills/bug-hunter in WrongStack/WrongStack) into .claude/skills/bug-hunter in your project. Claude Code loads it when a task matches its description.
Run `npx skills add WrongStack/WrongStack --skill bug-hunter -a codex`. Or copy the skill folder (packages/core/skills/bug-hunter in WrongStack/WrongStack) into .agents/skills/bug-hunter in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill bug-hunter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bug-hunter, .gemini/skills/bug-hunter, .github/skills/bug-hunter and .opencode/skills/bug-hunter in your project.
SKILL.md names no scripts, command-line tools or credentials: Bug Hunter is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Bug Hunter is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Bug Hunter: ast-grep Structural Search (code-yeongyu/oh-my-openagent, 70k stars), Gograph Go Repository Intelligence (ozgurcd/gograph, 227 stars), jscpd Duplicate Code Detector (kucherenko/jscpd, 6.4k stars) and Ripwire Graph Query (redhat-et/ripwire, 2.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 370 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 7, 2026.
Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.