Agent skill

Bug Hunter

by WrongStack in WrongStack/WrongStack

A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…

MITAuto-check passedDevelopment

Install Bug Hunter

skills CLI
$ npx skills add WrongStack/WrongStack --skill bug-hunter -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install WrongStack/WrongStack bug-hunter --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/bug-hunter .claude/skills/bug-hunter && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bug-hunter
GitHub stars
370
Token cost
~3.7k tokens
SKILL.md length
1,897 words
Files
2
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…

  • Works in 4 steps: Standalone scan (default) → Fan-out worker → Cascade agent (behind a chimera review) → …
  • Scanning source code for bugs
  • SKILL.md covers Rules, Workflow, Severity levels and Bug patterns to find, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Bug Hunter is an agent skill from WrongStack/WrongStack. Use this skill when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and verify one real defect. Trigger on the explicit vocabulary — "bug", "bug hunt", "/bughunt", "scan for issues", "find problems", "anti-pattern", "code smell", "static analysis" — and on the task shape, which is how it usually arrives: "audit these files", "scan this module", "check for leaks", "something's wrong in X", "look for…

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `SKILL.save.md`).

It sits in Development, covering Refactoring and Static analysis and SAST. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.

When your agent uses it

  • Scanning source code for bugs
  • Quality issues in a codebase
  • Running a proof-driven bug hunt that must find
  • Verify one real defect

Example prompts

  • “bug hunt”
  • “/bughunt”
  • “scan for issues”
  • “/bug-hunter”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Standalone scan (default)
  2. Fan-out worker
  3. Cascade agent (behind a chimera review)
  4. Proof-driven round (Proof-Driven Bug Hunter, /bughunt)

What it can do on your machine

Read from SKILL.md and the folder at commit 57f6018. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bug Hunter loads about 3.7k tokens when it runs. Until then it costs about 191 tokens; SKILL.md has 1,897 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~191
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from WrongStack/WrongStack at commit 57f6018, republished under its MIT licence (© WrongStack). 1,897 words, ~3,718 tokens.

Download SKILL.mdSave it as .claude/skills/bug-hunter/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
bug-hunter
description
Use this skill when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and verify one real defect. Trigger on the explicit vocabulary — "bug", "bug hunt", "/bughunt", "scan for issues", "find problems", "anti-pattern", "code smell", "static analysis" — and on the task shape, which is how it usually arrives: "audit these files", "scan this module", "check for leaks", "something's wrong in X", "look for anything dangerous here", "clean pass before release". Also use it when running as a cascade agent behind a chimera review, or as a fan-out worker auditing a chunk of files in parallel — those modes have extra constraints documented below.
version
2.1.0
required-capabilities
filesystem.read, code.inspect
optional-capabilities
verification.run

Bug Hunter

Finds real defects in code. In a scan it outputs a prioritized hit list with file:line references; in a proof-driven round it selects the one candidate it can prove, and hands it to the proof, fix, and verification discipline.

Rules

  1. Always include a file:line you have actually read — verify the line exists; never invent, guess, or extrapolate a reference. No line reference = can't be fixed.
  2. Grep finds candidates; reading finds bugs. No hit becomes a finding until you can state the input that triggers it and what breaks.
  3. Never scan node_modules, build output, or generated code.
  4. Don't report style issues as bugs — those are lint findings.
  5. Don't inflate severity or pad the report. Twelve confirmed findings beat forty maybes, and a clean scan is a valid result.
  6. Sort output: critical > high > medium > low.

Workflow

1. Scope:    Accept file/dir globs, explicit paths, a feature, or a symptom
2. Map:      Entry points, callers, and the contract the code must honour
3. Scan:     grep/read across target files, lifecycle and async paths first
4. Confirm:  Open each hit and answer the three questions below
5. Classify: Categorize by type and severity
6. Deliver:  Report (scan modes) or select one candidate (proof-driven mode)
Confirm every candidate

A regex hit is a place to look, never a finding. Before any hit becomes a line in the report, open it and answer three questions:

  1. Is the triggering value actually reachable from a caller, user, or environment? element.innerHTML = "<b>Loading</b>" is not XSS.
  2. Is the path reachable? Dead code, unexported helpers with no callers, and branches behind a permanently-false flag are at most Low.
  3. Is it already handled nearby? A .catch() chained further down, a validated input, an outer try/catch, a cleanup in the owner's teardown — read enough surrounding lines to know.

Also establish what correct behaviour is and why: a documented contract, a caller's requirement, or an established test. A deliberate tradeoff or a stylistic preference is not a bug, however it looks.

Start from the index and scanners when they exist

When the codebase index and quality tools are available, let them narrow the search and grep for the rest:

  • the security-ast-scan tool for injection, hardcoded secrets, prototype pollution, ReDoS, unsafe eval, and N+1 queries in a file;
  • the dead-code-scan tool for unreferenced exports (candidates only — dynamic imports and config-driven registration are invisible to it);
  • the codebase-incoming-calls tool to confirm a suspicious function is reachable and to see how many callers inherit the defect.

Tool output is a candidate list like any grep hit: every finding is read before it ships.

Exclude before you scan

node_modules, dist, build, .next, out, coverage, lockfiles, *.min.*, generated clients and protobufs, snapshots (__snapshots__), vendored third-party directories, and .git.

Test files and fixtures are a special case. Do not scan them for secrets — mock credentials are expected there. Do still scan them for leaks and unawaited promises, since those cause real flakiness. When a finding lands in a test file, say so in the finding.


Severity levels

LevelMeaningAction
CriticalSecurity breach, data loss, crashFix immediately
HighLogic bug, race condition, memory leakFix before release
MediumError handling gap, type unsafetyFix soon
LowMinor code smell with a real consequenceConsider fixing
  • Reachability discounts it. The same as any is Medium at a network boundary and Low in an internal helper that only ever receives typed input.
  • Blast radius promotes it. A bug in one leaf component is what it is; the same bug in a shared util imported by forty modules is a level higher.

When torn between two levels, pick the lower one. Over-calling costs the reader's trust in every other line.


Bug patterns to find

Regex column = where to start grepping. Confirm column = what must be true in the actual code before it becomes a finding.

PatternRegex hintConfirm by readingSeverity
Uncaught promise\.then\( without .catchNo .catch on the chain and no enclosing try/catch on an awaited callhigh
Missing awaitasync call as a bare statementThe call has side effects whose ordering or failure mattershigh
Listener / timer leak\.on\(, addEventListener, setInterval, setTimeout, subscribeNo matching removal or clear in teardown, on abort, or on the error path, and the owner outlives the handlerhigh
Abort not honouredAbortSignal, signal parametersSignal accepted but not passed down, not checked between steps, or its listener is never removed after completionhigh
Stateful regex/g or /y flag on a shared or module-level regexReused with .test()/.exec() across calls, so lastIndex makes alternate calls misshigh
Ignored optionoption or config field in a type or signatureAccepted but never read on some path, or overwritten by a defaultmedium
Unsafe fallback|| or ?? defaults, catch returning a defaultA valid falsy value (0, '', false) is replaced, or a failure is turned into a plausible successmedium
Stale statecaches, memos, module-level maps, let captured by closuresThe key omits an input that changes the result, or nothing invalidates ithigh
Race / check-then-actan await between a check and the act it guardsAnother caller can change the checked state in between; a second call can start before the first finisheshigh
Path / name normalizationpath.join, split('/'), endsWith('., toLowerCaseSeparators, drive-letter case, trailing slashes, or extension case differ between producer and consumermedium
Boundary / off-by-one<=, length - 1, slice(, pagination, limitsEmpty, single-element, exact-limit, or last-page input breaks the contractmedium
Unreachable branchconditions over narrowed types, duplicate caseThe branch can never run, so the handling it promises never happensmedium
Swallowed errorcatch {}, catch (e) {}, .catch(() => {})The failure it hides is meaningful rather than genuinely ignorablemedium
Unbounded resourcewhile (true), recursion, unpaginated fetch-all, unbounded arrays or mapsNo break condition, timeout, eviction, or limit on a path that can growhigh
Hardcoded secretsk-, AKIA, -----BEGIN, api[_-]?key\s*=It's a live credential, not a hash, digest, or test fixturecritical
Injectionexec( or execSync( with ${; SQL built with + or ${; innerHTML =The interpolated value can carry caller-controlled input and is not escaped or parameterizedcritical
Unsafe any:\s*any\b or as anySits at a trust boundary (parsed JSON, network, DB, user input) rather than internal gluemedium

Extend this table when a hunt turns up a pattern worth watching for — but only with rows that pass the same test: a grep that narrows the search plus a condition that decides it.


Output format (scan modes)

## Bug Hunt Report — <scope>

### Critical (must fix)
1. [SHELL-INJ] `tools/shell.ts:42` — template literal in exec()
   `exec(\`echo ${userInput}\`)` → use execFile with args array

### High
2. [LEAK] `tools/pool.ts:89` — listener never removed on abort

### Summary
| Severity | Count |
|----------|-------|
| Critical | 1 |
| High     | 1 |

Total: 2 findings in 2 files

<nextsteps>
1. Fix the shell injection in tools/shell.ts:42
2. Fix the listener leak in tools/pool.ts:89
</nextsteps>

When more than 30% of hits were noise, add one line under Summary: False positive rate: ~N% — <one-line cause>. If a scan turns up nothing, say so plainly with the scope and file count.


Running modes

1. Standalone scan (default)

As documented above. Report only; suggest fixes, don't apply them, unless the user asked for fixes.

2. Fan-out worker

Dispatched by a leader across a chunk of files (typically 5–10 per worker).

  • Stay inside the assigned paths. Scope creep breaks the leader's coverage math.
  • Return the same result shape every sibling worker returns — severity, file:line, one-line fix — so findings deduplicate cleanly.
  • If the chunk is too large to finish, report what you confirmed and name the files you did not reach. Silent partial coverage is the failure that matters.
Show full SKILL.md (759 more words)Show less
3. Cascade agent (behind a chimera review)

When verified chimera findings meet the cascadeOn threshold (high or critical; default high), the runtime spawns bug-hunter for findings at or above that severity. You receive the review report and the changed files; you investigate each finding and apply fixes. Results go directly to the session transcript. NEVER send mailbox messages to the leader. You take part in the re-review loop, up to maxCascadeDepth cycles.

  • Minimal diff. Fix the flagged defect and nothing else.
  • Verify the line first. If the cited line doesn't say what the report claims, report the discrepancy instead of editing something adjacent.
  • Don't fix what you can't check. If the fix needs a design decision or would change a public contract, leave it and say why.
  • List what you didn't fix and the reason.
4. Proof-driven round (Proof-Driven Bug Hunter, /bughunt)

One round = at most one proven, fixed, verified root cause. The round's own instructions are the protocol; this mode governs how the candidate is chosen. It overrides the out-of-scope list below: in this mode you do fix the bug and do write its regression test, and you never fan out, however large the target.

  1. Read prior round reports first. Collect their root-cause fingerprints (affected path + trigger + violated contract) and skip any candidate with the same root cause, even if it surfaces through a different symptom.
  2. Survey, then shortlist. Walk the target layer by layer with the pattern table, lifecycle and async paths first. Keep two or three confirmed candidates, not one guess.
  3. Rank by provability × impact. Prefer a reachable defect you can reproduce deterministically through the production path over a scarier one you can only argue for. A candidate whose proof would need mocking the very code under suspicion is not provable; drop it.
  4. Commit to one. Write down its trigger, expected behaviour and its basis, observed behaviour, and impact. Then prove it with debugging and testing before touching production code.
  5. If the proof won't go red, the candidate is unproven, not fixed. Move to the next shortlisted candidate within the round's budget, or end the round with no proven bug. Never edit production code to "see if it helps".
  6. Keep a coverage note: surfaces inspected, candidates rejected and why, and unresolved leads. An unsuccessful reproduction does not make a surface bug-free, and the report must not imply it does.

Finish with verify-before-done: the same proof green, the regression test in the normal suite, related checks, and an honest outcome label.


Anti-patterns

  • Reporting grep output as findings — every hit is read before it ships
  • Flagging test fixtures as leaked secrets — mock credentials belong there
  • Inflating severity to make the scan look productive
  • Proof-driven: fixing before the proof is red, or picking the most dramatic candidate over the most provable one
  • Proof-driven: re-reporting a prior round's root cause under a new symptom

Out of scope (scan modes)

  • Don't fix the bugs you find in the default scan. Apply fixes only when the user explicitly asks, in cascade mode, or in a proof-driven round.
  • Don't review code quality, design, or style. Quality and design are chimera's read-only lane; style is the linter's job. Multi-file restructuring is refactor-planner's.
  • Don't run dependency audits. Supply chain and lockfile scanning are security-scanner's lane.
  • Don't write tests in a scan. State the failing test that would catch the bug; test authoring is testing's lane outside proof-driven rounds.
  • Don't start a multi-agent fan-out on your own. For a target larger than roughly 10–15 files, report its size and let the leader dispatch.

Skills in scope

  • debugging — for the reproduction and root cause once a candidate is chosen
  • testing — for the proof and the durable regression test
  • verify-before-done — for the final evidence and report
  • code-review — for reviewing a specific change set
  • security-scanner — for hardcoded secrets and injection vectors
  • refactor-planner — for fixing findings across multiple files
  • typescript-strict — for TypeScript type safety rules
  • output-standards — for standardized <nextsteps> formatting
  • multi-agent — for fanning out scans across large targets (never in a proof-driven round)

Before returning

  • Every file:line opened and confirmed — none from grep output alone
  • Every finding states a triggering input, a consequence, and the basis for the expected behaviour
  • Excluded paths honoured; test-file findings labelled as such
  • Severities pass the reachability and blast-radius checks; nothing rounded up
  • Scan: summary counts match the findings; <nextsteps> mirrors them in order
  • Cascade: fixes are minimal, unfixed findings listed with reasons, no mailbox message sent
  • Proof-driven: one root cause, not a duplicate of a prior round; the choice, rejected candidates, and coverage gaps are in the report

© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in packages/core/skills/bug-hunter of WrongStack/WrongStack.

  • SKILL.md
  • SKILL.save.md

Open the folder on GitHubat commit 57f6018

Compare with similar skills

Bug Hunter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bug Hunter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bug Hunter this skillWrongStack/WrongStack370—~3.7kAutomated safety check: PassMIT
ast-grep Structural Searchcode-yeongyu/oh-my-openagent70k—~3.3kAutomated safety check: PassMIT
Gograph Go Repository Intelligenceozgurcd/gograph227—~4.8kAutomated safety check: NotesMIT
jscpd Duplicate Code Detectorkucherenko/jscpd6.4k—~4.5kAutomated safety check: PassMIT
Ripwire Graph Queryredhat-et/ripwire2.4k—~1.1kAutomated safety check: NotesApache-2.0
Refactorabilitymeain/dotfiles285—~2kAutomated safety check: PassMIT

Similar skills

  • ast-grep Structural Search

    code-yeongyu/oh-my-openagent

    Searches and rewrites code by syntax-tree shape across 25 languages with ast-grep, for codemods, structural queries and YAML lint rules, using a Python wrapper script.

    70k GitHub stars~3.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Gives an agent working in a Go codebase a structural view through a local MCP server: call graphs, blast-radius and impact analysis, and bounded first-call exploration.

    227 GitHub stars~4.8k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Finds duplicated code in 220+ languages with jscpd, reports exact, renamed and near-miss clones in a compact agent-friendly format and measures duplication.

    6.4k GitHub stars~4.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Ripwire Graph Query

    redhat-et/ripwire

    Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.

    2.4k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Refactorability

    meain/dotfiles

    Review code for refactorability — surface concrete, prioritized refactoring opportunities grounded in Martin Fowler's smell catalog and SOLID, augmented with static analysis tools (gocyclo…

    285 GitHub stars~2k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Verification loop for Quarkus projects: build, static analysis (Checkstyle, PMD, SpotBugs), tests with JaCoCo coverage, OWASP dependency and container security scans, GraalVM native compilation…

    275k GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed

More from WrongStack/WrongStack

All 38 skills in this repo
  • Design Craft

    WrongStack/WrongStack

    Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.

    370 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Design Critique

    WrongStack/WrongStack

    A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…

    370 GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Mailbox Bridge

    WrongStack/WrongStack

    A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…

    370 GitHub stars~3.9k tokensUpdated yesterday
    Auto-check passed
  • Multi Agent

    WrongStack/WrongStack

    A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.

    370 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Web Platform Baseline

    WrongStack/WrongStack

    Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…

    370 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Wrongstack Mailbox

    WrongStack/WrongStack

    A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…

    370 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed

Questions about Bug Hunter

What does Bug Hunter do?

A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…. Bug Hunter is an agent skill from WrongStack/WrongStack. Use this skill when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and verify one real defect.

When should I use Bug Hunter?

Bug Hunter fits situations like: scanning source code for bugs; quality issues in a codebase; running a proof-driven bug hunt that must find; verify one real defect.

How do I install Bug Hunter in Claude Code?

Run `npx skills add WrongStack/WrongStack --skill bug-hunter -a claude-code`. Or copy the skill folder (packages/core/skills/bug-hunter in WrongStack/WrongStack) into .claude/skills/bug-hunter in your project. Claude Code loads it when a task matches its description.

How do I install Bug Hunter in Codex?

Run `npx skills add WrongStack/WrongStack --skill bug-hunter -a codex`. Or copy the skill folder (packages/core/skills/bug-hunter in WrongStack/WrongStack) into .agents/skills/bug-hunter in your project. Codex loads it when a task matches its description.

Can I use Bug Hunter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill bug-hunter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bug-hunter, .gemini/skills/bug-hunter, .github/skills/bug-hunter and .opencode/skills/bug-hunter in your project.

What does Bug Hunter need to run?

SKILL.md names no scripts, command-line tools or credentials: Bug Hunter is instructions for the agent only.

Does Bug Hunter access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bug Hunter safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bug Hunter use?

Bug Hunter is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bug Hunter use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bug Hunter?

Skills that share tags, products or a category with Bug Hunter: ast-grep Structural Search (code-yeongyu/oh-my-openagent, 70k stars), Gograph Go Repository Intelligence (ozgurcd/gograph, 227 stars), jscpd Duplicate Code Detector (kucherenko/jscpd, 6.4k stars) and Ripwire Graph Query (redhat-et/ripwire, 2.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bug Hunter?

WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 370 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 7, 2026.

Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.