bug-review
Hunts bugs with evidence trails Skill: bug-review Owner: athola Summary: Hunts bugs with evidence trails Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:18:31.877Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:38:47.959Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:55:30.129Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:03:54.050Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:21:57.800Z | user Release v1.9.13 v1.9.12 | 2026-06-19
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
1.9.19
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.9.19release · observed Aug 26, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-pensive-bug-review- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/snapshot"
Documentation
CLAWHUB
145,152 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: bug-review
description: Hunts bugs with evidence trails
version: 1.9.8
triggers:
- bugs
- defects
- debugging
- code-quality
- fixes
- verification
- investigating unexpected behavior or before merging code with potential hidden defects
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/pensive", "emoji": "\ud83d\udd0d", "requires": {"config": ["night-market.pensive:shared", "night-market.imbue:proof-of-work", "night-market.imbue:diff-analysis/modules/risk-assessment-framework"]}}}
source: claude-night-market
source_plugin: pensive
---
> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.
## Table of Contents
- [Quick Start](#quick-start)
- [When to Use](#when-to-use)
- [Required TodoWrite Items](#required-todowrite-items)
- [Progressive Loading](#progressive-loading)
- [Workflow](#workflow)
- [Step 1: Detect Languages (`bug-review:language-detected`)](#step-1:-detect-languages-(bug-review:language-detected))
- [Step 2: Plan Reproduction (`bug-review:repro-plan`)](#step-2:-plan-reproduction-(bug-review:repro-plan))
- [Step 3: Document Defects (`bug-review:defects-documented`)](#step-3:-document-defects-(bug-review:defects-documented))
- [Step 4: Prepare Fixes (`bug-review:fixes-prepared`)](#step-4:-prepare-fixes-(bug-review:fixes-prepared))
- [Step 5: Verification Plan (`bug-review:verification-plan`)](#step-5:-verification-plan-(bug-review:verification-plan))
- [Defect Classification (Condensed)](#defect-classification-(condensed))
- [Output Format](#output-format)
- [Summary](#summary)
- [Defects Found](#defects-found)
- [[D1] file.rs:142 - Title](#[d1]-filers:142---title)
- [Proposed Fixes](#proposed-fixes)
- [Fix for D1](#fix-for-d1)
- [Test Updates](#test-updates)
- [Evidence](#evidence)
- [Best Practices](#best-practices)
- [Exit Criteria](#exit-criteria)
# Bug Review Workflow
Systematic bug identification and fixing with language-specific expertise.
## Quick Start
```bash
/bug-review
```
**Verification:** Run the command with `--help` flag to verify availability.
## When To Use
- Reviewing code for potential bugs
- After receiving bug reports
- Before major releases
- During security audits
- Investigating production issues
## When NOT To Use
- Test coverage audit - use test-review instead
## Required TodoWrite Items
1. `bug-review:language-detected`
2. `bug-review:repro-plan`
3. `bug-review:defects-documented`
4. `bug-review:fixes-prepared`
5. `bug-review:verification-plan`
## Progressive Loading
Load additional context as needed:
- **Language Detection**: `@include modules/language-detection.md` - Manifest heuristics, expertise framing, version constraints
- **Defect Documentation**: `@include modules/defect-documentation.md` - Severity classification, root cause analy_meta.json
{
"ownerId": "kn7d107jg9jv602h9ytsegydq184a42s",
"slug": "nm-pensive-bug-review",
"version": "1.9.19",
"publishedAt": 1787750311877
}modules/defect-documentation.md
--- parent_skill: pensive:bug-review category: analysis estimated_tokens: 400 progressive_loading: true dependencies: [imbue:proof-of-work] --- # Defect Documentation Systematic defect identification with precise file references and severity classification. ## File/Line References Every defect must include: - **File path**: Absolute or relative from project root - **Line number**: Exact location of issue - **Function/method**: Containing scope - **Code snippet**: 3-5 lines of context Example: ``` src/parser/tokenizer.rs:142 in `parse_string()` ``` ## Severity Classification | Level | Description | Impact | Response Time | |-------|-------------|--------|---------------| | **Critical** | Crash, data loss, security vulnerability | Service down, data corruption | Immediate | | **High** | Major functionality broken | Core features unusable | This sprint | | **Medium** | Degraded experience, workaround exists | Reduced performance/UX | Next sprint | | **Low** | Minor issues, edge cases | Rare scenarios affected | Backlog | ## Root Cause Categories ### Logic Errors - Incorrect conditions (off-by-one, wrong operator) - Null/None handling gaps - Missing validation - Boundary condition failures ### API Misuse - Wrong parameter types/order - Deprecated method usage - Incorrect error handling - Lifetime/ownership violations (Rust) ### Concurrency Issues - Race conditions - Deadlocks - Data races - Improper synchronization - Channel misuse (Go) ### Resource Leaks - Memory leaks - File handle leaks - Connection pool exhaustion - Lock not released ### Validation Gaps - Missing input validation - Insufficient boundary checks - Type coercion errors - Injection vulnerabilities ## Static Analyzer Commands Run language-specific linters: **Rust** ```bash cargo clippy --all-targets --all-features ``` **Python** ```bash ruff check . mypy src/ ``` **Go** ```bash golangci-lint run staticcheck ./... ``` **JavaScript/TypeScript** ```bash eslint . tsc --noEmit ``` **Java** ```bash ./gradlew check spotbugs ``` ## Documentation Format ```markdown ### [D1] file.rs:142 - Null pointer dereference - **Severity**: Critical - **Root Cause**: Logic error - missing null check - **Impact**: Crash on malformed input - **Evidence**: Line 142 dereferences `config.value` without validation - **Context**: ```rust let value = config.value.unwrap(); // PANIC if None ``` ``` ## Cross-References When relevant, link to: - CVE databases for security issues - Language RFCs or proposals - Standard library documentation - Known issue trackers
modules/fix-preparation.md
---
parent_skill: pensive:bug-review
category: remediation
estimated_tokens: 450
progressive_loading: true
---
# Fix Preparation
Create minimal, idiomatic patches with detailed test coverage.
## Minimal Patch Patterns
Apply smallest change that fixes the issue:
**Guard Clause** (prevent invalid state)
```rust
// Before: crash on None
let value = config.value.unwrap();
// After: guard clause
let Some(value) = config.value else {
return Err(Error::MissingConfig);
};
```
**Validation** (check inputs)
```python
# Before: no validation
def process(count: int):
return items[:count]
# After: boundary check
def process(count: int):
if count < 0 or count > len(items):
raise ValueError(f"Invalid count: {count}")
return items[:count]
```
**Resource Cleanup** (prevent leaks)
```go
// Before: file handle leak
file, err := os.Open(path)
data, _ := io.ReadAll(file)
// After: defer cleanup
file, err := os.Open(path)
if err != nil {
return err
}
defer file.Close()
data, err := io.ReadAll(file)
```
## Idiomatic Fixes by Language
### Rust
- Use `?` operator for error propagation
- Prefer pattern matching over `unwrap()`
- Use `Option::ok_or()` for conversions
- Apply ownership transfer instead of cloning
```rust
// Idiomatic error handling
fn load_config() -> Result<Config, Error> {
let path = env::var("CONFIG_PATH")
.map_err(|_| Error::MissingEnv)?;
let contents = fs::read_to_string(&path)?;
toml::from_str(&contents)
.map_err(Error::Parse)
}
```
### Python
- Use context managers for resources
- Apply type hints for clarity
- Use specific exception types
- Prefer `pathlib` over string paths
```python
# Idiomatic resource handling
from pathlib import Path
from contextlib import contextmanager
def load_config(path: Path) -> dict:
if not path.exists():
raise FileNotFoundError(f"Config not found: {path}")
with path.open() as f:
return json.load(f)
```
### Go
- Check errors immediately
- Use `defer` for cleanup
- Apply early returns
- Wrap errors with context
```go
// Idiomatic error handling
func LoadConfig(path string) (*Config, error) {
data, err := os.ReadFile(path)
if err != nil {
return nil, fmt.Errorf("reading config: %w", err)
}
var cfg Config
if err := json.Unmarshal(data, &cfg); err != nil {
return nil, fmt.Errorf("parsing config: %w", err)
}
return &cfg, nil
}
```
### TypeScript
- Use strict null checks
- Apply discriminated unions
- Prefer async/await over promises
- Use type guards for narrowing
```typescript
// Idiomatic null handling
function processValue(value: string | null): Result {
if (value === null) {
throw new Error("Value required");
}
// TypeScript knows value is string here
return { data: value.toLowerCase() };
}
```
## Test Coverage Requirements
Every fix must include tests following Red → Green pattern:
### 1. Red: Write Failing Test
```rust
#[test]
fn test_config_missing_modules/language-detection.md
---
parent_skill: pensive:bug-review
category: detection
estimated_tokens: 250
progressive_loading: true
---
# Language Detection and Expertise Framing
Identify project languages and establish appropriate expertise context.
## Manifest Heuristics
Use manifest files to detect primary languages:
| Manifest | Language | Ecosystem |
|----------|----------|-----------|
| `Cargo.toml` | Rust | cargo |
| `package.json` | JavaScript/TypeScript | npm/yarn/pnpm |
| `go.mod` | Go | go modules |
| `pyproject.toml`, `setup.py` | Python | pip/poetry/uv |
| `pom.xml`, `build.gradle` | Java | maven/gradle |
| `*.csproj` | C# | dotnet |
## Version Constraints
Extract and note version requirements:
**Rust**: Check MSRV (Minimum Supported Rust Version)
```toml
[package]
rust-version = "1.70.0"
```
**Python**: Check required version
```toml
[project]
requires-python = ">=3.8"
```
**Node**: Check engine constraints
```json
"engines": {
"node": ">=18.0.0"
}
```
**Go**: Check minimum version
```go
go 1.21
```
## Expertise Persona
Frame appropriate expertise based on detected languages:
**Rust**: "Staff engineer specializing in Rust systems programming with expertise in ownership, lifetimes, and async runtimes"
**Python**: "Senior Python developer with expertise in type systems, async patterns, and performance optimization"
**Go**: "Go engineer with deep understanding of concurrency, channels, and idiomatic error handling"
**TypeScript**: "TypeScript expert focused on type safety, React patterns, and async workflows"
State this persona explicitly to establish review context and credibility.AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/athola/skills/nm-pensive-bug-review",
"sourceUrl": "https://clawhub.ai/athola/skills/nm-pensive-bug-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T05:44:08.578Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T05:44:08.578Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/athola/nm-pensive-bug-review",
"sourceUrl": "https://clawhub.ai/athola/nm-pensive-bug-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T05:44:08.578Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.9.19",
"href": "https://clawhub.ai/athola/nm-pensive-bug-review",
"sourceUrl": "https://clawhub.ai/athola/nm-pensive-bug-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:18:31.877Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.9.19",
"description": "Release v1.9.19",
"href": "https://clawhub.ai/athola/nm-pensive-bug-review",
"sourceUrl": "https://clawhub.ai/athola/nm-pensive-bug-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:18:31.877Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
