agentCLAWHUBUnverified

bug-review

Hunts bugs with evidence trails Skill: bug-review Owner: athola Summary: Hunts bugs with evidence trails Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:18:31.877Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:38:47.959Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:55:30.129Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:03:54.050Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:21:57.800Z | user Release v1.9.13 v1.9.12 | 2026-06-19

OpenClaw

Rank

62

Safety

84

Downloads

1.6k

Updated

Oct 10, 2026

Version

1.9.19

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.6K downloadsadoption · observed Oct 10, 2026
Latest release
1.9.19release · observed Aug 26, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-pensive-bug-review
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/snapshot"

Documentation

CLAWHUB

145,152 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: bug-review
description: Hunts bugs with evidence trails
version: 1.9.8
triggers:
  - bugs
  - defects
  - debugging
  - code-quality
  - fixes
  - verification
  - investigating unexpected behavior or before merging code with potential hidden defects
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/pensive", "emoji": "\ud83d\udd0d", "requires": {"config": ["night-market.pensive:shared", "night-market.imbue:proof-of-work", "night-market.imbue:diff-analysis/modules/risk-assessment-framework"]}}}
source: claude-night-market
source_plugin: pensive
---

> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.


## Table of Contents

- [Quick Start](#quick-start)
- [When to Use](#when-to-use)
- [Required TodoWrite Items](#required-todowrite-items)
- [Progressive Loading](#progressive-loading)
- [Workflow](#workflow)
- [Step 1: Detect Languages (`bug-review:language-detected`)](#step-1:-detect-languages-(bug-review:language-detected))
- [Step 2: Plan Reproduction (`bug-review:repro-plan`)](#step-2:-plan-reproduction-(bug-review:repro-plan))
- [Step 3: Document Defects (`bug-review:defects-documented`)](#step-3:-document-defects-(bug-review:defects-documented))
- [Step 4: Prepare Fixes (`bug-review:fixes-prepared`)](#step-4:-prepare-fixes-(bug-review:fixes-prepared))
- [Step 5: Verification Plan (`bug-review:verification-plan`)](#step-5:-verification-plan-(bug-review:verification-plan))
- [Defect Classification (Condensed)](#defect-classification-(condensed))
- [Output Format](#output-format)
- [Summary](#summary)
- [Defects Found](#defects-found)
- [[D1] file.rs:142 - Title](#[d1]-filers:142---title)
- [Proposed Fixes](#proposed-fixes)
- [Fix for D1](#fix-for-d1)
- [Test Updates](#test-updates)
- [Evidence](#evidence)
- [Best Practices](#best-practices)
- [Exit Criteria](#exit-criteria)


# Bug Review Workflow

Systematic bug identification and fixing with language-specific expertise.

## Quick Start

```bash
/bug-review
```
**Verification:** Run the command with `--help` flag to verify availability.

## When To Use

- Reviewing code for potential bugs
- After receiving bug reports
- Before major releases
- During security audits
- Investigating production issues

## When NOT To Use

- Test coverage audit - use test-review instead

## Required TodoWrite Items

1. `bug-review:language-detected`
2. `bug-review:repro-plan`
3. `bug-review:defects-documented`
4. `bug-review:fixes-prepared`
5. `bug-review:verification-plan`

## Progressive Loading

Load additional context as needed:
- **Language Detection**: `@include modules/language-detection.md` - Manifest heuristics, expertise framing, version constraints
- **Defect Documentation**: `@include modules/defect-documentation.md` - Severity classification, root cause analy

_meta.json

{
  "ownerId": "kn7d107jg9jv602h9ytsegydq184a42s",
  "slug": "nm-pensive-bug-review",
  "version": "1.9.19",
  "publishedAt": 1787750311877
}

modules/defect-documentation.md

---
parent_skill: pensive:bug-review
category: analysis
estimated_tokens: 400
progressive_loading: true
dependencies: [imbue:proof-of-work]
---

# Defect Documentation

Systematic defect identification with precise file references and severity classification.

## File/Line References

Every defect must include:
- **File path**: Absolute or relative from project root
- **Line number**: Exact location of issue
- **Function/method**: Containing scope
- **Code snippet**: 3-5 lines of context

Example:
```
src/parser/tokenizer.rs:142 in `parse_string()`
```

## Severity Classification

| Level | Description | Impact | Response Time |
|-------|-------------|--------|---------------|
| **Critical** | Crash, data loss, security vulnerability | Service down, data corruption | Immediate |
| **High** | Major functionality broken | Core features unusable | This sprint |
| **Medium** | Degraded experience, workaround exists | Reduced performance/UX | Next sprint |
| **Low** | Minor issues, edge cases | Rare scenarios affected | Backlog |

## Root Cause Categories

### Logic Errors
- Incorrect conditions (off-by-one, wrong operator)
- Null/None handling gaps
- Missing validation
- Boundary condition failures

### API Misuse
- Wrong parameter types/order
- Deprecated method usage
- Incorrect error handling
- Lifetime/ownership violations (Rust)

### Concurrency Issues
- Race conditions
- Deadlocks
- Data races
- Improper synchronization
- Channel misuse (Go)

### Resource Leaks
- Memory leaks
- File handle leaks
- Connection pool exhaustion
- Lock not released

### Validation Gaps
- Missing input validation
- Insufficient boundary checks
- Type coercion errors
- Injection vulnerabilities

## Static Analyzer Commands

Run language-specific linters:

**Rust**
```bash
cargo clippy --all-targets --all-features
```

**Python**
```bash
ruff check .
mypy src/
```

**Go**
```bash
golangci-lint run
staticcheck ./...
```

**JavaScript/TypeScript**
```bash
eslint .
tsc --noEmit
```

**Java**
```bash
./gradlew check
spotbugs
```

## Documentation Format

```markdown
### [D1] file.rs:142 - Null pointer dereference

- **Severity**: Critical
- **Root Cause**: Logic error - missing null check
- **Impact**: Crash on malformed input
- **Evidence**: Line 142 dereferences `config.value` without validation
- **Context**:
  ```rust
  let value = config.value.unwrap(); // PANIC if None
  ```
```

## Cross-References

When relevant, link to:
- CVE databases for security issues
- Language RFCs or proposals
- Standard library documentation
- Known issue trackers

modules/fix-preparation.md

---
parent_skill: pensive:bug-review
category: remediation
estimated_tokens: 450
progressive_loading: true
---

# Fix Preparation

Create minimal, idiomatic patches with detailed test coverage.

## Minimal Patch Patterns

Apply smallest change that fixes the issue:

**Guard Clause** (prevent invalid state)
```rust
// Before: crash on None
let value = config.value.unwrap();

// After: guard clause
let Some(value) = config.value else {
    return Err(Error::MissingConfig);
};
```

**Validation** (check inputs)
```python
# Before: no validation
def process(count: int):
    return items[:count]

# After: boundary check
def process(count: int):
    if count < 0 or count > len(items):
        raise ValueError(f"Invalid count: {count}")
    return items[:count]
```

**Resource Cleanup** (prevent leaks)
```go
// Before: file handle leak
file, err := os.Open(path)
data, _ := io.ReadAll(file)

// After: defer cleanup
file, err := os.Open(path)
if err != nil {
    return err
}
defer file.Close()
data, err := io.ReadAll(file)
```

## Idiomatic Fixes by Language

### Rust
- Use `?` operator for error propagation
- Prefer pattern matching over `unwrap()`
- Use `Option::ok_or()` for conversions
- Apply ownership transfer instead of cloning

```rust
// Idiomatic error handling
fn load_config() -> Result<Config, Error> {
    let path = env::var("CONFIG_PATH")
        .map_err(|_| Error::MissingEnv)?;
    let contents = fs::read_to_string(&path)?;
    toml::from_str(&contents)
        .map_err(Error::Parse)
}
```

### Python
- Use context managers for resources
- Apply type hints for clarity
- Use specific exception types
- Prefer `pathlib` over string paths

```python
# Idiomatic resource handling
from pathlib import Path
from contextlib import contextmanager

def load_config(path: Path) -> dict:
    if not path.exists():
        raise FileNotFoundError(f"Config not found: {path}")
    with path.open() as f:
        return json.load(f)
```

### Go
- Check errors immediately
- Use `defer` for cleanup
- Apply early returns
- Wrap errors with context

```go
// Idiomatic error handling
func LoadConfig(path string) (*Config, error) {
    data, err := os.ReadFile(path)
    if err != nil {
        return nil, fmt.Errorf("reading config: %w", err)
    }

    var cfg Config
    if err := json.Unmarshal(data, &cfg); err != nil {
        return nil, fmt.Errorf("parsing config: %w", err)
    }

    return &cfg, nil
}
```

### TypeScript
- Use strict null checks
- Apply discriminated unions
- Prefer async/await over promises
- Use type guards for narrowing

```typescript
// Idiomatic null handling
function processValue(value: string | null): Result {
    if (value === null) {
        throw new Error("Value required");
    }
    // TypeScript knows value is string here
    return { data: value.toLowerCase() };
}
```

## Test Coverage Requirements

Every fix must include tests following Red → Green pattern:

### 1. Red: Write Failing Test
```rust
#[test]
fn test_config_missing_

modules/language-detection.md

---
parent_skill: pensive:bug-review
category: detection
estimated_tokens: 250
progressive_loading: true
---

# Language Detection and Expertise Framing

Identify project languages and establish appropriate expertise context.

## Manifest Heuristics

Use manifest files to detect primary languages:

| Manifest | Language | Ecosystem |
|----------|----------|-----------|
| `Cargo.toml` | Rust | cargo |
| `package.json` | JavaScript/TypeScript | npm/yarn/pnpm |
| `go.mod` | Go | go modules |
| `pyproject.toml`, `setup.py` | Python | pip/poetry/uv |
| `pom.xml`, `build.gradle` | Java | maven/gradle |
| `*.csproj` | C# | dotnet |

## Version Constraints

Extract and note version requirements:

**Rust**: Check MSRV (Minimum Supported Rust Version)
```toml
[package]
rust-version = "1.70.0"
```

**Python**: Check required version
```toml
[project]
requires-python = ">=3.8"
```

**Node**: Check engine constraints
```json
"engines": {
  "node": ">=18.0.0"
}
```

**Go**: Check minimum version
```go
go 1.21
```

## Expertise Persona

Frame appropriate expertise based on detected languages:

**Rust**: "Staff engineer specializing in Rust systems programming with expertise in ownership, lifetimes, and async runtimes"

**Python**: "Senior Python developer with expertise in type systems, async patterns, and performance optimization"

**Go**: "Go engineer with deep understanding of concurrency, channels, and idiomatic error handling"

**TypeScript**: "TypeScript expert focused on type safety, React patterns, and async workflows"

State this persona explicitly to establish review context and credibility.
Github ReposUpdated 15h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/athola/skills/nm-pensive-bug-review",
      "sourceUrl": "https://clawhub.ai/athola/skills/nm-pensive-bug-review",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T05:44:08.578Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T05:44:08.578Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.6K downloads",
      "href": "https://clawhub.ai/athola/nm-pensive-bug-review",
      "sourceUrl": "https://clawhub.ai/athola/nm-pensive-bug-review",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T05:44:08.578Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.9.19",
      "href": "https://clawhub.ai/athola/nm-pensive-bug-review",
      "sourceUrl": "https://clawhub.ai/athola/nm-pensive-bug-review",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-26T13:18:31.877Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.9.19",
      "description": "Release v1.9.19",
      "href": "https://clawhub.ai/athola/nm-pensive-bug-review",
      "sourceUrl": "https://clawhub.ai/athola/nm-pensive-bug-review",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-26T13:18:31.877Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to bug-review and adjacent AI workflows.