ia-debugging
Systematic root-cause debugging with verification. Use for errors, stack traces, broken tests, flaky tests, regressions, or anything not working as expected. For validating bug reports before fixing, use bug-reproduction-validator agent. Skill: ia-debugging Owner: iliaal Summary: Systematic root-cause debugging with verification. Use for errors, stack traces, broken tests, flaky tests, regressions, or anything not working as expected. For validating bug reports before fixing, use bug-reproduction-validator agent. Tags: latest:5.0.1 Version history: v5.0.1 | 2026-10-03T17:05:52.023Z | user v5.0.1 v5.0.0 | 2026-09-26T23:09:34.228Z | user v5.0.0 v4.5.2
Rank
62
Safety
84
Downloads
2.1k
Updated
Oct 9, 2026
Version
5.0.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.1K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.1K downloadsadoption · observed Oct 9, 2026
- Latest release
- 5.0.1release · observed Oct 3, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17bcar8wq0xhegs0ny6f57ypd8484bw:compound-eng-debugging- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-iliaal-compound-eng-debugging/snapshot"
Documentation
CLAWHUB
146,458 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: ia-debugging class: discipline description: >- Systematic root-cause debugging with verification. Use for errors, stack traces, broken tests, flaky tests, regressions, or anything not working as expected. For validating bug reports before fixing, use bug-reproduction-validator agent. --- # Debugging Ground permanent repairs in an evidence-backed causal explanation. A hypothesis may justify a bounded reversible experiment; label it as experimental until verified. During an active incident, an authorized rollback or feature disable may restore service before root cause is known. Record remaining uncertainty and keep the repair investigation open: mitigation is not proof of repair. ## Scope and modes For diagnosis-only requests, inspect source/artifacts and run safe read-only checks within caller authority; do not repair or violate a no-build constraint. Diagnosis may finish with an evidenced cause while its proposed repair remains unverified. Use `NEEDS_CONTEXT` only for information blocking the requested work. Keep edits within the hypothesis's narrow file scope; revise the hypothesis before expanding it. Preserve other work. Before sharing diagnostics or searching externally, remove credentials, customer data, hostnames, IPs, paths, and SQL fragments as appropriate; use environment-sourced credentials rather than embedding secrets. Read [baseline-and-data-handling.md](./references/baseline-and-data-handling.md) for branch/build comparisons or diagnostic data sharing. ## Process 1. **Read and reproduce.** Read the full error and totals, not just filtered matches. Confirm HEAD after session resumption before trusting carried file content. Run a provided reproducer before editing. Match the reported symptom exactly; a nearby failure is not the same reproduction. Use the cheapest actual trigger. For intermittent bugs, bound attempts and report conditions/frequency; a finite clean run does not disprove a race. Read [reproduction-and-investigation.md](./references/reproduction-and-investigation.md) when constructing, reducing, or instrumenting a reproducer. 2. **Ground hypotheses.** Form two to three candidates, each citing an observation. A trivial verified typo needs only a short causal check; an import error alone does not identify why import failed. Reduce irrelevant inputs while retaining the actual trigger. If no loop is available, report missing access, artifacts, credentials, or steps, and continue independent source investigation without claiming reproduction. 3. **Trace and discriminate.** Explain the violated invariant and triggering conditions, without imposing a fixed stack depth. Compare code, inputs, state, timing, environment, and build configuration. Identical source that passes another build can still contain undefined behavior or races. Use [root-cause-tracing.md](./references/root-cause-tracing.md) for backward tracing/test pollution and [collect-diagnostics.sh](./scripts/collect-diagnostics.sh) for relevant
_meta.json
{
"ownerId": "kn715jrbbh71q9zncr0bqdkr8n848q1a",
"slug": "compound-eng-debugging",
"version": "5.0.1",
"publishedAt": 1791047152023
}references/baseline-and-data-handling.md
# Baselines and diagnostic data Read when comparing branches or builds, using external searches, or sharing diagnostic artifacts. Preserve the working tree and redact secrets regardless of mode. **Pre-existing failure proof:** run the same check against an explicit base SHA in an isolated worktree or scratch checkout with comparable dependencies and build state. Stashing removes local edits but does not switch a committed feature branch to its base. Compare failure names, assertions, and relevant output, not just exit status; matching failures can still have different causes. Preserve the user's working tree and any concurrent agent's state. **A cross-branch A/B needs a pristine baseline.** `git checkout <baseline>` does not discard a dirty working-tree edit that merges cleanly; it carries it into the checked-out tree, so the "before" build silently contains the fix and the experiment runs patched-vs-patched. The tell is *before == after* to the byte when a delta was expected. Commit the fix on its branch first, then run `git status --porcelain` after the baseline checkout and before the baseline build; non-empty output means the comparison is already poisoned. When restoring a single file, name the source (`git checkout HEAD -- <file>` for the commit, `git checkout <base> -- <file>` for the baseline), because the bare `git checkout -- <file>` restores from the *index*, which may hold neither. Assert the expected diff before rebuilding. **Before external searches** (web, docs, forums): strip hostnames, IPs, file paths, SQL fragments, and customer data from the query. Raw stack traces leak privacy and return noise. **Redaction also applies to what gets shown back, not just what goes out.** This skill has the agent paste commands, probe output, and captured artifacts into the conversation, and those carry credentials: `Authorization` headers in a captured request, connection strings in a repro command, tokens in an environment dump. Replace each with `<REDACTED>` before it appears. Better, remove the need: build the reproduction loop so every credential is read from the environment (`$API_TOKEN`, `$DATABASE_URL`) rather than typed into the command, which keeps the value out of the transcript entirely, and quote only the lines of a captured artifact that carry signal. If redacting leaves too little to diagnose from, say so and ask for what is missing rather than pasting it raw.
references/competing-hypotheses.md
# Analysis of Competing Hypotheses (ACH) When the root cause is unclear, especially across multiple components, systematic hypothesis analysis prevents premature commitment to an incorrect explanation. ## When to Use - Multiple plausible explanations for a failure - Bug spans component boundaries (API -> service -> DB) - Three-Fix Threshold reached (3 failed attempts) - Intermittent failures with no clear reproduction pattern ## Six Failure Categories Generate hypotheses across these categories. Most bugs start as one category but have root causes in another. | Category | Symptoms | Example | |----------|----------|---------| | **Logic error** | Wrong output for valid input, off-by-one, incorrect branching | `<=` vs `<` in loop boundary | | **Data issue** | Unexpected null, wrong type, stale cache, encoding mismatch | JSON field renamed upstream, cached value from previous schema | | **State problem** | Race condition, leaked global state, order-dependent initialization | Test passes alone, fails in suite due to shared DB state | | **Integration failure** | Contract mismatch at boundary, wrong endpoint, auth expired | Service A sends `user_id`, service B expects `userId` | | **Resource exhaustion** | Timeout, OOM, connection pool depleted, disk full | DB pool max hit under load, queries queue indefinitely | | **Environment** | Config drift, wrong version, missing dependency, OS difference | Works on macOS, fails on Linux due to case-sensitive filesystem | ## Evidence Strength Scale Not all evidence is equal. Rank each piece: | Strength | Type | Example | |----------|------|---------| | **Strong** | Direct observation | Stack trace pointing to exact line, failing test output | | **Medium** | Correlational | Bug appeared after deploy X, timing correlates with load spike | | **Weak** | Testimonial | "I think I saw this before when..." (no logs or reproduction) | | **Variable** | Absence of evidence | "This component has no errors in its logs" (absence != proof) | ## The ACH Process ### 1. List hypotheses For each failure category, generate at least one hypothesis. Be specific: "data issue" is not a hypothesis; "the `user.email` field is null because the upstream API changed its response format" is. ### 2. Collect evidence For each hypothesis, gather evidence FOR and AGAINST: ``` H1: Race condition in session initialization FOR: Intermittent (strong), only under concurrent requests (medium) AGAINST: Single-threaded test also fails (strong) → WEAKENED by counter-evidence H2: Stale config cached after deploy FOR: Timestamp of first failure matches deploy (medium), restart fixes it (strong) AGAINST: None found → STRONGEST candidate ``` ### 3. Compare evidential support | Support | Meaning | Action | |------------|---------|--------| | **Strong** | Concrete causal path, competing explanations checked | Test the smallest supported remedy | | **Mixed** | Consequential premises unresolved | Choose a discriminating probe | | *
references/defense-in-depth.md
# Defense-in-Depth Validation
After verifying a fix for invalid data, inspect whether the invalid state can still be constructed through another reachable path. Prefer an existing validated type, constructor, or shared helper when the affected callers can use it within the repair's scope.
**Core principle:** Prevent invalid construction where possible. Add checks at boundaries that catch distinct failure classes or remain reachable without earlier validation.
## Why Multiple Layers
Use multiple layers when the layers enforce different requirements:
- Entry validation catches most invalid input
- Business logic catches domain-specific edge cases
- Environment guards prevent context-specific dangers (e.g., destructive operations in test)
- Debug instrumentation captures forensic context when checks fail; logging does not enforce an invariant
## Possible Layers
Select the layers required by the observed data flow. Repeating the same check at every function adds maintenance cost without preventing a new failure path.
### Layer 1: Entry Point Validation
Reject obviously invalid input at the API/function boundary. This is the first line of defense.
```php
function createProject(string $name, string $workingDirectory): Project
{
if (empty($workingDirectory)) {
throw new \InvalidArgumentException('workingDirectory cannot be empty');
}
if (!is_dir($workingDirectory)) {
throw new \InvalidArgumentException("workingDirectory does not exist: {$workingDirectory}");
}
// ... proceed
}
```
### Layer 2: Business Logic Validation
Ensure data makes sense for this specific operation, even if it passed entry validation.
```php
function initializeWorkspace(string $projectDir, string $sessionId): void
{
if ($sessionId === '') {
throw new \RuntimeException('sessionId required for workspace initialization');
}
// ... proceed
}
```
### Layer 3: Environment Guards
Prevent dangerous operations in specific contexts (test, staging, CI).
```python
import os
import tempfile
async def git_init(directory: str) -> None:
if os.environ.get("NODE_ENV") == "test":
normalized = os.path.realpath(directory)
tmp_dir = os.path.realpath(tempfile.gettempdir())
if normalized == tmp_dir or os.path.commonpath([normalized, tmp_dir]) != tmp_dir:
raise RuntimeError(
f"Refusing git init outside temp dir during tests: {directory}"
)
# ... proceed
```
Resolve symlinks before comparing path components; a string prefix also accepts sibling paths such as `/tmp-other`. Restrict the operation to a child of the temporary root, not the root itself. This check assumes the test owns the directory and no concurrent actor can replace its path components; use an isolated workspace or descriptor-relative operations when that assumption does not hold.
### Layer 4: Debug Instrumentation
Capture context for forensics when the other layers fail.
```typescript
async functAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/iliaal/skills/compound-eng-debugging",
"sourceUrl": "https://clawhub.ai/iliaal/skills/compound-eng-debugging",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T18:20:07.967Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-iliaal-compound-eng-debugging/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-iliaal-compound-eng-debugging/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T18:20:07.967Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.1K downloads",
"href": "https://clawhub.ai/iliaal/compound-eng-debugging",
"sourceUrl": "https://clawhub.ai/iliaal/compound-eng-debugging",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T18:20:07.967Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "5.0.1",
"href": "https://clawhub.ai/iliaal/compound-eng-debugging",
"sourceUrl": "https://clawhub.ai/iliaal/compound-eng-debugging",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-03T17:05:52.023Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-iliaal-compound-eng-debugging/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-iliaal-compound-eng-debugging/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 5.0.1",
"description": "v5.0.1",
"href": "https://clawhub.ai/iliaal/compound-eng-debugging",
"sourceUrl": "https://clawhub.ai/iliaal/compound-eng-debugging",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-03T17:05:52.023Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
