{"id":"52356c87-6eee-444a-b680-5ba9ec073854","entityType":"agent","slug":"clawhub-athola-nm-pensive-bug-review","name":"bug-review","canonicalUrl":"https://www.xpersona.co/agent/clawhub-athola-nm-pensive-bug-review","canonicalPath":"/agent/clawhub-athola-nm-pensive-bug-review","generatedAt":"2026-10-10T10:48:42.041Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T05:44:08.578Z","emptyReason":null},"description":"Hunts bugs with evidence trails Skill: bug-review Owner: athola Summary: Hunts bugs with evidence trails Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:18:31.877Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:38:47.959Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:55:30.129Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:03:54.050Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:21:57.800Z | user Release v1.9.13 v1.9.12 | 2026-06-19","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-pensive-bug-review","sourceUrl":"https://clawhub.ai/athola/nm-pensive-bug-review","homepage":"https://clawhub.ai/athola/skills/nm-pensive-bug-review","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/athola/nm-pensive-bug-review","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/athola/skills/nm-pensive-bug-review","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":64,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Hunts bugs with evidence trails Skill: bug-review Owner: athola Summary: Hunts bugs with evidence trails Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:44:08.578Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:44:08.578Z","emptyReason":null},"stars":null,"forks":null,"downloads":1643,"packageName":null,"latestVersion":"1.9.19","tractionLabel":"1.6K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:44:08.578Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T05:44:08.578Z","lastCrawledAt":"2026-10-10T05:44:08.578Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T05:44:08.578Z","lastVerifiedAt":null,"highlights":[{"version":"1.9.19","createdAt":"2026-08-26T13:18:31.877Z","changelog":"Release v1.9.19","fileCount":6,"zipByteSize":8791},{"version":"1.9.17","createdAt":"2026-07-30T05:38:47.959Z","changelog":"Release v1.9.17","fileCount":6,"zipByteSize":8948},{"version":"1.9.16","createdAt":"2026-07-14T19:55:30.129Z","changelog":"Release v1.9.16","fileCount":6,"zipByteSize":8843},{"version":"1.9.14","createdAt":"2026-06-30T18:03:54.050Z","changelog":"Release v1.9.14","fileCount":6,"zipByteSize":8985},{"version":"1.9.13","createdAt":"2026-06-27T16:21:57.800Z","changelog":"Release v1.9.13","fileCount":6,"zipByteSize":8917},{"version":"1.9.12","createdAt":"2026-06-19T03:17:01.048Z","changelog":"Release v1.9.12","fileCount":6,"zipByteSize":8943},{"version":"1.0.3","createdAt":"2026-06-18T14:11:52.870Z","changelog":"Release v1.9.12","fileCount":6,"zipByteSize":8873},{"version":"1.0.2","createdAt":"2026-05-09T02:19:11.339Z","changelog":"Release v1.9.5","fileCount":6,"zipByteSize":9043}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-pensive-bug-review","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T10:48:42.038Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-bug-review/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T05:44:08.578Z","emptyReason":null},"readme":"Skill: bug-review\n\nOwner: athola\n\nSummary: Hunts bugs with evidence trails\n\nTags: latest:1.9.19\n\nVersion history:\n\nv1.9.19 | 2026-08-26T13:18:31.877Z | user\n\nRelease v1.9.19\n\nv1.9.17 | 2026-07-30T05:38:47.959Z | user\n\nRelease v1.9.17\n\nv1.9.16 | 2026-07-14T19:55:30.129Z | user\n\nRelease v1.9.16\n\nv1.9.14 | 2026-06-30T18:03:54.050Z | user\n\nRelease v1.9.14\n\nv1.9.13 | 2026-06-27T16:21:57.800Z | user\n\nRelease v1.9.13\n\nv1.9.12 | 2026-06-19T03:17:01.048Z | user\n\nRelease v1.9.12\n\nv1.0.3 | 2026-06-18T14:11:52.870Z | user\n\nRelease v1.9.12\n\nv1.0.2 | 2026-05-09T02:19:11.339Z | user\n\nRelease v1.9.5\n\nv1.0.1 | 2026-05-06T14:20:23.727Z | user\n\nRelease v1.9.4\n\nv1.0.0 | 2026-04-15T14:01:44.456Z | auto\n\nInitial public release of the \"bug-review\" skill—systematic bug identification, documentation, and verification.\n\n- Guides users through a step-by-step bug review workflow (language detection, repro plan, defect logging, fixes, and verification).\n- Offers templates and best practices for evidence-based bug report and fix documentation.\n- Provides output formatting for summaries, defects, fixes, tests, and verification evidence.\n- Supports language-specific guidance and risk assessment via progressive documentation.\n\nArchive index:\n\nArchive v1.9.19: 6 files, 8791 bytes\n\nFiles: modules/defect-documentation.md (2568b), modules/fix-preparation.md (4190b), modules/language-detection.md (1614b), skill-card.md (1836b), SKILL.md (6590b), _meta.json (141b)\n\nFile v1.9.19:SKILL.md\n\n---\nname: bug-review\ndescription: Hunts bugs with evidence trails\nversion: 1.9.8\ntriggers:\n  - bugs\n  - defects\n  - debugging\n  - code-quality\n  - fixes\n  - verification\n  - investigating unexpected behavior or before merging code with potential hidden defects\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83d\\udd0d\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.imbue:proof-of-work\", \"night-market.imbue:diff-analysis/modules/risk-assessment-framework\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Quick Start](#quick-start)\n- [When to Use](#when-to-use)\n- [Required TodoWrite Items](#required-todowrite-items)\n- [Progressive Loading](#progressive-loading)\n- [Workflow](#workflow)\n- [Step 1: Detect Languages (`bug-review:language-detected`)](#step-1:-detect-languages-(bug-review:language-detected))\n- [Step 2: Plan Reproduction (`bug-review:repro-plan`)](#step-2:-plan-reproduction-(bug-review:repro-plan))\n- [Step 3: Document Defects (`bug-review:defects-documented`)](#step-3:-document-defects-(bug-review:defects-documented))\n- [Step 4: Prepare Fixes (`bug-review:fixes-prepared`)](#step-4:-prepare-fixes-(bug-review:fixes-prepared))\n- [Step 5: Verification Plan (`bug-review:verification-plan`)](#step-5:-verification-plan-(bug-review:verification-plan))\n- [Defect Classification (Condensed)](#defect-classification-(condensed))\n- [Output Format](#output-format)\n- [Summary](#summary)\n- [Defects Found](#defects-found)\n- [[D1] file.rs:142 - Title](#[d1]-filers:142---title)\n- [Proposed Fixes](#proposed-fixes)\n- [Fix for D1](#fix-for-d1)\n- [Test Updates](#test-updates)\n- [Evidence](#evidence)\n- [Best Practices](#best-practices)\n- [Exit Criteria](#exit-criteria)\n\n\n# Bug Review Workflow\n\nSystematic bug identification and fixing with language-specific expertise.\n\n## Quick Start\n\n```bash\n/bug-review\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## When To Use\n\n- Reviewing code for potential bugs\n- After receiving bug reports\n- Before major releases\n- During security audits\n- Investigating production issues\n\n## When NOT To Use\n\n- Test coverage audit - use test-review instead\n\n## Required TodoWrite Items\n\n1. `bug-review:language-detected`\n2. `bug-review:repro-plan`\n3. `bug-review:defects-documented`\n4. `bug-review:fixes-prepared`\n5. `bug-review:verification-plan`\n\n## Progressive Loading\n\nLoad additional context as needed:\n- **Language Detection**: `@include modules/language-detection.md` - Manifest heuristics, expertise framing, version constraints\n- **Defect Documentation**: `@include modules/defect-documentation.md` - Severity classification, root cause analysis, static analyzers\n- **Fix Preparation**: `@include modules/fix-preparation.md` - Minimal patches, idiomatic patterns, test coverage\n\n## Workflow\n\n### Step 1: Detect Languages (`bug-review:language-detected`)\n\nIdentify dominant languages using manifest files (Cargo.toml → Rust, package.json → Node, etc.).\n\nState expertise persona appropriate for the language ecosystem.\n\nNote version constraints (MSRV, Python versions, Node engines).\n\n**Progressive**: Load `modules/language-detection.md` for detailed manifest heuristics.\n\n### Step 2: Plan Reproduction (`bug-review:repro-plan`)\n\nIdentify reproduction methods:\n- Unit/integration test suites\n- Fuzzing tools\n- Manual reproduction commands\n\nDocument exact commands:\n```bash\ncargo test -p core\npytest tests/test_api.py\nnpm test -- pkg\n```\n**Verification:** Run `pytest -v tests/test_api.py` to verify.\n\nCapture blockers and propose mocks when dependencies unavailable.\n\n### Step 3: Document Defects (`bug-review:defects-documented`)\n\nReview code line-by-line, logging each bug with:\n- **File:line reference**: Precise location\n- **Severity**: Critical, High, Medium, Low\n- **Root cause**: Logic error, API misuse, concurrency, resource leak\n- **Impact**: What breaks and how\n\nRun static analyzers (`cargo clippy`, `ruff check`, `golangci-lint`, `eslint`).\n\nUse `imbue:proof-of-work` for reproducible capture.\n\n**Progressive**: Load `modules/defect-documentation.md` for classification details and analyzer commands.\n\n### Step 4: Prepare Fixes (`bug-review:fixes-prepared`)\n\nDraft minimal, idiomatic patches using language best practices:\n- Guard clauses (Rust: pattern matching, Python: early returns)\n- Resource cleanup (Go: defer, Python: context managers)\n- Error propagation (Rust: ?, Go: wrapped errors)\n\nCreate tests following Red → Green pattern:\n1. Write failing test\n2. Apply minimal fix\n3. Verify test passes\n\n**Progressive**: Load `modules/fix-preparation.md` for language-specific patterns and test strategies.\n\n### Step 5: Verification Plan (`bug-review:verification-plan`)\n\nExecute reproduction steps with fixes applied.\n\nCapture evidence:\n- Test output logs\n- Benchmark comparisons\n- Coverage reports\n\nDocument remaining risks using `imbue:diff-analysis/modules/risk-assessment-framework`.\n\nAssign owners and deadlines for follow-up items.\n\n## Defect Classification (Condensed)\n\n**Severity**: Critical (crash/data loss) → High (broken features) → Medium (degraded UX) → Low (edge cases)\n\n**Root Causes**: Logic errors | API misuse | Concurrency issues | Resource leaks | Validation gaps\n\n## Output Format\n\n```markdown\n## Summary\n[Brief scope description]\n\n## Defects Found\n### [D1] file.rs:142 - Title\n- Severity: High\n- Root Cause: Logic error\n- Impact: Data corruption possible\n- Fix: [description]\n\n## Proposed Fixes\n### Fix for D1\n[code diff with explanation]\n\n## Test Updates\n[new/updated tests with Red → Green verification]\n\n## Evidence\n- Commands executed\n- Logs and outputs\n- External references\n```\n**Verification:** Run `pytest -v` to verify tests pass.\n\n## Best Practices\n\n1. **Evidence-based**: Every finding has file:line reference\n2. **Reproducible**: Clear steps to reproduce each bug\n3. **Minimal fixes**: Smallest change that fixes the issue\n4. **Test coverage**: Every fix has corresponding test\n5. **Risk awareness**: Document remaining risks with severity scoring\n\n## Exit Criteria\n\n- All defects documented with precise references\n- Fixes prepared with test coverage verified\n- Verification plan includes commands and expected outputs\n- Remaining risks assessed and owners assigned\n\nFile v1.9.19:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-bug-review\",\n  \"version\": \"1.9.19\",\n  \"publishedAt\": 1787750311877\n}\n\nFile v1.9.19:modules/defect-documentation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: analysis\nestimated_tokens: 400\nprogressive_loading: true\ndependencies: [imbue:proof-of-work]\n---\n\n# Defect Documentation\n\nSystematic defect identification with precise file references and severity classification.\n\n## File/Line References\n\nEvery defect must include:\n- **File path**: Absolute or relative from project root\n- **Line number**: Exact location of issue\n- **Function/method**: Containing scope\n- **Code snippet**: 3-5 lines of context\n\nExample:\n```\nsrc/parser/tokenizer.rs:142 in `parse_string()`\n```\n\n## Severity Classification\n\n| Level | Description | Impact | Response Time |\n|-------|-------------|--------|---------------|\n| **Critical** | Crash, data loss, security vulnerability | Service down, data corruption | Immediate |\n| **High** | Major functionality broken | Core features unusable | This sprint |\n| **Medium** | Degraded experience, workaround exists | Reduced performance/UX | Next sprint |\n| **Low** | Minor issues, edge cases | Rare scenarios affected | Backlog |\n\n## Root Cause Categories\n\n### Logic Errors\n- Incorrect conditions (off-by-one, wrong operator)\n- Null/None handling gaps\n- Missing validation\n- Boundary condition failures\n\n### API Misuse\n- Wrong parameter types/order\n- Deprecated method usage\n- Incorrect error handling\n- Lifetime/ownership violations (Rust)\n\n### Concurrency Issues\n- Race conditions\n- Deadlocks\n- Data races\n- Improper synchronization\n- Channel misuse (Go)\n\n### Resource Leaks\n- Memory leaks\n- File handle leaks\n- Connection pool exhaustion\n- Lock not released\n\n### Validation Gaps\n- Missing input validation\n- Insufficient boundary checks\n- Type coercion errors\n- Injection vulnerabilities\n\n## Static Analyzer Commands\n\nRun language-specific linters:\n\n**Rust**\n```bash\ncargo clippy --all-targets --all-features\n```\n\n**Python**\n```bash\nruff check .\nmypy src/\n```\n\n**Go**\n```bash\ngolangci-lint run\nstaticcheck ./...\n```\n\n**JavaScript/TypeScript**\n```bash\neslint .\ntsc --noEmit\n```\n\n**Java**\n```bash\n./gradlew check\nspotbugs\n```\n\n## Documentation Format\n\n```markdown\n### [D1] file.rs:142 - Null pointer dereference\n\n- **Severity**: Critical\n- **Root Cause**: Logic error - missing null check\n- **Impact**: Crash on malformed input\n- **Evidence**: Line 142 dereferences `config.value` without validation\n- **Context**:\n  ```rust\n  let value = config.value.unwrap(); // PANIC if None\n  ```\n```\n\n## Cross-References\n\nWhen relevant, link to:\n- CVE databases for security issues\n- Language RFCs or proposals\n- Standard library documentation\n- Known issue trackers\n\nFile v1.9.19:modules/fix-preparation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: remediation\nestimated_tokens: 450\nprogressive_loading: true\n---\n\n# Fix Preparation\n\nCreate minimal, idiomatic patches with detailed test coverage.\n\n## Minimal Patch Patterns\n\nApply smallest change that fixes the issue:\n\n**Guard Clause** (prevent invalid state)\n```rust\n// Before: crash on None\nlet value = config.value.unwrap();\n\n// After: guard clause\nlet Some(value) = config.value else {\n    return Err(Error::MissingConfig);\n};\n```\n\n**Validation** (check inputs)\n```python\n# Before: no validation\ndef process(count: int):\n    return items[:count]\n\n# After: boundary check\ndef process(count: int):\n    if count < 0 or count > len(items):\n        raise ValueError(f\"Invalid count: {count}\")\n    return items[:count]\n```\n\n**Resource Cleanup** (prevent leaks)\n```go\n// Before: file handle leak\nfile, err := os.Open(path)\ndata, _ := io.ReadAll(file)\n\n// After: defer cleanup\nfile, err := os.Open(path)\nif err != nil {\n    return err\n}\ndefer file.Close()\ndata, err := io.ReadAll(file)\n```\n\n## Idiomatic Fixes by Language\n\n### Rust\n- Use `?` operator for error propagation\n- Prefer pattern matching over `unwrap()`\n- Use `Option::ok_or()` for conversions\n- Apply ownership transfer instead of cloning\n\n```rust\n// Idiomatic error handling\nfn load_config() -> Result<Config, Error> {\n    let path = env::var(\"CONFIG_PATH\")\n        .map_err(|_| Error::MissingEnv)?;\n    let contents = fs::read_to_string(&path)?;\n    toml::from_str(&contents)\n        .map_err(Error::Parse)\n}\n```\n\n### Python\n- Use context managers for resources\n- Apply type hints for clarity\n- Use specific exception types\n- Prefer `pathlib` over string paths\n\n```python\n# Idiomatic resource handling\nfrom pathlib import Path\nfrom contextlib import contextmanager\n\ndef load_config(path: Path) -> dict:\n    if not path.exists():\n        raise FileNotFoundError(f\"Config not found: {path}\")\n    with path.open() as f:\n        return json.load(f)\n```\n\n### Go\n- Check errors immediately\n- Use `defer` for cleanup\n- Apply early returns\n- Wrap errors with context\n\n```go\n// Idiomatic error handling\nfunc LoadConfig(path string) (*Config, error) {\n    data, err := os.ReadFile(path)\n    if err != nil {\n        return nil, fmt.Errorf(\"reading config: %w\", err)\n    }\n\n    var cfg Config\n    if err := json.Unmarshal(data, &cfg); err != nil {\n        return nil, fmt.Errorf(\"parsing config: %w\", err)\n    }\n\n    return &cfg, nil\n}\n```\n\n### TypeScript\n- Use strict null checks\n- Apply discriminated unions\n- Prefer async/await over promises\n- Use type guards for narrowing\n\n```typescript\n// Idiomatic null handling\nfunction processValue(value: string | null): Result {\n    if (value === null) {\n        throw new Error(\"Value required\");\n    }\n    // TypeScript knows value is string here\n    return { data: value.toLowerCase() };\n}\n```\n\n## Test Coverage Requirements\n\nEvery fix must include tests following Red → Green pattern:\n\n### 1. Red: Write Failing Test\n```rust\n#[test]\nfn test_config_missing_value() {\n    let config = Config { value: None };\n    // This should fail before fix\n    assert!(process_config(&config).is_err());\n}\n```\n\n### 2. Green: Apply Fix\nImplement the minimal change to pass the test.\n\n### 3. Verify: Run Test Suite\n```bash\ncargo test\npytest -v\ngo test ./...\nnpm test\n```\n\n## Test Categories\n\n**Unit Tests**: Test individual functions in isolation\n```python\ndef test_boundary_validation():\n    with pytest.raises(ValueError):\n        process(count=-1)\n```\n\n**Integration Tests**: Test component interactions\n```rust\n#[test]\nfn test_config_loading_integration() {\n    let cfg = load_config(\"test.toml\").unwrap();\n    assert_eq!(cfg.value, Some(42));\n}\n```\n\n**Regression Tests**: Prevent bug recurrence\n```go\nfunc TestNoPanicOnNilValue(t *testing.T) {\n    // Regression test for issue #123\n    result, err := Process(nil)\n    require.Error(t, err)\n    assert.Nil(t, result)\n}\n```\n\n## Explanation Requirements\n\nFor each fix, document:\n1. **What changed**: Specific code modifications\n2. **Why it works**: Mechanism that prevents the bug\n3. **Best practice**: Link to language idioms or patterns\n4. **Trade-offs**: Performance, complexity, or maintainability impact\n\nFile v1.9.19:modules/language-detection.md\n\n---\nparent_skill: pensive:bug-review\ncategory: detection\nestimated_tokens: 250\nprogressive_loading: true\n---\n\n# Language Detection and Expertise Framing\n\nIdentify project languages and establish appropriate expertise context.\n\n## Manifest Heuristics\n\nUse manifest files to detect primary languages:\n\n| Manifest | Language | Ecosystem |\n|----------|----------|-----------|\n| `Cargo.toml` | Rust | cargo |\n| `package.json` | JavaScript/TypeScript | npm/yarn/pnpm |\n| `go.mod` | Go | go modules |\n| `pyproject.toml`, `setup.py` | Python | pip/poetry/uv |\n| `pom.xml`, `build.gradle` | Java | maven/gradle |\n| `*.csproj` | C# | dotnet |\n\n## Version Constraints\n\nExtract and note version requirements:\n\n**Rust**: Check MSRV (Minimum Supported Rust Version)\n```toml\n[package]\nrust-version = \"1.70.0\"\n```\n\n**Python**: Check required version\n```toml\n[project]\nrequires-python = \">=3.8\"\n```\n\n**Node**: Check engine constraints\n```json\n\"engines\": {\n  \"node\": \">=18.0.0\"\n}\n```\n\n**Go**: Check minimum version\n```go\ngo 1.21\n```\n\n## Expertise Persona\n\nFrame appropriate expertise based on detected languages:\n\n**Rust**: \"Staff engineer specializing in Rust systems programming with expertise in ownership, lifetimes, and async runtimes\"\n\n**Python**: \"Senior Python developer with expertise in type systems, async patterns, and performance optimization\"\n\n**Go**: \"Go engineer with deep understanding of concurrency, channels, and idiomatic error handling\"\n\n**TypeScript**: \"TypeScript expert focused on type safety, React patterns, and async workflows\"\n\nState this persona explicitly to establish review context and credibility.\n\nFile v1.9.19:skill-card.md\n\n## Description:\n\nHunts bugs with evidence trails.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[athola](https://clawhub.ai/user/athola)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use this skill to review code for bugs, investigate production issues, prepare minimal fixes, and document verification evidence before release or merge.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Broad trigger words such as fixes or verification may activate the skill in ordinary coding conversations.\n\nMitigation: Confirm the user wants a bug-review workflow before applying the full review, reproduction, fixing, and verification process.\n\nRisk: The workflow may propose code changes and test or lint commands as part of bug investigation.\n\nMitigation: Review proposed patches and commands before execution, and run only project-appropriate verification steps.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-pensive-bug-review)\n- [Metadata homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, guidance]\n\n**Output Format:** [Markdown with inline code blocks and command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes defect summaries, file and line references, proposed fixes, test updates, verification evidence, and remaining-risk notes.]\n\n## Skill Version(s):\n\n1.9.19 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.9.17: 6 files, 8948 bytes\n\nFiles: modules/defect-documentation.md (2568b), modules/fix-preparation.md (4190b), modules/language-detection.md (1614b), skill-card.md (2269b), SKILL.md (6590b), _meta.json (141b)\n\nFile v1.9.17:SKILL.md\n\n---\nname: bug-review\ndescription: Hunts bugs with evidence trails\nversion: 1.9.8\ntriggers:\n  - bugs\n  - defects\n  - debugging\n  - code-quality\n  - fixes\n  - verification\n  - investigating unexpected behavior or before merging code with potential hidden defects\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83d\\udd0d\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.imbue:proof-of-work\", \"night-market.imbue:diff-analysis/modules/risk-assessment-framework\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Quick Start](#quick-start)\n- [When to Use](#when-to-use)\n- [Required TodoWrite Items](#required-todowrite-items)\n- [Progressive Loading](#progressive-loading)\n- [Workflow](#workflow)\n- [Step 1: Detect Languages (`bug-review:language-detected`)](#step-1:-detect-languages-(bug-review:language-detected))\n- [Step 2: Plan Reproduction (`bug-review:repro-plan`)](#step-2:-plan-reproduction-(bug-review:repro-plan))\n- [Step 3: Document Defects (`bug-review:defects-documented`)](#step-3:-document-defects-(bug-review:defects-documented))\n- [Step 4: Prepare Fixes (`bug-review:fixes-prepared`)](#step-4:-prepare-fixes-(bug-review:fixes-prepared))\n- [Step 5: Verification Plan (`bug-review:verification-plan`)](#step-5:-verification-plan-(bug-review:verification-plan))\n- [Defect Classification (Condensed)](#defect-classification-(condensed))\n- [Output Format](#output-format)\n- [Summary](#summary)\n- [Defects Found](#defects-found)\n- [[D1] file.rs:142 - Title](#[d1]-filers:142---title)\n- [Proposed Fixes](#proposed-fixes)\n- [Fix for D1](#fix-for-d1)\n- [Test Updates](#test-updates)\n- [Evidence](#evidence)\n- [Best Practices](#best-practices)\n- [Exit Criteria](#exit-criteria)\n\n\n# Bug Review Workflow\n\nSystematic bug identification and fixing with language-specific expertise.\n\n## Quick Start\n\n```bash\n/bug-review\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## When To Use\n\n- Reviewing code for potential bugs\n- After receiving bug reports\n- Before major releases\n- During security audits\n- Investigating production issues\n\n## When NOT To Use\n\n- Test coverage audit - use test-review instead\n\n## Required TodoWrite Items\n\n1. `bug-review:language-detected`\n2. `bug-review:repro-plan`\n3. `bug-review:defects-documented`\n4. `bug-review:fixes-prepared`\n5. `bug-review:verification-plan`\n\n## Progressive Loading\n\nLoad additional context as needed:\n- **Language Detection**: `@include modules/language-detection.md` - Manifest heuristics, expertise framing, version constraints\n- **Defect Documentation**: `@include modules/defect-documentation.md` - Severity classification, root cause analysis, static analyzers\n- **Fix Preparation**: `@include modules/fix-preparation.md` - Minimal patches, idiomatic patterns, test coverage\n\n## Workflow\n\n### Step 1: Detect Languages (`bug-review:language-detected`)\n\nIdentify dominant languages using manifest files (Cargo.toml → Rust, package.json → Node, etc.).\n\nState expertise persona appropriate for the language ecosystem.\n\nNote version constraints (MSRV, Python versions, Node engines).\n\n**Progressive**: Load `modules/language-detection.md` for detailed manifest heuristics.\n\n### Step 2: Plan Reproduction (`bug-review:repro-plan`)\n\nIdentify reproduction methods:\n- Unit/integration test suites\n- Fuzzing tools\n- Manual reproduction commands\n\nDocument exact commands:\n```bash\ncargo test -p core\npytest tests/test_api.py\nnpm test -- pkg\n```\n**Verification:** Run `pytest -v tests/test_api.py` to verify.\n\nCapture blockers and propose mocks when dependencies unavailable.\n\n### Step 3: Document Defects (`bug-review:defects-documented`)\n\nReview code line-by-line, logging each bug with:\n- **File:line reference**: Precise location\n- **Severity**: Critical, High, Medium, Low\n- **Root cause**: Logic error, API misuse, concurrency, resource leak\n- **Impact**: What breaks and how\n\nRun static analyzers (`cargo clippy`, `ruff check`, `golangci-lint`, `eslint`).\n\nUse `imbue:proof-of-work` for reproducible capture.\n\n**Progressive**: Load `modules/defect-documentation.md` for classification details and analyzer commands.\n\n### Step 4: Prepare Fixes (`bug-review:fixes-prepared`)\n\nDraft minimal, idiomatic patches using language best practices:\n- Guard clauses (Rust: pattern matching, Python: early returns)\n- Resource cleanup (Go: defer, Python: context managers)\n- Error propagation (Rust: ?, Go: wrapped errors)\n\nCreate tests following Red → Green pattern:\n1. Write failing test\n2. Apply minimal fix\n3. Verify test passes\n\n**Progressive**: Load `modules/fix-preparation.md` for language-specific patterns and test strategies.\n\n### Step 5: Verification Plan (`bug-review:verification-plan`)\n\nExecute reproduction steps with fixes applied.\n\nCapture evidence:\n- Test output logs\n- Benchmark comparisons\n- Coverage reports\n\nDocument remaining risks using `imbue:diff-analysis/modules/risk-assessment-framework`.\n\nAssign owners and deadlines for follow-up items.\n\n## Defect Classification (Condensed)\n\n**Severity**: Critical (crash/data loss) → High (broken features) → Medium (degraded UX) → Low (edge cases)\n\n**Root Causes**: Logic errors | API misuse | Concurrency issues | Resource leaks | Validation gaps\n\n## Output Format\n\n```markdown\n## Summary\n[Brief scope description]\n\n## Defects Found\n### [D1] file.rs:142 - Title\n- Severity: High\n- Root Cause: Logic error\n- Impact: Data corruption possible\n- Fix: [description]\n\n## Proposed Fixes\n### Fix for D1\n[code diff with explanation]\n\n## Test Updates\n[new/updated tests with Red → Green verification]\n\n## Evidence\n- Commands executed\n- Logs and outputs\n- External references\n```\n**Verification:** Run `pytest -v` to verify tests pass.\n\n## Best Practices\n\n1. **Evidence-based**: Every finding has file:line reference\n2. **Reproducible**: Clear steps to reproduce each bug\n3. **Minimal fixes**: Smallest change that fixes the issue\n4. **Test coverage**: Every fix has corresponding test\n5. **Risk awareness**: Document remaining risks with severity scoring\n\n## Exit Criteria\n\n- All defects documented with precise references\n- Fixes prepared with test coverage verified\n- Verification plan includes commands and expected outputs\n- Remaining risks assessed and owners assigned\n\nFile v1.9.17:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-bug-review\",\n  \"version\": \"1.9.17\",\n  \"publishedAt\": 1785389927959\n}\n\nFile v1.9.17:modules/defect-documentation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: analysis\nestimated_tokens: 400\nprogressive_loading: true\ndependencies: [imbue:proof-of-work]\n---\n\n# Defect Documentation\n\nSystematic defect identification with precise file references and severity classification.\n\n## File/Line References\n\nEvery defect must include:\n- **File path**: Absolute or relative from project root\n- **Line number**: Exact location of issue\n- **Function/method**: Containing scope\n- **Code snippet**: 3-5 lines of context\n\nExample:\n```\nsrc/parser/tokenizer.rs:142 in `parse_string()`\n```\n\n## Severity Classification\n\n| Level | Description | Impact | Response Time |\n|-------|-------------|--------|---------------|\n| **Critical** | Crash, data loss, security vulnerability | Service down, data corruption | Immediate |\n| **High** | Major functionality broken | Core features unusable | This sprint |\n| **Medium** | Degraded experience, workaround exists | Reduced performance/UX | Next sprint |\n| **Low** | Minor issues, edge cases | Rare scenarios affected | Backlog |\n\n## Root Cause Categories\n\n### Logic Errors\n- Incorrect conditions (off-by-one, wrong operator)\n- Null/None handling gaps\n- Missing validation\n- Boundary condition failures\n\n### API Misuse\n- Wrong parameter types/order\n- Deprecated method usage\n- Incorrect error handling\n- Lifetime/ownership violations (Rust)\n\n### Concurrency Issues\n- Race conditions\n- Deadlocks\n- Data races\n- Improper synchronization\n- Channel misuse (Go)\n\n### Resource Leaks\n- Memory leaks\n- File handle leaks\n- Connection pool exhaustion\n- Lock not released\n\n### Validation Gaps\n- Missing input validation\n- Insufficient boundary checks\n- Type coercion errors\n- Injection vulnerabilities\n\n## Static Analyzer Commands\n\nRun language-specific linters:\n\n**Rust**\n```bash\ncargo clippy --all-targets --all-features\n```\n\n**Python**\n```bash\nruff check .\nmypy src/\n```\n\n**Go**\n```bash\ngolangci-lint run\nstaticcheck ./...\n```\n\n**JavaScript/TypeScript**\n```bash\neslint .\ntsc --noEmit\n```\n\n**Java**\n```bash\n./gradlew check\nspotbugs\n```\n\n## Documentation Format\n\n```markdown\n### [D1] file.rs:142 - Null pointer dereference\n\n- **Severity**: Critical\n- **Root Cause**: Logic error - missing null check\n- **Impact**: Crash on malformed input\n- **Evidence**: Line 142 dereferences `config.value` without validation\n- **Context**:\n  ```rust\n  let value = config.value.unwrap(); // PANIC if None\n  ```\n```\n\n## Cross-References\n\nWhen relevant, link to:\n- CVE databases for security issues\n- Language RFCs or proposals\n- Standard library documentation\n- Known issue trackers\n\nFile v1.9.17:modules/fix-preparation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: remediation\nestimated_tokens: 450\nprogressive_loading: true\n---\n\n# Fix Preparation\n\nCreate minimal, idiomatic patches with detailed test coverage.\n\n## Minimal Patch Patterns\n\nApply smallest change that fixes the issue:\n\n**Guard Clause** (prevent invalid state)\n```rust\n// Before: crash on None\nlet value = config.value.unwrap();\n\n// After: guard clause\nlet Some(value) = config.value else {\n    return Err(Error::MissingConfig);\n};\n```\n\n**Validation** (check inputs)\n```python\n# Before: no validation\ndef process(count: int):\n    return items[:count]\n\n# After: boundary check\ndef process(count: int):\n    if count < 0 or count > len(items):\n        raise ValueError(f\"Invalid count: {count}\")\n    return items[:count]\n```\n\n**Resource Cleanup** (prevent leaks)\n```go\n// Before: file handle leak\nfile, err := os.Open(path)\ndata, _ := io.ReadAll(file)\n\n// After: defer cleanup\nfile, err := os.Open(path)\nif err != nil {\n    return err\n}\ndefer file.Close()\ndata, err := io.ReadAll(file)\n```\n\n## Idiomatic Fixes by Language\n\n### Rust\n- Use `?` operator for error propagation\n- Prefer pattern matching over `unwrap()`\n- Use `Option::ok_or()` for conversions\n- Apply ownership transfer instead of cloning\n\n```rust\n// Idiomatic error handling\nfn load_config() -> Result<Config, Error> {\n    let path = env::var(\"CONFIG_PATH\")\n        .map_err(|_| Error::MissingEnv)?;\n    let contents = fs::read_to_string(&path)?;\n    toml::from_str(&contents)\n        .map_err(Error::Parse)\n}\n```\n\n### Python\n- Use context managers for resources\n- Apply type hints for clarity\n- Use specific exception types\n- Prefer `pathlib` over string paths\n\n```python\n# Idiomatic resource handling\nfrom pathlib import Path\nfrom contextlib import contextmanager\n\ndef load_config(path: Path) -> dict:\n    if not path.exists():\n        raise FileNotFoundError(f\"Config not found: {path}\")\n    with path.open() as f:\n        return json.load(f)\n```\n\n### Go\n- Check errors immediately\n- Use `defer` for cleanup\n- Apply early returns\n- Wrap errors with context\n\n```go\n// Idiomatic error handling\nfunc LoadConfig(path string) (*Config, error) {\n    data, err := os.ReadFile(path)\n    if err != nil {\n        return nil, fmt.Errorf(\"reading config: %w\", err)\n    }\n\n    var cfg Config\n    if err := json.Unmarshal(data, &cfg); err != nil {\n        return nil, fmt.Errorf(\"parsing config: %w\", err)\n    }\n\n    return &cfg, nil\n}\n```\n\n### TypeScript\n- Use strict null checks\n- Apply discriminated unions\n- Prefer async/await over promises\n- Use type guards for narrowing\n\n```typescript\n// Idiomatic null handling\nfunction processValue(value: string | null): Result {\n    if (value === null) {\n        throw new Error(\"Value required\");\n    }\n    // TypeScript knows value is string here\n    return { data: value.toLowerCase() };\n}\n```\n\n## Test Coverage Requirements\n\nEvery fix must include tests following Red → Green pattern:\n\n### 1. Red: Write Failing Test\n```rust\n#[test]\nfn test_config_missing_value() {\n    let config = Config { value: None };\n    // This should fail before fix\n    assert!(process_config(&config).is_err());\n}\n```\n\n### 2. Green: Apply Fix\nImplement the minimal change to pass the test.\n\n### 3. Verify: Run Test Suite\n```bash\ncargo test\npytest -v\ngo test ./...\nnpm test\n```\n\n## Test Categories\n\n**Unit Tests**: Test individual functions in isolation\n```python\ndef test_boundary_validation():\n    with pytest.raises(ValueError):\n        process(count=-1)\n```\n\n**Integration Tests**: Test component interactions\n```rust\n#[test]\nfn test_config_loading_integration() {\n    let cfg = load_config(\"test.toml\").unwrap();\n    assert_eq!(cfg.value, Some(42));\n}\n```\n\n**Regression Tests**: Prevent bug recurrence\n```go\nfunc TestNoPanicOnNilValue(t *testing.T) {\n    // Regression test for issue #123\n    result, err := Process(nil)\n    require.Error(t, err)\n    assert.Nil(t, result)\n}\n```\n\n## Explanation Requirements\n\nFor each fix, document:\n1. **What changed**: Specific code modifications\n2. **Why it works**: Mechanism that prevents the bug\n3. **Best practice**: Link to language idioms or patterns\n4. **Trade-offs**: Performance, complexity, or maintainability impact\n\nFile v1.9.17:modules/language-detection.md\n\n---\nparent_skill: pensive:bug-review\ncategory: detection\nestimated_tokens: 250\nprogressive_loading: true\n---\n\n# Language Detection and Expertise Framing\n\nIdentify project languages and establish appropriate expertise context.\n\n## Manifest Heuristics\n\nUse manifest files to detect primary languages:\n\n| Manifest | Language | Ecosystem |\n|----------|----------|-----------|\n| `Cargo.toml` | Rust | cargo |\n| `package.json` | JavaScript/TypeScript | npm/yarn/pnpm |\n| `go.mod` | Go | go modules |\n| `pyproject.toml`, `setup.py` | Python | pip/poetry/uv |\n| `pom.xml`, `build.gradle` | Java | maven/gradle |\n| `*.csproj` | C# | dotnet |\n\n## Version Constraints\n\nExtract and note version requirements:\n\n**Rust**: Check MSRV (Minimum Supported Rust Version)\n```toml\n[package]\nrust-version = \"1.70.0\"\n```\n\n**Python**: Check required version\n```toml\n[project]\nrequires-python = \">=3.8\"\n```\n\n**Node**: Check engine constraints\n```json\n\"engines\": {\n  \"node\": \">=18.0.0\"\n}\n```\n\n**Go**: Check minimum version\n```go\ngo 1.21\n```\n\n## Expertise Persona\n\nFrame appropriate expertise based on detected languages:\n\n**Rust**: \"Staff engineer specializing in Rust systems programming with expertise in ownership, lifetimes, and async runtimes\"\n\n**Python**: \"Senior Python developer with expertise in type systems, async patterns, and performance optimization\"\n\n**Go**: \"Go engineer with deep understanding of concurrency, channels, and idiomatic error handling\"\n\n**TypeScript**: \"TypeScript expert focused on type safety, React patterns, and async workflows\"\n\nState this persona explicitly to establish review context and credibility.\n\nFile v1.9.17:skill-card.md\n\n## Description: <br>\nSystematically identifies, documents, fixes, and verifies software bugs with evidence trails. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to review code for defects, reproduce issues, document root causes, prepare minimal fixes, and produce verification evidence before releases, audits, or merges. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Broad triggers may activate the workflow during routine development requests. <br>\nMitigation: Confirm that bug review is the intended task before letting the agent inspect files, run verification commands, or prepare changes. <br>\nRisk: Suggested fixes or tests may be incorrect or incomplete for the target project. <br>\nMitigation: Review proposed code changes, run the documented verification commands locally, and keep normal code review gates in place. <br>\nRisk: Expertise-style wording can overstate authority. <br>\nMitigation: Treat persona language as review framing and verify findings against project evidence, tests, and maintainer judgment. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-pensive-bug-review) <br>\n- [Project homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, guidance] <br>\n**Output Format:** [Markdown with defect findings, proposed code changes, test updates, evidence notes, and shell command blocks] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include file and line references, severity labels, root cause summaries, verification commands, and remaining risk notes.] <br>\n\n## Skill Version(s): <br>\n1.9.17 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.16: 6 files, 8843 bytes\n\nFiles: modules/defect-documentation.md (2568b), modules/fix-preparation.md (4190b), modules/language-detection.md (1614b), skill-card.md (2008b), SKILL.md (6590b), _meta.json (141b)\n\nFile v1.9.16:SKILL.md\n\n---\nname: bug-review\ndescription: Hunts bugs with evidence trails\nversion: 1.9.8\ntriggers:\n  - bugs\n  - defects\n  - debugging\n  - code-quality\n  - fixes\n  - verification\n  - investigating unexpected behavior or before merging code with potential hidden defects\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83d\\udd0d\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.imbue:proof-of-work\", \"night-market.imbue:diff-analysis/modules/risk-assessment-framework\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Quick Start](#quick-start)\n- [When to Use](#when-to-use)\n- [Required TodoWrite Items](#required-todowrite-items)\n- [Progressive Loading](#progressive-loading)\n- [Workflow](#workflow)\n- [Step 1: Detect Languages (`bug-review:language-detected`)](#step-1:-detect-languages-(bug-review:language-detected))\n- [Step 2: Plan Reproduction (`bug-review:repro-plan`)](#step-2:-plan-reproduction-(bug-review:repro-plan))\n- [Step 3: Document Defects (`bug-review:defects-documented`)](#step-3:-document-defects-(bug-review:defects-documented))\n- [Step 4: Prepare Fixes (`bug-review:fixes-prepared`)](#step-4:-prepare-fixes-(bug-review:fixes-prepared))\n- [Step 5: Verification Plan (`bug-review:verification-plan`)](#step-5:-verification-plan-(bug-review:verification-plan))\n- [Defect Classification (Condensed)](#defect-classification-(condensed))\n- [Output Format](#output-format)\n- [Summary](#summary)\n- [Defects Found](#defects-found)\n- [[D1] file.rs:142 - Title](#[d1]-filers:142---title)\n- [Proposed Fixes](#proposed-fixes)\n- [Fix for D1](#fix-for-d1)\n- [Test Updates](#test-updates)\n- [Evidence](#evidence)\n- [Best Practices](#best-practices)\n- [Exit Criteria](#exit-criteria)\n\n\n# Bug Review Workflow\n\nSystematic bug identification and fixing with language-specific expertise.\n\n## Quick Start\n\n```bash\n/bug-review\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## When To Use\n\n- Reviewing code for potential bugs\n- After receiving bug reports\n- Before major releases\n- During security audits\n- Investigating production issues\n\n## When NOT To Use\n\n- Test coverage audit - use test-review instead\n\n## Required TodoWrite Items\n\n1. `bug-review:language-detected`\n2. `bug-review:repro-plan`\n3. `bug-review:defects-documented`\n4. `bug-review:fixes-prepared`\n5. `bug-review:verification-plan`\n\n## Progressive Loading\n\nLoad additional context as needed:\n- **Language Detection**: `@include modules/language-detection.md` - Manifest heuristics, expertise framing, version constraints\n- **Defect Documentation**: `@include modules/defect-documentation.md` - Severity classification, root cause analysis, static analyzers\n- **Fix Preparation**: `@include modules/fix-preparation.md` - Minimal patches, idiomatic patterns, test coverage\n\n## Workflow\n\n### Step 1: Detect Languages (`bug-review:language-detected`)\n\nIdentify dominant languages using manifest files (Cargo.toml → Rust, package.json → Node, etc.).\n\nState expertise persona appropriate for the language ecosystem.\n\nNote version constraints (MSRV, Python versions, Node engines).\n\n**Progressive**: Load `modules/language-detection.md` for detailed manifest heuristics.\n\n### Step 2: Plan Reproduction (`bug-review:repro-plan`)\n\nIdentify reproduction methods:\n- Unit/integration test suites\n- Fuzzing tools\n- Manual reproduction commands\n\nDocument exact commands:\n```bash\ncargo test -p core\npytest tests/test_api.py\nnpm test -- pkg\n```\n**Verification:** Run `pytest -v tests/test_api.py` to verify.\n\nCapture blockers and propose mocks when dependencies unavailable.\n\n### Step 3: Document Defects (`bug-review:defects-documented`)\n\nReview code line-by-line, logging each bug with:\n- **File:line reference**: Precise location\n- **Severity**: Critical, High, Medium, Low\n- **Root cause**: Logic error, API misuse, concurrency, resource leak\n- **Impact**: What breaks and how\n\nRun static analyzers (`cargo clippy`, `ruff check`, `golangci-lint`, `eslint`).\n\nUse `imbue:proof-of-work` for reproducible capture.\n\n**Progressive**: Load `modules/defect-documentation.md` for classification details and analyzer commands.\n\n### Step 4: Prepare Fixes (`bug-review:fixes-prepared`)\n\nDraft minimal, idiomatic patches using language best practices:\n- Guard clauses (Rust: pattern matching, Python: early returns)\n- Resource cleanup (Go: defer, Python: context managers)\n- Error propagation (Rust: ?, Go: wrapped errors)\n\nCreate tests following Red → Green pattern:\n1. Write failing test\n2. Apply minimal fix\n3. Verify test passes\n\n**Progressive**: Load `modules/fix-preparation.md` for language-specific patterns and test strategies.\n\n### Step 5: Verification Plan (`bug-review:verification-plan`)\n\nExecute reproduction steps with fixes applied.\n\nCapture evidence:\n- Test output logs\n- Benchmark comparisons\n- Coverage reports\n\nDocument remaining risks using `imbue:diff-analysis/modules/risk-assessment-framework`.\n\nAssign owners and deadlines for follow-up items.\n\n## Defect Classification (Condensed)\n\n**Severity**: Critical (crash/data loss) → High (broken features) → Medium (degraded UX) → Low (edge cases)\n\n**Root Causes**: Logic errors | API misuse | Concurrency issues | Resource leaks | Validation gaps\n\n## Output Format\n\n```markdown\n## Summary\n[Brief scope description]\n\n## Defects Found\n### [D1] file.rs:142 - Title\n- Severity: High\n- Root Cause: Logic error\n- Impact: Data corruption possible\n- Fix: [description]\n\n## Proposed Fixes\n### Fix for D1\n[code diff with explanation]\n\n## Test Updates\n[new/updated tests with Red → Green verification]\n\n## Evidence\n- Commands executed\n- Logs and outputs\n- External references\n```\n**Verification:** Run `pytest -v` to verify tests pass.\n\n## Best Practices\n\n1. **Evidence-based**: Every finding has file:line reference\n2. **Reproducible**: Clear steps to reproduce each bug\n3. **Minimal fixes**: Smallest change that fixes the issue\n4. **Test coverage**: Every fix has corresponding test\n5. **Risk awareness**: Document remaining risks with severity scoring\n\n## Exit Criteria\n\n- All defects documented with precise references\n- Fixes prepared with test coverage verified\n- Verification plan includes commands and expected outputs\n- Remaining risks assessed and owners assigned\n\nFile v1.9.16:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-bug-review\",\n  \"version\": \"1.9.16\",\n  \"publishedAt\": 1784058930129\n}\n\nFile v1.9.16:modules/defect-documentation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: analysis\nestimated_tokens: 400\nprogressive_loading: true\ndependencies: [imbue:proof-of-work]\n---\n\n# Defect Documentation\n\nSystematic defect identification with precise file references and severity classification.\n\n## File/Line References\n\nEvery defect must include:\n- **File path**: Absolute or relative from project root\n- **Line number**: Exact location of issue\n- **Function/method**: Containing scope\n- **Code snippet**: 3-5 lines of context\n\nExample:\n```\nsrc/parser/tokenizer.rs:142 in `parse_string()`\n```\n\n## Severity Classification\n\n| Level | Description | Impact | Response Time |\n|-------|-------------|--------|---------------|\n| **Critical** | Crash, data loss, security vulnerability | Service down, data corruption | Immediate |\n| **High** | Major functionality broken | Core features unusable | This sprint |\n| **Medium** | Degraded experience, workaround exists | Reduced performance/UX | Next sprint |\n| **Low** | Minor issues, edge cases | Rare scenarios affected | Backlog |\n\n## Root Cause Categories\n\n### Logic Errors\n- Incorrect conditions (off-by-one, wrong operator)\n- Null/None handling gaps\n- Missing validation\n- Boundary condition failures\n\n### API Misuse\n- Wrong parameter types/order\n- Deprecated method usage\n- Incorrect error handling\n- Lifetime/ownership violations (Rust)\n\n### Concurrency Issues\n- Race conditions\n- Deadlocks\n- Data races\n- Improper synchronization\n- Channel misuse (Go)\n\n### Resource Leaks\n- Memory leaks\n- File handle leaks\n- Connection pool exhaustion\n- Lock not released\n\n### Validation Gaps\n- Missing input validation\n- Insufficient boundary checks\n- Type coercion errors\n- Injection vulnerabilities\n\n## Static Analyzer Commands\n\nRun language-specific linters:\n\n**Rust**\n```bash\ncargo clippy --all-targets --all-features\n```\n\n**Python**\n```bash\nruff check .\nmypy src/\n```\n\n**Go**\n```bash\ngolangci-lint run\nstaticcheck ./...\n```\n\n**JavaScript/TypeScript**\n```bash\neslint .\ntsc --noEmit\n```\n\n**Java**\n```bash\n./gradlew check\nspotbugs\n```\n\n## Documentation Format\n\n```markdown\n### [D1] file.rs:142 - Null pointer dereference\n\n- **Severity**: Critical\n- **Root Cause**: Logic error - missing null check\n- **Impact**: Crash on malformed input\n- **Evidence**: Line 142 dereferences `config.value` without validation\n- **Context**:\n  ```rust\n  let value = config.value.unwrap(); // PANIC if None\n  ```\n```\n\n## Cross-References\n\nWhen relevant, link to:\n- CVE databases for security issues\n- Language RFCs or proposals\n- Standard library documentation\n- Known issue trackers\n\nFile v1.9.16:modules/fix-preparation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: remediation\nestimated_tokens: 450\nprogressive_loading: true\n---\n\n# Fix Preparation\n\nCreate minimal, idiomatic patches with detailed test coverage.\n\n## Minimal Patch Patterns\n\nApply smallest change that fixes the issue:\n\n**Guard Clause** (prevent invalid state)\n```rust\n// Before: crash on None\nlet value = config.value.unwrap();\n\n// After: guard clause\nlet Some(value) = config.value else {\n    return Err(Error::MissingConfig);\n};\n```\n\n**Validation** (check inputs)\n```python\n# Before: no validation\ndef process(count: int):\n    return items[:count]\n\n# After: boundary check\ndef process(count: int):\n    if count < 0 or count > len(items):\n        raise ValueError(f\"Invalid count: {count}\")\n    return items[:count]\n```\n\n**Resource Cleanup** (prevent leaks)\n```go\n// Before: file handle leak\nfile, err := os.Open(path)\ndata, _ := io.ReadAll(file)\n\n// After: defer cleanup\nfile, err := os.Open(path)\nif err != nil {\n    return err\n}\ndefer file.Close()\ndata, err := io.ReadAll(file)\n```\n\n## Idiomatic Fixes by Language\n\n### Rust\n- Use `?` operator for error propagation\n- Prefer pattern matching over `unwrap()`\n- Use `Option::ok_or()` for conversions\n- Apply ownership transfer instead of cloning\n\n```rust\n// Idiomatic error handling\nfn load_config() -> Result<Config, Error> {\n    let path = env::var(\"CONFIG_PATH\")\n        .map_err(|_| Error::MissingEnv)?;\n    let contents = fs::read_to_string(&path)?;\n    toml::from_str(&contents)\n        .map_err(Error::Parse)\n}\n```\n\n### Python\n- Use context managers for resources\n- Apply type hints for clarity\n- Use specific exception types\n- Prefer `pathlib` over string paths\n\n```python\n# Idiomatic resource handling\nfrom pathlib import Path\nfrom contextlib import contextmanager\n\ndef load_config(path: Path) -> dict:\n    if not path.exists():\n        raise FileNotFoundError(f\"Config not found: {path}\")\n    with path.open() as f:\n        return json.load(f)\n```\n\n### Go\n- Check errors immediately\n- Use `defer` for cleanup\n- Apply early returns\n- Wrap errors with context\n\n```go\n// Idiomatic error handling\nfunc LoadConfig(path string) (*Config, error) {\n    data, err := os.ReadFile(path)\n    if err != nil {\n        return nil, fmt.Errorf(\"reading config: %w\", err)\n    }\n\n    var cfg Config\n    if err := json.Unmarshal(data, &cfg); err != nil {\n        return nil, fmt.Errorf(\"parsing config: %w\", err)\n    }\n\n    return &cfg, nil\n}\n```\n\n### TypeScript\n- Use strict null checks\n- Apply discriminated unions\n- Prefer async/await over promises\n- Use type guards for narrowing\n\n```typescript\n// Idiomatic null handling\nfunction processValue(value: string | null): Result {\n    if (value === null) {\n        throw new Error(\"Value required\");\n    }\n    // TypeScript knows value is string here\n    return { data: value.toLowerCase() };\n}\n```\n\n## Test Coverage Requirements\n\nEvery fix must include tests following Red → Green pattern:\n\n### 1. Red: Write Failing Test\n```rust\n#[test]\nfn test_config_missing_value() {\n    let config = Config { value: None };\n    // This should fail before fix\n    assert!(process_config(&config).is_err());\n}\n```\n\n### 2. Green: Apply Fix\nImplement the minimal change to pass the test.\n\n### 3. Verify: Run Test Suite\n```bash\ncargo test\npytest -v\ngo test ./...\nnpm test\n```\n\n## Test Categories\n\n**Unit Tests**: Test individual functions in isolation\n```python\ndef test_boundary_validation():\n    with pytest.raises(ValueError):\n        process(count=-1)\n```\n\n**Integration Tests**: Test component interactions\n```rust\n#[test]\nfn test_config_loading_integration() {\n    let cfg = load_config(\"test.toml\").unwrap();\n    assert_eq!(cfg.value, Some(42));\n}\n```\n\n**Regression Tests**: Prevent bug recurrence\n```go\nfunc TestNoPanicOnNilValue(t *testing.T) {\n    // Regression test for issue #123\n    result, err := Process(nil)\n    require.Error(t, err)\n    assert.Nil(t, result)\n}\n```\n\n## Explanation Requirements\n\nFor each fix, document:\n1. **What changed**: Specific code modifications\n2. **Why it works**: Mechanism that prevents the bug\n3. **Best practice**: Link to language idioms or patterns\n4. **Trade-offs**: Performance, complexity, or maintainability impact\n\nFile v1.9.16:modules/language-detection.md\n\n---\nparent_skill: pensive:bug-review\ncategory: detection\nestimated_tokens: 250\nprogressive_loading: true\n---\n\n# Language Detection and Expertise Framing\n\nIdentify project languages and establish appropriate expertise context.\n\n## Manifest Heuristics\n\nUse manifest files to detect primary languages:\n\n| Manifest | Language | Ecosystem |\n|----------|----------|-----------|\n| `Cargo.toml` | Rust | cargo |\n| `package.json` | JavaScript/TypeScript | npm/yarn/pnpm |\n| `go.mod` | Go | go modules |\n| `pyproject.toml`, `setup.py` | Python | pip/poetry/uv |\n| `pom.xml`, `build.gradle` | Java | maven/gradle |\n| `*.csproj` | C# | dotnet |\n\n## Version Constraints\n\nExtract and note version requirements:\n\n**Rust**: Check MSRV (Minimum Supported Rust Version)\n```toml\n[package]\nrust-version = \"1.70.0\"\n```\n\n**Python**: Check required version\n```toml\n[project]\nrequires-python = \">=3.8\"\n```\n\n**Node**: Check engine constraints\n```json\n\"engines\": {\n  \"node\": \">=18.0.0\"\n}\n```\n\n**Go**: Check minimum version\n```go\ngo 1.21\n```\n\n## Expertise Persona\n\nFrame appropriate expertise based on detected languages:\n\n**Rust**: \"Staff engineer specializing in Rust systems programming with expertise in ownership, lifetimes, and async runtimes\"\n\n**Python**: \"Senior Python developer with expertise in type systems, async patterns, and performance optimization\"\n\n**Go**: \"Go engineer with deep understanding of concurrency, channels, and idiomatic error handling\"\n\n**TypeScript**: \"TypeScript expert focused on type safety, React patterns, and async workflows\"\n\nState this persona explicitly to establish review context and credibility.\n\nFile v1.9.16:skill-card.md\n\n## Description: <br>\nHunts bugs with evidence trails. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and code reviewers use this skill to investigate bugs, document evidence-backed defects, prepare minimal fixes, and plan verification before releases, audits, or production issue follow-up. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The workflow may trigger on broad debugging or verification requests and may suggest test, lint, or static-analysis commands. <br>\nMitigation: Review the intended scope and commands before running them, especially in sensitive repositories. <br>\nRisk: Bug findings and proposed fixes can be incomplete or incorrect when repository context is missing. <br>\nMitigation: Validate findings with file references, tests, and human review before applying changes. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/athola/skills/nm-pensive-bug-review) <br>\n- [Pensive Plugin Source](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Guidance] <br>\n**Output Format:** [Markdown review report with file references, proposed diffs, test updates, and command evidence.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include suggested test, lint, and static-analysis commands for user review before execution.] <br>\n\n## Skill Version(s): <br>\n1.9.16 (source: server release evidence; artifact frontmatter lists 1.9.8) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.14: 6 files, 8985 bytes\n\nFiles: modules/defect-documentation.md (2568b), modules/fix-preparation.md (4190b), modules/language-detection.md (1614b), skill-card.md (2365b), SKILL.md (6590b), _meta.json (141b)\n\nFile v1.9.14:SKILL.md\n\n---\nname: bug-review\ndescription: Hunts bugs with evidence trails\nversion: 1.9.8\ntriggers:\n  - bugs\n  - defects\n  - debugging\n  - code-quality\n  - fixes\n  - verification\n  - investigating unexpected behavior or before merging code with potential hidden defects\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83d\\udd0d\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.imbue:proof-of-work\", \"night-market.imbue:diff-analysis/modules/risk-assessment-framework\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Quick Start](#quick-start)\n- [When to Use](#when-to-use)\n- [Required TodoWrite Items](#required-todowrite-items)\n- [Progressive Loading](#progressive-loading)\n- [Workflow](#workflow)\n- [Step 1: Detect Languages (`bug-review:language-detected`)](#step-1:-detect-languages-(bug-review:language-detected))\n- [Step 2: Plan Reproduction (`bug-review:repro-plan`)](#step-2:-plan-reproduction-(bug-review:repro-plan))\n- [Step 3: Document Defects (`bug-review:defects-documented`)](#step-3:-document-defects-(bug-review:defects-documented))\n- [Step 4: Prepare Fixes (`bug-review:fixes-prepared`)](#step-4:-prepare-fixes-(bug-review:fixes-prepared))\n- [Step 5: Verification Plan (`bug-review:verification-plan`)](#step-5:-verification-plan-(bug-review:verification-plan))\n- [Defect Classification (Condensed)](#defect-classification-(condensed))\n- [Output Format](#output-format)\n- [Summary](#summary)\n- [Defects Found](#defects-found)\n- [[D1] file.rs:142 - Title](#[d1]-filers:142---title)\n- [Proposed Fixes](#proposed-fixes)\n- [Fix for D1](#fix-for-d1)\n- [Test Updates](#test-updates)\n- [Evidence](#evidence)\n- [Best Practices](#best-practices)\n- [Exit Criteria](#exit-criteria)\n\n\n# Bug Review Workflow\n\nSystematic bug identification and fixing with language-specific expertise.\n\n## Quick Start\n\n```bash\n/bug-review\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## When To Use\n\n- Reviewing code for potential bugs\n- After receiving bug reports\n- Before major releases\n- During security audits\n- Investigating production issues\n\n## When NOT To Use\n\n- Test coverage audit - use test-review instead\n\n## Required TodoWrite Items\n\n1. `bug-review:language-detected`\n2. `bug-review:repro-plan`\n3. `bug-review:defects-documented`\n4. `bug-review:fixes-prepared`\n5. `bug-review:verification-plan`\n\n## Progressive Loading\n\nLoad additional context as needed:\n- **Language Detection**: `@include modules/language-detection.md` - Manifest heuristics, expertise framing, version constraints\n- **Defect Documentation**: `@include modules/defect-documentation.md` - Severity classification, root cause analysis, static analyzers\n- **Fix Preparation**: `@include modules/fix-preparation.md` - Minimal patches, idiomatic patterns, test coverage\n\n## Workflow\n\n### Step 1: Detect Languages (`bug-review:language-detected`)\n\nIdentify dominant languages using manifest files (Cargo.toml → Rust, package.json → Node, etc.).\n\nState expertise persona appropriate for the language ecosystem.\n\nNote version constraints (MSRV, Python versions, Node engines).\n\n**Progressive**: Load `modules/language-detection.md` for detailed manifest heuristics.\n\n### Step 2: Plan Reproduction (`bug-review:repro-plan`)\n\nIdentify reproduction methods:\n- Unit/integration test suites\n- Fuzzing tools\n- Manual reproduction commands\n\nDocument exact commands:\n```bash\ncargo test -p core\npytest tests/test_api.py\nnpm test -- pkg\n```\n**Verification:** Run `pytest -v tests/test_api.py` to verify.\n\nCapture blockers and propose mocks when dependencies unavailable.\n\n### Step 3: Document Defects (`bug-review:defects-documented`)\n\nReview code line-by-line, logging each bug with:\n- **File:line reference**: Precise location\n- **Severity**: Critical, High, Medium, Low\n- **Root cause**: Logic error, API misuse, concurrency, resource leak\n- **Impact**: What breaks and how\n\nRun static analyzers (`cargo clippy`, `ruff check`, `golangci-lint`, `eslint`).\n\nUse `imbue:proof-of-work` for reproducible capture.\n\n**Progressive**: Load `modules/defect-documentation.md` for classification details and analyzer commands.\n\n### Step 4: Prepare Fixes (`bug-review:fixes-prepared`)\n\nDraft minimal, idiomatic patches using language best practices:\n- Guard clauses (Rust: pattern matching, Python: early returns)\n- Resource cleanup (Go: defer, Python: context managers)\n- Error propagation (Rust: ?, Go: wrapped errors)\n\nCreate tests following Red → Green pattern:\n1. Write failing test\n2. Apply minimal fix\n3. Verify test passes\n\n**Progressive**: Load `modules/fix-preparation.md` for language-specific patterns and test strategies.\n\n### Step 5: Verification Plan (`bug-review:verification-plan`)\n\nExecute reproduction steps with fixes applied.\n\nCapture evidence:\n- Test output logs\n- Benchmark comparisons\n- Coverage reports\n\nDocument remaining risks using `imbue:diff-analysis/modules/risk-assessment-framework`.\n\nAssign owners and deadlines for follow-up items.\n\n## Defect Classification (Condensed)\n\n**Severity**: Critical (crash/data loss) → High (broken features) → Medium (degraded UX) → Low (edge cases)\n\n**Root Causes**: Logic errors | API misuse | Concurrency issues | Resource leaks | Validation gaps\n\n## Output Format\n\n```markdown\n## Summary\n[Brief scope description]\n\n## Defects Found\n### [D1] file.rs:142 - Title\n- Severity: High\n- Root Cause: Logic error\n- Impact: Data corruption possible\n- Fix: [description]\n\n## Proposed Fixes\n### Fix for D1\n[code diff with explanation]\n\n## Test Updates\n[new/updated tests with Red → Green verification]\n\n## Evidence\n- Commands executed\n- Logs and outputs\n- External references\n```\n**Verification:** Run `pytest -v` to verify tests pass.\n\n## Best Practices\n\n1. **Evidence-based**: Every finding has file:line reference\n2. **Reproducible**: Clear steps to reproduce each bug\n3. **Minimal fixes**: Smallest change that fixes the issue\n4. **Test coverage**: Every fix has corresponding test\n5. **Risk awareness**: Document remaining risks with severity scoring\n\n## Exit Criteria\n\n- All defects documented with precise references\n- Fixes prepared with test coverage verified\n- Verification plan includes commands and expected outputs\n- Remaining risks assessed and owners assigned\n\nFile v1.9.14:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-bug-review\",\n  \"version\": \"1.9.14\",\n  \"publishedAt\": 1782842634050\n}\n\nFile v1.9.14:modules/defect-documentation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: analysis\nestimated_tokens: 400\nprogressive_loading: true\ndependencies: [imbue:proof-of-work]\n---\n\n# Defect Documentation\n\nSystematic defect identification with precise file references and severity classification.\n\n## File/Line References\n\nEvery defect must include:\n- **File path**: Absolute or relative from project root\n- **Line number**: Exact location of issue\n- **Function/method**: Containing scope\n- **Code snippet**: 3-5 lines of context\n\nExample:\n```\nsrc/parser/tokenizer.rs:142 in `parse_string()`\n```\n\n## Severity Classification\n\n| Level | Description | Impact | Response Time |\n|-------|-------------|--------|---------------|\n| **Critical** | Crash, data loss, security vulnerability | Service down, data corruption | Immediate |\n| **High** | Major functionality broken | Core features unusable | This sprint |\n| **Medium** | Degraded experience, workaround exists | Reduced performance/UX | Next sprint |\n| **Low** | Minor issues, edge cases | Rare scenarios affected | Backlog |\n\n## Root Cause Categories\n\n### Logic Errors\n- Incorrect conditions (off-by-one, wrong operator)\n- Null/None handling gaps\n- Missing validation\n- Boundary condition failures\n\n### API Misuse\n- Wrong parameter types/order\n- Deprecated method usage\n- Incorrect error handling\n- Lifetime/ownership violations (Rust)\n\n### Concurrency Issues\n- Race conditions\n- Deadlocks\n- Data races\n- Improper synchronization\n- Channel misuse (Go)\n\n### Resource Leaks\n- Memory leaks\n- File handle leaks\n- Connection pool exhaustion\n- Lock not released\n\n### Validation Gaps\n- Missing input validation\n- Insufficient boundary checks\n- Type coercion errors\n- Injection vulnerabilities\n\n## Static Analyzer Commands\n\nRun language-specific linters:\n\n**Rust**\n```bash\ncargo clippy --all-targets --all-features\n```\n\n**Python**\n```bash\nruff check .\nmypy src/\n```\n\n**Go**\n```bash\ngolangci-lint run\nstaticcheck ./...\n```\n\n**JavaScript/TypeScript**\n```bash\neslint .\ntsc --noEmit\n```\n\n**Java**\n```bash\n./gradlew check\nspotbugs\n```\n\n## Documentation Format\n\n```markdown\n### [D1] file.rs:142 - Null pointer dereference\n\n- **Severity**: Critical\n- **Root Cause**: Logic error - missing null check\n- **Impact**: Crash on malformed input\n- **Evidence**: Line 142 dereferences `config.value` without validation\n- **Context**:\n  ```rust\n  let value = config.value.unwrap(); // PANIC if None\n  ```\n```\n\n## Cross-References\n\nWhen relevant, link to:\n- CVE databases for security issues\n- Language RFCs or proposals\n- Standard library documentation\n- Known issue trackers\n\nFile v1.9.14:modules/fix-preparation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: remediation\nestimated_tokens: 450\nprogressive_loading: true\n---\n\n# Fix Preparation\n\nCreate minimal, idiomatic patches with detailed test coverage.\n\n## Minimal Patch Patterns\n\nApply smallest change that fixes the issue:\n\n**Guard Clause** (prevent invalid state)\n```rust\n// Before: crash on None\nlet value = config.value.unwrap();\n\n// After: guard clause\nlet Some(value) = config.value else {\n    return Err(Error::MissingConfig);\n};\n```\n\n**Validation** (check inputs)\n```python\n# Before: no validation\ndef process(count: int):\n    return items[:count]\n\n# After: boundary check\ndef process(count: int):\n    if count < 0 or count > len(items):\n        raise ValueError(f\"Invalid count: {count}\")\n    return items[:count]\n```\n\n**Resource Cleanup** (prevent leaks)\n```go\n// Before: file handle leak\nfile, err := os.Open(path)\ndata, _ := io.ReadAll(file)\n\n// After: defer cleanup\nfile, err := os.Open(path)\nif err != nil {\n    return err\n}\ndefer file.Close()\ndata, err := io.ReadAll(file)\n```\n\n## Idiomatic Fixes by Language\n\n### Rust\n- Use `?` operator for error propagation\n- Prefer pattern matching over `unwrap()`\n- Use `Option::ok_or()` for conversions\n- Apply ownership transfer instead of cloning\n\n```rust\n// Idiomatic error handling\nfn load_config() -> Result<Config, Error> {\n    let path = env::var(\"CONFIG_PATH\")\n        .map_err(|_| Error::MissingEnv)?;\n    let contents = fs::read_to_string(&path)?;\n    toml::from_str(&contents)\n        .map_err(Error::Parse)\n}\n```\n\n### Python\n- Use context managers for resources\n- Apply type hints for clarity\n- Use specific exception types\n- Prefer `pathlib` over string paths\n\n```python\n# Idiomatic resource handling\nfrom pathlib import Path\nfrom contextlib import contextmanager\n\ndef load_config(path: Path) -> dict:\n    if not path.exists():\n        raise FileNotFoundError(f\"Config not found: {path}\")\n    with path.open() as f:\n        return json.load(f)\n```\n\n### Go\n- Check errors immediately\n- Use `defer` for cleanup\n- Apply early returns\n- Wrap errors with context\n\n```go\n// Idiomatic error handling\nfunc LoadConfig(path string) (*Config, error) {\n    data, err := os.ReadFile(path)\n    if err != nil {\n        return nil, fmt.Errorf(\"reading config: %w\", err)\n    }\n\n    var cfg Config\n    if err := json.Unmarshal(data, &cfg); err != nil {\n        return nil, fmt.Errorf(\"parsing config: %w\", err)\n    }\n\n    return &cfg, nil\n}\n```\n\n### TypeScript\n- Use strict null checks\n- Apply discriminated unions\n- Prefer async/await over promises\n- Use type guards for narrowing\n\n```typescript\n// Idiomatic null handling\nfunction processValue(value: string | null): Result {\n    if (value === null) {\n        throw new Error(\"Value required\");\n    }\n    // TypeScript knows value is string here\n    return { data: value.toLowerCase() };\n}\n```\n\n## Test Coverage Requirements\n\nEvery fix must include tests following Red → Green pattern:\n\n### 1. Red: Write Failing Test\n```rust\n#[test]\nfn test_config_missing_value() {\n    let config = Config { value: None };\n    // This should fail before fix\n    assert!(process_config(&config).is_err());\n}\n```\n\n### 2. Green: Apply Fix\nImplement the minimal change to pass the test.\n\n### 3. Verify: Run Test Suite\n```bash\ncargo test\npytest -v\ngo test ./...\nnpm test\n```\n\n## Test Categories\n\n**Unit Tests**: Test individual functions in isolation\n```python\ndef test_boundary_validation():\n    with pytest.raises(ValueError):\n        process(count=-1)\n```\n\n**Integration Tests**: Test component interactions\n```rust\n#[test]\nfn test_config_loading_integration() {\n    let cfg = load_config(\"test.toml\").unwrap();\n    assert_eq!(cfg.value, Some(42));\n}\n```\n\n**Regression Tests**: Prevent bug recurrence\n```go\nfunc TestNoPanicOnNilValue(t *testing.T) {\n    // Regression test for issue #123\n    result, err := Process(nil)\n    require.Error(t, err)\n    assert.Nil(t, result)\n}\n```\n\n## Explanation Requirements\n\nFor each fix, document:\n1. **What changed**: Specific code modifications\n2. **Why it works**: Mechanism that prevents the bug\n3. **Best practice**: Link to language idioms or patterns\n4. **Trade-offs**: Performance, complexity, or maintainability impact\n\nFile v1.9.14:modules/language-detection.md\n\n---\nparent_skill: pensive:bug-review\ncategory: detection\nestimated_tokens: 250\nprogressive_loading: true\n---\n\n# Language Detection and Expertise Framing\n\nIdentify project languages and establish appropriate expertise context.\n\n## Manifest Heuristics\n\nUse manifest files to detect primary languages:\n\n| Manifest | Language | Ecosystem |\n|----------|----------|-----------|\n| `Cargo.toml` | Rust | cargo |\n| `package.json` | JavaScript/TypeScript | npm/yarn/pnpm |\n| `go.mod` | Go | go modules |\n| `pyproject.toml`, `setup.py` | Python | pip/poetry/uv |\n| `pom.xml`, `build.gradle` | Java | maven/gradle |\n| `*.csproj` | C# | dotnet |\n\n## Version Constraints\n\nExtract and note version requirements:\n\n**Rust**: Check MSRV (Minimum Supported Rust Version)\n```toml\n[package]\nrust-version = \"1.70.0\"\n```\n\n**Python**: Check required version\n```toml\n[project]\nrequires-python = \">=3.8\"\n```\n\n**Node**: Check engine constraints\n```json\n\"engines\": {\n  \"node\": \">=18.0.0\"\n}\n```\n\n**Go**: Check minimum version\n```go\ngo 1.21\n```\n\n## Expertise Persona\n\nFrame appropriate expertise based on detected languages:\n\n**Rust**: \"Staff engineer specializing in Rust systems programming with expertise in ownership, lifetimes, and async runtimes\"\n\n**Python**: \"Senior Python developer with expertise in type systems, async patterns, and performance optimization\"\n\n**Go**: \"Go engineer with deep understanding of concurrency, channels, and idiomatic error handling\"\n\n**TypeScript**: \"TypeScript expert focused on type safety, React patterns, and async workflows\"\n\nState this persona explicitly to establish review context and credibility.\n\nFile v1.9.14:skill-card.md\n\n## Description: <br>\nHunts bugs with evidence trails. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineering teams use this skill to review code for defects, plan reproductions, document findings with file and line evidence, prepare minimal fixes, and outline verification steps. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can read and reason about project code and may run normal local test, lint, or typecheck commands when directed. <br>\nMitigation: Invoke it intentionally for bug review, review commands before execution, and avoid providing secrets or unrelated sensitive files as context. <br>\nRisk: Generated bug findings or proposed fixes may be incomplete, incorrect, or introduce regressions. <br>\nMitigation: Review findings against the referenced code, apply changes incrementally, and run the documented verification plan before deployment. <br>\nRisk: Broad triggers around bugs, defects, debugging, fixes, and verification could make the skill relevant in many code-quality conversations. <br>\nMitigation: Use the skill deliberately for defect review workflows and confirm scope before relying on its recommendations. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/athola/skills/nm-pensive-bug-review) <br>\n- [Clawdis Homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Markdown, Code, Shell commands, Guidance] <br>\n**Output Format:** [Markdown with defect summaries, proposed code diffs, test updates, command snippets, and evidence notes] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Findings are expected to include file and line references, severity, root cause, impact, proposed fixes, and verification evidence.] <br>\n\n## Skill Version(s): <br>\n1.9.14 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.13: 6 files, 8917 bytes\n\nFiles: modules/defect-documentation.md (2568b), modules/fix-preparation.md (4190b), modules/language-detection.md (1614b), skill-card.md (2156b), SKILL.md (6590b), _meta.json (141b)\n\nFile v1.9.13:SKILL.md\n\n---\nname: bug-review\ndescription: Hunts bugs with evidence trails\nversion: 1.9.8\ntriggers:\n  - bugs\n  - defects\n  - debugging\n  - code-quality\n  - fixes\n  - verification\n  - investigating unexpected behavior or before merging code with potential hidden defects\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83d\\udd0d\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.imbue:proof-of-work\", \"night-market.imbue:diff-analysis/modules/risk-assessment-framework\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Quick Start](#quick-start)\n- [When to Use](#when-to-use)\n- [Required TodoWrite Items](#required-todowrite-items)\n- [Progressive Loading](#progressive-loading)\n- [Workflow](#workflow)\n- [Step 1: Detect Languages (`bug-review:language-detected`)](#step-1:-detect-languages-(bug-review:language-detected))\n- [Step 2: Plan Reproduction (`bug-review:repro-plan`)](#step-2:-plan-reproduction-(bug-review:repro-plan))\n- [Step 3: Document Defects (`bug-review:defects-documented`)](#step-3:-document-defects-(bug-review:defects-documented))\n- [Step 4: Prepare Fixes (`bug-review:fixes-prepared`)](#step-4:-prepare-fixes-(bug-review:fixes-prepared))\n- [Step 5: Verification Plan (`bug-review:verification-plan`)](#step-5:-verification-plan-(bug-review:verification-plan))\n- [Defect Classification (Condensed)](#defect-classification-(condensed))\n- [Output Format](#output-format)\n- [Summary](#summary)\n- [Defects Found](#defects-found)\n- [[D1] file.rs:142 - Title](#[d1]-filers:142---title)\n- [Proposed Fixes](#proposed-fixes)\n- [Fix for D1](#fix-for-d1)\n- [Test Updates](#test-updates)\n- [Evidence](#evidence)\n- [Best Practices](#best-practices)\n- [Exit Criteria](#exit-criteria)\n\n\n# Bug Review Workflow\n\nSystematic bug identification and fixing with language-specific expertise.\n\n## Quick Start\n\n```bash\n/bug-review\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## When To Use\n\n- Reviewing code for potential bugs\n- After receiving bug reports\n- Before major releases\n- During security audits\n- Investigating production issues\n\n## When NOT To Use\n\n- Test coverage audit - use test-review instead\n\n## Required TodoWrite Items\n\n1. `bug-review:language-detected`\n2. `bug-review:repro-plan`\n3. `bug-review:defects-documented`\n4. `bug-review:fixes-prepared`\n5. `bug-review:verification-plan`\n\n## Progressive Loading\n\nLoad additional context as needed:\n- **Language Detection**: `@include modules/language-detection.md` - Manifest heuristics, expertise framing, version constraints\n- **Defect Documentation**: `@include modules/defect-documentation.md` - Severity classification, root cause analysis, static analyzers\n- **Fix Preparation**: `@include modules/fix-preparation.md` - Minimal patches, idiomatic patterns, test coverage\n\n## Workflow\n\n### Step 1: Detect Languages (`bug-review:language-detected`)\n\nIdentify dominant languages using manifest files (Cargo.toml → Rust, package.json → Node, etc.).\n\nState expertise persona appropriate for the language ecosystem.\n\nNote version constraints (MSRV, Python versions, Node engines).\n\n**Progressive**: Load `modules/language-detection.md` for detailed manifest heuristics.\n\n### Step 2: Plan Reproduction (`bug-review:repro-plan`)\n\nIdentify reproduction methods:\n- Unit/integration test suites\n- Fuzzing tools\n- Manual reproduction commands\n\nDocument exact commands:\n```bash\ncargo test -p core\npytest tests/test_api.py\nnpm test -- pkg\n```\n**Verification:** Run `pytest -v tests/test_api.py` to verify.\n\nCapture blockers and propose mocks when dependencies unavailable.\n\n### Step 3: Document Defects (`bug-review:defects-documented`)\n\nReview code line-by-line, logging each bug with:\n- **File:line reference**: Precise location\n- **Severity**: Critical, High, Medium, Low\n- **Root cause**: Logic error, API misuse, concurrency, resource leak\n- **Impact**: What breaks and how\n\nRun static analyzers (`cargo clippy`, `ruff check`, `golangci-lint`, `eslint`).\n\nUse `imbue:proof-of-work` for reproducible capture.\n\n**Progressive**: Load `modules/defect-documentation.md` for classification details and analyzer commands.\n\n### Step 4: Prepare Fixes (`bug-review:fixes-prepared`)\n\nDraft minimal, idiomatic patches using language best practices:\n- Guard clauses (Rust: pattern matching, Python: early returns)\n- Resource cleanup (Go: defer, Python: context managers)\n- Error propagation (Rust: ?, Go: wrapped errors)\n\nCreate tests following Red → Green pattern:\n1. Write failing test\n2. Apply minimal fix\n3. Verify test passes\n\n**Progressive**: Load `modules/fix-preparation.md` for language-specific patterns and test strategies.\n\n### Step 5: Verification Plan (`bug-review:verification-plan`)\n\nExecute reproduction steps with fixes applied.\n\nCapture evidence:\n- Test output logs\n- Benchmark comparisons\n- Coverage reports\n\nDocument remaining risks using `imbue:diff-analysis/modules/risk-assessment-framework`.\n\nAssign owners and deadlines for follow-up items.\n\n## Defect Classification (Condensed)\n\n**Severity**: Critical (crash/data loss) → High (broken features) → Medium (degraded UX) → Low (edge cases)\n\n**Root Causes**: Logic errors | API misuse | Concurrency issues | Resource leaks | Validation gaps\n\n## Output Format\n\n```markdown\n## Summary\n[Brief scope description]\n\n## Defects Found\n### [D1] file.rs:142 - Title\n- Severity: High\n- Root Cause: Logic error\n- Impact: Data corruption possible\n- Fix: [description]\n\n## Proposed Fixes\n### Fix for D1\n[code diff with explanation]\n\n## Test Updates\n[new/updated tests with Red → Green verification]\n\n## Evidence\n- Commands executed\n- Logs and outputs\n- External references\n```\n**Verification:** Run `pytest -v` to verify tests pass.\n\n## Best Practices\n\n1. **Evidence-based**: Every finding has file:line reference\n2. **Reproducible**: Clear steps to reproduce each bug\n3. **Minimal fixes**: Smallest change that fixes the issue\n4. **Test coverage**: Every fix has corresponding test\n5. **Risk awareness**: Document remaining risks with severity scoring\n\n## Exit Criteria\n\n- All defects documented with precise references\n- Fixes prepared with test coverage verified\n- Verification plan includes commands and expected outputs\n- Remaining risks assessed and owners assigned\n\nFile v1.9.13:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-bug-review\",\n  \"version\": \"1.9.13\",\n  \"publishedAt\": 1782577317800\n}\n\nFile v1.9.13:modules/defect-documentation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: analysis\nestimated_tokens: 400\nprogressive_loading: true\ndependencies: [imbue:proof-of-work]\n---\n\n# Defect Documentation\n\nSystematic defect identification with precise file references and severity classification.\n\n## File/Line References\n\nEvery defect must include:\n- **File path**: Absolute or relative from project root\n- **Line number**: Exact location of issue\n- **Function/method**: Containing scope\n- **Code snippet**: 3-5 lines of context\n\nExample:\n```\nsrc/parser/tokenizer.rs:142 in `parse_string()`\n```\n\n## Severity Classification\n\n| Level | Description | Impact | Response Time |\n|-------|-------------|--------|---------------|\n| **Critical** | Crash, data loss, security vulnerability | Service down, data corruption | Immediate |\n| **High** | Major functionality broken | Core features unusable | This sprint |\n| **Medium** | Degraded experience, workaround exists | Reduced performance/UX | Next sprint |\n| **Low** | Minor issues, edge cases | Rare scenarios affected | Backlog |\n\n## Root Cause Categories\n\n### Logic Errors\n- Incorrect conditions (off-by-one, wrong operator)\n- Null/None handling gaps\n- Missing validation\n- Boundary condition failures\n\n### API Misuse\n- Wrong parameter types/order\n- Deprecated method usage\n- Incorrect error handling\n- Lifetime/ownership violations (Rust)\n\n### Concurrency Issues\n- Race conditions\n- Deadlocks\n- Data races\n- Improper synchronization\n- Channel misuse (Go)\n\n### Resource Leaks\n- Memory leaks\n- File handle leaks\n- Connection pool exhaustion\n- Lock not released\n\n### Validation Gaps\n- Missing input validation\n- Insufficient boundary checks\n- Type coercion errors\n- Injection vulnerabilities\n\n## Static Analyzer Commands\n\nRun language-specific linters:\n\n**Rust**\n```bash\ncargo clippy --all-targets --all-features\n```\n\n**Python**\n```bash\nruff check .\nmypy src/\n```\n\n**Go**\n```bash\ngolangci-lint run\nstaticcheck ./...\n```\n\n**JavaScript/TypeScript**\n```bash\neslint .\ntsc --noEmit\n```\n\n**Java**\n```bash\n./gradlew check\nspotbugs\n```\n\n## Documentation Format\n\n```markdown\n### [D1] file.rs:142 - Null pointer dereference\n\n- **Severity**: Critical\n- **Root Cause**: Logic error - missing null check\n- **Impact**: Crash on malformed input\n- **Evidence**: Line 142 dereferences `config.value` without validation\n- **Context**:\n  ```rust\n  let value = config.value.unwrap(); // PANIC if None\n  ```\n```\n\n## Cross-References\n\nWhen relevant, link to:\n- CVE databases for security issues\n- Language RFCs or proposals\n- Standard library documentation\n- Known issue trackers\n\nFile v1.9.13:modules/fix-preparation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: remediation\nestimated_tokens: 450\nprogressive_loading: true\n---\n\n# Fix Preparation\n\nCreate minimal, idiomatic patches with detailed test coverage.\n\n## Minimal Patch Patterns\n\nApply smallest change that fixes the issue:\n\n**Guard Clause** (prevent invalid state)\n```rust\n// Before: crash on None\nlet value = config.value.unwrap();\n\n// After: guard clause\nlet Some(value) = config.value else {\n    return Err(Error::MissingConfig);\n};\n```\n\n**Validation** (check inputs)\n```python\n# Before: no validation\ndef process(count: int):\n    return items[:count]\n\n# After: boundary check\ndef process(count: int):\n    if count < 0 or count > len(items):\n        raise ValueError(f\"Invalid count: {count}\")\n    return items[:count]\n```\n\n**Resource Cleanup** (prevent leaks)\n```go\n// Before: file handle leak\nfile, err := os.Open(path)\ndata, _ := io.ReadAll(file)\n\n// After: defer cleanup\nfile, err := os.Open(path)\nif err != nil {\n    return err\n}\ndefer file.Close()\ndata, err := io.ReadAll(file)\n```\n\n## Idiomatic Fixes by Language\n\n### Rust\n- Use `?` operator for error propagation\n- Prefer pattern matching over `unwrap()`\n- Use `Option::ok_or()` for conversions\n- Apply ownership transfer instead of cloning\n\n```rust\n// Idiomatic error handling\nfn load_config() -> Result<Config, Error> {\n    let path = env::var(\"CONFIG_PATH\")\n        .map_err(|_| Error::MissingEnv)?;\n    let contents = fs::read_to_string(&path)?;\n    toml::from_str(&contents)\n        .map_err(Error::Parse)\n}\n```\n\n### Python\n- Use context managers for resources\n- Apply type hints for clarity\n- Use specific exception types\n- Prefer `pathlib` over string paths\n\n```python\n# Idiomatic resource handling\nfrom pathlib import Path\nfrom contextlib import contextmanager\n\ndef load_config(path: Path) -> dict:\n    if not path.exists():\n        raise FileNotFoundError(f\"Config not found: {path}\")\n    with path.open() as f:\n        return json.load(f)\n```\n\n### Go\n- Check errors immediately\n- Use `defer` for cleanup\n- Apply early returns\n- Wrap errors with context\n\n```go\n// Idiomatic error handling\nfunc LoadConfig(path string) (*Config, error) {\n    data, err := os.ReadFile(path)\n    if err != nil {\n        return nil, fmt.Errorf(\"reading config: %w\", err)\n    }\n\n    var cfg Config\n    if err := json.Unmarshal(data, &cfg); err != nil {\n        return nil, fmt.Errorf(\"parsing config: %w\", err)\n    }\n\n    return &cfg, nil\n}\n```\n\n### TypeScript\n- Use strict null checks\n- Apply discriminated unions\n- Prefer async/await over promises\n- Use type guards for narrowing\n\n```typescript\n// Idiomatic null handling\nfunction processValue(value: string | null): Result {\n    if (value === null) {\n        throw new Error(\"Value required\");\n    }\n    // TypeScript knows value is string here\n    return { data: value.toLowerCase() };\n}\n```\n\n## Test Coverage Requirements\n\nEvery fix must include tests following Red → Green pattern:\n\n### 1. Red: Write Failing Test\n```rust\n#[test]\nfn test_config_missing_value() {\n    let config = Config { value: None };\n    // This should fail before fix\n    assert!(process_config(&config).is_err());\n}\n```\n\n### 2. Green: Apply Fix\nImplement the minimal change to pass the test.\n\n### 3. Verify: Run Test Suite\n```bash\ncargo test\npytest -v\ngo test ./...\nnpm test\n```\n\n## Test Categories\n\n**Unit Tests**: Test individual functions in isolation\n```python\ndef test_boundary_validation():\n    with pytest.raises(ValueError):\n        process(count=-1)\n```\n\n**Integration Tests**: Test component interactions\n```rust\n#[test]\nfn test_config_loading_integration() {\n    let cfg = load_config(\"test.toml\").unwrap();\n    assert_eq!(cfg.value, Some(42));\n}\n```\n\n**Regression Tests**: Prevent bug recurrence\n```go\nfunc TestNoPanicOnNilValue(t *testing.T) {\n    // Regression test for issue #123\n    result, err := Process(nil)\n    require.Error(t, err)\n    assert.Nil(t, result)\n}\n```\n\n## Explanation Requirements\n\nFor each fix, document:\n1. **What changed**: Specific code modifications\n2. **Why it works**: Mechanism that prevents the bug\n3. **Best practice**: Link to language idioms or patterns\n4. **Trade-offs**: Performance, complexity, or maintainability impact\n\nFile v1.9.13:modules/language-detection.md\n\n---\nparent_skill: pensive:bug-review\ncategory: detection\nestimated_tokens: 250\nprogressive_loading: true\n---\n\n# Language Detection and Expertise Framing\n\nIdentify project languages and establish appropriate expertise context.\n\n## Manifest Heuristics\n\nUse manifest files to detect primary languages:\n\n| Manifest | Language | Ecosystem |\n|----------|----------|-----------|\n| `Cargo.toml` | Rust | cargo |\n| `package.json` | JavaScript/TypeScript | npm/yarn/pnpm |\n| `go.mod` | Go | go modules |\n| `pyproject.toml`, `setup.py` | Python | pip/poetry/uv |\n| `pom.xml`, `build.gradle` | Java | maven/gradle |\n| `*.csproj` | C# | dotnet |\n\n## Version Constraints\n\nExtract and note version requirements:\n\n**Rust**: Check MSRV (Minimum Supported Rust Version)\n```toml\n[package]\nrust-version = \"1.70.0\"\n```\n\n**Python**: Check required version\n```toml\n[project]\nrequires-python = \">=3.8\"\n```\n\n**Node**: Check engine constraints\n```json\n\"engines\": {\n  \"node\": \">=18.0.0\"\n}\n```\n\n**Go**: Check minimum version\n```go\ngo 1.21\n```\n\n## Expertise Persona\n\nFrame appropriate expertise based on detected languages:\n\n**Rust**: \"Staff engineer specializing in Rust systems programming with expertise in ownership, lifetimes, and async runtimes\"\n\n**Python**: \"Senior Python developer with expertise in type systems, async patterns, and performance optimization\"\n\n**Go**: \"Go engineer with deep understanding of concurrency, channels, and idiomatic error handling\"\n\n**TypeScript**: \"TypeScript expert focused on type safety, React patterns, and async workflows\"\n\nState this persona explicitly to establish review context and credibility.\n\nFile v1.9.13:skill-card.md\n\n## Description: <br>\nHunts bugs with evidence trails. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to guide systematic bug review, defect documentation, fix preparation, and verification planning across common programming ecosystems. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Broad activation triggers may cause the bug-review workflow to run more often than intended. <br>\nMitigation: Invoke it for explicit debugging, defect review, release readiness, security audit, or production-issue investigation tasks. <br>\nRisk: Generated findings, patches, or verification commands may be incomplete or incorrect. <br>\nMitigation: Review proposed changes and run the relevant tests, linters, or reproduction commands before accepting fixes. <br>\nRisk: The artifact mentions an optional separate Claude Code plugin for the full experience. <br>\nMitigation: Review the separate plugin and its installation behavior before installing it. <br>\n\n\n## Reference(s): <br>\n- [Pensive plugin homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, guidance] <br>\n**Output Format:** [Markdown with file references, defect summaries, proposed fixes, test updates, evidence notes, and inline shell commands] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May propose code changes and verification commands for user review; no API keys or credential environment variables were detected.] <br>\n\n## Skill Version(s): <br>\n1.9.13 (source: server release metadata; artifact frontmatter reports 1.9.8) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.12: 6 files, 8943 bytes\n\nFiles: modules/defect-documentation.md (2568b), modules/fix-preparation.md (4190b), modules/language-detection.md (1614b), skill-card.md (2290b), SKILL.md (6590b), _meta.json (141b)\n\nFile v1.9.12:SKILL.md\n\n---\nname: bug-review\ndescription: Hunts bugs with evidence trails\nversion: 1.9.8\ntriggers:\n  - bugs\n  - defects\n  - debugging\n  - code-quality\n  - fixes\n  - verification\n  - investigating unexpected behavior or before merging code with potential hidden defects\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83d\\udd0d\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.imbue:proof-of-work\", \"night-market.imbue:diff-analysis/modules/risk-assessment-framework\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Quick Start](#quick-start)\n- [When to Use](#when-to-use)\n- [Required TodoWrite Items](#required-todowrite-items)\n- [Progressive Loading](#progressive-loading)\n- [Workflow](#workflow)\n- [Step 1: Detect Languages (`bug-review:language-detected`)](#step-1:-detect-languages-(bug-review:language-detected))\n- [Step 2: Plan Reproduction (`bug-review:repro-plan`)](#step-2:-plan-reproduction-(bug-review:repro-plan))\n- [Step 3: Document Defects (`bug-review:defects-documented`)](#step-3:-document-defects-(bug-review:defects-documented))\n- [Step 4: Prepare Fixes (`bug-review:fixes-prepared`)](#step-4:-prepare-fixes-(bug-review:fixes-prepared))\n- [Step 5: Verification Plan (`bug-review:verification-plan`)](#step-5:-verification-plan-(bug-review:verification-plan))\n- [Defect Classification (Condensed)](#defect-classification-(condensed))\n- [Output Format](#output-format)\n- [Summary](#summary)\n- [Defects Found](#defects-found)\n- [[D1] file.rs:142 - Title](#[d1]-filers:142---title)\n- [Proposed Fixes](#proposed-fixes)\n- [Fix for D1](#fix-for-d1)\n- [Test Updates](#test-updates)\n- [Evidence](#evidence)\n- [Best Practices](#best-practices)\n- [Exit Criteria](#exit-criteria)\n\n\n# Bug Review Workflow\n\nSystematic bug identification and fixing with language-specific expertise.\n\n## Quick Start\n\n```bash\n/bug-review\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## When To Use\n\n- Reviewing code for potential bugs\n- After receiving bug reports\n- Before major releases\n- During security audits\n- Investigating production issues\n\n## When NOT To Use\n\n- Test coverage audit - use test-review instead\n\n## Required TodoWrite Items\n\n1. `bug-review:language-detected`\n2. `bug-review:repro-plan`\n3. `bug-review:defects-documented`\n4. `bug-review:fixes-prepared`\n5. `bug-review:verification-plan`\n\n## Progressive Loading\n\nLoad additional context as needed:\n- **Language Detection**: `@include modules/language-detection.md` - Manifest heuristics, expertise framing, version constraints\n- **Defect Documentation**: `@include modules/defect-documentation.md` - Severity classification, root cause analysis, static analyzers\n- **Fix Preparation**: `@include modules/fix-preparation.md` - Minimal patches, idiomatic patterns, test coverage\n\n## Workflow\n\n### Step 1: Detect Languages (`bug-review:language-detected`)\n\nIdentify dominant languages using manifest files (Cargo.toml → Rust, package.json → Node, etc.).\n\nState expertise persona appropriate for the language ecosystem.\n\nNote version constraints (MSRV, Python versions, Node engines).\n\n**Progressive**: Load `modules/language-detection.md` for detailed manifest heuristics.\n\n### Step 2: Plan Reproduction (`bug-review:repro-plan`)\n\nIdentify reproduction methods:\n- Unit/integration test suites\n- Fuzzing tools\n- Manual reproduction commands\n\nDocument exact commands:\n```bash\ncargo test -p core\npytest tests/test_api.py\nnpm test -- pkg\n```\n**Verification:** Run `pytest -v tests/test_api.py` to verify.\n\nCapture blockers and propose mocks when dependencies unavailable.\n\n### Step 3: Document Defects (`bug-review:defects-documented`)\n\nReview code line-by-line, logging each bug with:\n- **File:line reference**: Precise location\n- **Severity**: Critical, High, Medium, Low\n- **Root cause**: Logic error, API misuse, concurrency, resource leak\n- **Impact**: What breaks and how\n\nRun static analyzers (`cargo clippy`, `ruff check`, `golangci-lint`, `eslint`).\n\nUse `imbue:proof-of-work` for reproducible capture.\n\n**Progressive**: Load `modules/defect-documentation.md` for classification details and analyzer commands.\n\n### Step 4: Prepare Fixes (`bug-review:fixes-prepared`)\n\nDraft minimal, idiomatic patches using language best practices:\n- Guard clauses (Rust: pattern matching, Python: early returns)\n- Resource cleanup (Go: defer, Python: context managers)\n- Error propagation (Rust: ?, Go: wrapped errors)\n\nCreate tests following Red → Green pattern:\n1. Write failing test\n2. Apply minimal fix\n3. Verify test passes\n\n**Progressive**: Load `modules/fix-preparation.md` for language-specific patterns and test strategies.\n\n### Step 5: Verification Plan (`bug-review:verification-plan`)\n\nExecute reproduction steps with fixes applied.\n\nCapture evidence:\n- Test output logs\n- Benchmark comparisons\n- Coverage reports\n\nDocument remaining risks using `imbue:diff-analysis/modules/risk-assessment-framework`.\n\nAssign owners and deadlines for follow-up items.\n\n## Defect Classification (Condensed)\n\n**Severity**: Critical (crash/data loss) → High (broken features) → Medium (degraded UX) → Low (edge cases)\n\n**Root Causes**: Logic errors | API misuse | Concurrency issues | Resource leaks | Validation gaps\n\n## Output Format\n\n```markdown\n## Summary\n[Brief scope description]\n\n## Defects Found\n### [D1] file.rs:142 - Title\n- Severity: High\n- Root Cause: Logic error\n- Impact: Data corruption possible\n- Fix: [description]\n\n## Proposed Fixes\n### Fix for D1\n[code diff with explanation]\n\n## Test Updates\n[new/updated tests with Red → Green verification]\n\n## Evidence\n- Commands executed\n- Logs and outputs\n- External references\n```\n**Verification:** Run `pytest -v` to verify tests pass.\n\n## Best Practices\n\n1. **Evidence-based**: Every finding has file:line reference\n2. **Reproducible**: Clear steps to reproduce each bug\n3. **Minimal fixes**: Smallest change that fixes the issue\n4. **Test coverage**: Every fix has corresponding test\n5. **Risk awareness**: Document remaining risks with severity scoring\n\n## Exit Criteria\n\n- All defects documented with precise references\n- Fixes prepared with test coverage verified\n- Verification plan includes commands and expected outputs\n- Remaining risks assessed and owners assigned\n\nFile v1.9.12:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-bug-review\",\n  \"version\": \"1.9.12\",\n  \"publishedAt\": 1781839021048\n}\n\nFile v1.9.12:modules/defect-documentation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: analysis\nestimated_tokens: 400\nprogressive_loading: true\ndependencies: [imbue:proof-of-work]\n---\n\n# Defect Documentation\n\nSystematic defect identification with precise file references and severity classification.\n\n## File/Line References\n\nEvery defect must include:\n- **File path**: Absolute or relative from project root\n- **Line number**: Exact location of issue\n- **Function/method**: Containing scope\n- **Code snippet**: 3-5 lines of context\n\nExample:\n```\nsrc/parser/tokenizer.rs:142 in `parse_string()`\n```\n\n## Severity Classification\n\n| Level | Description | Impact | Response Time |\n|-------|-------------|--------|---------------|\n| **Critical** | Crash, data loss, security vulnerability | Service down, data corruption | Immediate |\n| **High** | Major functionality broken | Core features unusable | This sprint |\n| **Medium** | Degraded experience, workaround exists | Reduced performance/UX | Next sprint |\n| **Low** | Minor issues, edge cases | Rare scenarios affected | Backlog |\n\n## Root Cause Categories\n\n### Logic Errors\n- Incorrect conditions (off-by-one, wrong operator)\n- Null/None handling gaps\n- Missing validation\n- Boundary condition failures\n\n### API Misuse\n- Wrong parameter types/order\n- Deprecated method usage\n- Incorrect error handling\n- Lifetime/ownership violations (Rust)\n\n### Concurrency Issues\n- Race conditions\n- Deadlocks\n- Data races\n- Improper synchronization\n- Channel misuse (Go)\n\n### Resource Leaks\n- Memory leaks\n- File handle leaks\n- Connection pool exhaustion\n- Lock not released\n\n### Validation Gaps\n- Missing input validation\n- Insufficient boundary checks\n- Type coercion errors\n- Injection vulnerabilities\n\n## Static Analyzer Commands\n\nRun language-specific linters:\n\n**Rust**\n```bash\ncargo clippy --all-targets --all-features\n```\n\n**Python**\n```bash\nruff check .\nmypy src/\n```\n\n**Go**\n```bash\ngolangci-lint run\nstaticcheck ./...\n```\n\n**JavaScript/TypeScript**\n```bash\neslint .\ntsc --noEmit\n```\n\n**Java**\n```bash\n./gradlew check\nspotbugs\n```\n\n## Documentation Format\n\n```markdown\n### [D1] file.rs:142 - Null pointer dereference\n\n- **Severity**: Critical\n- **Root Cause**: Logic error - missing null check\n- **Impact**: Crash on malformed input\n- **Evidence**: Line 142 dereferences `config.value` without validation\n- **Context**:\n  ```rust\n  let value = config.value.unwrap(); // PANIC if None\n  ```\n```\n\n## Cross-References\n\nWhen relevant, link to:\n- CVE databases for security issues\n- Language RFCs or proposals\n- Standard library documentation\n- Known issue trackers\n\nFile v1.9.12:modules/fix-preparation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: remediation\nestimated_tokens: 450\nprogressive_loading: true\n---\n\n# Fix Preparation\n\nCreate minimal, idiomatic patches with detailed test coverage.\n\n## Minimal Patch Patterns\n\nApply smallest change that fixes the issue:\n\n**Guard Clause** (prevent invalid state)\n```rust\n// Before: crash on None\nlet value = config.value.unwrap();\n\n// After: guard clause\nlet Some(value) = config.value else {\n    return Err(Error::MissingConfig);\n};\n```\n\n**Validation** (check inputs)\n```python\n# Before: no validation\ndef process(count: int):\n    return items[:count]\n\n# After: boundary check\ndef process(count: int):\n    if count < 0 or count > len(items):\n        raise ValueError(f\"Invalid count: {count}\")\n    return items[:count]\n```\n\n**Resource Cleanup** (prevent leaks)\n```go\n// Before: file handle leak\nfile, err := os.Open(path)\ndata, _ := io.ReadAll(file)\n\n// After: defer cleanup\nfile, err := os.Open(path)\nif err != nil {\n    return err\n}\ndefer file.Close()\ndata, err := io.ReadAll(file)\n```\n\n## Idiomatic Fixes by Language\n\n### Rust\n- Use `?` operator for error propagation\n- Prefer pattern matching over `unwrap()`\n- Use `Option::ok_or()` for conversions\n- Apply ownership transfer instead of cloning\n\n```rust\n// Idiomatic error handling\nfn load_config() -> Result<Config, Error> {\n    let path = env::var(\"CONFIG_PATH\")\n        .map_err(|_| Error::MissingEnv)?;\n    let contents = fs::read_to_string(&path)?;\n    toml::from_str(&contents)\n        .map_err(Error::Parse)\n}\n```\n\n### Python\n- Use context managers for resources\n- Apply type hints for clarity\n- Use specific exception types\n- Prefer `pathlib` over string paths\n\n```python\n# Idiomatic resource handling\nfrom pathlib import Path\nfrom contextlib import contextmanager\n\ndef load_config(path: Path) -> dict:\n    if not path.exists():\n        raise FileNotFoundError(f\"Config not found: {path}\")\n    with path.open() as f:\n        return json.load(f)\n```\n\n### Go\n- Check errors immediately\n- Use `defer` for cleanup\n- Apply early returns\n- Wrap errors with context\n\n```go\n// Idiomatic error handling\nfunc LoadConfig(path string) (*Config, error) {\n    data, err := os.ReadFile(path)\n    if err != nil {\n        return nil, fmt.Errorf(\"reading config: %w\", err)\n    }\n\n    var cfg Config\n    if err := json.Unmarshal(data, &cfg); err != nil {\n        return nil, fmt.Errorf(\"parsing config: %w\", err)\n    }\n\n    return &cfg, nil\n}\n```\n\n### TypeScript\n- Use strict null checks\n- Apply discriminated unions\n- Prefer async/await over promises\n- Use type guards for narrowing\n\n```typescript\n// Idiomatic null handling\nfunction processValue(value: string | null): Result {\n    if (value === null) {\n        throw new Error(\"Value required\");\n    }\n    // TypeScript knows value is string here\n    return { data: value.toLowerCase() };\n}\n```\n\n## Test Coverage Requirements\n\nEvery fix must include tests following Red → Green pattern:\n\n### 1. Red: Write Failing Test\n```rust\n#[test]\nfn test_config_missing_value() {\n    let config = Config { value: None };\n    // This should fail before fix\n    assert!(process_config(&config).is_err());\n}\n```\n\n### 2. Green: Apply Fix\nImplement the minimal change to pass the test.\n\n### 3. Verify: Run Test Suite\n```bash\ncargo test\npytest -v\ngo test ./...\nnpm test\n```\n\n## Test Categories\n\n**Unit Tests**: Test individual functions in isolation\n```python\ndef test_boundary_validation():\n    with pytest.raises(ValueError):\n        process(count=-1)\n```\n\n**Integration Tests**: Test component interactions\n```rust\n#[test]\nfn test_config_loading_integration() {\n    let cfg = load_config(\"test.toml\").unwrap();\n    assert_eq!(cfg.value, Some(42));\n}\n```\n\n**Regression Tests**: Prevent bug recurrence\n```go\nfunc TestNoPanicOnNilValue(t *testing.T) {\n    // Regression test for issue #123\n    result, err := Process(nil)\n    require.Error(t, err)\n    assert.Nil(t, result)\n}\n```\n\n## Explanation Requirements\n\nFor each fix, document:\n1. **What changed**: Specific code modifications\n2. **Why it works**: Mechanism that prevents the bug\n3. **Best practice**: Link to language idioms or patterns\n4. **Trade-offs**: Performance, complexity, or maintainability impact\n\nFile v1.9.12:modules/language-detection.md\n\n---\nparent_skill: pensive:bug-review\ncategory: detection\nestimated_tokens: 250\nprogressive_loading: true\n---\n\n# Language Detection and Expertise Framing\n\nIdentify project languages and establish appropriate expertise context.\n\n## Manifest Heuristics\n\nUse manifest files to detect primary languages:\n\n| Manifest | Language | Ecosystem |\n|----------|----------|-----------|\n| `Cargo.toml` | Rust | cargo |\n| `package.json` | JavaScript/TypeScript | npm/yarn/pnpm |\n| `go.mod` | Go | go modules |\n| `pyproject.toml`, `setup.py` | Python | pip/poetry/uv |\n| `pom.xml`, `build.gradle` | Java | maven/gradle |\n| `*.csproj` | C# | dotnet |\n\n## Version Constraints\n\nExtract and note version requirements:\n\n**Rust**: Check MSRV (Minimum Supported Rust Version)\n```toml\n[package]\nrust-version = \"1.70.0\"\n```\n\n**Python**: Check required version\n```toml\n[project]\nrequires-python = \">=3.8\"\n```\n\n**Node**: Check engine constraints\n```json\n\"engines\": {\n  \"node\": \">=18.0.0\"\n}\n```\n\n**Go**: Check minimum version\n```go\ngo 1.21\n```\n\n## Expertise Persona\n\nFrame appropriate expertise based on detected languages:\n\n**Rust**: \"Staff engineer specializing in Rust systems programming with expertise in ownership, lifetimes, and async runtimes\"\n\n**Python**: \"Senior Python developer with expertise in type systems, async patterns, and performance optimization\"\n\n**Go**: \"Go engineer with deep understanding of concurrency, channels, and idiomatic error handling\"\n\n**TypeScript**: \"TypeScript expert focused on type safety, React patterns, and async workflows\"\n\nState this persona explicitly to establish review context and credibility.\n\nFile v1.9.12:skill-card.md\n\n## Description: <br>\nHunts bugs with evidence trails. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to review code for defects, document evidence with file and line references, prepare minimal fixes, and plan verification before releases, audits, or production issue investigations. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Review bundles may be sent to configured external reviewer CLIs or use web search. <br>\nMitigation: Use the skill only with repositories and data approved for the configured reviewer tools, and avoid external review paths for sensitive code. <br>\nRisk: One optional reviewer path may rely on prompt instructions rather than enforced read-only controls. <br>\nMitigation: Prefer the default Codex path or engines with explicit read-only controls; manually review or harden the Droid engine before sensitive use. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/nm-pensive-bug-review) <br>\n- [Pensive source homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n- [Language Detection](artifact/modules/language-detection.md) <br>\n- [Defect Documentation](artifact/modules/defect-documentation.md) <br>\n- [Fix Preparation](artifact/modules/fix-preparation.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Guidance] <br>\n**Output Format:** [Markdown report with file references, code diffs, test updates, evidence, and shell command snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include proposed fixes and verification commands; users should review changes before applying them.] <br>\n\n## Skill Version(s): <br>\n1.9.12 (source: server release evidence; artifact frontmatter says 1.9.8) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.3: 6 files, 8873 bytes\n\nFiles: modules/defect-documentation.md (2568b), modules/fix-preparation.md (4190b), modules/language-detection.md (1614b), skill-card.md (2059b), SKILL.md (6590b), _meta.json (140b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: bug-review\ndescription: Hunts bugs with evidence trails\nversion: 1.9.8\ntriggers:\n  - bugs\n  - defects\n  - debugging\n  - code-quality\n  - fixes\n  - verification\n  - investigating unexpected behavior or before merging code with potential hidden defects\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83d\\udd0d\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.imbue:proof-of-work\", \"night-market.imbue:diff-analysis/modules/risk-assessment-framework\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Quick Start](#quick-start)\n- [When to Use](#when-to-use)\n- [Required TodoWrite Items](#required-todowrite-items)\n- [Progressive Loading](#progressive-loading)\n- [Workflow](#workflow)\n- [Step 1: Detect Languages (`bug-review:language-detected`)](#step-1:-detect-languages-(bug-review:language-detected))\n- [Step 2: Plan Reproduction (`bug-review:repro-plan`)](#step-2:-plan-reproduction-(bug-review:repro-plan))\n- [Step 3: Document Defects (`bug-review:defects-documented`)](#step-3:-document-defects-(bug-review:defects-documented))\n- [Step 4: Prepare Fixes (`bug-review:fixes-prepared`)](#step-4:-prepare-fixes-(bug-review:fixes-prepared))\n- [Step 5: Verification Plan (`bug-review:verification-plan`)](#step-5:-verification-plan-(bug-review:verification-plan))\n- [Defect Classification (Condensed)](#defect-classification-(condensed))\n- [Output Format](#output-format)\n- [Summary](#summary)\n- [Defects Found](#defects-found)\n- [[D1] file.rs:142 - Title](#[d1]-filers:142---title)\n- [Proposed Fixes](#proposed-fixes)\n- [Fix for D1](#fix-for-d1)\n- [Test Updates](#test-updates)\n- [Evidence](#evidence)\n- [Best Practices](#best-practices)\n- [Exit Criteria](#exit-criteria)\n\n\n# Bug Review Workflow\n\nSystematic bug identification and fixing with language-specific expertise.\n\n## Quick Start\n\n```bash\n/bug-review\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## When To Use\n\n- Reviewing code for potential bugs\n- After receiving bug reports\n- Before major releases\n- During security audits\n- Investigating production issues\n\n## When NOT To Use\n\n- Test coverage audit - use test-review instead\n\n## Required TodoWrite Items\n\n1. `bug-review:language-detected`\n2. `bug-review:repro-plan`\n3. `bug-review:defects-documented`\n4. `bug-review:fixes-prepared`\n5. `bug-review:verification-plan`\n\n## Progressive Loading\n\nLoad additional context as needed:\n- **Language Detection**: `@include modules/language-detection.md` - Manifest heuristics, expertise framing, version constraints\n- **Defect Documentation**: `@include modules/defect-documentation.md` - Severity classification, root cause analysis, static analyzers\n- **Fix Preparation**: `@include modules/fix-preparation.md` - Minimal patches, idiomatic patterns, test coverage\n\n## Workflow\n\n### Step 1: Detect Languages (`bug-review:language-detected`)\n\nIdentify dominant languages using manifest files (Cargo.toml → Rust, package.json → Node, etc.).\n\nState expertise persona appropriate for the language ecosystem.\n\nNote version constraints (MSRV, Python versions, Node engines).\n\n**Progressive**: Load `modules/language-detection.md` for detailed manifest heuristics.\n\n### Step 2: Plan Reproduction (`bug-review:repro-plan`)\n\nIdentify reproduction methods:\n- Unit/integration test suites\n- Fuzzing tools\n- Manual reproduction commands\n\nDocument exact commands:\n```bash\ncargo test -p core\npytest tests/test_api.py\nnpm test -- pkg\n```\n**Verification:** Run `pytest -v tests/test_api.py` to verify.\n\nCapture blockers and propose mocks when dependencies unavailable.\n\n### Step 3: Document Defects (`bug-review:defects-documented`)\n\nReview code line-by-line, logging each bug with:\n- **File:line reference**: Precise location\n- **Severity**: Critical, High, Medium, Low\n- **Root cause**: Logic error, API misuse, concurrency, resource leak\n- **Impact**: What breaks and how\n\nRun static analyzers (`cargo clippy`, `ruff check`, `golangci-lint`, `eslint`).\n\nUse `imbue:proof-of-work` for reproducible capture.\n\n**Progressive**: Load `modules/defect-documentation.md` for classification details and analyzer commands.\n\n### Step 4: Prepare Fixes (`bug-review:fixes-prepared`)\n\nDraft minimal, idiomatic patches using language best practices:\n- Guard clauses (Rust: pattern matching, Python: early returns)\n- Resource cleanup (Go: defer, Python: context managers)\n- Error propagation (Rust: ?, Go: wrapped errors)\n\nCreate tests following Red → Green pattern:\n1. Write failing test\n2. Apply minimal fix\n3. Verify test passes\n\n**Progressive**: Load `modules/fix-preparation.md` for language-specific patterns and test strategies.\n\n### Step 5: Verification Plan (`bug-review:verification-plan`)\n\nExecute reproduction steps with fixes applied.\n\nCapture evidence:\n- Test output logs\n- Benchmark comparisons\n- Coverage reports\n\nDocument remaining risks using `imbue:diff-analysis/modules/risk-assessment-framework`.\n\nAssign owners and deadlines for follow-up items.\n\n## Defect Classification (Condensed)\n\n**Severity**: Critical (crash/data loss) → High (broken features) → Medium (degraded UX) → Low (edge cases)\n\n**Root Causes**: Logic errors | API misuse | Concurrency issues | Resource leaks | Validation gaps\n\n## Output Format\n\n```markdown\n## Summary\n[Brief scope description]\n\n## Defects Found\n### [D1] file.rs:142 - Title\n- Severity: High\n- Root Cause: Logic error\n- Impact: Data corruption possible\n- Fix: [description]\n\n## Proposed Fixes\n### Fix for D1\n[code diff with explanation]\n\n## Test Updates\n[new/updated tests with Red → Green verification]\n\n## Evidence\n- Commands executed\n- Logs and outputs\n- External references\n```\n**Verification:** Run `pytest -v` to verify tests pass.\n\n## Best Practices\n\n1. **Evidence-based**: Every finding has file:line reference\n2. **Reproducible**: Clear steps to reproduce each bug\n3. **Minimal fixes**: Smallest change that fixes the issue\n4. **Test coverage**: Every fix has corresponding test\n5. **Risk awareness**: Document remaining risks with severity scoring\n\n## Exit Criteria\n\n- All defects documented with precise references\n- Fixes prepared with test coverage verified\n- Verification plan includes commands and expected outputs\n- Remaining risks assessed and owners assigned\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-bug-review\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1781791912870\n}\n\nFile v1.0.3:modules/defect-documentation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: analysis\nestimated_tokens: 400\nprogressive_loading: true\ndependencies: [imbue:proof-of-work]\n---\n\n# Defect Documentation\n\nSystematic defect identification with precise file references and severity classification.\n\n## File/Line References\n\nEvery defect must include:\n- **File path**: Absolute or relative from project root\n- **Line number**: Exact location of issue\n- **Function/method**: Containing scope\n- **Code snippet**: 3-5 lines of context\n\nExample:\n```\nsrc/parser/tokenizer.rs:142 in `parse_string()`\n```\n\n## Severity Classification\n\n| Level | Description | Impact | Response Time |\n|-------|-------------|--------|---------------|\n| **Critical** | Crash, data loss, security vulnerability | Service down, data corruption | Immediate |\n| **High** | Major functionality broken | Core features unusable | This sprint |\n| **Medium** | Degraded experience, workaround exists | Reduced performance/UX | Next sprint |\n| **Low** | Minor issues, edge cases | Rare scenarios affected | Backlog |\n\n## Root Cause Categories\n\n### Logic Errors\n- Incorrect conditions (off-by-one, wrong operator)\n- Null/None handling gaps\n- Missing validation\n- Boundary condition failures\n\n### API Misuse\n- Wrong parameter types/order\n- Deprecated method usage\n- Incorrect error handling\n- Lifetime/ownership violations (Rust)\n\n### Concurrency Issues\n- Race conditions\n- Deadlocks\n- Data races\n- Improper synchronization\n- Channel misuse (Go)\n\n### Resource Leaks\n- Memory leaks\n- File handle leaks\n- Connection pool exhaustion\n- Lock not released\n\n### Validation Gaps\n- Missing input validation\n- Insufficient boundary checks\n- Type coercion errors\n- Injection vulnerabilities\n\n## Static Analyzer Commands\n\nRun language-specific linters:\n\n**Rust**\n```bash\ncargo clippy --all-targets --all-features\n```\n\n**Python**\n```bash\nruff check .\nmypy src/\n```\n\n**Go**\n```bash\ngolangci-lint run\nstaticcheck ./...\n```\n\n**JavaScript/TypeScript**\n```bash\neslint .\ntsc --noEmit\n```\n\n**Java**\n```bash\n./gradlew check\nspotbugs\n```\n\n## Documentation Format\n\n```markdown\n### [D1] file.rs:142 - Null pointer dereference\n\n- **Severity**: Critical\n- **Root Cause**: Logic error - missing null check\n- **Impact**: Crash on malformed input\n- **Evidence**: Line 142 dereferences `config.value` without validation\n- **Context**:\n  ```rust\n  let value = config.value.unwrap(); // PANIC if None\n  ```\n```\n\n## Cross-References\n\nWhen relevant, link to:\n- CVE databases for security issues\n- Language RFCs or proposals\n- Standard library documentation\n- Known issue trackers\n\nFile v1.0.3:modules/fix-preparation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: remediation\nestimated_tokens: 450\nprogressive_loading: true\n---\n\n# Fix Preparation\n\nCreate minimal, idiomatic patches with detailed test coverage.\n\n## Minimal Patch Patterns\n\nApply smallest change that fixes the issue:\n\n**Guard Clause** (prevent invalid state)\n```rust\n// Before: crash on None\nlet value = config.value.unwrap();\n\n// After: guard clause\nlet Some(value) = config.value else {\n    return Err(Error::MissingConfig);\n};\n```\n\n**Validation** (check inputs)\n```python\n# Before: no validation\ndef process(count: int):\n    return items[:count]\n\n# After: boundary check\ndef process(count: int):\n    if count < 0 or count > len(items):\n        raise ValueError(f\"Invalid count: {count}\")\n    return items[:count]\n```\n\n**Resource Cleanup** (prevent leaks)\n```go\n// Before: file handle leak\nfile, err := os.Open(path)\ndata, _ := io.ReadAll(file)\n\n// After: defer cleanup\nfile, err := os.Open(path)\nif err != nil {\n    return err\n}\ndefer file.Close()\ndata, err := io.ReadAll(file)\n```\n\n## Idiomatic Fixes by Language\n\n### Rust\n- Use `?` operator for error propagation\n- Prefer pattern matching over `unwrap()`\n- Use `Option::ok_or()` for conversions\n- Apply ownership transfer instead of cloning\n\n```rust\n// Idiomatic error handling\nfn load_config() -> Result<Config, Error> {\n    let path = env::var(\"CONFIG_PATH\")\n        .map_err(|_| Error::MissingEnv)?;\n    let contents = fs::read_to_string(&path)?;\n    toml::from_str(&contents)\n        .map_err(Error::Parse)\n}\n```\n\n### Python\n- Use context managers for resources\n- Apply type hints for clarity\n- Use specific exception types\n- Prefer `pathlib` over string paths\n\n```python\n# Idiomatic resource handling\nfrom pathlib import Path\nfrom contextlib import contextmanager\n\ndef load_config(path: Path) -> dict:\n    if not path.exists():\n        raise FileNotFoundError(f\"Config not found: {path}\")\n    with path.open() as f:\n        return json.load(f)\n```\n\n### Go\n- Check errors immediately\n- Use `defer` for cleanup\n- Apply early returns\n- Wrap errors with context\n\n```go\n// Idiomatic error handling\nfunc LoadConfig(path string) (*Config, error) {\n    data, err := os.ReadFile(path)\n    if err != nil {\n        return nil, fmt.Errorf(\"reading config: %w\", err)\n    }\n\n    var cfg Config\n    if err := json.Unmarshal(data, &cfg); err != nil {\n        return nil, fmt.Errorf(\"parsing config: %w\", err)\n    }\n\n    return &cfg, nil\n}\n```\n\n### TypeScript\n- Use strict null checks\n- Apply discriminated unions\n- Prefer async/await over promises\n- Use type guards for narrowing\n\n```typescript\n// Idiomatic null handling\nfunction processValue(value: string | null): Result {\n    if (value === null) {\n        throw new Error(\"Value required\");\n    }\n    // TypeScript knows value is string here\n    return { data: value.toLowerCase() };\n}\n```\n\n## Test Coverage Requirements\n\nEvery fix must include tests following Red → Green pattern:\n\n### 1. Red: Write Failing Test\n```rust\n#[test]\nfn test_config_missing_value() {\n    let config = Config { value: None };\n    // This should fail before fix\n    assert!(process_config(&config).is_err());\n}\n```\n\n### 2. Green: Apply Fix\nImplement the minimal change to pass the test.\n\n### 3. Verify: Run Test Suite\n```bash\ncargo test\npytest -v\ngo test ./...\nnpm test\n```\n\n## Test Categories\n\n**Unit Tests**: Test individual functions in isolation\n```python\ndef test_boundary_validation():\n    with pytest.raises(ValueError):\n        process(count=-1)\n```\n\n**Integration Tests**: Test component interactions\n```rust\n#[test]\nfn test_config_loading_integration() {\n    let cfg = load_config(\"test.toml\").unwrap();\n    assert_eq!(cfg.value, Some(42));\n}\n```\n\n**Regression Tests**: Prevent bug recurrence\n```go\nfunc TestNoPanicOnNilValue(t *testing.T) {\n    // Regression test for issue #123\n    result, err := Process(nil)\n    require.Error(t, err)\n    assert.Nil(t, result)\n}\n```\n\n## Explanation Requirements\n\nFor each fix, document:\n1. **What changed**: Specific code modifications\n2. **Why it works**: Mechanism that prevents the bug\n3. **Best practice**: Link to language idioms or patterns\n4. **Trade-offs**: Performance, complexity, or maintainability impact\n\nFile v1.0.3:modules/language-detection.md\n\n---\nparent_skill: pensive:bug-review\ncategory: detection\nestimated_tokens: 250\nprogressive_loading: true\n---\n\n# Language Detection and Expertise Framing\n\nIdentify project languages and establish appropriate expertise context.\n\n## Manifest Heuristics\n\nUse manifest files to detect primary languages:\n\n| Manifest | Language | Ecosystem |\n|----------|----------|-----------|\n| `Cargo.toml` | Rust | cargo |\n| `package.json` | JavaScript/TypeScript | npm/yarn/pnpm |\n| `go.mod` | Go | go modules |\n| `pyproject.toml`, `setup.py` | Python | pip/poetry/uv |\n| `pom.xml`, `build.gradle` | Java | maven/gradle |\n| `*.csproj` | C# | dotnet |\n\n## Version Constraints\n\nExtract and note version requirements:\n\n**Rust**: Check MSRV (Minimum Supported Rust Version)\n```toml\n[package]\nrust-version = \"1.70.0\"\n```\n\n**Python**: Check required version\n```toml\n[project]\nrequires-python = \">=3.8\"\n```\n\n**Node**: Check engine constraints\n```json\n\"engines\": {\n  \"node\": \">=18.0.0\"\n}\n```\n\n**Go**: Check minimum version\n```go\ngo 1.21\n```\n\n## Expertise Persona\n\nFrame appropriate expertise based on detected languages:\n\n**Rust**: \"Staff engineer specializing in Rust systems programming with expertise in ownership, lifetimes, and async runtimes\"\n\n**Python**: \"Senior Python developer with expertise in type systems, async patterns, and performance optimization\"\n\n**Go**: \"Go engineer with deep understanding of concurrency, channels, and idiomatic error handling\"\n\n**TypeScript**: \"TypeScript expert focused on type safety, React patterns, and async workflows\"\n\nState this persona explicitly to establish review context and credibility.\n\nFile v1.0.3:skill-card.md\n\n## Description: <br>\nHunts bugs with evidence trails. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to review code for potential bugs, investigate bug reports or production issues, prepare minimal fixes, and document verification evidence before releases or security audits. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Review bundles can include code diffs and repo-relative evidence that may be sent to the selected reviewer provider. <br>\nMitigation: Keep secrets out of diffs, review the default web-search behavior, and choose narrower engine or option settings when working on highly confidential code. <br>\nRisk: Bug findings or proposed patches can be incorrect or incomplete. <br>\nMitigation: Require precise file and line evidence, run project tests and static analyzers, and review proposed changes before applying them. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/athola/nm-pensive-bug-review) <br>\n- [Pensive Plugin Homepage](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, guidance] <br>\n**Output Format:** [Markdown with code diffs, shell command blocks, and evidence notes] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Findings are expected to include precise file and line references, severity, root cause, impact, proposed fixes, test updates, and command evidence.] <br>\n\n## Skill Version(s): <br>\n1.0.3 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.2: 6 files, 9043 bytes\n\nFiles: modules/defect-documentation.md (2568b), modules/fix-preparation.md (4190b), modules/language-detection.md (1614b), skill-card.md (2259b), SKILL.md (6810b), _meta.json (140b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: bug-review\ndescription: Bug hunting with evidence trails: find defects, document them, and verify fixes\nversion: 1.9.5\ntriggers:\n  - bugs\n  - defects\n  - debugging\n  - code-quality\n  - fixes\n  - verification\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83d\\udd0d\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.imbue:proof-of-work\", \"night-market.imbue:diff-analysis/modules/risk-assessment-framework\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Quick Start](#quick-start)\n- [When to Use](#when-to-use)\n- [Required TodoWrite Items](#required-todowrite-items)\n- [Progressive Loading](#progressive-loading)\n- [Workflow](#workflow)\n- [Step 1: Detect Languages (`bug-review:language-detected`)](#step-1:-detect-languages-(bug-review:language-detected))\n- [Step 2: Plan Reproduction (`bug-review:repro-plan`)](#step-2:-plan-reproduction-(bug-review:repro-plan))\n- [Step 3: Document Defects (`bug-review:defects-documented`)](#step-3:-document-defects-(bug-review:defects-documented))\n- [Step 4: Prepare Fixes (`bug-review:fixes-prepared`)](#step-4:-prepare-fixes-(bug-review:fixes-prepared))\n- [Step 5: Verification Plan (`bug-review:verification-plan`)](#step-5:-verification-plan-(bug-review:verification-plan))\n- [Defect Classification (Condensed)](#defect-classification-(condensed))\n- [Output Format](#output-format)\n- [Summary](#summary)\n- [Defects Found](#defects-found)\n- [[D1] file.rs:142 - Title](#[d1]-filers:142---title)\n- [Proposed Fixes](#proposed-fixes)\n- [Fix for D1](#fix-for-d1)\n- [Test Updates](#test-updates)\n- [Evidence](#evidence)\n- [Best Practices](#best-practices)\n- [Exit Criteria](#exit-criteria)\n\n\n# Bug Review Workflow\n\nSystematic bug identification and fixing with language-specific expertise.\n\n## Quick Start\n\n```bash\n/bug-review\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## When To Use\n\n- Reviewing code for potential bugs\n- After receiving bug reports\n- Before major releases\n- During security audits\n- Investigating production issues\n\n## When NOT To Use\n\n- Test coverage audit - use test-review instead\n\n## Required TodoWrite Items\n\n1. `bug-review:language-detected`\n2. `bug-review:repro-plan`\n3. `bug-review:defects-documented`\n4. `bug-review:fixes-prepared`\n5. `bug-review:verification-plan`\n\n## Progressive Loading\n\nLoad additional context as needed:\n- **Language Detection**: `@include modules/language-detection.md` - Manifest heuristics, expertise framing, version constraints\n- **Defect Documentation**: `@include modules/defect-documentation.md` - Severity classification, root cause analysis, static analyzers\n- **Fix Preparation**: `@include modules/fix-preparation.md` - Minimal patches, idiomatic patterns, test coverage\n\n## Workflow\n\n### Step 1: Detect Languages (`bug-review:language-detected`)\n\nIdentify dominant languages using manifest files (Cargo.toml → Rust, package.json → Node, etc.).\n\nState expertise persona appropriate for the language ecosystem.\n\nNote version constraints (MSRV, Python versions, Node engines).\n\n**Progressive**: Load `modules/language-detection.md` for detailed manifest heuristics.\n\n### Step 2: Plan Reproduction (`bug-review:repro-plan`)\n\nIdentify reproduction methods:\n- Unit/integration test suites\n- Fuzzing tools\n- Manual reproduction commands\n\nDocument exact commands:\n```bash\ncargo test -p core\npytest tests/test_api.py\nnpm test -- pkg\n```\n**Verification:** Run `pytest -v tests/test_api.py` to verify.\n\nCapture blockers and propose mocks when dependencies unavailable.\n\n### Step 3: Document Defects (`bug-review:defects-documented`)\n\nReview code line-by-line, logging each bug with:\n- **File:line reference**: Precise location\n- **Severity**: Critical, High, Medium, Low\n- **Root cause**: Logic error, API misuse, concurrency, resource leak\n- **Impact**: What breaks and how\n\nRun static analyzers (`cargo clippy`, `ruff check`, `golangci-lint`, `eslint`).\n\nUse `imbue:proof-of-work` for reproducible capture.\n\n**Progressive**: Load `modules/defect-documentation.md` for classification details and analyzer commands.\n\n### Step 4: Prepare Fixes (`bug-review:fixes-prepared`)\n\nDraft minimal, idiomatic patches using language best practices:\n- Guard clauses (Rust: pattern matching, Python: early returns)\n- Resource cleanup (Go: defer, Python: context managers)\n- Error propagation (Rust: ?, Go: wrapped errors)\n\nCreate tests following Red → Green pattern:\n1. Write failing test\n2. Apply minimal fix\n3. Verify test passes\n\n**Progressive**: Load `modules/fix-preparation.md` for language-specific patterns and test strategies.\n\n### Step 5: Verification Plan (`bug-review:verification-plan`)\n\nExecute reproduction steps with fixes applied.\n\nCapture evidence:\n- Test output logs\n- Benchmark comparisons\n- Coverage reports\n\nDocument remaining risks using `imbue:diff-analysis/modules/risk-assessment-framework`.\n\nAssign owners and deadlines for follow-up items.\n\n## Defect Classification (Condensed)\n\n**Severity**: Critical (crash/data loss) → High (broken features) → Medium (degraded UX) → Low (edge cases)\n\n**Root Causes**: Logic errors | API misuse | Concurrency issues | Resource leaks | Validation gaps\n\n## Output Format\n\n```markdown\n## Summary\n[Brief scope description]\n\n## Defects Found\n### [D1] file.rs:142 - Title\n- Severity: High\n- Root Cause: Logic error\n- Impact: Data corruption possible\n- Fix: [description]\n\n## Proposed Fixes\n### Fix for D1\n[code diff with explanation]\n\n## Test Updates\n[new/updated tests with Red → Green verification]\n\n## Evidence\n- Commands executed\n- Logs and outputs\n- External references\n```\n**Verification:** Run `pytest -v` to verify tests pass.\n\n## Best Practices\n\n1. **Evidence-based**: Every finding has file:line reference\n2. **Reproducible**: Clear steps to reproduce each bug\n3. **Minimal fixes**: Smallest change that fixes the issue\n4. **Test coverage**: Every fix has corresponding test\n5. **Risk awareness**: Document remaining risks with severity scoring\n\n## Exit Criteria\n\n- All defects documented with precise references\n- Fixes prepared with test coverage verified\n- Verification plan includes commands and expected outputs\n- Remaining risks assessed and owners assigned\n## Troubleshooting\n\n### Common Issues\n\n**Command not found**\nEnsure all dependencies are installed and in PATH\n\n**Permission errors**\nCheck file permissions and run with appropriate privileges\n\n**Unexpected behavior**\nEnable verbose logging with `--verbose` flag\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-bug-review\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1778293151339\n}\n\nFile v1.0.2:modules/defect-documentation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: analysis\nestimated_tokens: 400\nprogressive_loading: true\ndependencies: [imbue:proof-of-work]\n---\n\n# Defect Documentation\n\nSystematic defect identification with precise file references and severity classification.\n\n## File/Line References\n\nEvery defect must include:\n- **File path**: Absolute or relative from project root\n- **Line number**: Exact location of issue\n- **Function/method**: Containing scope\n- **Code snippet**: 3-5 lines of context\n\nExample:\n```\nsrc/parser/tokenizer.rs:142 in `parse_string()`\n```\n\n## Severity Classification\n\n| Level | Description | Impact | Response Time |\n|-------|-------------|--------|---------------|\n| **Critical** | Crash, data loss, security vulnerability | Service down, data corruption | Immediate |\n| **High** | Major functionality broken | Core features unusable | This sprint |\n| **Medium** | Degraded experience, workaround exists | Reduced performance/UX | Next sprint |\n| **Low** | Minor issues, edge cases | Rare scenarios affected | Backlog |\n\n## Root Cause Categories\n\n### Logic Errors\n- Incorrect conditions (off-by-one, wrong operator)\n- Null/None handling gaps\n- Missing validation\n- Boundary condition failures\n\n### API Misuse\n- Wrong parameter types/order\n- Deprecated method usage\n- Incorrect error handling\n- Lifetime/ownership violations (Rust)\n\n### Concurrency Issues\n- Race conditions\n- Deadlocks\n- Data races\n- Improper synchronization\n- Channel misuse (Go)\n\n### Resource Leaks\n- Memory leaks\n- File handle leaks\n- Connection pool exhaustion\n- Lock not released\n\n### Validation Gaps\n- Missing input validation\n- Insufficient boundary checks\n- Type coercion errors\n- Injection vulnerabilities\n\n## Static Analyzer Commands\n\nRun language-specific linters:\n\n**Rust**\n```bash\ncargo clippy --all-targets --all-features\n```\n\n**Python**\n```bash\nruff check .\nmypy src/\n```\n\n**Go**\n```bash\ngolangci-lint run\nstaticcheck ./...\n```\n\n**JavaScript/TypeScript**\n```bash\neslint .\ntsc --noEmit\n```\n\n**Java**\n```bash\n./gradlew check\nspotbugs\n```\n\n## Documentation Format\n\n```markdown\n### [D1] file.rs:142 - Null pointer dereference\n\n- **Severity**: Critical\n- **Root Cause**: Logic error - missing null check\n- **Impact**: Crash on malformed input\n- **Evidence**: Line 142 dereferences `config.value` without validation\n- **Context**:\n  ```rust\n  let value = config.value.unwrap(); // PANIC if None\n  ```\n```\n\n## Cross-References\n\nWhen relevant, link to:\n- CVE databases for security issues\n- Language RFCs or proposals\n- Standard library documentation\n- Known issue trackers\n\nFile v1.0.2:modules/fix-preparation.md\n\n---\nparent_skill: pensive:bug-review\ncategory: remediation\nestimated_tokens: 450\nprogressive_loading: true\n---\n\n# Fix Preparation\n\nCreate minimal, idiomatic patches with detailed test coverage.\n\n## Minimal Patch Patterns\n\nApply smallest change that fixes the issue:\n\n**Guard Clause** (prevent invalid state)\n```rust\n// Before: crash on None\nlet value = config.value.unwrap();\n\n// After: guard clause\nlet Some(value) = config.value else {\n    return Err(Error::MissingConfig);\n};\n```\n\n**Validation** (check inputs)\n```python\n# Before: no validation\ndef process(count: int):\n    return items[:count]\n\n# After: boundary check\ndef process(count: int):\n    if count < 0 or count > len(items):\n        raise ValueError(f\"Invalid count: {count}\")\n    return items[:count]\n```\n\n**Resource Cleanup** (prevent leaks)\n```go\n// Before: file handle leak\nfile, err := os.Open(path)\ndata, _ := io.ReadAll(file)\n\n// After: defer cleanup\nfile, err := os.Open(path)\nif err != nil {\n    return err\n}\ndefer file.Close()\ndata, err := io.ReadAll(file)\n```\n\n## Idiomatic Fixes by Language\n\n### Rust\n- Use `?` operator for error propagation\n- Prefer pattern matching over `unwrap()`\n- Use `Option::ok_or()` for conversions\n- Apply ownership transfer instead of cloning\n\n```rust\n// Idiomatic error handling\nfn load_config() -> Result<Config, Error> {\n    let path = env::var(\"CONFIG_PATH\")\n        .map_err(|_| Error::MissingEnv)?;\n    let contents = fs::read_to_string(&path)?;\n    toml::from_str(&contents)\n        .map_err(Error::Parse)\n}\n```\n\n### Python\n- Use context managers for resources\n- Apply type hints for clarity\n- Use specific exception types\n- Prefer `pathlib` over string paths\n\n```python\n# Idiomatic resource handling\nfrom pathlib import Path\nfrom contextlib import contextmanager\n\ndef load_config(path: Path) -> dict:\n    if not path.exists():\n        raise FileNotFoundError(f\"Config not found: {path}\")\n    with path.open() as f:\n        return json.load(f)\n```\n\n### Go\n- Check errors immediately\n- Use `defer` for cleanup\n- Apply early returns\n- Wrap errors with context\n\n```go\n// Idiomatic error handling\nfunc LoadConfig(path string) (*Config, error) {\n    data, err := os.ReadFile(path)\n    if err != nil {\n        return nil, fmt.Errorf(\"reading config: %w\", err)\n    }\n\n    var cfg Config\n    if err := json.Unmarshal(data, &cfg); err != nil {\n        return nil, fmt.Errorf(\"parsing config: %w\", err)\n    }\n\n    return &cfg, nil\n}\n```\n\n### TypeScript\n- Use strict null checks\n- Apply discriminated unions\n- Prefer async/await over promises\n- Use type guards for narrowing\n\n```typescript\n// Idiomatic null handling\nfunction processValue(value: string | null): Result {\n    if (value === null) {\n        throw new Error(\"Value required\");\n    }\n    // TypeScript knows value is string here\n    return { data: value.toLowerCase() };\n}\n```\n\n## Test Coverage Requirements\n\nEvery fix must include tests following Red → Green pattern:\n\n### 1. Red: Write Failing Test\n```rust\n#[test]\nfn test_config_missing_value() {\n    let config = Config { value: None };\n    // This should fail before fix\n    assert!(process_config(&config).is_err());\n}\n```\n\n### 2. Green: Apply Fix\nImplement the minimal change to pass the test.\n\n### 3. Verify: Run Test Suite\n```bash\ncargo test\npytest -v\ngo test ./...\nnpm test\n```\n\n## Test Categories\n\n**Unit Tests**: Test individual functions in isolation\n```python\ndef test_boundary_validation():\n    with pytest.raises(ValueError):\n        process(count=-1)\n```\n\n**Integration Tests**: Test component interactions\n```rust\n#[test]\nfn test_config_loading_integration() {\n    let cfg = load_config(\"test.toml\").unwrap();\n    assert_eq!(cfg.value, Some(42));\n}\n```\n\n**Regression Tests**: Prevent bug recurrence\n```go\nfunc TestNoPanicOnNilValue(t *testing.T) {\n    // Regression test for issue #123\n    result, err := Process(nil)\n    require.Error(t, err)\n    assert.Nil(t, result)\n}\n```\n\n## Explanation Requirements\n\nFor each fix, document:\n1. **What changed**: Specific code modifications\n2. **Why it works**: Mechanism that prevents the bug\n3. **Best practice**: Link to language idioms or patterns\n4. **Trade-offs**: Performance, complexity, or maintainability impact\n\nFile v1.0.2:modules/language-detection.md\n\n---\nparent_skill: pensive:bug-review\ncategory: detection\nestimated_tokens: 250\nprogressive_loading: true\n---\n\n# Language Detection and Expertise Framing\n\nIdentify project languages and establish appropriate expertise context.\n\n## Manifest Heuristics\n\nUse manifest files to detect primary languages:\n\n| Manifest | Language | Ecosystem |\n|----------|----------|-----------|\n| `Cargo.toml` | Rust | cargo |\n| `package.json` | JavaScript/TypeScript | npm/yarn/pnpm |\n| `go.mod` | Go | go modules |\n| `pyproject.toml`, `setup.py` | Python | pip/poetry/uv |\n| `pom.xml`, `build.gradle` | Java | maven/gradle |\n| `*.csproj` | C# | dotnet |\n\n## Version Constraints\n\nExtract and note version requirements:\n\n**Rust**: Check MSRV (Minimum Supported Rust Version)\n```toml\n[package]\nrust-version = \"1.70.0\"\n```\n\n**Python**: Check required version\n```toml\n[project]\nrequires-python = \">=3.8\"\n```\n\n**Node**: Check engine constraints\n```json\n\"engines\": {\n  \"node\": \">=18.0.0\"\n}\n```\n\n**Go**: Check minimum version\n```go\ngo 1.21\n```\n\n## Expertise Persona\n\nFrame appropriate expertise based on detected languages:\n\n**Rust**: \"Staff engineer specializing in Rust systems programming with expertise in ownership, lifetimes, and async runtimes\"\n\n**Python**: \"Senior Python developer with expertise in type systems, async patterns, and performance optimization\"\n\n**Go**: \"Go engineer with deep understanding of concurrency, channels, and idiomatic error handling\"\n\n**TypeScript**: \"TypeScript expert focused on type safety, React patterns, and async workflows\"\n\nState this persona explicitly to establish review context and credibility.\n\nFile v1.0.2:skill-card.md\n\n## Description: <br>\nSystematic bug hunting by detecting languages, planning reproduction, documenting defects, preparing minimal fixes, and verifying with evidence-based workflows. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineering teams use this skill to review code for bugs, document defects with evidence, prepare minimal fixes, and plan verification before releases, audits, or production investigations. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The workflow can propose patches, tests, lint commands, or build commands that may be incorrect or unsafe for the target repository. <br>\nMitigation: Review proposed code and commands before applying or running them, especially when working with untrusted code. <br>\nRisk: The stated expertise persona and external Night Market plugin references may be mistaken for verified credentials or separately reviewed dependencies. <br>\nMitigation: Treat persona language as workflow framing, and evaluate any referenced external plugin independently before installing it. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/nm-pensive-bug-review) <br>\n- [Night Market pensive plugin page](https://github.com/athola/claude-night-market/tree/master/plugins/pensive) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, guidance] <br>\n**Output Format:** [Markdown with defect reports, proposed fixes, test updates, evidence, and inline shell commands] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include file and line references, severity labels, root-cause notes, code diffs, verification commands, logs, and remaining-risk notes.] <br>\n\n## Skill Version(s): <br>\n1.0.2 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.1: 5 files, 7835 bytes\n\nFiles: modules/defect-documentation.md (2568b), modules/fix-preparation.md (4190b), modules/language-detection.md (1614b), SKILL.md (6810b), _meta.json (140b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: bug-review\ndescription: Bug hunting with evidence trails: find defects, document them, and verify fixes\nversion: 1.9.4\ntriggers:\n  - bugs\n  - defects\n  - debugging\n  - code-quality\n  - fixes\n  - verification\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83d\\udd0d\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.imbue:proof-of-work\", \"night-market.imbue:diff-analysis/modules/risk-assessment-framework\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Quick Start](#quick-start)\n- [When to Use](#when-to-use)\n- [Required TodoWrite Items](#required-todowrite-items)\n- [Progressive Loading](#progressive-loading)\n- [Workflow](#workflow)\n- [Step 1: Detect Languages (`bug-review:language-detected`)](#step-1:-detect-languages-(bug-review:language-detected))\n- [Step 2: Plan Reproduction (`bug-review:repro-plan`)](#step-2:-plan-reproduction-(bug-review:repro-plan))\n- [Step 3: Document Defects (`bug-review:defects-documented`)](#step-3:-document-defects-(bug-review:defects-documented))\n- [Step 4: Prepare Fixes (`bug-review:fixes-prepared`)](#step-4:-prepare-fixes-(bug-review:fixes-prepared))\n- [Step 5: Verification Plan (`bug-review:verification-plan`)](#step-5:-verification-plan-(bug-review:verification-plan))\n- [Defect Classification (Condensed)](#defect-classification-(condensed))\n- [Output Format](#output-format)\n- [Summary](#summary)\n- [Defects Found](#defects-found)\n- [[D1] file.rs:142 - Title](#[d1]-filers:142---title)\n- [Proposed Fixes](#proposed-fixes)\n- [Fix for D1](#fix-for-d1)\n- [Test Updates]\n\nArchive v1.0.0: 5 files, 7835 bytes\n\nFiles: modules/defect-documentation.md (2568b), modules/fix-preparation.md (4190b), modules/language-detection.md (1614b), SKILL.md (6810b), _meta.json (140b)","readmeExcerpt":"Skill: bug-review Owner: athola Summary: Hunts bugs with evidence trails Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:18:31.877Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:38:47.959Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:55:30.129Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:03:54.050Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:21:57.800Z | user Release v1.9.13 v1.9.12 | 2026-06-19","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"/bug-review"},{"language":"bash","snippet":"cargo test -p core\npytest tests/test_api.py\nnpm test -- pkg"},{"language":"markdown","snippet":"## Summary\n[Brief scope description]\n\n## Defects Found\n### [D1] file.rs:142 - Title\n- Severity: High\n- Root Cause: Logic error\n- Impact: Data corruption possible\n- Fix: [description]\n\n## Proposed Fixes\n### Fix for D1\n[code diff with explanation]\n\n## Test Updates\n[new/updated tests with Red → Green verification]\n\n## Evidence\n- Commands executed\n- Logs and outputs\n- External references"},{"language":"text","snippet":"src/parser/tokenizer.rs:142 in `parse_string()`"},{"language":"bash","snippet":"cargo clippy --all-targets --all-features"},{"language":"bash","snippet":"ruff check .\nmypy src/"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: bug-review\ndescription: Hunts bugs with evidence trails\nversion: 1.9.8\ntriggers:\n  - bugs\n  - defects\n  - debugging\n  - code-quality\n  - fixes\n  - verification\n  - investigating unexpected behavior or before merging code with potential hidden defects\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/pensive\", \"emoji\": \"\\ud83d\\udd0d\", \"requires\": {\"config\": [\"night-market.pensive:shared\", \"night-market.imbue:proof-of-work\", \"night-market.imbue:diff-analysis/modules/risk-assessment-framework\"]}}}\nsource: claude-night-market\nsource_plugin: pensive\n---\n\n> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Quick Start](#quick-start)\n- [When to Use](#when-to-use)\n- [Required TodoWrite Items](#required-todowrite-items)\n- [Progressive Loading](#progressive-loading)\n- [Workflow](#workflow)\n- [Step 1: Detect Languages (`bug-review:language-detected`)](#step-1:-detect-languages-(bug-review:language-detected))\n- [Step 2: Plan Reproduction (`bug-review:repro-plan`)](#step-2:-plan-reproduction-(bug-review:repro-plan))\n- [Step 3: Document Defects (`bug-review:defects-documented`)](#step-3:-document-defects-(bug-review:defects-documented))\n- [Step 4: Prepare Fixes (`bug-review:fixes-prepared`)](#step-4:-prepare-fixes-(bug-review:fixes-prepared))\n- [Step 5: Verification Plan (`bug-review:verification-plan`)](#step-5:-verification-plan-(bug-review:verification-plan))\n- [Defect Classification (Condensed)](#defect-classification-(condensed))\n- [Output Format](#output-format)\n- [Summary](#summary)\n- [Defects Found](#defects-found)\n- [[D1] file.rs:142 - Title](#[d1]-filers:142---title)\n- [Proposed Fixes](#proposed-fixes)\n- [Fix for D1](#fix-for-d1)\n- [Test Updates](#test-updates)\n- [Evidence](#evidence)\n- [Best Practices](#best-practices)\n- [Exit Criteria](#exit-criteria)\n\n\n# Bug Review Workflow\n\nSystematic bug identification and fixing with language-specific expertise.\n\n## Quick Start\n\n```bash\n/bug-review\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## When To Use\n\n- Reviewing code for potential bugs\n- After receiving bug reports\n- Before major releases\n- During security audits\n- Investigating production issues\n\n## When NOT To Use\n\n- Test coverage audit - use test-review instead\n\n## Required TodoWrite Items\n\n1. `bug-review:language-detected`\n2. `bug-review:repro-plan`\n3. `bug-review:defects-documented`\n4. `bug-review:fixes-prepared`\n5. `bug-review:verification-plan`\n\n## Progressive Loading\n\nLoad additional context as needed:\n- **Language Detection**: `@include modules/language-detection.md` - Manifest heuristics, expertise framing, version constraints\n- **Defect Documentation**: `@include modules/defect-documentation.md` - Severity classification, root cause analy"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-pensive-bug-review\",\n  \"version\": \"1.9.19\",\n  \"publishedAt\": 1787750311877\n}"},{"path":"modules/defect-documentation.md","content":"---\nparent_skill: pensive:bug-review\ncategory: analysis\nestimated_tokens: 400\nprogressive_loading: true\ndependencies: [imbue:proof-of-work]\n---\n\n# Defect Documentation\n\nSystematic defect identification with precise file references and severity classification.\n\n## File/Line References\n\nEvery defect must include:\n- **File path**: Absolute or relative from project root\n- **Line number**: Exact location of issue\n- **Function/method**: Containing scope\n- **Code snippet**: 3-5 lines of context\n\nExample:\n```\nsrc/parser/tokenizer.rs:142 in `parse_string()`\n```\n\n## Severity Classification\n\n| Level | Description | Impact | Response Time |\n|-------|-------------|--------|---------------|\n| **Critical** | Crash, data loss, security vulnerability | Service down, data corruption | Immediate |\n| **High** | Major functionality broken | Core features unusable | This sprint |\n| **Medium** | Degraded experience, workaround exists | Reduced performance/UX | Next sprint |\n| **Low** | Minor issues, edge cases | Rare scenarios affected | Backlog |\n\n## Root Cause Categories\n\n### Logic Errors\n- Incorrect conditions (off-by-one, wrong operator)\n- Null/None handling gaps\n- Missing validation\n- Boundary condition failures\n\n### API Misuse\n- Wrong parameter types/order\n- Deprecated method usage\n- Incorrect error handling\n- Lifetime/ownership violations (Rust)\n\n### Concurrency Issues\n- Race conditions\n- Deadlocks\n- Data races\n- Improper synchronization\n- Channel misuse (Go)\n\n### Resource Leaks\n- Memory leaks\n- File handle leaks\n- Connection pool exhaustion\n- Lock not released\n\n### Validation Gaps\n- Missing input validation\n- Insufficient boundary checks\n- Type coercion errors\n- Injection vulnerabilities\n\n## Static Analyzer Commands\n\nRun language-specific linters:\n\n**Rust**\n```bash\ncargo clippy --all-targets --all-features\n```\n\n**Python**\n```bash\nruff check .\nmypy src/\n```\n\n**Go**\n```bash\ngolangci-lint run\nstaticcheck ./...\n```\n\n**JavaScript/TypeScript**\n```bash\neslint .\ntsc --noEmit\n```\n\n**Java**\n```bash\n./gradlew check\nspotbugs\n```\n\n## Documentation Format\n\n```markdown\n### [D1] file.rs:142 - Null pointer dereference\n\n- **Severity**: Critical\n- **Root Cause**: Logic error - missing null check\n- **Impact**: Crash on malformed input\n- **Evidence**: Line 142 dereferences `config.value` without validation\n- **Context**:\n  ```rust\n  let value = config.value.unwrap(); // PANIC if None\n  ```\n```\n\n## Cross-References\n\nWhen relevant, link to:\n- CVE databases for security issues\n- Language RFCs or proposals\n- Standard library documentation\n- Known issue trackers"},{"path":"modules/fix-preparation.md","content":"---\nparent_skill: pensive:bug-review\ncategory: remediation\nestimated_tokens: 450\nprogressive_loading: true\n---\n\n# Fix Preparation\n\nCreate minimal, idiomatic patches with detailed test coverage.\n\n## Minimal Patch Patterns\n\nApply smallest change that fixes the issue:\n\n**Guard Clause** (prevent invalid state)\n```rust\n// Before: crash on None\nlet value = config.value.unwrap();\n\n// After: guard clause\nlet Some(value) = config.value else {\n    return Err(Error::MissingConfig);\n};\n```\n\n**Validation** (check inputs)\n```python\n# Before: no validation\ndef process(count: int):\n    return items[:count]\n\n# After: boundary check\ndef process(count: int):\n    if count < 0 or count > len(items):\n        raise ValueError(f\"Invalid count: {count}\")\n    return items[:count]\n```\n\n**Resource Cleanup** (prevent leaks)\n```go\n// Before: file handle leak\nfile, err := os.Open(path)\ndata, _ := io.ReadAll(file)\n\n// After: defer cleanup\nfile, err := os.Open(path)\nif err != nil {\n    return err\n}\ndefer file.Close()\ndata, err := io.ReadAll(file)\n```\n\n## Idiomatic Fixes by Language\n\n### Rust\n- Use `?` operator for error propagation\n- Prefer pattern matching over `unwrap()`\n- Use `Option::ok_or()` for conversions\n- Apply ownership transfer instead of cloning\n\n```rust\n// Idiomatic error handling\nfn load_config() -> Result<Config, Error> {\n    let path = env::var(\"CONFIG_PATH\")\n        .map_err(|_| Error::MissingEnv)?;\n    let contents = fs::read_to_string(&path)?;\n    toml::from_str(&contents)\n        .map_err(Error::Parse)\n}\n```\n\n### Python\n- Use context managers for resources\n- Apply type hints for clarity\n- Use specific exception types\n- Prefer `pathlib` over string paths\n\n```python\n# Idiomatic resource handling\nfrom pathlib import Path\nfrom contextlib import contextmanager\n\ndef load_config(path: Path) -> dict:\n    if not path.exists():\n        raise FileNotFoundError(f\"Config not found: {path}\")\n    with path.open() as f:\n        return json.load(f)\n```\n\n### Go\n- Check errors immediately\n- Use `defer` for cleanup\n- Apply early returns\n- Wrap errors with context\n\n```go\n// Idiomatic error handling\nfunc LoadConfig(path string) (*Config, error) {\n    data, err := os.ReadFile(path)\n    if err != nil {\n        return nil, fmt.Errorf(\"reading config: %w\", err)\n    }\n\n    var cfg Config\n    if err := json.Unmarshal(data, &cfg); err != nil {\n        return nil, fmt.Errorf(\"parsing config: %w\", err)\n    }\n\n    return &cfg, nil\n}\n```\n\n### TypeScript\n- Use strict null checks\n- Apply discriminated unions\n- Prefer async/await over promises\n- Use type guards for narrowing\n\n```typescript\n// Idiomatic null handling\nfunction processValue(value: string | null): Result {\n    if (value === null) {\n        throw new Error(\"Value required\");\n    }\n    // TypeScript knows value is string here\n    return { data: value.toLowerCase() };\n}\n```\n\n## Test Coverage Requirements\n\nEvery fix must include tests following Red → Green pattern:\n\n### 1. Red: Write Failing Test\n```rust\n#[test]\nfn test_config_missing_"},{"path":"modules/language-detection.md","content":"---\nparent_skill: pensive:bug-review\ncategory: detection\nestimated_tokens: 250\nprogressive_loading: true\n---\n\n# Language Detection and Expertise Framing\n\nIdentify project languages and establish appropriate expertise context.\n\n## Manifest Heuristics\n\nUse manifest files to detect primary languages:\n\n| Manifest | Language | Ecosystem |\n|----------|----------|-----------|\n| `Cargo.toml` | Rust | cargo |\n| `package.json` | JavaScript/TypeScript | npm/yarn/pnpm |\n| `go.mod` | Go | go modules |\n| `pyproject.toml`, `setup.py` | Python | pip/poetry/uv |\n| `pom.xml`, `build.gradle` | Java | maven/gradle |\n| `*.csproj` | C# | dotnet |\n\n## Version Constraints\n\nExtract and note version requirements:\n\n**Rust**: Check MSRV (Minimum Supported Rust Version)\n```toml\n[package]\nrust-version = \"1.70.0\"\n```\n\n**Python**: Check required version\n```toml\n[project]\nrequires-python = \">=3.8\"\n```\n\n**Node**: Check engine constraints\n```json\n\"engines\": {\n  \"node\": \">=18.0.0\"\n}\n```\n\n**Go**: Check minimum version\n```go\ngo 1.21\n```\n\n## Expertise Persona\n\nFrame appropriate expertise based on detected languages:\n\n**Rust**: \"Staff engineer specializing in Rust systems programming with expertise in ownership, lifetimes, and async runtimes\"\n\n**Python**: \"Senior Python developer with expertise in type systems, async patterns, and performance optimization\"\n\n**Go**: \"Go engineer with deep understanding of concurrency, channels, and idiomatic error handling\"\n\n**TypeScript**: \"TypeScript expert focused on type safety, React patterns, and async workflows\"\n\nState this persona explicitly to establish review context and credibility."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Hunts bugs with evidence trails Skill: bug-review Owner: athola Summary: Hunts bugs with evidence trails Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:18:31.877Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:38:47.959Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:55:30.129Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:03:54.050Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:21:57.800Z | user Release v1.9.13 v1.9.12 | 2026-06-19","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1182,"uniquenessScore":58,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T05:44:08.578Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T05:44:08.578Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:48:42.041Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}