CtrlK
BlogDocsLog inGet started
Tessl Logo

bughunt

Fully autonomous bug hunting pipeline — discover bugs in a scoped area using parallel subagents, independently triage each finding, fix confirmed issues with subagents, then audit all fixes against repo constraints and target platforms. Runs end-to-end without user interaction.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/bughunt/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced orchestration skill with copy-paste prompt templates, explicit validation checkpoints, and thoughtful handling of null results and prior-run memory. Its weaknesses are repetitive autonomy/parallelism instructions that could be consolidated and a report format that is referenced throughout but never specified.

Suggestions

Consolidate the repeated autonomy instructions — state 'run all phases without pausing for user input; after each phase, proceed immediately to the next' once in the header and delete the per-phase repetitions.

State 'launch all subagents for a phase in a single message' once in the Guidance section instead of repeating it in Phases 2, 3, and 4.

Define the report's structure (sections for summary counts, findings, rejection table, severity trend) once, since it is written to incrementally throughout but never specified.

DimensionReasoningScore

Conciseness

The core guidance earns its place, but the autonomy instruction is repeated roughly six times ('never block on user input', 'do not wait for user input' at the end of Phases 2-4, 'Fully autonomous', 'Log, don't ask') and 'send all Agent calls in a single message' appears four times. This is more than the minor trimmable padding of a 4 but well short of the heavily padded verbosity of a 2.

3 / 5

Actionability

The skill provides copy-paste-ready subagent prompt templates for all three agent phases, concrete commands ('bash -n', 'python -m py_compile', 'tsc --noEmit', 'mkdir -p {OUTPUT_DIR}/evidence'), and a specific list of platform traps with named flags. As an instruction-only orchestration skill its guidance is fully executable and covers the common cases, matching the 5 anchor.

5 / 5

Workflow Clarity

Five phases are numbered and clearly sequenced with explicit validation checkpoints: adversarial triage of every finding, syntax/parse checks after applying edits, and a five-step audit with a fix-and-re-run feedback loop ('Apply the correction directly... Re-run the relevant check to confirm'). Not 4: the error-recovery loops and checkpoints are explicit, satisfying the 5 anchor.

5 / 5

Progressive Disclosure

The body is a well-sectioned single file with clear headers, a parameters table, and no nested references — good structure for a self-contained skill. It is not 5 because at ~200 lines with no bundle files, content like the subagent prompt templates or the platform-portability trap list could plausibly live in one-level-deep reference files to slim the always-loaded context; it is not 3 because what is inline is appropriately placed and easy to navigate.

4 / 5

Total

17

/

20

Passed

Description

71%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, concrete description that clearly communicates a four-stage autonomous bug-hunting pipeline with specific mechanisms. Its main weakness is the absence of any 'Use when...' trigger clause, which both caps completeness and leaves triggering contexts implicit.

Suggestions

Add an explicit trigger clause, e.g. 'Use when the user asks to find and fix bugs in a specific area, hunt for defects, or run an autonomous bug sweep over a module.'

Include common user synonyms such as 'defects', 'debug', or 'bug sweep' to broaden natural trigger coverage.

State the invocation shape (e.g. a scope argument like a directory or subsystem) so users know what input the skill expects.

DimensionReasoningScore

Specificity

The description lists four concrete pipeline actions — 'discover bugs in a scoped area using parallel subagents, independently triage each finding, fix confirmed issues with subagents, then audit all fixes against repo constraints and target platforms' — with mechanisms and targets named for each. It is comprehensive across the pipeline rather than having minor gaps, so it matches the 5 anchor over the 4.

5 / 5

Completeness

The 'what' is explicit and detailed, but there is no 'Use when...' clause or equivalent explicit trigger guidance — the 'when' is only weakly implied by 'in a scoped area'. Per the judging guideline, a missing 'Use when...' clause caps completeness at 3; it is not 4 because 'when' is absent rather than merely imprecise.

3 / 5

Trigger Term Quality

Natural phrases users would say are present ('bug hunting', 'discover bugs', 'triage', 'fix confirmed issues', 'audit'), giving good keyword coverage. It falls short of 5 because common synonyms like 'defects', 'debugging', or 'code review' variations are missing, but exceeds 3 because the natural terms go beyond a bare domain mention.

4 / 5

Distinctiveness Conflict Risk

'Fully autonomous bug hunting pipeline' with subagent orchestration, triage, and platform audit is a clear niche unlikely to trigger for unrelated skills. Minor overlap risk remains with generic debugging or code-review skills since no trigger phrase distinguishes those contexts, placing it at 4 rather than 5.

4 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
av/harbor
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.