Review a code change for off-by-one and boundary errors, null propagation, changed sentinel meanings, tooling and provisioning drift, race conditions, invalid state transitions, React effect cleanup gaps, and broken error propagation. Use when reviewing for logic bugs, behavioral correctness, or edge cases that tests miss.
76
95%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
Passed
No findings from the security scan
Review a change by mentally executing it, tracing inputs through branches and state across calls, to find bugs that pass tests because nobody tested that input.
"undefined" in a string or NaN in arithmetic.null, undefined, empty array or object, or fallback enum, so one value now means several states. Check call sites and user-visible rendering, metrics and actions for the new path; not crashing is not enough if the message or action is false.PATH and exported variable propagation, child and background process inheritance, consistency between paired local and cloud fallbacks, quoting and interpolation in generated scripts, and docs or config lists that drift from the executable source of truth. For a check, build or deploy step, confirm it reproduces the real thing's build context, working directory, prepared directories and environment, not merely that it runs.useEffect exit path and check that each mutation before return has matching cleanup, including "already loaded" guards, early returns after touching window, script injection, listeners, timers, and DOM append and remove pairs.Trace boundary math with concrete values at the edges. Follow each changed return value to its callers and each mutation to its cleanup.
Report bugs you can trace from an input, through the branch it takes, to the line that produces the wrong result, where a normal caller will hit it. Report a bug that depends on a condition you cannot confirm, such as whether a caller outside the change passes null, only when it is severe.
Do not report bugs that need timing, input shapes or external state you have no evidence for. Do not report style, naming, or missing optimizations in correct code. Do not report duplicate PATH exports or repeated environment setup unless they change process resolution, shadow an executable, or make paired scripts behave differently. Do not suggest null checks for values that cannot be null on the current path.
caafac3
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.