--- name: deep-bug-hunt description: Run a deep, multi-agent bug-hunt expedition over a whole codebase - one finder pass per bug-class lens, a different-model adversarial verifier that tries to refute every candidate, fingerprint plus judgment dedup against the issue tracker, and filing of only verified, non-duplicate defects, in operator-gated rounds. Use when the user asks for a bug hunt, bug sweep, "find bugs across the repo", a deep defect audit, or to resume or continue a previous hunt. Not for reviewing a single diff or PR, and not for fixing bugs. --- # Deep Bug-Hunt Expedition You are the hunt lead. You orchestrate finders and verifiers, own dedup, file the survivors, and report to the operator at every round boundary. You do not fix anything: the output of a hunt is filed issues and a run log, never code changes. The shape of a hunt: ``` preflight -> [ round: N lens passes -> verify -> dedup -> file -> metrics -> ASK OPERATOR ] -> wrap-up ``` Reference files (read when you reach that step, not up front): | File | Read it when | |---|---| | `references/harness.md` | Before launching the first round - how to run finders/verifiers in this agent environment | | `references/lenses.md` | When writing finder prompts - the lens catalog | | `references/contracts.md` | When writing finder and verifier prompts - contracts and schemas | | `references/dedup.md` | Before filing anything - fingerprints and judgment dedup | | `references/tracker.md` | Before the first tracker command - bd, GitHub Issues, and file-based trackers | | `profiles/TEMPLATE.md` | At wrap-up, when saving a profile for a repo that has none | ## 1. Parameters Resolve these in preflight. Sources, in priority order: what the operator said when invoking the skill, then the repo profile, then the defaults. | Parameter | Meaning | Default | |---|---|---| | `STACK` | Languages/frameworks; steers lens emphasis | Detect from the repo | | `TRACKER` | Where bugs are listed and filed | Detect: `.beads/` -> `bd`; GitHub remote -> `gh`; else a JSONL file | | `VERIFIER_MODEL` | A model **different from the finder model** | `opus` in Claude Code; see `references/harness.md` elsewhere | | `LABEL` | Label for this hunt's filings; one per hunt, never reused | `bughunt-` | | `MAX_AGENTS` | Concurrency cap | 16 | | `MAX_PASSES` | Hard ceiling on lens passes | 10 | | `CHECKPOINT_EVERY` | Lens passes per round | 3 | | Scope | Optional narrowing | Whole tree, all lenses | Scope add-ons the operator may give: only certain lenses; only files changed since a ref; skip anything already carrying a `bughunt-*` label. **Repo profile.** Nothing in this skill is specific to any repo; everything repo-specific lives in `.bughunt/profile.md` inside the repo itself. A profile supplies parameters, a slicing plan, lens emphases, tracker quirks, and the hunt history. If none exists, derive what you need from the repo and offer at wrap-up to save one from `profiles/TEMPLATE.md`. **Severity mapping** (keep it stable across hunts or the trend metrics are noise): P0 crash, data loss, or authz bypass · P1 wrong behavior in normal use · P2 edge case · P3 latent. ## 2. Preflight 1. Confirm you are in the right repo and the right tracker database (see `references/tracker.md`). A batch filed into the wrong database is tedious to unwind. 2. Load the corpus: every open bug as `{id, title}`, plus every `hunt_fingerprint` ever filed across all hunts. This is the dedup memory. 3. Read the hunt history (`.bughunt/HUNTS.md` or the profile footer). Un-run lenses and un-sliced areas from earlier hunts are un-swept ground and go first. 4. Build the slicing plan: about `MAX_AGENTS` balanced groups of files by area, with an explicit file list per slice. Every source file belongs to exactly one slice. 5. Choose the lens order (`references/lenses.md`): drop lenses with no surface in this repo, add stack-specific ones, put never-run lenses first, then historically rich ones. 6. Create `.bughunt/runs/