Installs into .claude/skills of the current project.
Are you the author of Diagnosing Bugs?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/harmitx7-diagnosing-bugs-tribunal-kit)
---
name: diagnosing-bugs
description: "Use when Systematic bug diagnosis methodology for hard bugs: Phase 1 (Build feedback loop), Phase 2 (Reproduce + minimise), Phase 3 (Hypothesise), Phase 4 (Instrument), Phase 5 (Fix + regression test), Phase 6 (Cleanup + post-mortem)."
version: 5.0.0
last-updated: 2026-09-13
skills:
- systematic-debugging
- test-result-analyzer
- tdd-workflow
tools: Read, Grep, Glob, Bash, Edit, Write
scripts-binding:
- .agent/scripts/test_runner.js
- .agent/scripts/verify_all.js
- .agent/scripts/lint_runner.js
---
# Diagnosing Bugs β A Discipline for Hard Bugs
---
## π οΈ Technical Architecture & Reference Recipes
---
---
## Protocol Overview
```
Phase 1: Build a Feedback Loop βββΊ Phase 2: Reproduce + Minimise βββΊ Phase 3: Hypothesise
β
Phase 6: Cleanup + Post-Mortem βββ Phase 5: Fix + Regression Test βββ Phase 4: Instrument
```
---
## Phase 1 β Build a Feedback Loop
This is the core skill. Everything else is mechanical. If you have a tight pass/fail signal for the bug β one that goes red on this bug β you will find the cause; bisection, hypothesis-testing, and instrumentation all just consume it. If you don't have one, no amount of staring at code will save you.
Spend disproportionate effort here. Be aggressive. Be creative. Refuse to give up.
### 10 Strategies to Construct a Feedback Loop (in priority order)
1. **Failing Test at Whatever Seam Reaches the Bug**: Unit, integration, or E2E test.
2. **Curl / HTTP Script**: Send requests against a running dev server.
3. **CLI Invocation with Fixture Input**: Diffing stdout/stderr against a known-good snapshot.
4. **Headless Browser Script (Playwright / Puppeteer)**: Drives the UI, asserts on DOM/console/network.
5. **Replay a Captured Trace**: Save a real network request / payload / event log to disk; replay it through the code path in isolation.
6. **Throwaway Harness**: Spin up a minimal subset of the system (one service, mocked deps) that exercises the bug code path with a single function call.
7. **Property / Fuzz Loop**: If the bug is "sometimes wrong output", run 1000 random inputs and look for the failure mode.
8. **Bisection Harness**: If the bug appeared between two known states (commit, dataset, version), automate "boot at state X, check, repeat" so you can run `git bisect`.
9. **Differential Loop**: Run the same input through old-version vs new-version (or two configs) and diff outputs.
10. **HITL Bash Script**: Last resort. If a human must click, drive them with `scripts/hitl-loop.template.sh` so the loop is still structured. Captured output feeds back to you.
Build the right feedback loop, and the bug is 90% fixed.
### Tighten the Loop
Treat the loop as a product. Once you have a loop, tighten it:
- **Can I make it faster?** (Cache setup, skip unrelated init, narrow the test scope.)
- **Can I make the signal sharper?** (Assert on the specific symptom, not "didn't crash".)
- **Can I make it more deterministic?** (Pin time, seed RNG, isolate filesystem, freeze network.)
> β‘ **Debugging Superpower**: A 30-second flaky loop is barely better than no loop; a 2-second deterministic one is a debugging superpower.
### Non-Deterministic Bugs
The goal is not a clean repro but a higher reproduction rate. Loop the trigger 100Γ, parallelise, add stress, narrow timing windows, inject sleeps. A 50%-flake bug is debuggable; 1% is not β keep raising the rate until it's debuggable.
### When You Genuinely Cannot Build a Loop
Stop and say so explicitly. List what you tried. Ask the user for:
1. Access to whatever environment reproduces it.
2. A captured artifact (HAR file, log dump, core dump, screen recording with timestamps).
3. Permission to add temporary production instrumentation.
_Do not proceed to hypothesise without a loop._
### Phase 1 Completion Criterion β A Tight Loop That Goes Red
Phase 1 is done when the loop is tight and red-capable: you can name **one command** β a script path, a test invocation, a curl β that you have already run at least once (paste the invocation and its output), and that is:
- β **Red-capable**: Drives the actual bug code path and asserts the user's exact symptom, going red on this bug and green once fixed. Not "runs without erroring" β it must catch this specific bug.
- β **Deterministic**: Same verdict every run (or high, pinned reproduction rate).
- β **Fast**: Seconds, not minutes.
- β **Agent-runnable**: Runnable unattended (HITL only via `scripts/hitl-loop.template.sh`).
_If you catch yourself reading code to build a theory before this command exists, stop. No red-capable command, no Phase 2._
---
## Phase 2 β Reproduce + Minimise
Run the loop. Watch it go red β the bug appears.
### Confirm
1. The loop produces the failure mode the user described β not a different failure nearby. (Wrong bug = wrong fix.)
2. The failure is reproducible across multiple runs (or at a high enough reproduction rate).
3. You have captured the exact symptom (error message, wrong output, slow timing) so later phases can verify the fix addresses it.
### Minimise
Once it's red, shrink the repro to the smallest scenario that still goes red. Cut inputs, callers, config, data, and steps one at a time, re-running the loop after each cut β keep only what's load-bearing for the failure.
> π― **Why bother**: A minimal repro shrinks the hypothesis space in Phase 3 (fewer moving parts left to suspect) and becomes the clean regression test in Phase 5.
**Done when every remaining element is load-bearing β removing any single one makes the loop go green.**
---
## Phase 3 β Hypothesise
Generate **3β5 ranked hypotheses** before testing any of them. Single-hypothesis generation anchors on the first plausible idea.
Each hypothesis must be **falsifiable**: state the prediction it makes.
**Format**: `"If [X] is the cause, then [Y] will make the bug disappear / will make it worse."`
If you cannot state the prediction, the hypothesis is a vibe β discard or sharpen it.
Show the ranked list to the user before testing. (Proceed with your ranking if the user is AFK.)
---
## Phase 4 β Instrument
Each probe must map to a specific prediction from Phase 3. Change one variable at a time.
### Tool Preference
1. **Debugger / REPL Inspection**: If the environment supports it. One breakpoint beats ten logs.
2. **Targeted Logs**: Place logs at boundaries that distinguish hypotheses. Never "log everything and grep".
3. **Tag Every Debug Log**: Prefix every debug log with a unique tag, e.g. `[DEBUG-a4f2]`. Cleanup at the end becomes a single grep.
4. **Performance Profiling Branch**: For performance regressions, establish a baseline measurement (`timing harness`, `performance.now()`, profiler, query plan), then bisect. Measure first, fix second.
---
## Phase 5 β Fix + Regression Test
Write the regression test before the fix β but only if there is a correct seam for it.
A correct seam is one where the test exercises the real bug pattern as it occurs at the call site. If the only available seam is too shallow (single-caller test when the bug needs multiple callers, unit test that can't replicate the chain that triggered the bug), a regression test there gives false confidence.
If no correct seam exists, note it. The codebase architecture is preventing the bug from being locked down. Flag this for Phase 6.
### If a Correct Seam Exists:
1. Turn the minimised repro into a failing test at that seam.
2. Watch it fail.
3. Apply the fix.
4. Watch it pass.
5. Re-run the Phase 1 feedback loop against the original (un-minimised) scenario.
---
## Phase 6 β Cleanup + Post-Mortem
### Required Before Declaring Done
- [ ] Original repro no longer reproduces (re-run Phase 1 loop)
- [ ] Regression test passes (or absence of seam is documented)
- [ ] All `[DEBUG-...]` instrumentation removed (grep the prefix)
- [ ] Throwaway prototypes deleted (or moved to debug location)
- [ ] Correct hypothesis stated in commit / PR message
### Post-Mortem Handoff
Ask: **What would have prevented this bug?** If the answer involves architectural debt (no good test seam, tangled callers, hidden coupling), hand off to `/improve-codebase-architecture` with specific findings.