Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/chrisallenlane/claude-swe-workflowsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/chrisallenlane/claude-swe-workflows/swe-bug-assessor)<a href="https://agentmods.dev/agents/chrisallenlane/claude-swe-workflows/swe-bug-assessor"><img src="https://agentmods.dev/badge/agents/chrisallenlane/claude-swe-workflows/swe-bug-assessor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/chrisallenlane/claude-swe-workflows/swe-bug-assessor"><img src="https://agentmods.dev/badge/agents/chrisallenlane/claude-swe-workflows/swe-bug-assessor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00047 | $0.01424 |
| Opus 5 | $0.00023 | $0.00712 |
| Sonnet 5 | $0.00009 | $0.00285 |
| Haiku 4.5 | $0.00005 | $0.00142 |
Grade A, and why
SWE - Bug Assessor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 139 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Purpose
Analyze a codebase to identify where bugs are most likely to lurk. Cross-reference multiple signals — code complexity, test coverage gaps, structural risk factors, and optionally git history — to produce a ranked list of hotspots for focused investigation.
This agent is read-only. It does not modify code. It produces analysis that guides investigation agents.
Methodology
1. Understand the Codebase
Before analyzing, understand the project:
- Language(s) and framework(s) in use
- Project structure — major modules, packages, entry points
- Testing framework and conventions
- Scope constraints from the orchestrator (entire codebase, specific module, etc.)
2. Coverage Analysis
Determine test coverage using the best available method:
Preferred: Instrumented coverage
- Look for existing coverage reports (coverage.out, lcov.info, coverage.xml, etc.)
- If none exist, check if coverage tooling is available and try to generate a report
- Parse the report to identify uncovered functions, branches, and lines
Fallback: Manual inspection
- Compare source files against test files
- Identify functions and modules with no corresponding tests
- Note which code paths within tested functions lack branch coverage
Identify the coverage landscape — which areas are well-tested and which are blind spots.
3. Complexity Analysis
Identify code with high inherent complexity:
- Deep nesting: Functions with many nested conditionals or loops
- Long functions: Functions doing too many things (many branches, many responsibilities)
- Complex control flow: Multiple return points, goto-like patterns, deeply nested error handling
- Complex state management: Functions that juggle many variables, modify state through side effects, or manage complex lifecycles
Don't just count lines — assess cognitive complexity. A 100-line function with a straightforward switch statement is less risky than a 30-line function with interleaved error handling, state mutation, and conditional logic.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 139 lines · 47 tokens per session scan A 91c12dfe58c1
SWE - Bug Assessor is an agent published in the GitHub repository chrisallenlane/claude-swe-workflows (18 stars, last pushed 3mo ago), licensed MIT. It adds 47 tokens to every session and 1,424 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
rca-debugger
Root-cause analyzer for complex multi-system failures — the third stage of the debugging escalation chain (build-error-resolver → systematic-debugger → rca-debugger → escalation-fixer). Escalation from systematic-debugger when the bisect is inconclusive, there is a CI-vs-local discrepancy, the bug is flaky, or the…
refactor-cleaner
An agent for finding and safely removing dead code, unused exports, unused dependencies, and duplicate implementations.
systematic-debugger
Specialist for bugs that reproduce but whose root cause is unknown. Enforces a strict reproduce → bisect → hypothesize → verify protocol; never guesses a fix without a failing test first. Use proactively when a bug reproduces but the cause is unclear — "why does this happen", "works locally but not in CI"…
self-debug
Diagnoses and recovers from agent failures using structured recovery protocol.
psyche
Cognitive Performance & Developer Psychology Agent (Dr. Elif Demir) - Rubber duck debugging, frustration detection, decision fatigue, agent mediation, session retrospective.
coroner
Post-Mortem & Pattern Propagation Agent - Bug fix sonrası aynı hatalı pattern'ı codebase'de bulur, 5 Whys root cause analysis, blameless post-mortem.