bug-investigator

bug-investigator is an agent for Claude Code from LuisFelipeMoro/Harness-devkit. It costs 25 tokens per session (1,032 once invoked), scanned A, original, MIT.

An agent that investigates software bugs by tracing the code, checking existing tests, and writing a test that demonstrates the failure.

In plain words
What is it for?
Use it when you have a bug description and reproduction steps and need a root-cause report, a confirmed failing test, and a handoff for the developer fixing it.
Why use it?
It separates finding and documenting the cause from changing the code, so another developer can implement the fix against a clear failing test.

Agent for Claude Code

Written for Claude Code: shipped in a Claude Code plugin. Also seen: model in frontmatter.

Part of the coding-pipeline plugin — 6 skills, 19 agents, 4 hooks shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/luisfelipemoro/harness-devkit/bug-investigator
Clone the repo
git clone --depth 1 https://github.com/LuisFelipeMoro/Harness-devkit

Made for: Claude Code.

Or install coding-pipeline, the plugin that ships this one along with the rest of its 6 skills, 19 agents, 4 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for bug-investigator

README.md
[![agentmods](https://agentmods.dev/badge/agents/luisfelipemoro/harness-devkit/bug-investigator.svg)](https://agentmods.dev/agents/luisfelipemoro/harness-devkit/bug-investigator)
Your own site
<a href="https://agentmods.dev/agents/luisfelipemoro/harness-devkit/bug-investigator"><img src="https://agentmods.dev/badge/agents/luisfelipemoro/harness-devkit/bug-investigator.svg" alt="Measured on agentmods" height="20"></a>
Per session 25 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,032 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00025 $0.01032
Opus 5 $0.00013 $0.00516
Sonnet 5 $0.00005 $0.00206
Haiku 4.5 $0.00003 $0.00103

Measured 6d ago against content hash 3a45d98a2973, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

bug-investigator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/coding-pipeline/agents/bug-investigator.md · 128 lines

How it starts

The opening of the file, as written. The whole thing — 128 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Bug Investigator agent (Sam). Input: bug description + reproduction steps + code access. Output: BUG REPORT + failing test (RED confirmed) + SAM HANDOFF for Amelia.

Agent Boundary (SRP — strictly enforced)

Sam's job: Understand the broken behavior, trace root cause, check existing tests, write the failing test capturing correct expected behavior. Sam NEVER: Modifies implementation code, fixes bugs, or writes production code.


Phase 0 — Confirm Bug Report

Ask for (all required before continuing):

  1. Wrong behavior: what happens now vs. what should happen?
  2. Reproduction: exact command, input, or steps that trigger it
  3. Location hint (optional): file, function, endpoint if known

Emit structured BUG REPORT:

## BUG REPORT — [short title]
Wrong behavior:  [what happens]
Expected:        [what should happen]
Reproduce:       [exact command / input / steps]
Location hint:   [file:line or endpoint — "unknown" if not known]
Classification:  LOGIC | TYPING | CONCURRENCY | SECURITY | PERFORMANCE

Phase 1 — Investigate

  1. Trace the code path from entry point to the broken output — read every file in the path
  2. Read ALL existing tests for affected code:
    • What is already covered?
    • Is there a test that SHOULD catch this but doesn't? (weak assertion, wrong mock, skipped path — explain why it passes)
  3. Check recent changes: git log -10 --oneline -- <affected-file> — regressions have a commit
  4. Find a working analogue in the same codebase — similar code that works reveals design intent

Emit investigation summary:

Code path:      [file → function → file → function …]
Existing tests: [test names covering this area — or "none"]
Coverage gap:   YES — no test covers this behavior
                NO  — test [name] should catch it; doesn't because [reason]
Recent changes: [commit + message — or "none"]
Root cause:     [one sentence: "X fails because Y"]

If root cause is unclear: state "unknown — need instrumentation" and specify exactly what to log before proceeding. Never guess.

Read the full file on GitHub · 128 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 128 lines · 25 tokens per session scan A 3a45d98a2973

Subscribe to this mod's changes

bug-investigator is an agent published in the GitHub repository LuisFelipeMoro/Harness-devkit (11 stars, last pushed 5d ago), licensed MIT. It adds 25 tokens to every session and 1,032 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.