Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/junghwayang/oh-my-codex/debugnpx skills add junghwaYang/oh-my-codex --skill debuggit clone --depth 1 https://github.com/junghwaYang/oh-my-codexWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00862 |
| Opus 5 | $0.00000 | $0.00431 |
| Sonnet 5 | $0.00000 | $0.00172 |
| Haiku 4.5 | $0.00000 | $0.00086 |
Grade A, and why
debug scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 171 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Debug Skill
Systematic debugging and troubleshooting.
When to Use
- Unexpected errors or behavior
- Performance issues
- Intermittent failures
- Complex bugs that resist simple fixes
When NOT to Use
- Clear, simple errors with obvious fixes
- Feature development (use autopilot)
Debugging Methodology
1. REPRODUCE
Before fixing anything:
- Get exact steps to reproduce
- Identify if it's consistent or intermittent
- Note environment (OS, browser, versions)
- Capture error messages verbatim
2. ISOLATE
Narrow down the problem:
- Binary search through code/commits
- Remove components until bug disappears
- Check if bug exists in isolation
3. HYPOTHESIZE
Form theories:
- What changed recently?
- What assumptions might be wrong?
- What are the edge cases?
4. TEST
Verify hypothesis:
- Add logging/breakpoints
- Write failing test
- Check in debugger
5. FIX
Apply minimal fix:
- Fix root cause, not symptoms
- Don't introduce new bugs
- Add regression test
6. VERIFY
Confirm fix:
- Original bug is gone
- No new bugs introduced
- Tests pass
Common Bug Patterns
Off-by-One
// Bug: skips last item
for (let i = 0; i < arr.length - 1; i++)
// Fix:
for (let i = 0; i < arr.length; i++)
Null/Undefined
// Bug: crashes on null
user.profile.name
// Fix: optional chaining
user?.profile?.name
Async Race Condition
// Bug: uses stale data
setData(await fetch('/api'));
doSomething(data); // data not updated yet
// Fix: use returned value
const newData = await fetch('/api');
setData(newData);
doSomething(newData);
State Mutation
// Bug: mutates original
const sorted = arr.sort();
// Fix: copy first
const sorted = [...arr].sort();
Closure Capture
// Bug: all callbacks use final i
for (var i = 0; i < 5; i++) {
setTimeout(() => console.log(i), 100);
}
// Fix: use let or IIFE
for (let i = 0; i < 5; i++) {
setTimeout(() => console.log(i), 100);
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 171 lines · 0 tokens per session scan A 675c024174fd
debug is a skill published in the GitHub repository junghwaYang/oh-my-codex (5 stars, last pushed 6mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 862 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…