Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/laurigates/claude-plugins/code-hidden-failuresnpx skills add laurigates/claude-plugins --skill code-hidden-failuresgit clone --depth 1 https://github.com/laurigates/claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/laurigates/claude-plugins/code-hidden-failures)<a href="https://agentmods.dev/skills/laurigates/claude-plugins/code-hidden-failures"><img src="https://agentmods.dev/badge/skills/laurigates/claude-plugins/code-hidden-failures.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00045 | $0.03175 |
| Opus 5 | $0.00023 | $0.01588 |
| Sonnet 5 | $0.00009 | $0.00635 |
| Haiku 4.5 | $0.00005 | $0.00317 |
Grade A, and why
code-hidden-failures scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 228 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Hidden-Failure Scanner
Detect code that fails without saying so. Two tracks:
| Track | Failure shape | Example |
|---|---|---|
| errors | Syntactic — an error signal is discarded | catch (e) {}, || true, 2>/dev/null, floating promise, _ = err |
| degradation | Logical — an operation "succeeds" with empty/useless output because a precondition was silently unmet | success toast on count === 0, if (!apiKey) return [], a 1-of-3 detector run with no indication |
The two were previously separate skills (code-error-swallowing +
code-silent-degradation); they are the same user intent — "the work
reported success but nothing real happened" — so they live in one scanner
with a --track selector.
When to Use This Skill
| Use this skill when... | Use another skill instead when... |
|---|---|
| Scripts/CI report success but real work failed | /code:antipatterns — broad multi-category scan |
|| true, 2>/dev/null, empty catch {}, except: pass suspected (errors track) |
/code:review — prose code review |
| A feature reports success but produces nothing (degradation track) | /code:lint — a linter already flags the issue |
| Scans return 0 results / success banners on empty outcomes | /code:dead-code — you suspect code never runs |
| You need severity classification + a surfacing recommendation | — |
Context
- Scan path:
$ARGUMENTS(defaults to current directory) - Language signals: !
find . -maxdepth 2 \( -name '*.sh' -o -name '*.bash' -o -name '*.ts' -o -name '*.tsx' -o -name '*.js' -o -name '*.jsx' -o -name '*.py' -o -name '*.go' -o -name '*.rs' \) -type f -not -path './node_modules/*' -not -path './.git/*' - App-type signals (frontend): !
find . -maxdepth 2 \( -name 'index.html' -o -name 'vite.config.*' -o -name 'next.config.*' \) -type f - App-type signals (CLI): !
find . -maxdepth 2 \( -name 'bin' -type d -o -name 'Makefile' -o -name 'justfile' \) - App-type signals (service): !
find . -maxdepth 2 \( -name 'Dockerfile' -o -name '*.service' -o -name 'pyproject.toml' \) -type f - Config signals: !
find . -maxdepth 2 \( -name '.env*' -o -name 'config.*' -o -name 'settings.*' \) -type f - Workflows: !
find . -path '*/.github/workflows/*' -maxdepth 3 -name '*.yml' -type f
What ships with it
30 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- fixtures/sample.sh 1.1 KB runs code
- REFERENCE-degradation.md 6.5 KB
- REFERENCE-go.md 3.6 KB
- REFERENCE-js.md 4.8 KB
- REFERENCE-python.md 4.1 KB
- REFERENCE-rust.md 4.1 KB
- REFERENCE-shell.md 3.6 KB
- REFERENCE-surfacing.md 5.7 KB
- rules/lib/go-defer-close-unchecked.yml 197 B
- rules/lib/go-ignore-underscore.yml 237 B
- rules/lib/js-empty-catch.yml 152 B
- rules/lib/js-promise-catch-empty.yml 242 B
- rules/lib/js-void-ignore.yml 184 B
- rules/lib/py-bare-except-pass.yml 259 B
- rules/lib/py-broad-except-pass.yml 282 B
- rules/lib/rs-let-underscore-result.yml 181 B
- rules/lib/rs-ok-discard.yml 153 B
- rules/sgconfig.yml 852 B
- rules/tests/go-defer-close-unchecked-test.yml 284 B
- rules/tests/go-ignore-underscore-test.yml 222 B
- rules/tests/js-empty-catch-test.yml 135 B
- rules/tests/js-promise-catch-empty-test.yml 232 B
- rules/tests/js-void-ignore-test.yml 74 B
- rules/tests/py-bare-except-pass-test.yml 173 B
- rules/tests/py-broad-except-pass-test.yml 215 B
- rules/tests/rs-let-underscore-result-test.yml 180 B
- rules/tests/rs-ok-discard-test.yml 206 B
- scripts/scan-shell.sh 5.8 KB runs code
- scripts/test-fixture.sh 1.9 KB runs code
- scripts/tests/test-rules-project.sh 4.1 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 228 lines · 45 tokens per session scan A a4ef3d13b9f4
code-hidden-failures is a skill published in the GitHub repository laurigates/claude-plugins (57 stars, last pushed yesterday), licensed MIT. It adds 45 tokens to every session and 3,175 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
plan
Produce structured implementation plans with goal, approach, test strategy, blast-radius assessment, parallelism analysis, and a user approval gate before any code is written. Persisting PLAN.md for fresh-session handoff. Use when: 'plan this', 'architect this', 'how should we implement', 'implementation plan', 'write…
extract-ssot
Deduplicate repeated markdown content, rule files, skill bodies, ADRs, docs, into a single named source of truth and migrate every call site to cite it by exact heading. Use when the same prose, literal, or concept appears (or is reworded) across files: 'DRY this prose', 'extract a shared rule', 'single source of…
map-corpus
Map a multi-resource documentation corpus into a verified, classified, triaged slice BEFORE any digesting: bounded discovery (llms.txt + sitemap), a user-approved link map classifying every discovered URL, deterministic node manifests over immutable snapshots, and a per-node relevance inventory whose evidence a script…
feature-branch-pr-writing
Use this skill when the user asks to write, draft, create, or improve a PR description for a Shopware core repository PR — AND that PR targets a non-trunk feature branch (not trunk itself). Trigger phrases like "write a PR description", "draft the PR", "what should I put in the PR body". The skill detects the target…
ci-log-interpretation
Use this skill when reading or analyzing CI logs from a Shopware GitHub Actions workflow to figure out why a build failed — phrases like "why did CI fail", "what broke the build", "check the pipeline", "interpret these logs", "debug this red build" — or whenever raw run logs, job logs, or check annotations from a…
repo-activity
Scan all git repositories under /repos and report recent activity — last commit age, branch, uncommitted changes — in age-bucketed tables. Use when the user asks for a repo activity overview, "what have I been working on", portfolio status, or which repos are active/dormant.