Scan for hidden failures: swallowed errors (empty catch, || true, 2>/dev/null) and silent degradation (success on zero results). Use when failures vanish or success masks empty output.
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Um comando direto ignora o prompt de revisão. Verifique a origem antes de executá-lo.
Scan for hidden failures: swallowed errors (empty catch, || true, 2>/dev/null) and silent degradation (success on zero results). Use when failures vanish or success masks empty output.
name
code-hidden-failures
model
opus
Hidden-Failure Scanner
Detect code that fails without saying so. Two tracks:
Logical — an operation "succeeds" with empty/useless output because a precondition was silently unmet
success toast on count === 0, if (!apiKey) return [], a 1-of-3 detector run with no indication
The two were previously separate skills (code-error-swallowing +
code-silent-degradation); they are the same user intent — "the work
reported success but nothing real happened" — so they live in one scanner
with a --track selector.
--track <errors|degradation|both>: which track to run (default both)
--lang <shell|js|py|go|rust|auto>: errors track — restrict to one language (default auto)
--severity <low|med|high>: minimum severity to report (default med)
--emit-patch: errors track — emit a unified-diff patch on stdout (no in-place mutation; apply with git apply)
--fix: degradation track — apply recommended fixes in place (precondition checks, status indicators, distinguishing copy)
--emit-patch and --fix are mutually exclusive — the errors track reviews
its surfacing copy via a patch, the degradation track applies structural
fixes directly.
Execution
Run the selected track(s). Default both: run errors first, then degradation,
then a combined summary.
Track A — Error swallowing
Run when --track is errors or both.
Step A1: Detect languages and app context
From the context commands above, determine which language matchers to run.
For the app-context matrix (signals → surfacing channel), load
REFERENCE-surfacing.md.
Step A2: Run the matchers
The AST-shaped swallowed-error patterns (js/ts, python, go, rust) live as an
ast-grep rule project in rules/ (one *.yml per pattern under
rules/lib/, each with a valid/invalid fixture in rules/tests/). Run the whole
catalog in one deterministic pass — do not re-type sg -p '…' per language:
Graceful degradation — if ast-grep (packaged as ast-grep or sg) is not
installed, fall back to the per-pattern flow: read the REFERENCE-{js,python,go, rust}.md files (each links its patterns to the rule .yml) and run the
individual sg -p '<pattern>' --lang <lang> commands by hand. Prefer the repo's
own errcheck/staticcheck (Go) or cargo clippy (Rust) when configured — the
rule project surfaces what those linters would catch, it does not replace them.
For every finding, capture: file:line, matched snippet, surrounding function
name if discoverable.
Step A3: Classify severity
For every raw finding, assign Low / Medium / High:
Severity
Criteria
Examples
Low
Matches a documented allowlist entry or the catch block has a log call + rethrow.
Frontmatter extraction || true (see .claude/rules/shell-scripting.md lines 135–162); except FileNotFoundError: pass around an optional cache.
Medium
Error suppressed with no log, no fallback value, no surfacing, on a recoverable operation.
catch (e) {} around a UI-layer fetch; || true after make lint.
High
Suppression around a required operation: data writes, auth, secret handling, config loading, release builds, push/deploy.
npm publish 2>/dev/null || true; except: pass around a DB commit; _ = os.Remove(tmpPath) on a path the caller assumed was cleaned.
Apply the per-language allowlist rules from each REFERENCE-*.md before
assigning Low.
Step A4: Recommend a surfacing channel
For each Medium/High finding, consult REFERENCE-surfacing.md to pick the
channel appropriate to the detected app context — do not recommend a
uniform "log and rethrow":
App context
Recommended channel
CLI / shell
echo "warn: ..." >&2 + non-zero exit on High
Web frontend
console.error + user-facing toast/banner with sanitized copy
Re-raise / return Result / propagate — do not surface to user
CI / build script
echo "::error::..." (GitHub) or stderr + non-zero exit
Step A5: Apply privacy redaction
Every suggested replacement (report and--emit-patch) MUST pass through
the redaction rules in REFERENCE-surfacing.md §Privacy:
Redact env values by name pattern (*TOKEN*, *KEY*, *SECRET*, *PASSWORD*, GH_*, ANTHROPIC_*, AWS_*) → [REDACTED].
Rewrite absolute home paths ($HOME, /Users/…, /home/…) → ~.
Truncate message payloads at 200 characters.
Prefer action-oriented copy over raw stderr forwarding.
Never forward set -x / xtrace output.
For web frontend, split: verbose detail → console.error; short sanitized
copy → UI channel.
Step A6: Emit patch (if --emit-patch)
Generate a unified diff to stdout (not written to files) that covers only
Medium/High findings, applies the app-context-appropriate channel, runs every
inserted string through the Step A5 redaction, and adds a
# TODO(hidden-failures): review wording comment next to each generated
user-facing message. Remind the user: git apply <patchfile>.
Track B — Silent degradation
Run when --track is degradation or both. Detection patterns, severity
guide, and fixes live in REFERENCE-degradation.md.
Step B1: Discover source files
Glob **/*.{ts,tsx,js,jsx,py,go,rs} in the target path, excluding
node_modules, dist, build, .git, vendor, __pycache__.
Step B2: Scan for the five degradation patterns
Match the five pattern categories from
REFERENCE-degradation.md: silent config skip,
success on zero results, silent step skipping, missing precondition
validation, hidden degraded mode. For each finding capture file:line, which
pattern, what the user experiences, and the preconditions the code needs.
Step B3: Classify (degradation severity)
High = success messaging when nothing worked (patterns 2, 3); Medium =
functionality silently disabled by config/env (patterns 1, 5); Low = missing
upfront validation (pattern 4).
Step B4: Apply fixes (if --fix)
Apply the per-pattern fixes from
REFERENCE-degradation.md § Recommended Fixes in
place, then list every change with file:line references.
Combined Report
Group by severity descending; omit Low unless --severity low. Tag each row
with its track.
rules/ — the executable ast-grep catalog for the errors track (sgconfig.yml + rules/lib/*.yml + rules/tests/*-test.yml); run ast-grep test -c rules/sgconfig.yml --skip-snapshot-tests to verify every rule against its fixtures
/code:antipatterns — delegates here for the error-swallowing category
/code:review — prose code review
.claude/rules/shell-scripting.md — canonical allowlist for shell \|\| true / 2>/dev/null