Plugin
bugbash
Bugbash is a Claude Code plugin for hands-on bug hunting: you exercise the running app (API, UI, CLI) first, then use code only to narrow what you already observed. It’s built around a clear charter, find and reproduce issues with evidence, not to debug or ship fixes unless you ask. It includes quick / standard / deep intensity, evidence bars by severity, a flaky vs confirmed split, optional JSON for filing tickets, and subagents tuned for API vs UI testing.
- Analysed
- Last observed
What the code does
Static analysis found none of the capabilities we track, such as shell commands, network requests or file writes, in the latest version.
Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.
This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.
Risk
Sign in to see this tool's overall risk level and what drives it. Free.
Coverage
Detailed report
1 finding from automated static analysis of the latest version, with severities and explanations.
Using this tool across your team? We can assess your whole inventory.
Request an inventory assessment