Verune

Plugin

bugbash

Bugbash is a Claude Code plugin for hands-on bug hunting: you exercise the running app (API, UI, CLI) first, then use code only to narrow what you already observed. It’s built around a clear charter, find and reproduce issues with evidence, not to debug or ship fixes unless you ask. It includes quick / standard / deep intensity, evidence bars by severity, a flaky vs confirmed split, optional JSON for filing tickets, and subagents tuned for API vs UI testing.

Analysed
Last observed

What the code does

Static analysis found none of the capabilities we track, such as shell commands, network requests or file writes, in the latest version.

Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.

This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.

Risk

Sign in to see this tool's overall risk level and what drives it. Free.

Sign in to see the risk level

Coverage

Complete static analysis

How coverage is measured

Detailed report

1 finding from automated static analysis of the latest version, with severities and explanations.

Sign in to view detailed report

Using this tool across your team? We can assess your whole inventory.

Request an inventory assessment