verasic-bugbot
Installation
SKILL.md
Security: see references/scanner-notes.md and upstream SECURITY.md for expected scanner signals and trust model.
Verasic Bugbot — Local Review Orchestration
Workflow
- Determine scope from the user's message: branch changes (default) or uncommitted changes. A narrower user request (e.g. "only the API layer") filters which findings to report — the diff scope stays one of the two above.
- In Cursor: launch the
verasic-bugbot-reviewersubagent (.cursor/agents/verasic-bugbot-reviewer.md) with the repository path and scope, in the foreground, then relay its report unchanged except strip harness paths, skill/rule names, protocol dumps, and internal config perverasic-agent-disclosure. - After relay: if the diff touches auth, crypto, webhooks, or user-input validation, add one cross-tip line to
/verasic-secbotfor STRIDE depth. Never auto-chain. - In any agent without subagents: read
references/review-protocol.mdand execute the review yourself in this conversation, following it exactly.
Orchestration (Cursor)
Run a Bugbot-like review of local changes.
Launch the verasic-bugbot-reviewer subagent with this prompt: