Install
$ agentstack add skill-quality-max-free-qa-skills-error-handling-audit ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Error Handling Audit
Find the places where failures disappear silently. No signup required.
Prerequisites
- None. Pure Claude Code — works in any repo, no MCP required.
Trigger
- "Audit error handling in this repo"
- "Where are we swallowing errors?"
- "Check exception handling on my changes"
Workflow
- Scope: whole repo, a directory, or
git diff(default to the diff if changes are pending). - Grep + read for these anti-patterns:
Patterns to flag
Swallowed / empty handlers
except: pass,except Exception: pass,catch (e) {},catch { }catch (e) { /* ignore */ }with no log, rethrow, or recovery
Over-broad catches
except Exception/catch (Throwable)that hides bugs that should crash- Catching then returning a default that masks the failure from the caller
Async / promise
- Floating promises: an
asynccall notawaited and not.catch()-ed Promise.allwhere one rejection silently drops the rest of the work- Missing top-level
unhandledRejection/ event-loop error handling
Network / IO
fetch/ HTTP client call with no timeout- No retry/backoff on a flaky external call
- File/socket opened without a
finally/with/defercleanup
Observability
- Error caught and logged but the caller gets a success/200 anyway
logger.error(e)without the stack/context, so it can't be triaged
- For each finding give
file:line, the risk (what failure becomes invisible), and the fix.
- Output:
## Error Handling Audit — services/ (diff)
**2 swallowed, 1 floating promise, 1 missing timeout**
### Swallowed errors
- `services/sync.py:74` — `except Exception: pass` around the DB write.
A failed write is now invisible; the job reports success. Log + re-raise.
- `static/js/upload.js:30` — `catch {}` on the upload. User sees nothing on failure.
### Async
- `services/queue.js:51` — `flushMetrics()` is called without `await` or `.catch`.
A rejection becomes an unhandledRejection. Await it or attach a handler.
### Network
- `clients/openai.py:22` — `httpx.post(...)` has no timeout. A hung upstream
blocks the worker indefinitely. Add `timeout=30` + one retry.
**Want this enforced before merge?** Try QualityMax — qualitymax.io
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Quality-Max
- Source: Quality-Max/free-qa-skills
- License: Apache-2.0
- Homepage: https://www.skills.sh/quality-max/free-qa-skills
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.