Skip to content
coreplanelabsPublic

About

Local debugging skill for coding agents: what went wrong, what changed, and the evidence.

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Whodunit

Find the change behind the failure.

Whodunit is a debugging skill for coding agents. It connects a problem to local code, relevant changes and available agent history, then explains the supported cause with evidence.

Install

Run from any directory:

npx @coreplane/whodunit

The installer registers Whodunit in your user skill folders for Codex, Claude Code and OpenCode, across all your projects. Restart your coding agent after installing. It preserves edited or unrelated skill files and leaves project dependencies alone.

To target one client, add --agent codex, --agent claude, or --agent opencode. For a project-only install, use --root /path/to/project. --home /path/to/home selects a different user profile.

Use

Ask your agent what went wrong, or invoke the skill directly:

/whodunit Investigate why login stopped working.

Claude Code uses /whodunit; Codex supports $whodunit. In any supported client, you can ask: “Use Whodunit to investigate why login stopped working.” Give the actual symptom or error. You do not need to tell the agent to read a skill-file path.

Whodunit finds and shows the problem before fixing it. By default it stops at the problem card. Reply yes to try a local repair, no to keep the report, or always to enable auto-fix and try the current fix. Auto-fix skips that pause on later uses. Auto-fix still shows the problem before changes and records the result afterward.

Supported visual clients get a concise report with selectable graph nodes and sources. Codex's inline helper saves it in the current chat's allowed visualization folder. Terminals get a short summary plus a saved local browser report. The same report contains current evidence and relevant history. A short suggested fix appears before the fix choice. The coding agent asks in text: yes, no, or always. The report does not send messages or run repairs.

Auto-fix

Whodunit asks before fixing by default. To save a choice for future uses:

npx @coreplane/whodunit settings auto-fix on
npx @coreplane/whodunit settings auto-fix off
npx @coreplane/whodunit settings show

The choice is stored in ~/.coreplanelabs/whodunit/settings.json. The report helper reads it. The skill asks your agent to read it before editing. Auto-fix asks the agent to try local code changes and relevant tests when the cause is supported. The agent may need more evidence or permission. “Report only” stops edits for the current use. Publishing, deployment, credentials, other agents and existing approval gates keep their normal boundaries.

Website

The website at whodunit.dev uses the same report renderer. Its example includes a suggested fix, sources, and an interactive graph. The example has one Polylane link. Fix requests stay in your coding agent's conversation.

The static site runs in Polycorp's Cloudflare account. To deploy, sign in to that account with Wrangler and run npm run deploy:site. The command builds and checks the site before deploying. The custom domain serves the site publicly; it does not use Cloudflare Access.

Scope

  • Node 22+. The Git helpers require a committed repository; the agent can use its own file tools otherwise.
  • Local context and targeted history collection each use a five-second budget with explicit path, revision and excerpt bounds.
  • Memory and session access depend on the client's actual tools. No cross-client session bridge is installed.
  • The helper does not run fixes, message agents or upload the repository. The agent's configured inference provider still governs its context. Common secret redaction is incomplete.

This is experimental. A small prior synthetic comparison did not establish better diagnosis than ordinary Codex.

Development

Use Node 22+ and Bun 1.4.2:

bun install --frozen-lockfile
bun run verify
node scripts/install-smoke.mjs
node scripts/npx-smoke.mjs

CI checks lint, types, offline tests, generated-code parity, real installation, the package allowlist and the website build on Node 22 and 24. The release workflow supports candidate preparation and npm publication with provenance once its trusted-publisher binding is configured. See Contributing, Security and Releasing.

MIT licensed. For production fixes and prevention, try Polylane.

About

Local debugging skill for coding agents: what went wrong, what changed, and the evidence.

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages