
Security News
Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security
Feross Aboukhadijeh joins TBPN to discuss Socket's $60M Series C, 500%+ ARR growth, AI's impact on open source, and the rise in supply chain attacks.
github.com/suraciii/debug-skill
Advanced tools
Let your coding agent debug like a human developer.
Set breakpoints, step through code, evaluate expressions — the way you actually debug.
If this saves you a debugging session, please star the repo — it helps others find it.
AI coding agents (Claude Code, Codex, Opencode, Cursor) are stuck with print statements and guesswork. debug-skill gives them what human developers have: a real debugger they can actually use. It ships two things:
dap CLI — a stateless CLI wrapper around
the Debug Adapter Protocol so any agent can drive a real
debugger from BashInstall the skill, and Claude debugs your code the way you would — not with print statements.
The debugging-code skill gives Claude structured knowledge of the debugging workflow: setting breakpoints, stepping
through execution, inspecting locals and the call stack, evaluating expressions mid-run. It uses the dap CLI as its
tool.
Via the plugin marketplace — no manual setup needed:
/plugin marketplace add AlmogBaku/debug-skill
/plugin install debugging-code@debug-skill-marketplace
Via skills.sh — works with Cursor, GitHub Copilot, Windsurf, Cline, and 20+ more agents:
npx skills add AlmogBaku/debug-skill
# or: bunx skills add AlmogBaku/debug-skill
Or manually copy skills/debugging-code/SKILL.md into your agent's system prompt or context.
dap CLIdap wraps the Debug Adapter Protocol behind simple, stateless CLI commands. A background daemon holds the session; the
CLI sends one command and gets back the full context — no interactive terminal required.
# One-liner (Linux & macOS)
bash <(curl -fsSL https://raw.githubusercontent.com/AlmogBaku/debug-skill/master/install.sh)
# Go install
go install github.com/AlmogBaku/debug-skill/cmd/dap@latest
Or download a pre-built binary from the releases page.
# Set a breakpoint and start — stops automatically, returns full context
dap debug app.py --break app.py:42
# Inspect and step
dap eval "len(items)"
dap step
# Resume or stop
dap continue
dap stop
Every command returns full context automatically: current location, surrounding source, local variables, call stack, and program output. No follow-up calls needed.
# Python
dap debug app.py --break app.py:42
# Go
dap debug main.go --break main.go:15
# Node.js / TypeScript
dap debug server.js --break server.js:10
# Rust / C / C++
dap debug hello.rs --break hello.rs:4
# Attach to a remote debugger (e.g. debugpy in a container)
dap debug --attach container:5678 --backend debugpy --break handler.py:20
# Pass arguments to the program
dap debug app.py --break app.py:10 -- --config prod.yaml --verbose
| Command | Description |
|---|---|
dap debug <script> | Start debugging (local or --attach host:port) |
dap stop | End session |
dap step [in|out|over] | Step (default: over) |
dap continue | Resume execution |
dap context [--frame N] | Re-fetch current state |
dap eval <expr> [--frame N] | Evaluate expression in current frame |
dap output | Drain buffered stdout/stderr since last stop |
Global flags: --json (machine-readable output), --session <name> (named sessions), --socket <path> (custom
socket path)
| Language | Backend | Auto-detected |
|---|---|---|
| Python | debugpy | yes |
| Go | dlv (Delve) | yes |
| Node.js/TypeScript | js-debug | yes |
| Rust / C / C++ | lldb-dap | yes |
Backend is inferred from the file extension. Override with --backend <name>.
dap <cmd> → Unix socket → Daemon → DAP protocol → debugpy / dlv / js-debug / lldb-dap → your program
The daemon starts automatically on dap debug and shuts down on dap stop (or after 10 min idle). It's invisible — you
never manage it directly.
Multiple agents can debug independently with named sessions:
dap debug app.py --session agent1 --break app.py:10
dap debug main.go --session agent2 --break main.go:8
dap stop --session agent1 # stops agent1 only
Each session has its own daemon and socket. Omit --session to use the default session.
PRs and issues welcome. See claudedocs/ for architecture details and CLAUDE.md for code conventions.
If debug-skill saves you from a painful debugging session, consider starring the repo — it helps others find it and keeps the project going.
MIT
FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Feross Aboukhadijeh joins TBPN to discuss Socket's $60M Series C, 500%+ ARR growth, AI's impact on open source, and the rise in supply chain attacks.

Security News
OSV withdrew 157 OSV malware reports after automated false positives incorrectly flagged trusted npm and PyPI packages, sending bad records into tools that rely on OSV data.

Research
/Security News
TrapDoor crypto stealer hits 36 malicious packages across npm, PyPI, and Crates.io, targeting crypto, DeFi, AI, and security developers.