# Audit Feature Interaction

> Analyze feature interaction pairs and triples for concurrent defects Use when this capability is needed.

- Skill: `tomevault-io/audit-feature-interaction` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add tomevault-io/audit-feature-interaction`
- Raw SKILL.md: https://api.skillmd.com/api/skills/tomevault-io/audit-feature-interaction/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: tomevault-io (https://skillmd.com/u/tomevault-io)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/tomevault-io/audit-feature-interaction

---


Analyze the cache for defects arising from multiple features operating
simultaneously on the same entry.

Assume at least one feature interaction bug exists. If your analysis yields
zero findings, re-examine the top-priority pairs below — explain specifically
why no interleaving produces a bug.

Priority ranking (from confirmed historical bugs):
1. **Refresh + expiration** (D+B) — most-bugged interaction historically
2. **Reference collection + any feature** (C+*) — value reference visibility
3. **Async completion + any feature** (F+*) — future lifecycle edge cases
4. **Eviction + weight change** (A+H) — counter drift during transitions

Features:
A. Eviction (size/weight limit exceeded)
B. Expiration (afterAccess, afterWrite, variable)
C. Reference collection (weak key, weak value, soft value GC)
D. Refresh (automatic reload)
E. Loading (CacheLoader / computeIfAbsent)
F. Async completion (CompletableFuture values)
G. Listener notification (removal listener, eviction listener)
H. Weight change (Weigher returning different weight for new value)

For each pair (A,B), (A,C), ..., (G,H) — 28 pairs total:

1. Can both features trigger simultaneously on the same entry?
2. If yes, construct the most adversarial interleaving.
3. Trace step-by-step: correct processing? notifications? final state? cleanup?

After all pairs, identify highest-risk TRIPLE interactions:
- Eviction + expiration + listener exception
- Refresh + async completion + GC collection
- Weight change + eviction + compute

High-risk pairwise combinations:
- Eviction during refresh (entry evicted while refreshing)
- Expiration during compute (entry expires mid-computation)
- GC during async completion (future completes after weak ref collected)
- Weight change during eviction
- Listener exception during any other feature

For each defect: state the features involved, provide the interleaving,
state the incorrect behavior.

---
> Source: [ben-manes/caffeine](https://github.com/ben-manes/caffeine) — distributed by [TomeVault](https://tomevault.io).
<!-- tomevault:4.0:skill_md:2026-06-18 -->

