Technical Debt Diagnostic Analyzer
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md to install @user_f37e97ba/technical-debt-diagnostic into your AI assistant.
About this skill
Problem
Large codebases accumulate code smells, architecture decay, dependency risks, and security hazards at the same time. These issues rarely fail in one obvious way; they make refactoring slower, increase review cost, and complicate security patching. This skill turns scattered signals into a traceable diagnostic report instead of generic advice.
How It Works
The skill follows a fixed workflow:
- It confirms language, scan granularity, and focus area for a file, module, or repository.
- It statically checks code for long functions, duplicate code, god classes, and deep nesting, with file locations or snippets where possible.
- It inspects module boundaries and layering for circular dependencies, layer violations, and bloated files.
- It scans manifests such as
package.json,requirements.txt, andpom.xmlfor stale locked versions, deprecated packages, unused dependencies, and version conflicts. - It flags common risk patterns related to SQL injection, hardcoded credentials, unsafe deserialization, and sensitive logging, with a “needs manual review” note.
- It ranks findings by severity, fix cost, and impact, then produces a Sprint-level repayment roadmap.
Boundaries
The skill is best for static diagnosis and prioritization, not for executing user code or replacing a full SCA/security audit. Dependency findings rely on known CVE data and manifest files, so teams should still verify impact with tools like Snyk or OWASP Dependency Check. For repositories over 10,000 lines, module-by-module analysis is preferable.
Use Cases
- After taking over a Python service, identify god classes, long functions, and deep nesting before a refactoring review, then rank fixes.
- Before release, inspect `package.json` and `requirements.txt` for stale versions, deprecated packages, unused dependencies, and version conflicts.
- During a microservice decomposition review, map circular dependencies, layer violations, and bloated files, then produce a Sprint-level repayment plan.
- Before a security audit, review login, payment, and upload modules for static risks, flagging hardcoded credentials and SQL injection for manual validation.
Best For
- Engineers refactoring legacy Python or Java services who need high-maintenance modules identified and a Sprint-level roadmap.
- Backend owners performing pre-release dependency reviews who need risky packages from `package.json` or `pom.xml` ranked by upgrade priority.
- Architects preparing microservice decomposition or design reviews who need circular dependencies, layer violations, and bloated files mapped.
- Security engineers building pre-audit static risk lists who need hardcoded credentials and SQL injection patterns flagged for manual review.
Related Skills
A one-shot coding agent built on Claude Code CLI that runs non-interactively, supports a specified workdir, and can be monitored in the foreground or background.
Preview and confirm file sorting by extension, with recursive cleanup, ignore rules, and transactional rollback.
An engineering assistant for static HTML/CSS/JS pages, design-token extraction, IE8-compatible review, and structured delivery.
An engineering workflow for requirement analysis, scenario modeling, risk planning, quality gates, testing, and knowledge capture, with lightweight, standard, and full modes.