AI Agent Hub
Back to skills
Technical Debt Diagnostic Analyzer icon

Technical Debt Diagnostic Analyzer

Development Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md to install @user_f37e97ba/technical-debt-diagnostic into your AI assistant.

About this skill

Problem

Large codebases accumulate code smells, architecture decay, dependency risks, and security hazards at the same time. These issues rarely fail in one obvious way; they make refactoring slower, increase review cost, and complicate security patching. This skill turns scattered signals into a traceable diagnostic report instead of generic advice.

How It Works

The skill follows a fixed workflow:

  • It confirms language, scan granularity, and focus area for a file, module, or repository.
  • It statically checks code for long functions, duplicate code, god classes, and deep nesting, with file locations or snippets where possible.
  • It inspects module boundaries and layering for circular dependencies, layer violations, and bloated files.
  • It scans manifests such as package.json, requirements.txt, and pom.xml for stale locked versions, deprecated packages, unused dependencies, and version conflicts.
  • It flags common risk patterns related to SQL injection, hardcoded credentials, unsafe deserialization, and sensitive logging, with a “needs manual review” note.
  • It ranks findings by severity, fix cost, and impact, then produces a Sprint-level repayment roadmap.

Boundaries

The skill is best for static diagnosis and prioritization, not for executing user code or replacing a full SCA/security audit. Dependency findings rely on known CVE data and manifest files, so teams should still verify impact with tools like Snyk or OWASP Dependency Check. For repositories over 10,000 lines, module-by-module analysis is preferable.

Use Cases

  • After taking over a Python service, identify god classes, long functions, and deep nesting before a refactoring review, then rank fixes.
  • Before release, inspect `package.json` and `requirements.txt` for stale versions, deprecated packages, unused dependencies, and version conflicts.
  • During a microservice decomposition review, map circular dependencies, layer violations, and bloated files, then produce a Sprint-level repayment plan.
  • Before a security audit, review login, payment, and upload modules for static risks, flagging hardcoded credentials and SQL injection for manual validation.

Best For

  • Engineers refactoring legacy Python or Java services who need high-maintenance modules identified and a Sprint-level roadmap.
  • Backend owners performing pre-release dependency reviews who need risky packages from `package.json` or `pom.xml` ranked by upgrade priority.
  • Architects preparing microservice decomposition or design reviews who need circular dependencies, layer violations, and bloated files mapped.
  • Security engineers building pre-audit static risk lists who need hardcoded credentials and SQL injection patterns flagged for manual review.