| name | scan-codebase-health |
| version | 2.0.0 |
| description | [Documentation] Use when you need to detect codebase health issues: unused exports, doc count-drift, orphan files, stale config references. |
Quick Summary
Goal: Detect structural rot in AI-assisted codebases — dead code, count-drift, orphan files, stale configs, dead feature flags, broken cross-references. Works on any project via docs/project-config.json.
Workflow:
- Classify — Load config, detect available tooling (graph.db, CI, feature-flag patterns)
- Run Detections — Execute 7 detection categories (graph-dependent checks skipped if no graph.db)
- Fresh-Eyes Review — Verify findings before writing report
- Generate Report — Write to
plans/reports/codebase-health-scan-{YYMMDD}.md
- Present Summary — Show actionable findings with severity levels
Key Rules:
- Generic — reads all paths from project-config.json, never hardcodes project names
- Graceful degradation — graph-dependent checks skipped if
.code-graph/graph.db not found
- Report format — each finding has
file:line, category, severity (HIGH/MEDIUM/LOW), suggested action
MUST ATTENTION NEVER report a finding without file:line proof
Scan Codebase Health
Phase 0: Classify & Detect
Before any other step, in parallel:
- Read
docs/project-config.json for the codebaseHealth section:
{
"codebaseHealth": {
"sourcePaths": ["{discovered-source-root}/"],
"docPaths": ["docs/"],
"configPatterns": ["**/appsettings*.json", "**/environment*.ts"],
"excludePaths": ["node_modules", "dist", "bin", "obj"]
}
}
If codebaseHealth section is missing, discover source roots from project config, manifests, and populated code directories; use docPaths: ["docs/"] when docs exist.
- Detect available tooling to determine which phases to run:
| Signal | Phase Enabled |
|---|
.code-graph/graph.db exists | Phase 3 (Unused Exports) + Phase 4 (Orphan Files) |
CI config found (.github/workflows, azure-pipelines.yml) | Phase 6 (CI Health) — optional |
Feature flag patterns found (FeatureFlags, IFeatureManager, LaunchDarkly) | Phase 6 (Dead Feature Flags) |
Cross-reference patterns in docs (file:line, [link]()) | Phase 7 (Broken Cross-References) |
- Create
TaskCreate entries for each enabled phase before proceeding.
Evidence gate: If docs/project-config.json not found and no detectable source paths, report and ask user for guidance. DO NOT guess project structure.
Phase 1: Doc Count-Drift Detection (No Graph Required)
Think: Which numeric claims in docs can actually be verified? What's the drift threshold that signals a real maintenance problem vs normal growth?
Scan docs/ for numeric claims: "N files", "N tests", "N hooks", "N services", "N skills", "N components".
For each claim:
- Extract number and what it counts
- Glob/grep to verify actual count
- Flag if actual differs from claimed
Severity thresholds:
- Drift ≤10% → LOW (normal growth)
- Drift >10% and ≤30% → MEDIUM (needs update)
- Drift >30% → HIGH (significantly stale)
- Claim cannot be verified → MEDIUM (ambiguous claim)
Write findings incrementally to report after each doc scanned. NEVER batch at end.
Phase 2: Stale Config Reference Detection (No Graph Required)
Think: Which config values reference code artifacts (class names, module names, connection strings)? Could those artifacts have been renamed or deleted?
For each file matching configPatterns:
- Extract class names, module names, or connection strings referenced
- Grep codebase to verify each reference still exists
- Flag missing references as HIGH severity
Evidence gate: NEVER flag a reference as stale without attempting grep. Confidence <80% → flag as MEDIUM "unverified" only.
Phase 3: Unused Exports Detection (Graph Required)
Skip if .code-graph/graph.db does not exist — log "Phase 3 skipped: no graph.db".
Think: Which public API surface has zero consumers? Could be dead code, or could be an intentional entry point — distinguish by file type.
For key exported symbols in source files:
- Run
python .claude/scripts/code_graph query importers_of <symbol> --json
- Flag symbols with zero importers as MEDIUM severity
- Exclude known entry points (main files, test files, config files, startup files)
Phase 4: Orphan File Detection (Graph Required)
Skip if .code-graph/graph.db does not exist — log "Phase 4 skipped: no graph.db".
Find source files (.ts,.cs,.py, etc.) with zero inbound edges:
- Run
python .claude/scripts/code_graph query importers_of <file> --json
- Flag files with zero importers as LOW severity (may be entry points)
- Exclude known entry points
Phase 5: Pattern Drift Detection (No Graph Required)
Think: Where does the same pattern appear across services/modules? Does it look different in different places? Is that divergence intentional or accidental?
Compare the same pattern across services/modules:
- Pick a pattern (e.g., repository registration, service configuration, error handling)
- Grep across all services/modules
- Flag inconsistencies as MEDIUM severity
Phase 6: Dead Feature Flag Detection (If Feature Flags Detected)
Skip if no feature flag patterns found in Phase 0.
Think: Which flags exist in config but have no code references? Which code references flags that no longer exist in config?
- Grep for feature flag names in config files
- Grep for feature flag usage in code
- Flag config-only flags (no code usage) as LOW
- Flag code-only flags (no config entry) as HIGH (runtime error risk)
Phase 7: Broken Cross-Reference Detection (No Graph Required)
Think: Which doc links point to files that no longer exist? Which file:line references in docs are stale?
For docs containing markdown links [text](path) or file:line references:
- Extract all file path references
- Glob to verify each path exists
- Flag missing paths as MEDIUM severity
Phase 8: Fresh-Eyes Review
Before writing final report, spawn a fresh sub-agent (zero memory) to:
- Sample 5-10 findings from the report
- Verify each has a real
file:line evidence source
- Check: is the severity classification justified by the description?
- Flag false positives (things flagged but actually acceptable)
Max 2 rounds → escalate to user if review finds >30% false positive rate.
Phase 9: Generate Report
Write to plans/reports/codebase-health-scan-{YYMMDD}.md:
# Codebase Health Scan Report
**Date:** {YYYY-MM-DD}
**Phases Completed:** {N}/{total} ({reason for skipped phases})
**Findings:** {total} ({HIGH} high, {MEDIUM} medium, {LOW} low)
## Summary
| Phase | Status | Findings |
| ----------------------- | ----------------------------------- | ---------- |
| Doc Count-Drift | Scanned | N findings |
| Stale Config Refs | Scanned | N findings |
| Unused Exports | Scanned/Skipped (no graph.db) | N findings |
| Orphan Files | Scanned/Skipped (no graph.db) | N findings |
| Pattern Drift | Scanned | N findings |
| Dead Feature Flags | Scanned/Skipped (no flags detected) | N findings |
| Broken Cross-References | Scanned | N findings |
## Findings
### HIGH Severity
- `{file}:{line}`: {description} — Action: {action}
### MEDIUM Severity
- `{file}:{line}`: {description} — Action: {action}
### LOW Severity
- `{file}:{line}`: {description} — Action: {action}
## False Positives (Fresh-Eyes Review)
{Findings dismissed by Round 2 review with reasoning}
[IMPORTANT] Use TaskCreate to break ALL work into small tasks BEFORE starting.
Critical Thinking Mindset — Apply critical thinking, sequential thinking. Every claim needs traced proof, confidence >80% to act.
Anti-hallucination: Never present guess as fact — cite sources for every claim, admit uncertainty freely, self-check output for errors, cross-reference independently, stay skeptical of own confidence — certainty without evidence root of all hallucination.
Output Quality — Token efficiency without sacrificing quality.
- No inventories/counts — AI can
grep | wc -l. Counts go stale instantly
- No directory trees — AI can
glob/ls. Use 1-line path conventions
- No TOCs — AI reads linearly. TOC wastes tokens
- No examples that repeat what rules say — one example only if non-obvious
- Lead with answer, not reasoning. Skip filler words and preamble
- Sacrifice grammar for concision in reports
- Unresolved questions at end, if any
AI Mistake Prevention — Failure modes to avoid on every task:
Re-read files after context changes. Context compaction, resume, or long-running work can make memory stale; verify current files before acting.
Verify generated content against source evidence. AI hallucinates APIs, names, claims, and document facts. Check the relevant source before documenting or referencing.
Check downstream references before deleting or renaming. Removing an artifact can stale docs, generated mirrors, configs, and callers; map references first.
Trace the full impact chain after edits. Changing a definition can miss derived outputs and consumers. Follow the affected chain before declaring done.
Verify ALL affected outputs, not just the first. One green check is not all green checks; validate every output surface the change can affect.
Assume existing values are intentional — ask WHY before changing. Before changing a constant, limit, flag, wording, or pattern, read nearby context and history.
Surface ambiguity before acting — don't pick silently. Multiple valid interpretations require an explicit question or stated assumption with risk.
Keep shared guidance role-relevant. Universal guidance must help every receiving skill or agent; code-specific obligations belong only in code-specific protocols.
IMPORTANT MUST ATTENTION output quality: no counts/trees/TOCs, 1 example per pattern, lead with answer.
MUST ATTENTION apply critical + sequential thinking — every claim needs appropriate traced evidence (file:line for repo/code claims; source URL or artifact section for research, product, content, and docs claims); confidence >80% to act, <60% DO NOT recommend. Anti-hallucination: never present guess as fact, admit uncertainty freely, cross-reference independently, stay skeptical of own confidence.
MUST ATTENTION apply AI mistake prevention — verify generated content against evidence, trace downstream references before deleting or renaming, verify all affected outputs, re-read files after context loss, and surface ambiguity before acting.
Closing Reminders
IMPORTANT MUST ATTENTION break work into small TaskCreate tasks BEFORE starting — one per phase
MUST ATTENTION — Protocols in force (concise digest of the SYNC/shared blocks this skill carries):
- Critical Thinking: apply critical+sequential thinking; traced
file:line proof, >80% to act.
- Output Quality: no counts/trees/TOCs; 1 example per pattern; lead with answer.
- AI Mistake Prevention: verify generated content against evidence, trace downstream references, verify all affected outputs, re-read after context loss, surface ambiguity.
IMPORTANT MUST ATTENTION detect available tooling in Phase 0 — never assume graph.db exists
IMPORTANT MUST ATTENTION NEVER report a finding without file:line evidence
IMPORTANT MUST ATTENTION write findings incrementally after each phase — NEVER batch at end
IMPORTANT MUST ATTENTION severity thresholds are concrete: HIGH = runtime failure risk; MEDIUM = drift/dead code; LOW = cleanup candidate
IMPORTANT MUST ATTENTION Phase 8 fresh-eyes review is mandatory — prevents false positives from rationalization
Anti-Rationalization:
| Evasion | Rebuttal |
|---|
| "Graph not needed, skip Phases 3-4" | Phases 3-4 are explicitly gated — state skip reason in report, don't silently omit |
| "Count drift is small, LOW severity is fine" | Apply the threshold table: >10% = MEDIUM, >30% = HIGH. No discretionary override. |
| "Finding looks valid, skip Round 2 review" | Main agent rationalizes own findings. Fresh-eyes is non-negotiable. |
| "No feature flags found, skip Phase 6" | Log "Phase 6 skipped: no feature flag patterns detected" in report |
| "Config reference might still exist" | Grep to verify. Confidence <80% → flag as MEDIUM "unverified" not LOW "probably fine" |
[TASK-PLANNING] Before acting, analyze task scope and break into small todo tasks and sub-tasks using TaskCreate.