Catalog
affaan-m/repo-scan

affaan-m

repo-scan

Cross-stack source code asset audit — classifies every file, detects embedded third-party libraries, and delivers actionable four-level verdicts per module with interactive HTML reports.

global
origin:community
New~872
v1.2Saved Jul 14, 2026

repo-scan

Every ecosystem has its own dependency manager, but no tool looks across C++, Android, iOS, and Web to tell you: how much code is actually yours, what's third-party, and what's dead weight.

When to Use

  • Taking over a large legacy codebase and need a structural overview
  • Before major refactoring — identify what's core, what's duplicate, what's dead
  • Auditing third-party dependencies embedded directly in source (not declared in package managers)
  • Preparing architecture decision records for monorepo reorganization

Installation

# Fetch only the pinned commit for reproducibility
mkdir -p ~/.claude/skills/repo-scan
git init repo-scan
cd repo-scan
git remote add origin https://github.com/haibindev/repo-scan.git
git fetch --depth 1 origin 2742664
git checkout --detach FETCH_HEAD
cp -r . ~/.claude/skills/repo-scan

Review the source before installing any agent skill.

Core Capabilities

Capability Description
Cross-stack scanning C/C++, Java/Android, iOS (OC/Swift), Web (TS/JS/Vue) in one pass
File classification Every file tagged as project code, third-party, or build artifact
Library detection 50+ known libraries (FFmpeg, Boost, OpenSSL…) with version extraction
Four-level verdicts Core Asset / Extract & Merge / Rebuild / Deprecate
HTML reports Interactive dark-theme pages with drill-down navigation
Monorepo support Hierarchical scanning with summary + sub-project reports

Analysis Depth Levels

Level Files Read Use Case
fast 1-2 per module Quick inventory of huge directories
standard 2-5 per module Default audit with full dependency + architecture checks
deep 5-10 per module Adds thread safety, memory management, API consistency
full All files Pre-merge comprehensive review

How It Works

  1. Classify the repo surface: enumerate files, then tag each as project code, embedded third-party code, or build artifact.
  2. Detect embedded libraries: inspect directory names, headers, license files, and version markers to identify bundled dependencies and likely versions.
  3. Score each module: group files by module or subsystem, then assign one of the four verdicts based on ownership, duplication, and maintenance cost.
  4. Highlight structural risks: call out dead-weight artifacts, duplicated wrappers, outdated vendored code, and modules that should be extracted, rebuilt, or deprecated.
  5. Produce the report: return a concise summary plus the interactive HTML output with per-module drill-down so the audit can be reviewed asynchronously.

Examples

On a 50,000-file C++ monorepo:

  • Found FFmpeg 2.x (2015 vintage) still in production
  • Discovered the same SDK wrapper duplicated 3 times
  • Identified 636 MB of committed Debug/ipch/obj build artifacts
  • Classified: 3 MB project code vs 596 MB third-party

Best Practices

  • Start with standard depth for first-time audits
  • Use fast for monorepos with 100+ modules to get a quick inventory
  • Run deep incrementally on modules flagged for refactoring
  • Review the cross-module analysis for duplicate detection across sub-projects
Files1
1 files · 1.0 KB

Select a file to preview

Overall Score

72/100

Grade

B

Good

Safety

75

Quality

68

Clarity

78

Completeness

63

Summary

repo-scan is a cross-stack source code asset audit tool that classifies files across C++, Android, iOS, and Web ecosystems, detects embedded third-party libraries, and generates interactive HTML reports with four-level verdicts (Core Asset / Extract & Merge / Rebuild / Deprecate) per module. The skill guides users to install a pinned external repository and use it for legacy codebase analysis.

Detected Capabilities

file read (enumeration and header inspection)git clone (specific commit)code classification analysishtml report generationdirectory traversal and pattern matching

Trigger Keywords

Phrases that MCP clients use to match this skill to user intent.

legacy code auditthird-party library detectioncode classificationmonorepo analysisvendor code discoveryrefactor planning

Risk Signals

WARNING

External repository fetch and execution without in-skill logic detail

Installation section (git fetch + checkout)
WARNING

No documentation of what analysis engine runs post-install or what it does with files

Core Capabilities section
INFO

No specification of output directory or report location

How It Works section
INFO

No error handling or validation steps documented for the scan operation

Full skill
INFO

No explicit statement of what file types are safe/unsafe to scan

Analysis Depth Levels section

Referenced Domains

External domains referenced in skill content, detected by static analysis.

github.com

Use Cases

  • Taking over legacy codebases and understanding structural composition
  • Identifying embedded third-party dependencies not tracked in package managers
  • Detecting duplicate code and dead artifacts before major refactoring
  • Auditing monorepo architecture and preparing reorganization decisions
  • Assessing maintenance burden and version currency of vendored libraries

Quality Notes

  • Skill clearly defines cross-stack scope (C++, Java, iOS, Web) — good domain boundaries
  • Four analysis depth levels (fast/standard/deep/full) are well-explained with use cases
  • Real example (50,000-file C++ repo findings) is concrete and actionable
  • Best Practices section provides clear guidance for depth selection
  • Monorepo support is well-positioned as a key capability
  • Installation instructions include a 'review before installing' warning — good security hygiene
  • Weakness: skill does not document what the external tool actually does, how it accesses files, or how the HTML report is generated — this is delegated entirely to an external repository
  • Weakness: no discussion of how sensitive files (credentials, configs) are handled during scan
  • Weakness: no error scenarios or failure modes documented
  • Strength: license explicitly included (MIT)
Model: claude-haiku-4-5-20251001Analyzed: Jul 14, 2026

Reviews

Add this skill to your library to leave a review.

No reviews yet

Be the first to share your experience.

Version History

v1.2

Content updated

2026-07-14

Latest
v1.1

Content updated

2026-04-20

v1.0

No changelog

2026-04-12

Use affaan-m/repo-scan in your dev environment

Command Palette

Search for a command to run...