codebase-analysis-ee7f61 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited codebase-analysis-ee7f61 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Execute a structured 3-phase codebase analysis workflow to gather insights.
Goal: Explore the codebase and synthesize findings.
.agents/sessions/exploration-cache/manifest.md existscodebase_path matches the current working directory, and timestamp is within the configured cache TTL (default 24 hours).agents/sessions/exploration-cache/synthesis.md and recon from recon_summary.md. Set CACHE_HIT = true and CACHE_TIMESTAMP to the cache's timestamp. Skip step 3 and proceed directly to step 4.CACHE_HIT = false, and proceed to step 3CACHE_HIT = false and proceed to step 3CACHE_TIMESTAMP = null (fresh results, no prior cache)CACHE_HIT), cache timestamp if applicable (CACHE_TIMESTAMP), and the number of explorer agents used (from the deep-analysis team plan, or 0 if cached)Goal: Present a structured analysis to the user.
Structure the report with these sections (see Report Template below for full details):
Goal: Let the user save, document, or retain analysis insights from the report through a multi-step interactive flow.
Prompt the user to choose (multi-select) from all available actions:
If the user selects no actions, the workflow is complete. Thank the user and end.
Process selected actions in the following fixed order. Complete all sub-steps for each action before moving to the next.
#### Action: Save Codebase Analysis Report
Step 2a-1: Prompt for file location
internal/docs/ directory exists in the project rootinternal/docs/codebase-analysis-report-{YYYY-MM-DD}.mdcodebase-analysis-report-{YYYY-MM-DD}.md in the project rootStep 2a-2: Generate and save the report
#### Action: Save Custom Report
Step 2b-1: Gather report requirements
Step 2b-2: Prompt for file location
internal/docs/ directory exists in the project rootinternal/docs/custom-report-{YYYY-MM-DD}.mdcustom-report-{YYYY-MM-DD}.md in the project rootStep 2b-3: Generate and save the custom report
#### Action: Update Project Documentation
Step 2c-1: Select documentation files and gather directions
Prompt the user to choose (multi-select):
Then prompt for update directions for all selected files: "What content from the analysis should be added or updated? Provide general directions or specific sections to focus on (applies across all selected files, or specify per-file directions)."
Step 2c-2: Generate and approve documentation drafts
For each selected file, read the existing file and generate a draft based on the user's directions and Phase 2 analysis data:
Present all drafts together in a single output, clearly labeled by file. Then prompt the user to choose:
If approved, apply updates by modifying existing files or writing new files.
#### Action: Keep Insights in Memory
This step always executes after Step 2 completes. The Phase 2 analysis is available in conversation context regardless of whether a report file was saved.
Prompt the user to choose:
If the user selects "Skip", proceed to Step 4.
If the user selects "Address actionable insights":
Step 3a: Extract actionable items from the report
Parse the Phase 2 report (in conversation context) to extract items from:
If no actionable items are found, inform the user and skip to Step 4.
Step 3b: Present severity-ranked item list
Present items sorted High to Medium to Low using the Actionable Insights format (see below), each showing:
Prompt the user to choose which items to address (multi-select). If no items selected, skip to Step 4.
Step 3c: Process each selected item in priority order (High to Medium to Low)
For each item:
agents/code-architect.md for instructions) with context: the item title, severity, description, the relevant report section text, and any files or components mentioned. The agent designs the fix and returns a proposal.../deep-analysis/agents/code-explorer.md) with context: the item title, description, suspected files/components, and what needs investigation. The agent explores and returns findings for you to formulate a fix proposal.Step 3d: Summarize results
Present a summary covering:
Summarize which actions were executed and confirm the workflow is complete.
If any phase fails:
If a file write or edit fails when applying documentation updates:
If a code-architect or code-explorer agent fails during actionable insight processing:
Exploration and synthesis agent coordination is handled by the deep-analysis skill in Phase 1, which uses agent teams with hub-and-spoke coordination. Deep-analysis performs reconnaissance, composes a team plan (auto-approved when invoked by another skill), assembles the team, and manages the exploration/synthesis lifecycle. See that skill for team setup, approval flow, and failure handling details.
This skill uses the following nested agent:
This skill also cross-references agents from the deep-analysis skill:
Use this template when presenting analysis findings in Phase 2.
# Codebase Analysis Report
**Analysis Context**: {What was analyzed and why}
**Codebase Path**: {Path analyzed}
**Date**: {YYYY-MM-DD}
{If the report exceeds approximately 100 lines, add a **Table of Contents** here linking to each major section.}
---
## Executive Summary
{Lead with the most important finding. 2-3 sentences covering: what was analyzed, the key architectural insight, and the primary recommendation or risk.}
---
## Architecture Overview
{2-3 paragraphs describing:}
- How the codebase is structured (layers, modules, boundaries)
- The design philosophy and architectural style
- Key architectural decisions and their rationale
{Include a Mermaid architecture diagram (flowchart or C4 Context) showing the major layers/components. Use `classDef` with `color:#000` for all node styles.}
---
## Tech Stack
| Category | Technology | Version (if detected) | Role |
|----------|-----------|----------------------|------|
| Language | {e.g., TypeScript} | {e.g., 5.x} | Primary language |
| Framework | {e.g., Next.js} | {e.g., 16} | Web framework |
{Include only technologies actually detected in config files or code. Omit categories that don't apply.}
---
## Critical Files
{Limit to 5-10 most important files}
| File | Purpose | Relevance |
|------|---------|-----------|
| `path/to/file` | Brief description | High/Medium |
### File Details
#### `path/to/critical-file`
- **Key exports**: What this file provides to others
- **Core logic**: What it does
- **Connections**: What depends on it and what it depends on
---
## Patterns & Conventions
### Code Patterns
- **Pattern**: Description and where it's used
### Naming Conventions
- **Convention**: Description and examples
### Project Structure
- **Organization**: How files and directories are organized
---
## Relationship Map
{Describe how key components connect — limit to 15-20 most significant connections. Use Mermaid flowcharts for both data flows and dependency maps.}
---
## Challenges & Risks
| Challenge | Severity | Impact |
|-----------|----------|--------|
| {Description} | High/Medium/Low | {What could go wrong} |
---
## Recommendations
1. **{Recommendation}** _(addresses: {Challenge name})_: {Brief rationale}
2. **{Recommendation}** _(addresses: {Challenge name})_: {Brief rationale}
---
## Analysis Methodology
- **Exploration agents**: {Number} agents with focus areas: {list}
- **Synthesis**: Findings merged and critical files read in depth
- **Scope**: {What was included and what was intentionally excluded}
- **Cache status**: {Fresh analysis / Cached results from YYYY-MM-DD}Executive Summary: Lead with the most important finding, not a generic overview. Keep to 2-3 sentences. Include at least one actionable insight.
Critical Files: Limit to 5-10 files that someone must understand. Include both the "what" (purpose) and "why" (relevance to analysis context).
Patterns & Conventions: Only include patterns that are consistently applied. Note deviations from patterns — these are often more interesting than the patterns themselves.
Relationship Map: Focus on the most important connections, not an exhaustive dependency graph. Use directional language (calls, depends on, triggers, reads from). Cap at 15-20 connections.
Challenges & Risks: Rate severity based on likelihood and impact combined. Include specific details, not vague warnings.
Recommendations: Make recommendations actionable. Each must reference the specific challenge it addresses using the format: _(addresses: {Challenge name})_. Limit to 3-5 recommendations.
For Feature-Focused Analysis: Emphasize integration points and files that would need modification. Include a "Feature Implementation Context" section before Recommendations.
For General Codebase Understanding: Broader Architecture Overview with layer descriptions. More extensive Patterns & Conventions section.
For Debugging/Investigation: Emphasize the execution path and data flow. Include a "Relevant Execution Paths" section.
Present extracted items grouped by severity, highest first:
### High Severity
1. **{Title}** — _{Source: Challenges & Risks}_
{Brief description of the issue and its impact}
### Medium Severity
2. **{Title}** — _{Source: Recommendations}_
{Brief description and rationale}
### Low Severity
3. **{Title}** — _{Source: Other Findings}_
{Brief description}From Challenges & Risks Table: Use the Severity column value directly. Title comes from the Challenge column. Description comes from the Impact column.
From Recommendations Section: Each recommendation should cite which challenge it addresses. Use this citation to inherit severity. If no challenge link is present, default to Medium.
From Other Findings: Default to Low unless the finding explicitly describes a critical issue.
| Complexity | Typical Effort | Description |
|---|---|---|
| Simple | Low (~minutes) | Single targeted change, clear fix |
| Complex — Architectural | Medium-High (~30min-1hr+) | Multi-file refactoring, design decisions |
| Complex — Investigation | Medium (~15-30min) + varies | Investigation phase + fix implementation |
#### {Item Title} ({Severity})
**Complexity:** Simple / Complex (architectural) / Complex (investigation)
**Effort:** Low (~minutes) / Medium (~30min) / High (~1hr+)
**Files to modify:**
| File | Change Type |
|------|-------------|
| `path/to/file` | Edit / Create / Delete |
**Proposed changes:**
{Description of what will change and why.}
**Rationale:**
{Why this approach was chosen. Reference the original finding.}## Actionable Insights Summary
### Items Addressed
| # | Item | Severity | Files Modified |
|---|------|----------|----------------|
| 1 | {Title} | High | `file1.ts`, `file2.ts` |
### Items Skipped
| # | Item | Severity | Reason |
|---|------|----------|--------|
| 2 | {Title} | Low | User skipped |
### Files Modified
| File | Changes |
|------|---------|
| `path/to/file` | {Brief description of change} |
**Total:** {N} items addressed, {M} items skipped, {P} files modified~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.