find-dead-code-a2959f — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited find-dead-code-a2959f (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Identify dead code in a codebase. Core rule: code only used in tests is still dead code. Only production usage counts.
Determine the project structure:
package.json, tsconfig.json, pyproject.toml, setup.py, Package.swift, .xcodeproj, Cargo.toml, go.mod, pom.xml, build.gradle**/*.ts, **/*.py, **/*.swift, **/*.go, **/*.rs, **/*.javasrc/, lib/, Sources/)src/auth/, src/api/, src/utils/, lib/models/). Each directory becomes one subagent's scope in Step 3.If the user specified a scope, restrict analysis to that scope.
Establish which files are test files. Code referenced ONLY from these locations is dead.
| Language | Test file patterns |
|---|---|
| TS/JS | *.test.{ts,tsx,js,jsx}, *.spec.{ts,tsx,js,jsx}, __tests__/**, __mocks__/**, *.stories.{ts,tsx,js,jsx} |
| Python | test_*.py, *_test.py, tests/**, test/**, conftest.py |
| Swift | *Tests.swift, *Test.swift, Tests/**, *UITests.swift, XCTestCase subclasses |
| Go | *_test.go, testdata/** |
| Rust | tests/**, benches/**, #[cfg(test)] modules (inline test modules within source files) |
| Java/Kotlin | src/test/**, *Test.java, *Tests.java, *Spec.java, *Test.kt |
| General | fixtures/**, __fixtures__/**, mocks/**, testutils/**, testhelpers/**, spec/** |
Also exclude: test runner configs (jest.config.*, vitest.config.*, pytest.ini), storybook files, benchmark files.
If a CLI tool is installed, run it as a fast first pass for zero-reference dead code.
| Language | Tool | Check | Run | |
|---|---|---|---|---|
| TS/JS | knip | npx knip --version | npx knip --no-exit-code | |
| Python | vulture | vulture --version | vulture <src_dirs> --min-confidence 80 | |
| Swift | periphery | which periphery | periphery scan --skip-build | |
| Go | deadcode | which deadcode | deadcode ./... | |
| Rust | compiler warnings | — | `cargo build 2>&1 \ | grep "dead_code"` |
Important limitation: CLI tools count test imports as real usage. They cannot detect code that is only used in tests. They only find symbols with literally zero references anywhere. Step 3 is required for test-only detection.
If no CLI tool is installed, skip to Step 3. Do not ask the user to install anything.
This is the primary analysis. Launch one subagent per top-level source directory from Step 1 in a single assistant message so they run concurrently. State the count explicitly when emitting the calls. Each subagent's prompt directs it to treat the shared working tree and its git index as read-only — any empirical check runs in an isolated git worktree the subagent discards afterward.
Each subagent receives:
Each subagent performs these steps on its assigned directory:
a) Find exported/public symbols:
| Language | Exported symbol patterns |
|---|---|
| TS/JS | export function, export const, export let, export var, export class, export interface, export type, export enum, export default, module.exports |
| Python | Top-level def and class in non-_-prefixed modules, module-level constants (FOO = ...), symbols in __all__, public functions (no _ prefix) |
| Swift | public func, public var, public let, public class, public struct, public enum, public protocol, open class, open func, open var |
| Go | Capitalized identifiers: func FooBar, type FooBar struct, var FooBar, const FooBar (Go uses capitalization for public visibility) |
| Rust | pub fn, pub struct, pub enum, pub trait, pub const, pub static, pub type, pub mod |
| Java/Kotlin | public class, public static, public void, public fields, val/var properties, fun (top-level), @Bean, @Component, @Service annotated classes |
b) For each symbol, grep across the entire codebase for references, excluding:
node_modules/, dist/, build/, vendor/, __pycache__/, .tox/, .build/, DerivedData/, target/)c) Classify each reference as test or production based on the test file patterns.
CRITICAL — same-module references count as production usage. A symbol called by another production file within the same module/package is alive. Do not report symbols as "dead" when they have zero external callers but are used internally. Only report symbols with zero production references from any file. "Unnecessarily public" (could be internal/unexported) is a visibility issue, not dead code — do not include it.
d) Report structured results for each symbol:
dead (zero prod refs anywhere), test-only (only test refs), alive (has prod refs)After all subagents complete, collect and merge their results. Deduplicate any symbols that appear in multiple reports (e.g., re-exports).
Apply these filters to the merged results from Steps 2 and 3:
init() and main() functions, Go interface implementations, Rust main(), Rust trait implementations, #[derive(...)] generated code, CLI handlers registered in main, magic/lifecycle methods (__init__, __repr__), serialization methods (to_json, from_dict), interface/protocol implementationsindex.ts, __init__.py) before declaring a symbol dead. A symbol re-exported through a barrel may have indirect consumers.getattr, importlib, reflect package in Go, proc_macro in Rust), string-based lookups, or decorator/attribute registration as "likely dead" rather than "definite".turbo/specs/, ROADMAP.md, TODO.md), cross-reference test-only findings against them. Test-only APIs may be planned features awaiting integration — flag as investigate rather than deleteClassify each finding:
Run the $evaluate-findings skill on the classified results to verify each finding against the actual code and weed out false positives. Read the full definition file for each finding — not just the flagged symbol. The surrounding code may reveal that the feature is already implemented differently (e.g., a public ping() method may be test-only while a private keepalive loop in handleConnect() does the real work).
Proceed with the evaluation results in the next section.
For each surviving finding, assign a recommendation:
| Signal | Recommendation |
|---|---|
| No tests, no production usage | delete |
| Has tests but no production usage, and no spec/roadmap reference | delete (method + test assertions) |
| Has tests but no production usage, referenced in spec/roadmap/TODO | investigate (planned feature, not dead) |
| Partially wired up, unclear intent, or needs domain context | investigate |
For findings marked investigate, run the $investigate skill to determine whether the code is a planned feature, an unwired integration, or truly dead.
Watch for these high-yield patterns that tools and simple grep often miss:
isEnabled, count, currentItems). The module's production consumers use behavior (events, callbacks, side effects) — only tests peek at the internal state. When removing these, the corresponding test assertions must also be removed or rewritten to use behavior-based verification.While scanning for dead code, note (but do not act on) these related issues for the user:
Group results by confidence level:
| File | Symbol | Type | Line Range | Recommendation |
|---|
| File | Symbol | Type | Test files referencing it | Recommendation |
|---|
| File | Symbol | Type | Reason for uncertainty | Recommendation |
|---|
Include:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.