@agentty-xyz/tech-debt
ASweep the codebase for tech debt and return a prioritized markdown task list of findings.
Install
agr install @agentty-xyz/tech-debt --target claudeWrites 1 file into .claude/skills/, pinned to git-af15c185.
- .claude/skills/tech-debt/SKILL.md
Document
name: tech-debt description: Sweep the codebase for tech debt and return a prioritized markdown task list of findings.
Tech Debt Skill
Use this skill when asked to find tech debt, stale patterns, or maintenance issues in a codebase.
The user may scope the sweep to specific directories or modules (e.g., "sweep
crates/agentty/src/app"). When a scope is given, restrict traversal to those paths.
When no scope is given, sweep the full codebase.
Workflow
-
Read Project Context
- Read the root
AGENTS.mdfor project conventions, architecture references, and style rules. - Identify which directories and modules are relevant to the sweep (respecting any user-provided scope).
- Read the root
-
Traverse Target Directories
- Navigate into each target directory and read the nearest available
AGENTS.mdfor local conventions, entry points, and change guidance. - Use the architecture docs and module routers to prioritize which files and modules to inspect when no deeper local guide exists.
- Navigate into each target directory and read the nearest available
-
Analyze for Tech Debt
- TODOs and FIXMEs: Find
TODO,FIXME,HACK, andXXXcomments that indicate deferred work. - Outdated Patterns: Identify deprecated API usage, legacy code paths retained without justification, and patterns that conflict with current project conventions.
- Inconsistent Error Handling: Flag mixed error handling strategies (e.g.,
unwrap()alongside properResultpropagation), swallowed errors, and missing error context. - Missing Documentation: Note public types, traits, and functions lacking doc comments, especially in areas with complex logic.
- Stale Dependencies: Look for pinned dependency versions that lag behind current releases, unused dependencies, or feature flags that are no longer needed.
- Dead Code: Identify unused functions, modules, imports, or feature gates that can be removed.
- Test Gaps: Flag critical logic paths that lack test coverage or tests that are
marked
#[ignore]. - Convention Violations: Check code against the project conventions discovered in Step 1 (e.g., naming rules, module layout, import style, constructor patterns) and flag deviations.
- TODOs and FIXMEs: Find
-
Return Findings as a Task List
- Structure your answer as a prioritized markdown task list.
- Use the format below for each finding.
Task List Format
# Tech Debt Report
## Summary
[Brief overview: total finding count, highest-risk area, and overall codebase health impression.]
## Critical
- [ ] **[Title]** — `[file/module scope]`
[Description of the issue and why it is critical.]
## High
- [ ] **[Title]** — `[file/module scope]`
[Description of the issue and recommended action.]
## Medium
- [ ] **[Title]** — `[file/module scope]`
[Description of the issue and recommended action.]
## Low
- [ ] **[Title]** — `[file/module scope]`
[Description of the issue and recommended action.]
Priority Guidelines
| Priority | Criteria |
|---|---|
| Critical | Causes runtime failures, data loss, or blocks other work. |
| High | Significant maintenance burden, outdated patterns actively causing confusion, or missing error handling in critical paths. |
| Medium | Style inconsistencies, missing documentation, minor dead code, or deferred TODOs with clear scope. |
| Low | Cosmetic issues, minor naming improvements, or optional cleanup with no immediate impact. |
Trustgrade A
- passBody integrity
Whether the stored document is plausibly the kind of file the artifact declares, rather than something fetched by mistake.
- passType matchnot applicable to this artifact type
Whether the artifact is really the kind of thing its metadata claims it is.
- passFreshness
How long since the source repository was last pushed to.
- passPrompt injection
Scans the artifact's own text for instructions aimed at your agent rather than at you.
- passLicense
Whether the source repository declares an SPDX license permissive enough to redistribute.
How the grade is calculated
Each check contributes 0 points when it passes, 1 when it warns, and 2 when it fails. The total maps to a letter:
- Aevery check passed
- Bone warning
- Ctwo warnings
- Dprompt injection or body integrity failed, or three warnings
- Fone of those failed, and something else is wrong
These are automated hygiene checks, not a security audit, and not a dependency or vulnerability scan. A grade of A means nothing was flagged — not that the artifact is safe.
Versions
git-af15c1851fda2026-07-31