Source profileQuality 81/100

wshobson/agents/plugins/skill-forge-essentials/skills/ai-debt-detector/SKILL.md

ai-debt-detector

Use after generating code, after accepting AI suggestions, or when reviewing AI-written modules. Also use when code works but feels brittle, when error handling seems thin, when orphaned resources or missing cleanup are suspected, or when the agent claims done but hidden debt may exist. Catches the specific failure patterns AI agents produce that humans would not.

Source repository stars
38,313
Declared platforms
0
Static risk flags
0
Last source update
2026-07-22
Source checked
2026-07-28

Decision brief

What it does—and where it fits

Use after generating code, after accepting AI suggestions, or when reviewing AI-written modules. Catches the specific failure patterns AI agents produce that humans would not.

Best for

  • After any AI code generation session (20+ lines produced)
  • Before merging AI-generated PRs
  • When code works but something feels off

Not for

  • Trusting that compilation means correctness (compilation checks syntax, not logic)
  • Reviewing only the diff without checking what the AI did NOT generate (missing error paths)

Compatibility matrix

Platform support, with evidence labels

PlatformStatusEvidenceWhat to check
CodexNot declaredNo explicit evidencePortability before use
Claude CodeNot declaredNo explicit evidencePortability before use
CursorNot declaredNo explicit evidencePortability before use
Gemini CLINot declaredNo explicit evidencePortability before use
Open the compatibility checker

Installation

Inspect first. Install second.

The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

Source-detected install commandSource
npx skills add https://github.com/wshobson/agents --skill "plugins/skill-forge-essentials/skills/ai-debt-detector"
Safe inspection promptEditorial

Inspect the Agent Skill "ai-debt-detector" from https://github.com/wshobson/agents/blob/c4b82b0ad771190355eb8e204b1329732a18449a/plugins/skill-forge-essentials/skills/ai-debt-detector/SKILL.md at commit c4b82b0ad771190355eb8e204b1329732a18449a. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

Workflow

What the source asks the agent to do

  1. 01

    Process

    After code generation, scan for these AI-specific debt patterns:

    FAILURE MODES - What happens when this fails?Network timeout? Disk full? Permission denied? Null input?Is there a try/catch? Does it catch SPECIFIC errors or swallow everything?
  2. 02

    When to Use

    After any AI code generation session (20+ lines produced)

    After any AI code generation session (20+ lines produced)Before merging AI-generated PRsWhen code works but something feels off
  3. 03

    Red Flags (stop and fix immediately)

    catch (e) {} or catch (e) { console.log(e) } - swallowed error

    catch (e) {} or catch (e) { console.log(e) } - swallowed errorNo finally block when resources were opened// TODO: handle error - AI's way of punting
  4. 04

    Common Mistakes

    Trusting that compilation means correctness (compilation checks syntax, not logic)

    Trusting that compilation means correctness (compilation checks syntax, not logic)Reviewing only the diff without checking what the AI did NOT generate (missing error paths)Assuming the AI used the right library version (it often uses deprecated APIs)

Permission review

Static risk signals and limitations

No configured static risk pattern was detected

This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.

Evidence record

Why each signal appears

EvidenceSourceComputedTestedEditorial
SignalValueEvidence typeMeaning
Quality score81/100ComputedDocumentation, specificity, maintenance, and trust rules
Repository stars38,313SourceRepository attention, not individual Skill quality
Compatibility0 platformsSourceDeclared in the catalog source record
Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

Pinned source

Provenance and original SKILL.md

Repository
wshobson/agents
Skill path
plugins/skill-forge-essentials/skills/ai-debt-detector/SKILL.md
Commit
c4b82b0ad771190355eb8e204b1329732a18449a
License
MIT
Collected
2026-07-28
Default branch
main
View the original SKILL.md

AI Debt Detector

Overview

AI agents generate code that passes the happy path but hides debt: missing error handling, orphaned resources, ignored failure modes, hallucinated packages, silent architectural drift. This skill forces a targeted audit for the exact patterns AI agents get wrong.

When to Use

  • After any AI code generation session (20+ lines produced)
  • Before merging AI-generated PRs
  • When code works but something feels off
  • After vibe-coding sprints where debt accumulates fastest
  • When the agent claims done without showing verification

Process

After code generation, scan for these AI-specific debt patterns:

  1. FAILURE MODES - What happens when this fails?

    • Network timeout? Disk full? Permission denied? Null input?
    • Is there a try/catch? Does it catch SPECIFIC errors or swallow everything?
    • Are resources cleaned up on failure? (streams closed, connections returned, temp files deleted)
  2. ORPHANS - What gets created but never cleaned up?

    • Temp files, event listeners, intervals, subscriptions, connections
    • Are there corresponding cleanup/dispose/close calls for every open/create?
    • In React: does every addEventListener have a removeEventListener in cleanup?
  3. EDGE CASES - What inputs break this?

    • Empty array/string? null/undefined? Multi-MB input? Unicode? Concurrent calls?
    • Does the code assume the happy path? (AI almost always does)
  4. HALLUCINATED DEPS - Do all imports actually exist?

    • Is every package in package.json/requirements.txt?
    • Are API methods real? (AI invents plausible-sounding methods that don't exist)
    • Does this library's latest version still export this function?
  5. ARCHITECTURAL DRIFT - Does this match the project's patterns?

    • Same error handling style as existing code?
    • Uses the project's established utilities (not reinventing)?
    • Follows the file structure convention?

Red Flags (stop and fix immediately)

  • catch (e) {} or catch (e) { console.log(e) } - swallowed error
  • No finally block when resources were opened
  • // TODO: handle error - AI's way of punting
  • Import from a path that doesn't exist in the project
  • Timeout set but no abort/cleanup on timeout
  • Database connection opened but never released back to pool

Common Mistakes

  • Trusting that compilation means correctness (compilation checks syntax, not logic)
  • Reviewing only the diff without checking what the AI did NOT generate (missing error paths)
  • Assuming the AI used the right library version (it often uses deprecated APIs)
  • Skipping the orphan check because garbage collection handles it (it doesn't for connections, listeners, timers)

Why This Exists

AI agents systematically optimize for "looks correct" and "passes the happy path." They miss failure modes, orphan resources, and hallucinate dependencies at rates significantly higher than manual code. This skill forces an audit for those specific blind spots.

Alternatives

Compare before choosing