boshu2/agentops/skills/codebase-recon/SKILL.md
codebase-recon
Reconstruct a repository as cited entry-to-test flows and bounded claims. Triggers: "codebase recon", "trace this codebase", "repository audit", "refresh the prior recon".
- Source repository stars
- 416
- Declared platforms
- 0
- Static risk flags
- 0
- Last source update
- 2026-08-05
- Source checked
- 2026-08-05
Decision brief
What it does—and where it fits
Build a reusable, falsifiable model of a repository. This skill reports what the tree and executable probes support; it does not edit code or issue a final PASS/WARN/FAIL verdict.
Not for
- Tasks that require unconfirmed production actions or broad system permissions.
- Environments where the pinned source and install steps cannot be inspected.
Compatibility matrix
Platform support, with evidence labels
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
Inspect first. Install second.
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/boshu2/agentops --skill "skills/codebase-recon"Inspect the Agent Skill "codebase-recon" from https://github.com/boshu2/agentops/blob/c0f78fddd95ab30f8adadc5e513e27064980a529/skills/codebase-recon/SKILL.md at commit c0f78fddd95ab30f8adadc5e513e27064980a529. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
What the source asks the agent to do
- 01
Workflow
1. Record the current commit and the repository's local source-of-truth precedence. Search for a prior recon pack before starting. 2. If no prior pack exists, use baseline mode. If one exists, verify its still-valid claims against the current commit and use delta mode. Preserve…
Record the current commit and the repository's local source-of-truthIf no prior pack exists, use baseline mode. If one exists, verify itsTrace representative paths from entry point to domain logic, integration - 02
Constraints
To prevent a floating recon, record the exact repository commit and local
To prevent a floating recon, record the exact repository commit and localBecause confidence is not evidence, type every material claim and cite eachTo preserve traceability, prefer a verified delta when a prior pack exists - 03
Modes, views, and lenses
One skill replaces a cluster of loose recon skills. Steer it with mode, view emphasis, lens, and depth — do not invent a second skill for each shape.
One skill replaces a cluster of loose recon skills. Steer it with mode, view emphasis, lens, and depth — do not invent a second skill for each shape.Ask for the shape explicitly, for example:Natural-language equivalents count. The durable pack still carries all four views; emphasis changes what you spend tokens on and what the companion report leads with. Pattern packaging beyond evidence pointers belongs i… - 04
Docs-first entry-point tracing
Enter through what the repository declares about itself — README, architecture docs, build manifests, CLI help — and only then verify those declarations against the tree. Before the first broad search, list the declared entry points and trace at least one of them to code. The na…
Enter through what the repository declares about itself — README, architecture docs, build manifests, CLI help — and only then verify those declarations against the tree. Before the first broad search, list the declared… - 05
One-domain-deep lens per pass
Each pass adopts exactly one lens — persistence, auth, CLI surface, build system, test harness — and follows it from entry point through domain logic to its tests before switching lenses. A pass ends in exactly one of two states: the lens has one complete entry-to-test flow, or…
Each pass adopts exactly one lens — persistence, auth, CLI surface, build system, test harness — and follows it from entry point through domain logic to its tests before switching lenses. A pass ends in exactly one of t…
Permission review
Static risk signals and limitations
No configured static risk pattern was detected
This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.
Evidence record
Why each signal appears
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 89/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 416 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Provenance and original SKILL.md
- Repository
- boshu2/agentops
- Skill path
- skills/codebase-recon/SKILL.md
- Commit
- c0f78fddd95ab30f8adadc5e513e27064980a529
- License
- Apache-2.0
- Collected
- 2026-08-05
- Default branch
- main
View the original SKILL.md
Codebase Recon
Build a reusable, falsifiable model of a repository. This skill reports what the tree and executable probes support; it does not edit code or issue a final PASS/WARN/FAIL verdict.
Constraints
- To prevent a floating recon, record the exact repository commit and local source-of-truth precedence.
- Because confidence is not evidence, type every material claim and cite each fact and inference.
- To preserve traceability, prefer a verified delta when a prior pack exists instead of rewriting unchanged evidence as fresh discovery.
Modes, views, and lenses
One skill replaces a cluster of loose recon skills. Steer it with mode, view emphasis, lens, and depth — do not invent a second skill for each shape.
| Control | Values | Use when |
|---|---|---|
| Mode | baseline | delta | First pack vs refresh after a prior recon |
| View emphasis | mental model · bounded audit · pattern evidence · synthesis | Archaeology-style map, audit-style findings, pattern harvest, or executive synthesis |
| Lens | persistence · auth · CLI · build · test (one per pass) | Domain-deep cut instead of a shallow whole-tree sweep |
| Depth | quick · standard · deep | Orientation vs onboarding vs decision-grade evidence |
Ask for the shape explicitly, for example:
codebase-recon --mode=delta --view=audit --lens=cli --depth=standard
codebase-recon baseline, mental-model view, persistence lens, deep
Natural-language equivalents count. The durable pack still carries all four
views; emphasis changes what you spend tokens on and what the companion report
leads with. Pattern packaging beyond evidence pointers belongs in
pattern-mining. Binding PASS/FAIL stays with
validate.
Workflow
- Record the current commit and the repository's local source-of-truth precedence. Search for a prior recon pack before starting.
- If no prior pack exists, use
baselinemode. If one exists, verify its still-valid claims against the current commit and usedeltamode. Preserve valid evidence by reference and describe only changed paths and synthesis. - Trace representative paths from entry point to domain logic, integration boundary, and test. Prefer a few complete flows over a broad file inventory.
- Keep four views distinct in the report: mental model, bounded audit, pattern
evidence, and synthesis. Label each claim
fact,inference, orunknown, assign confidence, and cite evidence for facts and inferences. - List inspected and uninspected scope. Write the JSON manifest and companion report, then run the validator. Missing evidence and hidden coverage gaps are contract failures, not prose caveats.
Docs-first entry-point tracing
Enter through what the repository declares about itself — README, architecture
docs, build manifests, CLI help — and only then verify those declarations
against the tree. Before the first broad search, list the declared entry points
and trace at least one of them to code. The named failure mode is grep-first
drift: opening with keyword sweeps builds a model of whatever happened to
match, and the recon inherits the search terms' blind spots instead of the
repository's actual shape. When declaration and code disagree, that is a
finding, not noise: record the doc's claim as inference, the traced behavior
as fact, and cite both.
One-domain-deep lens per pass
Each pass adopts exactly one lens — persistence, auth, CLI surface, build system, test harness — and follows it from entry point through domain logic to its tests before switching lenses. A pass ends in exactly one of two states: the lens has one complete entry-to-test flow, or the report names the file and line where the trace was cut and why. The named failure mode is the shallow sweep: touching every directory at depth one produces a file inventory that reads like a model but supports no claim, because no path was followed far enough to falsify anything.
Citation floor: file:line or downgrade
The durable output doc earns its keep only if a future reader can re-verify a
claim without redoing the recon. Every fact cites file:line; every
inference cites the file:line facts it rests on. A claim that cannot be
cited is downgraded to unknown before the report ships — never shipped
uncited at its original confidence. The manifest validator accepts a bare file
path (it requires the path resolve to an existing regular file, so a bare
directory is rejected as a coverage gap), but does not require the line number;
hold the companion report to the stricter floor: a path without a line is a
pointer to homework, not a citation, and counts as a coverage gap in the
report's own terms.
When reconstructing a repository other than the one that ships this skill, pass
--repo-root <target> to the validator so evidence resolves against the target
tree rather than the skill's own checkout.
Output Specification
- Artifact directory:
.agents/recon/<run-id>/ - Filename convention:
codebase-recon.jsonwith companion reportcodebase-recon.mdin the same directory. - Format:
codebase-recon.v1JSON manifest plus an evidence-cited Markdown report covering the same commit, mode, flows, claims, and scope boundaries. - Validation command:
skills/codebase-recon/scripts/validate-output.sh <codebase-recon.json>validates the machine-readable manifest; the cited Markdown report remains its human-readable companion. - Downstream handoff: pass both validated artifact paths to the requesting research, planning, review, or documentation workflow; the consumer owns any decision or code-change plan.
Baseline manifests carry at least one complete entry-to-test flow. Delta
manifests name an existing prior recon, prove baseline_verified: true, and
describe at least one changed path. Every manifest lists both inspected and
uninspected scope.
The validator is the machine boundary:
skills/codebase-recon/scripts/validate-output.sh <recon.json>
Evidence entries are existing file paths, optionally followed by a line number.
Delta manifests require an existing prior pack, baseline_verified: true, and
at least one described change.
Executable behavior: references/codebase-recon.feature.
Quality
- Every fact and inference resolves to existing evidence; unknowns remain visibly typed and never masquerade as established behavior.
- Representative flows reach entry, domain, integration, and test surfaces, while inspected and uninspected scope stay explicit.
- The named validator passes before the JSON manifest and companion report are handed to a downstream consumer.
Do not
- Regenerate a full replacement report when a verified delta is possible.
- Present an inference as fact or omit uninspected scope.
- Turn the recon artifact into a completion verdict or a code-change plan.
Alternatives
Compare before choosing
mgiovani/cc-arsenal
team-review
Multi-agent review team: architecture, security, performance, testing, style, docs/UX, plus an adversary that cross-examines the other 6, for security-sensitive, architectural, or large PRs (15+ files) where a single-agent pass risks missing cross-cutting issues. Use for auth/payments/PII changes, schema/pattern changes, compliance sign-off, or when asked to 'get the review team on this' / 'multi-agent review' / 'thorough review before merge'. For a standard PR or a quick pre-merge check, use /r
trailofbits/skills
differential-review
Performs security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses git history for context, calculates blast radius, checks test coverage, and generates comprehensive markdown reports. Automatically detects and prevents security regressions.
trailofbits/skills
genotoxic
Graph-informed mutation testing triage. Parses codebases with Trailmark, runs mutation testing and necessist, then uses survived mutants, unnecessary test statements, and call graph data to identify false positives, missing test coverage, and fuzzing targets. Use when triaging survived mutants, analyzing mutation testing results, identifying test gaps, finding fuzzing targets from weak tests, running mutation frameworks (including circomvent and cairo-mutants), or using necessist.
alirezarezvani/claude-skills
pr-review-expert
Use when the user asks to review pull requests, analyze code changes, check for security issues in PRs, or assess code quality of diffs.