Repo Scan

affaan-m/ECC/skills/repo-scan

by affaan-mef648e01899ba3e8dc6371642deaaf64b4477775No license275K starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated 4 days ago

Bootstrap pointer that installs the external repo-scan skill from a pinned, reviewable commit. Use when repo-scan must be installed before running its cross-stack source-code asset audit; this ECC pointer does not perform the audit itself.

Instructions onlyAI & Agents
AI-generated overview

Bootstrap pointer that installs the external repo-scan skill from a pinned commit; it does not run the audit itself.

What it does
This skill is an installation pointer: it clones a pinned commit of an external repository, stages the files, and asks for confirmation before replacing the target skill directory. It performs no scanning itself and states that the audit only runs after the harness is reloaded and repo-scan is invoked again. The external skill it installs is described as auditing cross-stack source code to classify project code, embedded third-party code, and build artifacts.
When to use it
Use it when the external repo-scan skill must be installed before its cross-stack source-code asset audit can be run. It is not meant for performing the audit, which happens after installation and a harness reload.
Requirements
Requires git, tar, a POSIX shell with mkdir, mv, rmdir and mktemp, network access to clone the repository, and interactive confirmation typed as install. It ships no scripts; the installation commands are embedded in the document.

repo-scan

Every ecosystem has its own dependency manager, but no tool looks across C++, Android, iOS, and Web to tell you: how much code is actually yours, what's third-party, and what's dead weight.

When to Use

  • Taking over a large legacy codebase and need a structural overview
  • Before major refactoring — identify what's core, what's duplicate, what's dead
  • Auditing third-party dependencies embedded directly in source (not declared in package managers)
  • Preparing architecture decision records for monorepo reorganization

Installation

bash
# Clone first so the pinned commit can be reviewed before installationset -euo pipefail
REPO_SCAN_COMMIT=2742664ebcad1450c208eda0ae45d3c17fad5dd8REPO_SCAN_INSTALL_DIR="${CLAUDE_CONFIG_DIR:-$HOME/.claude}/skills/repo-scan"REPO_SCAN_INSTALL_PARENT="$(dirname "$REPO_SCAN_INSTALL_DIR")"mkdir -p "$REPO_SCAN_INSTALL_PARENT"REPO_SCAN_TMP="$(mktemp -d "$REPO_SCAN_INSTALL_PARENT/.repo-scan-install.XXXXXX")"REPO_SCAN_TOKEN="${REPO_SCAN_TMP##*.}"REPO_SCAN_STAGE="$REPO_SCAN_TMP/stage-$REPO_SCAN_TOKEN"REPO_SCAN_BACKUP="$REPO_SCAN_TMP/backup-$REPO_SCAN_TOKEN"REPO_SCAN_LOCK="$REPO_SCAN_INSTALL_PARENT/.repo-scan-install.lock"REPO_SCAN_KEEP_TMP=0REPO_SCAN_LOCK_HELD=0REPO_SCAN_MV_HAS_NO_TARGET=0cleanup_repo_scan_install() {  if [ "$REPO_SCAN_KEEP_TMP" -eq 0 ]; then    rm -rf -- "$REPO_SCAN_TMP"  fi  if [ "$REPO_SCAN_LOCK_HELD" -eq 1 ] && ! rmdir -- "$REPO_SCAN_LOCK"; then    printf 'Could not release installation lock at %s\n' "$REPO_SCAN_LOCK" >&2  fi}trap cleanup_repo_scan_install EXITmkdir "$REPO_SCAN_TMP/mv-probe-source"if mv -T -- "$REPO_SCAN_TMP/mv-probe-source" \  "$REPO_SCAN_TMP/mv-probe-destination" 2>/dev/null; then  REPO_SCAN_MV_HAS_NO_TARGET=1  rmdir "$REPO_SCAN_TMP/mv-probe-destination"else  rmdir "$REPO_SCAN_TMP/mv-probe-source"fimove_repo_scan_dir() {  REPO_SCAN_MOVE_SOURCE=$1  REPO_SCAN_MOVE_DESTINATION=$2  REPO_SCAN_MOVE_NAME=${REPO_SCAN_MOVE_SOURCE##*/}  if [ -e "$REPO_SCAN_MOVE_DESTINATION" ] || [ -L "$REPO_SCAN_MOVE_DESTINATION" ]; then    return 1  fi  if [ "$REPO_SCAN_MV_HAS_NO_TARGET" -eq 1 ]; then    mv -T -- "$REPO_SCAN_MOVE_SOURCE" "$REPO_SCAN_MOVE_DESTINATION"    return  fi  if ! mv -- "$REPO_SCAN_MOVE_SOURCE" "$REPO_SCAN_MOVE_DESTINATION"; then    return 1  fi  if [ -e "$REPO_SCAN_MOVE_DESTINATION/$REPO_SCAN_MOVE_NAME" ] || \    [ -L "$REPO_SCAN_MOVE_DESTINATION/$REPO_SCAN_MOVE_NAME" ]; then    if ! mv -- "$REPO_SCAN_MOVE_DESTINATION/$REPO_SCAN_MOVE_NAME" \      "$REPO_SCAN_MOVE_SOURCE"; then      REPO_SCAN_KEEP_TMP=1      printf 'Move conflict recovery failed; staged data remains at %s\n' \        "$REPO_SCAN_MOVE_DESTINATION/$REPO_SCAN_MOVE_NAME" >&2    fi    return 1  fi}
git clone --filter=blob:none --no-checkout \  https://github.com/haibindev/repo-scan.git "$REPO_SCAN_TMP/source"git -C "$REPO_SCAN_TMP/source" checkout --detach "$REPO_SCAN_COMMIT"mkdir -p "$REPO_SCAN_STAGE"git -C "$REPO_SCAN_TMP/source" archive "$REPO_SCAN_COMMIT" | \  tar -xf - -C "$REPO_SCAN_STAGE"
# Review "$REPO_SCAN_TMP/source" before approving installation.printf 'Type install to replace %s after reviewing the pinned source: ' \  "$REPO_SCAN_INSTALL_DIR" >&2read -r REPO_SCAN_CONFIRMif [ "$REPO_SCAN_CONFIRM" != install ]; then  printf 'Installation cancelled.\n' >&2  exit 1fiif ! mkdir -- "$REPO_SCAN_LOCK" 2>/dev/null; then  printf 'Another repo-scan installation holds the lock at %s\n' \    "$REPO_SCAN_LOCK" >&2  exit 1fiREPO_SCAN_LOCK_HELD=1
if [ -e "$REPO_SCAN_INSTALL_DIR" ] || [ -L "$REPO_SCAN_INSTALL_DIR" ]; then  move_repo_scan_dir "$REPO_SCAN_INSTALL_DIR" "$REPO_SCAN_BACKUP"fiif ! move_repo_scan_dir "$REPO_SCAN_STAGE" "$REPO_SCAN_INSTALL_DIR"; then  if [ -e "$REPO_SCAN_BACKUP" ] || [ -L "$REPO_SCAN_BACKUP" ]; then    if [ -e "$REPO_SCAN_INSTALL_DIR" ] || [ -L "$REPO_SCAN_INSTALL_DIR" ]; then      REPO_SCAN_KEEP_TMP=1      printf 'Replacement failed and target was recreated; previous installation preserved at %s\n' \        "$REPO_SCAN_BACKUP" >&2    elif ! move_repo_scan_dir "$REPO_SCAN_BACKUP" "$REPO_SCAN_INSTALL_DIR"; then      REPO_SCAN_KEEP_TMP=1      printf 'Replacement and rollback failed; previous installation preserved at %s\n' \        "$REPO_SCAN_BACKUP" >&2    fi  fi  exit 1fi

Review the source before installing any agent skill.

Installation completes only the bootstrap. Reload your agent harness, then invoke repo-scan again. This ECC pointer installs the external skill but does not run a scan itself.

Core Capabilities

CapabilityDescription
Cross-stack scanningC/C++, Java/Android, iOS (OC/Swift), Web (TS/JS/Vue) in one pass
File classificationEvery file tagged as project code, third-party, or build artifact
Library detection50+ known libraries (FFmpeg, Boost, OpenSSL…) with version extraction
Four-level verdictsCore Asset / Extract & Merge / Rebuild / Deprecate
HTML reportsInteractive dark-theme pages with drill-down navigation
Monorepo supportHierarchical scanning with summary + sub-project reports

Analysis Depth Levels

LevelFiles ReadUse Case
fast1-2 per moduleQuick inventory of huge directories
standard2-5 per moduleDefault audit with full dependency + architecture checks
deep5-10 per moduleAdds thread safety, memory management, API consistency
fullAll filesPre-merge comprehensive review

How It Works

  1. Classify the repo surface: enumerate files, then tag each as project code, embedded third-party code, or build artifact.
  2. Detect embedded libraries: inspect directory names, headers, license files, and version markers to identify bundled dependencies and likely versions.
  3. Score each module: group files by module or subsystem, then assign one of the four verdicts based on ownership, duplication, and maintenance cost.
  4. Highlight structural risks: call out dead-weight artifacts, duplicated wrappers, outdated vendored code, and modules that should be extracted, rebuilt, or deprecated.
  5. Produce the report: return a concise summary plus the interactive HTML output with per-module drill-down so the audit can be reviewed asynchronously.

Examples

On a 50,000-file C++ monorepo:

  • Found FFmpeg 2.x (2015 vintage) still in production
  • Discovered the same SDK wrapper duplicated 3 times
  • Identified 636 MB of committed Debug/ipch/obj build artifacts
  • Classified: 3 MB project code vs 596 MB third-party

Best Practices

  • Start with standard depth for first-time audits
  • Use fast for monorepos with 100+ modules to get a quick inventory
  • Run deep incrementally on modules flagged for refactoring
  • Review the cross-module analysis for duplicate detection across sub-projects

Links

Source and attribution

Source:affaan-m/ECCinskills/repo-scanat commitef648e0

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal