Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Legacy Codebase Audit

ASecurity

Onboarding audit checklist for TypeScript/React codebases flagged as legacy, built with less powerful agents, or showing quality-debt signals. Use on the first session in an unfamiliar TS/React codebase or before feature work on quality-debt code. Triggers on "audit", "codebase audit", "legacy", "technical debt", "modernization", "built with older/less powerful agents", "quality debt", "altlast", "altlasten", "technische schulden", "modernisierung", "code-audit", "codebasis prüfen", "aufräume...

2 stars
0 votes
0 copies
0 views
Added 9/27/2026
developmenttypescriptgobashsqlreactnodesecuritydocumentation

Security Analysis

A100/100

Scanned 9/27/2026

$npx -y skills add emanuelrechsteiner/claude-rcode --skill legacy-codebase-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Legacy Codebase Audit?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Legacy Codebase Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/emanuelrechsteiner-legacy-codebase-audit/badge)](https://www.skillsdirectory.com/skills/emanuelrechsteiner-legacy-codebase-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: legacy-codebase-audit
description: Onboarding audit checklist for TypeScript/React codebases flagged as legacy, built with less powerful agents, or showing quality-debt signals. Use on the first session in an unfamiliar TS/React codebase or before feature work on quality-debt code. Triggers on "audit", "codebase audit", "legacy", "technical debt", "modernization", "built with older/less powerful agents", "quality debt", "altlast", "altlasten", "technische schulden", "modernisierung", "code-audit", "codebasis prüfen", "aufräumen vor feature-arbeit".
---

# Legacy Codebase Audit

> Onboarding checklist for TypeScript/React codebases flagged as "built with less powerful agents" or showing quality-debt signals. Derived from an example legacy TS/React project audit, 2026-04-12. On-demand skill — demoted from always-loaded rule per IMP-079 (2026-07-03).

## When This Skill Applies

- First session on an unfamiliar TS/React codebase
- User mentions "technical debt", "modernization", "audit", "legacy", or "built with older/less powerful agents"
- Type-check or test metrics look poor on first read

Run the audit **before** making feature changes. Audit-first prevents compounding debt.

## Audit Checklist (Run in Order)

### 1. TypeScript Strictness
```bash
grep -E '"strict"\s*:\s*(true|false)' tsconfig.json
grep -c ': any\b' src/**/*.ts src/**/*.tsx 2>/dev/null  # baseline any-count
```
**Triage thresholds:**
- `strict: false` → Critical. Migration roadmap required before feature work.
- `any`-count > 50 → High. Schedule dedicated type-coverage sprint.
- `any`-count 10–50 → Medium. Ban new any, attrit over 2–3 PRs.
- `any`-count < 10 → Low. Add lint rule `@typescript-eslint/no-explicit-any: error`.

### 2. Test Coverage
```bash
# Depending on framework
npx vitest run --coverage 2>/dev/null || npx jest --coverage 2>/dev/null
```
**Triage thresholds:**
- < 20% line coverage → Critical. Cannot refactor safely. Write characterization tests before touching code.
- 20–60% → High. Write tests for any file touched.
- 60–80% → Medium. Maintain; add tests for new code.
- 80%+ → OK.

### 3. Security Audit — Cryptography
Hunt for `Math.random()` in security-relevant contexts:
```bash
grep -rn "Math\.random" src/ | grep -viE "test|spec|mock|fixture"
```
**Critical pattern:** `Math.random()` used for:
- Differential privacy noise → non-crypto RNG violates privacy guarantees
- Tokens, IDs, secrets → predictable, enables attacks
- Sampling for compliance/audit → bias risk

**Remediation:** Replace with `crypto.randomInt()` (Node) or `crypto.getRandomValues()` (browser).

### 4. Framework Duplication
```bash
jq '.devDependencies | keys[]' package.json | grep -iE "(jest|vitest|mocha|ava)"
jq '.devDependencies | keys[]' package.json | grep -iE "(react-query|swr|apollo|urql)"
```
**Red flags:**
- Jest AND Vitest both present → Migrate to one, document which wins.
- React Query installed but no `useQuery` calls → Dead dependency; remove or start using.
- Multiple form libraries (react-hook-form + formik) → Pick one.

### 5. File-Size Thresholds
```bash
find src -type f \( -name "*.ts" -o -name "*.tsx" \) -exec wc -l {} + | sort -rn | head -20
```
**Triage:**
- Files > 1500 LOC → Refactor candidates. Split by responsibility.
- Files > 2500 LOC → Critical. Break up before touching.
- Components > 250 LOC → Review for extraction (threshold aligned with `CLAUDE_LINE_LIMIT` default per IMP-050; was 400).

### 6. Dead Dependencies
```bash
npx depcheck 2>/dev/null || npx knip 2>/dev/null
```
Remove unused. Every dead dep is supply-chain surface + install time + mental overhead.

### 7. Build & Lint State
```bash
npx tsc --noEmit 2>&1 | grep -c "error TS"
npx eslint . --max-warnings 0 2>&1 | tail -5
```
If either fails on main branch → first task is restoring green, before feature work.

## Prioritization Matrix

After audit, sequence fixes as:

1. **Security-critical** (Math.random in crypto, secrets exposure, SQL injection) — before any deploy
2. **Build-blocking** (TS errors, lint errors on main) — before next merge
3. **TypeScript strict migration** (stepwise: enable in new files → ban new `any` → attrit existing) — ongoing
4. **Test coverage** (characterize before refactor) — per-PR uplift
5. **File-size / architecture** (split monoliths) — during feature work that touches them
6. **Dep cleanup** — single-PR sweep when stable

**Do NOT start with lowest-risk cleanup.** Security + build-blocking first; aesthetics last.

## Documentation Requirements

For each legacy project, create / update:
- `docs/AUDIT-YYYY-MM-DD.md` — full audit snapshot with metrics
- `docs/MODERNIZATION-ROADMAP.md` — sequenced remediation plan
- `CLAUDE.md` — notes on strictness level, test framework (after consolidation), known hotspots

## Example Reference Case

Specifics from a 2026-04-12 audit (`/path/to/your/legacy-project`):
- TypeScript `strict: false`, 111+ `any` types
- Line coverage 8.7% (far below 20% critical threshold)
- `Math.random()` used for Differential Privacy noise → privacy guarantee violated
- Jest AND Vitest both present → framework consolidation needed
- Largest files > 1500 LOC
- React Query installed but never called

→ Priority order: Security (crypto RNG) → TypeScript strict migration → Code splitting → Coverage uplift. See IMP-010 in improvement-ledger.json.

Attribution

emanuelrechsteineremanuelrechsteiner
View sourceSee grades on GitHubMore from emanuelrechsteiner →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Clean Code

Pragmatic coding standards - concise, direct, no over-engineering, no unnecessary comments

304955 votes

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

286712 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Writing Plans

Use when you have a spec or requirements for a multi-step task, before touching code

2927051 votes
View all in development →