Codebase Auditor (L2 Coordinator)
Coordinates 9 specialized audit workers to perform comprehensive codebase quality analysis.
Purpose & Scope
- Coordinates 9 audit workers (ln-621 through ln-629) running in parallel
- Research current best practices for detected tech stack via MCP tools ONCE
- Pass shared context to all workers (token-efficient)
- Aggregate worker results into single consolidated report
- Create single refactoring task in Linear under Epic 0 with all findings
- Manual invocation by user; not part of Story pipeline
Workflow
- Discovery: Load tech_stack.md, principles.md, package manifests, auto-discover Team ID
- Research: Query MCP tools for current best practices per major dependency ONCE
- Build Context: Create contextStore with best practices + tech stack metadata
- Domain Discovery: Detect project domains from folder structure (NEW)
- Delegate: Two-stage delegation - global workers + domain-aware workers (UPDATED)
- Aggregate: Collect worker results, group by domain, calculate scores
- Generate Report: Build consolidated report with Domain Health Summary, Findings by Domain
- Create Task: Create Linear task in Epic 0 titled "Codebase Refactoring: [YYYY-MM-DD]"
Phase 1: Discovery
Load project metadata:
docs/project/tech_stack.md - detect tech stack for research
docs/principles.md - project-specific quality principles
- Package manifests:
package.json, requirements.txt, go.mod, Cargo.toml
- Auto-discover Team ID from
docs/tasks/kanban_board.md
Extract metadata only (not full codebase scan):
- Programming language(s)
- Major frameworks/libraries
- Database system(s)
- Build tools
- Test framework(s)
Phase 2: Research Best Practices (ONCE)
For each major dependency identified in Phase 1:
- Use
mcp__Ref__ref_search_documentation for current best practices
- Use
mcp__context7__get-library-docs for up-to-date library documentation
- Focus areas by technology type:
| Type |
Research Focus |
| Web Framework |
Async patterns, middleware, error handling, request lifecycle |
| ML/AI Libraries |
Inference optimization, memory management, batching |
| Database |
Connection pooling, transactions, query optimization |
| Containerization |
Multi-stage builds, security, layer caching |
| Language Runtime |
Idioms, performance patterns, memory management |
Build contextStore:
{
"tech_stack": {...},
"best_practices": {...},
"principles": {...},
"codebase_root": "..."
}
Phase 3: Domain Discovery
Purpose: Detect project domains from folder structure for domain-aware auditing.
Algorithm:
Priority 1: Explicit domain folders
- Check for:
src/domains/*/, src/features/*/, src/modules/*/
- Monorepo patterns:
packages/*/, libs/*/, apps/*/
- If found (>1 match) → use these as domains
Priority 2: Top-level src/ folders*
- List folders:
src/users/, src/orders/, src/payments/
- Exclude infrastructure:
utils, shared, common, lib, helpers, config, types, interfaces, constants, middleware, infrastructure, core
- If remaining >1 → use as domains
Priority 3: Fallback to global mode
- If <2 domains detected →
domain_mode = "global"
- All workers scan entire codebase (backward-compatible behavior)
Heuristics for domain detection:
| Heuristic |
Indicator |
Example |
| File count |
>5 files in folder |
src/users/ with 12 files |
| Structure |
controllers/, services/, models/ present |
MVC/Clean Architecture |
| Barrel export |
index.ts/index.js exists |
Module pattern |
| README |
README.md describes domain |
Domain documentation |
Output:
{
"domain_mode": "domain-aware",
"all_domains": [
{"name": "users", "path": "src/users", "file_count": 45, "is_shared": false},
{"name": "orders", "path": "src/orders", "file_count": 32, "is_shared": false},
{"name": "shared", "path": "src/shared", "file_count": 15, "is_shared": true}
]
}
Shared folder handling:
- Folders named
shared, common, utils, lib, core → mark is_shared: true
- Shared code audited but grouped separately in report
- Does not affect domain-specific scores
Phase 4: Delegate to Workers
Phase 4a: Global Workers (PARALLEL)
Global workers scan entire codebase (not domain-aware):
| # |
Worker |
Priority |
What It Audits |
| 1 |
ln-621-security-auditor |
CRITICAL |
Hardcoded secrets, SQL injection, XSS, insecure deps |
| 2 |
ln-622-build-auditor |
CRITICAL |
Compiler/linter errors, deprecations, type errors |
| 5 |
ln-625-dependencies-auditor |
MEDIUM |
Outdated packages, unused deps, custom implementations |
| 6 |
ln-626-dead-code-auditor |
LOW |
Dead code, unused imports/variables, commented-out code |
| 7 |
ln-627-observability-auditor |
MEDIUM |
Structured logging, health checks, metrics, tracing |
| 8 |
ln-628-concurrency-auditor |
HIGH |
Race conditions, async/await, resource contention |
| 9 |
ln-629-lifecycle-auditor |
MEDIUM |
Bootstrap, graceful shutdown, resource cleanup |
Invocation (7 workers in PARALLEL):
FOR EACH worker IN [ln-621, ln-622, ln-625, ln-626, ln-627, ln-628, ln-629]:
Skill(skill=worker, args=JSON.stringify(contextStore))
Phase 4b: Domain-Aware Workers (PARALLEL per domain)
Domain-aware workers run once per domain:
| # |
Worker |
Priority |
What It Audits |
| 3 |
ln-623-architecture-auditor |
HIGH |
DRY/KISS/YAGNI violations, layer breaks, TODO/FIXME |
| 4 |
ln-624-code-quality-auditor |
MEDIUM |
Cyclomatic complexity, O(n²), N+1 queries, magic numbers |
Invocation (2 workers × N domains):
IF domain_mode == "domain-aware":
FOR EACH domain IN all_domains:
domain_context = {
...contextStore,
domain_mode: "domain-aware",
current_domain: { name: domain.name, path: domain.path }
}
// Invoke both workers for this domain
Skill(skill="ln-623-architecture-auditor", args=JSON.stringify(domain_context))
Skill(skill="ln-624-code-quality-auditor", args=JSON.stringify(domain_context))
ELSE:
// Fallback: invoke once for entire codebase (global mode)
Skill(skill="ln-623-architecture-auditor", args=JSON.stringify(contextStore))
Skill(skill="ln-624-code-quality-auditor", args=JSON.stringify(contextStore))
Parallelism strategy:
- Phase 4a: All 7 global workers run in PARALLEL
- Phase 4b: All (2 × N) domain-aware invocations run in PARALLEL
- Example: 3 domains → 6 invocations (ln-363×3 + ln-364×3) in single message
Phase 5: Aggregate Results
Collect results from workers:
Global worker output (unchanged):
{
"category": "Security",
"score": 7,
"total_issues": 5,
"critical": 1,
"high": 2,
"medium": 2,
"low": 0,
"findings": [...]
}
Domain-aware worker output (NEW):
{
"category": "Architecture & Design",
"score": 6,
"domain": "users",
"scan_path": "src/users",
"total_issues": 4,
"critical": 1,
"high": 2,
"medium": 1,
"low": 0,
"findings": [
{
"severity": "CRITICAL",
"location": "src/users/controllers/UserController.ts:45",
"issue": "Controller directly uses Repository",
"principle": "Layer Separation (Clean Architecture)",
"recommendation": "Create UserService",
"effort": "L",
"domain": "users"
}
]
}
Aggregation steps:
- Global workers → merge findings (as before)
- Domain-aware workers → group by domain.name:
- Calculate domain-level scores (Architecture + Quality per domain)
- Build Domain Health Summary table
- Overall score → average of all category scores (Architecture/Quality averaged across domains)
- Severity summary → sum critical/high/medium/low across ALL workers
- Findings grouping:
- Global categories (Security, Build, etc.) → single table
- Domain-aware categories → subtables per domain
Output Format
## Codebase Audit Report - [DATE]
### Executive Summary
[2-3 sentences on overall codebase health, major risks, and key strengths]
### Compliance Score
| Category | Score | Notes |
|----------|-------|-------|
| Security | X/10 | ... |
| Build Health | X/10 | ... |
| Architecture & Design | X/10 | ... |
| Code Quality | X/10 | ... |
| Dependencies & Reuse | X/10 | ... |
| Dead Code | X/10 | ... |
| Observability | X/10 | ... |
| Concurrency | X/10 | ... |
| Lifecycle | X/10 | ... |
| **Overall** | **X/10** | |
### Severity Summary
| Severity | Count |
|----------|-------|
| Critical | X |
| High | X |
| Medium | X |
| Low | X |
### Domain Health Summary (NEW - if domain_mode="domain-aware")
| Domain | Files | Arch Score | Quality Score | Issues |
|--------|-------|------------|---------------|--------|
| users | 45 | 7/10 | 8/10 | 5 |
| orders | 32 | 5/10 | 6/10 | 8 |
| payments | 28 | 8/10 | 7/10 | 3 |
| shared | 15 | 6/10 | 9/10 | 2 |
| **Total** | **120** | **6.5/10** | **7.5/10** | **18** |
### Strengths
- [What's done well in this codebase]
- [Good patterns and practices identified]
### Findings by Category
#### 1. Security (Global)
| Severity | Location | Issue | Principle Violated | Recommendation | Effort |
|----------|----------|-------|-------------------|----------------|--------|
| CRITICAL | src/api/auth.ts:45 | Hardcoded API key | Secrets Management | Move to .env | S |
#### 2. Build Health (Global)
| Severity | Location | Issue | Principle Violated | Recommendation | Effort |
|----------|----------|-------|-------------------|----------------|--------|
| CRITICAL | Multiple files | TypeScript strict errors | Type Safety | Fix types | S |
#### 3. Architecture & Design (Domain-Grouped)
##### Domain: users (src/users/)
| Severity | Location | Issue | Principle Violated | Recommendation | Effort |
|----------|----------|-------|-------------------|----------------|--------|
| CRITICAL | UserController.ts:12 | Controller→Repository bypass | Layer Separation | Add Service layer | L |
##### Domain: orders (src/orders/)
| Severity | Location | Issue | Principle Violated | Recommendation | Effort |
|----------|----------|-------|-------------------|----------------|--------|
| HIGH | OrderService.ts:45 | DRY violation (duplicate validation) | DRY Principle | Extract to validators/ | M |
##### Domain: shared (src/shared/)
| Severity | Location | Issue | Principle Violated | Recommendation | Effort |
|----------|----------|-------|-------------------|----------------|--------|
| MEDIUM | utils.ts:78 | TODO older than 6 months | Code Hygiene | Complete or remove | S |
#### 4. Code Quality (Domain-Grouped)
##### Domain: users (src/users/)
| Severity | Location | Issue | Principle Violated | Recommendation | Effort |
|----------|----------|-------|-------------------|----------------|--------|
| HIGH | UserService.ts:120 | Complexity 25 | Maintainability | Split function | M |
... (continue for remaining global categories: 5-9)
### Recommended Actions (Priority-Sorted)
| Priority | Category | Domain | Location | Issue | Recommendation | Effort |
|----------|----------|--------|----------|-------|----------------|--------|
| CRITICAL | Security | - | src/api/auth.ts:45 | Hardcoded API key | Move to .env | S |
| CRITICAL | Architecture | users | UserController.ts:12 | Controller→Repository bypass | Add Service layer | L |
| CRITICAL | Build | - | Multiple files | TypeScript strict errors | Fix types | S |
| HIGH | Architecture | orders | OrderService.ts:45 | DRY violation | Extract to validators/ | M |
| HIGH | Code Quality | users | UserService.ts:120 | Complexity 25 | Split function | M |
### Priority Actions
1. Fix all Critical issues before next release
2. Address High issues within current sprint
3. Plan Medium issues for technical debt sprint
4. Track Low issues in backlog
### Sources Consulted
- [Framework] best practices: [URL from MCP Ref]
- [Library] documentation: [URL from Context7]
Phase 6: Create Linear Task
Create task in Epic 0:
- Title:
Codebase Refactoring: [YYYY-MM-DD]
- Description: Full report from Phase 5 (markdown format)
- Team: Auto-discovered from kanban_board.md
- Epic: 0 (technical debt / refactoring epic)
- Labels:
refactoring, technical-debt, audit
- Priority: Based on highest severity findings (Critical → Urgent, High → High, etc.)
Critical Rules
- Two-stage delegation: Global workers (7) + Domain-aware workers (2 × N domains)
- Domain discovery: Auto-detect domains from folder structure; fallback to global mode
- Parallel execution: All workers (global + domain-aware) run in PARALLEL
- Single context gathering: Research best practices ONCE, pass contextStore to all workers
- Metadata-only loading: Coordinator loads metadata only; workers load full file contents
- Domain-grouped output: Architecture & Code Quality findings grouped by domain
- Language preservation: Task description in project's language (EN/RU from kanban_board.md)
- Single task: Create ONE task with all findings; do not create multiple tasks
- Do not audit: Coordinator orchestrates only; audit logic lives in workers
Definition of Done
- Best practices researched via MCP tools for major dependencies
- Domain discovery completed (domain_mode determined)
- contextStore built with tech stack + best practices + domain info
- Global workers (7) invoked in PARALLEL
- Domain-aware workers (2 × N domains) invoked in PARALLEL
- All workers completed successfully (or reported errors)
- Results aggregated with domain grouping
- Domain Health Summary built (if domain_mode="domain-aware")
- Compliance score (X/10) calculated per category + overall
- Executive Summary and Strengths sections included
- Linear task created in Epic 0 with full report
- Sources consulted listed with URLs
Workers
See individual worker SKILL.md files for detailed audit rules:
Reference Files
- Principles:
docs/principles.md
- Tech stack:
docs/project/tech_stack.md
- Kanban board:
docs/tasks/kanban_board.md
Version: 5.0.0
Last Updated: 2025-12-23
1---2name: ln-620-codebase-auditor3description: Coordinates 9 specialized audit workers (security, build, architecture, code quality, dependencies, dead code, observability, concurrency, lifecycle). Researches best practices, delegates parallel audits, aggregates results into single Linear task in Epic 0.4---5
6# Codebase Auditor (L2 Coordinator)
7
8Coordinates 9 specialized audit workers to perform comprehensive codebase quality analysis.
9
10## Purpose & Scope
11
12- **Coordinates 9 audit workers** (ln-621 through ln-629) running in parallel
13- Research current best practices for detected tech stack via MCP tools ONCE
14- Pass shared context to all workers (token-efficient)
15- Aggregate worker results into single consolidated report
16- Create single refactoring task in Linear under Epic 0 with all findings
17- Manual invocation by user; not part of Story pipeline
18
19## Workflow
20
211) **Discovery:** Load tech_stack.md, principles.md, package manifests, auto-discover Team ID
222) **Research:** Query MCP tools for current best practices per major dependency ONCE
233) **Build Context:** Create contextStore with best practices + tech stack metadata
244) **Domain Discovery:** Detect project domains from folder structure (NEW)
255) **Delegate:** Two-stage delegation - global workers + domain-aware workers (UPDATED)
266) **Aggregate:** Collect worker results, group by domain, calculate scores
277) **Generate Report:** Build consolidated report with Domain Health Summary, Findings by Domain
288) **Create Task:** Create Linear task in Epic 0 titled "Codebase Refactoring: [YYYY-MM-DD]"
29
30## Phase 1: Discovery
31
32**Load project metadata:**
33- `docs/project/tech_stack.md` - detect tech stack for research
34- `docs/principles.md` - project-specific quality principles
35- Package manifests: `package.json`, `requirements.txt`, `go.mod`, `Cargo.toml`
36- Auto-discover Team ID from `docs/tasks/kanban_board.md`
37
38**Extract metadata only** (not full codebase scan):
39- Programming language(s)
40- Major frameworks/libraries
41- Database system(s)
42- Build tools
43- Test framework(s)
44
45## Phase 2: Research Best Practices (ONCE)
46
47**For each major dependency identified in Phase 1:**
48
491. Use `mcp__Ref__ref_search_documentation` for current best practices
502. Use `mcp__context7__get-library-docs` for up-to-date library documentation
513. Focus areas by technology type:
52
53| Type | Research Focus |
54|------|----------------|
55| Web Framework | Async patterns, middleware, error handling, request lifecycle |
56| ML/AI Libraries | Inference optimization, memory management, batching |
57| Database | Connection pooling, transactions, query optimization |
58| Containerization | Multi-stage builds, security, layer caching |
59| Language Runtime | Idioms, performance patterns, memory management |
60
61**Build contextStore:**
62```json
63{
64 "tech_stack": {...},
65 "best_practices": {...},
66 "principles": {...},
67 "codebase_root": "..."
68}
69```
70
71## Phase 3: Domain Discovery
72
73**Purpose:** Detect project domains from folder structure for domain-aware auditing.
74
75**Algorithm:**
76
771. **Priority 1: Explicit domain folders**
78 - Check for: `src/domains/*/`, `src/features/*/`, `src/modules/*/`
79 - Monorepo patterns: `packages/*/`, `libs/*/`, `apps/*/`
80 - If found (>1 match) → use these as domains
81
822. **Priority 2: Top-level src/* folders**
83 - List folders: `src/users/`, `src/orders/`, `src/payments/`
84 - Exclude infrastructure: `utils`, `shared`, `common`, `lib`, `helpers`, `config`, `types`, `interfaces`, `constants`, `middleware`, `infrastructure`, `core`
85 - If remaining >1 → use as domains
86
873. **Priority 3: Fallback to global mode**
88 - If <2 domains detected → `domain_mode = "global"`
89 - All workers scan entire codebase (backward-compatible behavior)
90
91**Heuristics for domain detection:**
92
93| Heuristic | Indicator | Example |
94|-----------|-----------|---------|
95| File count | >5 files in folder | `src/users/` with 12 files |
96| Structure | controllers/, services/, models/ present | MVC/Clean Architecture |
97| Barrel export | index.ts/index.js exists | Module pattern |
98| README | README.md describes domain | Domain documentation |
99
100**Output:**
101```json
102{
103 "domain_mode": "domain-aware",
104 "all_domains": [
105 {"name": "users", "path": "src/users", "file_count": 45, "is_shared": false},
106 {"name": "orders", "path": "src/orders", "file_count": 32, "is_shared": false},
107 {"name": "shared", "path": "src/shared", "file_count": 15, "is_shared": true}
108 ]
109}
110```
111
112**Shared folder handling:**
113- Folders named `shared`, `common`, `utils`, `lib`, `core` → mark `is_shared: true`
114- Shared code audited but grouped separately in report
115- Does not affect domain-specific scores
116
117## Phase 4: Delegate to Workers
118
119### Phase 4a: Global Workers (PARALLEL)
120
121**Global workers** scan entire codebase (not domain-aware):
122
123| # | Worker | Priority | What It Audits |
124|---|--------|----------|----------------|
125| 1 | ln-621-security-auditor | CRITICAL | Hardcoded secrets, SQL injection, XSS, insecure deps |
126| 2 | ln-622-build-auditor | CRITICAL | Compiler/linter errors, deprecations, type errors |
127| 5 | ln-625-dependencies-auditor | MEDIUM | Outdated packages, unused deps, custom implementations |
128| 6 | ln-626-dead-code-auditor | LOW | Dead code, unused imports/variables, commented-out code |
129| 7 | ln-627-observability-auditor | MEDIUM | Structured logging, health checks, metrics, tracing |
130| 8 | ln-628-concurrency-auditor | HIGH | Race conditions, async/await, resource contention |
131| 9 | ln-629-lifecycle-auditor | MEDIUM | Bootstrap, graceful shutdown, resource cleanup |
132
133**Invocation (7 workers in PARALLEL):**
134```javascript
135FOR EACH worker IN [ln-621, ln-622, ln-625, ln-626, ln-627, ln-628, ln-629]:
136 Skill(skill=worker, args=JSON.stringify(contextStore))
137```
138
139### Phase 4b: Domain-Aware Workers (PARALLEL per domain)
140
141**Domain-aware workers** run once per domain:
142
143| # | Worker | Priority | What It Audits |
144|---|--------|----------|----------------|
145| 3 | ln-623-architecture-auditor | HIGH | DRY/KISS/YAGNI violations, layer breaks, TODO/FIXME |
146| 4 | ln-624-code-quality-auditor | MEDIUM | Cyclomatic complexity, O(n²), N+1 queries, magic numbers |
147
148**Invocation (2 workers × N domains):**
149```javascript
150IF domain_mode == "domain-aware":
151 FOR EACH domain IN all_domains:
152 domain_context = {
153 ...contextStore,
154 domain_mode: "domain-aware",
155 current_domain: { name: domain.name, path: domain.path }
156 }
157 // Invoke both workers for this domain
158 Skill(skill="ln-623-architecture-auditor", args=JSON.stringify(domain_context))
159 Skill(skill="ln-624-code-quality-auditor", args=JSON.stringify(domain_context))
160ELSE:
161 // Fallback: invoke once for entire codebase (global mode)
162 Skill(skill="ln-623-architecture-auditor", args=JSON.stringify(contextStore))
163 Skill(skill="ln-624-code-quality-auditor", args=JSON.stringify(contextStore))
164```
165
166**Parallelism strategy:**
167- Phase 4a: All 7 global workers run in PARALLEL
168- Phase 4b: All (2 × N) domain-aware invocations run in PARALLEL
169- Example: 3 domains → 6 invocations (ln-363×3 + ln-364×3) in single message
170
171## Phase 5: Aggregate Results
172
173**Collect results from workers:**
174
175**Global worker output (unchanged):**
176```json
177{
178 "category": "Security",
179 "score": 7,
180 "total_issues": 5,
181 "critical": 1,
182 "high": 2,
183 "medium": 2,
184 "low": 0,
185 "findings": [...]
186}
187```
188
189**Domain-aware worker output (NEW):**
190```json
191{
192 "category": "Architecture & Design",
193 "score": 6,
194 "domain": "users",
195 "scan_path": "src/users",
196 "total_issues": 4,
197 "critical": 1,
198 "high": 2,
199 "medium": 1,
200 "low": 0,
201 "findings": [
202 {
203 "severity": "CRITICAL",
204 "location": "src/users/controllers/UserController.ts:45",
205 "issue": "Controller directly uses Repository",
206 "principle": "Layer Separation (Clean Architecture)",
207 "recommendation": "Create UserService",
208 "effort": "L",
209 "domain": "users"
210 }
211 ]
212}
213```
214
215**Aggregation steps:**
216
2171. **Global workers** → merge findings (as before)
2182. **Domain-aware workers** → group by domain.name:
219 - Calculate domain-level scores (Architecture + Quality per domain)
220 - Build Domain Health Summary table
2213. **Overall score** → average of all category scores (Architecture/Quality averaged across domains)
2224. **Severity summary** → sum critical/high/medium/low across ALL workers
2235. **Findings grouping:**
224 - Global categories (Security, Build, etc.) → single table
225 - Domain-aware categories → subtables per domain
226
227## Output Format
228
229```markdown
230## Codebase Audit Report - [DATE]
231
232### Executive Summary
233[2-3 sentences on overall codebase health, major risks, and key strengths]
234
235### Compliance Score
236
237| Category | Score | Notes |
238|----------|-------|-------|
239| Security | X/10 | ... |
240| Build Health | X/10 | ... |
241| Architecture & Design | X/10 | ... |
242| Code Quality | X/10 | ... |
243| Dependencies & Reuse | X/10 | ... |
244| Dead Code | X/10 | ... |
245| Observability | X/10 | ... |
246| Concurrency | X/10 | ... |
247| Lifecycle | X/10 | ... |
248| **Overall** | **X/10** | |
249
250### Severity Summary
251
252| Severity | Count |
253|----------|-------|
254| Critical | X |
255| High | X |
256| Medium | X |
257| Low | X |
258
259### Domain Health Summary (NEW - if domain_mode="domain-aware")
260
261| Domain | Files | Arch Score | Quality Score | Issues |
262|--------|-------|------------|---------------|--------|
263| users | 45 | 7/10 | 8/10 | 5 |
264| orders | 32 | 5/10 | 6/10 | 8 |
265| payments | 28 | 8/10 | 7/10 | 3 |
266| shared | 15 | 6/10 | 9/10 | 2 |
267| **Total** | **120** | **6.5/10** | **7.5/10** | **18** |
268
269### Strengths
270- [What's done well in this codebase]
271- [Good patterns and practices identified]
272
273### Findings by Category
274
275#### 1. Security (Global)
276
277| Severity | Location | Issue | Principle Violated | Recommendation | Effort |
278|----------|----------|-------|-------------------|----------------|--------|
279| CRITICAL | src/api/auth.ts:45 | Hardcoded API key | Secrets Management | Move to .env | S |
280
281#### 2. Build Health (Global)
282
283| Severity | Location | Issue | Principle Violated | Recommendation | Effort |
284|----------|----------|-------|-------------------|----------------|--------|
285| CRITICAL | Multiple files | TypeScript strict errors | Type Safety | Fix types | S |
286
287#### 3. Architecture & Design (Domain-Grouped)
288
289##### Domain: users (src/users/)
290
291| Severity | Location | Issue | Principle Violated | Recommendation | Effort |
292|----------|----------|-------|-------------------|----------------|--------|
293| CRITICAL | UserController.ts:12 | Controller→Repository bypass | Layer Separation | Add Service layer | L |
294
295##### Domain: orders (src/orders/)
296
297| Severity | Location | Issue | Principle Violated | Recommendation | Effort |
298|----------|----------|-------|-------------------|----------------|--------|
299| HIGH | OrderService.ts:45 | DRY violation (duplicate validation) | DRY Principle | Extract to validators/ | M |
300
301##### Domain: shared (src/shared/)
302
303| Severity | Location | Issue | Principle Violated | Recommendation | Effort |
304|----------|----------|-------|-------------------|----------------|--------|
305| MEDIUM | utils.ts:78 | TODO older than 6 months | Code Hygiene | Complete or remove | S |
306
307#### 4. Code Quality (Domain-Grouped)
308
309##### Domain: users (src/users/)
310
311| Severity | Location | Issue | Principle Violated | Recommendation | Effort |
312|----------|----------|-------|-------------------|----------------|--------|
313| HIGH | UserService.ts:120 | Complexity 25 | Maintainability | Split function | M |
314
315... (continue for remaining global categories: 5-9)
316
317### Recommended Actions (Priority-Sorted)
318
319| Priority | Category | Domain | Location | Issue | Recommendation | Effort |
320|----------|----------|--------|----------|-------|----------------|--------|
321| CRITICAL | Security | - | src/api/auth.ts:45 | Hardcoded API key | Move to .env | S |
322| CRITICAL | Architecture | users | UserController.ts:12 | Controller→Repository bypass | Add Service layer | L |
323| CRITICAL | Build | - | Multiple files | TypeScript strict errors | Fix types | S |
324| HIGH | Architecture | orders | OrderService.ts:45 | DRY violation | Extract to validators/ | M |
325| HIGH | Code Quality | users | UserService.ts:120 | Complexity 25 | Split function | M |
326
327### Priority Actions
3281. Fix all Critical issues before next release
3292. Address High issues within current sprint
3303. Plan Medium issues for technical debt sprint
3314. Track Low issues in backlog
332
333### Sources Consulted
334- [Framework] best practices: [URL from MCP Ref]
335- [Library] documentation: [URL from Context7]
336```
337
338## Phase 6: Create Linear Task
339
340Create task in Epic 0:
341- Title: `Codebase Refactoring: [YYYY-MM-DD]`
342- Description: Full report from Phase 5 (markdown format)
343- Team: Auto-discovered from kanban_board.md
344- Epic: 0 (technical debt / refactoring epic)
345- Labels: `refactoring`, `technical-debt`, `audit`
346- Priority: Based on highest severity findings (Critical → Urgent, High → High, etc.)
347
348## Critical Rules
349
350- **Two-stage delegation:** Global workers (7) + Domain-aware workers (2 × N domains)
351- **Domain discovery:** Auto-detect domains from folder structure; fallback to global mode
352- **Parallel execution:** All workers (global + domain-aware) run in PARALLEL
353- **Single context gathering:** Research best practices ONCE, pass contextStore to all workers
354- **Metadata-only loading:** Coordinator loads metadata only; workers load full file contents
355- **Domain-grouped output:** Architecture & Code Quality findings grouped by domain
356- **Language preservation:** Task description in project's language (EN/RU from kanban_board.md)
357- **Single task:** Create ONE task with all findings; do not create multiple tasks
358- **Do not audit:** Coordinator orchestrates only; audit logic lives in workers
359
360## Definition of Done
361
362- Best practices researched via MCP tools for major dependencies
363- Domain discovery completed (domain_mode determined)
364- contextStore built with tech stack + best practices + domain info
365- Global workers (7) invoked in PARALLEL
366- Domain-aware workers (2 × N domains) invoked in PARALLEL
367- All workers completed successfully (or reported errors)
368- Results aggregated with domain grouping
369- Domain Health Summary built (if domain_mode="domain-aware")
370- Compliance score (X/10) calculated per category + overall
371- Executive Summary and Strengths sections included
372- Linear task created in Epic 0 with full report
373- Sources consulted listed with URLs
374
375## Workers
376
377See individual worker SKILL.md files for detailed audit rules:
378- [ln-621-security-auditor](../ln-621-security-auditor/SKILL.md)
379- [ln-622-build-auditor](../ln-622-build-auditor/SKILL.md)
380- [ln-623-architecture-auditor](../ln-623-architecture-auditor/SKILL.md)
381- [ln-624-code-quality-auditor](../ln-624-code-quality-auditor/SKILL.md)
382- [ln-625-dependencies-auditor](../ln-625-dependencies-auditor/SKILL.md)
383- [ln-626-dead-code-auditor](../ln-626-dead-code-auditor/SKILL.md)
384- [ln-627-observability-auditor](../ln-627-observability-auditor/SKILL.md)
385- [ln-628-concurrency-auditor](../ln-628-concurrency-auditor/SKILL.md)
386- [ln-629-lifecycle-auditor](../ln-629-lifecycle-auditor/SKILL.md)
387
388## Reference Files
389
390- Principles: `docs/principles.md`
391- Tech stack: `docs/project/tech_stack.md`
392- Kanban board: `docs/tasks/kanban_board.md`
393
394---
395**Version:** 5.0.0
396**Last Updated:** 2025-12-23