Internal Safety Override
- Status: local-only unless explicitly opted into external access.
- Before using network tools, account connectors, browser automation, or APIs, state the destination, data scope, and credential source.
- Do not transmit repository files, secrets, credentials, or private documents by default.
- Audit categories: network, secrets.
Code Tour
Create CodeTour files — persona-targeted, step-by-step walkthroughs of a codebase that link directly to files and line numbers. CodeTour files live in .tours/ and work with the VS Code CodeTour extension.
Overview
A great tour is a narrative — a story told to a specific person about what matters, why it matters, and what to do next. Only create .tour JSON files. Never modify source code.
When to Use This Skill
- User asks to create a code tour, onboarding tour, or architecture walkthrough
- User says "tour for this PR", "explain how X works", "vibe check", "RCA tour"
- User wants a contributor guide, security review, or bug investigation walkthrough
- Any request for a structured walkthrough with file/line anchors
Core Workflow
1. Discover the repo
Before asking anything, explore the codebase:
In parallel: list root directory, read README, check config files.
Then: identify language(s), framework(s), project purpose. Map folder structure 1-2 levels deep. Find entry points — every path in the tour must be real.
If the repo has fewer than 5 source files, create a quick-depth tour regardless of persona — there's not enough to warrant a deep one.
2. Infer the intent
One message should be enough. Infer persona, depth, and focus silently.
| User says |
Persona |
Depth |
| "tour for this PR" |
pr-reviewer |
standard |
| "why did X break" / "RCA" |
rca-investigator |
standard |
| "onboarding" / "new joiner" |
new-joiner |
standard |
| "quick tour" / "vibe check" |
vibecoder |
quick |
| "architecture" |
architect |
deep |
| "security" / "auth review" |
security-reviewer |
standard |
| (no qualifier) |
new-joiner |
standard |
When intent is ambiguous, default to new-joiner persona at standard depth — it's the most generally useful.
3. Read actual files
Every file path and line number must be verified. A tour pointing to the wrong line is worse than no tour.
4. Write the tour
Save to .tours/<persona>-<focus>.tour.
{
"$schema": "https://aka.ms/codetour-schema",
"title": "Descriptive Title — Persona / Goal",
"description": "Who this is for and what they'll understand after.",
"ref": "<current-branch-or-commit>",
"steps": []
}
Step types
| Type |
When to use |
Example |
| Content |
Intro/closing only (max 2) |
{ "title": "Welcome", "description": "..." } |
| Directory |
Orient to a module |
{ "directory": "src/services", "title": "..." } |
| File + line |
The workhorse |
{ "file": "src/auth.ts", "line": 42, "title": "..." } |
| Selection |
Highlight a code block |
{ "file": "...", "selection": {...}, "title": "..." } |
| Pattern |
Regex match (volatile files) |
{ "file": "...", "pattern": "class App", "title": "..." } |
| URI |
Link to PR, issue, doc |
{ "uri": "https://...", "title": "..." } |
Step count
| Depth |
Steps |
Use for |
| Quick |
5-8 |
Vibecoder, fast exploration |
| Standard |
9-13 |
Most personas |
| Deep |
14-18 |
Architect, RCA |
Writing descriptions — SMIG formula
- S — Situation: What is the reader looking at?
- M — Mechanism: How does this code work?
- I — Implication: Why does this matter for this persona?
- G — Gotcha: What would a smart person get wrong?
5. Validate
Personas
| Persona |
Goal |
Must cover |
| Vibecoder |
Get the vibe fast |
Entry point, main modules. Max 8 steps. |
| New joiner |
Structured ramp-up |
Directories, setup, business context |
| Bug fixer |
Root cause fast |
Trigger -> fault points -> tests |
| RCA investigator |
Why did it fail |
Causality chain, observability anchors |
| Feature explainer |
End-to-end |
UI -> API -> backend -> storage |
| PR reviewer |
Review correctly |
Change story, invariants, risky areas |
| Architect |
Shape and rationale |
Boundaries, tradeoffs, extension points |
| Security reviewer |
Trust boundaries |
Auth flow, validation, secret handling |
| Refactorer |
Safe restructuring |
Seams, hidden deps, extraction order |
| External contributor |
Contribute safely |
Safe areas, conventions, landmines |
Narrative Arc
- Orientation —
file or directory step (never content-only first step — blank in VS Code)
- High-level map — 1-3 directory steps showing major modules
- Core path — file/line steps, the heart of the tour
- Closing — what the reader can now do, suggested follow-ups
Anti-Patterns
| Anti-pattern |
Fix |
| File listing — "this file contains the models" |
Tell a story. Each step depends on the previous. |
| Generic descriptions |
Name the specific pattern unique to this codebase. |
| Line number guessing |
Never write a line you didn't verify by reading. |
| Too many steps for quick depth |
Actually cut steps. |
| Hallucinated files |
If it doesn't exist, skip the step. |
| Recap closing — "we covered X, Y, Z" |
Tell the reader what they can now do. |
| Content-only first step |
Anchor step 1 to a file or directory. |
Cross-References
- Related:
engineering/codebase-onboarding — for broader onboarding beyond tours
- Related:
engineering/pr-review-expert — for automated PR review workflows
- CodeTour extension: microsoft/codetour
- Real-world tours: coder/code-server
1---2name: code-tour3description: Use when the user asks to create a CodeTour .tour file — persona-targeted, step-by-step walkthroughs that link to real files and line numbers. Trigger for: create a tour, onboarding tour, architecture tour, PR review tour, explain how X works, vibe check, RCA tour, contributor guide, or any structured code walkthrough request.4---56## Internal Safety Override78- Status: local-only unless explicitly opted into external access.9- Before using network tools, account connectors, browser automation, or APIs, state the destination, data scope, and credential source.10- Do not transmit repository files, secrets, credentials, or private documents by default.11- Audit categories: network, secrets.1213# Code Tour1415Create **CodeTour** files — persona-targeted, step-by-step walkthroughs of a codebase that link directly to files and line numbers. CodeTour files live in `.tours/` and work with the [VS Code CodeTour extension](https://github.com/microsoft/codetour).1617## Overview1819A great tour is a **narrative** — a story told to a specific person about what matters, why it matters, and what to do next. Only create `.tour` JSON files. Never modify source code.2021## When to Use This Skill2223- User asks to create a code tour, onboarding tour, or architecture walkthrough24- User says "tour for this PR", "explain how X works", "vibe check", "RCA tour"25- User wants a contributor guide, security review, or bug investigation walkthrough26- Any request for a structured walkthrough with file/line anchors2728## Core Workflow2930### 1. Discover the repo3132Before asking anything, explore the codebase:3334In parallel: list root directory, read README, check config files.35Then: identify language(s), framework(s), project purpose. Map folder structure 1-2 levels deep. Find entry points — every path in the tour must be real.3637If the repo has fewer than 5 source files, create a quick-depth tour regardless of persona — there's not enough to warrant a deep one.3839### 2. Infer the intent4041One message should be enough. Infer persona, depth, and focus silently.4243| User says | Persona | Depth |44|-----------|---------|-------|45| "tour for this PR" | pr-reviewer | standard |46| "why did X break" / "RCA" | rca-investigator | standard |47| "onboarding" / "new joiner" | new-joiner | standard |48| "quick tour" / "vibe check" | vibecoder | quick |49| "architecture" | architect | deep |50| "security" / "auth review" | security-reviewer | standard |51| (no qualifier) | new-joiner | standard |5253When intent is ambiguous, default to **new-joiner** persona at **standard** depth — it's the most generally useful.5455### 3. Read actual files5657**Every file path and line number must be verified.** A tour pointing to the wrong line is worse than no tour.5859### 4. Write the tour6061Save to `.tours/<persona>-<focus>.tour`.6263```json64{65 "$schema": "https://aka.ms/codetour-schema",66 "title": "Descriptive Title — Persona / Goal",67 "description": "Who this is for and what they'll understand after.",68 "ref": "<current-branch-or-commit>",69 "steps": []70}71```7273### Step types7475| Type | When to use | Example |76|------|-------------|---------|77| **Content** | Intro/closing only (max 2) | `{ "title": "Welcome", "description": "..." }` |78| **Directory** | Orient to a module | `{ "directory": "src/services", "title": "..." }` |79| **File + line** | The workhorse | `{ "file": "src/auth.ts", "line": 42, "title": "..." }` |80| **Selection** | Highlight a code block | `{ "file": "...", "selection": {...}, "title": "..." }` |81| **Pattern** | Regex match (volatile files) | `{ "file": "...", "pattern": "class App", "title": "..." }` |82| **URI** | Link to PR, issue, doc | `{ "uri": "https://...", "title": "..." }` |8384### Step count8586| Depth | Steps | Use for |87|-------|-------|---------|88| Quick | 5-8 | Vibecoder, fast exploration |89| Standard | 9-13 | Most personas |90| Deep | 14-18 | Architect, RCA |9192### Writing descriptions — SMIG formula9394- **S — Situation**: What is the reader looking at?95- **M — Mechanism**: How does this code work?96- **I — Implication**: Why does this matter for this persona?97- **G — Gotcha**: What would a smart person get wrong?9899### 5. Validate100101- [ ] Every `file` path relative to repo root (no leading `/` or `./`)102- [ ] Every `file` confirmed to exist103- [ ] Every `line` verified by reading the file104- [ ] First step has `file` or `directory` anchor105- [ ] At most 2 content-only steps106- [ ] `nextTour` matches another tour's `title` exactly if set107108## Personas109110| Persona | Goal | Must cover |111|---------|------|------------|112| **Vibecoder** | Get the vibe fast | Entry point, main modules. Max 8 steps. |113| **New joiner** | Structured ramp-up | Directories, setup, business context |114| **Bug fixer** | Root cause fast | Trigger -> fault points -> tests |115| **RCA investigator** | Why did it fail | Causality chain, observability anchors |116| **Feature explainer** | End-to-end | UI -> API -> backend -> storage |117| **PR reviewer** | Review correctly | Change story, invariants, risky areas |118| **Architect** | Shape and rationale | Boundaries, tradeoffs, extension points |119| **Security reviewer** | Trust boundaries | Auth flow, validation, secret handling |120| **Refactorer** | Safe restructuring | Seams, hidden deps, extraction order |121| **External contributor** | Contribute safely | Safe areas, conventions, landmines |122123## Narrative Arc1241251. **Orientation** — `file` or `directory` step (never content-only first step — blank in VS Code)1262. **High-level map** — 1-3 directory steps showing major modules1273. **Core path** — file/line steps, the heart of the tour1284. **Closing** — what the reader can now do, suggested follow-ups129130## Anti-Patterns131132| Anti-pattern | Fix |133|---|---|134| **File listing** — "this file contains the models" | Tell a story. Each step depends on the previous. |135| **Generic descriptions** | Name the specific pattern unique to this codebase. |136| **Line number guessing** | Never write a line you didn't verify by reading. |137| **Too many steps** for quick depth | Actually cut steps. |138| **Hallucinated files** | If it doesn't exist, skip the step. |139| **Recap closing** — "we covered X, Y, Z" | Tell the reader what they can now *do*. |140| **Content-only first step** | Anchor step 1 to a file or directory. |141142## Cross-References143144- Related: `engineering/codebase-onboarding` — for broader onboarding beyond tours145- Related: `engineering/pr-review-expert` — for automated PR review workflows146- CodeTour extension: [microsoft/codetour](https://github.com/microsoft/codetour)147- Real-world tours: [coder/code-server](https://github.com/coder/code-server/blob/main/.tours/contributing.tour)