Codebase Audit Skill
Systematic, phased codebase auditing with progressive scan → diagnose → repair workflow.
When to Use
- User requests full project review/architecture mapping
- Before major refactoring or onboarding to a new codebase
- User wants technical debt assessment with prioritization
Phased Approach
Phase 1: Architecture Mapping (Read-Only)
- Scan
pages.json / router config for page hierarchy
- Map directory structure (main package vs sub-packages/modules)
- Identify framework stack (Vue version, state management, UI libraries)
- Identify infrastructure (HTTP layer, i18n, storage, utilities)
- Count files by size — flag files >500 lines
- Output: Architecture Audit Report with page tree + infrastructure table
Phase 2: Deep Diagnostic (Read-Only)
Use Python execute_code scripts for parallel multi-dimensional scanning:
Scan 1: File Scale & API Style
# Walk project, parse Vue files, detect:
# - Mixed API styles (setup + data/methods)
# - Files >500/1000/2000 lines
# - v-for without :key, v-if+v-for on same element
# - data() with >10 properties
Scan 2: HTTP/Network Layer
# Check: config.js for hardcoded env/test flags
# Check: auth.js for token expiry handling
# Check: client.js for timeout, retry, abort mechanisms
# Check: interceptors for 401 handling
# Find direct uni.request/wx.fetch calls bypassing HTTP client
Scan 3: Lifecycle & State
# Detect onShow+mounted, onLoad+mounted mixing
# Find onShow triggering API calls (duplicate requests)
# Track uni.$emit/$on usage patterns
# Check uni.$on without corresponding uni.$off (memory leaks)
# Find pages with API calls but no login guard
Scan 4: UI/UX Consistency
# Detect hardcoded colors not using CSS variables
# Find px+rpx mixed usage in same file
# Check list components missing empty/loading states
# Count inline style="..." attributes (>5 is suspicious)
# Find console.log/warn in production code
# Detect font-size < 24rpx
# Find complex template expressions (>{{50+ chars}})
Phase 3: Auto-Repair (Write Mode)
- Only after explicit [EXECUTE] command from user
- One-step commit: one fix at a time
- Logic guard: never change core business logic
- Verification note after each fix
Prioritization Framework
| Priority |
Criteria |
Examples |
| P0 Critical |
Memory leaks, security, data corruption, production config leaks |
uni.$on without $off, hardcoded prod URLs, missing 401 handling |
| P1 High |
Giant files (>1000 lines), missing auth guards, broken lifecycle |
3000-line component, unguarded API pages, onShow+mounted duplicate |
| P2 Medium |
Missing UX states, style inconsistency, event bus overuse |
No empty state, inline styles, hardcoded colors |
| P3 Low |
Architecture improvements, optimization suggestions |
Add Pinia, extract composables, request cancellation |
Key Vue/uni-app Specific Checks
- Lifecycle mixing:
onShow/onLoad (小程序) vs onMounted (Vue) — they fire at different times
- Event leaks:
uni.$on in onMounted without uni.$off in onUnmounted
- Mixed API:
<script setup> + data()/methods() causes reactivity issues
- onShow duplicate:
onShow fires on every return from background — avoid heavy API calls
- Hardcoded env:
config.js with isTest = true without .env files
- ⚠️ uni-app 微信小程序端不支持原生
process.env 注入,需在 vite.config.js 中配置 define 或使用条件编译 #ifdef
Output Format
Always produce structured reports with:
- Specific file paths and line numbers
- Exact code snippets showing the issue
- Impact analysis
- Concrete fix recommendation
- Priority tag (P0-P3)
1---2name: codebase-audit3description: Systematic multi-phase codebase audit for technical debt, architecture mapping, and defect detection. Read-only scanning before any modifications. Supports Vue/uni-app, JS/TS projects.4---56# Codebase Audit Skill78Systematic, phased codebase auditing with progressive scan → diagnose → repair workflow.910## When to Use11- User requests full project review/architecture mapping12- Before major refactoring or onboarding to a new codebase13- User wants technical debt assessment with prioritization1415## Phased Approach1617### Phase 1: Architecture Mapping (Read-Only)181. Scan `pages.json` / router config for page hierarchy192. Map directory structure (main package vs sub-packages/modules)203. Identify framework stack (Vue version, state management, UI libraries)214. Identify infrastructure (HTTP layer, i18n, storage, utilities)225. Count files by size — flag files >500 lines236. Output: Architecture Audit Report with page tree + infrastructure table2425### Phase 2: Deep Diagnostic (Read-Only)26Use Python `execute_code` scripts for parallel multi-dimensional scanning:2728#### Scan 1: File Scale & API Style29```python30# Walk project, parse Vue files, detect:31# - Mixed API styles (setup + data/methods)32# - Files >500/1000/2000 lines33# - v-for without :key, v-if+v-for on same element34# - data() with >10 properties35```3637#### Scan 2: HTTP/Network Layer38```python39# Check: config.js for hardcoded env/test flags40# Check: auth.js for token expiry handling41# Check: client.js for timeout, retry, abort mechanisms42# Check: interceptors for 401 handling43# Find direct uni.request/wx.fetch calls bypassing HTTP client44```4546#### Scan 3: Lifecycle & State47```python48# Detect onShow+mounted, onLoad+mounted mixing49# Find onShow triggering API calls (duplicate requests)50# Track uni.$emit/$on usage patterns51# Check uni.$on without corresponding uni.$off (memory leaks)52# Find pages with API calls but no login guard53```5455#### Scan 4: UI/UX Consistency56```python57# Detect hardcoded colors not using CSS variables58# Find px+rpx mixed usage in same file59# Check list components missing empty/loading states60# Count inline style="..." attributes (>5 is suspicious)61# Find console.log/warn in production code62# Detect font-size < 24rpx63# Find complex template expressions (>{{50+ chars}})64```6566### Phase 3: Auto-Repair (Write Mode)67- Only after explicit [EXECUTE] command from user68- One-step commit: one fix at a time69- Logic guard: never change core business logic70- Verification note after each fix7172## Prioritization Framework73| Priority | Criteria | Examples |74|----------|----------|----------|75| P0 Critical | Memory leaks, security, data corruption, production config leaks | uni.$on without $off, hardcoded prod URLs, missing 401 handling |76| P1 High | Giant files (>1000 lines), missing auth guards, broken lifecycle | 3000-line component, unguarded API pages, onShow+mounted duplicate |77| P2 Medium | Missing UX states, style inconsistency, event bus overuse | No empty state, inline styles, hardcoded colors |78| P3 Low | Architecture improvements, optimization suggestions | Add Pinia, extract composables, request cancellation |7980## Key Vue/uni-app Specific Checks811. **Lifecycle mixing**: `onShow`/`onLoad` (小程序) vs `onMounted` (Vue) — they fire at different times822. **Event leaks**: `uni.$on` in `onMounted` without `uni.$off` in `onUnmounted`833. **Mixed API**: `<script setup>` + `data()`/`methods()` causes reactivity issues844. **onShow duplicate**: `onShow` fires on every return from background — avoid heavy API calls855. **Hardcoded env**: `config.js` with `isTest = true` without `.env` files86 - ⚠️ uni-app 微信小程序端不支持原生 `process.env` 注入,需在 `vite.config.js` 中配置 `define` 或使用条件编译 `#ifdef`8788## Output Format89Always produce structured reports with:90- Specific file paths and line numbers91- Exact code snippets showing the issue92- Impact analysis93- Concrete fix recommendation94- Priority tag (P0-P3)