# Codebase Audit

> Systematic multi-phase codebase audit for technical debt, architecture mapping, and defect detection. Read-only scanning before any modifications. Supports Vue/uni-app, JS/TS projects.

- Skill: `ichichuang/codebase-audit` (Agent Skill)
- Install (CLI): `npx skillmds@latest add ichichuang/codebase-audit`
- Raw SKILL.md: https://api.skillmd.com/api/skills/ichichuang/codebase-audit/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Web & Frontend
- Author: ichichuang (https://skillmd.com/u/ichichuang)
- Updated: 2026-08-19
- Page: https://skillmd.com/skills/ichichuang/codebase-audit

---


# Codebase Audit Skill

Systematic, phased codebase auditing with progressive scan → diagnose → repair workflow.

## When to Use
- User requests full project review/architecture mapping
- Before major refactoring or onboarding to a new codebase
- User wants technical debt assessment with prioritization

## Phased Approach

### Phase 1: Architecture Mapping (Read-Only)
1. Scan `pages.json` / router config for page hierarchy
2. Map directory structure (main package vs sub-packages/modules)
3. Identify framework stack (Vue version, state management, UI libraries)
4. Identify infrastructure (HTTP layer, i18n, storage, utilities)
5. Count files by size — flag files >500 lines
6. Output: Architecture Audit Report with page tree + infrastructure table

### Phase 2: Deep Diagnostic (Read-Only)
Use Python `execute_code` scripts for parallel multi-dimensional scanning:

#### Scan 1: File Scale & API Style
```python
# Walk project, parse Vue files, detect:
# - Mixed API styles (setup + data/methods)
# - Files >500/1000/2000 lines
# - v-for without :key, v-if+v-for on same element
# - data() with >10 properties
```

#### Scan 2: HTTP/Network Layer
```python
# Check: config.js for hardcoded env/test flags
# Check: auth.js for token expiry handling
# Check: client.js for timeout, retry, abort mechanisms
# Check: interceptors for 401 handling
# Find direct uni.request/wx.fetch calls bypassing HTTP client
```

#### Scan 3: Lifecycle & State
```python
# Detect onShow+mounted, onLoad+mounted mixing
# Find onShow triggering API calls (duplicate requests)
# Track uni.$emit/$on usage patterns
# Check uni.$on without corresponding uni.$off (memory leaks)
# Find pages with API calls but no login guard
```

#### Scan 4: UI/UX Consistency
```python
# Detect hardcoded colors not using CSS variables
# Find px+rpx mixed usage in same file
# Check list components missing empty/loading states
# Count inline style="..." attributes (>5 is suspicious)
# Find console.log/warn in production code
# Detect font-size < 24rpx
# Find complex template expressions (>{{50+ chars}})
```

### Phase 3: Auto-Repair (Write Mode)
- Only after explicit [EXECUTE] command from user
- One-step commit: one fix at a time
- Logic guard: never change core business logic
- Verification note after each fix

## Prioritization Framework
| Priority | Criteria | Examples |
|----------|----------|----------|
| P0 Critical | Memory leaks, security, data corruption, production config leaks | uni.$on without $off, hardcoded prod URLs, missing 401 handling |
| P1 High | Giant files (>1000 lines), missing auth guards, broken lifecycle | 3000-line component, unguarded API pages, onShow+mounted duplicate |
| P2 Medium | Missing UX states, style inconsistency, event bus overuse | No empty state, inline styles, hardcoded colors |
| P3 Low | Architecture improvements, optimization suggestions | Add Pinia, extract composables, request cancellation |

## Key Vue/uni-app Specific Checks
1. **Lifecycle mixing**: `onShow`/`onLoad` (小程序) vs `onMounted` (Vue) — they fire at different times
2. **Event leaks**: `uni.$on` in `onMounted` without `uni.$off` in `onUnmounted`
3. **Mixed API**: `<script setup>` + `data()`/`methods()` causes reactivity issues
4. **onShow duplicate**: `onShow` fires on every return from background — avoid heavy API calls
5. **Hardcoded env**: `config.js` with `isTest = true` without `.env` files
   - ⚠️ uni-app 微信小程序端不支持原生 `process.env` 注入，需在 `vite.config.js` 中配置 `define` 或使用条件编译 `#ifdef`

## Output Format
Always produce structured reports with:
- Specific file paths and line numbers
- Exact code snippets showing the issue
- Impact analysis
- Concrete fix recommendation
- Priority tag (P0-P3)
