Ponytail Audit

Whole-repo audit for over-engineering. Scans the codebase and ranks what to delete, simplify, or replace with stdlib/native equivalents. Use when the user asks to audit a repo for bloat, unnecessary abstractions, redundant dependencies, or "what can I delete from this codebase".

summersec 3938ad1 1.3 KB Updated

File contents

ponytail-review, but repo-wide. Scan the whole tree instead of a diff. Rank findings biggest cut first.

Tags

  • delete: dead code, unused flexibility, speculative feature. Replacement: nothing.
  • stdlib: hand-rolled thing the standard library already ships. Name the function.
  • native: dependency or code doing what the platform already does. Name the feature.
  • yagni: abstraction with one implementation, config nobody sets, layer with one caller.
  • shrink: same logic, fewer lines. Show the shorter form.

Hunt

Look for:

  • dependencies the stdlib or platform already covers
  • single-implementation interfaces
  • factories with one product
  • wrappers that only delegate
  • dead flags and config
  • hand-rolled stdlib

Output

One line per finding, ranked: <tag> <what to cut>. <replacement>. [path]

End with: net: -<N> lines, -<M> deps possible.

If there is nothing to cut, say Lean already. Ship.

Scope: over-engineering only. Correctness, security, and performance are out of scope.

summersec/sumsec-skills/tree/main/dev-tools/skills/ponytail-audit commit 3938ad16ce

Frequently asked questions

npx skillmds@latest add summersec/ponytail-audit