All skills
asyrafhussin avatar

/code-slop

@346603c

Detect AI-generated code patterns ("slop") in PHP/Laravel and TypeScript/React source — comment narration, generic naming, premature interfaces, defensive overdose, mock-everything tests, and the absence of human "scars". Use when reviewing AI-assisted PRs, auditing code for taste/quality (not metrics — that's technical-debt), or hardening a code-review checklist. Triggers on "review for AI slop", "find AI patterns", "check code feels human", "audit code-quality taste".

Use this Skill: https://skilld.dev/gh/asyrafhussin/agent-skills/code-slop

This session only. Nothing lands on disk.

README.md

≈655 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Code Slop Detection

Taste-level review of code for AI-generated patterns ("slop") in PHP/Laravel and TypeScript/React projects. Catches code that passes every metric but reads like a tutorial blog post — not what a human teammate would write.

Version: 1.0.0

Overview

  • Audits AI-assisted PRs and codebases for AI-fingerprint patterns
  • Verdict bands: CLEAN / SUSPICIOUS / INFLATED / CRITICAL
  • Stack: PHP / Laravel + Node / TypeScript / React
  • 24 rules across 6 categories
  • Complements technical-debt (quantitative metrics) with qualitative taste

What it catches that linters don't

Slop pattern Why linters miss it
Narration comments Looks like a "valid comment" to any linter
Generic names (data, result) Passes naming conventions
Premature interfaces / single-method classes Valid code structure
Generic catch (e) { console.error(...) } Try/catch is a valid pattern
Mock-everything tests Tests pass and run; coverage looks fine
Missing // HACK: scars No tool checks for absence of human imperfection

Categories

1. Comments (CRITICAL)

Narration, empty docblocks, placeholder TODOs, closing-brace labels.

2. Naming (CRITICAL)

Generic placeholders, over-descriptive run-ons, suffix abuse, type-in-name.

3. Over-engineering (HIGH)

Premature interfaces, single-method classes, useless wrappers, dependency creep.

4. Defensive overdose (HIGH)

Generic catch blocks, impossible null checks, missing real defenses.

5. Test slop (HIGH)

Mock-everything, "doesn't throw" assertions, mirror-implementation, snapshot abuse.

6. Style fingerprints (MEDIUM)

Hyper-consistent formatting, as any escapes, no // HACK: scars, debug artifacts, trivial boilerplate.

Usage

Review this PR for AI slop
Audit src/ for AI-generated code patterns
Does this code look human-written?
Find the slop in app/Services/
Check this file against the slop checklist

Differentiator vs technical-debt

Skill Lens
technical-debt Quantitative — complexity, duplication, CVEs, missing indexes
code-slop Qualitative — does this code feel AI-written?

Some overlap exists on dead code and generic catch blocks, but framing and remediation differ.

References

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides heuristics for auditing code quality in PHP and TypeScript projects and is generally safe. It contains a low-severity risk of indirect prompt injection because it processes untrusted source code and PR diffs using shell-based analysis tools without defining boundary markers or sanitization procedures.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 346603c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 5 months ago
metadata
{
  "author": "agent-skills",
  "version": "1.0.0"
}

README badge

README badge for asyrafhussin/agent-skills/code-slop