All skills
asyrafhussin avatar

/technical-debt

@4df703d

Technical debt inventory, prioritization, and audit for PHP/Laravel (MySQL) and Node/TypeScript/React projects. Use when assessing code health, identifying refactoring candidates, planning debt paydown, or auditing a codebase for accumulated debt. Triggers on "audit technical debt", "find tech debt", "debt inventory", "what should we refactor first", or tasks involving code health, security debt, performance debt, data debt, observability debt, debt prioritization, or remediation planning.

Use this Skill: https://skilld.dev/gh/asyrafhussin/agent-skills/technical-debt

This session only. Nothing lands on disk.

rulesdeps-security-advisories.md

≈608 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Known Security Advisories

Impact: CRITICAL (Public CVEs are pre-published attack instructions)

Once a CVE is public, exploit attempts start within hours. A HIGH/CRITICAL advisory in your dependency tree is not "tech debt to schedule" — it's an unmitigated security incident you haven't responded to yet.

How to Detect

# Node
npm audit                                # full report
npm audit --audit-level=high             # CI-friendly threshold
npm audit fix                            # auto-fix non-breaking

# PHP
composer audit                           # built-in since Composer 2.4
composer audit --format=json

# Cross-stack
snyk test            # https://snyk.io

Incorrect

# ❌ Pre-commit and CI ignore audit results
$ npm audit
12 vulnerabilities (3 moderate, 7 high, 2 critical)
$ git push   # CI passes — audit isn't a gate

Problems:

  • CRITICAL CVEs sitting in main are public attack surface
  • No paper trail of when each was acknowledged
  • Each new dep adds more without anyone noticing

Correct

# ✅ CI gate that fails on high+ vulnerabilities
# .github/workflows/security.yml
- name: Audit dependencies
  run: |
    npm audit --audit-level=high
    composer audit --abandoned=fail

# ✅ Renovate / Dependabot configured for security PRs
# renovate.json
{
  "vulnerabilityAlerts": { "enabled": true, "labels": ["security"] },
  "osvVulnerabilityAlerts": true
}

Benefits:

  • New CVEs auto-generate PRs within hours of disclosure
  • CI fails the moment a high-severity advisory lands
  • Audit log of every advisory acknowledgement and fix

Remediation Strategy

  • Effort:
    • S — patch/minor bump available, no breaking change
    • M — requires upgrade across multiple deps
    • L — vulnerable code is in an abandoned dep; replacement needed
  • When to pay down:
    • CRITICAL / HIGH: within 24–72 hours
    • MEDIUM: within the current sprint
    • LOW: opportunistically with other dep work
  • If a fix is genuinely blocked, document the compensating control (WAF rule, input validation, feature disable) and the target unblocking date.

Reference: GitHub Advisory Database · OSV.dev

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides a comprehensive and safe framework for identifying, prioritizing, and auditing technical debt in PHP/Laravel and Node/TypeScript/React projects. No security risks or malicious behaviors were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 4df703d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 5 months ago
metadata
{
  "author": "agent-skills",
  "version": "1.0.0"
}

README badge

README badge for asyrafhussin/agent-skills/technical-debt