All skills
asyrafhussin avatar

/technical-debt

@4df703d

Technical debt inventory, prioritization, and audit for PHP/Laravel (MySQL) and Node/TypeScript/React projects. Use when assessing code health, identifying refactoring candidates, planning debt paydown, or auditing a codebase for accumulated debt. Triggers on "audit technical debt", "find tech debt", "debt inventory", "what should we refactor first", or tasks involving code health, security debt, performance debt, data debt, observability debt, debt prioritization, or remediation planning.

Use this Skill: https://skilld.dev/gh/asyrafhussin/agent-skills/technical-debt

This session only. Nothing lands on disk.

rulesdeps-unused-deps.md

≈616 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Unused Dependencies

Impact: MEDIUM (Inflate install size, supply-chain surface, and audit noise)

A dependency you don't use is one you still ship, audit, and trust. Each unused dep is a potential supply-chain footgun (compromised maintainer, malicious post-install script) for zero benefit.

How to Detect

# Node / TypeScript
npx depcheck                         # unused + missing deps
npx knip                             # also finds unused files and exports

# PHP / Composer
composer-unused                      # https://github.com/composer-unused/composer-unused
vendor/bin/composer-unused

Incorrect

// ❌ package.json declares deps no longer imported
{
  "dependencies": {
    "lodash": "^4.17.21",        // grep shows zero `from 'lodash'` imports
    "axios": "^1.6.0",           // migrated to fetch 6 months ago
    "moment": "^2.29.4",         // migrated to date-fns; one stale import left
    "node-fetch": "^3.3.0"       // only used in a deleted script
  }
}

Problems:

  • Each npm install downloads code that does nothing
  • Each npm audit reports advisories you can't act on (you don't even use the affected code paths)
  • New engineers see them and assume they're load-bearing

Correct

# ✅ Remove unused deps
$ npx depcheck
Unused dependencies: lodash, axios, moment, node-fetch
$ npm uninstall lodash axios moment node-fetch
$ npm audit            # quieter report
# Add to CI to keep it clean
- run: npx depcheck --ignores="@types/*,eslint-*"

Benefits:

  • Smaller node_modules, faster installs, faster CI
  • Audit reports are signal, not noise
  • Reduced supply-chain attack surface

Remediation Strategy

  • Effort: S (almost always)
  • When to pay down: Immediately on detection. Add a depcheck/composer-unused step to CI to prevent regression.

Watch out for:

  • Transitive usage only: some deps are loaded by tooling (e.g., babel plugins listed in babel.config.js). Verify before removing.
  • Type-only packages: @types/* packages are used by the compiler but invisible to import scanners — configure your tool to ignore them.

Reference: depcheck · composer-unused

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides a comprehensive and safe framework for identifying, prioritizing, and auditing technical debt in PHP/Laravel and Node/TypeScript/React projects. No security risks or malicious behaviors were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 4df703d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 5 months ago
metadata
{
  "author": "agent-skills",
  "version": "1.0.0"
}

README badge

README badge for asyrafhussin/agent-skills/technical-debt