All skills
github avatar

/acquire-codebase-knowledge

@9ce8148 official
by githubgithub/awesome-copilot40k stars
5,040

Use this skill when the user explicitly asks to map, document, or onboard into an existing codebase. Trigger for prompts like "map this codebase", "document this architecture", "onboard me to this repo", or "create codebase docs". Do not trigger for routine feature implementation, bug fixes, or narrow code edits unless the user asks for repository-level discovery.

Use this Skill: https://skilld.dev/gh/github/awesome-copilot/acquire-codebase-knowledge

This session only. Nothing lands on disk.

referencesinquiry-checkpoints.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Inquiry Checkpoints

Per-template investigation questions for Phase 2 of the acquire-codebase-knowledge workflow. For each template area, look for answers in the scan output first, then read source files to fill gaps.


1. STACK.md — Tech Stack

  • What is the primary language and exact version? (check .nvmrc, go.mod, pyproject.toml, Docker FROM line)
  • What package manager is used? (npm, yarn, pnpm, go mod, pip, uv)
  • What are the core runtime frameworks? (web server, ORM, DI container)
  • What do dependencies (production) vs devDependencies (dev tooling) contain?
  • Is there a Docker image and what base image does it use?
  • What are the key scripts in package.json / Makefile / pyproject.toml?

2. STRUCTURE.md — Directory Layout

  • Where does source code live? (usually src/, lib/, or project root for Go)
  • What are the entry points? (check main in package.json, scripts.start, cmd/main.go, app.py)
  • What is the stated purpose of each top-level directory?
  • Are there non-obvious directories (e.g., eng/, platform/, infra/)?
  • Are there hidden config directories (.github/, .vscode/, .husky/)?
  • What naming conventions do directories follow? (camelCase, kebab-case, domain-based vs layer-based)

3. ARCHITECTURE.md — Patterns

  • Is the code organized by layer (controllers → services → repos) or by feature?
  • What is the primary data flow? Trace one request or command from entry to data store.
  • Are there singletons, dependency injection patterns, or explicit initialization order requirements?
  • Are there background workers, queues, or event-driven components?
  • What design patterns appear repeatedly? (Factory, Repository, Decorator, Strategy)

4. CONVENTIONS.md — Coding Standards

  • What is the file naming convention? (check 10+ files — camelCase, kebab-case, PascalCase)
  • What is the function and variable naming convention?
  • Are private methods/fields prefixed (e.g., _methodName, #field)?
  • What linter and formatter are configured? (check .eslintrc, .prettierrc, golangci.yml)
  • What are the TypeScript strictness settings? (strict, noImplicitAny, etc.)
  • How are errors handled at each layer? (throw vs. return structured error)
  • What logging library is used and what is the log message format?
  • How are imports organized? (barrel exports, path aliases, grouping rules)

5. INTEGRATIONS.md — External Services

  • What external APIs are called? (search for axios., fetch(, http.Get(, base URLs in constants)
  • How are credentials stored and accessed? (.env, secrets manager, env vars)
  • What databases are connected? (check manifest for pg, mongoose, prisma, typeorm, sqlalchemy)
  • Is there an API gateway, service mesh, or proxy between the app and external services?
  • What monitoring or observability tools are used? (APM, Prometheus, logging pipeline)
  • Are there message queues or event buses? (Kafka, RabbitMQ, SQS, Pub/Sub)

6. TESTING.md — Test Setup

  • What test runner is configured? (check scripts.test in package.json, pytest.ini, go test)
  • Where are test files located? (alongside source, in tests/, in __tests__/)
  • What assertion library is used? (Jest expect, Chai, pytest assert)
  • How are external dependencies mocked? (jest.mock, dependency injection, fixtures)
  • Are there integration tests that hit real services vs. unit tests with mocks?
  • Is there a coverage threshold enforced? (check jest.config.js, .nycrc, pyproject.toml)

7. CONCERNS.md — Known Issues

  • How many TODOs/FIXMEs/HACKs are in production code? (see scan output)
  • Which files have the highest git churn in the last 90 days? (see scan output)
  • Are there any files over 500 lines that mix multiple responsibilities?
  • Do any services make sequential calls that could be parallelized?
  • Are there hardcoded values (URLs, IDs, magic numbers) that should be config?
  • What security risks exist? (missing input validation, raw error messages exposed to clients, missing auth checks)
  • Are there performance patterns that don't scale? (N+1 queries, in-memory caches in multi-instance setups)

Source: SKILL.md on GitHub

No alerts15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill facilitates codebase onboarding by scanning local project files and git history to generate documentation. It is generally safe and authored by a trusted vendor, but it carries an inherent low risk of indirect prompt injection if the analyzed codebase contains malicious instructions designed to influence the documentation process.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 9ce8148. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
Other metadata
compatibility
Cross-platform. Requires Python 3.8+ and git. Run scripts/scan.py from the target project root.
metadata
{
  "version": "1.3",
  "enhancements": [
    "Multi-language manifest detection (25+ languages supported)",
    "CI/CD pipeline detection (10+ platforms)",
    "Container & orchestration detection",
    "Code metrics by language",
    "Security & compliance config detection",
    "Performance testing markers"
  ]
}
argument-hint
Optional: specific area to focus on, e.g. "architecture only", "testing and concerns"

README badge

README badge for github/awesome-copilot/acquire-codebase-knowledge

Scans a codebase with a Python script to extract stack, structure, architecture, conventions, integrations, testing setup, and known concerns, then populates seven markdown documents in docs/codebase/ with verified facts only. Targets onboarding scenarios where a developer or agent needs to understand an unfamiliar repository quickly.

Generated from the current SKILL.md.

Does this skill work with monorepos?
Yes. The skill detects workspaces and packages directories, and maps each sub-package separately with independent dependencies and conventions.
What languages and platforms does this support?
Cross-platform (Windows, macOS, Linux). Requires Python 3.8+, git, and detects 25+ programming languages. Run scripts/scan.py from the target project root.
Does this document generated code and build artifacts?
No. The skill documents only source conventions and patterns, explicitly avoiding dist/, build/, generated/, .next/, out/, and __pycache__ directories.
What happens if the skill can't determine something about the codebase?
Unknown items are marked [TODO]. If the answer requires team intent or context, it is marked [ASK USER] and presented as a numbered question at the end.
What output does this skill produce?
Seven documented files in docs/codebase/: STACK.md, STRUCTURE.md, ARCHITECTURE.md, CONVENTIONS.md, INTEGRATIONS.md, TESTING.md, and CONCERNS.md, with evidence trails to source files.

Generated from the current SKILL.md. These answers refresh after source changes.