All skills
jeffallan avatar

/spec-miner

@efebc44
by jeffallanjeffallan/claude-skills12k stars
1,124

Reverse-engineering specialist that extracts specifications from existing codebases. Use when working with legacy or undocumented systems, inherited projects, or old codebases with no documentation. Invoke to map code dependencies, generate API documentation from source, identify undocumented business logic, figure out what code does, or create architecture documentation from implementation. Trigger phrases: reverse engineer, old codebase, no docs, no documentation, figure out how this works, inherited project, legacy analysis, code archaeology, undocumented features.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/spec-miner

This session only. Nothing lands on disk.

referencesanalysis-checklist.md

≈510 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Analysis Checklist

Comprehensive Checklist

Area What to Find Glob/Grep Patterns
Entry points main.ts, app.ts, index.ts **/main.{ts,js,py}
Routes Controllers, route files **/routes/**/*, @Controller
Models Entities, schemas **/models/**/*, @Entity
Auth Guards, middleware, JWT **/auth/**/*, passport
Validation DTOs, validators, pipes **/dto/**/*, @IsString
Error handling Exception filters, try/catch ExceptionFilter, catch
External calls HTTP clients, SDK usage fetch(, axios.
Config Env files, config modules **/.env*, ConfigService
Tests Test files reveal behaviors **/*.spec.ts, **/*.test.ts
Background jobs Queues, cron, workers @Cron, Bull, Queue

Analysis Phases

Phase 1: Structure Discovery

  • Identify technology stack
  • Map directory structure
  • Find entry points
  • List all modules/packages

Phase 2: API Surface

  • Document all endpoints
  • Note HTTP methods and paths
  • Identify request/response formats
  • Find authentication requirements

Phase 3: Data Layer

  • Map all data models
  • Document relationships
  • Find migrations
  • Note validation rules

Phase 4: Business Logic

  • Trace main flows
  • Identify business rules
  • Document state transitions
  • Find external integrations

Phase 5: Security

  • Check authentication method
  • Review authorization patterns
  • Find input validation
  • Note security configurations

Phase 6: Quality & Testing

  • Review existing tests
  • Note test coverage
  • Document error handling
  • Find logging patterns

Verification Questions

Before finalizing specification:

  • All endpoints documented?
  • All models mapped?
  • Authentication flow clear?
  • Error responses documented?
  • External dependencies listed?
  • Uncertainties flagged?

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    The skill facilitates reverse-engineering of codebases but directs the agent to access sensitive credentials in .env files and environment configurations. Security scanners have flagged the skill file itself and its external documentation links as potentially malicious.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    1/5 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at efebc44. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
What it can do
Reads files Runs commands
All 4 allowed tools
ReadGrepGlobBash
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.0",
  "domain": "workflow",
  "triggers": "reverse engineer, legacy code, code analysis, undocumented, understand codebase, existing system",
  "role": "specialist",
  "scope": "review",
  "output-format": "document",
  "related-skills": "feature-forge, fullstack-guardian, architecture-designer"
}
  • Documentation
  • reverse-engineering
  • legacy-code
  • code-analysis
  • codebase-exploration
  • requirements-extraction
  • architecture
  • undocumented-systems

README badge

README badge for jeffallan/claude-skills/spec-miner

Extracts specifications from undocumented or legacy codebases by systematically exploring code structure, tracing data flows, and documenting observed behavior in EARS format. Use this skill when onboarding to inherited projects, creating documentation from implementation, or understanding systems with no written specification.

Generated from the current SKILL.md.

What tools can this skill use to explore a codebase?
The skill uses Read, Grep, Glob, and Bash to map file structure, locate patterns, trace data flows, and extract observable behaviors from source code.
Does this skill generate documentation in a specific format?
Yes. It documents observed requirements using EARS (Easy Approach to Requirements Syntax) format, which structures behavior as ubiquitous, event-driven, state-driven, or optional rules.
Can this skill work on any codebase or language?
The skill is language-agnostic and designed for any codebase, but examples in the documentation focus on Python (Flask, Django) and Express. Adjustment of Glob and Grep patterns may be needed for other languages or frameworks.
Does this skill make assumptions or only report what it finds in code?
The skill must ground all observations in actual code evidence and distinguish between observed facts and inferences. It documents uncertainties in a dedicated section rather than making unsupported assumptions.
What does the skill output?
It produces a specification document saved as `specs/{project_name}_reverse_spec.md`, including technology stack, module structure, observed requirements, non-functional observations, inferred acceptance criteria, uncertainties, and recommendations.

Generated from the current SKILL.md. These answers refresh after source changes.