All skills
millionco avatar

/react-doctor

@1971506

Use when finishing a feature, fixing a bug, before committing React code, or when the user types `/doctor`, asks to scan, triage, or clean up React diagnostics. Covers lint, accessibility, bundle size, architecture. Includes a regression check and a full local-triage workflow that fetches the canonical playbook.

Use this Skill: https://skilld.dev/gh/millionco/react-doctor/react-doctor

This session only. Nothing lands on disk.

SKILL.md

≈82 tokens always: the name and description. ≈925 when used: this file. ≈1.1k more on demand in 1 file.

React Doctor

Scans React codebases for security, performance, correctness, and architecture issues. Outputs a 0–100 health score.

After making React code changes:

Run npx react-doctor@latest --verbose --scope changed and check the score did not regress.

If the score dropped, fix the regressions before committing.

For general cleanup or code improvement:

Run npx react-doctor@latest --verbose (the default --scope full) to scan the full codebase. Fix issues by severity — errors first, then warnings.

For a focused UI design audit:

Run npx react-doctor@latest design --verbose. This selects only design-tagged UI composition, typography, interaction, accessibility, and motion rules, including focused rules that remain opt-in during a general health scan.

For runtime performance problems:

Run npx react-doctor@latest scan <url> --format json in an interactive terminal. React Doctor opens an isolated system Chrome profile, records a DevTools trace while the user reproduces the slow interaction, and flashes purple outlines with component names as React renders. It stops when they press Enter. Read the structured summary first, then inspect the returned local .json.gz trace for CPU, browser, and React component evidence.

If the user needs their authenticated browser state, use --cdp <remote-debugging-url>. This requires Chrome to already be running with remote debugging. Never ask for cookies or copy the user's browser profile. Treat the trace as sensitive local application data and never upload it without explicit permission.

/doctor — full local triage workflow

When the user types /doctor, says "run react doctor", or asks for a full triage / cleanup pass (not just a regression check), fetch the canonical local-triage playbook and follow every step in it:

curl --fail --silent --show-error \
  --header 'Cache-Control: no-cache' \
  https://www.react.doctor/prompts/react-doctor-agent.md

The playbook is the single source of truth — a scan → filter → triage → fix → validate loop that edits the working tree directly (never commits, never opens PRs). Updating the prompt at its source updates every agent on its next fetch — no skill reinstall needed.

Pair it with the matching per-rule prompts at https://www.react.doctor/prompts/rules/<plugin>/<rule>.md (fetched on demand inside the playbook) so each fix uses the canonical, reviewer-tested recipe.

Configuring or explaining rules

When the user wants to understand a rule, disagrees with one, or wants to disable / tune which rules run (not fix code), read references/explain.md and follow it. Start with npx react-doctor@latest rules explain <rule>, then apply the narrowest control via npx react-doctor@latest rules disable|set|category|ignore-tag …, which edits your doctor.config.* (or package.json#reactDoctor).

Command

npx react-doctor@latest --verbose --scope changed
Flag Purpose
. Scan current directory
--verbose Show affected files and line numbers per rule
--scope changed Only report issues introduced vs the base branch (default: full)
--scope lines Only report issues on the changed lines
--score Output only the numeric score
design Run only the focused UI design diagnostics

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk HIGH
  • Gen Agent Trust Hub16d

    The skill instructs the agent to fetch a remote 'playbook' from an external URL and follow its instructions to directly modify the user's codebase. This architecture allows the external server to dynamically control the agent's behavior and file-system operations, bypassing the skill's static instructions and creating a high risk of unauthorized code execution.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 2 issues

  • Runlayer7mo

    1 file scanned · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 1971506. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
version
1.2.0

README badge

README badge for millionco/react-doctor

Scans React codebases for security, performance, correctness, and architecture issues, outputting a 0–100 health score. Use before committing to catch regressions, or run the full `/doctor` workflow to triage and fix issues by severity across the entire codebase.

Generated from the current SKILL.md.

Does this work with Next.js or other React frameworks?
React Doctor scans React codebases generally. The SKILL.md does not specify framework-specific limitations, so it should work with Next.js, Remix, and similar React-based projects, though the scope of checks may vary.
What categories of issues does react-doctor check for?
It scans for security, performance, correctness, and architecture issues. It also covers linting, accessibility, and bundle size concerns.
Can I check only the code I just changed instead of the full codebase?
Yes. Use `--scope changed` to report only issues introduced vs the base branch, or `--scope lines` to report only issues on the changed lines themselves.
Can I disable or customize which rules run?
Yes. Use `npx react-doctor@latest rules disable|set|category|ignore-tag` to control which rules apply, and the configuration is stored in `doctor.config.*` or `package.json#reactDoctor`.
Does the skill update automatically, or do I need to reinstall it?
The canonical playbook and per-rule prompts are fetched from react.doctor on demand, so updates to the source prompt apply automatically on the next fetch without skill reinstall.

Generated from the current SKILL.md. These answers refresh after source changes.