All skills
oaustegard avatar

/assessing-impact

@4b31e7d

Pre-change blast-radius report for a symbol or file. Walks tree-sitting references, augments with a plain-text scan over non-parsed files (configs, plain docs), and clusters affected sites by feature (`_FEATURES.md`) or top-level package. Use when about to refactor, rename, or delete something in a repo you don't own — "what breaks if I change `validateUser`", "who calls this", "is this safe to remove", "where is this used", "blast radius", "impact analysis". This is the CONVERGENT pre-change risk skill — for "what is this repo?" use exploring-codebases; for "where is X?" use searching-codebases.

Use this Skill: https://skilld.dev/gh/oaustegard/claude-skills/assessing-impact

This session only. Nothing lands on disk.

README.md

≈534 tokens on demand. Your agent reads this file only when SKILL.md points to it.

assessing-impact

Pre-change blast-radius reports for a symbol or file in a local codebase. Walks the tree-sitting AST cache for direct references, augments with a plain-text scan over file types tree-sitting doesn't parse, and clusters affected sites by package, tests, docs, and (when present) _FEATURES.md features.

Features

  • Symbol or file targets — identify what breaks if you change validateUser or refactor auth.py
  • AST-aware ref discovery — uses tree-sitting's parsed corpus, excluding definition lines so refs are uses, not declarations
  • Non-AST text scan — picks up Dockerfile, .ini, .env, .properties, plain .txt/.rst references that the AST scanner misses
  • Three-axis clustering — code-by-package, tests, and docs, with optional _FEATURES.md overlay
  • Test surface suggestion — surfaces tests that already reference the target plus tests neighboring the definition
  • No opinionated risk score — structured report is input for the LLM that writes the final summary
  • Substring-fallback warning — flags when the target had no exact match so the resulting noise is visible
  • Markdown or JSON output

Dependency

Requires the tree-sitting skill — imports engine.py directly and uses its bundled grammars.

Relationship to Other Skills

  • exploring-codebases — divergent first-encounter EDA; run before assessing-impact if the repo also needs an _FEATURES.md
  • searching-codebases — convergent "where is X" search; complementary, not a replacement for impact analysis
  • tree-sitting — drill into specific call sites once impact has identified them
  • featuring — produces the _FEATURES.md files that assessing-impact overlays for feature-area clustering

Honest Limits

Text-based ref discovery, no type/MRO resolution, no cross-language or cross-repo tracing, no persistent index. For deep ongoing impact analysis on a daily codebase, GitNexus or SourceGraph remain the right tool. This skill is for the ad-hoc case: "I'm about to refactor X in a repo I don't own, what should I be careful about?"

Source: SKILL.md on GitHub

1 warning9d3 checks · Risk MEDIUM
  • Gen Agent Trust Hub9d

    This skill analyzes codebase impact by walking AST trees and scanning text. It contains dynamic loading mechanisms to import its core engine from a peer skill and processes source code snippets that could potentially host indirect prompt injections.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at 4b31e7d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "version": "0.1.1"
}

README badge

README badge for oaustegard/claude-skills/assessing-impact