All skills
oaustegard avatar

/exploring-codebases

@5e58100

First-encounter orientation on a repository nobody here has worked in yet. Runs a fixed five-step workflow — venv setup, tarball fetch, tree-sitting structural scan, featuring synthesis, then reasoning over the two — and yields an account of what the repo contains and how it is arranged, optionally written out as _FEATURES.md. Use for "I just cloned this", "what is this repo", "what does this do", "explore this repo", "give me an orientation", "what are the main features", "review what's new in this repo", or before starting work in a codebase you have not seen. This is the divergent what's-here skill. Route elsewhere for: a named symbol, a file's structure or a line range (tree-sitting); all callers of a Python symbol (searching-codebases); teaching a human the codebase through exercises (orienting-codebases); fetching or cloning a repo without analysing it (accessing-github-repos, cloning-project).

Use this Skill: https://skilld.dev/gh/oaustegard/claude-skills/exploring-codebases

This session only. Nothing lands on disk.

referencessubagent-delegation.md

≈564 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Delegating exploration to subagents

Loaded from the exploring-codebases workflow. Applies only when the repo is large (>1000 files or several distinct subsystems) AND this environment exposes a subagent tool. Steps 2-3 of the main workflow stay inline either way -- they are mechanical and cheap; only step 4's judgment work fans out.

Gate first: does this environment expose a subagent tool (Agent/Task in Claude Code and CCotw)? Claude.ai chat and bare-skill runs have none — run steps 2–4 inline and skip this section entirely. Never simulate fan-out by other means when the tool is absent.

When the tool exists and the repo is large (>1000 files or several distinct subsystems), keep steps 2–3 inline — they're mechanical and cheap — and fan out only step 4's judgment work, one agent per subsystem.

Subagents inherit nothing. Not your conversation, not this SKILL.md, not the knowledge that scan artifacts exist on disk. An agent prompted only with "explore crates/foo" will re-derive structure by ls/glob crawling at full tier cost. (Observed 2026-07-16: four Sonnet agents launched onto a 2,300-file repo without the handoff spent their opening turns running ls, with the full symbol index already on disk.)

Every subagent prompt must therefore carry:

  1. Its structure slice, pre-computed. Partition the gather output's ## Public API section by subsystem path prefix, write each slice to a file, and point the agent at its file: "grep/Read this instead of listing directories." Small slices (<50KB) can be pasted inline instead.
  2. The treesit recipe verbatim — the full command including the venv python path, plus the batch rule (one invocation, many queries; each invocation pays the scan, extra queries are free).
  3. Anti-crawl instructions — no ls/Glob for discovery; Read only to confirm or expand a line range the slice or treesit already located.
  4. An output spec — what to report, a line budget, and "file paths + line refs" so results are verifiable.

Routing (see the agent-routing skill): multi-turn exploration is outside Haiku's calibrated zone — use sonnet for subsystem agents and keep the final cross-cluster synthesis in the orchestrator.

Source: SKILL.md on GitHub

2 warnings14d4 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    This skill allows an AI agent to explore new codebases by downloading them from GitHub and performing structural analysis. It is designed to help the agent orient itself in unfamiliar repositories. The security profile is generally safe as it uses trusted sources, but there is an inherent risk of indirect prompt injection because the agent is tasked with processing and reasoning over untrusted external code.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    7/7 files flagged

Signed by skilld at 5e58100. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 weeks ago
metadata
{
  "version": "2.5.2"
}

README badge

README badge for oaustegard/claude-skills/exploring-codebases