Working With Legacy Code
wondelai/skills
Safely change and test untested codebases using Feathers' "Working Effectively with Legacy Code".
Produces comprehensive summaries and insights about legacy codebases to help understand unfamiliar code.
$ npx skills add ArabelaTso/Skills-4-SE --skill legacy-code-summarizer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ArabelaTso/Skills-4-SE legacy-code-summarizer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/legacy-code-summarizer .claude/skills/legacy-code-summarizer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "legacy-code-summarizer" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/legacy-code-summarizer into .claude/skills/legacy-code-summarizer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "legacy-code-summarizer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/legacy-code-summarizerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ArabelaTso/Skills-4-SE --skill legacy-code-summarizer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ArabelaTso/Skills-4-SE legacy-code-summarizer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/legacy-code-summarizer .agents/skills/legacy-code-summarizer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "legacy-code-summarizer" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/legacy-code-summarizer into .agents/skills/legacy-code-summarizer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "legacy-code-summarizer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ArabelaTso/Skills-4-SE --skill legacy-code-summarizer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ArabelaTso/Skills-4-SE legacy-code-summarizer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/legacy-code-summarizer .cursor/skills/legacy-code-summarizer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "legacy-code-summarizer" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/legacy-code-summarizer into .cursor/skills/legacy-code-summarizer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "legacy-code-summarizer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ArabelaTso/Skills-4-SE.git --path skills/legacy-code-summarizer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ArabelaTso/Skills-4-SE --skill legacy-code-summarizer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ArabelaTso/Skills-4-SE legacy-code-summarizer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/legacy-code-summarizer .gemini/skills/legacy-code-summarizer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "legacy-code-summarizer" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/legacy-code-summarizer into .gemini/skills/legacy-code-summarizer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "legacy-code-summarizer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ArabelaTso/Skills-4-SE legacy-code-summarizerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ArabelaTso/Skills-4-SE --skill legacy-code-summarizer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/legacy-code-summarizer .github/skills/legacy-code-summarizer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "legacy-code-summarizer" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/legacy-code-summarizer into .github/skills/legacy-code-summarizer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "legacy-code-summarizer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ArabelaTso/Skills-4-SE --skill legacy-code-summarizer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ArabelaTso/Skills-4-SE legacy-code-summarizer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/legacy-code-summarizer .opencode/skills/legacy-code-summarizer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "legacy-code-summarizer" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/legacy-code-summarizer into .opencode/skills/legacy-code-summarizer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "legacy-code-summarizer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
legacy-code-summarizerProduces comprehensive summaries and insights about legacy codebases to help understand unfamiliar code.
Legacy Code Summarizer is an agent skill from ArabelaTso/Skills-4-SE. Produces comprehensive summaries and insights about legacy codebases to help understand unfamiliar code. Use when onboarding to a new project, planning refactoring efforts, assessing code for acquisition/migration, or generating documentation for undocumented systems. Analyzes architecture, dependencies, code quality issues, and test coverage. Creates high-level overviews with architecture diagrams, key components, entry points, and actionable insights for understanding and improving legacy code.
Its SKILL.md is about 5.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/architecture_patterns.md`, `references/code_quality_checklist.md` and `references/dependency_analysis.md`).
It sits in Development, covering Legacy modernization, Test coverage and Diagrams. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pytestpipmvnnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Legacy Code Summarizer loads about 5.2k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 131 tokens; SKILL.md has 560 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 560 words, ~5,179 tokens.
.claude/skills/legacy-code-summarizer/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Analyze and summarize legacy codebases to quickly understand their structure, quality, and improvement opportunities.
This skill helps understand legacy code by:
Get an overview of the project structure and size.
Initial Questions:
Commands to Run:
# Count lines of code
find . -name "*.py" | xargs wc -l | tail -1 # Python
find . -name "*.java" | xargs wc -l | tail -1 # Java
# Count files
find . -name "*.py" | wc -l
find . -name "*.java" | wc -l
# Directory structure
tree -L 3 -I '__pycache__|node_modules|target|build'
# Or without tree command
find . -type d -not -path '*/\.*' | head -20Identify Project Type:
Find where execution starts and main workflows.
Common Entry Points:
Python:
# Find main entry points
grep -r "if __name__ == '__main__':" --include="*.py"
# Find Flask/Django apps
grep -r "app = Flask\|application = " --include="*.py"
grep -r "INSTALLED_APPS\|MIDDLEWARE" --include="*.py"
# Find CLI entry points (setup.py, pyproject.toml)
grep -A 10 "entry_points\|console_scripts" setup.py pyproject.tomlJava:
# Find main methods
grep -r "public static void main" --include="*.java"
# Find Spring Boot applications
grep -r "@SpringBootApplication" --include="*.java"
# Find servlets
grep -r "extends HttpServlet\|@WebServlet" --include="*.java"JavaScript/TypeScript:
# Check package.json for entry points
cat package.json | grep -A 5 "main\|scripts"
# Find Express apps
grep -r "app = express()\|express()" --include="*.js" --include="*.ts"
# Find React entry points
find . -name "index.js" -o -name "index.tsx" -o -name "App.js"Understand the high-level structure and key modules.
Analyze Directory Structure:
# List top-level directories
ls -d */ | head -20
# Common patterns to look for:
# - src/ or lib/ (source code)
# - tests/ or test/ (test files)
# - config/ (configuration)
# - docs/ (documentation)
# - scripts/ (utility scripts)
# - models/ or entities/ (data models)
# - views/ or templates/ (UI)
# - controllers/ or handlers/ (business logic)
# - services/ or api/ (external services)
# - utils/ or helpers/ (utilities)Identify Architecture Pattern:
Common patterns in legacy code:
See references/architecture_patterns.md for detailed pattern identification.
Create Architecture Diagram:
Example Web Application Architecture:
┌─────────────────────────────────────────┐
│ Frontend (React) │
│ - components/ │
│ - pages/ │
│ - hooks/ │
└───────────────┬─────────────────────────┘
│ API Calls
↓
┌─────────────────────────────────────────┐
│ API Layer (Flask/Express) │
│ - routes/ │
│ - middleware/ │
└───────────────┬─────────────────────────┘
│
↓
┌─────────────────────────────────────────┐
│ Business Logic │
│ - services/ │
│ - controllers/ │
└───────────────┬─────────────────────────┘
│
↓
┌─────────────────────────────────────────┐
│ Data Layer │
│ - models/ │
│ - repositories/ │
└───────────────┬─────────────────────────┘
│
↓
┌─────────────────────────────────────────┐
│ Database (PostgreSQL/MongoDB) │
└─────────────────────────────────────────┘Map module relationships and identify coupling issues.
Find Direct Dependencies:
Python:
# Find imports in all Python files
grep -rh "^import \|^from " --include="*.py" | sort | uniq
# Analyze requirements
cat requirements.txt
# Or from setup.py
grep -A 20 "install_requires" setup.pyJava:
# Analyze Maven dependencies
cat pom.xml | grep -A 3 "<dependency>"
# Or Gradle
cat build.gradle | grep -A 3 "implementation\|compile"
# Find imports in code
grep -rh "^import " --include="*.java" | sort | uniq | head -50JavaScript:
# Analyze package.json
cat package.json | grep -A 50 "dependencies"
# Find imports
grep -rh "^import \|require(" --include="*.js" --include="*.ts" | head -50Create Dependency Map:
Key Internal Dependencies:
auth module
├─ depends on: user_model, database, config
└─ used by: api_routes, admin_panel
user_model
├─ depends on: database, validators
└─ used by: auth, profile, admin
payment module
├─ depends on: user_model, external_api, logger
└─ used by: checkout, subscription
Circular dependencies detected:
⚠️ module_a → module_b → module_c → module_aSee references/dependency_analysis.md for tools and techniques.
Detect technical debt, code smells, and improvement opportunities.
Common Quality Issues to Look For:
1. Large Files (God Objects)
# Find files over 500 lines
find . -name "*.py" -exec wc -l {} \; | awk '$1 > 500' | sort -rn
# Find files over 1000 lines (serious issue)
find . -name "*.java" -exec wc -l {} \; | awk '$1 > 1000' | sort -rn2. Dead Code
# Find unused imports (Python - requires tools)
# Install: pip install autoflake
find . -name "*.py" -exec autoflake --check {} \;
# Find TODO/FIXME comments
grep -rn "TODO\|FIXME\|HACK\|XXX" --include="*.py" --include="*.java"3. Code Duplication
# Find duplicate code (requires tool)
# Install: pip install pylint
pylint --disable=all --enable=duplicate-code src/
# Or use PMD for Java
# pmd cpd --minimum-tokens 100 --files src/4. Complex Functions
# Find long functions (crude check - look for large blocks)
# Python: Look for functions with many lines between def and next def
# Java: Look for methods with many lines between { and }
# Use complexity tools for accurate analysis:
# Python: radon cc src/ -a
# Java: Use PMD or Checkstyle5. Missing Documentation
# Find functions without docstrings (Python)
grep -A 1 "^def " --include="*.py" -r . | grep -v '"""' | grep -v "'''"
# Find classes without documentation (Java)
grep -B 1 "^public class\|^class " --include="*.java" -r . | grep -v "/\*\*" | grep -v "//"6. Outdated Patterns
Look for:
print "hello", raw_input())See references/code_quality_checklist.md for comprehensive quality checks.
Identify testing gaps and quality of existing tests.
Find Tests:
# Python tests
find . -name "test_*.py" -o -name "*_test.py"
ls tests/ test/
# Java tests
find . -name "*Test.java" -o -name "*Tests.java"
ls src/test/
# JavaScript tests
find . -name "*.test.js" -o -name "*.spec.js" -o -name "*.test.ts"Calculate Test Coverage:
Python:
# Install coverage tool
pip install pytest-cov
# Run tests with coverage
pytest --cov=src --cov-report=term-missing
# Generate HTML report
pytest --cov=src --cov-report=html
open htmlcov/index.htmlJava:
# Maven with JaCoCo
mvn clean test jacoco:report
# View report
open target/site/jacoco/index.htmlJavaScript:
# Jest with coverage
npm test -- --coverage
# View report
open coverage/lcov-report/index.htmlAssess Test Quality:
Quality Checklist:
- [ ] Unit tests exist for core business logic
- [ ] Integration tests cover key workflows
- [ ] Tests are readable and maintainable
- [ ] Tests run quickly (< 10 seconds for unit tests)
- [ ] Mocking is used appropriately
- [ ] Edge cases are tested
- [ ] Tests don't depend on external services (or are mocked)
- [ ] Coverage > 70% for critical modulesCreate actionable documentation for the team.
Summary Template:
# Legacy Codebase Summary: [Project Name]
## Executive Summary
[2-3 sentence overview of what the codebase does]
**Key Metrics:**
- Lines of Code: [X]
- Number of Files: [Y]
- Primary Language: [Language]
- Test Coverage: [Z%]
- Last Major Update: [Date]
## Architecture Overview
### High-Level Structure
[Include architecture diagram from Step 3]
### Key Components
1. **[Component Name]** (`path/to/component/`)
- **Purpose:** [What it does]
- **Entry Point:** [Main file/class]
- **Dependencies:** [Key dependencies]
- **Lines of Code:** [X]
2. **[Component Name]** (`path/to/component/`)
- **Purpose:** [What it does]
- **Entry Point:** [Main file/class]
- **Dependencies:** [Key dependencies]
- **Lines of Code:** [X]
[Repeat for 5-10 key components]
### Technology Stack
**Core Technologies:**
- [Language] [Version]
- [Framework] [Version]
- [Database] [Version]
**Key Dependencies:**
- [Library 1] - [Purpose]
- [Library 2] - [Purpose]
- [Library 3] - [Purpose]
## Entry Points and Workflows
### Main Entry Points
1. **[Entry Point Name]** - `path/to/file.py:function()`
- **Purpose:** [What it does]
- **Triggered by:** [User action, cron, API call, etc.]
2. **[Entry Point Name]** - `path/to/file.java:main()`
- **Purpose:** [What it does]
- **Triggered by:** [How it's invoked]
### Critical Workflows
**Workflow 1: [Name]** (e.g., User Registration)
**Workflow 2: [Name]** (e.g., Payment Processing)[Step-by-step flow]
## Dependency Analysis
### External Dependencies
**Total Dependencies:** [X]
**Outdated Dependencies (require updates):**
- [Library Name] [Current Version] → [Latest Version]
- [Library Name] [Current Version] → [Latest Version]
**Deprecated Dependencies (require replacement):**
- [Library Name] - Deprecated since [Date]
- **Suggested Replacement:** [New Library]
### Internal Dependencies
**Highly Coupled Modules (>5 dependencies):**
- `module_a` - depends on [X] modules
- `module_b` - depends on [Y] modules
**Circular Dependencies:**
- ⚠️ `auth` → `user` → `auth`
- ⚠️ `order` → `payment` → `order`
## Code Quality Assessment
### Metrics Summary
- **Average File Size:** [X] lines
- **Largest File:** `path/to/file.py` ([X] lines) ⚠️
- **TODO/FIXME Comments:** [X] occurrences
- **Code Duplication:** [Low/Medium/High]
### Quality Issues
**Critical Issues (Fix Immediately):**
1. **Security Vulnerability:** SQL injection in `path/to/file.py:45`
2. **Large File:** `god_class.java` (2,500 lines) - violates SRP
3. **Circular Dependency:** [Details]
**High Priority (Address Soon):**
1. **No Error Handling:** Missing try/catch in payment module
2. **Hardcoded Credentials:** Found in `config/settings.py`
3. **Deprecated API:** Using old authentication library
**Medium Priority (Technical Debt):**
1. **Code Duplication:** Copy-pasted validation logic in 5 files
2. **Missing Documentation:** 60% of functions lack docstrings
3. **Long Methods:** 15 methods exceed 100 lines
**Low Priority (Improvements):**
1. **Outdated Naming:** Inconsistent variable names
2. **Missing Type Hints:** (Python) or generics (Java)
3. **Verbose Code:** Could be simplified with modern patterns
### Code Smells Detected
- **God Objects:** [List large classes/modules]
- **Feature Envy:** [Methods accessing other objects' data frequently]
- **Dead Code:** [Unused functions/classes]
- **Magic Numbers:** [Hardcoded values without constants]
## Test Coverage Analysis
### Coverage Summary
- **Overall Coverage:** [X%]
- **Critical Modules Coverage:**
- auth module: [Y%]
- payment module: [Z%]
- user management: [W%]
### Testing Gaps
**Untested Critical Code:**
1. `payment/processor.py` - 0% coverage ⚠️
2. `auth/security.py` - 30% coverage
3. `api/routes.py` - 45% coverage
**Missing Test Types:**
- [ ] No integration tests for payment flow
- [ ] No end-to-end tests for user journey
- [ ] No performance/load tests
### Test Quality Issues
- **Slow Tests:** 20 tests take >5 seconds each
- **Flaky Tests:** `test_async_operation` fails intermittently
- **Coupled Tests:** Tests depend on database state
## Recommendations
### Immediate Actions (This Sprint)
1. **Fix Security Issues**
- Patch SQL injection vulnerability in `auth/login.py`
- Remove hardcoded credentials, use environment variables
2. **Add Critical Tests**
- Write integration tests for payment processor
- Add unit tests for authentication logic
3. **Break Circular Dependencies**
- Refactor `auth` ↔ `user` circular dependency
- Extract shared code to new `common` module
### Short-Term Improvements (This Quarter)
1. **Reduce Technical Debt**
- Refactor `god_class.java` into 3-4 focused classes
- Eliminate code duplication in validation logic
- Update deprecated dependencies
2. **Improve Documentation**
- Add docstrings to all public functions
- Create architecture diagram
- Document deployment process
3. **Enhance Test Coverage**
- Achieve 70% coverage for core modules
- Add integration tests for critical workflows
- Set up CI/CD with automated testing
### Long-Term Improvements (This Year)
1. **Architectural Refactoring**
- Extract microservices for payment and notification
- Implement proper layering (separate business logic from data access)
- Introduce dependency injection for better testability
2. **Modernization**
- Upgrade to [Language] [Latest Version]
- Adopt modern patterns (async/await, type hints, etc.)
- Migrate from [Old Framework] to [New Framework]
3. **Quality Infrastructure**
- Set up automated code quality checks (linting, complexity analysis)
- Implement pre-commit hooks
- Add performance monitoring
## Quick Reference
### Key Files to Understand First
1. `path/to/main.py` - Application entry point
2. `path/to/config.py` - Configuration
3. `path/to/models/user.py` - Core data model
4. `path/to/api/routes.py` - API endpoints
5. `path/to/services/auth_service.py` - Authentication logic
### Common Commands
```bash
# Start application
[command]
# Run tests
[command]
# Build for production
[command]
# Deploy
[command]
## Summary Output Examples
### Example 1: Small Python Flask App
```markdown
# Legacy Codebase Summary: Internal Dashboard
## Executive Summary
Internal dashboard for monitoring application metrics, built with Flask.
Provides real-time data visualization and alerting for operations team.
**Key Metrics:**
- Lines of Code: 3,500
- Number of Files: 42
- Primary Language: Python 3.7
- Test Coverage: 45%
- Last Major Update: 18 months ago
## Architecture Overview
Simple Flask application with SQLAlchemy ORM and PostgreSQL database.
┌─────────────────┐ │ Flask Routes │ │ (app/routes/) │ └────────┬────────┘ │ ↓ ┌─────────────────┐ │ Services │ │ (app/services/)│ └────────┬────────┘ │ ↓ ┌─────────────────┐ │ Models │ │ (app/models/) │ └────────┬────────┘ │ ↓ ┌─────────────────┐ │ PostgreSQL DB │ └─────────────────┘
### Key Components
1. **Metrics Dashboard** (`app/routes/dashboard.py`)
- Purpose: Display real-time metrics
- Entry Point: `dashboard_view()`
- Dependencies: metrics_service, chart_generator
- Lines of Code: 250
2. **Data Collection** (`app/services/collector.py`)
- Purpose: Fetch metrics from external APIs
- Entry Point: `collect_metrics()` (cron job)
- Dependencies: requests, database models
- Lines of Code: 180
3. **Alert System** (`app/services/alerts.py`)
- Purpose: Send notifications when thresholds exceeded
- Entry Point: `check_alerts()` (background task)
- Dependencies: email_service, metrics_service
- Lines of Code: 150
## Recommendations
### Immediate Actions
1. Update Flask to latest version (security patches)
2. Add tests for alert system (currently 0% coverage)
3. Fix hardcoded database credentials
### Short-Term
1. Increase test coverage to 70%
2. Add API documentation
3. Refactor large dashboard route (300+ lines)# Legacy Codebase Summary: E-Commerce Platform
## Executive Summary
Full-featured e-commerce platform handling product catalog, orders, payments,
and customer management. Serves 100K+ daily active users.
**Key Metrics:**
- Lines of Code: 185,000
- Number of Files: 1,240
- Primary Language: Java 8
- Test Coverage: 62%
- Last Major Update: 6 months ago
## Architecture Overview
Layered Spring Boot application with microservice patterns emerging.
[Detailed architecture diagram showing layers]
### Critical Issues Identified
**High Priority:**
1. **Memory Leak:** Order processing service shows increasing heap usage
2. **N+1 Query Problem:** Product listing generates 500+ DB queries
3. **No Monitoring:** Missing APM tools for production
**Modernization Opportunities:**
1. Migrate to Java 17 (LTS)
2. Extract payment service as microservice
3. Implement caching layer (Redis)
## Recommendations
[Detailed phased approach to refactoring]references/architecture_patterns.md - Common architectural patterns in legacy systems and how to identify themreferences/dependency_analysis.md - Tools and techniques for analyzing module dependencies and couplingreferences/code_quality_checklist.md - Comprehensive checklist for assessing code quality and technical debt| Task | Command/Approach |
|---|---|
| Count LOC | find . -name "*.py" | xargs wc -l |
| Find entry points | grep -r "if __name__ == '__main__'" |
| Analyze imports | grep -rh "^import |^from " | sort | uniq |
| Find large files | find . -name "*.py" -exec wc -l {} \\; | sort -rn |
| Test coverage | pytest --cov=src --cov-report=term |
| Find TODOs | grep -rn "TODO|FIXME" |
© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/legacy-code-summarizer of ArabelaTso/Skills-4-SE.
Open the folder on GitHubat commit 4f38503
Legacy Code Summarizer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Legacy Code Summarizer this skillArabelaTso/Skills-4-SE | 253 | — | ~5.2k | Automated safety check: Pass | Apache-2.0 | |
| Working With Legacy Codewondelai/skills | 2.4k | — | ~4.9k | Automated safety check: Pass | MIT | |
| Code Refactoring Workflowluongnv89/claude-howto | 42k | — | ~3.1k | Automated safety check: Pass | MIT | |
| Code ReviewerYikai-Liao/symusic | 189 | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Modern JavaScript Patternswshobson/agents | 40k | 12 repos | ~548 | Automated safety check: Pass | MIT | |
| Fowler-Style Refactoringlhfer/claude-howto-zh-cn | 2.3k | — | ~156 | Automated safety check: Pass | MIT |
wondelai/skills
Safely change and test untested codebases using Feathers' "Working Effectively with Legacy Code".
luongnv89/claude-howto
Guides systematic, test-backed refactoring in the style of Martin Fowler, moving through research, planning and small incremental changes with your approval at each phase.
Yikai-Liao/symusic
Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…
wshobson/agents
Covers ES6+ syntax and functional patterns for refactoring older JavaScript: async/await, destructuring, spread, modules, generators and data pipelines.
lhfer/claude-howto-zh-cn
基于 Martin Fowler 方法论做系统化重构。Use when users ask to refactor code, improve structure, reduce technical debt, clean up legacy code, or improve maintainability.
luongnv89/claude-howto
Vietnamese edition of a systematic refactoring skill based on Martin Fowler's book, working in approved phases with small, test-backed changes.
ArabelaTso/Skills-4-SE
Generate prioritized CVE watchlists and actionable security recommendations for repositories.
ArabelaTso/Skills-4-SE
Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).
ArabelaTso/Skills-4-SE
Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.
ArabelaTso/Skills-4-SE
Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.
ArabelaTso/Skills-4-SE
Automatically migrate Spring MVC applications to Spring Boot.
ArabelaTso/Skills-4-SE
Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.
Categories
Produces comprehensive summaries and insights about legacy codebases to help understand unfamiliar code. Legacy Code Summarizer is an agent skill from ArabelaTso/Skills-4-SE. Produces comprehensive summaries and insights about legacy codebases to help understand unfamiliar code.
Legacy Code Summarizer fits situations like: onboarding to a new project; planning refactoring efforts; assessing code for acquisition/migration; generating documentation for undocumented systems.
Run `npx skills add ArabelaTso/Skills-4-SE --skill legacy-code-summarizer -a claude-code`. Or copy the skill folder (skills/legacy-code-summarizer in ArabelaTso/Skills-4-SE) into .claude/skills/legacy-code-summarizer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ArabelaTso/Skills-4-SE --skill legacy-code-summarizer -a codex`. Or copy the skill folder (skills/legacy-code-summarizer in ArabelaTso/Skills-4-SE) into .agents/skills/legacy-code-summarizer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill legacy-code-summarizer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/legacy-code-summarizer, .gemini/skills/legacy-code-summarizer, .github/skills/legacy-code-summarizer and .opencode/skills/legacy-code-summarizer in your project.
Going by SKILL.md and its folder, Legacy Code Summarizer needs the command-line tools its instructions call (pytest, pip, mvn and npm). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use pip and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Legacy Code Summarizer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.2k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Legacy Code Summarizer: Working With Legacy Code (wondelai/skills, 2.4k stars), Code Refactoring Workflow (luongnv89/claude-howto, 42k stars), Code Reviewer (Yikai-Liao/symusic, 189 stars) and Modern JavaScript Patterns (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 170 skills in this directory. The repository was last updated on August 21, 2026.
Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.