Agent skill

Codebase Scanner

by EmeaAppGbb in EmeaAppGbb/spec2cloud

Scan project structure, detect languages and frameworks, identify entry points and application boundaries.

MITAuto-check: notesDevelopment

Install Codebase Scanner

skills CLI
$ npx skills add EmeaAppGbb/spec2cloud --skill codebase-scanner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EmeaAppGbb/spec2cloud codebase-scanner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EmeaAppGbb/spec2cloud.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/codebase-scanner .claude/skills/codebase-scanner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codebase-scanner
GitHub stars
100
Token cost
~2.2k tokens
SKILL.md length
829 words
Files
1
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

Scan project structure, detect languages and frameworks, identify entry points and application boundaries.

  • Works in 6 steps: Scan the File Tree → Detect Languages → Detect Frameworks and Libraries → …
  • You need a factual inventory of a projects technology footprint before any migration
  • SKILL.md covers Role, Inputs, Process and Output Format, plus 2 more sections
  • Calls python

What it does

Codebase Scanner is an agent skill from EmeaAppGbb/spec2cloud. Scan project structure, detect languages and frameworks, identify entry points and application boundaries. Pure extraction — document what exists with zero judgment, zero assessment, zero recommendations. Use when you need a factual inventory of a project's technology footprint before any migration, assessment, or modernization work begins.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Legacy modernization. It works with SQL, TypeScript and Gradle. The licence is MIT.

When your agent uses it

  • You need a factual inventory of a projects technology footprint before any migration
  • Modernization work begins

Example prompts

  • “/codebase-scanner”

Requirements

  • Python 3
  • Node.js
  • Docker

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Scan the File Tree
  2. Detect Languages
  3. Detect Frameworks and Libraries
  4. Identify Build Tools and Toolchain
  5. Find Entry Points
  6. Map Directory Structure Conventions

What it can do on your machine

Read from SKILL.md and the folder at commit 8e76618. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codebase Scanner loads about 2.2k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 829 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:134
    ig directories (`config/`, `settings/`, `.env*` files)?

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from EmeaAppGbb/spec2cloud at commit 8e76618, republished under its MIT licence (© EmeaAppGbb). 829 words, ~2,157 tokens.

Download SKILL.mdSave it as .claude/skills/codebase-scanner/SKILL.md (or your agent's skills folder).
name
codebase-scanner
description
Scan project structure, detect languages and frameworks, identify entry points and application boundaries. Pure extraction — document what exists with zero judgment, zero assessment, zero recommendations. Use when you need a factual inventory of a project's technology footprint before any migration, assessment, or modernization work begins.

Codebase Scanner

Role

You are the Codebase Scanner — a factual inventory agent. Your job is to create a comprehensive, accurate catalog of what exists in a project's source tree: languages, frameworks, build tools, entry points, directory conventions, and runtime characteristics.

You are a camera, not a critic. You record what is there. You NEVER assess quality, suggest improvements, flag concerns, or express opinions. If the project uses jQuery and hand-rolled SQL queries, you document "jQuery" and "raw SQL queries" — nothing more.

Inputs

  • The root directory of the project to scan
  • Any existing documentation (README, CONTRIBUTING, docs/) — treat as supplementary, not authoritative. Code is the source of truth.

Process

Step 1 — Scan the File Tree

Walk the entire project directory. For each file and directory:

  1. Record the file extension and path.
  2. Skip .git/, node_modules/, vendor/, __pycache__/, bin/, obj/, .idea/, .vscode/ (IDE/tooling directories).
  3. Count files per extension to identify dominant languages.
  4. Note the top-level directory structure and any conventions (e.g., src/, lib/, app/, cmd/, internal/, tests/).
Step 2 — Detect Languages

Identify every programming language in use. Use both file extensions and configuration file presence:

LanguageExtensionsConfig Indicators
TypeScript.ts, .tsxtsconfig.json
JavaScript.js, .jsx, .mjs, .cjspackage.json without tsconfig.json
Python.pyrequirements.txt, setup.py, pyproject.toml, Pipfile
C#.cs*.csproj, *.sln, Directory.Build.props
Java.javapom.xml, build.gradle, build.gradle.kts
Go.gogo.mod, go.sum
Rust.rsCargo.toml, Cargo.lock
Ruby.rbGemfile, Rakefile
PHP.phpcomposer.json
Kotlin.kt, .ktsbuild.gradle.kts with Kotlin plugin
Swift.swiftPackage.swift, *.xcodeproj
HTML/CSS.html, .css, .scss, .less—
SQL.sql—
Shell.sh, .bash, .zsh—

Record the percentage of the codebase each language represents (by file count).

Step 3 — Detect Frameworks and Libraries

Identify frameworks by parsing configuration and manifest files:

Node.js / JavaScript / TypeScript:

  • package.json → scan dependencies and devDependencies for known frameworks: React, Next.js, Angular, Vue, Svelte, Express, Fastify, NestJS, Hono, Remix, Astro, Vite, Webpack, esbuild, etc.
  • Check for framework-specific config files: next.config.*, angular.json, vue.config.*, svelte.config.*, vite.config.*, .babelrc

Python:

  • requirements.txt / pyproject.toml / Pipfile → Django, Flask, FastAPI, SQLAlchemy, Celery, pytest, etc.
  • Check for manage.py (Django), app.py / main.py with framework imports

C# / .NET:

  • *.csproj → scan PackageReference elements for ASP.NET Core, Entity Framework, Blazor, MAUI, etc.
  • Check Program.cs / Startup.cs for builder patterns

Java:

  • pom.xml / build.gradle → Spring Boot, Jakarta EE, Micronaut, Quarkus, Hibernate, etc.
  • Check for @SpringBootApplication, application.properties/application.yml

Go:

  • go.mod → Gin, Echo, Fiber, Chi, GORM, etc.

Rust:

  • Cargo.toml → Actix, Axum, Rocket, Diesel, Tokio, etc.
Step 4 — Identify Build Tools and Toolchain

Document every build, bundling, and toolchain component:

  • Package managers: npm, yarn, pnpm, pip, Poetry, Maven, Gradle, Cargo, Go modules
  • Bundlers: Webpack, Vite, esbuild, Parcel, Rollup, Turbopack
  • Compilers/transpilers: TypeScript (tsc), Babel, SWC, Sass/SCSS
  • Task runners: Make, Just, Taskfile, npm scripts, Gradle tasks
  • Code generators: Prisma, protobuf, GraphQL codegen, OpenAPI generators
  • Container tools: Dockerfile, docker-compose.yml, .dockerignore
Step 5 — Find Entry Points

Identify how the application starts and where requests enter:

  1. Server entry points: main.go, Program.cs, app.py, server.ts, index.ts, main.rs, or whatever scripts.start / scripts.dev points to in package.json.
  2. CLI entry points: bin/ directories, console_scripts in setup.py, main functions.
  3. Web entry points: index.html, App.tsx, pages/, routes/.
  4. Serverless entry points: function.json, serverless.yml, handler files.
  5. Background workers: queue consumers, cron jobs, scheduled tasks.

For each entry point, record: file path, type (server/CLI/web/serverless/worker), and the start command if identifiable.

Show full SKILL.md (296 more words)Show less
Step 6 — Map Directory Structure Conventions

Document the project's organizational patterns:

  • Is source code in src/, app/, lib/, or root?
  • Are tests colocated or in a separate tests//test//__tests__/ directory?
  • Is there a monorepo structure (Lerna, Turborepo, Nx, workspaces)?
  • Are there config directories (config/, settings/, .env* files)?
  • Infrastructure-as-code directories (infra/, terraform/, bicep/, cdk/)?
  • CI/CD configuration (.github/workflows/, .gitlab-ci.yml, Jenkinsfile, .circleci/, azure-pipelines.yml)?
  • Documentation directories (docs/, wiki/, ADR/)?

Output Format

Produce specs/docs/technology/stack.md with the following structure:

markdown
# Technology Stack — [Project Name]

_Extracted on [date]. This is a factual inventory of the project as it exists._

## Languages

| Language | File Count | Percentage | Config File |
|----------|-----------|------------|-------------|
| TypeScript | 142 | 68% | tsconfig.json |
| ... | ... | ... | ... |

## Frameworks

| Framework | Version | Category | Detected From |
|-----------|---------|----------|---------------|
| Next.js | 14.1.0 | Web framework | package.json |
| ... | ... | ... | ... |

## Build Tools

| Tool | Version | Purpose | Config File |
|------|---------|---------|-------------|
| ... | ... | ... | ... |

## Runtime Dependencies

[List from package manifests — direct dependencies only]

## Dev Dependencies

[List from package manifests — devDependencies only]

## Entry Points

| File | Type | Start Command |
|------|------|---------------|
| src/index.ts | Server | npm start |
| ... | ... | ... |

## Directory Structure

[Tree representation of top-level directories with descriptions]

## Additional Observations

[Raw facts only — e.g., "The project contains 3 Dockerfiles",
"There are 2 package.json files indicating a monorepo structure"]

Rules

  1. Facts only. Every statement must be verifiable by looking at the code.
  2. No assessment. Do not say "outdated", "modern", "legacy", "good", "bad", "should", "could", or "recommend". These words are banned.
  3. No opinions. Do not comment on code quality, architecture decisions, or technology choices.
  4. Code over docs. If README says "Python 3.11" but pyproject.toml says python = "^3.9", report both — but the config file is the primary record.
  5. Complete inventory. Missing a language or framework that's actually in use is a failure. When in doubt, include it.
  6. Version precision. Report exact version constraints as written in manifest files (e.g., "^18.2.0" not just "18").
  7. No inferencing beyond the code. If you can't determine something from the files, say "not determinable from source" — do not guess.

Mandatory Completion Checklist

The orchestrator MUST verify ALL of the following before marking codebase-scanner as complete:

  • specs/docs/technology/stack.md exists and contains: languages, frameworks, package managers, build tools, and entry points
  • Every language detected has version constraints documented (from manifest files)
  • Every framework detected has its role documented (web, API, testing, etc.)
  • Entry points are identified for each application boundary
  • Monorepo workspaces (if any) are inventoried separately

BLOCKING: If any item is unchecked, the skill has NOT completed successfully. The orchestrator must loop back and complete the missing items before advancing to the next extraction step.

© EmeaAppGbb, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/codebase-scanner of EmeaAppGbb/spec2cloud.

Open the folder on GitHubat commit 8e76618

Compare with similar skills

Codebase Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codebase Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codebase Scanner this skillEmeaAppGbb/spec2cloud100—~2.2kAutomated safety check: NotesMIT
jscpd Code Migration Trackerkucherenko/jscpd6.3k—~5kAutomated safety check: PassMIT
Convert Internal Package to TypeScriptTryGhost/Ghost55k—~1.2kAutomated safety check: PassMIT
Coding Agentmastra-ai/mastra29k—~2.3kAutomated safety check: PassCustom licence
AngularJS to Angular Migrationwshobson/agents40k10 repos~1.8kAutomated safety check: PassMIT
Code Explainermergisi/awesome-openclaw-agents4k—~283Automated safety check: PassMIT

Similar skills

  • Measures a code port between languages or frameworks with jscpd's function-level comparison, porting tests before code and tracking what is left unmatched.

    6.3k GitHub stars~5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Moves a legacy internal Ghost package from JavaScript and CommonJS to TypeScript and ESM in three focused commits that keep git file history intact.

    55k GitHub stars~1.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Coding Agent

    mastra-ai/mastra

    Authoring playbook for building agents that write, edit, review, or refactor code.

    29k GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Guides migrating AngularJS 1.x apps to modern Angular: choosing a strategy, running a hybrid app with ngUpgrade, and converting controllers, directives and services.

    40k GitHub starsUsed in 10 repos~1.8k tokens
    DevelopmentAuto-check passed
  • Code Explainer

    mergisi/awesome-openclaw-agents

    Explains a pasted code snippet in plain English, returning the detected language, a one-sentence summary, how it works and one practical tip.

    4k GitHub stars~283 tokensUpdated 11 days ago
    DevelopmentAuto-check passed
  • Aspire Project V2 Migration

    CommunityToolkit/Aspire

    WORKFLOW SKILL - Safely migrates eligible Aspire 13.6+ AppHosts from legacy ProjectResource APIs to experimental DotnetProjectResource APIs after a per-resource assessment and explicit approval of…

    629 GitHub stars~3.4k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from EmeaAppGbb/spec2cloud

All 39 skills in this repo
  • Azure Deployment

    EmeaAppGbb/spec2cloud

    Provision Azure infrastructure, deploy to Azure Container Apps, and verify via smoke tests.

    100 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Contract Generation

    EmeaAppGbb/spec2cloud

    Generate API contracts, shared TypeScript types, and infrastructure resource definitions from Gherkin scenarios and test files.

    100 GitHub stars~1.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Ddd Modeling

    EmeaAppGbb/spec2cloud

    Create Domain-Driven Design proposals from product specs or brownfield extraction outputs.

    100 GitHub stars~2.4k tokensUpdated 5 mo ago
    Auto-check passed
  • Implementation

    EmeaAppGbb/spec2cloud

    Write application code to make failing tests pass using contract-driven, slice-based architecture.

    100 GitHub stars~2.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Spec Refinement

    EmeaAppGbb/spec2cloud

    Review PRDs and FRDs through product and technical lenses. An agent skill from EmeaAppGbb/spec2cloud.

    100 GitHub stars~2.2k tokensUpdated 5 mo ago
    Auto-check passed
  • State Management

    EmeaAppGbb/spec2cloud

    Read, write, and maintain .spec2cloud/state.json across phases and increments.

    100 GitHub stars~1.5k tokensUpdated 5 mo ago
    Auto-check passed

Questions about Codebase Scanner

What does Codebase Scanner do?

Scan project structure, detect languages and frameworks, identify entry points and application boundaries. Codebase Scanner is an agent skill from EmeaAppGbb/spec2cloud. Scan project structure, detect languages and frameworks, identify entry points and application boundaries.

When should I use Codebase Scanner?

Codebase Scanner fits situations like: you need a factual inventory of a projects technology footprint before any migration; modernization work begins.

How do I install Codebase Scanner in Claude Code?

Run `npx skills add EmeaAppGbb/spec2cloud --skill codebase-scanner -a claude-code`. Or copy the skill folder (.github/skills/codebase-scanner in EmeaAppGbb/spec2cloud) into .claude/skills/codebase-scanner in your project. Claude Code loads it when a task matches its description.

How do I install Codebase Scanner in Codex?

Run `npx skills add EmeaAppGbb/spec2cloud --skill codebase-scanner -a codex`. Or copy the skill folder (.github/skills/codebase-scanner in EmeaAppGbb/spec2cloud) into .agents/skills/codebase-scanner in your project. Codex loads it when a task matches its description.

Can I use Codebase Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EmeaAppGbb/spec2cloud --skill codebase-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codebase-scanner, .gemini/skills/codebase-scanner, .github/skills/codebase-scanner and .opencode/skills/codebase-scanner in your project.

What does Codebase Scanner need to run?

Going by SKILL.md and its folder, Codebase Scanner needs the command-line tools its instructions call (python). Our summary lists: Python 3; Node.js; Docker.

Does Codebase Scanner access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Codebase Scanner safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Codebase Scanner use?

Codebase Scanner is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codebase Scanner use?

About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codebase Scanner?

Skills that share tags, products or a category with Codebase Scanner: jscpd Code Migration Tracker (kucherenko/jscpd, 6.3k stars), Convert Internal Package to TypeScript (TryGhost/Ghost, 55k stars), Coding Agent (mastra-ai/mastra, 29k stars) and AngularJS to Angular Migration (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codebase Scanner?

EmeaAppGbb (a GitHub organization) maintains it in EmeaAppGbb/spec2cloud, which has 100 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on April 16, 2026.

Source: EmeaAppGbb/spec2cloud on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.