Agent skill

Codebase Onboarding

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when you land in an unfamiliar or inherited codebase and must get productive fast: a breadth-first map of entry points, request flow, module ownership, hidden side effects…

MITAuto-check passedDevelopment

Install Codebase Onboarding

skills CLI
$ npx skills add ericrisco/rsc-harness --skill codebase-onboarding -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness codebase-onboarding --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codebase-onboarding .claude/skills/codebase-onboarding && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codebase-onboarding
GitHub stars
167
Token cost
~2.4k tokens
SKILL.md length
1,092 words
Files
5 (incl. scripts, references)
Skills in repo
227
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when you land in an unfamiliar or inherited codebase and must get productive fast: a breadth-first map of entry points, request flow, module ownership, hidden side effects…

  • Works in 2 steps: Breadth before depth. First pass maps… → Hypothesis before answer. Spend ~5…
  • You land in an unfamiliar
  • SKILL.md covers Lead with the deliverable, Two operating rules, The recon pass — ordered and Scope the effort, plus 3 more sections
  • Runs Shell scripts from its folder; calls rg and git

What it does

Codebase Onboarding is an agent skill from ericrisco/rsc-harness. Use when you land in an unfamiliar or inherited codebase and must get productive fast: a breadth-first map of entry points, request flow, module ownership, hidden side effects (cron, webhooks, workers) and churn hotspots, committed as CODEBASE-MAP.md. NOT a deep audit of one module (that is analyze) or chasing one failure (that is debug).

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/recon-playbook.md`).

It sits in Development, covering Codebase onboarding, Webhooks and Scheduled and recurring tasks. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • You land in an unfamiliar
  • Inherited codebase and must get productive fast: a breadth-first map of entry points
  • Module ownership
  • Hidden side effects (cron

Example prompts

  • “/codebase-onboarding”

Requirements

  • A Bash shell

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Breadth before depth. First pass maps where things are, not how they work. You are drawing the subway map, not reading every passenger's…
  2. Hypothesis before answer. Spend ~5 minutes forming your own guess ("auth probably lives in src/middleware"), then grep to confirm or kill…

What it can do on your machine

Read from SKILL.md and the folder at commit e3d5b33. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • rg
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codebase Onboarding loads about 2.4k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 1,092 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit e3d5b33, republished under its MIT licence (© ericrisco). 1,092 words, ~2,371 tokens.

Download SKILL.mdSave it as .claude/skills/codebase-onboarding/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
codebase-onboarding
description
Use when you land in an unfamiliar or inherited codebase and must get productive fast: a breadth-first map of entry points, request flow, module ownership, hidden side effects (cron, webhooks, workers) and churn hotspots, committed as CODEBASE-MAP.md. NOT a deep audit of one module (that is `analyze`) or chasing one failure (that is `debug`).
tags
onboarding, codebase, code-mapping, legacy-code, architecture, reverse-engineering, hotspots
recommends
analyze, debug, decision-records, harness, init, knowledge-ops
origin
risco

Codebase onboarding — get oriented fast, leave a map

You have just landed in a codebase you did not write: a fresh clone, an inherited project, an acquired repo, an abandoned side project someone handed you. The instinct is to start reading files top-to-bottom. Resist it. That is how a week disappears and you still cannot answer "where does X happen". This skill runs a disciplined breadth-first reconnaissance pass and produces one durable artifact: a map a teammate can trust and you can re-read tomorrow.

The payoff is measured. Engineers using AI to onboard reach the same milestones roughly 2x faster — productive in 1–2 weeks instead of 4–6 — and the biggest gains are exactly in searching for code, decoding undocumented patterns, and tracing data flows (super-productivity.com, accessed 2026-06-02). That is what the recon pass below targets, in order.

Lead with the deliverable

Before you grep a single line, know the target: a single living file, CODEBASE-MAP.md, committed at the repo root. You work backward from its sections — every recon step fills one. Minimal schema:

markdown
# CODEBASE-MAP.md — <repo name>

## Stack          # languages, framework + versions, package manager, run scripts
## Entry points   # main / server bootstrap / route registration / CLI commands
## Request flow   # one real path traced transport -> business logic -> persistence
## Module ownership   # who owns transport / business logic / persistence / UI
## Hidden behavior    # cron, webhooks, queue workers, event listeners, env branches
## Hotspots       # most-churned + most-complex files = highest risk
## How to run     # the exact commands to boot it and hit one path locally

Why a file and not a chat answer: a map that lives only in the conversation dies when the session ends, and the next agent re-does the work. The artifact is the point. verify.sh checks these sections exist (structure, not content).

Two operating rules

  1. Breadth before depth. First pass maps where things are, not how they work. You are drawing the subway map, not reading every passenger's diary. Depth is analyze/debug work, on demand, later. — Reading everything is the failure mode onboarding exists to replace.
  2. Hypothesis before answer. Spend ~5 minutes forming your own guess ("auth probably lives in src/middleware"), then grep to confirm or kill it. — Verifying a hypothesis builds the mental model that makes you fast; a handed-to-you answer does not stick (martinfowler.com, Böckeler, accessed 2026-06-02).

The recon pass — ordered

Run these in order. Each step writes one map section. Stop escalating the moment the section is answerable.

a. Orient — read the manifest, size the repo. Read the manifest(s) and lockfile, not the README first: package.json / pyproject.toml / go.mod / Gemfile / pom.xml tell you the real stack, framework version and run scripts; the lockfile tells you what is actually installed. Then size it:

bash
scc --by-file --sort lines .   # LOC, complexity, COCOMO estimate per file

scc (Sloc Cloc and Code, pure-Go, v3.7.0 Apr 2026) is the fast structural counter of record — materially faster than cloc/tokei and it reports per-file complexity, which you reuse for hotspots. Why manifest-first: the README describes intent (often stale); the manifest describes reality.

b. Find the entry points. Where does execution start? Look for main, the server bootstrap, route registration, CLI command definitions. Let the framework's convention guide you (Next.js app//pages/, Express app.use/router mounts, Django urls.py, FastAPI @app/APIRouter, Rails routes.rb, Spring @RestController). See references/recon-playbook.md for per-ecosystem patterns.

c. Trace one real request end-to-end. Pick a single meaningful path (a login, a checkout, the main CLI command) and follow it: transport (route/handler) → business logic → persistence → response. One path traced beats ten skimmed. This is the spine of the map.

d. Map module ownership. For the directories scc flagged as large, label each: transport, business logic, persistence, UI, shared/util. You are answering "if I need to change pricing, which folder do I open" — the question teammates actually ask.

e. Hunt hidden behavior. The bugs live in what runs without a request. Grep for cron schedules, webhook receivers, queue/background workers, event listeners and env-driven branches (see the appendix). Why this step is non-negotiable: side effects are invisible in a top-down read and they are where inherited codebases bite.

f. Rank hotspots. Git churn is the cheapest risk signal — no extra tooling, and high-churn files are a proxy for "lacks tests/abstraction":

bash
git log --format=format: --name-only --since=12.month \
  | grep -v '^$' | sort | uniq -c | sort -nr | head -50

The richer move is churn × complexity: the top-right quadrant (changes constantly and is hard to read) is your real danger zone (understandlegacycode.com Hotspots, accessed 2026-06-02). Escalate to that — or to a tree-sitter dependency graph — only when grep + churn is not enough: references/recon-playbook.md has the churn×complexity recipe (code-maat) and when codegraph PageRank / FileScopeMCP earn their setup cost.

g. Confirm hands-on. Run the app, walk one end-user journey, send a real request, watch the logs. Reading alone leaves the map unverified; a single real request validates the whole trace in step c.

Show full SKILL.md (398 more words)Show less

Scope the effort

Match the pass to the repo. Do not stand up heavy tooling on a small project.

Repo shapeMap fullySkip / deferEscalate to a graph tool?
Tiny (<20 files)a, b, c, gchurn, ownership tableNo — grep is faster than setup
Single-service appall a–g—Only if ownership is unclear after grep
Large monorepoa, b, then per-package c–fmapping every package at onceYes — codegraph PageRank to find the load-bearing packages
Polyglota, b, c per language boundaryone unified flow diagramYes, if cross-language calls obscure the flow

Command appendix

Language-tagged, copy-ready. Per-ecosystem depth lives in references/recon-playbook.md.

bash
# Size + complexity (reuse the complexity column for hotspots)
scc --by-file --sort complexity .

# Route registration (adjust per framework)
rg -n "app\.(get|post|put|delete|use)\(|@app\.(get|post)|APIRouter|router\.(get|post)" --type-add 'web:*.{js,ts,py}' -tweb

# Cron / scheduled jobs
rg -n "cron|schedule|@scheduled|setInterval|celery\.beat|node-cron" -i

# Webhook receivers
rg -n "webhook|/hooks/|stripe.*signature|x-hub-signature" -i

# Queue / background workers
rg -n "queue|worker|bull|sidekiq|celery|sqs|rabbitmq|kafka|@task" -i

# Env-driven branches (hidden config-conditional behavior)
rg -n "process\.env\.|os\.environ|ENV\[|getenv" 

Writing & maintaining the map

  • Commit it. CODEBASE-MAP.md at the repo root, in version control. A map outside the repo rots silently.
  • Keep it living. When the recon reveals you guessed wrong, fix the line — the map is the record of what is true now, not your first impression.
  • Link out, do not duplicate. The map says what is. For why a choice was made, write an ADR (../decision-records/SKILL.md). To scaffold project tooling and a wiki, that is ../harness/SKILL.md. To write the agent-memory CLAUDE.md, that is ../init/SKILL.md — onboarding is the broader recon that feeds it. For generic note/wiki capture, ../knowledge-ops/SKILL.md.
  • Hand off to depth tools. Once the map exists, a deep correctness/security read of one module is ../analyze/SKILL.md; chasing a specific failure through the system is ../debug/SKILL.md. Onboarding builds the map you debug with.

Anti-patterns

BadWhy it bitesGood
Read every file top-to-bottomBurns the week; you finish exhausted and still can't trace one requestBreadth-first: map locations first, depth on demand
Trust the README over the codeREADMEs drift; the manifest and the routes are the truthRead manifest + lockfile first, confirm by grep
Map everything at full depthAnalysis paralysis on a monorepo; you map dead modulesTrace one real flow end-to-end; expand only where needed
Skip the run stepAn unverified map is a hypothesis, not a mapBoot it, hit one path, watch logs before you trust the trace
Map lives only in chatDies with the session; next agent redoes itWrite & commit CODEBASE-MAP.md
Guess instead of grepConfident-wrong is worse than slow-rightForm the hypothesis, then rg to confirm or kill it
Stand up a tree-sitter MCP graph on a 5-file repoSetup costs more than the whole reconReserve graph tools for large monorepos; grep + churn first

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/codebase-onboarding of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/recon-playbook.md
  • scripts/verify.sh

Open the folder on GitHubat commit e3d5b33

Compare with similar skills

Codebase Onboarding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codebase Onboarding compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codebase Onboarding this skillericrisco/rsc-harness167—~2.4kAutomated safety check: PassMIT
Claude Code Clawdbotwin4r/claude-code-clawdbot-skill123—~2.5kAutomated safety check: WarnNone
Setup RoutinesYesterday-AI/paperclip-plugin-company-wizard184—~3.1kAutomated safety check: PassMIT
Workspace APIfriday-platform/friday-studio104—~9.3kAutomated safety check: NotesCustom licence
Neon Functionsneondatabase/agent-skills100—~12kAutomated safety check: NotesApache-2.0
Function Devbutterbase-ai/butterbase-skills534—~2.8kAutomated safety check: PassMIT

Similar skills

  • Claude Code Clawdbot

    win4r/claude-code-clawdbot-skill

    Run Claude Code (Anthropic) from this host via the claude CLI (Agent SDK) in headless mode (-p) for codebase analysis, refactors, test fixing, and structured output.

    123 GitHub stars~2.5k tokensUpdated 8 mo ago
    AI & LLM EngineeringAuto-check: warnings
  • Setup Routines

    Yesterday-AI/paperclip-plugin-company-wizard

    Analyze a Paperclip company's issue history, agent health, recurring failure patterns, and project architecture to design and provision tailored routines with cron/webhook triggers.

    184 GitHub stars~3.1k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Workspace API

    friday-platform/friday-studio

    Create, list, update, delete, and clean up workspaces via the daemon HTTP API at $FRIDAYDURL.

    104 GitHub stars~9.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Neon Functions

    neondatabase/agent-skills

    Official

    Long-running, serverless Node.js HTTP functions deployed onto your Neon branch, with DATABASEURL injected automatically and compute that runs next to your data.

    100 GitHub stars~12k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Function Dev

    butterbase-ai/butterbase-skills

    A skill your agent uses when developing, deploying, or debugging Butterbase serverless functions, or when the user needs to add backend logic like webhooks, scheduled jobs, or custom API endpoints

    534 GitHub stars~2.8k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Upstash Qstash

    davila7/claude-code-templates

    Upstash QStash expert for serverless message queues, scheduled jobs, and reliable HTTP-based task delivery without managing infrastructure.

    32k GitHub starsUsed in 5 repos~597 tokens
    Backend & APIsAuto-check passed

More from ericrisco/rsc-harness

All 227 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    167 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    167 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    167 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    167 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    167 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    167 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Questions about Codebase Onboarding

What does Codebase Onboarding do?

A skill your agent uses when you land in an unfamiliar or inherited codebase and must get productive fast: a breadth-first map of entry points, request flow, module ownership, hidden side effects…. Codebase Onboarding is an agent skill from ericrisco/rsc-harness.md.

When should I use Codebase Onboarding?

Codebase Onboarding fits situations like: you land in an unfamiliar; inherited codebase and must get productive fast: a breadth-first map of entry points; module ownership; hidden side effects (cron.

How do I install Codebase Onboarding in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill codebase-onboarding -a claude-code`. Or copy the skill folder (skills/codebase-onboarding in ericrisco/rsc-harness) into .claude/skills/codebase-onboarding in your project. Claude Code loads it when a task matches its description.

How do I install Codebase Onboarding in Codex?

Run `npx skills add ericrisco/rsc-harness --skill codebase-onboarding -a codex`. Or copy the skill folder (skills/codebase-onboarding in ericrisco/rsc-harness) into .agents/skills/codebase-onboarding in your project. Codex loads it when a task matches its description.

Can I use Codebase Onboarding in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill codebase-onboarding -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codebase-onboarding, .gemini/skills/codebase-onboarding, .github/skills/codebase-onboarding and .opencode/skills/codebase-onboarding in your project.

What does Codebase Onboarding need to run?

Going by SKILL.md and its folder, Codebase Onboarding needs a shell for the scripts in its folder and the command-line tools its instructions call (rg and git). Our summary lists: A Bash shell.

Does Codebase Onboarding access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codebase Onboarding safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Codebase Onboarding use?

Codebase Onboarding is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codebase Onboarding use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Codebase Onboarding?

Skills that share tags, products or a category with Codebase Onboarding: Claude Code Clawdbot (win4r/claude-code-clawdbot-skill, 123 stars), Setup Routines (Yesterday-AI/paperclip-plugin-company-wizard, 184 stars), Workspace API (friday-platform/friday-studio, 104 stars) and Neon Functions (neondatabase/agent-skills, 100 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codebase Onboarding?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 167 GitHub stars. The repository holds 227 skills in this directory. The repository was last updated on October 7, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.