Agent skill

Squid Architecture Review

by iusztinpaul in iusztinpaul/squid

Periodic architectural sweep — reads existing ADRs, maps modules/dependencies/layering, and reports up to 10 prioritised findings shaped as refactor proposals /squid-refactor can consume directly.

Apache-2.0Auto-check passedDevelopment

Install Squid Architecture Review

skills CLI
$ npx skills add iusztinpaul/squid --skill squid-architecture-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install iusztinpaul/squid squid-architecture-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/iusztinpaul/squid.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/squid-architecture-review .claude/skills/squid-architecture-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
squid-architecture-review
GitHub stars
203
Token cost
~2.6k tokens
SKILL.md length
817 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0

At a glance

Periodic architectural sweep — reads existing ADRs, maps modules/dependencies/layering, and reports up to 10 prioritised findings shaped as refactor proposals /squid-refactor can consume directly.

  • Works in 7 steps: Frame the scope → Read prior decisions → Map the current architecture → …
  • Tasks that involve Software architecture
  • SKILL.md covers When NOT to use, Step 1 — Frame the scope, Step 2 — Read prior decisions and Step 3 — Map the current…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Squid Architecture Review is an agent skill from iusztinpaul/squid. Periodic architectural sweep — reads existing ADRs, maps modules/dependencies/layering, and reports up to 10 prioritised findings shaped as refactor proposals /squid-refactor can consume directly.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Software architecture, Architecture decision records and Refactoring. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Software architecture
  • Tasks that involve Architecture decision records
  • Tasks that involve Refactoring

Example prompts

  • “/squid-architecture-review”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Frame the scope
  2. Read prior decisions
  3. Map the current architecture
  4. Identify smells
  5. Score and prioritise
  6. Write the report
  7. Hand off

What it can do on your machine

Read from SKILL.md and the folder at commit f5bf6b3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Squid Architecture Review loads about 2.6k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 817 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from iusztinpaul/squid at commit f5bf6b3, republished under its Apache-2.0 licence (© iusztinpaul). 817 words, ~2,576 tokens.

Download SKILL.mdSave it as .claude/skills/squid-architecture-review/SKILL.md (or your agent's skills folder).
name
squid-architecture-review
description
Periodic architectural sweep — reads existing ADRs, maps modules/dependencies/layering, and reports up to 10 prioritised findings shaped as refactor proposals `/squid-refactor` can consume directly.
disable-model-invocation
true
argument-hint
[scope-path or component name; default = whole repo]

Architecture review — periodic structural audit

The team's day-to-day pipeline (/squid-implement-task, /squid-implement-night) operates at task grain. Long-horizon codebase health — drift, unintended coupling, dead modules, layering violations — accumulates between tasks and never gets addressed unless someone deliberately looks. This skill is that deliberate look.

The output is not a single PR. It's a prioritised backlog of refactor proposals, each shaped so /squid-refactor can pick one up and turn it into a Tasks Plan.

You are the auditor — you delegate exploration to sub-agents, you read the target repo's docs/adr/ to avoid re-proposing settled questions, and you produce a written report. You do NOT write code, do NOT start refactors, and do NOT decide priority for the team — you propose, the human prioritises.

$ARGUMENTS:

  • Empty → audit the whole repo.
  • A path (packages/backend/) → audit only that subtree.
  • A component name (backend, frontend-web) → audit only that component.

When NOT to use

  • During active feature delivery — review when the team has bandwidth to act on findings, not as theatre.
  • On a codebase < 6 months old. There isn't yet enough crystallised pattern to review against.
  • When the team has clear architectural anxieties already named — go straight to /squid-refactor with the named target.
  • As a substitute for code review on a specific PR — open or update the PR with gh and review it there instead.
  • On infra-only repos (Terraform, CI tooling). The shape doesn't fit; this skill assumes application code with modules, layers, dependencies.

Step 1 — Frame the scope

Resolve $ARGUMENTS. If empty, ask the user one question via AskUserQuestion:

Whole repo, one component, or a specific subtree?

Echo the resolved scope back as a one-line confirmation. Don't block.

Step 2 — Read prior decisions

Read the repo's docs/adr/ end-to-end if it exists. Build a mental model of:

  • What decisions are Accepted and still in force.
  • What decisions are Superseded (and by what).
  • What constraints (technical, business, team-shape) the ADRs cite.

Never re-propose what an ADR already settled. If ADRs don't exist, the hand-off's ADR action (Step 7) says so.

Also read, if present:

  • docs/glossary.md (spec: squid-scaffold/specs/ubiquitous-language.md) — to know whether the team already names concepts consistently.
  • The root CLAUDE.md and any per-component CLAUDE.md — for stated rules.

Step 3 — Map the current architecture

Spawn 2–3 Explore agents in parallel:

Agent(
  subagent_type="Explore",
  prompt="""Architecture mapping pass on {scope}.

  Produce four artefacts:
  (1) Module / package list with one-line responsibility per module (file:line for the canonical entry point).
  (2) Dependency graph — who imports whom. Flag any cycles. Flag any "junk drawer" modules imported by everyone.
  (3) Layering — name the de-facto layers (e.g., handlers → services → repositories → models) and list any layer-skipping imports.
  (4) Public surface — what's exported / consumed by other components or external callers. Mark anything intended-internal that's leaked.

  Be exhaustive on the dependency graph; missing an edge produces a wrong recommendation. Report as four sections."""
)

Agent(
  subagent_type="Explore",
  prompt="""Hot-spot scan on {scope}.

  Find:
  (1) Files with > 500 lines.
  (2) Files / modules touched by > 30% of commits in the last 6 months — `git log --since='6 months ago' --name-only | sort | uniq -c | sort -rn | head -20`.
  (3) Tests with > 100 setup lines or > 5 fixtures — usually a smell that the system-under-test is too coupled.
  (4) `# TODO` / `# FIXME` / `# HACK` markers — count and cluster.
  (5) Any `# type: ignore` / `eslint-disable` / `nolint` clusters — places where the team is fighting their own static analysis.

  Report as five sections with file:line."""
)

When agents return, read the top-3 most-implicated files yourself. Don't rely on summaries on the load-bearing modules — you need firsthand familiarity to call findings credibly.

Show full SKILL.md (424 more words)Show less

Step 4 — Identify smells

Walk these dimensions. For each, form 0 or more findings. Don't manufacture findings to pad the report — empty dimensions are fine and signal health; say so explicitly in the report ("Layer violations: none observed").

DimensionWhat to look for
CyclesImport cycles between modules / packages. Always a smell.
Layer violationsLower layers (e.g., models) importing higher layers (e.g., HTTP handlers).
God modulesOne module that everything imports; usually means responsibilities accreted.
Junk drawersutils/, common/, helpers/ modules with > 10 unrelated functions.
Hidden couplingTwo modules that should be independent but share a hidden contract (a shape, a magic string, an env var).
Test smellsHigh setup-to-assert ratio; brittle tests on private internals; flaky tests. Usually rooted in a structural problem in the SUT.
API leakageInternal types reaching public surface; public surface that should be private (e.g., a route that no caller uses).
Dead codeUnused exports, unreachable branches, modules with zero importers.
Over-engineeringAbstraction the code doesn't earn: a single-implementation interface / factory / wrapper that only forwards, a layer with one caller, config nobody sets, hand-rolled logic the stdlib ships, or a dependency duplicating a platform/framework feature. Tag each with the same delete/stdlib/native/yagni/shrink vocabulary the PR-Reviewer uses (Dimension F).
Drift from CLAUDE.mdStated rules the codebase no longer follows. The rule is right; the code drifted.
ADR driftDecisions ADRs describe that the code no longer reflects (silently superseded). Either update the ADR or fix the code.
Performance shapeSync I/O in async handlers; N+1 patterns; in-memory aggregation that should be a query.
Observability gapsCritical paths without logs / metrics / traces; logs that don't include correlation IDs.

Step 5 — Score and prioritise

For each finding, assign:

  • Severity: S1 (active risk — security, data loss, ongoing pain) / S2 (significant friction) / S3 (technical debt without acute symptom) / S4 (cosmetic, defer).
  • Effort: S (small, ≤ half a day) / M (medium, 1–3 days) / L (large, > 3 days; probably needs to split).
  • Confidence: High (you've read the code yourself) / Medium (one sub-agent finding, you spot-checked) / Low (sub-agent finding, you haven't verified).

Prioritise by severity / effort ratio, with confidence as a tiebreaker — a High-confidence S2 beats a Low-confidence S1; don't recommend a refactor on a finding you haven't personally read. Do not propose more than 10 findings. Cluster related findings into one if they share a root cause.

Step 6 — Write the report

Path:

  • File mode: docs/architecture-review-{YYYY-MM-DD}.md (a report, not a task — it doesn't enter tasks/; each accepted finding becomes a task via /squid-refactor).
  • gh mode: a single issue, label squid-architecture-review.

Template:

markdown
# Architecture review — {scope}, {YYYY-MM-DD}

**Scope:** {whole repo / component / path}
**ADRs read:** {N} ({list, e.g. "0001–0007"})
**Findings:** {N total — by severity: S1×N, S2×N, S3×N, S4×N}

## Summary

{2–3 sentences. The headline shape: "Three module cycles between auth/ and core/, all introduced in the last 4 months, blocking the planned auth-extraction work. Tests on the affected modules have grown 2× in setup size. No ADR governs the boundary. Recommend ADR + extraction refactor."}

## Findings

### F1 — {one-line title} (S{1–4}, effort: {S/M/L}, confidence: {H/M/L})

**Where:** `path/to/a.py:42`, `path/to/b.py:117`

**Symptom:** {what is concretely wrong, observable}

**Root cause hypothesis:** {your best read on why}

**Proposed refactor:** {one paragraph; the shape of the fix, not the fix itself}

**ADR exposure:** {does an ADR govern this? if yes, cite. If no, an ADR should accompany the refactor.}

**Out of scope (explicit):** {what this finding is NOT recommending}

### F2 — ...

(Repeat for each finding, top to bottom by priority.)

## Not recommended

{Smells you found but are deliberately NOT proposing. State why — e.g., "F-skip-1: The `utils/strings.py` module has 12 unrelated functions and looks like a junk drawer. Skipping because every function is < 10 lines and the cost of splitting exceeds the reading cost."}

## Pre-existing decisions (from ADRs) you should NOT undo

{One-bullet-each summary of ADRs that explain *why* something looks weird but is intentional. This protects the next reader from re-litigating.}

## Suggested order of operations

1. F{best-first} — {why it goes first}
2. F{next} — {why}
...

Pick up a finding with `/squid-refactor F{N}`; run the top 1–3 first, not all at once.

Step 7 — Hand off

Single block:

markdown
## Architecture review complete — {scope}

**Report:** {path or issue URL}
**Findings:** {N} ({severity breakdown})
**Top recommendation:** F1 — {title}

### Recommended next step

`/squid-refactor F1` (or paste the F1 body into a fresh `/squid-refactor` invocation). The first finding is the highest leverage by severity-over-effort.

### Open question (if applicable)

{Anything you found but couldn't conclude on without team input — e.g., "F4 hinges on whether the auth/billing boundary should be a hard-coded contract or a feature-flag-toggled split. Surfacing for team decision before refactoring."}

### ADR action

{One of:}
- "Recommend ADR-{NNNN} to record the resolution of F{X} when its refactor lands."
- "No ADRs in `docs/adr/` — recommend bootstrapping with the `adr` spec (`squid-scaffold/specs/adr.md`) before proceeding so this review's findings stay durable."

© iusztinpaul, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/squid-architecture-review of iusztinpaul/squid.

Open the folder on GitHubat commit f5bf6b3

Compare with similar skills

Squid Architecture Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Squid Architecture Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Squid Architecture Review this skilliusztinpaul/squid203—~2.6kAutomated safety check: PassApache-2.0
Improve Codebase Architectureywwynm/EverythingDone14415 repos~1.3kAutomated safety check: PassGPL-3.0
Architecture PatternsKartikLabhshetwar/better-shot2.4k2 repos~1.4kAutomated safety check: PassCustom licence
Learning OpportunitiesDrCatHicks/learning-opportunities2.5k—~2.5kAutomated safety check: PassCC-BY-4.0
Create Vibe Featuremistralai/mistral-vibe5.1k—~1.4kAutomated safety check: PassApache-2.0
Task Workflowikarenkov/Modo343—~2.4kAutomated safety check: PassNone

Similar skills

  • Improve Codebase Architecture

    ywwynm/EverythingDone

    Find deepening opportunities in a codebase, informed by the domain language in CONTEXT.md and the decisions in docs/adr/.

    144 GitHub starsUsed in 15 repos~1.3k tokens
    DevelopmentAuto-check passed
  • Architecture Patterns

    KartikLabhshetwar/better-shot

    Deep dive into software architecture for macOS. An agent skill from KartikLabhshetwar/better-shot.

    2.4k GitHub starsUsed in 2 repos~1.4k tokens
    DevelopmentAuto-check passed
  • Learning Opportunities

    DrCatHicks/learning-opportunities

    Facilitates deliberate skill development during AI-assisted coding.

    2.5k GitHub stars~2.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Create Vibe Feature

    mistralai/mistral-vibe

    Official

    Guides feature work in the Mistral Vibe Python CLI so each change lands in the right module and matches the project's architecture decision records.

    5.1k GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Task Workflow

    ikarenkov/Modo

    Spec-driven workflow for non-trivial work. An agent skill from ikarenkov/Modo.

    343 GitHub stars~2.4k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Brooks Audit

    hyhmrright/brooks-lint

    Architecture audit that maps module dependencies, checks layering integrity, and flags structural decay across a codebase, drawing on twelve classic engineering books.

    1.5k GitHub starsUsed in 1 repo~537 tokens
    DevelopmentAuto-check passed

More from iusztinpaul/squid

All 13 skills in this repo
  • Squid Implement Night

    iusztinpaul/squid

    Run the full agent-team pipeline end-to-end for one feature whose Tasks Plan is already approved by /squid-plan, handing the human a validated, ready-to-squash-merge PR.

    203 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Squid Implement Task

    iusztinpaul/squid

    Implement one task — or a whole list / an approved Tasks Plan — via the inner SWE↔Tester loop, committing each task on PASS.

    203 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Squid Review

    iusztinpaul/squid

    Push the committed feature branch, create or update its PR, then run Product Architect acceptance and PR-Reviewer on it.

    203 GitHub stars~873 tokensUpdated 1 mo ago
    Auto-check passed
  • Squid Review CI

    iusztinpaul/squid

    Drive CI green on a pushed, review-clean feature PR — On-Call diagnoses failures and hands fix tasks to the SWE.

    203 GitHub stars~607 tokensUpdated 1 mo ago
    Auto-check passed
  • Squid Testing Python

    iusztinpaul/squid

    Write and evaluate effective Python tests using pytest. An agent skill from iusztinpaul/squid.

    203 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Squid Clean Harness

    iusztinpaul/squid

    Shrink an agent harness (.agents/ skills + resources) to the minimum tokens that keep the exact same logic.

    203 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Squid Architecture Review

What does Squid Architecture Review do?

Periodic architectural sweep — reads existing ADRs, maps modules/dependencies/layering, and reports up to 10 prioritised findings shaped as refactor proposals /squid-refactor can consume directly. Squid Architecture Review is an agent skill from iusztinpaul/squid. Periodic architectural sweep — reads existing ADRs, maps modules/dependencies/layering, and reports up to 10 prioritised findings shaped as refactor proposals /squid-refactor can consume directly.

When should I use Squid Architecture Review?

Squid Architecture Review fits situations like: tasks that involve Software architecture; tasks that involve Architecture decision records; tasks that involve Refactoring.

How do I install Squid Architecture Review in Claude Code?

Run `npx skills add iusztinpaul/squid --skill squid-architecture-review -a claude-code`. Or copy the skill folder (skills/squid-architecture-review in iusztinpaul/squid) into .claude/skills/squid-architecture-review in your project. Claude Code loads it when a task matches its description.

How do I install Squid Architecture Review in Codex?

Run `npx skills add iusztinpaul/squid --skill squid-architecture-review -a codex`. Or copy the skill folder (skills/squid-architecture-review in iusztinpaul/squid) into .agents/skills/squid-architecture-review in your project. Codex loads it when a task matches its description.

Can I use Squid Architecture Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add iusztinpaul/squid --skill squid-architecture-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/squid-architecture-review, .gemini/skills/squid-architecture-review, .github/skills/squid-architecture-review and .opencode/skills/squid-architecture-review in your project.

What does Squid Architecture Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Squid Architecture Review is instructions for the agent only.

Does Squid Architecture Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Squid Architecture Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Squid Architecture Review use?

Squid Architecture Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Squid Architecture Review use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Squid Architecture Review?

Skills that share tags, products or a category with Squid Architecture Review: Improve Codebase Architecture (ywwynm/EverythingDone, 144 stars), Architecture Patterns (KartikLabhshetwar/better-shot, 2.4k stars), Learning Opportunities (DrCatHicks/learning-opportunities, 2.5k stars) and Create Vibe Feature (mistralai/mistral-vibe, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Squid Architecture Review?

iusztinpaul (a GitHub user) maintains it in iusztinpaul/squid, which has 203 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on September 3, 2026.

Source: iusztinpaul/squid on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.