Agent skill

Hotspots

by lexler in lexler/skill-factory

Find where a codebase actually costs time by mining its git history (Tornhill hotspot analysis).

Apache-2.0Auto-check passedDevelopment

Install Hotspots

skills CLI
$ npx skills add lexler/skill-factory --skill hotspots -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install lexler/skill-factory hotspots --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/lexler/skill-factory.git skills-src && mkdir -p .claude/skills && cp -r skills-src/output_skills/practices/hotspots .claude/skills/hotspots && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hotspots
GitHub stars
239
Token cost
~1.2k tokens
SKILL.md length
608 words
Files
5 (incl. scripts, references)
Skills in repo
25
Repo updated
First seen
Licence
Apache-2.0

At a glance

Find where a codebase actually costs time by mining its git history (Tornhill hotspot analysis).

  • Works in 5 steps: SCOPE → MINE → VALIDATE → …
  • Tasks that involve Refactoring
  • SKILL.md covers 1. SCOPE, 2. MINE, 3. VALIDATE and 4. DEEPEN, plus 3 more sections
  • Runs Python scripts from its folder; calls uv and git

What it does

Hotspots is an agent skill from lexler/skill-factory. Find where a codebase actually costs time by mining its git history (Tornhill hotspot analysis). Produces ranked refactoring targets with evidence, change-coupling seams, and a do-not-refactor list; re-run after refactoring to verify it paid off.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/interpretation.md`, `scripts/coupling.py` and `scripts/gitlog.py`).

It sits in Development, covering Refactoring and Git workflow. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Refactoring
  • Tasks that involve Git workflow

Example prompts

  • “/hotspots”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. SCOPE
  2. MINE
  3. VALIDATE
  4. DEEPEN
  5. REPORT

What it can do on your machine

Read from SKILL.md and the folder at commit 8017333. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • uv
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hotspots loads about 1.2k tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 608 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from lexler/skill-factory at commit 8017333, republished under its Apache-2.0 licence (© lexler). 608 words, ~1,206 tokens.

Download SKILL.mdSave it as .claude/skills/hotspots/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
hotspots
description
Find where a codebase actually costs time by mining its git history (Tornhill hotspot analysis). Produces ranked refactoring targets with evidence, change-coupling seams, and a do-not-refactor list; re-run after refactoring to verify it paid off.
disable-model-invocation
true

STARTER_CHARACTER = 🔥

Hotspot analysis ranks files by change frequency × complexity. Code that is both complicated and changed often is where refactoring pays; complicated but stable code is not — "if it never changes, it's not costing us money." The scripts compute every number deterministically; your job is scoping, validation, and interpretation. A hotspot is a pointer to where to look, never a diagnosis.

If the user wants to check whether a past refactoring paid off and hotspots/data/mine.json exists in the repo, jump to VERIFY. Otherwise run the steps in order.

1. SCOPE

Decide and record:

  • Window: default 12 months; use "since last major release" if the user names one. Under ~6 months of history, warn that rankings are unreliable.
  • Target: repo root, or the subtree the user cares about in a monorepo.
  • Extra excludes: skim the tree for generated/vendored content the defaults miss (see default list in scripts/mine.py). Keep test files in — a test file as top hotspot is a real and common finding.
  • History quality: if most commits are PR squashes, note that coupling signal is weakened.

Done when window, target, and extra excludes are chosen and any history caveats are noted for the report header.

2. MINE

bash
uv run ${CLAUDE_SKILL_DIR}/scripts/mine.py <repo> --months <N> [--exclude PATTERN]... --out hotspots/data/mine.json
uv run ${CLAUDE_SKILL_DIR}/scripts/coupling.py <repo> --months <N> [--exclude PATTERN]... --out hotspots/data/coupling.json

Pass the same --months and --exclude flags to both. If summary.warnings reports too few commits or nothing ranked, widen the window or lower --min-revs and re-run.

Done when both JSON files exist and files_ranked > 0.

3. VALIDATE

Take the top ~10 files by score from mine.json. Read each one and give a verdict — confirmed hotspot, or discarded with the false-positive class it belongs to (catalog in references/interpretation.md). When discards free up slots, pull in the next candidates so ~10 get verdicts.

Done when every candidate has a verdict and one-line reason.

4. DEEPEN

For each confirmed hotspot:

  • X-ray: find the hot functions inside the file. Read it, then check which regions keep changing: git log --since=<window> -p -- <file> (or git log -L :<function>:<file> for a suspect function).
  • Seams: pull the file's partners from coupling.json. A test↔code pair is normal; coupling across module boundaries is an architecture finding worth naming.

Done when every confirmed hotspot has internal target functions and its coupling partners (or "none above thresholds").

Show full SKILL.md (245 more words)Show less

5. REPORT

Write hotspots/report.md:

  • Header: repo, window, excludes, params, history caveats.
  • Refactoring targets, ranked: per file — the numbers (commits, churn, authors, LOC, indentation), the evidence in one or two sentences, hot functions, coupling seams.
  • Do-not-refactor: stable_complex entries plus stable-complex quadrant files — complex but quiet; touching them is risk without payoff.
  • Discarded candidates with reasons.
  • Method footnote: score = change-frequency percentile × size percentile; thresholds used; pointer to hotspots/data/ as the verify baseline.

Keep the two JSONs — they are the baseline VERIFY compares against. Done when the report answers "what to refactor first, why, and what to leave alone" without opening the JSONs. Offer the top target to the refactoring workflow the user normally uses.

VERIFY (after a refactoring)

  1. Read params from hotspots/data/mine.json and re-run both scripts with the same flags to fresh files (e.g. hotspots/data/mine-after.json).
  2. For each refactored file, compare raw complexity against the baseline: LOC, indent_total, indent_mean, indent_sd. Falling numbers mean the refactoring paid off structurally; scores and ranks are percentile-relative, so never compare those across runs. A split file counts as improved when the successor files are each simpler than the original.
  3. Append a dated "Verification" section to hotspots/report.md with a per-file verdict — improved / unchanged / worse — and the numbers behind it, then replace the baseline JSONs with the fresh ones.

Done when every refactored file has a verdict backed by before/after numbers.

Reference

references/interpretation.md — read during VALIDATE and when writing the report: quadrant meanings, the false-positive catalog, metric caveats, and threshold tuning.

© lexler, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in output_skills/practices/hotspots of lexler/skill-factory.

  • SKILL.md
  • references/interpretation.md
  • scripts/coupling.py
  • scripts/gitlog.py
  • scripts/mine.py

Open the folder on GitHubat commit 8017333

Compare with similar skills

Hotspots next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hotspots compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hotspots this skilllexler/skill-factory239—~1.2kAutomated safety check: PassApache-2.0
Merge Masterkeybase/client9.3k—~1.3kAutomated safety check: PassBSD-3-Clause
Docs Update from DiffQwenLM/qwen-code28k—~1.1kAutomated safety check: PassApache-2.0
Generate Snapshotmicrosoft/vscode-python-environments141—~1.1kAutomated safety check: PassMIT
Refactor Command To Commandlineresultruby-git/ruby-git1.8k—~1.3kAutomated safety check: PassMIT
Nemo Rl Auto ResearchNVIDIA/skills3.5k—~2.3kAutomated safety check: PassApache-2.0

Similar skills

  • Merge Master

    keybase/client

    A skill your agent uses when periodically merging upstream master commits into a long-running refactor branch where code has moved, been renamed, or restructured — guiding careful per-commit…

    9.3k GitHub stars~1.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Docs Update from Diff

    QwenLM/qwen-code

    Reads local git changes and updates only the matching docs pages, so documentation stays in sync with uncommitted or recent code changes.

    28k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Generate Snapshot

    microsoft/vscode-python-environments

    Official

    Generate a codebase health snapshot for technical debt tracking and planning.

    141 GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Migrates a command class that still performs parsing or custom execution logic to return raw Git::CommandLine::Result, moving parsing to facade/parser layers.

    1.8k GitHub stars~1.3k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Official

    Autonomous NeMo-RL research agent workflow for directed hypothesis testing and open-ended discovery.

    3.5k GitHub stars~2.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Change Boot

    tikalk/adlc-team-skills

    A skill your agent uses when past-change rationale matters (refactoring unfamiliar code, revert or hotfix analysis, issue-linked commit archaeology, session authors git changes with human-authored…

    141 GitHub stars~1.8k tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from lexler/skill-factory

All 25 skills in this repo
  • C4 Architecture Diagrams

    lexler/skill-factory

    Creates C4 model diagrams at every zoom level, from system landscape to code, in ASCII, Mermaid or Structurizr, for designing or documenting software architecture.

    239 GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Launching Agent Teams

    lexler/skill-factory

    Plans and launches Claude Code agent teams with distinct roles, right-sized tasks and detailed spawn prompts, and says when subagents or worktrees fit better.

    239 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Claude Code Statusline Writer

    lexler/skill-factory

    Guides writing and debugging Claude Code status line scripts that read session JSON from stdin and print one line of text.

    239 GitHub stars~872 tokensUpdated 1 mo ago
    Auto-check passed
  • Catalog of obstacles, anti-patterns and patterns for working with AI coding agents, covering context management and reliability, from a published patterns collection.

    239 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Approval Testing Toolkit

    lexler/skill-factory

    Writes snapshot-style approval tests in Python, JavaScript, TypeScript or Java, comparing output against an approved file instead of writing individual assertions.

    239 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Nullables Testing Pattern

    lexler/skill-factory

    Teaches the Nullables pattern for testing without mocking libraries: production classes with an off switch, stubbed only at the third-party edge.

    239 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Hotspots

What does Hotspots do?

Find where a codebase actually costs time by mining its git history (Tornhill hotspot analysis). Hotspots is an agent skill from lexler/skill-factory. Find where a codebase actually costs time by mining its git history (Tornhill hotspot analysis).

When should I use Hotspots?

Hotspots fits situations like: tasks that involve Refactoring; tasks that involve Git workflow.

How do I install Hotspots in Claude Code?

Run `npx skills add lexler/skill-factory --skill hotspots -a claude-code`. Or copy the skill folder (output_skills/practices/hotspots in lexler/skill-factory) into .claude/skills/hotspots in your project. Claude Code loads it when a task matches its description.

How do I install Hotspots in Codex?

Run `npx skills add lexler/skill-factory --skill hotspots -a codex`. Or copy the skill folder (output_skills/practices/hotspots in lexler/skill-factory) into .agents/skills/hotspots in your project. Codex loads it when a task matches its description.

Can I use Hotspots in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lexler/skill-factory --skill hotspots -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hotspots, .gemini/skills/hotspots, .github/skills/hotspots and .opencode/skills/hotspots in your project.

What does Hotspots need to run?

Going by SKILL.md and its folder, Hotspots needs Python for the scripts in its folder and the command-line tools its instructions call (uv and git). Our summary lists: Python 3.

Does Hotspots access the network?

SKILL.md contains no URLs. Its commands use uv and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Hotspots safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Hotspots use?

Hotspots is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hotspots use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 923 tokens, read only when the agent opens those files.

What are the alternatives to Hotspots?

Skills that share tags, products or a category with Hotspots: Merge Master (keybase/client, 9.3k stars), Docs Update from Diff (QwenLM/qwen-code, 28k stars), Generate Snapshot (microsoft/vscode-python-environments, 141 stars) and Refactor Command To Commandlineresult (ruby-git/ruby-git, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hotspots?

lexler (a GitHub user) maintains it in lexler/skill-factory, which has 239 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on August 26, 2026.

Source: lexler/skill-factory on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.