Astro Code Review
withastro/astro
Perform a static, read-only code review of an Astro pull request or of a local branch, commit range, diff, patch, or working tree being prepared as a pull request.
Audit a stale, inherited, or messy codebase — deps, bugs, security, tests, CI, docs, UI/UX — then emit a phased, testable modernization plan.
$ npx skills add luongnv89/skills --skill codebase-modernizer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install luongnv89/skills codebase-modernizer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codebase-modernizer .claude/skills/codebase-modernizer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codebase-modernizer" agent skill from https://github.com/luongnv89/skills/tree/main/skills/codebase-modernizer into .claude/skills/codebase-modernizer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-modernizer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/luongnv89/skills/tree/main/skills/codebase-modernizerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add luongnv89/skills --skill codebase-modernizer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install luongnv89/skills codebase-modernizer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/codebase-modernizer .agents/skills/codebase-modernizer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codebase-modernizer" agent skill from https://github.com/luongnv89/skills/tree/main/skills/codebase-modernizer into .agents/skills/codebase-modernizer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-modernizer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add luongnv89/skills --skill codebase-modernizer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install luongnv89/skills codebase-modernizer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/codebase-modernizer .cursor/skills/codebase-modernizer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codebase-modernizer" agent skill from https://github.com/luongnv89/skills/tree/main/skills/codebase-modernizer into .cursor/skills/codebase-modernizer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-modernizer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/luongnv89/skills.git --path skills/codebase-modernizer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add luongnv89/skills --skill codebase-modernizer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install luongnv89/skills codebase-modernizer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/codebase-modernizer .gemini/skills/codebase-modernizer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codebase-modernizer" agent skill from https://github.com/luongnv89/skills/tree/main/skills/codebase-modernizer into .gemini/skills/codebase-modernizer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-modernizer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install luongnv89/skills codebase-modernizerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add luongnv89/skills --skill codebase-modernizer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/codebase-modernizer .github/skills/codebase-modernizer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codebase-modernizer" agent skill from https://github.com/luongnv89/skills/tree/main/skills/codebase-modernizer into .github/skills/codebase-modernizer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-modernizer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add luongnv89/skills --skill codebase-modernizer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install luongnv89/skills codebase-modernizer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/codebase-modernizer .opencode/skills/codebase-modernizer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codebase-modernizer" agent skill from https://github.com/luongnv89/skills/tree/main/skills/codebase-modernizer into .opencode/skills/codebase-modernizer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-modernizer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codebase-modernizerAudit a stale, inherited, or messy codebase — deps, bugs, security, tests, CI, docs, UI/UX — then emit a phased, testable modernization plan.
Codebase Modernizer is an agent skill from luongnv89/skills. Audit a stale, inherited, or messy codebase — deps, bugs, security, tests, CI, docs, UI/UX — then emit a phased, testable modernization plan. Read-only: plans upgrades, never applies them. Not for single-PR review, PRD-to-tasks, or UX-only audits.
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 22 other files, including scripts and reference files (for example `agents/dependency-auditor.md`, `agents/dimension-auditor.md` and `agents/plan-architect.md`).
It sits in Development, covering Legacy modernization, Pull requests and UI design. It works with Git. The repository describes itself as: Supercharge your AI agents/bots with reusable skills. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8f80262. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
gitnpmcargopoetryFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Codebase Modernizer loads about 5k tokens when it runs, and up to ~21k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 2,474 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from luongnv89/skills at commit 8f80262, republished under its MIT licence (© luongnv89). 2,474 words, ~4,997 tokens.
.claude/skills/codebase-modernizer/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.For a codebase you are returning to after a long gap, or one that has drifted through many unoptimized changes. It audits every applicable dimension, then converts the findings into a phased, sprint-sized, testable plan for a better, up-to-date version.
Produces exactly two files in the target repo root:
| File | Contents |
|---|---|
MODERNIZATION_REPORT.md | Baseline evidence + every finding, severity-ranked, each citing path:line |
MODERNIZATION_PLAN.md | Phases → sprints → tasks → milestones, every task closing named findings |
This skill never modifies source code, dependencies, lockfiles, or configuration — no tracked
file's content changes. On a clean tree that is git diff --stat empty. On a stale, already-dirty
tree, git status --porcelain and git diff after the run must match a snapshot taken before it
(declared artifacts set aside). Beyond the two reports, only two kinds of new file may appear,
both enumerated in the report's Artifacts section: a declared delegate artifact
(CODE_REVIEW.md, from code-review mode review) and probe byproducts (build dirs such as
obj/, .dart_tool/, target/, .gradle/). Nothing else.
npm update, ncu -u,
cargo update, poetry update, or any equivalent. A blind bulk upgrade on a stale tree produces a
broken build and an unreviewable diff, which is exactly what the plan exists to prevent.CLAUDE.md, AGENTS.md) are planned via /agent-config create or
/agent-config update in the plan's Pre step — never created or rewritten during the audit.This skill invokes the two skills declared in frontmatter dependencies: code-review (modes
review and perf, for BUG and PERF) and dont-make-me-think (UX). Run this before Phase 0,
the first phase that probes anything. Discovery acquires nothing:
if command -v asm >/dev/null && asm deps --help >/dev/null 2>&1; then
asm deps discover codebase-modernizer --json || echo "discover failed; acquire at first use" >&2
printf 'cm_session=%s\n' "codebase-modernizer-$(date +%s)-$$" # record it; reuse it verbatim
else
echo "asm deps unavailable: npm install -g agent-skill-manager@latest" >&2
fiasm deps unavailable, record every delegated dimension Not Assessed —
skill unavailable, skip steps 2–5, and continue.BUG or PERF, run
asm deps acquire code-review --session <cm_session> --json. When it first reaches UX, run the
same command for dont-make-me-think. Never acquire for a dimension that is Not Assessed.skillMdPath to the dimension worker as
delegate_skill_md. Read that path directly.references/delegation-policy.md
(Missing dependency). Record Not Assessed — skill unavailable for BUG and PERF
(code-review) or UX (dont-make-me-think), continue, and name it in Limitations. A missing
dependency is fail-soft, not fatal.finally. If any acquire ran, run
asm deps release --session <cm_session> --json once at every terminal outcome (after Phase 5,
on a stop, or on an error), before the final report. Put a failed release under Uncertainty:.Lease-owned copies live outside the target repo, so they are not target artifacts. The six inline dimensions name their skill in a plan task and never invoke it, so they need no dependency entry.
Used throughout this skill and its references with these exact meanings:
F-<DIM>-<NNN>, e.g.
F-DEP-003). The report lists them; the plan's tasks close them by ID.Default: do not sync. This skill merges nothing and commits nothing — it writes two untracked
report files. Rebasing mid-audit can pull in a year of upstream commits, invalidating every
path:line citation and the recorded SHA. Audit the tree as you found it.
Sync only when the user asks for the reports committed or pushed. Then sync at the start of
Phase 3, after the audit is recorded. Because HEAD moves, re-record the commit SHA and re-verify
every citation. If any citation no longer resolves, stop with Result: BLOCKED — audit stale after sync and re-run the audit.
When syncing, sync the current branch with remote — stash first if the tree is not clean:
git stash push -u -m "pre-sync" # only when `git status --porcelain` is non-empty
branch="$(git rev-parse --abbrev-ref HEAD)"
git fetch origin && git pull --rebase origin "$branch"
git stash pop # only if you stashedIf origin is missing, pull is unavailable, or rebase/stash conflicts occur, stop and ask the user
before continuing. A dirty tree is common on a neglected repo — never discard uncommitted work.
Resolve all nine branches in references/scope-detection.md before Phase 0. Each is a real
branch in the workflow, not a preference. Check these two first, because they change what is
obtainable at all:
If a branch was not checked, take its restrictive side.
The finding-generators already exist. This skill's own contribution is dependency and runtime currency, the baseline gate, and the audit → plan bridge. Everything else is delegated.
| Dim | Dimension | Audited by | Skip when |
|---|---|---|---|
DEP | Dependency + runtime currency | this skill — references/dependency-audit.md, scripts/dep_scan.sh | no manifest found |
BUG | Bugs, security holes, quality | invoke code-review mode review | never |
PERF | Bottlenecks, leaks, algorithmic waste | invoke code-review mode perf | never |
UX | Usability and UI flow | invoke dont-make-me-think | no UI detected |
CLEAN | Readability vs Clean Code standards | inline — plan task runs code-review mode clean | never |
DEAD | Dead code, duplication, slop, weak types | inline — plan task runs code-review mode cleanup | never |
TEST | Untested branches and edge cases | inline — plan task runs test-coverage | never — an absent suite is itself a Critical finding |
CI | Pipelines, pre-commit, quality gates | inline — plan task runs devops-pipeline | never |
SEC | Secrets, dependency vulnerabilities | inline — plan task runs security-setup | never |
DOCS | Docs drifted from code | inline — plan task runs doc-manager | never |
Delegation policy — one rule: a delegate is invoked only if it changes no tracked file.
BUG, PERF, UX) — normalize the output into finding records and record
Path: delegated. Never let dont-make-me-think enter its Redesign Mode, which edits UI
source files.CLEAN, DEAD, TEST, CI, SEC, DOCS) — these delegates write, so never
invoke one during the audit. Audit the dimension with its checklist in
references/dimension-map.md, record Path: inline, and name that skill in the plan task.
inline is the expected path, not a degradation.Read references/delegation-policy.md before Phase 2. It holds the invocation args, the
CODE_REVIEW.md declared-artifact handling, the review-only rule for dont-make-me-think, the
/agent-config Pre-step rule, and the Skill-tool-unavailable fallback (which is reduced depth).
Follow references/baseline.md. Record each of these with the command that produced it: build
status, test command and pass rate, coverage if obtainable, lint status, CI presence and last
result, runtime/toolchain versions in use.
A RED baseline (does not build, tests do not run, there is no suite, or the build could not be
probed at all) does not stop the audit. Record Baseline: RED, continue, and make restoring
baseline-green the plan's Sprint 0 — nothing downstream is verifiable without it.
Probes must not mutate tracked files. A tracked file a probe changes is a finding. The
snapshot procedure and the no-test-command fallback are in references/baseline.md (Phase 0
rules: tracked files and the no-test-command fallback).
Completion criteria: every row of the baseline table in references/baseline.md holds a recorded
value or an explicit Not Assessed with a reason; the overall verdict is GREEN, AMBER, or
RED; every value cites the command that produced it.
Detect stack, ecosystems, UI presence, repo size, and entry points. Produce the dimension worklist: each of the 10 dimensions marked audit or Not Assessed + reason. If a requested area maps to no dimension ID, or to more than one, ask the user once which to audit. Otherwise proceed without asking.
Completion criteria: all 10 dimensions have a disposition; every ecosystem with a manifest is listed; repo-size branch and Agent-tool branch are both resolved and stated.
Read references/delegation-policy.md before invoking any delegated dimension.
Run DEP first — its output feeds the plan's upgrade waves and often explains findings in other
dimensions. Then run the remaining audited dimensions. If the Repo size and Agent tool branches
select subagents, spawn one agents/dimension-auditor.md per dimension in parallel. Otherwise run
them inline, one at a time.
DEP uses agents/dependency-auditor.md and references/dependency-audit.md, one invocation per
ecosystem. All DEP findings share the F-DEP- prefix, so allocate each ecosystem a distinct
id_start (1, 101, 201, …) before spawning them; gaps in the numbering are fine, collisions
are not.agents/dimension-auditor.md with that dimension's row from
references/dimension-map.md. Each has its own prefix and numbers from 1, so they need no ID
coordination.path:line (or a manifest entry and version
for DEP), or it is dropped. A dimension that produced nothing citable is Not Assessed, not
"no issues found".Completion criteria: every dimension marked audit in Phase 1 returned either ≥ 1 finding record
or an explicit "clean — checked X, found nothing" with the checks named; zero finding records lack
evidence; finding IDs are unique and follow F-<DIM>-<NNN>.
Merge all finding records into MODERNIZATION_REPORT.md using references/report-template.md.
Rank by severity: Critical → High → Medium → Low.
Deduplicate before writing, by the Deduplication rule in references/report-template.md.
Completion criteria: the file exists at the repo root; it contains the baseline table, a dimension coverage table showing all 10 dispositions, and the full finding table; every finding has ID, dimension, severity, evidence, and fix direction; the counts in the summary equal the rows in the table.
Spawn agents/plan-architect.md with the report path (or run it inline when the Agent tool is
unavailable). It writes MODERNIZATION_PLAN.md from references/plan-template.md, using the fixed
skeleton: unconditional Pre Agent environment (ME), then P0 Stabilize (M0), P1 Secure
& Patch (M1), P2 Modernize (M2), P3 Clean & Harden (M3), and P4 Polish (M4).
Do not rename or renumber P0–P4. Each phase's goal and exit milestone are in
references/plan-template.md (The fixed phase skeleton). Phases split into sprints. Every task uses the tasks-generator task format so the plan interoperates
with that skill, plus a Closes: line naming finding IDs.
Completion criteria: Pre is present and ordered before P0; every Critical and High finding
is closed by ≥ 1 task; every task has ≥ 2 testable acceptance criteria; every P0–P4 task asserts
baseline-green still holds; the dependency table references only task IDs that exist and has no
cycles; the critical path is stated explicitly; Pre and each of P0–P4 have a milestone with a
measurable exit condition. references/plan-template.md carries the task-ID format, the Pre
create-vs-update rule, and the RED-baseline exemption.
agents/plan-validator.md with fresh context, giving it both output files and the repo.
It verifies evidence citations resolve, severities are defensible, no finding is orphaned, no
task invents work not traceable to a finding or a milestone, and the stated critical path is
actually the longest chain in the dependency table.must-fix correction it returns.must-fix, re-run the validator once. Never run a third round.must-fix still open after round 2 in the report's Limitations, with a reason.Completion criteria: the validator has run at least twice when round 1 returned any must-fix;
zero unresolved must-fix items remain, or each survivor is recorded in Limitations with a reason.
After each phase, emit:
◆ [Phase Name] (phase N of 5 — [context])
··································································
[Check 1]: √ pass
[Check 2]: × fail — [reason]
[Criteria]: √ N/M met
____________________________
Result: PASS | FAIL | PARTIALUse the per-phase check names in references/output-format.md. Never report PASS while a phase
completion criterion, required output file, or safety guardrail is unresolved.
Walk references/acceptance-criteria.md before writing the final report. It is the full run
checklist: outputs, the read-only contract, findings, the plan, and an understandable final report.
The two bars this skill exists to keep:
git status --short is one of the two reports, a declared delegate
artifact (CODE_REVIEW.md), or a probe byproduct listed in the report's Artifacts section.If any criterion fails, report it as a FAIL row in the Step Completion Report and set Result: by
the rules below.
End the run with one final report in chat. Its first four lines are fixed; field contents, the
outcome table, and the format rule are in references/output-format.md.
Result: COMPLETE | PARTIAL — <reason> | BLOCKED — <reason>
Evidence: <checks that actually ran, and what each showed>
Uncertainty: <Not Assessed rows, degraded paths, untested items, labeled assumptions>
Decision: <approval needed, or "No approval needed."> Next: <remaining user action>Set Result: with the first rule that matches:
BUG, PERF, or UX ran inline at reduced depth; a huge-repo
cap left paths unscanned; the read-only check could not run (not a git repo); a must-fix
survived round 2; an acceptance criterion fails.Result: COMPLETE — 47 findings; Pre + P0–P4 plan; 0 must-fix
Evidence: git status --porcelain and git diff match the pre-run snapshot; validator ran 1 round
Uncertainty: coverage Not Assessed (no coverage tool); no plan task was executed
Decision: No approval needed. Next: review MODERNIZATION_PLAN.md, then run Task Pre.1The summary facts that follow these four lines (target, baseline, dimensions, findings, outputs,
plan, validation, source files changed) are in references/output-format.md (Full example).
Read references/edge-cases.md when a case arises: not a git repo, no manifest, no network,
baseline RED, a huge repo, a narrowed dimension filter, a monorepo, or existing report
files. A user asking mid-run to apply fixes is handled by the Read-only contract above.
Read each file only when its phase needs it; that keeps the agent's context budget for the audit.
references/scope-detection.md — the nine scope branches, detection, and resolution order.references/delegation-policy.md — invocation args, artifact handling, fallbacks per path.references/baseline.md — Phase 0 probe protocol per stack, and the baseline evidence table.references/dependency-audit.md — per-ecosystem fail-soft probes, classification schema,
upgrade wave rules, and migration lookup for majors.references/dimension-map.md — the 10 dimensions: inline checklist, severity rubric, skip rules.references/report-template.md — report structure and the deduplication rule.references/plan-template.md — plan structure, task format, task-ID and Pre rules.references/acceptance-criteria.md — the full run checklist.references/output-format.md — Step Completion Report checks, final-report fields, format rule.references/edge-cases.md — the full edge-case list.scripts/dep_scan.sh — read-only ecosystem and dependency probe; prints a markdown summary.Agents (spawn with the Agent tool; run inline if unavailable): agents/dependency-auditor.md
(DEP), agents/dimension-auditor.md (one delegated dimension per invocation),
agents/plan-architect.md (report → plan), agents/plan-validator.md (fresh-context validation).
© luongnv89, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 18 other files (scripts, references) in skills/codebase-modernizer of luongnv89/skills.
Open the folder on GitHubat commit 8f80262
Codebase Modernizer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codebase Modernizer this skillluongnv89/skills | 131 | — | ~5k | Automated safety check: Pass | MIT | |
| Astro Code Reviewwithastro/astro | 63k | — | ~7.6k | Automated safety check: Pass | Custom licence | |
| Spec App Consistency Auditleo-kuang-ai/spec-first | 107 | — | ~4.6k | Automated safety check: Pass | MIT | |
| Pi Enshare-skills/pi | 108 | — | ~9.9k | Automated safety check: Warn | Apache-2.0 | |
| PR Createvfarcic/dot-agent-deck | 109 | — | ~3k | Automated safety check: Pass | MIT | |
| Pi En Progressiveshare-skills/pi | 108 | — | ~9.3k | Automated safety check: Warn | Apache-2.0 |
withastro/astro
Perform a static, read-only code review of an Astro pull request or of a local branch, commit range, diff, patch, or working tree being prepared as a pull request.
leo-kuang-ai/spec-first
Audit mobile App PRD/Figma/local-source consistency across page routes, KMP/Clean Architecture, components, analytics, i18n, engineering quality, and industry lenses before runtime validation; use…
share-skills/pi
PI Cognitive AI. An agent skill from share-skills/pi.
vfarcic/dot-agent-deck
Take committed work from a branch to a verified pull request — push, open the PR, settle CI and the automated review, answer and resolve every finding, and hand off.
share-skills/pi
PI Cognitive AI. An agent skill from share-skills/pi.
CorridorTech/PoseCap
Two-axis fresh-context code review per WORKFLOW §10. An agent skill from CorridorTech/PoseCap.
luongnv89/skills
Review UI usability using Steve Krug's principles and produce a scannable report.
luongnv89/skills
Manage AI agent fleets in Herdr: tile root + sub-agents in one tab, start/prompt/wait/read/monitor via the herdr agent CLI, steer any pane; help lists every operation.
luongnv89/skills
Optimize Ollama configuration for the current machine's hardware.
luongnv89/skills
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
luongnv89/skills
Generate sprint-based development tasks from a PRD. An agent skill from luongnv89/skills.
luongnv89/skills
Manage AI agents in tmux: spawn sessions, send messages, wait, capture replies, inspect fleets, and tear down safely.
Works with
Categories
Audit a stale, inherited, or messy codebase — deps, bugs, security, tests, CI, docs, UI/UX — then emit a phased, testable modernization plan. Codebase Modernizer is an agent skill from luongnv89/skills. Audit a stale, inherited, or messy codebase — deps, bugs, security, tests, CI, docs, UI/UX — then emit a phased, testable modernization plan.
Codebase Modernizer fits situations like: tasks that involve Legacy modernization; tasks that involve Pull requests; tasks that involve UI design.
Run `npx skills add luongnv89/skills --skill codebase-modernizer -a claude-code`. Or copy the skill folder (skills/codebase-modernizer in luongnv89/skills) into .claude/skills/codebase-modernizer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add luongnv89/skills --skill codebase-modernizer -a codex`. Or copy the skill folder (skills/codebase-modernizer in luongnv89/skills) into .agents/skills/codebase-modernizer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add luongnv89/skills --skill codebase-modernizer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codebase-modernizer, .gemini/skills/codebase-modernizer, .github/skills/codebase-modernizer and .opencode/skills/codebase-modernizer in your project.
Going by SKILL.md and its folder, Codebase Modernizer needs the command-line tools its instructions call (git, npm, cargo and poetry). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Codebase Modernizer is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Codebase Modernizer: Astro Code Review (withastro/astro, 63k stars), Spec App Consistency Audit (leo-kuang-ai/spec-first, 107 stars), Pi En (share-skills/pi, 108 stars) and PR Create (vfarcic/dot-agent-deck, 109 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
luongnv89 (a GitHub user) maintains it in luongnv89/skills, which has 131 GitHub stars. The repository holds 37 skills in this directory. The repository was last updated on October 7, 2026.
Source: luongnv89/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.