Agent skill

Scan Hardcoded Strings

by rajbos in rajbos/ai-engineering-fluency

Inventory hardcoded (non-localized) UI text across vscode-extension/src/webview/ and the webview-HTML-producing code in vscode-extension/src/extension.ts — string/template literals rendered as UI…

MITAuto-check passedFrontend & Design

Install Scan Hardcoded Strings

skills CLI
$ npx skills add rajbos/ai-engineering-fluency --skill scan-hardcoded-strings -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rajbos/ai-engineering-fluency scan-hardcoded-strings --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rajbos/ai-engineering-fluency.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/scan-hardcoded-strings .claude/skills/scan-hardcoded-strings && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
scan-hardcoded-strings
GitHub stars
116
Token cost
~2.1k tokens
SKILL.md length
948 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

Inventory hardcoded (non-localized) UI text across vscode-extension/src/webview/ and the webview-HTML-producing code in vscode-extension/src/extension.ts — string/template literals rendered as UI…

  • Works in 6 steps: Recursively scan every *.ts file… → Flag string/template literals in… → Skip anything already wrapped in… → …
  • Tasks that involve Internationalization
  • SKILL.md covers When to Use This Skill, Running the Check, Interpreting Output and After Finding Hardcoded Strings, plus 2 more sections
  • Calls npm and node

What it does

Scan Hardcoded Strings is an agent skill from rajbos/ai-engineering-fluency. Inventory hardcoded (non-localized) UI text across vscode-extension/src/webview/ and the webview-HTML-producing code in vscode-extension/src/extension.ts — string/template literals rendered as UI text that never go through localize()/localizeFormat()/t()/vscode.l10n.t(). Produces a human-triageable report; never fails the build. Use after a UI change, before a release, or periodically as a localization audit.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Frontend & Design, covering Internationalization. It works with Visual Studio Code. The repository describes itself as: Extension that shows information about the estimated token usage and more of AI in editors/CLI's. The licence is MIT.

When your agent uses it

  • Tasks that involve Internationalization

Example prompts

  • “/scan-hardcoded-strings”

Requirements

  • Node.js

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Recursively scan every *.ts file (excluding *.test.ts) under
  2. Flag string/template literals in UI-rendering positions — assignments to
  3. Skip anything already wrapped in localize(, localizeFormat(, t(, or
  4. Print a console report grouped by file, with line numbers and snippets
  5. Write the same findings to hardcoded-strings-report.md at the repo root
  6. Set process.exitCode = 0 rather than forcing process.exit() — this

What it can do on your machine

Read from SKILL.md and the folder at commit 64b51e6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Scan Hardcoded Strings loads about 2.1k tokens when it runs. Until then it costs about 109 tokens; SKILL.md has 948 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rajbos/ai-engineering-fluency at commit 64b51e6, republished under its MIT licence (© rajbos). 948 words, ~2,150 tokens.

Download SKILL.mdSave it as .claude/skills/scan-hardcoded-strings/SKILL.md (or your agent's skills folder).
name
scan-hardcoded-strings
description
Inventory hardcoded (non-localized) UI text across vscode-extension/src/webview/** and the webview-HTML-producing code in vscode-extension/src/extension.ts — string/template literals rendered as UI text that never go through localize()/localizeFormat()/t()/vscode.l10n.t(). Produces a human-triageable report; never fails the build. Use after a UI change, before a release, or periodically as a localization audit.

Scan Hardcoded Strings Skill

Scans the VS Code extension's webview UI code for candidate hardcoded (non-localized) UI strings and writes a triage report. This is an informational inventory tool, not a CI gate — it never exits non-zero and never modifies source files.

When to Use This Skill

Use this skill when you need to:

  • Audit UI text after adding or changing a webview panel or a section of extension.ts's get*Html methods, to catch strings that were typed directly instead of routed through localization
  • Build or refresh a localization backlog before a release
  • Periodically re-run as a maintenance/audit pass to see whether the backlog of non-localized strings is growing or shrinking
  • Investigate a specific UI surface (e.g. a webview panel) that appears not to translate correctly under a non-English locale

It complements two existing scripts that only check consistency of strings already wired through localization (scripts/validate-localization.js / npm --prefix vscode-extension run lint:l10n, and vscode-extension/scripts/validate-l10n.mjs / npm --prefix vscode-extension run validate:l10n) — neither of those, nor anything else in the repo, detects a plain string literal that never calls localize(/t(/ vscode.l10n.t( in the first place. A separate, stricter AST-based CI gate for new instances of this may exist as an independent effort; this skill is not that gate — it is a full-codebase inventory for manual triage.

Running the Check

bash
node .github/skills/scan-hardcoded-strings/scan-hardcoded-strings.js

# Machine-readable JSON output
node .github/skills/scan-hardcoded-strings/scan-hardcoded-strings.js --json

The script will:

  1. Recursively scan every *.ts file (excluding *.test.ts) under vscode-extension/src/webview/, plus only the get*Html(...) method bodies in vscode-extension/src/extension.ts (not the whole file — this keeps out unrelated string literals like GitHub issue Markdown templates or VS Code panel titles), after blanking out /* ... */ block/JSDoc comments so example markup in a doc comment isn't mistaken for real UI text
  2. Flag string/template literals in UI-rendering positions — assignments to .textContent/.innerText/.innerHTML/.title/.placeholder (a direct literal or a conditional/ternary RHS whose branches are literals), aria-label="..."/title="..."/placeholder="..." HTML attributes (or the same three set via .setAttribute('title', '...')), a literal document.createTextNode('...') argument, text inside <div>, <button>, <vscode-button>, <label>, <h1>–<h6>, <p>, <span>, <td>, <th>, <option>, <summary>, <caption>, <li>, <title>, and SVG's <text> tags in template literals (tolerating simple nested inline tags like <a>/<strong>/<span>, which are also matched as a literal's own root tag so e.g. el.innerHTML = '<strong>Save changes</strong>' isn't missed, and void/structural tags like <input>/<br> that never need a closing tag), and the UI-text argument of a known shared DOM helper call (el(...), iconHeading(...), createButton(...) from vscode-extension/src/webview/shared/domUtils.ts) — that argument may be several string/template literals joined by +, or a top-level ternary or ??/|| fallback of (recursively) literal/+-joined branches, not just a single direct literal
  3. Skip anything already wrapped in localize(, localizeFormat(, t(, or vscode.l10n.t(, and anything that doesn't look like prose (pure numbers/symbols, URLs, CSS values, HTML character references like &middot;/&#8226;, a narrow denylist of single CSS-keyword tokens — not every single lowercase word; the letter check itself is Unicode-aware, so non-English text isn't exempted) — but recover string literals that are themselves a whole ternary branch, or the fallback side of a || default, inside an interpolation's expression, e.g. `${flag ? 'Enable Overrides' : 'Disable Overrides'}` or `${msg || '<em>No message</em>'}` (a *plain* quoted literal that is merely an argument to some other call in the same interpolation, e.g. `${buttonHtml('btn-refresh')}`, is left alone — but a *template* literal there, e.g. `${escapeHtml(`${a} · ${b} AIU`)}`, is still recovered, since a template literal builds display text while a plain quoted string is routinely a lookup key/id), checking each recovered literal on its own so one non-prose branch can't suppress another genuine one
  4. Print a console report grouped by file, with line numbers and snippets
  5. Write the same findings to hardcoded-strings-report.md at the repo root
  6. Set process.exitCode = 0 rather than forcing process.exit() — this script informs, it does not gate, and letting the process exit naturally avoids truncating buffered output when piped (e.g. in CI or --json | ...). Any unexpected error during the scan is caught and logged to stderr rather than crashing with a non-zero exit code, preserving that contract.
Show full SKILL.md (312 more words)Show less

Interpreting Output

Each finding shows the file, line number, which detector matched (the "kind"), and a truncated snippet of the offending code. There is no severity ranking — triage each entry:

SituationAction
Genuine hardcoded UI proseAdd a localization key and reference it via localize() (webview) or t() (extension host)
False positive (e.g. unusual formatting the regex misjudged)No action — this is a line-scan, not an AST parse; use judgement
Text intentionally not localized (e.g. a raw model/tool name)No action, but consider a code comment if the reason isn't obvious

After Finding Hardcoded Strings

  1. Add the missing key:
    • Extension-host text (via t('key')): add it to vscode-extension/package.nls.json (+ package.nls.zh-cn.json where translated).
    • Webview text (via localize('key')): add it to DEFAULT_LOCALIZATION in vscode-extension/src/webview/shared/localization.ts (the English fallback) and to getWebviewLocalization() in vscode-extension/src/extension.ts (via l10n.t('key')) plus package.nls.json / package.nls.zh-cn.json. Without the getWebviewLocalization() entry, the webview always falls back to the English DEFAULT_LOCALIZATION text regardless of locale.
  2. Replace the literal with a t('key') / localize('key') call at the flagged site.
  3. Add test coverage per the repo's "Localization changes require test coverage" rule (vscode-extension/test/unit/l10n.test.ts).
  4. Re-run this script to confirm the finding disappeared, then run npm --prefix vscode-extension run lint:l10n and npm --prefix vscode-extension run validate:l10n (both scripts live in vscode-extension/package.json, not the repo root) to confirm the new key is consistent across locale files.

Files in This Directory

  • SKILL.md — This file; instructions for the skill
  • scan-hardcoded-strings.js — Node.js script that performs the scan
  • scan-hardcoded-strings.test.js — Unit tests (node --test .github/skills/scan-hardcoded-strings/scan-hardcoded-strings.test.js)
  • README.md — Overview and detailed detection rules
  • vscode-extension/src/webview/shared/localization.ts — localize() / DEFAULT_LOCALIZATION (English fallback) for webview UI strings
  • vscode-extension/src/extension.ts — getWebviewLocalization(), which must also list a webview key (via l10n.t('key')) for it to resolve to a real translation instead of the DEFAULT_LOCALIZATION fallback
  • vscode-extension/src/l10n.ts — t() for extension-host runtime strings
  • vscode-extension/package.nls.json (+ package.nls.<locale>.json) — extension-host translation tables
  • scripts/validate-localization.js, vscode-extension/scripts/validate-l10n.mjs — consistency checks for strings already routed through localization
  • hardcoded-strings-report.md (repo root) — the generated inventory report

© rajbos, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/scan-hardcoded-strings of rajbos/ai-engineering-fluency.

Open the folder on GitHubat commit 64b51e6

Compare with similar skills

Scan Hardcoded Strings next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Scan Hardcoded Strings compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Scan Hardcoded Strings this skillrajbos/ai-engineering-fluency116—~2.1kAutomated safety check: PassMIT
Command UIforcedotcom/salesforcedx-vscode1k—~1.4kAutomated safety check: PassBSD-3-Clause
Vscode Ext Commandsgithub/awesome-copilot40k3 repos~387Automated safety check: PassMIT
Vscode Ext Localizationgithub/awesome-copilot40k2 repos~369Automated safety check: PassMIT
Roo Translationzgsm-ai/costrict4.4k—~1.8kAutomated safety check: PassApache-2.0
Impeccablebestofjs/bestofjs3.1k27 repos~2.6kAutomated safety check: PassMIT

Similar skills

  • Command UI

    forcedotcom/salesforcedx-vscode

    Command palette, CodeLens, context menus, package.nls titles, and NotificationModeService.

    1k GitHub stars~1.4k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Vscode Ext Commands

    github/awesome-copilot

    Official

    Guidelines for contributing commands in VS Code extensions. An agent skill from github/awesome-copilot.

    40k GitHub starsUsed in 3 repos~387 tokens
    Frontend & DesignAuto-check passed
  • Vscode Ext Localization

    github/awesome-copilot

    Official

    Guidelines for proper localization of VS Code extensions, following VS Code extension development guidelines, libraries and good practices

    40k GitHub starsUsed in 2 repos~369 tokens
    Frontend & DesignAuto-check passed
  • Roo Translation

    zgsm-ai/costrict

    Provides comprehensive guidelines for translating and localizing CoStrict extension strings.

    4.4k GitHub stars~1.8k tokensUpdated 7 days ago
    Writing & ContentAuto-check passed
  • Impeccable

    bestofjs/bestofjs

    A skill your agent uses when the user wants to design, redesign, shape, critique, audit, polish, clarify, distill, harden, optimize, adapt, animate, colorize, extract, or otherwise improve a…

    3.1k GitHub starsUsed in 27 repos~2.6k tokens
    Frontend & DesignAuto-check passed
  • Chatbox i18n Translator

    chatboxai/chatbox

    Translates new or changed i18n keys from a Chatbox Pro diff, staged changes or a commit range, writing the locale JSON files directly with a built-in glossary.

    42k GitHub stars~508 tokensUpdated 13 days ago
    Frontend & DesignAuto-check passed

More from rajbos/ai-engineering-fluency

All 21 skills in this repo
  • Check Urls

    rajbos/ai-engineering-fluency

    Find all hardcoded URLs in TypeScript source files and verify they resolve (return HTTP 2xx/3xx).

    116 GitHub stars~662 tokensUpdated today
    Auto-check passed
  • Create Issue

    rajbos/ai-engineering-fluency

    Create a well-scoped GitHub issue in this repo. An agent skill from rajbos/ai-engineering-fluency.

    116 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Deduplicate Code

    rajbos/ai-engineering-fluency

    Detect copy-pasted code blocks across the shared source (vscode-extension/src, the repo-root src/, cli/src) with the dependency-free check-code-duplication.js detector, then pick one duplicate group…

    116 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Improve Tool Families

    rajbos/ai-engineering-fluency

    Analyze coverage of the vscode-extension's tool-family definitions (DEFAULTTOOLFAMILIES in vscode-extension/src/toolFamilies.ts) against the canonical tool-name list in src/toolNames.json and/or a…

    116 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Load Cache Data

    rajbos/ai-engineering-fluency

    Load and display the last 10 cache entries as raw JSON output.

    116 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • PR Risk Review

    rajbos/ai-engineering-fluency

    Assess the risk of a changeset (a PR, a branch, or the working tree) and classify it as low, medium, or high with a written rationale.

    116 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Questions about Scan Hardcoded Strings

What does Scan Hardcoded Strings do?

Inventory hardcoded (non-localized) UI text across vscode-extension/src/webview/ and the webview-HTML-producing code in vscode-extension/src/extension.ts — string/template literals rendered as UI…. Scan Hardcoded Strings is an agent skill from rajbos/ai-engineering-fluency.t().

When should I use Scan Hardcoded Strings?

Scan Hardcoded Strings fits situations like: tasks that involve Internationalization.

How do I install Scan Hardcoded Strings in Claude Code?

Run `npx skills add rajbos/ai-engineering-fluency --skill scan-hardcoded-strings -a claude-code`. Or copy the skill folder (.claude/skills/scan-hardcoded-strings in rajbos/ai-engineering-fluency) into .claude/skills/scan-hardcoded-strings in your project. Claude Code loads it when a task matches its description.

How do I install Scan Hardcoded Strings in Codex?

Run `npx skills add rajbos/ai-engineering-fluency --skill scan-hardcoded-strings -a codex`. Or copy the skill folder (.claude/skills/scan-hardcoded-strings in rajbos/ai-engineering-fluency) into .agents/skills/scan-hardcoded-strings in your project. Codex loads it when a task matches its description.

Can I use Scan Hardcoded Strings in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rajbos/ai-engineering-fluency --skill scan-hardcoded-strings -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scan-hardcoded-strings, .gemini/skills/scan-hardcoded-strings, .github/skills/scan-hardcoded-strings and .opencode/skills/scan-hardcoded-strings in your project.

What does Scan Hardcoded Strings need to run?

Going by SKILL.md and its folder, Scan Hardcoded Strings needs the command-line tools its instructions call (npm and node). Our summary lists: Node.js.

Does Scan Hardcoded Strings access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Scan Hardcoded Strings safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Scan Hardcoded Strings use?

Scan Hardcoded Strings is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Scan Hardcoded Strings use?

About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Scan Hardcoded Strings?

Skills that share tags, products or a category with Scan Hardcoded Strings: Command UI (forcedotcom/salesforcedx-vscode, 1k stars), Vscode Ext Commands (github/awesome-copilot, 40k stars), Vscode Ext Localization (github/awesome-copilot, 40k stars) and Roo Translation (zgsm-ai/costrict, 4.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Scan Hardcoded Strings?

rajbos (a GitHub user) maintains it in rajbos/ai-engineering-fluency, which has 116 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 8, 2026.

Source: rajbos/ai-engineering-fluency on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.