Agent skill

Code Quality

by WrongStack in WrongStack/WrongStack

Find and remove unused code, ghost dependencies, unnecessary coupling and bundle waste with source-confirmed reachability.

MITAuto-check passedDevelopment

Install Code Quality

skills CLI
$ npx skills add WrongStack/WrongStack --skill code-quality -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install WrongStack/WrongStack code-quality --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/code-quality .claude/skills/code-quality && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-quality
GitHub stars
371
Token cost
~763 tokens
SKILL.md length
295 words
Files
1
Skills in repo
100
Repo updated
First seen
Licence
MIT

At a glance

Find and remove unused code, ghost dependencies, unnecessary coupling and bundle waste with source-confirmed reachability.

  • Works in 6 steps: Inspect scripts, package exports, plugin… → Separate internal unused code from… → Verify every removal through import/call… → …
  • Cleaning exports
  • SKILL.md covers Selection card, Overview, Rules and Workflow, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Quality is an agent skill from WrongStack/WrongStack. Find and remove unused code, ghost dependencies, unnecessary coupling and bundle waste with source-confirmed reachability. Use when cleaning exports or packages, reviewing Knip output or reducing dead code; use security-scanner for security findings and preserve public/dynamic entrypoints.

Its SKILL.md is about 760 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code quality and Vulnerability scanning. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.

When your agent uses it

  • Cleaning exports
  • Reviewing Knip output
  • Reducing dead code
  • Use security-scanner for security findings and preserve public/dynamic entrypoints

Example prompts

  • “/code-quality”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Inspect scripts, package exports, plugin registries, framework conventions,
  2. Separate internal unused code from public API: external consumers may not
  3. Verify every removal through import/call sites, dynamic use and relevant
  4. Fix configuration false positives narrowly; broad ignores hide later defects.
  5. Keep behavior changes separate from cleanup and preserve dirty work.
  6. Measure bundle/runtime savings against matched builds; deleted lines are

What it can do on your machine

Read from SKILL.md and the folder at commit a744bdc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • knip.dev
    • biomejs.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Quality loads about 763 tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 295 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~763

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from WrongStack/WrongStack at commit a744bdc, republished under its MIT licence (© WrongStack). 295 words, ~763 tokens.

Download SKILL.mdSave it as .claude/skills/code-quality/SKILL.md (or your agent's skills folder).
name
code-quality
description
Find and remove unused code, ghost dependencies, unnecessary coupling and bundle waste with source-confirmed reachability. Use when cleaning exports or packages, reviewing Knip output or reducing dead code; use security-scanner for security findings and preserve public/dynamic entrypoints.
version
1.0.1
trigger
cleaning exports or packages, reviewing Knip output or reducing dead code; use security-scanner for security findings and preserve public/dynamic entrypoints.
required-capabilities
filesystem.read
optional-capabilities
verification.run, web.research, filesystem.write
metadata.routing-group
quality

Code Quality

Selection card

  • Task: Measure dead code, unused dependencies and bundle waste. / TR: Ölü kod, kullanılmayan bağımlılık ve bundle israfını ölç.
  • Start: Identify the scope and obtain an executable before-proof or review evidence.
  • Finish: apply the acceptance checks below; report observed results and unresolved constraints.

Overview

Latest checked targets on 2026-10-09: Knip 6.41.0 and Biome 2.5.15. Use the repo's configured tools and verify migration deltas before upgrading. Static reachability findings are candidates until real consumers are checked.

Rules

  1. Inspect scripts, package exports, plugin registries, framework conventions, generated entrypoints and test/build configuration before declaring code unused.
  2. Separate internal unused code from public API: external consumers may not exist in this repository. Do not remove a public export merely because local references are absent.
  3. Verify every removal through import/call sites, dynamic use and relevant build output. Explain the evidence rather than dumping scanner results.
  4. Fix configuration false positives narrowly; broad ignores hide later defects.
  5. Keep behavior changes separate from cleanup and preserve dirty work.
  6. Measure bundle/runtime savings against matched builds; deleted lines are not proof of a smaller shipped artifact or faster execution.

Workflow

  1. Run the current quality command and record its candidate list/baseline.
  2. Group findings by entrypoint/config/dependency/export and confirm reachability.
  3. Remove a coherent set of confirmed unused items. Regenerate lockfiles through the package manager when dependencies change.
  4. Run affected type/build/tests and verify package export/consumer behavior.
  5. Rerun the quality scan; report resolved candidates, justified exclusions, unknown external usage and measured artifact changes where relevant.

Sources

Knip issue resolution, Biome.

Acceptance checks

  • Run the selected analyzer against the scoped source, confirm findings and verify behavioral checks after cleanup.

Skills in scope

  • codebase-navigation — actual consumers.
  • refactor-planner — coupling and staged structural changes.
  • testing — behavior preservation.
  • tech-stack — dependency justification.

© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in packages/core/skills/code-quality of WrongStack/WrongStack.

Open the folder on GitHubat commit a744bdc

Compare with similar skills

Code Quality next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Quality compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Quality this skillWrongStack/WrongStack371—~763Automated safety check: PassMIT
Frontend Review Hygienemizchi/skills360—~717Automated safety check: PassNone
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Ponytail Lazy Developer ModeDietrichGebert/ponytail160k1 repos~873Automated safety check: PassMIT
Dep Updatestrufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0
Systematic Code Refactoringluongnv89/claude-howto42k—~3kAutomated safety check: PassMIT

Similar skills

  • A skill your agent uses when assessing code quality hygiene — TypeScript strictness, lint violations, dead code, and duplication.

    360 GitHub stars~717 tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Ponytail Lazy Developer Mode

    DietrichGebert/ponytail

    Makes the agent pick the laziest solution that works: skip unneeded work, reuse what exists, prefer the standard library and platform features, and keep diffs small.

    160k GitHub starsUsed in 1 repo~873 tokens
    DevelopmentAuto-check passed
  • Dep Updates

    trufflesecurity/trufflehog

    Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

    28k GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Systematic Code Refactoring

    luongnv89/claude-howto

    Guides refactoring in phases based on Martin Fowler's method: research, test coverage check, planning and small tested steps, with your approval at each phase.

    42k GitHub stars~3k tokensUpdated 10 days ago
    DevelopmentAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.4k GitHub stars~2.2k tokensUpdated 29 days ago
    DevelopmentAuto-check passed

More from WrongStack/WrongStack

All 100 skills in this repo
  • Tech Stack

    WrongStack/WrongStack

    Validate and upgrade dependencies against live registries and official migration guides in any ecosystem.

    371 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Skill Creator

    WrongStack/WrongStack

    Create, improve and validate WrongStack SKILL.md bundles with precise discovery, progressive resources and current runtime contracts.

    371 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Bug Hunter

    WrongStack/WrongStack

    A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…

    371 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Design Craft

    WrongStack/WrongStack

    Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.

    371 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Design Critique

    WrongStack/WrongStack

    A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…

    371 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Mailbox Bridge

    WrongStack/WrongStack

    A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…

    371 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Categories

Questions about Code Quality

What does Code Quality do?

Find and remove unused code, ghost dependencies, unnecessary coupling and bundle waste with source-confirmed reachability. Code Quality is an agent skill from WrongStack/WrongStack. Find and remove unused code, ghost dependencies, unnecessary coupling and bundle waste with source-confirmed reachability.

When should I use Code Quality?

Code Quality fits situations like: cleaning exports; reviewing Knip output; reducing dead code; use security-scanner for security findings and preserve public/dynamic entrypoints.

How do I install Code Quality in Claude Code?

Run `npx skills add WrongStack/WrongStack --skill code-quality -a claude-code`. Or copy the skill folder (packages/core/skills/code-quality in WrongStack/WrongStack) into .claude/skills/code-quality in your project. Claude Code loads it when a task matches its description.

How do I install Code Quality in Codex?

Run `npx skills add WrongStack/WrongStack --skill code-quality -a codex`. Or copy the skill folder (packages/core/skills/code-quality in WrongStack/WrongStack) into .agents/skills/code-quality in your project. Codex loads it when a task matches its description.

Can I use Code Quality in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill code-quality -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-quality, .gemini/skills/code-quality, .github/skills/code-quality and .opencode/skills/code-quality in your project.

What does Code Quality need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Quality is instructions for the agent only.

Does Code Quality access the network?

SKILL.md names 2 domains. As links in the text: knip.dev and biomejs.dev. This is read from the text; nothing was executed.

Is Code Quality safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Quality use?

Code Quality is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Quality use?

About 763 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Quality?

Skills that share tags, products or a category with Code Quality: Frontend Review Hygiene (mizchi/skills, 360 stars), WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Ponytail Lazy Developer Mode (DietrichGebert/ponytail, 160k stars) and Dep Updates (trufflesecurity/trufflehog, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Quality?

WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 371 GitHub stars. The repository holds 100 skills in this directory. The repository was last updated on October 10, 2026.

Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.