skills/code-necromancer/SKILL.md
Systematic framework for resurrecting and modernizing legacy codebases through archaeology, resurrection, and rejuvenation phases. Activate on "legacy code", "inherited codebase", "no documentation", "technical debt", "resurrect", "modernize". NOT for greenfield projects or well-documented active codebases.
npx skillsauth add curiositech/windags-skills code-necromancerInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Tagline: Raise dead codebases from the grave
Systematic framework for understanding, resurrecting, and modernizing legacy codebases.
✅ Use when:
❌ NOT for:
Objective: Create a complete map before touching anything.
| Output | Description |
|--------|-------------|
| repo-inventory.json | All repos with metadata, languages, activity |
| dependency-graph.mmd | Inter-repo and external dependencies |
| architecture-diagram.mmd | Visual system topology |
| tech-stack-matrix.md | Language/framework versions per repo |
| maturity-assessment.md | Code quality, test coverage, docs quality |
| missing-pieces.md | Gaps, orphaned repos, broken integrations |
Process: Inventory → Deep Scan → Cross-Reference → Visualize → Assess
→ See references/archaeology-guide.md for detailed techniques.
Objective: Get the system running in development.
| Output | Description |
|--------|-------------|
| dependency-audit.md | Outdated packages, vulnerabilities, breaking changes |
| environment-variables.md | All required env vars with defaults |
| secrets-needed.md | API keys, certs, OAuth credentials |
| infrastructure-status.md | Cloud resources, what exists vs deleted |
| resurrection-blockers.md | Critical issues preventing launch |
| integration-tests/ | Tests verifying components work and communicate |
Process: Audit Dependencies → Map Environment → Check Infrastructure → Write Tests → Document Blockers
→ See references/integration-test-patterns.md for resurrection test patterns.
Objective: Modernize while maintaining feature parity.
| Output | Description |
|--------|-------------|
| security-recommendations.md | Vulnerability fixes, compliance |
| modernization-roadmap.md | Prioritized upgrades with effort estimates |
| architecture-improvements.md | Scalability, performance, maintainability |
Process: Security First → Infrastructure (containerize, CI/CD) → Code Quality → Architecture
# List all repos in org
gh repo list ORG --limit 1000 --json name,primaryLanguage,pushedAt
# Dependency analysis
npm audit && npm outdated # Node.js
pip list --outdated && safety check # Python
go mod graph # Go
# Find env vars in code
grep -rn 'process\.env\|os\.environ' --include="*.js" --include="*.py"
→ See references/framework-detection.md for framework/stack identification.
→ See references/infrastructure-mapping.md for cloud resource discovery.
→ See references/dependency-patterns.md for dependency detection.
What it looks like: Running npm install before reading any code
Why it's wrong: You'll fix the same bug 5 times; dependencies have changed
Fix: Complete archaeology first; understand before touching
What it looks like: "Let's also refactor while we're here" Why it's wrong: Scope explosion; never actually resurrect Fix: Strict phase separation; refactoring is Phase 3
What it looks like: Update all dependencies in one commit Why it's wrong: Something breaks, no idea what Fix: Update incrementally; test after each
What it looks like: "It runs, ship it" Why it's wrong: Regression city; no baseline for changes Fix: Write resurrection tests as you go; they prove progress
What it looks like: "I fixed it but forgot what I changed" Why it's wrong: Tribal knowledge returns; next person is you in 6 months Fix: Document everything you learn and change
What it looks like: Following README from 2019 Why it's wrong: APIs change, services get deprecated Fix: Verify every instruction; documentation lies
→ references/archaeology-guide.md - Deep code archaeology techniques
→ references/dependency-patterns.md - Dependency detection across ecosystems
→ references/framework-detection.md - Framework/stack identification
→ references/infrastructure-mapping.md - Cloud resource discovery
→ references/integration-test-patterns.md - Resurrection test patterns
→ templates/repo-inventory.json - Repository catalog
→ templates/archaeology-report.md - Phase 1 output
→ templates/resurrection-plan.md - Phase 2 output
→ templates/rejuvenation-roadmap.md - Phase 3 output
data-ai
license: Apache-2.0 NOT for unrelated tasks outside this domain.
development
Use when designing caching strategies (cache-aside, write-through, write-behind), implementing distributed locks, building rate limiters, leaderboards, real-time streams (XADD/consumer groups), pub/sub, or tuning eviction policies. Triggers: thundering-herd on cache miss, dogpile on key expiry, Redlock vs SET-NX-PX choice, sliding-window rate limiter, hot-key on a single cluster slot, big-key blowup, MULTI/EXEC across slots, KEYS in production. NOT for Redis Cluster operations/admin (different domain), embedded KV (SQLite, leveldb), in-process LRU caches, or Memcached.
tools
Drawing the `'use client'` boundary correctly in React Server Components apps (Next.js App Router, RSC frameworks) — leaf-pushing, slot composition, serialization rules, and environment poisoning prevention. Grounded in react.dev and Next.js 16 docs.
development
Use when designing rate limiting for an API, choosing between token bucket / sliding window / leaky bucket / fixed window, implementing it in Redis, deciding edge (Cloudflare/Upstash) vs origin enforcement, sizing per-user vs per-IP vs per-endpoint quotas, returning the right 429 response with Retry-After, or fixing the boundary-burst bug in fixed-window limiters. Triggers: 429 too many requests, INCR + EXPIRE, ZADD + ZREMRANGEBYSCORE + ZCARD, X-RateLimit-Remaining header, Cloudflare WAF rate limiting rules, Upstash @upstash/ratelimit, leaky bucket shaping vs policing, distributed rate limiter consistency. NOT for DDoS mitigation specifically (different scale), CAPTCHA / bot management, full WAF design, or per-user quota billing.