code-quality-plugin/skills/code-antipatterns/SKILL.md
Analyze a codebase for anti-patterns using ast-grep. Use when finding magic numbers, console.logs, var usage, excessive any, eval/innerHTML security issues, or deep nesting.
npx skillsauth add laurigates/claude-plugins code-antipatternsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
| Use this skill when... | Use something else instead when... |
|------------------------|------------------------------------|
| Running a parallel anti-pattern scan and producing a report | Looking up the full YAML rule catalog → see REFERENCE.md |
| Specifically targeting empty catches, floating promises, or \|\| true | Use the dedicated scanner → code-hidden-failures --track errors |
| Finding success-on-empty / silent degradation patterns | Use the dedicated scanner → code-hidden-failures --track degradation |
| Broad code-quality review across security, perf, and architecture | Run the full review delegate → code-review |
$1 (defaults to current directory if not specified)find . -type f \( -name "*.js" -o -name "*.ts" -o -name "*.jsx" -o -name "*.tsx" \)find . -name "*.vue"find . -name "*.py"Perform comprehensive anti-pattern analysis. The mechanical detection is one
deterministic ast-grep scan over a shipped rule project — you do not re-type
sg -p '…' patterns and do not fan out agents just to run them. Your job is
the judgment: severity triage, recommendations, and fix planning on top of the
scan's structured findings.
The detection catalog lives as an ast-grep rule project in
rules/ (one *.yml per pattern under rules/lib/, each with a
valid/invalid test fixture in rules/tests/). Run the whole catalog in one pass:
ast-grep scan -c ${CLAUDE_SKILL_DIR}/rules/sgconfig.yml --json=compact <path>
Each JSON finding carries ruleId, file, range (line/column), message, and
the matched text. Parse this — it is the raw finding set for every category
below. The rules cover: empty catch, console.log, var, eval/new Function,
innerHTML/outerHTML, as any / : any annotations, magic-number timers, Vue
props mutation, Python mutable defaults, bare except, global, and
type() ==.
Graceful degradation — if ast-grep (packaged as ast-grep or sg) is not
installed, fall back to the per-pattern flow: read REFERENCE.md,
which links each rule to its source .yml, and run the individual
ast-grep -p '<pattern>' --lang <lang> commands by hand. The rule project is the
fast path; the reference is the fallback.
The scan is mechanical and reproducible; triage, recommendation, and fix planning are the judgment work — do them yourself on the scan output rather than spawning agents to re-run patterns:
/code:hidden-failures --track errors for its severity model,
surfacing recommendations, and privacy redaction. Do not re-classify them here.fix, and recommend process changes (lint rules, pre-commit).Reserve any parallel Task fan-out for genuinely independent reasoning (e.g.
a deep security review or a framework-specific architecture pass) — never for
running the patterns, which Step 1 already did once, deterministically.
Based on the detected languages, analyze for these categories:
JavaScript/TypeScript Anti-patterns
/code:hidden-failures --track errorsAsync/Promise Patterns
/code:hidden-failures --track errorsFramework-Specific (if detected)
TypeScript Quality (if .ts files present)
any types, non-null assertions, type safety issuesCode Complexity
Security Concerns
Memory & Performance
Python Anti-patterns (if detected)
/code:hidden-failures --track errorsDo NOT re-implement empty-catch / bare-except / floating-promise detection
here. Invoke /code:hidden-failures --track errors via the SlashCommand tool with the
same PATH and severity filter, then fold its findings into the
consolidated report under a dedicated Error Swallowing section.
Rationale: a single source of truth prevents drift between severity
models, app-context surfacing recommendations, and privacy redaction
policies. See code-quality-plugin/skills/code-hidden-failures/SKILL.md.
Two catalog concerns are not structural single-node matches and stay as agent-judgment passes on the code, not rules:
/code:complexity or read the flagged files.tsc + the no-floating-promises ESLint rule, or /code:hidden-failures --track errors, rather than a broad structural rule that would flag every call.Consolidate findings into this structure:
## Anti-pattern Analysis Report
### Summary
- Total issues: X
- Critical: X | High: X | Medium: X | Low: X
- Categories with most issues: [list]
### Critical Issues (Fix Immediately)
| File | Line | Issue | Category |
|------|------|-------|----------|
| ... | ... | ... | ... |
### High Priority Issues
| File | Line | Issue | Category |
|------|------|-------|----------|
| ... | ... | ... | ... |
### Medium Priority Issues
[Similar table]
### Low Priority / Style Issues
[Similar table or summary count]
### Recommendations
1. [Prioritized fix recommendations]
2. [...]
### Category Breakdown
- **Security**: X issues (details)
- **Async/Promises**: X issues (details)
- **Code Complexity**: X issues (details)
- [...]
--focus <category>: Focus on specific category (security, async, complexity, framework)--severity <level>: Minimum severity to report (critical, high, medium, low)--fix: Attempt automated fixes where safeAfter consolidating findings:
rules/ — the executable ast-grep catalog (sgconfig.yml + rules/lib/*.yml + rules/tests/*-test.yml); run ast-grep test -c rules/sgconfig.yml --skip-snapshot-tests to verify every rule against its fixturesast-grep-search - ast-grep usage reference/code:review - Comprehensive code reviewsecurity-audit - Deep security analysiscode-refactoring - Automated refactoring/configure:linting for automated enforcement/configure:security for CI integrationdevelopment
Debug HTTP APIs: trace requests, inspect headers. Use when a request fails: check status first.
documentation
Render architecture diagrams from text sources. Use when documenting system topology.
tools
Inspect JSON payloads and extract nested fields. Use when parsing API responses.
tools
--- name: no-description allowed-tools: Read --- # No Description This skill has no description and must be dropped with a warning.