옵션
집집 Skill 보안 repo-scan

repo-scan

affaan-m/ECC affaan-m/ECC

C++, Android, iOS 및 웹 전반의 소스 코드 저장소를 스캔하여 파일을 분류하고, 내장된 타사 라이브러리를 탐지하며, 모듈별 4단계의 실행 가능한 판정 결과를 대화형 HTML 보고서를 통해 제공합니다.

...모든 것을 확장하십시오
0
업데이트 된 시간 2026년 10월 1일

repo-scan

모든 생태계에는 각자의 의존성 관리 도구가 있지만, C++, 안드로이드, iOS, 웹 전반을 아우르며 ‘실제로 내 코드인 부분은 얼마나 되고, 타사 코드는 무엇이며, 불필요한 코드는 무엇인지’를 알려주는 도구는 없습니다.

사용 시점

  • 대규모 레거시 코드베이스를 인수하여 구조적 개요가 필요한 경우
  • 대규모 리팩토링 전 — 핵심 코드, 중복 코드, 불필요한 코드를 파악해야 할 때
  • 소스 코드에 직접 내장된(패키지 관리자에 선언되지 않은) 타사 의존성을 감사할 때
  • 모노레포 재구성을 위한 아키텍처 결정 기록 준비 시

설치

# Fetch only the pinned commit for reproducibility
mkdir -p ~/.claude/skills/repo-scan
git init repo-scan
cd repo-scan
git remote add origin https://github.com/haibindev/repo-scan.git
git fetch --depth 1 origin 2742664
git checkout --detach FETCH_HEAD
cp -r . ~/.claude/skills/repo-scan

에이전트 스킬을 설치하기 전에 소스 코드를 검토하십시오.

핵심 기능

기능 설명
크로스 스택 스캔 한 번의 실행으로 C/C++, Java/Android, iOS (OC/Swift), 웹 (TS/JS/Vue) 스캔
파일 분류 모든 파일을 프로젝트 코드, 타사 코드 또는 빌드 아티팩트로 태그 지정
라이브러리 감지 50개 이상의 알려진 라이브러리(FFmpeg, Boost, OpenSSL 등) 및 버전 추출
4단계 판정 핵심 자산 / 추출 및 병합 / 재빌드 / 사용 중단
HTML 보고서 드릴다운 탐색 기능이 있는 대화형 다크 테마 페이지
모노레포 지원 요약 및 하위 프로젝트 보고서를 포함한 계층적 스캔

분석 깊이 수준

레벨 읽은 파일 수 사용 사례
fast 모듈당 1~2개 대용량 디렉터리의 신속한 현황 파악
standard 모듈당 2~5개 전체 종속성 및 아키텍처 검사가 포함된 기본 감사
deep 모듈당 5~10개 스레드 안전성, 메모리 관리, API 일관성 추가
full 모든 파일 병합 전 종합 검토

작동 방식

  1. 리포지토리 범위를 분류합니다. 파일을 열거한 다음, 각 파일을 프로젝트 코드, 포함된 타사 코드 또는 빌드 아티팩트로 태그 지정합니다.
  2. 내장된 라이브러리 감지: 디렉터리 이름, 헤더, 라이선스 파일 및 버전 마커를 검사하여 번들된 종속성과 예상 버전을 식별합니다.
  3. 각 모듈에 점수 부여: 파일을 모듈 또는 하위 시스템별로 그룹화한 다음, 소유권, 중복 여부 및 유지 관리 비용을 기준으로 네 가지 판정 중 하나를 할당합니다.
  4. 구조적 위험 요소 강조: 불필요한 아티팩트, 중복된 래퍼, 구식 벤더 코드, 추출·재구축·사용 중단이 필요한 모듈을 지적합니다.
  5. 보고서 생성: 간결한 요약과 함께 모듈별 세부 정보를 확인할 수 있는 대화형 HTML 출력을 제공하여, 감사 결과를 비동기적으로 검토할 수 있도록 합니다.

예시

50,000개의 파일이 포함된 C++ 모노레포의 경우:

  • 여전히 프로덕션 환경에서 사용 중인 FFmpeg 2.x(2015년 버전) 발견
  • 동일한 SDK 래퍼가 3번 중복되어 있는 것을 발견
  • 커밋된 Debug/ipch/obj 빌드 아티팩트가 636 MB에 달하는 것으로 확인됨
  • 분류 결과: 프로젝트 코드 3 MB 대 타사 코드 596 MB

모범 사례

  • 다음부터 시작하십시오 standard 첫 번째 감사 시 심도 있게 시작하세요
  • 100개 이상의 모듈이 포함된 모노리포의 경우 fast 모듈이 100개 이상인 모노리포지토리의 경우, 빠른 현황 파악을 위해 이 기능을 사용하세요
  • 실행 deep 리팩토링 대상으로 표시된 모듈에 대해 점진적으로 실행
  • 하위 프로젝트 전반의 중복 감지를 위해 모듈 간 분석 결과를 검토하십시오

링크

  • GitHub 저장소
GitHub에서 보기
---
name: repo-scan
description: Scans source code repositories across C++, Android, iOS, and Web to classify files, detect embedded third-party libraries, and produce actionable four-level verdicts per module with interactive HTML reports.
---

# repo-scan

> Every ecosystem has its own dependency manager, but no tool looks across C++, Android, iOS, and Web to tell you: how much code is actually yours, what's third-party, and what's dead weight.

## When to Use

- Taking over a large legacy codebase and need a structural overview
- Before major refactoring — identify what's core, what's duplicate, what's dead
- Auditing third-party dependencies embedded directly in source (not declared in package managers)
- Preparing architecture decision records for monorepo reorganization

## Installation

```bash
# Fetch only the pinned commit for reproducibility
mkdir -p ~/.claude/skills/repo-scan
git init repo-scan
cd repo-scan
git remote add origin https://github.com/haibindev/repo-scan.git
git fetch --depth 1 origin 2742664
git checkout --detach FETCH_HEAD
cp -r . ~/.claude/skills/repo-scan
```

> Review the source before installing any agent skill.

## Core Capabilities

| Capability | Description |
|---|---|
| **Cross-stack scanning** | C/C++, Java/Android, iOS (OC/Swift), Web (TS/JS/Vue) in one pass |
| **File classification** | Every file tagged as project code, third-party, or build artifact |
| **Library detection** | 50+ known libraries (FFmpeg, Boost, OpenSSL…) with version extraction |
| **Four-level verdicts** | Core Asset / Extract & Merge / Rebuild / Deprecate |
| **HTML reports** | Interactive dark-theme pages with drill-down navigation |
| **Monorepo support** | Hierarchical scanning with summary + sub-project reports |

## Analysis Depth Levels

| Level | Files Read | Use Case |
|---|---|---|
| `fast` | 1-2 per module | Quick inventory of huge directories |
| `standard` | 2-5 per module | Default audit with full dependency + architecture checks |
| `deep` | 5-10 per module | Adds thread safety, memory management, API consistency |
| `full` | All files | Pre-merge comprehensive review |

## How It Works

1. **Classify the repo surface**: enumerate files, then tag each as project code, embedded third-party code, or build artifact.
2. **Detect embedded libraries**: inspect directory names, headers, license files, and version markers to identify bundled dependencies and likely versions.
3. **Score each module**: group files by module or subsystem, then assign one of the four verdicts based on ownership, duplication, and maintenance cost.
4. **Highlight structural risks**: call out dead-weight artifacts, duplicated wrappers, outdated vendored code, and modules that should be extracted, rebuilt, or deprecated.
5. **Produce the report**: return a concise summary plus the interactive HTML output with per-module drill-down so the audit can be reviewed asynchronously.

## Examples

On a 50,000-file C++ monorepo:
- Found FFmpeg 2.x (2015 vintage) still in production
- Discovered the same SDK wrapper duplicated 3 times
- Identified 636 MB of committed Debug/ipch/obj build artifacts
- Classified: 3 MB project code vs 596 MB third-party

## Best Practices

- Start with `standard` depth for first-time audits
- Use `fast` for monorepos with 100+ modules to get a quick inventory
- Run `deep` incrementally on modules flagged for refactoring
- Review the cross-module analysis for duplicate detection across sub-projects

## Links

- [GitHub Repository](https://github.com/haibindev/repo-scan)

모든 파일

1개 파일

repo-scan 설치

스킬 파일을 다운로드하여 .claude/skills/ 디렉터리에 압축을 풀어주세요.

ZIP 다운로드

저장소를 클론하고 스킬 파일을 프로젝트에 복사하세요.

git clone https://github.com/affaan-m/ECC/tree/main/skills/repo-scan # Copy SKILL.md to your .claude/skills/ directory

복사 복사
빠른 설정: 스킬 폴더를 .claude/skills/로 복사하세요. Claude가 해당 스킬을 자동으로 감지하여 사용할 것입니다.
저장소 affaan-m/ECC

관련 스킬

gmgn-portfolio
업데이트 된 시간 2026년 7월 1일
device-integrity
업데이트 된 시간 2026년 6월 29일
zeroize-audit
업데이트 된 시간 2026년 7월 1일
flutter-use-http-package
업데이트 된 시간 2026년 6월 30일
OR