選項
首頁首頁 Skill 安全 repo-scan

repo-scan

affaan-m/ECC affaan-m/ECC

掃描 C++、Android、iOS 及 Web 平台的原始碼儲存庫,以分類檔案、偵測嵌入的第三方函式庫,並針對每個模組產生可採取行動的四級評估結果,同時提供互動式 HTML 報告。

...展開全部
0
更新時間 2026-10-01

repo-scan

每個生態系統都有自己的依賴管理工具,但目前尚無任何工具能橫跨 C++、Android、iOS 和 Web 等平台,告訴你:究竟有多少程式碼是真正屬於你的、哪些是第三方程式碼,以及哪些是冗餘代碼。

何時使用

  • 接手大型既有程式碼庫時,需要掌握整體結構概覽
  • 進行重大重構之前——辨識哪些是核心、哪些是重複、哪些是冗餘
  • 審計直接嵌入原始碼中的第三方依賴項(未在套件管理器中宣告)
  • 為單一儲存庫(monorepo)重組準備架構決策紀錄

安裝

# Fetch only the pinned commit for reproducibility
mkdir -p ~/.claude/skills/repo-scan
git init repo-scan
cd repo-scan
git remote add origin https://github.com/haibindev/repo-scan.git
git fetch --depth 1 origin 2742664
git checkout --detach FETCH_HEAD
cp -r . ~/.claude/skills/repo-scan

在安裝任何代理程式技能之前,請先審閱原始碼。

核心功能

功能 說明
跨堆疊掃描 一次掃描即可涵蓋 C/C++、Java/Android、iOS (OC/Swift) 及 Web (TS/JS/Vue)
檔案分類 將每個檔案標記為專案程式碼、第三方程式碼或建置產出
函式庫偵測 50 多種已知函式庫(FFmpeg、Boost、OpenSSL…)並擷取版本資訊
四級判定結果 核心資產 / 萃取與合併 / 重新建置 / 已廢棄
HTML 報告 具備鑽取式導航功能的互動式深色主題頁面
單一儲存庫支援 具摘要與子專案報告的分層掃描

分析深度層級

層級 已讀取檔案 使用案例
fast 每個模組 1-2 個 對龐大目錄進行快速清點
standard 每個模組 2-5 次 包含完整依賴關係與架構檢查的預設稽核
deep 每個模組 5-10 次 新增執行緒安全性、記憶體管理及 API 一致性
full 所有檔案 合併前全面審查

運作原理

  1. 分類儲存庫範圍:枚舉檔案,然後將每個檔案標記為專案程式碼、嵌入式第三方程式碼或建置產物。
  2. 偵測嵌入式函式庫:檢查目錄名稱、標頭檔、授權檔案及版本標記,以識別捆綁的依賴項及其可能的版本。
  3. 為每個模組評分:將檔案按模組或子系統分組,然後根據所有權、重複性及維護成本,分配四種評定結果之一。
  4. 標示結構性風險:指出無用產物、重複的封裝函式、過時的供應商代碼,以及應被提取、重建或廢棄的模組。
  5. 生成報告:回傳簡明摘要,並附帶具備模組級別深入檢視功能的互動式 HTML 輸出,以便能異步檢視稽核結果。

範例

以一個包含 50,000 個檔案的 C++ 單一儲存庫為例:

  • 發現 FFmpeg 2.x(2015 年版本)仍處於生產環境中
  • 發現同一個 SDK 封裝函式被重複了 3 次
  • 識別出 636 MB 已提交的 Debug/ipch/obj 建置產出
  • 分類結果:3 MB 專案程式碼 對比 596 MB 第三方程式碼

最佳實務

  • 從 standard 深度進行首次稽核
  • 針對 fast 針對擁有 100 多個模組的單一儲存庫,以快速進行清點
  • 針對 deep 對標記為需重構的模組進行增量分析
  • 檢視跨模組分析結果,以偵測子專案間的重複內容

連結

  • GitHub 儲存庫
在 GitHub 上查看
---
name: repo-scan
description: Scans source code repositories across C++, Android, iOS, and Web to classify files, detect embedded third-party libraries, and produce actionable four-level verdicts per module with interactive HTML reports.
---

# repo-scan

> Every ecosystem has its own dependency manager, but no tool looks across C++, Android, iOS, and Web to tell you: how much code is actually yours, what's third-party, and what's dead weight.

## When to Use

- Taking over a large legacy codebase and need a structural overview
- Before major refactoring — identify what's core, what's duplicate, what's dead
- Auditing third-party dependencies embedded directly in source (not declared in package managers)
- Preparing architecture decision records for monorepo reorganization

## Installation

```bash
# Fetch only the pinned commit for reproducibility
mkdir -p ~/.claude/skills/repo-scan
git init repo-scan
cd repo-scan
git remote add origin https://github.com/haibindev/repo-scan.git
git fetch --depth 1 origin 2742664
git checkout --detach FETCH_HEAD
cp -r . ~/.claude/skills/repo-scan
```

> Review the source before installing any agent skill.

## Core Capabilities

| Capability | Description |
|---|---|
| **Cross-stack scanning** | C/C++, Java/Android, iOS (OC/Swift), Web (TS/JS/Vue) in one pass |
| **File classification** | Every file tagged as project code, third-party, or build artifact |
| **Library detection** | 50+ known libraries (FFmpeg, Boost, OpenSSL…) with version extraction |
| **Four-level verdicts** | Core Asset / Extract & Merge / Rebuild / Deprecate |
| **HTML reports** | Interactive dark-theme pages with drill-down navigation |
| **Monorepo support** | Hierarchical scanning with summary + sub-project reports |

## Analysis Depth Levels

| Level | Files Read | Use Case |
|---|---|---|
| `fast` | 1-2 per module | Quick inventory of huge directories |
| `standard` | 2-5 per module | Default audit with full dependency + architecture checks |
| `deep` | 5-10 per module | Adds thread safety, memory management, API consistency |
| `full` | All files | Pre-merge comprehensive review |

## How It Works

1. **Classify the repo surface**: enumerate files, then tag each as project code, embedded third-party code, or build artifact.
2. **Detect embedded libraries**: inspect directory names, headers, license files, and version markers to identify bundled dependencies and likely versions.
3. **Score each module**: group files by module or subsystem, then assign one of the four verdicts based on ownership, duplication, and maintenance cost.
4. **Highlight structural risks**: call out dead-weight artifacts, duplicated wrappers, outdated vendored code, and modules that should be extracted, rebuilt, or deprecated.
5. **Produce the report**: return a concise summary plus the interactive HTML output with per-module drill-down so the audit can be reviewed asynchronously.

## Examples

On a 50,000-file C++ monorepo:
- Found FFmpeg 2.x (2015 vintage) still in production
- Discovered the same SDK wrapper duplicated 3 times
- Identified 636 MB of committed Debug/ipch/obj build artifacts
- Classified: 3 MB project code vs 596 MB third-party

## Best Practices

- Start with `standard` depth for first-time audits
- Use `fast` for monorepos with 100+ modules to get a quick inventory
- Run `deep` incrementally on modules flagged for refactoring
- Review the cross-module analysis for duplicate detection across sub-projects

## Links

- [GitHub Repository](https://github.com/haibindev/repo-scan)

所有檔案

1 個檔案

安裝 repo-scan

請將技能檔案下載並解壓縮至您的 .claude/skills/ 目錄中。

下載 ZIP

複製儲存庫並將技能檔案複製到您的專案中。

git clone https://github.com/affaan-m/ECC/tree/main/skills/repo-scan # Copy SKILL.md to your .claude/skills/ directory

複製 複製
快速設定: 將技能資料夾複製到 .claude/skills/ Claude 會自動偵測並使用該技能
儲存庫 affaan-m/ECC

相關技能

gmgn-portfolio
更新時間 2026-07-01
device-integrity
更新時間 2026-06-29
zeroize-audit
更新時間 2026-07-01
flutter-use-http-package
更新時間 2026-06-30
OR