repo-scan
affaan-m/ECC
扫描 C++、Android、iOS 和 Web 领域的源代码仓库,对文件进行分类,检测嵌入的第三方库,并针对每个模块生成可操作的四级评估结果,同时提供交互式 HTML 报告。
...展开全部repo-scan
每个生态系统都有自己的依赖管理器,但目前还没有任何工具能够跨C++、Android、iOS和Web平台,告诉你:有多少代码是真正属于你的,哪些是第三方代码,哪些又是冗余代码。
何时使用
- 接手大型遗留代码库并需要了解其结构概览时
- 进行重大重构之前——识别核心代码、重复代码和冗余代码
- 审核直接嵌入源代码中的第三方依赖项(未在包管理器中声明的)
- 为单仓库(monorepo)重组准备架构决策记录
安装
# Fetch only the pinned commit for reproducibility
mkdir -p ~/.claude/skills/repo-scan
git init repo-scan
cd repo-scan
git remote add origin https://github.com/haibindev/repo-scan.git
git fetch --depth 1 origin 2742664
git checkout --detach FETCH_HEAD
cp -r . ~/.claude/skills/repo-scan
在安装任何代理技能之前,请先审查源代码。
核心功能
| 功能 | 描述 |
|---|---|
| 跨栈扫描 | 一次扫描即可覆盖 C/C++、Java/Android、iOS(OC/Swift)和 Web(TS/JS/Vue) |
| 文件分类 | 将每个文件标记为项目代码、第三方文件或构建产物 |
| 库检测 | 识别50余种已知库(FFmpeg、Boost、OpenSSL等)并提取版本信息 |
| 四级判定 | 核心资产 / 提取与合并 / 重建 / 弃用 |
| HTML 报告 | 支持钻取导航的交互式深色主题页面 |
| 单仓库支持 | 支持摘要及子项目报告的分层扫描 |
分析深度级别
| 级别 | 读取的文件 | 用例 |
|---|---|---|
fast |
每个模块 1-2 个 | 对庞大目录进行快速清点 |
standard |
每个模块 2-5 次 | 包含完整依赖关系和架构检查的默认审计 |
deep |
每个模块 5-10 个 | 添加线程安全、内存管理、API 一致性 |
full |
所有文件 | 合并前的全面审查 |
工作原理
- 对代码库范围进行分类:枚举文件,然后将每个文件标记为项目代码、嵌入的第三方代码或构建工件。
- 检测嵌入的库:检查目录名称、头文件、许可证文件和版本标记,以识别捆绑的依赖项及其可能的版本。
- 为每个模块打分:按模块或子系统对文件进行分组,然后根据所有权、重复性和维护成本,分配四种判定结果之一。
- 突出显示结构性风险:标出冗余构建产物、重复的封装类、过时的第三方代码,以及应被提取、重建或弃用的模块。
- 生成报告:返回简明摘要以及支持按模块深入查看的交互式 HTML 输出,以便异步审查审计结果。
示例
在一个包含 50,000 个文件的 C++ 单一仓库中:
- 发现 FFmpeg 2.x(2015 年版本)仍处于生产环境中
- 发现同一个 SDK 封装器被重复了 3 次
- 识别出 636 MB 已提交的 Debug/ipch/obj 构建产物
- 分类结果:3 MB 项目代码 vs 596 MB 第三方代码
最佳实践
- 从
standard深度 - 针对
fast针对包含100个以上模块的单仓库,快速进行资源盘点 - 运行
deep对标记为需重构的模块进行增量分析 - 审查跨模块分析结果,以检测子项目间的重复内容
链接
- GitHub 仓库
---
name: repo-scan
description: Scans source code repositories across C++, Android, iOS, and Web to classify files, detect embedded third-party libraries, and produce actionable four-level verdicts per module with interactive HTML reports.
---
# repo-scan
> Every ecosystem has its own dependency manager, but no tool looks across C++, Android, iOS, and Web to tell you: how much code is actually yours, what's third-party, and what's dead weight.
## When to Use
- Taking over a large legacy codebase and need a structural overview
- Before major refactoring — identify what's core, what's duplicate, what's dead
- Auditing third-party dependencies embedded directly in source (not declared in package managers)
- Preparing architecture decision records for monorepo reorganization
## Installation
```bash
# Fetch only the pinned commit for reproducibility
mkdir -p ~/.claude/skills/repo-scan
git init repo-scan
cd repo-scan
git remote add origin https://github.com/haibindev/repo-scan.git
git fetch --depth 1 origin 2742664
git checkout --detach FETCH_HEAD
cp -r . ~/.claude/skills/repo-scan
```
> Review the source before installing any agent skill.
## Core Capabilities
| Capability | Description |
|---|---|
| **Cross-stack scanning** | C/C++, Java/Android, iOS (OC/Swift), Web (TS/JS/Vue) in one pass |
| **File classification** | Every file tagged as project code, third-party, or build artifact |
| **Library detection** | 50+ known libraries (FFmpeg, Boost, OpenSSL…) with version extraction |
| **Four-level verdicts** | Core Asset / Extract & Merge / Rebuild / Deprecate |
| **HTML reports** | Interactive dark-theme pages with drill-down navigation |
| **Monorepo support** | Hierarchical scanning with summary + sub-project reports |
## Analysis Depth Levels
| Level | Files Read | Use Case |
|---|---|---|
| `fast` | 1-2 per module | Quick inventory of huge directories |
| `standard` | 2-5 per module | Default audit with full dependency + architecture checks |
| `deep` | 5-10 per module | Adds thread safety, memory management, API consistency |
| `full` | All files | Pre-merge comprehensive review |
## How It Works
1. **Classify the repo surface**: enumerate files, then tag each as project code, embedded third-party code, or build artifact.
2. **Detect embedded libraries**: inspect directory names, headers, license files, and version markers to identify bundled dependencies and likely versions.
3. **Score each module**: group files by module or subsystem, then assign one of the four verdicts based on ownership, duplication, and maintenance cost.
4. **Highlight structural risks**: call out dead-weight artifacts, duplicated wrappers, outdated vendored code, and modules that should be extracted, rebuilt, or deprecated.
5. **Produce the report**: return a concise summary plus the interactive HTML output with per-module drill-down so the audit can be reviewed asynchronously.
## Examples
On a 50,000-file C++ monorepo:
- Found FFmpeg 2.x (2015 vintage) still in production
- Discovered the same SDK wrapper duplicated 3 times
- Identified 636 MB of committed Debug/ipch/obj build artifacts
- Classified: 3 MB project code vs 596 MB third-party
## Best Practices
- Start with `standard` depth for first-time audits
- Use `fast` for monorepos with 100+ modules to get a quick inventory
- Run `deep` incrementally on modules flagged for refactoring
- Review the cross-module analysis for duplicate detection across sub-projects
## Links
- [GitHub Repository](https://github.com/haibindev/repo-scan)
所有文件
1 个文件安装 repo-scan
下载技能文件并将其解压到 .claude/skills/ 目录中。
下载ZIP克隆仓库并复制技能文件到您的项目中。
git clone https://github.com/affaan-m/ECC/tree/main/skills/repo-scan # Copy SKILL.md to your .claude/skills/ directory
复制





首页
