Tech Debt Skill — Security skill for Claude Code
Claude Code skill that produces a thorough, file-cited tech debt audit of an entire codebase.
How to install Tech Debt Skill
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open ksimback/tech-debt-skill and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Tech Debt Skill does
Claude Code skill that produces a thorough, file-cited tech debt audit of an entire codebase.
Alternatives in Security
- Skill Audit — Audit codebases for quality, consistency, and broken patterns — use for pre-release or tech debt review 2.8k ★
- Tier 3 Code Refinement Report — Date: 2026-03-20 Status: ALL 54 FINDINGS IMPLEMENTED Scope: Full codebase (18 plugins, 888 files, ~266K lines) 222 ★
- Gdpr Review — Audit the codebase (or a given path/feature) for GDPR compliance and produce a prioritized findings report 172 ★
README
tech-debt-audit
A Claude Code skill that produces a thorough, citable tech debt audit of your entire codebase — not a generic best-practices checklist.
/tech-debt-audit
That's the whole interface. Run it in any repo, get back `TECH_DEBT_AUDIT.md` with file-cited findings, severity, effort estimates, and a ranked list of what to actually fix.
Why this exists
LLM-generated code reviews fail in a predictable way: they pattern-match against generic heuristics, surface obvious findings without grounding them in the actual code, and produce comprehensive-feeling output that nobody acts on. The result is a tab nobody opens twice.
This skill is opinionated about avoiding that failure mode. Three design choices do most of the work:
**Forced orientation before judgment.** The protocol requires the model to read the manifest, map the directory structure, analyze git churn, and write a mental model of the architecture *before* it forms any opinions. Phase 1 isn't optional. Findings without context are vibes.
**File:line citations on every finding.** A finding without a citation is unfalsifiable, and unfalsifiable findings don't get fixed. The skill rejects vague claims like "the code generally..." and requires `path/to/file.ext:LINE` on every concrete finding.
**A required "looks bad but is actually fine" section.** This is the single biggest separator between a real audit and a checklist regurgitation. Forcing the model to surface calls it considered making and chose not to is what catches shallow analysis. If that section comes back empty, the audit didn't look hard enough.
The skill also explicitly forbids recommending rewrites, forbids padding categories with filler, and produces a persistent artifact (`TECH_DEBT_AUDIT.md`) you can commit and track over time.
Why not the built-in Claude Code skills?
Claude Code ships several skills that touch this space. None of them do what a debt audit needs to do.
| Built-in | What it does | Why it's not a de
Related Skills
Gaia Debt
Fix the tech-debt backlog, a single issue or a recommended related batch, highest severity then oldest first,
Ctxinit
Claude Code skill that scaffolds a single-source context/ knowledge hub — engineering rules, security law, com
Arch Crusade
Unleash parallel Architecture Purist agents to audit layer boundaries, import graphs, and structural integrity
Audit Deep
Full-stack audit: architecture, code quality, performance, UX debt, security, test gaps. Produces prioritized
Audit Ur Harness
An Agent Skill that audits a project's AI harness — guardrails, memory, verification, observability, tool desi
Security Audit Review
Performs deep security audits on any codebase — finds vulnerabilities, exploits, and attack vectors. Supports
Related Agents
Audit Specialist
Use this agent for codebase audits — tech-debt audits, hotspot analysis, dead-code sweeps, coupling/churn fore
Tech Debt Verifier
Adjudicates a single candidate tech-debt finding produced by the tech-debt-assessor hunter. Independently re-r
Context Gatherer
Gathers minimal relevant context from codebase without pulling entire repo. Use before writing PRDs, tech spec