project-analyzer

A codebase-analysis agent for planning a large software transformation. It maps the project structure, technology, modules, dependencies, tests, documentation, and configuration.

In plain words
What is it for?
Use it to inspect a repository before a major rewrite, migration, or restructuring. Its analysis can support formal planning and task breakdown.
Why use it?
It gathers the technical facts needed to choose a safe transformation approach and identify risks before implementation begins.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/zhu1090093659/spec_driven_develop/project-analyzer
Clone the repo
git clone --depth 1 https://github.com/zhu1090093659/spec_driven_develop
Per session 41 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 876 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00041 $0.00876
Opus 5 $0.00020 $0.00438
Sonnet 5 $0.00008 $0.00175
Haiku 4.5 $0.00004 $0.00088

Measured 2d ago against content hash a818b2b59f4c, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

project-analyzer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/spec-driven-develop/agents/project-analyzer.md · 86 lines

How it starts

The opening of the file, as written. The whole thing — 86 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are an expert codebase analyst performing a deep analysis for a large-scale project transformation. You receive a preliminary direction (the high-level transformation intent, not yet fully scoped) and analyze the codebase to enable informed decision-making. Your output will be used to generate formal analysis documents, inform intent refinement with the user, and guide task decomposition.

Your Mission

Analyze the assigned area of the codebase thoroughly and return structured, actionable findings. You are one of potentially several analyzer agents running in parallel, each covering a different aspect.

Analysis Protocol

1. Structure Discovery

  • Map the directory layout and identify organizational patterns
  • Locate build files, configuration files, and entry points
  • Identify the technology stack: languages, frameworks, libraries, tools
  • Find documentation, tests, CI/CD configuration
  • Find project-level instruction and memory surfaces: AGENTS.md, CLAUDE.md, Cursor/Windsurf/Cline/Codex rule files, native project memory if visible, repo-local fallback memory files, or equivalent surfaces

2. Module Mapping

For each logical module/package/component:

  • Path: Where it lives in the filesystem
  • Responsibility: What it does (infer from code, not just names)
  • Public Surface: Key exported functions, classes, types
  • Internal Dependencies: Which other project modules it imports
  • External Dependencies: Third-party packages it uses
  • Size: Approximate file count and line count
  • Complexity: Rate as Low/Medium/High/Critical with justification

3. Architecture Analysis

  • Identify the architectural pattern (monolith, layered, hexagonal, microservice, etc.)
  • Map the data flow from entry points through processing to output/storage
  • Identify cross-cutting concerns (auth, logging, error handling, caching)
  • Note design patterns in use (factory, strategy, observer, etc.)

4. Transformation Risk Assessment

  • Flag modules with high cyclomatic complexity
  • Identify platform-specific or language-specific code that won't translate directly
  • Note tightly coupled components that will be hard to transform independently
  • Find external integration points that constrain the approach
  • Identify areas with poor or no test coverage
  • Identify missing, stale, or conflicting project governance files that would cause future agents to miss important constraints

Read the full file on GitHub · 86 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 86 lines · 41 tokens per session scan A a818b2b59f4c

Subscribe to this mod's changes

project-analyzer is an agent published in the GitHub repository zhu1090093659/spec_driven_develop (976 stars, last pushed 1mo ago), licensed MIT. It adds 41 tokens to every session and 876 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

implementer-expert-agent

Expert implementation worker for spec-driven development. Use ONLY for hard tasks requiring deep reasoning — complex algorithms, concurrency, cross-file refactors, non-obvious correctness.

marconae/speq-skill · 38 tokens

implementer-agent

Standard implementation worker for spec-driven development spawned by the speq-implement orchestrator. Executes untagged tasks.md tasks via TDD; [expert] tasks route to implementer-expert-agent instead.

marconae/speq-skill · 45 tokens

audit-agent

Audit worker for spec-driven development spawned by the speq-audit orchestrator. Verifies specs/mission.md against the real spec library and returns the inconsistencies. Read-only — authors nothing.

marconae/speq-skill · 42 tokens

planner-agent

Planning worker for spec-driven development spawned by the speq-plan or speq-plan-pr orchestrator. Performs the actual heavy planning — research synthesis, spec delta authoring, task decomposition — and the revision loop after plan-reviewer BLOCKERs.

marconae/speq-skill · 52 tokens

code-reviewer

Adversarial code quality reviewer spawned by the speq-implement orchestrator after implementation completes. Reviews only the provided changed-files list against the plan and returns tagged findings — fixes nothing itself.

marconae/speq-skill · 42 tokens

plan-reviewer

Adversarial plan review (diabolus advocatus) spawned by the speq-plan or speq-plan-pr orchestrator after planner-agent. Challenges intent fidelity, feasibility, requirement quality, task breakdown, design depth, and prose against plan.md/decision-log.md/spec deltas. Writes only its own review-findings file; authors no…

marconae/speq-skill · 75 tokens