codebase-recon

A repository analysis tool that builds a traceable model of a codebase and its entry-to-test paths. A repository is the project's files and version history.

In plain words
What is it for?
Use it to map a repository, audit specific areas, refresh an earlier analysis, or inspect persistence, authentication, command-line, build, or test code.
Why use it?
It helps you understand how the code works while separating verified facts from assumptions.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/boshu2/agentops/codebase-recon
Any agent
npx skills add boshu2/agentops --skill codebase-recon
Clone the repo
git clone --depth 1 https://github.com/boshu2/agentops

Made for: Claude Code, Codex.

Per session 43 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,365 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00043 $0.02365
Opus 5 $0.00022 $0.01182
Sonnet 5 $0.00009 $0.00473
Haiku 4.5 $0.00004 $0.00236

Measured yesterday against content hash 9511fbcaf578, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

codebase-recon scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

images/gemini/skills/codebase-recon/SKILL.md · 226 lines

How it starts

The opening of the file, as written. The whole thing — 226 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Codebase Recon

Build a reusable, falsifiable model of a repository. This skill reports what the tree and executable probes support; it does not edit code or issue a final PASS/WARN/FAIL verdict.

Constraints

  • To prevent a floating recon, record the exact repository commit and local source-of-truth precedence.
  • Because confidence is not evidence, type every material claim and cite each fact and inference.
  • To preserve traceability, prefer a verified delta when a prior pack exists instead of rewriting unchanged evidence as fresh discovery.

Modes, views, and lenses

One skill replaces a cluster of loose recon skills. Steer it with mode, view emphasis, lens, and depth — do not invent a second skill for each shape.

Control Values Use when
Mode baseline | delta First pack vs refresh after a prior recon
View emphasis mental model · bounded audit · pattern evidence · synthesis Archaeology-style map, audit-style findings, pattern harvest, or executive synthesis
Lens persistence · auth · CLI · build · test (one per pass) Domain-deep cut instead of a shallow whole-tree sweep
Depth quick · standard · deep Orientation vs onboarding vs decision-grade evidence

Ask for the shape explicitly, for example:

codebase-recon --mode=delta --view=audit --lens=cli --depth=standard
codebase-recon baseline, mental-model view, persistence lens, deep

Natural-language equivalents count. The durable pack still carries all four views; emphasis changes what you spend tokens on and what the companion report leads with. Pattern packaging beyond evidence pointers belongs in pattern-mining. Binding PASS/FAIL stays with validate.

Workflow

  1. Record the current commit and the repository's local source-of-truth precedence. Search for validated prior manifests before starting with skills/codebase-recon/scripts/validate-output.sh --repo-root <target> --discover-priors. Successful empty output means no prior pack exists at either documented default.
  2. If no prior pack exists, use baseline mode. If one exists, verify its still-valid claims against the current commit and use delta mode. Preserve valid evidence by reference and describe only changed paths and synthesis.
  3. Trace representative paths from entry point to domain logic, integration boundary, and test. Prefer a few complete flows over a broad file inventory.
  4. Keep four views distinct in the report: mental model, bounded audit, pattern evidence, and synthesis. Label each claim fact, inference, or unknown, assign confidence, and cite evidence for facts and inferences.
  5. List inspected and uninspected scope. Write the JSON manifest and companion report, then run the validator. Missing evidence and hidden coverage gaps are contract failures, not prose caveats.

Read the full file on GitHub · 226 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 226 lines · 43 tokens per session scan A 9511fbcaf578

Subscribe to this mod's changes

codebase-recon is a skill published in the GitHub repository boshu2/agentops (431 stars, last pushed 3d ago), licensed Apache-2.0. It adds 43 tokens to every session and 2,365 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

brainstorm

Explore vague or ambitious ideas into a right-sized requirements-only plan. Use when the user wants to brainstorm, think through scope, decide what to build, or needs collaborative product framing before planning, not for a decisive verdict on whether to adopt or switch to a specific external technology, library, or…

OutlineDriven/odin-claude-plugin · 85 tokens

doc-review

Use when the user asks to review or critique a prose planning document — a plan, spec, PRD, requirements doc, or design doc.

OutlineDriven/odin-claude-plugin · 32 tokens

audit-project

Run an iterative multi-agent code audit until critical and high findings are resolved. Use when the user says "audit my code", "find all the bugs", "deep code audit", "iterative review", or "review until clean".

OutlineDriven/odin-claude-plugin · 50 tokens

autolearn

Compound a solved problem into a durable in-repo learning doc. Use when a verified non-trivial fix lands, the user says "compound this", "document this fix", or "remember this". This is the automatic-capture entry point; for an explicitly requested one-off write-up, use compound.

OutlineDriven/odin-claude-plugin · 65 tokens

doubt-driven

Doubt-driven adversarial review. Use when correctness matters more than speed, the code is unfamiliar, stakes are high, a claim can't be checked by the type system or compiler, or verifying now is cheaper than debugging later.

OutlineDriven/odin-claude-plugin · 49 tokens

drift-detect

Use when the user says "plan drift", asks whether the roadmap, plans, or docs still match the code, or is deciding what to rebuild when restarting a stalled project. For doc-vs-code drift inside a specific diff, use sync-docs.

OutlineDriven/odin-claude-plugin · 56 tokens