Scanning for Issues

SkillSecurity

Passive codebase scan — find potential bugs, anti-patterns, security issues. Spawns subagents if available.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Scanning for Issues skill

What this skill tells your AI

The instructions your AI receives, as published by neuron-mr-white/unipi in packages/workflow/skills/scan-issues/SKILL.md and read by ahel’s review.

Passive investigation of codebase to find potential bugs, anti-patterns, security issues, and technical debt.

Boundaries

This skill MAY: read codebase, run read-only analysis commands, spawn subagents, write findings. This skill MAY NOT: edit code, fix issues, run tests that modify state, deploy.

This is investigation only — not fixing.

Note: For active debugging of specific bugs, use /unipi:debug instead. scan-issues finds potential problems; debug diagnoses known issues.

Command Format

/unipi:scan-issues <string(greedy)>(optional)
  • string(greedy) — optional scope (e.g., "focus on auth", "check for SQL injection", "find dead code")
  • If not provided → full codebase scan
  • Read-only sandbox
  • Spawns subagents if @unipi/subagents extension is installed

Process

Phase 1: Determine Scope

If scope provided:

  1. Parse the focus area
  2. Determine scan type:
    • Security scan
    • Bug hunt
    • Anti-pattern detection
    • Tech debt assessment
    • Performance issues

If no scope:

  1. Ask user what to focus on, or
  2. Run broad scan covering all categories

Exit: Scope defined.

Phase 2: Deep Investigation

If subagents available:

  1. Spawn parallel subagents for different scan types
  2. Each subagent investigates independently
  3. Collect findings from all subagents

If no subagents:

  1. Investigate sequentially
  2. Use grep, find, read commands
  3. Build findings incrementally

Scan categories:

Security:

  • Hardcoded secrets/credentials
  • SQL injection vulnerabilities
  • XSS vulnerabilities
  • Insecure dependencies
  • Missing input validation
  • Exposed sensitive data

Bugs:

  • Null/undefined handling
  • Race conditions
  • Error handling gaps
  • Edge cases missed
  • Logic errors
  • Off-by-one errors

Anti-patterns:

  • Code duplication
  • God objects/functions
  • Circular dependencies
  • Tight coupling
  • Magic numbers/strings
  • Inconsistent patterns

Tech debt:

  • TODO/FIXME comments
  • Deprecated API usage
  • Outdated dependencies
  • Dead code
  • Missing tests
  • Poor naming

Performance:

  • N+1 queries
  • Unnecessary re-renders
  • Large bundle imports
  • Missing caching
  • Inefficient algorithms

Exit: Findings collected.

Phase 3: Categorize & Prioritize

Organize findings by severity:

Critical (P0):

  • Security vulnerabilities
  • Data loss risks
  • Production-breaking bugs

High (P1):

  • Significant bugs
  • Major anti-patterns
  • Performance bottlenecks

Medium (P2):

  • Minor bugs
  • Tech debt
  • Code smells

Low (P3):

  • Style issues
  • Minor improvements
  • Nice-to-haves

Phase 4: Present Findings

## Issue Scan Results

### Critical (P0)
- {Finding} — {file:line} — {description}

### High (P1)
- {Finding} — {file:line} — {description}

### Medium (P2)
- {Finding} — {file:line} — {description}

### Low (P3)
- {Finding} — {file:line} — {description}

### Summary
- Total issues: {count}
- Critical: {count}
- High: {count}
- Medium: {count}
- Low: {count}

Phase 5: Handoff

Based on findings:

If critical issues found:

"Critical issues found. Recommend addressing immediately."

/unipi:quick-work "fix critical security issue in auth.ts"

If many issues:

"Multiple issues found. Consider planning a cleanup sprint."

/unipi:brainstorm "tech debt cleanup plan"

If few/no issues:

"Codebase looks healthy. No critical issues found."

/unipi:consolidate

Notes

  • Investigation only — findings are reported, not fixed
  • Subagent support enables parallel scanning when available
  • Can focus on specific categories or scan broadly
  • Prioritized findings help triage what to fix first
  • Natural lead-in to quick-work (for critical) or brainstorm (for planned cleanup)

Differences from debug

Aspect/unipi:scan-issues/unipi:debug
PurposeFind potential issuesInvestigate specific bug
InputScope / categoryBug report / error message
OutputIssue list with prioritiesDebug report with root cause
DepthBroad codebase scanDeep single-issue analysis
Handoff/unipi:quick-work or /unipi:brainstorm/unipi:fix

Signals

GitHub stars
64
Forks
15
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
scan-issues
Source
github.com/neuron-mr-white/unipi