code-assessment

v2026.09.24

Detect, review, and fix code-quality and correctness issues in an AEM as a Cloud Service project — locally, with no external services or network calls. Use whenever a user wants to check, review, assess, audit, scan, modernize, upgrade, or fix AEM Java, Sling Models, OSGi, or Maven code — for example: "check my Sling Models are implemented correctly", "review my @Inject usage", "are my Maven dependencies up to date", "scan this AEM project for issues", "modernize my Sling Models", or "fix code-quality problems". Name the files to assess, or ask it to scan the repo; it detects issues, plans, and — only when you ask — applies surgical edits on a branch or in place, then verifies with mvn compile. It recognises the intent and handles each issue type itself, reporting anything it cannot yet fix.

GitHub
安装命令
npx skhub add adobe/code-assessment
Markdown
SKILL.md

AEM as a Cloud Service — Code Assessment

Single skill for detecting and fixing AEM CS code-quality issues, entirely against the local workspace — no external services or network calls. Findings reach the runbook from one of two sources; everything downstream is identical.

Findings sources

SourceWhenTarget versions (deps)
User-namedthe user names files or coordinatesuser-supplied
Discoverthe user asks to scan, or names no filesuser-supplied (per the pattern's resolution contract)

Discovery runs through the deterministic analyzer (scripts/analyze.sh): it parses the workspace once and runs the enabled detectors, emitting the shared findings shape. Every ready pattern has an analyzer detector. One detector — remove-deprecated-api — loads its rules dynamically from a preflight-produced cache (remove-deprecated-api/scripts/detect.sh runs the AEM Analyser Maven Plugin and writes the cache TSV before the analyzer is invoked); the detector's shape and integration are otherwise identical. Patterns without a detector are planned only — not yet detectable and not yet built; there is no LLM-scan fallback in this version (see Scope & limitations) — the scan value on planned rows in references/patterns.md marks the intended future detection method, not an active code path.

Routing

  1. User named files / coordinates → run the runbook in with_findings mode against those paths.
  2. "Scan my repo" / no files named → run the runbook in discover mode (per-pattern Discovery, workspace roots only).

Then follow the runbook: references/runbook.md.

Manual Pattern Hints (classification → expert skill)

Route the request to one expert skill. Two pattern families share this skill:

Mechanical fixes (analyzer-driven detection, deterministic edits — follow the runbook flow):

User said / sawExpert skill
"update aem sdk", "upgrade mockito", stale <version> or ${property} in pomoutdated-dependencies/
"fix @Inject", "modernize Sling Models", javax.inject.Inject on @Model fieldsinject-in-sling-model/
"add HTTP timeouts", "outbound/external call has no timeout", HttpClient / HttpClients / OkHttpClient built without a timeoutoutbound-call-timeouts/
"bound my query", "unbounded query", "query causing OOM", p.limit=-1, setLimit(-1)unbounded-query/
"remove deprecated API", "fix deprecated imports", "Cloud Manager deprecated API failure", region-deprecated-api / api-regions-check / Import-Package not satisfied pipeline failures, log4j migration, commons-lang/collections upgrades, deprecated Maven deps, unmodifiable OSGi configsremove-deprecated-api/ (analyzer detector with dynamic rules — preflight runs aemanalyser-maven-plugin; hint-driven fixes; see recipe.md)

Architectural migration patterns (guided remediation — full before/after, troubleshooting, modern alternatives; invoked directly or via migration for BPA/CAM-driven discovery):

User said / sawExpert skillBPA pattern ID
org.apache.sling.commons.scheduler.Scheduler or scheduler.schedule( with Runnablescheduler/scheduler
implements ResourceChangeListener, lightweight listener + JobConsumerresource-change-listener/resourceChangeListener
com.day.cq.replication.Replicator, org.apache.sling.replication.*, "publish/preview activation"replication/replication
javax.jcr.observation.EventListener, org.osgi.service.event.EventHandler on non-resource topics (replication, workflow, custom)event-migration/eventListener / eventHandler
com.day.cq.dam.api.AssetManager create/upload/delete APIs, createAssetForBinary, removeAssetForBinaryasset-manager/assetApi
HTL build warning data-sly-test: redundant constant value comparisonreferences/data-sly-test-redundant-constant.mdhtlLint (reference, no expert skill subdirectory)

Broad / correctness-review asks ("check my Sling Models are implemented correctly", "review my code", "is my AEM project healthy", "assess this project") are not a single pattern: run the runbook in discover mode with intent report — the analyzer runs every detector and the report covers all built patterns, explicitly noting aspects not yet supported. Only narrow to one pattern when the user targets a specific fix.

If nothing matches, say the issue is not yet supported and offer to file a request for a new expert skill.

Full catalog (built + planned patterns, with severity / detection / fix): references/patterns.md.

Invocation from the migration skill

migration performs BPA/CAM/MCP discovery and handles batching + one-pattern-per-session workflow. After it has identified (pattern, file) pairs from BPA findings, it hands off here for the actual transformation. When invoked with (pattern, file) from migration:

  • Skip HA/analyzer discovery (caller already identified the pattern + file)
  • Open the pattern's expert skill directly (per the Manual Pattern Hints table above)
  • Apply the steps in the expert skill against the named file(s)
  • Return the result; migration continues with the next finding in its batch

The pattern guides themselves are agnostic about who invoked them — they apply identically whether reached from migration (BPA/CAM) or from the runbook in this skill (HA / analyzer).

Runbook

All detection, planning, edits, verification, git/in-place handling, and the run log live in references/runbook.md. The runbook is the sole owner of repo-environment detection (edit_mode, git snapshot) — this control plane does not duplicate it.

One pattern per session

Report may span every pattern found; apply touches one pattern per session (atomic revert, single-story diff). Refuse "fix everything" for the apply phase. Rationale: references/shared-principles.md.

Critical rules

  • Local only — no network calls or external services; operate solely on the workspace. Documented exception: remove-deprecated-api is plugin-driven and needs Maven Central (to resolve aemanalyser-maven-plugin and, transitively, the AEM SDK's api-regions data) plus optionally Adobe Experience League as a fallback source for successor guidance. If offline, that one pattern is skipped with a clear message; all other patterns remain local-only.
  • Requires a local JDK (Java 11+) for detection — the analyzer compiles/runs in memory; no install beyond the JDK, no network. If absent, detection stops with a clear message.
  • The analyzer is detection — never substitute external tooling. Do not run mvn versions:display-dependency-updates / mvn versions:display-property-updates, npm outdated, or Maven Central / registry lookups in place of analyzer discovery. Those answer "what is the latest on the network" — outside this skill's local-only contract. If the user explicitly wants a live registry comparison, say it needs network and offer it as a separate step after delivering the skill report. remove-deprecated-api's preflight (remove-deprecated-api/scripts/detect.sh) is the one documented exception: it invokes the AEM Analyser Maven Plugin against the project to populate its rules cache, then hands off to the shared analyzer.
  • Never commit, push, or open a PR — branch (git) or in-place edits only; the developer reviews and commits.
  • Surgical edits — no reformatting / re-serialization.
  • Skip with a reason — record un-applicable findings as skipped with an exact reason; never silently drop.
  • One pattern per session for apply.

Full rationale: references/shared-principles.md.

Scope & limitations

Local static detection and remediation only — no external services, no network, no live AEM instance. Issues that require runtime or live-repository state, telemetry, or history across runs are out of scope for this skill. Detection requires a local JDK (Java 11+); there is no remote or LLM-scan fallback in this version. A large apply (e.g. an @Inject migration across 100+ files) is processed in resumable batches: the run checkpoints each file to .autofix/last-run.json and pauses at a per-pass cap, so it survives context limits — reply apply <pattern> to continue (see references/git-workflow.md).

Adding a new pattern

Full end-to-end procedure — detector → fixtures/tests → catalog + routing → expert skill → verify: references/adding-a-pattern.md. The [wiring] test keeps the detector, catalog row, and expert-skill directory in sync.

Triggering scales without touching the description. The description above is intentionally broad (intent verbs + AEM domain), so it already fires on "check / review / fix my <AEM thing>"; a new pattern is reached by its Manual Pattern Hints + patterns.md rows, not by editing the description. Update the description only if the new pattern introduces a domain keyword it does not already cover (a new subsystem or file type). The [wiring] test keeps the detector, catalog row, and expert-skill directory in sync.

Related skills

  • migration — drives BPA/CAM/MCP-based legacy-AEM migration workflow. Discovers findings, batches them, enforces one-pattern-per-session, and hands off (pattern, file) pairs to this skill for transformation. See the "Invocation from the migration skill" section above.
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

Apache-2.0

源路径

plugins/aem/cloud-service/skills/code-assessment

默认分支

main

最新提交

e26e61d

Tree SHA

b0267ec