Home
cd ../playbooks
Developer ToolsIntermediate

Tech Debt Analyzer

Identify, analyze, document, and track technical debt in JavaScript/TypeScript codebases with automated detection and prioritized remediation plans.

10 minutes
By AI LabsSource
#tech-debt#code-quality#refactoring#javascript#typescript#maintenance

Your codebase has accumulated years of TODO comments, deprecated patterns, and copy-pasted modules — but you can't justify a refactoring sprint without data. This playbook scans JavaScript/TypeScript codebases to identify, quantify, and prioritize technical debt with actionable remediation plans.

Who it's for: engineering managers building data-driven cases for tech debt remediation sprints, tech leads identifying the highest-impact refactoring targets in legacy codebases, frontend developers tracking code quality degradation across React and Node projects, CTOs presenting technical debt reports to stakeholders with business impact estimates, senior engineers creating systematic debt reduction roadmaps for their teams

Example

"Analyze tech debt in our React/Node codebase and prioritize fixes" → Tech debt pipeline: automated codebase scan for deprecated APIs, duplicated code, and complexity hotspots, debt categorization (architecture, code quality, dependency, testing), severity and effort scoring for each debt item, prioritized remediation plan ranked by impact-to-effort ratio, and tracking dashboard showing debt reduction progress over sprints

CLAUDE.md Template

New here? 3-minute setup guide → | Already set up? Copy the template below.

# Technical Debt Analyzer

## Your Role
You are my technical debt specialist. Help me identify, analyze, document, and track technical debt in JavaScript/TypeScript codebases.

## Analysis Workflow

### Step 1: Automated Code Analysis
Detect code smells and issues:

**Code Quality Indicators**
- Large files (>500 lines)
- Complex functions (cyclomatic complexity >10)
- Debt markers (TODO, FIXME, HACK comments)
- Console statements in production code
- Weak typing (any, unknown overuse)
- Long parameter lists (>5 params)
- Deep nesting (>4 levels)
- Magic numbers

**Dependency Analysis**
- Deprecated packages
- Duplicate functionality
- Version conflicts
- Security vulnerabilities

### Step 2: Manual Code Review
Review areas automation can't catch:
- Architectural debt
- Test debt (coverage, reliability)
- Documentation gaps
- Performance issues
- Security vulnerabilities

### Step 3: Categorization

**Nine Debt Categories**
1. **Code Quality**: Complexity, readability, maintainability
2. **Architectural**: Design patterns, coupling, cohesion
3. **Test**: Coverage gaps, flaky tests, missing tests
4. **Documentation**: Outdated docs, missing examples
5. **Dependency**: Outdated packages, vulnerabilities
6. **Performance**: Slow paths, memory issues
7. **Security**: Vulnerabilities, unsafe patterns
8. **Infrastructure**: CI/CD, deployment, monitoring
9. **Design**: API design, interface issues

**Severity Levels**
| Level | Action | Timeframe |
|-------|--------|-----------|
| Critical | Fix immediately | Now |
| High | Current/next sprint | 1-2 weeks |
| Medium | Plan quarterly | 1-3 months |
| Low | Opportunistic | When convenient |

### Step 4: Documentation

**Tech Debt Register Template**
```markdown
# Technical Debt Register

## Active Items

### [DEBT-001] [Title]
- **Category**: [Code Quality/Architectural/etc.]
- **Severity**: [Critical/High/Medium/Low]
- **Location**: [file(s) affected]
- **Description**: [What's wrong]
- **Impact**: [Why it matters]
- **Proposed Solution**: [How to fix]
- **Effort Estimate**: [T-shirt size]
- **Created**: [Date]
- **Owner**: [Who's responsible]

### [DEBT-002] ...

---

## Resolved Items
[Moved here when fixed]

---

## Won't Fix
[With justification]

---

## Trends
[Summary of debt over time]
```

**Architecture Decision Record (ADR) Template**
```markdown
# ADR-[XXX]: [Title]

## Status
[Proposed/Accepted/Deprecated/Superseded]

## Context
[Why this decision was needed]

## Decision
[What was decided]

## Consequences
[Positive and negative outcomes]

## Alternatives Considered
[Other options evaluated]
```

### Step 5: Prioritization

**Sprint Allocation**
- Recommend 20% capacity for tech debt
- Focus on high-impact, low-effort items first

**Prioritization Matrix**
| Impact ↓ / Effort → | Low | Medium | High |
|---------------------|-----|--------|------|
| High | Do first | Schedule | Plan carefully |
| Medium | Do soon | Evaluate | Defer |
| Low | Quick wins | Defer | Don't do |

### Step 6: Prevention Strategies

**Weekly**
- Review new TODO/FIXME comments
- Code review for new debt introduction

**Monthly**
- Dependency updates
- Security scanning
- Coverage review

**Quarterly**
- Full codebase analysis
- Debt register review
- Architecture review

**Automated Enforcement**
```json
// Example linting rules
{
  "rules": {
    "no-console": "error",
    "complexity": ["error", 10],
    "max-lines": ["warn", 500],
    "@typescript-eslint/no-explicit-any": "error"
  }
}
```

**CI/CD Integration**
- Strict TypeScript mode
- 80% minimum test coverage
- Security vulnerability scanning
- Complexity thresholds

## Success Metrics

| Metric | Target | Current |
|--------|--------|---------|
| Total debt items | Decreasing | [X] |
| Critical items | 0 | [X] |
| Test coverage | >80% | [X%] |
| Avg complexity | <10 | [X] |
| Resolution velocity | Consistent | [X/week] |

## Report Template

```markdown
# Tech Debt Report: [Date]

## Summary
- Total items: [X]
- Critical: [X] | High: [X] | Medium: [X] | Low: [X]
- New this period: [X]
- Resolved this period: [X]

## Top Priority Items
1. [DEBT-XXX]: [Title] - [Why urgent]
2. ...

## Trends
[Improving/Stable/Degrading]

## Recommendations
1. [Action item]
2. [Action item]

## Next Review
[Date]
```

## Best Practices
- Document every significant debt item
- Link debt to business impact
- Make debt visible to stakeholders
- Celebrate debt resolution
- Prevent new debt with automation

Get new playbooks like this one

One email a week with new Claude Code workflows. Free, like everything here.

No spam. Unsubscribe anytime.

README.md

What This Does

Systematically identify and track technical debt in JavaScript/TypeScript projects. Automated analysis detects code smells, dependency issues, and quality problems. Get prioritized remediation plans and documentation templates.


Quick Start

Step 1: Navigate to Your Project

cd ~/your-js-project

Step 2: Download the Template

Click Download above, then:

mv ~/Downloads/CLAUDE.md ./

Step 3: Analyze Your Codebase

claude

Then ask: "Analyze this codebase for technical debt"


What Gets Detected

Automated Analysis

Category Indicators
Code Quality Large files (>500 lines), complex functions
Debt Markers TODO, FIXME, HACK comments
Bad Practices Console statements, weak typing
Complexity Deep nesting (>4 levels), long params

Manual Review Areas

Category Focus
Architecture Design patterns, coupling
Testing Coverage gaps, flaky tests
Documentation Outdated docs, missing examples
Dependencies Outdated packages, vulnerabilities

Severity Levels

Level Action Examples
Critical Fix immediately Security issues, broken builds
High Current/next sprint Major blockers
Medium Plan quarterly Refactoring needs
Low Opportunistic Nice-to-haves

Example Prompts

  • "Scan for technical debt in this project"
  • "Find all TODO and FIXME comments"
  • "Analyze dependency health"
  • "Create a tech debt remediation plan"
  • "Generate a tech debt register"

Nine Debt Categories

  1. Code Quality: Complexity, readability
  2. Architectural: Design issues, coupling
  3. Test Debt: Coverage, reliability
  4. Documentation: Outdated, missing
  5. Dependency: Outdated, vulnerable
  6. Performance: Slow code paths
  7. Security: Vulnerabilities
  8. Infrastructure: CI/CD, deployment
  9. Design: API, interface issues

Recommended Capacity

20% of sprint capacity for tech debt maintenance.


Maintenance Schedule

Frequency Activity
Weekly Review TODO/FIXME comments
Monthly Dependency updates
Quarterly Full codebase analysis

Tips

  • Track everything: Use a debt register
  • Prioritize ruthlessly: Not all debt needs fixing
  • Automate detection: Integrate into CI/CD
  • Document decisions: Use ADRs for context

$Related Playbooks

Developer Tools

Test Specialist

Comprehensive JavaScript/TypeScript testing guidance with test writing, bug analysis, coverage analysis, and proactive issue detection.

10 minutes
Intermediate
Developer Tools

Accessibility Engineering for Components

Build accessible UI components at the code level, not just the audit level — 14 concrete engineering principles (focus-visible over bare :focus, roving tabindex for composite widgets, inert-based modal focus trapping, WCAG 2.5.8 hit-area minimums), a common-mistakes table with fixes, and a severity-rated review format ending in a hard Block/Needs-changes/Approve verdict.

5 minutes
Intermediate
Developer Tools

Adversary Emulation: MuddyWater

An intelligence-grounded, authorized purple-team emulation profile for MuddyWater (MITRE ATT&CK G0069), Iran's MOIS-linked cyber-espionage group — attribution, targeting, representative TTPs by ATT&CK tactic, emulation guidance mapped to generic red-team tooling, and paired detection/defense recommendations for every offensive technique, all under an explicit authorized-use caveat.

15 minutes
Advanced
Developer Tools

Adversary Emulation: Turla

An intelligence-grounded, authorized purple-team emulation profile for Turla (MITRE ATT&CK G0010), Russia's FSB-linked espionage group — attribution, distinctive TTPs (satellite C2 hijacking, steganographic email backdoors, parasitizing rival APT infrastructure), emulation guidance mapped to generic red-team tooling, and paired detection recommendations, under an explicit authorized-use and lab-only caveat for rootkit techniques.

15 minutes
Advanced
Developer Tools

AI Agent Red Team Methodology

A first-principles methodology for authorized red-team exercises against AI products, agents, MCP servers, skills, and repositories — capability and trust-boundary modeling, AI-specific attack hypothesis families (prompt injection, tool misuse, data leakage, SSRF), harmless-proof testing with canaries, one-variable-at-a-time adaptive iteration, and business-language evidence-based reporting.

10 minutes
Advanced
Developer Tools

Contribution PR Review

Review an external contributor's PR the way an open-source maintainer should — check automated bot security findings first (across every channel they might post to), watch specifically for suspicious AGENTS.md or workflow-permission changes, scale size and test-coverage expectations by contributor experience, and separate intent/scope alignment from code quality that bots already covered.

10 minutes
Intermediate
Developer Tools

Datadog Error Triage to PR

Take Datadog Error Tracking issues from raw occurrence counts to a reviewable, tested PR — a five-class bug taxonomy that filters out infra noise and deploy-skew before ranking, a recency premium that catches fresh regressions early, a mandatory approval gate before any fix is written, and a test-first fix workflow that generalizes past the one reported occurrence.

10 minutes
Advanced
Developer Tools

React Native Video (v6 & v7)

Give correct react-native-video guidance by detecting the installed major version first — v6's imperative <Video> component and v7's completely different useVideoPlayer/VideoView player-object model share a name but no API, and mixing them up is the single most common mistake when helping with this library.

5 minutes
Intermediate
Developer Tools

React Three Fiber Animation Reference

Animate React Three Fiber scenes correctly — useFrame fundamentals with render priority, full GLTF animation control via useAnimations (playback, crossfade, event listeners, speed-based blending between Idle/Walk/Run), @react-spring/three physics animations with gesture and chain integration, and the five performance rules that keep per-frame updates from triggering React re-renders.

10 minutes
Intermediate
Developer Tools

Reshape PR Commits

Turn a branch's messy WIP/fixup commit history into a clean, logically-grouped set of commits before review — proposed regrouping with explicit approval, git reset --soft plus staged re-commits instead of interactive rebase, and hard guardrails (feature branches only, force-with-lease only, never touch another author's commits).

5 minutes
Intermediate
Developer Tools

Planning with Files

Persistent, file-based planning for multi-step AI-agent work — task_plan.md, findings.md, and progress.md on disk, a 2-action rule for capturing multimodal findings before they're lost, a 3-strike error protocol, and a 5-question reboot test to verify state survives a compaction.

5 minutes
Intermediate
Developer Tools

PR Queue Triage

Clear a backlog of open pull requests before a release by classifying every PR into an evidence-based disposition — never by title — with a real git merge-tree test against the actual release branch, not the platform's often-wrong mergeable flag.

10 minutes
Intermediate

Browse all Developer Tools playbooks →