Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
github avatar

Acquire Codebase Knowledge

  • 1.4k installs
  • 37.1k repo stars
  • Updated July 28, 2026
  • github/awesome-copilot

Acquire Codebase Knowledge is a CLI documentation generator that scans a project root, analyzes source manifests and configs, and produces seven verified documents mapping stack, structure, architecture, conventions, int

About

Acquire Codebase Knowledge is a CLI skill that produces seven structured documents (STACK, STRUCTURE, ARCHITECTURE, CONVENTIONS, INTEGRATIONS, TESTING, CONCERNS) covering everything needed to work effectively on a project. It runs a Python scan script from the target project root to detect languages, frameworks, CI/CD pipelines, containers, security configs, and testing patterns. Every claim is traceable to source files or terminal output; unknowns are marked [TODO] and intent-dependent decisions [ASK USER]. Supports monorepos, TypeScript path aliases, and 25+ languages with validation against inquiry checkpoints.

  • Generates seven verified documents in docs/codebase/ with evidence traceability and validation loop
  • Multi-language manifest detection (25+ languages) plus CI/CD (10+ platforms), containers, security, and performance metr
  • Focus area mode: prioritize specific documentation areas while maintaining phase 1-4 workflow integrity
  • Map, document, and onboard developers into existing codebases via automated scan and seven-document deliverable
  • Map, document, and onboard developers into existing codebases via automated scan and seven-document deliverable

Acquire Codebase Knowledge by the numbers

  • 1,357 all-time installs (skills.sh)
  • +69 installs in the week ending Jul 28, 2026 (Skillselion tracking)
  • Ranked #213 of 1,901 Documentation skills by installs in the Skillselion catalog
  • Security screen: LOW risk (skills.sh audit)
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

acquire-codebase-knowledge capabilities & compatibility

Capabilities
code scanning · manifest detection · ci cd detection · container detection · security config analysis · metrics collection · documentation generation
Works with
github · gitlab
Use cases
documentation · refactoring · code review
Platforms
macOS · Windows · Linux · WSL
Runs
Runs locally
Pricing
Free
npx skills add https://github.com/github/awesome-copilot --skill acquire-codebase-knowledge

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs1.4k
repo stars37.1k
Security audit3 / 3 scanners passed
Last updatedJuly 28, 2026
Repositorygithub/awesome-copilot

What it does

Map, document, and onboard developers into existing codebases via automated scan and seven-document deliverable

Who is it for?

Onboarding developers into unfamiliar codebases, documenting existing projects before major refactors, and establishing shared understanding across distributed teams

Skip if: Routine feature implementation, bug fixes, or narrow code edits unless explicitly requested; projects with no version control or manifest files

When should I use this skill?

User explicitly asks to 'map this codebase', 'document this architecture', 'onboard me to this repo', or 'create codebase docs'

What you get

Seven interconnected documents providing verifiable stack inventory, architectural patterns, conventions, integration points, testing strategy, and known concerns

  • architecture brief
  • system flow diagram
  • layer responsibility table

By the numbers

  • Supports 25+ languages via manifest detection
  • Detects CI/CD pipelines across 10+ platforms
  • Produces exactly 7 required output documents

Files

SKILL.mdMarkdownGitHub ↗

Acquire Codebase Knowledge

Produces seven populated documents in docs/codebase/ covering everything needed to work effectively on the project. Only document what is verifiable from files or terminal output — never infer or assume.

Output Contract (Required)

Before finishing, all of the following must be true:

1. Exactly these files exist in docs/codebase/: STACK.md, STRUCTURE.md, ARCHITECTURE.md, CONVENTIONS.md, INTEGRATIONS.md, TESTING.md, CONCERNS.md. 2. Every claim is traceable to source files, config, or terminal output. 3. Unknowns are marked as [TODO]; intent-dependent decisions are marked [ASK USER]. 4. Every document includes a short "evidence" list with concrete file paths. 5. Final response includes numbered [ASK USER] questions and intent-vs-reality divergences.

Workflow

Copy and track this checklist:

- [ ] Phase 1: Run scan, read intent documents
- [ ] Phase 2: Investigate each documentation area
- [ ] Phase 3: Populate all seven docs in docs/codebase/
- [ ] Phase 4: Validate docs, present findings, resolve all [ASK USER] items

Focus Area Mode

If the user supplies a focus area (for example: "architecture only" or "testing and concerns"):

1. Always run Phase 1 in full. 2. Fully complete focus-area documents first. 3. For non-focus documents not yet analyzed, keep required sections present and mark unknowns as [TODO]. 4. Still run the Phase 4 validation loop on all seven documents before final output.

Phase 1: Scan and Read Intent

1. Run the scan script from the target project root:

   python3 "$SKILL_ROOT/scripts/scan.py" --output docs/codebase/.codebase-scan.txt

Where $SKILL_ROOT is the absolute path to the skill folder. Works on Windows, macOS, and Linux.

Quick start: If you have the path inline:

   python3 /absolute/path/to/skills/acquire-codebase-knowledge/scripts/scan.py --output docs/codebase/.codebase-scan.txt

2. Search for PRD, TRD, README, ROADMAP, SPEC, DESIGN files and read them. 3. Summarise the stated project intent before reading any source code.

Phase 2: Investigate

Use the scan output to answer questions for each of the seven templates. Load `references/inquiry-checkpoints.md` for the full per-template question list.

If the stack is ambiguous (multiple manifest files, unfamiliar file types, no package.json), load `references/stack-detection.md`.

Phase 3: Populate Templates

Copy each template from assets/templates/ into docs/codebase/. Fill in this order:

1. STACK.md — language, runtime, frameworks, all dependencies 2. STRUCTURE.md — directory layout, entry points, key files 3. ARCHITECTURE.md — layers, patterns, data flow 4. CONVENTIONS.md — naming, formatting, error handling, imports 5. INTEGRATIONS.md — external APIs, databases, auth, monitoring 6. TESTING.md — frameworks, file organization, mocking strategy 7. CONCERNS.md — tech debt, bugs, security risks, perf bottlenecks

Use [TODO] for anything that cannot be determined from code. Use [ASK USER] where the right answer requires team intent.

Phase 4: Validate, Repair, Verify

Run this mandatory validation loop before finalizing:

1. Validate each doc against references/inquiry-checkpoints.md. 2. For each non-trivial claim, confirm at least one evidence reference exists. 3. If any required section is missing or unsupported:

  • Fix the document.
  • Re-run validation.

4. Repeat until all seven docs pass.

Then present a summary of all seven documents, list every [ASK USER] item as a numbered question, and highlight any Intent vs. Reality divergences from Phase 1.

Validation pass criteria:

  • No unsupported claims.
  • No empty required sections.
  • Unknowns use [TODO] rather than assumptions.
  • Team-intent gaps are explicitly marked [ASK USER].

---

Gotchas

Monorepos: Root package.json may have no source — check for workspaces, packages/, or apps/ directories. Each workspace may have independent dependencies and conventions. Map each sub-package separately.

Outdated README: README often describes intended architecture, not the current one. Cross-reference with actual file structure before treating any README claim as fact.

TypeScript path aliases: tsconfig.json paths config means imports like @/foo don't map directly to the filesystem. Map aliases to real paths before documenting structure.

Generated/compiled output: Never document patterns from dist/, build/, generated/, .next/, out/, or __pycache__/. These are artefacts — document source conventions only.

`.env.example` reveals required config: Secrets are never committed. Read .env.example, .env.template, or .env.sample to discover required environment variables.

`devDependencies` ≠ production stack: Only dependencies (or equivalent, e.g. [tool.poetry.dependencies]) runs in production. Document linters, formatters, and test frameworks separately as dev tooling.

Test TODOs ≠ production debt: TODOs inside test/, tests/, __tests__/, or spec/ are coverage gaps, not production technical debt. Separate them in CONCERNS.md.

High-churn files = fragile areas: Files appearing most in recent git history have the highest modification rate and likely hidden complexity. Always note them in CONCERNS.md.

---

Anti-Patterns

❌ Don't✅ Do instead
"Uses Clean Architecture with Domain/Data layers." (when no such directories exist)State only what directory structure actually shows.
"This is a Next.js project." (without checking package.json)Check dependencies first. State what's actually there.
Guess the database from a variable name like dbUrlCheck manifest for pg, mysql2, mongoose, prisma, etc.
Document dist/ or build/ naming patterns as conventionsSource files only.

---

Enhanced Scan Output Sections

The scan.py script now produce the following sections in addition to the original output:

  • CODE METRICS — Total files, lines of code by language, largest files (complexity signals)
  • CI/CD PIPELINES — Detected GitHub Actions, GitLab CI, Jenkins, CircleCI, etc.
  • CONTAINERS & ORCHESTRATION — Docker, Docker Compose, Kubernetes, Vagrant configs
  • SECURITY & COMPLIANCE — Snyk, Dependabot, SECURITY.md, SBOM, security policies
  • PERFORMANCE & TESTING — Benchmark configs, profiling markers, load testing tools

Use these sections during Phase 2 to inform investigation questions and identify tool-specific patterns.

---

Bundled Assets

AssetWhen to load
`scripts/scan.py`Phase 1 — run first, before reading any code (Python 3.8+ required)

| `references/inquiry-checkpoints.md` | Phase 2 — load for per-template investigation questions | | `references/stack-detection.md` | Phase 2 — only if stack is ambiguous | | `assets/templates/STACK.md` | Phase 3 step 1 | | `assets/templates/STRUCTURE.md` | Phase 3 step 2 | | `assets/templates/ARCHITECTURE.md` | Phase 3 step 3 | | `assets/templates/CONVENTIONS.md` | Phase 3 step 4 | | `assets/templates/INTEGRATIONS.md` | Phase 3 step 5 | | `assets/templates/TESTING.md` | Phase 3 step 6 | | `assets/templates/CONCERNS.md` | Phase 3 step 7 |

Template usage mode:

  • Default mode: complete only the "Core Sections (Required)" in each template.
  • Extended mode: add optional sections only when the repo complexity justifies them.

Related skills

How it compares

Use acquire-codebase-knowledge instead of ad-hoc file grepping when you need a structured, evidence-linked architecture brief agents can reuse across sessions.

FAQ

What triggers this skill?

Explicit prompts like 'map this codebase', 'document this architecture', 'onboard me to this repo', or 'create codebase docs'. Does not trigger for routine feature implementation or bug fixes.

What are the seven output documents?

STACK.md (languages, frameworks, dependencies), STRUCTURE.md (directories, entry points, key files), ARCHITECTURE.md (layers, patterns, data flow), CONVENTIONS.md (naming, formatting, error handling), INTEGRATIONS.md (APIs, databases, auth, monitoring), TESTING.md (frameworks, or

How are claims verified?

Every claim is traceable to source files, config, or terminal output. Unknowns marked [TODO]; intent-dependent decisions marked [ASK USER]. Each document includes an evidence list with concrete file paths and runs mandatory validation against inquiry checkpoints.

Is Acquire Codebase Knowledge safe to install?

skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Documentationdocsbackend

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.