PluginBench
Skill
Pass
Audit score 90

ai-debt-detector

wshobson/agents

Audit AI-generated code for hidden debt: missing error handling, orphaned resources, and hallucinated dependencies.

What is ai-debt-detector?

Run this skill after AI generates code to catch systematic failure patterns that AI agents produce but humans typically avoid. It forces a targeted scan for orphaned resources, missing error handling, edge cases, hallucinated dependencies, and architectural drift—the specific debt patterns AI code accumulates.

  • Identifies missing error handling and swallowed exceptions in AI-generated code
  • Detects orphaned resources (temp files, listeners, connections, subscriptions) without cleanup
  • Finds edge cases and failure modes the AI assumed away (null inputs, timeouts, concurrent calls)
  • Validates that all imports and API methods actually exist in the specified versions
  • Checks whether generated code matches the project's established patterns and conventions

How to install ai-debt-detector

npx skills add https://github.com/wshobson/agents --skill ai-debt-detector
Claude Code
Cursor
Windsurf
Cline

How to use ai-debt-detector

  1. 1.After AI generates code, scan for FAILURE MODES: check for try/catch blocks, specific error handling, and resource cleanup on failure
  2. 2.Look for ORPHANS: identify every open/create call (files, listeners, connections, subscriptions) and verify corresponding cleanup code exists
  3. 3.Test EDGE CASES mentally: empty inputs, null/undefined, large inputs, Unicode, concurrent calls—verify the code handles them
  4. 4.Validate HALLUCINATED DEPS: confirm every import exists in the project, check that API methods are real in the library's current version
  5. 5.Review ARCHITECTURAL DRIFT: ensure error handling style, utility usage, and file structure match the project's existing patterns

Use cases

Good for
  • After a 20+ line AI code generation session to catch debt before it ships
  • Before merging AI-generated pull requests to verify error handling and resource cleanup
  • When working code feels brittle or incomplete to audit for hidden failure paths
  • During code review of vibe-coding sprints where debt accumulates fastest
  • When an AI agent claims done but hasn't shown verification of edge cases
Who it's for
  • Developers reviewing AI-generated code
  • Teams using coding agents (Claude Code, Cursor) for significant portions of their codebase
  • Code reviewers who need to spot systematic AI failure patterns
  • Engineers maintaining projects with mixed human and AI-written modules

ai-debt-detector FAQ

Should I run this on all code or just AI-generated code?

Primarily on AI-generated code. This skill targets systematic patterns AI agents produce at much higher rates than humans (missing error paths, orphaned resources, hallucinated APIs). Human-written code benefits from general code review instead.

What does 'orphaned resources' mean?

Resources created but never cleaned up: temp files left on disk, event listeners never removed, database connections never returned to the pool, timers/intervals never cleared, subscriptions never unsubscribed. These leak memory, connections, or file handles.

Why does compilation passing not mean the code is correct?

Compilation checks syntax only. AI code often compiles but fails at runtime: it catches all exceptions silently, assumes happy paths, invokes methods that don't exist in the actual library version, or leaves resources open on error.

What's a 'hallucinated dependency'?

An import or API method the AI invented because it sounds plausible but doesn't actually exist in the library. Example: calling `fs.readFileAsync()` when the real method is `fs.promises.readFile()`. Always verify imports and method names against current documentation.

How do I fix red flags like `catch (e) {}`?

Replace swallowed errors with specific error handling: log the error, retry with backoff, fail fast with a clear message, or propagate it. Add a `finally` block to clean up resources (close files, return connections). Replace `// TODO: handle error` with actual error logic before merging.

Full instructions (SKILL.md)

Source of truth, from wshobson/agents.


name: ai-debt-detector description: >- Use after generating code, after accepting AI suggestions, or when reviewing AI-written modules. Also use when code works but feels brittle, when error handling seems thin, when orphaned resources or missing cleanup are suspected, or when the agent claims done but hidden debt may exist. Catches the specific failure patterns AI agents produce that humans would not.

AI Debt Detector

Overview

AI agents generate code that passes the happy path but hides debt: missing error handling, orphaned resources, ignored failure modes, hallucinated packages, silent architectural drift. This skill forces a targeted audit for the exact patterns AI agents get wrong.

When to Use

  • After any AI code generation session (20+ lines produced)
  • Before merging AI-generated PRs
  • When code works but something feels off
  • After vibe-coding sprints where debt accumulates fastest
  • When the agent claims done without showing verification

Process

After code generation, scan for these AI-specific debt patterns:

  1. FAILURE MODES - What happens when this fails?

    • Network timeout? Disk full? Permission denied? Null input?
    • Is there a try/catch? Does it catch SPECIFIC errors or swallow everything?
    • Are resources cleaned up on failure? (streams closed, connections returned, temp files deleted)
  2. ORPHANS - What gets created but never cleaned up?

    • Temp files, event listeners, intervals, subscriptions, connections
    • Are there corresponding cleanup/dispose/close calls for every open/create?
    • In React: does every addEventListener have a removeEventListener in cleanup?
  3. EDGE CASES - What inputs break this?

    • Empty array/string? null/undefined? Multi-MB input? Unicode? Concurrent calls?
    • Does the code assume the happy path? (AI almost always does)
  4. HALLUCINATED DEPS - Do all imports actually exist?

    • Is every package in package.json/requirements.txt?
    • Are API methods real? (AI invents plausible-sounding methods that don't exist)
    • Does this library's latest version still export this function?
  5. ARCHITECTURAL DRIFT - Does this match the project's patterns?

    • Same error handling style as existing code?
    • Uses the project's established utilities (not reinventing)?
    • Follows the file structure convention?

Red Flags (stop and fix immediately)

  • catch (e) {} or catch (e) { console.log(e) } - swallowed error
  • No finally block when resources were opened
  • // TODO: handle error - AI's way of punting
  • Import from a path that doesn't exist in the project
  • Timeout set but no abort/cleanup on timeout
  • Database connection opened but never released back to pool

Common Mistakes

  • Trusting that compilation means correctness (compilation checks syntax, not logic)
  • Reviewing only the diff without checking what the AI did NOT generate (missing error paths)
  • Assuming the AI used the right library version (it often uses deprecated APIs)
  • Skipping the orphan check because garbage collection handles it (it doesn't for connections, listeners, timers)

Why This Exists

AI agents systematically optimize for "looks correct" and "passes the happy path." They miss failure modes, orphan resources, and hallucinate dependencies at rates significantly higher than manual code. This skill forces an audit for those specific blind spots.