# Scope Creep Detector

> >-

- **Type:** Skill
- **Install:** `agentstack add skill-shubhamsaboo-awesome-llm-apps-scope-creep-detector`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Shubhamsaboo](https://agentstack.voostack.com/s/shubhamsaboo)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [Shubhamsaboo](https://github.com/Shubhamsaboo)
- **Source:** https://github.com/Shubhamsaboo/awesome-llm-apps/tree/main/agent_skills/scope-creep-detector
- **Website:** https://www.theunwindai.com

## Install

```sh
agentstack add skill-shubhamsaboo-awesome-llm-apps-scope-creep-detector
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Scope Creep Detector

A one-line fix should not require a reviewer to reverse-engineer fourteen files
across three subsystems. This skill compares a git diff with its stated intent,
surfaces scope signals, and turns them into keep, split, or justify decisions.

Everything runs locally. The script makes no network calls and does not change
the working tree, index, commits, or branches.

## When to use

- Before opening a pull request whose diff may have grown beyond its intent
- When a bug fix touches unexpected files or subsystems
- When the user asks whether staged changes are too broad
- When a diff includes dependency, public API, config, CI, or build changes
- When the user wants a concrete split plan for a mixed change

## When not to use

- Formatting code, running a linter, or writing a commit message
- Reviewing correctness, security, or test quality inside an agreed scope
- Measuring historical project growth across many commits
- Editing or reverting files without the user's approval

## Establish the intent

Use the user's one-line intent when available. Keep it concrete, such as
`fix null dereference in parser` or `add retry limit to webhook delivery`.

If no intent was given, the script falls back to the current branch name. If
that name is generic, detached, or unrelated to the work, ask for one line of
intent before treating relatedness as meaningful.

## Run the classifier

Run from this skill directory and point `--repo` at the target repository.

Working tree diff:

```bash
python3 scripts/scope_creep.py --repo /path/to/repo \
  --intent "fix null dereference in parser" --json
```

Staged diff:

```bash
python3 scripts/scope_creep.py --repo /path/to/repo --staged \
  --intent "fix null dereference in parser" --json
```

Branch diff against a merge base:

```bash
python3 scripts/scope_creep.py --repo /path/to/repo --base main \
  --intent "fix null dereference in parser" --json
```

Saved diff or stdin:

```bash
python3 scripts/scope_creep.py --diff change.diff --intent "parser fix" --json
git diff --staged | python3 scripts/scope_creep.py --diff - \
  --intent "parser fix" --json
```

Use `--hunk-threshold` only when the repository has a documented reason to
change the default churn threshold. Do not tune the threshold merely to make a
warning disappear.

## Interpret the JSON

Read [references/scope-signals.md](references/scope-signals.md) before making a
recommendation. Treat the classifier as triage evidence, not proof of authorial
intent.

- `in_scope`: file paths with at least one intent/path keyword overlap
- `likely_creep`: paths without overlap, with the reason and detected signals
- `new_deps`: dependencies introduced in supported manifest formats
- `api_renames`: nearby removed and added public function or class declarations
- `config_edits`: CI, container, build, YAML, and TOML changes
- `stats`: churn, subsystem counts, oversized hunks, and formatting-only files

Empty arrays are evidence too. Say that no signal was detected, not that the
diff is guaranteed to be in scope.

## Recommend keep, split, or justify

Give every item in `likely_creep` one disposition:

1. **Keep** when the path is necessary for the stated intent and the connection
   is direct. Explain the connection in one sentence.
2. **Split** when it can land independently, belongs to another subsystem, or
   introduces a dependency, API rename, config edit, or large hunk that is not
   required for the intent. Name the files or hunks for the follow-up change.
3. **Justify** when a cross-cutting edit cannot be separated safely. State the
   invariant or build constraint that requires it and call out reviewer risk.

Prefer split when evidence is ambiguous. Never claim that a zero overlap score
proves a file is unrelated. Path vocabulary is a cheap, deterministic proxy.

## Write the scope report

Use this compact structure:

1. Intent and diff source
2. Files and subsystems touched, with total additions and deletions
3. In-scope changes
4. Likely creep with signal evidence
5. Keep, split, or justify table
6. Proposed follow-up grouping, if any

Name file paths and hunk headers. For an oversized mixed hunk, explain that the
script cannot split it automatically and describe the smallest coherent edit.
Ask before applying any split, revert, staging, or commit operation.

## Files

- `scripts/scope_creep.py`: deterministic unified-diff parser and classifier
- `references/scope-signals.md`: signal definitions, thresholds, and limits

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Shubhamsaboo](https://github.com/Shubhamsaboo)
- **Source:** [Shubhamsaboo/awesome-llm-apps](https://github.com/Shubhamsaboo/awesome-llm-apps)
- **License:** Apache-2.0
- **Homepage:** https://www.theunwindai.com

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-shubhamsaboo-awesome-llm-apps-scope-creep-detector
- Seller: https://agentstack.voostack.com/s/shubhamsaboo
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
