Back to the marketplace · Skill
Legacy system assessment
Assesses legacy code before modernization: size and complexity, technology, domain map, top technical debt, CWE-tagged security findings with masked credentials, documentation gaps and a recommended pattern; can rank several systems. Size indices rank systems, never a cost or timeline. Derived from Anthropic's Claude Code plugin code-modernization without its Workflow and report scripts or raw-secret option; code is analyzed read-only.
Copy this sentence and send it to any employee in Teloa:In Teloa, open Marketplace, search for "Legacy system assessment" and add it (Skill anthropic.modernize-assess).
- Source
- Teloa official · Derived from Anthropic (anthropics/claude-plugins-official)
Change list (13)
Removed (3)
The original Claude Code slash-command file is not shipped; its text is rewritten as SKILL.md at the resource root (each change is listed in the other entries).
Why: Teloa loads skills from SKILL.md and does not support the Claude Code command format (`argument-hint`, `arguments`, `$ARGUMENTS`/`$system`).
commands/modernize-assess.mdMAS-M01 · View originalThe portfolio Workflow script is not shipped; its measuring method is written into SKILL.md's portfolio mode (see MAS-M07).
Why: The script depends on the Claude Code Workflow tool runtime (agent(), pipeline(), plugin-registered agentType, resumeFromRunId); the Teloa marketplace does not accept executable scripts and Teloa's orchestration tools have a different interface. The original already falls back to per-system measuring in the session when the Workflow tool is missing.
workflows/portfolio-assess.jsMAS-M02 · View originalThe Python script that builds REPORT.html is not shipped; SKILL.md step 7 no longer calls it (see MAS-M10).
Why: The Teloa marketplace does not accept executable scripts; the original already treats it as optional (if it fails or python3 is missing, say so and carry on).
scripts/build_report.pyMAS-M03 · View original
Adapted (9)
The frontmatter keeps only `name: modernize-assess` and a single-line `description`; `argument-hint` and `arguments` are removed.
Why: Skills in the Teloa marketplace may only have single-line name and description frontmatter keys.
SKILL.md · frontmatter (L1-5)MAS-M04 · View originalAdds a visible change notice below the title, "Derived work: modified by Teloa from anthropics/claude-plugins-official@fa59bc90…", naming the original file and license and pointing to MODIFICATIONS.md.
Why: Apache-2.0 section 4(b) requires modified files to carry a prominent change notice; visible text is used instead of an HTML comment, which security scans would flag as hidden content.
SKILL.md · below the titleMAS-M05 · View original`$ARGUMENTS`, `--portfolio`, `$system` and the `legacy/$system` convention become: the user gives the code path and a short system name; stop if the path does not exist; say where a symbolic link points; reports go to `analysis/<system>/` in the workspace. The pointer to `/code-modernization:modernize … --source` for creating the legacy link is removed.
Why: Teloa skills have no argument substitution; the `legacy/` link is created by another command of the original plugin that is not included.
SKILL.md · Mode and code location (L7-12); Steps 1-3 and 6 (`legacy/$system`)MAS-M06 · View originalPortfolio mode follows the original's "without the Workflow tool, gather the same row per system yourself" path and takes over the workflow's measuring rules: list the subdirectories and give the count, accept only plain subdirectory names, ask first when there are many; measure complexity the same way for every system (sum of scc's Complexity column, or the same decision keywords without scc, never mixing in per-function figures); 1-3 risk notes per system; the index always computed as `2.94 × KSLOC^1.10`; systems that could not be measured are marked "not measured" with the reason.
Why: The original keeps the uniform rules inside the Workflow script's prompt, and its fallback only says "gather the same row per system yourself"; without the rules the numbers are not comparable across systems.
SKILL.md · Portfolio modeMAS-M07 · View original"three subagents, in parallel" and "Run every subagent in the foreground" become three specialist passes that follow the shipped `agents/legacy-analyst.md` and `agents/security-auditor.md`: delegated to read-only subtasks when the host allows one-off delegation (such as subagent_task), otherwise run in turn, synthesizing after all of them; adds read-only rules (never build, run or modify the analyzed code; only write reports under analysis/, through the host's confirmation), no self-installing scc/cloc or other tools, and npm audit/pip-audit only with the user's agreement; step 4's "APM MCP server" becomes a monitoring connector the user has already set up.
Why: Teloa has no Claude Code Task tool and no plugin-registered named subagents; whether an AI colleague can delegate depends on whether its role was granted the one-off delegation tool (subagent_task), so the text says to delegate when possible and otherwise work in turn, and drops model tiers in favour of the host's configured model. npm audit and pip-audit send the dependency list to public services, and outbound traffic in Teloa needs the user's agreement.
SKILL.md · Working rules (new); Step 3 (L83-100); Step 4 (L104)MAS-M09 · View originalThe recommended pattern no longer routes to the `uplift`, `transform`, `reimagine`, `map`, `harden` and `preflight` commands, which are not included; it names the kind of work instead (in-place uplift, incremental transformation, re-architecture), and Replace points to the `modernize-extract-rules` skill. Step 7 drops build_report.py and "next step /code-modernization:modernize-map", and reports the output files, the number of security findings and credentials, the measuring tool used and what could not be determined.
Why: Those commands and scripts are not part of this resource and cannot be called in Teloa.
SKILL.md · Step 6 recommended pattern (L140-148); Step 7 (L153-158)MAS-M10 · View originalRemoves `--show-secrets` (a raw-value column in SECRETS.local.md) and writing to `~/.modernize/$system/` without Git: this skill never writes a raw credential value; it writes a masked-only SECRETS.local.md only in a Git repository where `git check-ignore` confirms analysis/.gitignore takes effect, and otherwise gives the masked inventory to the user in the conversation with the reason; the `*.local.patch` ignore entry, used only by other commands of the original plugin, is dropped.
Why: Teloa keeps credential values out of conversations and AI-written files, and anyone who needs a value can open the source at file:line; `~/.modernize` is outside the workspace, where an AI colleague should not write.
SKILL.md · Step 6, secrets (L117-131); argument-hint (L3)MAS-M11 · View originalTurns the Claude Code subagent definition into a role file shipped with the skill: the frontmatter (name, description, tools) becomes a title, the change notice, a "Role" line (the original description) and a "Tools" line (read, glob, grep; bash for read-only inspection only; no installing tools or dependencies); the body is unchanged.
Why: Teloa does not read Claude Code subagent frontmatter; the skill hands the role file to a one-off delegated subtask when possible, otherwise the main session follows it.
agents/legacy-analyst.md · frontmatter (L1-5)MAS-M12 · View originalThe frontmatter becomes a title, the change notice and Role and Tools lines as in MAS-M12; "run `npm audit` / `pip-audit`" becomes: read manifests and lock files first, run them only with the user's agreement (they send the dependency list to public services), and say when no online audit was run; the SAST sentence follows.
Why: Teloa does not read subagent frontmatter; both tools send the dependency list over the network, and outbound traffic in Teloa needs the user's agreement.
agents/security-auditor.md · frontmatter (L1-5); L29-30, L40MAS-M13 · View original
Added (1)
portfolio.html must contain no scripts and no external resources, and every value taken from the analyzed code is escaped.
Why: System names and file paths come from an untrusted code tree and, written straight into HTML, can carry tags or scripts; the original escapes and applies a CSP in build_report.py, but the model-written portfolio.html had no such requirement.
SKILL.md · Portfolio mode, portfolio.html (L50-55)MAS-M08 · View original
The other file matches the original (verified)
- GitHub
- Resource file: catalog/skills/anthropic.modernize-assess.json
Files kept by the marketplace: artifacts/skills/anthropic.modernize-assess/1.0.0/
Original source (locked version): GitHub anthropics/claude-plugins-official@fa59bc9 - License
- Apache-2.0
License files: LICENSE - Review
- Reviewed by Teloa on 2026-09-28
- Compatibility
- Needs configuration · Teloa >=0.2.0-alpha.7 · DSH 0.1.7-rc.1
- Needs the read, glob and grep tools and permission to write reports under analysis/ (writes go through the host's confirmation); bash is used only for read-only counting (scc, cloc, find, wc, grep), never to build or run the analyzed code.
- scc and cloc are optional; without them it falls back to find + wc and says so; it never installs tools. npm audit and pip-audit send the dependency list to a public service and run only with your agreement.
- Credentials are recorded only as file:line with at most a 2-4 character mask, never the value; SECRETS.local.md is written only in a Git repository where analysis/.gitignore takes effect, otherwise the inventory stays in the conversation.
- A reference run of the skill was done on a small sample legacy system (single-system and portfolio modes); local qwen3:14b runs did not complete (test harness timeouts) and gave no usable result. The sibling rule-extraction skill was unreliable on that model, so use a capable model. Not validated end to end in a Teloa host; large systems take long and use many model calls; check the conclusions by hand.
- Permissions and requirements
- Tools: read, glob, grep, bash, write
Uses the network: no - Data flow
- The files come with Teloa; nothing is downloaded when you add it. You can browse without signing in. Page views are counted with Cloudflare Web Analytics, which uses no cookies and does not record who you are. Data used for sign-in and reviews: privacy and community rules
Skill anthropic.modernize-assess · version 1.0.0