Public report — gemini-cli, published 22 Sep 2026.
Concrete security findings (which rule fired, in which file, on which line; CVE IDs, secret matches,
dependency versions) are REDACTED in this version; ask the repo owner for the full report.
Public
Codebase surveyMeasured under the Code Assurance Index · rubric rubric-2026.09.15 (frozen) · verify this surveyFiledcd_2ca89d470a384fec80e624d7f8e1852a
Filed 25 September 2026, 05:09 UTC
Public
Large · 270,753 LoC · rebuild ~4.2 person-years · weakest lens: Accessibility (40%)
Findings by grade
86 critical1549 serious85 minor22 could not be resolved — could be critical — see Limitations
This survey was produced by
Watchdog
Producer
Canine Development
Analyzer
Watchdog engine 1.0.0
Measured
22 September 2026, 21:55 UTC
A measurement, not a certificate. The Code Assurance Index does not certify,
approve or guarantee this codebase; it records a reproducible number and the evidence it was computed from. The
standard is authored by Canine Development, who also build Watchdog — its only implementation today. That is said
here so the number is checked rather than believed.
Grounded in facts. Every number here is computed, not narrated — reproducible, tool-backed, and traceable to a line of code. How to trust this ▸
1692findings with an exact file:lineof 1720 — the remainder are repo-wide signals (a dimension-level measurement, not a single line); open any file:line and verify
72/133dimensions across the health lenses270753 LoC — wide & deep
⚠ A critical security finding caps this grade — resolve it before relying on the score below; see the Security lens.
Preview (pre-1.0). This repo hasn't declared a stable release, so it's judged against a relaxed, pre-production bar.
The platform is a large, high-value asset currently rated at risk. With a significant rebuild cost of approximately €610,000, the system’s stability is compromised by critical gaps in accessibility and a pervasive tax on development velocity. While the core logic is substantial, the current state exposes the business to compliance liabilities and slows every future change.
The most urgent risk lies in accessibility, which scores poorly against a massive codebase. This is not merely a technical debt issue but a direct business exposure. Failing to address these gaps invites regulatory scrutiny and limits user reach. The cost of inaction is high, as the annual drag on productivity from these defects far exceeds the one-time effort required to fix them. Remediation here offers the strongest protection for the brand and the bottom line.
Every modification to the system suffers from a velocity tax. Poor code quality and cohesion mean that changes cost significantly more than they should, compounding as the codebase grows. This inefficiency drains engineering resources that could otherwise drive new features. The financial impact is measurable: the top priority fix pays for itself within months by reducing this annual drag, turning a recurring cost into a net gain.
Despite these risks, the system demonstrates strong maturity and operational readiness. The team has established solid foundations in documentation and production safety, ensuring the platform is reliable and maintainable by new teams. These strengths provide a stable base from which to address the critical gaps without destabilizing the core service.
Focus first on making custom controls keyboard-operable and enforcing accessibility standards in the toolchain. This single action delivers the highest return on effort, breaking even quickly and reducing long-term maintenance costs. Other improvements can follow once this critical foundation is secured. Note that domain modeling and event-driven architecture were not measured, so the full picture remains partially incomplete.
How the score is built — each lens's share of the headlineWidth is the lens's weight in the worst-heaviest fold (the weakest area pulls hardest); colour is that lens's own band. A lens fixes the score in proportion to its width.
1519 finding(s) are new versus the previous scan (2026-08-05) — surfaced by this scheduled scan itself, no pull request required. Showing the first 100; the full set is in the report.
A full-fidelity diff against the previous run's complete recorded findings — line-move tolerant: a finding that only shifted line counts as unchanged, only genuinely new titles/files surface here.
Rebuild cost & value ~ Modeled — €200,000–€1,000,000
0.7× (at 51% quality) — the last 20% of quality is most of the work
Size & shape
Large · effort split not classified for 270,292 line(s) outside the .NET model (the tier breakdown is a C#-only syntax walk)
This codebase represents roughly ~4.2 person-years of build effort (about ~€610,000 to rebuild). Its weakest lens is Accessibility at 40% — the part of that asset most exposed by the findings below.
How we model this: boilerplate at a scaffolding rate + logic × domain Standard (×1.1) — transaction-script/CRUD, high decision density × a 0.7× quality factor, at €60–95/h; indicative, ±~30% · size measured directly from source. Indicative only — most sensitive to the hourly rate and the domain tier (both tunable in config).
Top priorities
The highest-leverage moves; the full ranked list is in the Roadmap below.
1
Make custom controls keyboard-operable (role + tabindex + key handler), drop positive tabindex, and give anchors a real href.
Value concentrated against a weak lens · REDACTED · Value at risk
This is a Large asset (~4.2 person-years to rebuild), and its weakest lens is Accessibility at 40%. The operational and business risk on an asset this size concentrates there — that's where remediation buys the most protection.
→ Direct remediation budget at Accessibility first — highest risk-reduction per euro on an asset this size.
A velocity tax on every change · REDACTED · Economics
The code-quality signals (complexity, duplication, cohesion) average 2.0/10, which acts as a tax on every change in the weaker areas: modifications there plausibly cost on the order of 15–34% more than in clean code, and the tax compounds as the codebase grows. (A modelled estimate, not a measured fact.)
Evidence: D1/D2 code quality: averaging 2.0/10 across the code-quality signals actually measured
→ Pay it down where churn is highest — the hotspots — not everywhere; that's where the tax is actually paid.
The top fix pays for itself · REDACTED · Economics
The top-ranked fix costs roughly 3–10 engineer-days once. Not doing it costs about 72–431.7 engineer-days every year, paid as drag on the ~191,876 lines this team changes annually — a bill that arrives whether or not anyone books it. On those figures the fix breaks even in roughly 1–2 months and is free after that. Method, stated so this is not read as a quotation: debt from the ranked task's effort band; interest = annual changed lines (measured, annualised from the 90-day window) ÷ an ASSUMED 150–400 lines per engineer-day × the 15–34% drag implied by the code-quality signals; breaking point = debt ÷ annual interest. A modelled planning range built from measured inputs and one named assumption — not a quotation, a valuation, or a certified figure.
Evidence: D15 churn: 47,312 line(s) changed over a 90-day window ⇒ ~191,876/year · D1/D2 code quality: averaging 2.0/10 ⇒ a 15–34% drag on each change · top-ranked remediation: REDACTED effort ⇒ about 3–10 engineer-day(s)
→ Do the top-ranked fix now if this code will still be yours in 2 months.
Highest-leverage move · REDACTED · Leverage
Of everything flagged, the best return on effort is: Make custom controls keyboard-operable (role + tabindex + key handler), drop positive tabindex, and give anchors a real href. The rest can wait behind it.
Evidence: priority ranking: top of 5 ranked by impact/effort
→ Make custom controls keyboard-operable (role + tabindex + key handler), drop positive tabindex, and give anchors a real href.
Architecture — module dependency matrix
Rows and columns are the same modules, ordered so that a module only depends on ones above it. A cell means the row depends on the column, and its number is how many type pairs create that dependency. Read one thing: is anything above the diagonal? A mark there is a dependency cycle. (A cycle is all this shows — an unusual but cycle-free dependency sits below the diagonal like any other.)
836 modules, 1328 dependencies. 2 dependency cycles across 68 modules, marked above the diagonal.
Showing the 40 most-connected modules; 796 more are not drawn.
Module dependency matrix. The row depends on the column; the number is how many type pairs create the dependency. A cell above the diagonal is part of a dependency cycle.
core.src.confirmation-bus.message-bus uses cli.src.ui.types. Changing cli.src.ui.types can break core.src.confirmation-bus.message-bus, not the reverse.
Position
Above the diagonal — a cycle. Neither module can be changed, tested or deployed independently until one of these dependencies goes.
9→4 core.src.core.contentGenerator depends on core.src.code_assist.types✕
Type pairs
2 distinct (type in core.src.core.contentGenerator → type in core.src.code_assist.types) references.
core.src.core.contentGenerator uses core.src.code_assist.types. Changing core.src.code_assist.types can break core.src.core.contentGenerator, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
9→6 core.src.core.contentGenerator depends on core.src.telemetry.llmRole✕
Type pairs
1 distinct (type in core.src.core.contentGenerator → type in core.src.telemetry.llmRole) reference.
core.src.core.contentGenerator uses core.src.telemetry.llmRole. Changing core.src.telemetry.llmRole can break core.src.core.contentGenerator, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
10→5 core.src.policy.types depends on core.src.services.sandboxManager✕
Type pairs
1 distinct (type in core.src.policy.types → type in core.src.services.sandboxManager) reference.
core.src.policy.types uses core.src.services.sandboxManager. Changing core.src.services.sandboxManager can break core.src.policy.types, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
11→3 core.src.scheduler.types depends on core.src.agent.types✕
Type pairs
2 distinct (type in core.src.scheduler.types → type in core.src.agent.types) references.
core.src.core.baseLlmClient uses core.src.telemetry.llmRole. Changing core.src.telemetry.llmRole can break core.src.core.baseLlmClient, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
12→9 core.src.core.baseLlmClient depends on core.src.core.contentGenerator✕
Type pairs
2 distinct (type in core.src.core.baseLlmClient → type in core.src.core.contentGenerator) references.
core.src.core.baseLlmClient uses core.src.core.contentGenerator. Changing core.src.core.contentGenerator can break core.src.core.baseLlmClient, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
12→25 core.src.core.baseLlmClient depends on core.src.config.configcycle✕
Type pairs
1 distinct (type in core.src.core.baseLlmClient → type in core.src.config.config) reference.
core.src.telemetry.types uses core.src.scheduler.types. Changing core.src.scheduler.types can break core.src.telemetry.types, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
13→25 core.src.telemetry.types depends on core.src.config.configcycle✕
Type pairs
51 distinct (type in core.src.telemetry.types → type in core.src.config.config) references. Showing 25 of them; the rest are in namespace-graph.json in this report's bundle.
core.src.tools.mcp-client uses core.src.confirmation-bus.message-bus. Changing core.src.confirmation-bus.message-bus can break core.src.tools.mcp-client, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
14→25 core.src.tools.mcp-client depends on core.src.config.configcycle✕
Type pairs
1 distinct (type in core.src.tools.mcp-client → type in core.src.config.config) reference.
core.src.tools.tools uses core.src.confirmation-bus.message-bus. Changing core.src.confirmation-bus.message-bus can break core.src.tools.tools, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
15→10 core.src.tools.tools depends on core.src.policy.types✕
Type pairs
1 distinct (type in core.src.tools.tools → type in core.src.policy.types) reference.
core.src.context.pipeline.environment uses core.src.core.baseLlmClient. Changing core.src.core.baseLlmClient can break core.src.context.pipeline.environment, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
19→15 core.src.services.chatRecordingTypes depends on core.src.tools.tools✕
Type pairs
1 distinct (type in core.src.services.chatRecordingTypes → type in core.src.tools.tools) reference.
core.src.services.chatRecordingTypes uses core.src.tools.tools. Changing core.src.tools.tools can break core.src.services.chatRecordingTypes, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
20→6 core.src.core.geminiChat depends on core.src.telemetry.llmRole✕
Type pairs
1 distinct (type in core.src.core.geminiChat → type in core.src.telemetry.llmRole) reference.
core.src.core.geminiChat uses core.src.services.chatRecordingTypes. Changing core.src.services.chatRecordingTypes can break core.src.core.geminiChat, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
20→24 core.src.core.geminiChat depends on core.src.config.agent-loop-contextcycle✕
Type pairs
1 distinct (type in core.src.core.geminiChat → type in core.src.config.agent-loop-context) reference.
core.src.core.geminiChat uses core.src.config.agent-loop-context. Changing core.src.config.agent-loop-context can break core.src.core.geminiChat, not the reverse.
Position
Above the diagonal — a cycle. Neither module can be changed, tested or deployed independently until one of these dependencies goes.
21→6 core.src.telemetry.uiTelemetry depends on core.src.telemetry.llmRole✕
Type pairs
1 distinct (type in core.src.telemetry.uiTelemetry → type in core.src.telemetry.llmRole) reference.
core.src.telemetry.uiTelemetry uses core.src.telemetry.llmRole. Changing core.src.telemetry.llmRole can break core.src.telemetry.uiTelemetry, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
21→13 core.src.telemetry.uiTelemetry depends on core.src.telemetry.types✕
Type pairs
2 distinct (type in core.src.telemetry.uiTelemetry → type in core.src.telemetry.types) references.
core.src.telemetry.uiTelemetry uses core.src.telemetry.types. Changing core.src.telemetry.types can break core.src.telemetry.uiTelemetry, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
21→16 core.src.telemetry.uiTelemetry depends on cli.src.ui.types✕
Type pairs
1 distinct (type in core.src.telemetry.uiTelemetry → type in cli.src.ui.types) reference.
core.src.telemetry.uiTelemetry uses core.src.services.chatRecordingTypes. Changing core.src.services.chatRecordingTypes can break core.src.telemetry.uiTelemetry, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
22→6 core.src.core.client depends on core.src.telemetry.llmRole✕
Type pairs
1 distinct (type in core.src.core.client → type in core.src.telemetry.llmRole) reference.
core.src.core.client uses core.src.services.chatRecordingTypes. Changing core.src.services.chatRecordingTypes can break core.src.core.client, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
22→20 core.src.core.client depends on core.src.core.geminiChat✕
Type pairs
1 distinct (type in core.src.core.client → type in core.src.core.geminiChat) reference.
core.src.core.client uses core.src.config.agent-loop-context. Changing core.src.config.agent-loop-context can break core.src.core.client, not the reverse.
Position
Above the diagonal — a cycle. Neither module can be changed, tested or deployed independently until one of these dependencies goes.
22→25 core.src.core.client depends on core.src.config.configcycle✕
Type pairs
1 distinct (type in core.src.core.client → type in core.src.config.config) reference.
core.src.core.client uses core.src.config.config. Changing core.src.config.config can break core.src.core.client, not the reverse.
Position
Above the diagonal — a cycle. Neither module can be changed, tested or deployed independently until one of these dependencies goes.
23→13 core.src.telemetry depends on core.src.telemetry.types✕
Type pairs
56 distinct (type in core.src.telemetry → type in core.src.telemetry.types) references. Showing 25 of them; the rest are in namespace-graph.json in this report's bundle.
core.src.config.agent-loop-context uses core.src.services.sandboxManager. Changing core.src.services.sandboxManager can break core.src.config.agent-loop-context, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
24→8 core.src.config.agent-loop-context depends on core.src.confirmation-bus.message-bus✕
Type pairs
1 distinct (type in core.src.config.agent-loop-context → type in core.src.confirmation-bus.message-bus) reference.
core.src.config.agent-loop-context uses core.src.confirmation-bus.message-bus. Changing core.src.confirmation-bus.message-bus can break core.src.config.agent-loop-context, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
24→22 core.src.config.agent-loop-context depends on core.src.core.client✕
Type pairs
1 distinct (type in core.src.config.agent-loop-context → type in core.src.core.client) reference.
core.src.config.agent-loop-context uses core.src.core.client. Changing core.src.core.client can break core.src.config.agent-loop-context, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
24→25 core.src.config.agent-loop-context depends on core.src.config.configcycle✕
Type pairs
1 distinct (type in core.src.config.agent-loop-context → type in core.src.config.config) reference.
core.src.config.agent-loop-context uses core.src.config.config. Changing core.src.config.config can break core.src.config.agent-loop-context, not the reverse.
Position
Above the diagonal — a cycle. Neither module can be changed, tested or deployed independently until one of these dependencies goes.
25→1 core.src.config.config depends on cli.src.config.settings✕
Type pairs
3 distinct (type in core.src.config.config → type in cli.src.config.settings) references.
core.src.config.config uses core.src.services.sandboxManager. Changing core.src.services.sandboxManager can break core.src.config.config, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
25→8 core.src.config.config depends on core.src.confirmation-bus.message-bus✕
Type pairs
1 distinct (type in core.src.config.config → type in core.src.confirmation-bus.message-bus) reference.
core.src.config.config uses core.src.confirmation-bus.message-bus. Changing core.src.confirmation-bus.message-bus can break core.src.config.config, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
25→9 core.src.config.config depends on core.src.core.contentGenerator✕
Type pairs
3 distinct (type in core.src.config.config → type in core.src.core.contentGenerator) references.
core.src.config.config uses core.src.config.agent-loop-context. Changing core.src.config.agent-loop-context can break core.src.config.config, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
26→25 a2a-server.src.commands.types depends on core.src.config.config✕
Type pairs
1 distinct (type in a2a-server.src.commands.types → type in core.src.config.config) reference.
cli.src.config.extension-manager uses cli.src.config.settings. Changing cli.src.config.settings can break cli.src.config.extension-manager, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
27→25 cli.src.config.extension-manager depends on core.src.config.config✕
Type pairs
3 distinct (type in cli.src.config.extension-manager → type in core.src.config.config) references.
cli.src.config.extension-manager uses core.src.config.config. Changing core.src.config.config can break cli.src.config.extension-manager, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
28→1 cli.src.ui.utils depends on cli.src.config.settings✕
Type pairs
2 distinct (type in cli.src.ui.utils → type in cli.src.config.settings) references.
core.src.routing.routingStrategy uses core.src.core.baseLlmClient. Changing core.src.core.baseLlmClient can break core.src.routing.routingStrategy, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
30→25 core.src.routing.routingStrategy depends on core.src.config.config✕
Type pairs
2 distinct (type in core.src.routing.routingStrategy → type in core.src.config.config) references.
core.src.routing.routingStrategy uses core.src.config.config. Changing core.src.config.config can break core.src.routing.routingStrategy, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
31→8 core.src.scheduler.scheduler depends on core.src.confirmation-bus.message-bus✕
Type pairs
2 distinct (type in core.src.scheduler.scheduler → type in core.src.confirmation-bus.message-bus) references.
core.src.scheduler.scheduler uses core.src.confirmation-bus.message-bus. Changing core.src.confirmation-bus.message-bus can break core.src.scheduler.scheduler, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
31→10 core.src.scheduler.scheduler depends on core.src.policy.types✕
Type pairs
1 distinct (type in core.src.scheduler.scheduler → type in core.src.policy.types) reference.
core.src.scheduler.scheduler uses core.src.confirmation-bus.types. Changing core.src.confirmation-bus.types can break core.src.scheduler.scheduler, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
31→24 core.src.scheduler.scheduler depends on core.src.config.agent-loop-context✕
Type pairs
2 distinct (type in core.src.scheduler.scheduler → type in core.src.config.agent-loop-context) references.
core.src.scheduler.scheduler uses core.src.config.agent-loop-context. Changing core.src.config.agent-loop-context can break core.src.scheduler.scheduler, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
31→25 core.src.scheduler.scheduler depends on core.src.config.config✕
Type pairs
1 distinct (type in core.src.scheduler.scheduler → type in core.src.config.config) reference.
core.src.services uses core.src.services.chatRecordingTypes. Changing core.src.services.chatRecordingTypes can break core.src.services, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
32→24 core.src.services depends on core.src.config.agent-loop-context✕
Type pairs
1 distinct (type in core.src.services → type in core.src.config.agent-loop-context) reference.
a2a-server.src.agent.task uses core.src.confirmation-bus.types. Changing core.src.confirmation-bus.types can break a2a-server.src.agent.task, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
35→22 a2a-server.src.agent.task depends on core.src.core.client✕
Type pairs
1 distinct (type in a2a-server.src.agent.task → type in core.src.core.client) reference.
a2a-server.src.agent.task uses core.src.scheduler.scheduler. Changing core.src.scheduler.scheduler can break a2a-server.src.agent.task, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
36→25 cli.src.commands.extensions depends on core.src.config.config✕
Type pairs
1 distinct (type in cli.src.commands.extensions → type in core.src.config.config) reference.
cli.src.commands.extensions uses cli.src.config.extension-manager. Changing cli.src.config.extension-manager can break cli.src.commands.extensions, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
37→1 cli.src.config depends on cli.src.config.settings✕
Type pairs
5 distinct (type in cli.src.config → type in cli.src.config.settings) references.
cli.src.ui.contexts.UIStateContext uses core.src.agents.types. Changing core.src.agents.types can break cli.src.ui.contexts.UIStateContext, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
38→9 cli.src.ui.contexts.UIStateContext depends on core.src.core.contentGenerator✕
Type pairs
1 distinct (type in cli.src.ui.contexts.UIStateContext → type in core.src.core.contentGenerator) reference.
cli.src.ui.contexts.UIStateContext uses core.src.core.contentGenerator. Changing core.src.core.contentGenerator can break cli.src.ui.contexts.UIStateContext, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
38→10 cli.src.ui.contexts.UIStateContext depends on core.src.policy.types✕
Type pairs
1 distinct (type in cli.src.ui.contexts.UIStateContext → type in core.src.policy.types) reference.
cli.src.ui.contexts.UIStateContext uses core.src.policy.types. Changing core.src.policy.types can break cli.src.ui.contexts.UIStateContext, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
38→16 cli.src.ui.contexts.UIStateContext depends on cli.src.ui.types✕
Type pairs
1 distinct (type in cli.src.ui.contexts.UIStateContext → type in cli.src.ui.types) reference.
cli.src.ui.contexts.UIStateContext uses a2a-server.src.commands.types. Changing a2a-server.src.commands.types can break cli.src.ui.contexts.UIStateContext, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
39→1 cli.src.ui.hooks depends on cli.src.config.settings✕
Type pairs
6 distinct (type in cli.src.ui.hooks → type in cli.src.config.settings) references.
cli.src.ui.components uses cli.src.ui.contexts.UIStateContext. Changing cli.src.ui.contexts.UIStateContext can break cli.src.ui.components, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
At a glance — Code Health · 68% · Adequate · gated by D1, D2 ·
Findings mapped to OWASP categories; the specific CVEs/secrets are in the Security dimension cards below and findings.md (redacted only on the public version of this report).
OWASP category
Findings
Severity
A06:2021 — Vulnerable & Outdated Components
53
REDACTED / Critical
A05:2021 — Security Misconfiguration
36
REDACTED / Critical
A03:2021 — Injection
24
REDACTED / Critical
A02:2021 — Cryptographic Failures
3
REDACTED / Critical
Roadmap
First, ensure all interactive elements are fully keyboard-accessible and properly linked, while fixing structural issues like missing language attributes and main landmarks. Next, enforce accessibility standards by adding programmatic labels to every form control and button, then integrate automated a11y checks into the development toolchain and CI pipeline. Finally, resolve the 29 high-severity dependency vulnerabilities to secure the codebase.
Ranked by impact ÷ effort. "Helps" is the estimated gain on the 0–100 health score.
Do this
Helps
Effort
Dimension
Make custom controls keyboard-operable (role + tabindex + key handler), drop positive tabindex, and give anchors a real href.
Every finding carries one of four grades. Three say how serious it is. The fourth says this
survey could not settle it — and it is a grade, not a gap.
Critical — 86
A definite problem that already costs you something and drags the score down: a
missing authorisation check, a dependency with a known exploit, a build that does not reproduce. Failure here
tends to cause failures elsewhere.
Serious — 1549
Likely wrong, but not failing yet. It degrades
the codebase over a longer horizon and can cause failures elsewhere — not urgent this week, not something to
carry for two years either.
Minor — 85
Recorded, with no effect on how the codebase functions.
Present so the survey is complete, not because it needs doing.
Could not be resolved — 22
Something this survey could not settle
from the outside, and which could be critical or serious. Either a control was required and no
positive evidence of it exists in the repository — a backup job that nothing shows was ever restored from proves
nothing about restores — or our own analysis could not run over that part of the tree. This is not a clean
result. These are excluded from the score rather than awarded a pass, so the number on the cover neither
rewards nor penalises them: if you act on this survey without resolving them, you carry that risk yourself. Each
one is named under Limitations.
Methodology & how to trust this report
Watchdog is a deep, periodic assessment — run each sprint, monthly, or quarterly, taking the time to go wider and deeper than a quick check and surfacing in one coherent report what you'd otherwise piece together from a dozen separate tools. It scores deterministically: the same commit yields the same score, every run. 69 of 72 evaluated dimensions are computed purely by tools and static analysis (confidence 1.0); 3 documentation/naming judgement(s) are LLM-assisted and labelled advisory. Overall confidence is 0.9 — the weighted average across measured dimensions; it falls as more of the score leans on LLM-assisted judgement and rises when it's fully tool-backed.
Every figure here is one of three kinds, and we label which: ✓ Measured — a deterministic fact (LoC, complexity, coverage); ~ Modeled — an estimate from a stated model (cost, effort, value-at-risk), always a range with its assumptions, never a precise fact; ◐ Advisory — an LLM prose judgement. We never present a modelled estimate as if it were measured. Perfect or absent scores carry their provenance too (ADR-0011): ✓ Tool-verified means the property itself was measured across the surface; ○ Nothing flagged means the probes came back clean — a claim bounded by what a repository can show; ⊘ Not evidenced means a working control (a tested restore, an automated rollback) showed no positive evidence — absence of evidence is not evidence of a control, so it's excluded from the score rather than awarded a spurious 10; ◐ Sampled · advisory marks an LLM verdict over a bounded sample — advisory, never a deterministic measurement.
What we checked — 72 dimensions across the health lenses
Each chip is a dimension scored from real signals across architecture, testing, dependencies, security & compliance, documentation, git-history and code quality — in one coherent pass. A surface report typically covers a handful.
How to trust any code-health report — three questions
Can you open the finding? Real findings cite a repo-relative file and line you can open at the cited line — never an absolute scratch path. Here, 1692 of 1720 do; the remainder are repo-wide signals — a dimension-level measurement, not a single line. (Every path in this report is repo-relative by construction: paths are normalized at the producer and the report is rejected if any rooted path leaks through.)
Is there a tool behind the number? Every score below names the method that produced it — Roslyn, git, a scanner, or (for a handful of documentation/naming dimensions) an LLM labelled sampled · advisory — not a narrative.
Does re-running give the same result? Run it again on the same commit and the score — and this report, byte for byte — is identical. A report whose numbers move between runs is describing the run, not the code.
This report answers yes to all three. That's the bar to hold any assessment to.
Tools & methods
The actual versions used this run (captured at analysis time) — re-run on the same commit for the identical score.
Method
Backs
Version
Evaluator
Roslyn static analysis
Complexity, cohesion, coupling, dead code, API surface, layering
What ran differently this time — a tool absent, degraded, or that fell back to an estimate. Named openly, not folded silently into the scores. A degraded run also records its exact cause in diagnostics.md.
D4 Code Duplication — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. Most of this repository's production source (.cs, .py) was not read by duplication detection: no source of those file kinds was exposed to the token comparison by any language model this pass could load. Duplication in .ts, .tsx is measured by R10 Code Duplication and is not part of this gap.
D10 Test Quality — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. The 14,404 test(s) behind this row are the ones the JavaScript/TypeScript census could read, and this repository also carries at least 16 test source file(s) (.py) that it cannot: it reads JavaScript/TypeScript test declarations off disk, so a JUnit/pytest-style suite is invisible to it. Skipped tests, zero-assertion tests and the other quality signals on this row are UNMEASURED in that suite — their absence from the counts above is a gap in this analyzer's language coverage, not a finding that those tests are sound.
D11 Test Reliability — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. Test reliability not included — the JavaScript/TypeScript suite (vitest via `npm ci --ignore-scripts` in the repository root (5699 tests); vitest via `npm ci --ignore-scripts` in packages/a2a-server/ (7 tests); vitest via `npm ci --ignore-scripts` in packages/cli/; vitest via `npm ci --ignore-scripts` in packages/core/; vitest via `npm ci --ignore-scripts` in packages/sdk/; vitest via `npm ci --ignore-scripts` in packages/test-utils/; vitest via `npm ci --ignore-scripts` in packages/vscode-ide-companion/; jest via `npm ci --ignore-scripts` in third_party/get-ripgrep/; vitest via `npm ci --ignore-scripts` in tools/caretaker-agent/cloudrun/egress-service/; vitest via `npm ci --ignore-scripts` in tools/caretaker-agent/cloudrun/ingestion-service/) did not finish re-running within its budget: too large to re-run within its budget.
D12 Dependency Hygiene — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. Not scored — 9 shipped Python distribution(s) were read, but the outdated signal needs pypi.org, and no declaration here carries an exact pin to ask about — a floor or a range installs the newest release it admits and cannot be behind one, so this dimension's own question is only partly answered. NOT a finding that these dependencies are current or healthy.
D14 License Compliance — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. This repository declares package.json, but the licence verdict published here was taken over its Python distribution dependencies. Nothing was read about its npm dependencies' licensing in either direction, and a clean score on this card must not be read as covering them.
D22 Internal API Consistency — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. D22 identifies the intentionally-exposed surface from `IsPackable` and `.Contracts` project names, MSBuild conventions read off the loaded project set. This target exposed no such projects, so the probe never ran; this says nothing about whether the repository has a public API.
D31 IaC & Container Security — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. REDACTED.dockerignore carries no `FROM` instruction, so it declares no build stage and every REDACTED rule this engine owns — the runtime-hardening, key-material, mutable-clone, no-op-shim, build-context, trust-anchor, install-guard, setuid and world-writable-path rules — is outside its own premise there and returned nothing. That silence is deliberate and correct: with no base image there is no image to reason about. It is reported here because it is NOT the same fact as a clean file, and coverage is stated as 9 of 10 Infrastructure-as-Code manifest(s) fully judged rather than as 100%. The vendor scanners (trivy, checkov) do read these files and their findings above stand; only this engine's own stage-keyed rules are absent. No owner action: a build file with no FROM is a legitimate include fragment.
D32 Data Compliance (PII/GDPR) — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. `packages/cli/src/config/settings.ts`, `packages/cli/src/config/settingsSchema.ts`, `packages/cli/src/nonInteractiveCliAgentSession.ts`, `packages/cli/src/ui/hooks/useAgentStream.ts`, `packages/cli/src/ui/hooks/useAtCompletion.ts`, … (+11 more) produced a parse error, so every rule in this engine's `gdpr.yml` was absent there. That absence is NOT a clean result: these rules detect personal data crossing a boundary into a log sink, a URL or browser storage, and a file that was never parsed cannot report any of the three. The rest of the tree analysed normally and its rows above stand; only these files are unaccounted for. You can widen what we reach: fix the syntax error (or exclude the file deliberately) and re-scan to cover it.
AX3 Project dependency cycles — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. This check is computed over which project references which — facts that live in .csproj references. This repository either commits no MSBuild project at all (its C# may still have been parsed as syntax-only projects, which carry no references between them) or its projects failed to load, so there was no graph to read. That is a gap in this analyzer's reach — not a finding that the repository is free of what this check looks for.
AX8 Test isolation — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. This check is computed over which projects are test projects, and what they reference — facts that live in .csproj references. This repository either commits no MSBuild project at all (its C# may still have been parsed as syntax-only projects, which carry no references between them) or its projects failed to load, so there was no graph to read. That is a gap in this analyzer's reach — not a finding that the repository is free of what this check looks for.
C1 Data Protection — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. These personal data controls are read from declarative annotations, request middleware, entity/column names and guard methods in a C# source model, and none was loaded on this run, so there was nothing to gather. That is a gap in this analyzer's language reach — not a finding that the repository lacks personal data controls.
C2 Access Controls — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. These authorization controls are read from declarative annotations, request middleware, entity/column names and guard methods in a C# source model, and none was loaded on this run, so there was nothing to gather. That is a gap in this analyzer's language reach — not a finding that the repository lacks authorization controls.
C3 Audit Trail — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. These audit controls are read from declarative annotations, request middleware, entity/column names and guard methods in a C# source model, and none was loaded on this run, so there was nothing to gather. That is a gap in this analyzer's language reach — not a finding that the repository lacks audit controls.
C4 Data Retention — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. These retention controls are read from declarative annotations, request middleware, entity/column names and guard methods in a C# source model, and none was loaded on this run, so there was nothing to gather. That is a gap in this analyzer's language reach — not a finding that the repository lacks retention controls.
C5 Data-Subject Rights — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. These data-subject rights controls are read from declarative annotations, request middleware, entity/column names and guard methods in a C# source model, and none was loaded on this run, so there was nothing to gather. That is a gap in this analyzer's language reach — not a finding that the repository lacks data-subject rights controls.
DM1 Aggregate boundaries — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. Not scored for TypeScript: a class holding another class reads the same whether the inner type is an aggregate or a value object, so this cannot be decided from source without guessing — reported as guidance rather than measured.
DM2 Strongly-typed ids — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. Not scored for TypeScript: branded ids (`type Id = string & { __brand }`) are an uncommon idiom, so a bare-string id is not on its own evidence of a missing typed id — reported as guidance rather than measured.
DM3 Integration-event coupling — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. Not scored for TypeScript: a domain type used across packages is indistinguishable in source from a deliberate shared-kernel package, so this is reported as guidance rather than measured.
DM4 Rich vs anemic model — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. Not scored for TypeScript: telling a rich domain entity from an anemic data holder needs the behaviour a source-only read cannot always attribute (components, DTOs and readonly value objects are all legitimately data-shaped), so this is reported as guidance rather than measured.
DM5 Encapsulated state — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. Not scored for TypeScript: the language already steers state behind #private/private/readonly, so a mutable public field is rare enough that we report this as guidance rather than measuring it.
DM7 Repository granularity — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. Not scored for TypeScript: deciding whether a repository belongs to an aggregate root needs the aggregate structure, which source alone does not state — reported as guidance rather than measured.
P5 DR & Backup — not measured this run — This is a true statement about the repository that carries nothing for its owner to act on, so it is reported here rather than as a defect in their code. No backup/snapshot/replication config, RTO/RPO or restore-procedure documentation was found — and no production persistence was detected either (no data-access packages, no data-store services, no database resources), so there is nothing in this repository whose loss a DR control would recover. If this system's data lives in a platform or ops repo we can't see, that's where the DR evidence belongs.
R10 Code Duplication — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. 589 further occurrence(s) are not listed individually; the score already reflects all 629.
R4 Test Coverage — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. 30 further occurrence(s) are not listed individually; the score already reflects all 70.
R7 Dead Code — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. 7 further occurrence(s) are not listed individually; the score already reflects all 47.
S1 Web-Security Posture — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. These web-security controls are read from declarative annotations, request middleware, entity/column names and guard methods in a C# source model, and none was loaded on this run, so there was nothing to gather. That is a gap in this analyzer's language reach — not a finding that the repository lacks web-security controls.
X24 Document value interpolated into markup unescaped — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. This repository's C# was parsed (it ships no .sln or .csproj, so it was read as syntax-only projects), but this check proves its findings from resolved symbols and a reference-free parse resolves none. It abstained rather than report a clean bill it could not earn. That is a gap in this analyzer's reach into build-less repositories — not a finding that the repository is free of what this check looks for.
X27 Collection changed while being enumerated — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. This repository's C# was parsed (it ships no .sln or .csproj, so it was read as syntax-only projects), but this check proves its findings from resolved symbols and a reference-free parse resolves none. It abstained rather than report a clean bill it could not earn. That is a gap in this analyzer's reach into build-less repositories — not a finding that the repository is free of what this check looks for.
X5 Nullable reference types — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. This repository's C# was parsed (it ships no .sln or .csproj, so it was read as syntax-only projects), but this check proves its findings from the project graph and a reference-free parse supplies none. It abstained rather than report a clean bill it could not earn. That is a gap in this analyzer's reach into build-less repositories — not a finding that the repository is free of what this check looks for.
Repo exclusion declarations: 42 pattern(s) declared (.gitattributes linguist-generated/vendored, .editorconfig generated_code) excluded 0 source file(s) from code-quality scoring. Declarations are the repo's own visible statement that a tree is machine-written or vendored — auditable in any diff, honored by GitHub the same way.
Limitations & what we did not check
Watchdog assesses the repository exactly as committed, and only the repository. By design it does not reach outside the source tree: the live cloud account, the running CI/CD pipeline, the host's branch-protection and approval rules, the production configuration, or a restore actually exercised against a backup are all out of scope. That boundary is a feature, not a gap — a repo-relative, deterministic scan re-runs identically on any commit and every finding opens at a real file and line, where a live audit can neither be reproduced nor traced. The visible consequence is that controls which leave no in-repo evidence are reported as "not evidenced" and excluded from the score rather than awarded a number a static scan cannot justify.
Per-dimension blind spots
For each dimension that was measured, what a static, repo-only scan structurally cannot see — the honest edge of the measurement, not a failure of it.
D1 Cyclomatic Complexity: Cyclomatic complexity counts branches statically — it cannot tell an essential decision tree from accidental tangle, nor see complexity that lives in data or configuration (large switch-case token tables, DSL lexers/parsers, data-as-code rule tables) rather than control flow: a tokenizer's many single-character cases read as high complexity though each branch is trivial.
D2 Cognitive Complexity: Cognitive-complexity heuristics approximate how hard code is to follow; genuine domain difficulty and well-named intent that eases reading are not captured.
D3 God Classes: "God class" is sized by members and responsibilities visible in the type — a deliberately broad facade over a coherent subsystem can read the same as an accidental grab-bag. For front-end JS the file-length check is cohesion-aware (a single-responsibility module — one class/IIFE — earns a 3× threshold), but cohesion is approximated from top-level declarations, not true dependency structure.
D9 Test Distribution: The test-pyramid shape is inferred from project/folder naming and references, with a single test host bucketed per-file by its path tier and content signals — a suite that names tiers unconventionally and gives no per-file signal can still be mis-bucketed.
D10 Test Quality: Assertion density is structural — it cannot tell a meaningful behavioural assertion from a trivial one, only that an assertion is present.
D13 REDACTED Scanning: REDACTED detection is signature- and entropy-based on the current tree — a secret that does not match a known pattern, or one already rotated, will not be flagged (a clean scan is "nothing matched", not "no secrets exist").
D14 License Compliance: License compatibility is checked against declared package metadata and a policy — mislabelled or missing license metadata, and obligations that depend on how you distribute, are not resolved here.
D15 Churn × Complexity Hotspots: Churn hotspots come from git history — a freshly imported or squashed repository has no churn signal, and recent rewrites can mask a historically risky file.
D16 Bus Factor: Bus-factor is a time-decayed model of commit attribution (who has recently, repeatedly worked a file), not comprehension — pairing, review and reading-without-committing spread knowledge it can't see; bot commits and shared accounts still distort it.
D17 Explicit Debt: Acknowledged-debt signals (TODO/FIXME, suppressions, dead code) are textual — undocumented debt that nobody marked, and debt that lives in design rather than annotations, is invisible. Committed machine-written code (scaffolded migrations, designer/codegen output, generated stubs) is excluded — it is never the team's dead code to delete.
D19 Documentation Quality: Documentation quality is judged by an LLM over a bounded sample of docs — it reads what is written, not whether the docs match the running system, and it is advisory, not a measurement. Its critique rows are drawn from a closed category vocabulary and each row means the same thing in every run, so two scans can be compared row by row; the SET that fires is still a sample, and does not repeat exactly. Measured on one frozen input, six scans at one engine SHA: 2-5 critique rows per scan, 8 distinct rows across the six, 3 of those 8 seen in only one scan. So a D19 row is evidence about the documentation, but a COUNT of D19 rows is not a quantity — never read a change in it as an improvement or a regression.
D20 ADR Quality: ADR quality is an LLM read of the decision records present — it cannot know about decisions made and never recorded, and its verdict is sampled and advisory.
D21 Naming Consistency: Naming quality is an LLM judgement over a bounded sample — it assesses clarity/consistency of the names it sees, not domain-correctness, and is advisory.
D28 Secrets (history): Secret-history scanning sweeps the git log for known patterns — a secret that predates the available history, or never matched a signature, is not found (clean means "nothing matched in the history we can see").
D29 Static Analysis (SAST): SAST findings are pattern-based (semgrep) — it finds classes of bug it has rules for; logic flaws, auth/authorization gaps and issues needing runtime context are out of reach (and clean means "no rule matched").
D30 Dependency Vulnerabilities: CVE matching depends on accurate package/version metadata and on the advisory databases — a vulnerability with no published advisory, or in code not declared as a dependency, is not seen. Coverage needs a RESOLVED graph: an unpinned requirements.txt, or a pom without a resolved build, yields partial coverage rather than a clean verdict. An ecosystem the analyzer cannot scan is reported as unmeasured, never as clean.
D31 IaC & Container Security: IaC scanning checks Dockerfiles/Terraform/Kubernetes against best-practice rules — it cannot see the live cloud account, runtime configuration, or drift between the committed config and what is actually deployed.
D34 Knowledge Freshness: Freshness is decayed commit RECENCY, not comprehension — code read often but rarely committed reads as orphaned, and stable code that genuinely needs no changes is penalised the same as forgotten code; bot/squash commits distort it like the bus factor.
D35 Change Coupling: Change coupling is co-change in COMMITS — files split across separate commits, or coupled only through a shared config/build step, read as uncoupled, and a sweeping commit (rename/format) is excluded so it doesn't couple everything. It shows that files change together, not WHY: a high coupling can be a healthy cohesive pair as readily as a hidden leak.
D43 Malicious Dependencies: Only packages some vulnerability database has already NAMED as malicious are seen — a compromise published in the last hours, or never reported at all, is invisible here, and this dimension reading 10 is not evidence that a dependency is trustworthy. There is no typosquat or dependency-confusion analysis: a package nobody has reported is simply absent from the feeds. Coverage is the dependency scan's: an ecosystem that could not be scanned is disclosed as unmeasured, never as clean.
D44 Platform End-of-Life: The support table is FROZEN, so it goes out of date by losing RECALL: a release that ended support after the table was written is missed until the table is refreshed, and this dimension reading 10 is not evidence that a platform is current. Only platforms the repository DECLARES in a place this pass reads are seen — a runtime named only in a REDACTED (D31's subject), in a CI workflow (D29's), or in a file this pass does not parse (go.mod, a Gemfile ruby directive) is invisible here, which is why a repository declaring none of them abstains rather than scoring. Only frameworks with a PUBLISHED support policy are tracked: React, Flask and Express publish none, so their age cannot be judged and their absence from a report is not a statement that they are supported.
AC2 Forms & labels: Label association is read from static markup — a label wired up at runtime (JS-set aria-labelledby, framework-injected ids) reads as missing, a present label says nothing about whether its text is correct. A known UI-library field component (e.g. a JSX <TextField>) is now checked conservatively — flagged only when it carries NO label/aria-label/aria-labelledby/id/name — but wrapper/context-labelled libraries (Chakra/Radix FormControl+FormLabel) aren't statically visible (possible false positive) and non-JSX lowercased components are still skipped. A click handler on a plain element is now asked for a name too (it is a control the author declared), but the subtree test that answers it is deliberately generous: any DYNAMIC text expression in the subtree counts as a name, so an icon chosen by a ternary ({cond ? <IconA/> : <IconB/>}) reads as named, and a glyph component from a library the icon-import list does not know still names its parent. A clean result is "no unlabelled control found", not a labelling proof.
AC3 Page structure: Page structure is read from the static markup tree — landmarks, headings and lang injected at runtime aren't seen, heading ORDER is checked structurally (not against the rendered visual hierarchy), and lang/title/main fire only on full documents, never partials, and the data-table check sees header-cell presence (a <th> exists), not whether each header correctly associates with its cells. Static readiness, not conformance.
AC4 Keyboard semantics: Keyboard semantics are inferred from markup attributes — interactivity wired purely in script, focus managed at runtime, and component-level handlers are invisible. A clean result means "no static keyboard-trap shape", not a keyboard-operability proof.
AC6 Visual & motion safety: Contrast and motion safety are PARTIAL by construction — literal colours (hex/rgb/hsl/named) in inline styles, in-repo <style> blocks, in-repo .css files, var() tokens, Tailwind neutral utilities and CSS-in-JS top-level declarations are read (same-rule/same-element colour+background pairs only); computed/runtime/theme colour, external-CDN stylesheets, CSS-in-JS dynamic (${…}) and nested-selector colours, cross-element pairs and image contrast stay out of reach, so a clean result is bounded by what the static CSS itself shows.
AC7 A11y enforcement: Enforcement is scored from in-repo config/CI evidence only — an a11y gate enforced in external tooling with no in-repo trace can't be credited, and a configured linter is presence, not proof the rules actually run or block a merge.
AX10 Code composition: Role is inferred from namespace/folder convention, not semantics — a domain concept living in a folder named "Services" reads as application, and the split is lines-of-code, not business value. The business-logic-share score is a SOFT, FLOORED signal: it contributes to the Architecture lens but is floored at the Critical gate, so an infrastructure-heavy design (a gateway, an ETL, a driver) is legitimately low without being nuked to zero.
M4 Documentation accuracy: Onboarding quality is an LLM read of the docs/setup present — it cannot run the onboarding or measure how long a real new joiner takes; the verdict is sampled and advisory.
P4 Deployment & Rollback: Approval/branch-protection rules live in repository settings the scan cannot see — only their in-repo evidence (config files, workflows) is checked, so a control enforced purely in the host's settings reads as "not evidenced".
P6 Release Hygiene: Rollback/observability controls are inferred from repo artefacts (pipelines, dashboards-as-code) — controls configured in external tooling, with no in-repo trace, cannot be credited.
The LLM boundary
LLM-set scores this run (3): D19, D21, M4 (model: Local LLM). For these, a model reads a bounded sample and sets the numeric score; each names its own sample and method on its card. They are sampled and advisory by design: they vary at the margins between runs and are never a deterministic measurement. Every other score in this report is tool-computed at confidence 1.0.
What it measures: How tangled the control flow is — methods with many branches are hard to test and change.
Method: Cyclomatic complexity per method (1 + decision points), computed exhaustively across production source; test projects separated by convention. Deterministic.
375 method(s) exceeded the cyclomatic complexity threshold of 15; the worst was InputPrompt.InputPrompt at 350. A further 4 method(s) were over the threshold but excluded as flat dispatchers (a long switch/match over independent cases: many branches, almost no nesting), the largest being ActivityLogger.patchGlobalFetch at 23 — they are counted neither in the figure above nor in this dimension's score. 1 file carries no cyclomatic complexity row at all for this reason — every one of its over-threshold methods was excluded, so the exclusion is disclosed nowhere in the file itself: packages/cli/src/ui/components/views/ExtensionsList.tsx (ExtensionsList.ExtensionsList at 18). They are named here because the per-file figures other dimensions report are taken BEFORE this exclusion, so such a file can show a high maximum complexity elsewhere in this report and nothing here, with nothing to reconcile the two.
+ 369 more group(s) — more in Appendix A; the complete list is findings.md.
What to do
Resolve the 1 InputPrompt.InputPrompt (cyclomatic 350) finding(s) in Cyclomatic Complexity — start with InputPrompt.tsx. — One of this dimension's main actionable groups (1 warning-level).
Resolve the 1 AppContainer.AppContainer (cyclomatic 276) finding(s) in Cyclomatic Complexity — start with AppContainer.tsx. — One of this dimension's main actionable groups (1 warning-level).
Resolve the 1 useGeminiStream.useGeminiStream (cyclomatic 261) finding(s) in Cyclomatic Complexity — start with useGeminiStream.ts. — One of this dimension's main actionable groups (1 warning-level).
Enforce Cyclomatic Complexity in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d1_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: How hard the code is for a person to follow, beyond raw branching.
Method: Cognitive complexity per method (Sonar-style nesting-penalized score), computed exhaustively over production code, excluding test projects. Deterministic.
+ 522 more group(s) — more in Appendix A; the complete list is findings.md.
What to do
Resolve the 1 InputPrompt.InputPrompt (cognitive 530) finding(s) in Cognitive Complexity — start with InputPrompt.tsx. — One of this dimension's main actionable groups (1 warning-level).
Resolve the 1 vim-buffer-actions.handleVimAction (cognitive 394) finding(s) in Cognitive Complexity — start with vim-buffer-actions.ts. — One of this dimension's main actionable groups (1 warning-level).
Resolve the 1 useGeminiStream.useGeminiStream (cognitive 355) finding(s) in Cognitive Complexity — start with useGeminiStream.ts. — One of this dimension's main actionable groups (1 warning-level).
Enforce Cognitive Complexity in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d2_recommendation.md · top locations in Appendix A, every location in findings.md.
Do you agree with this assessment?
D3 · God Classes7.1 / 10Strong✓ Tool-verified
What it measures: Over-large classes that try to do too much ("god classes").
Method: God-class detection by line and method-count thresholds per logical type (partial classes unified), filtered for generated code and registration/contract false positives. Deterministic.
Resolve the 100 FunctionTooLong finding(s) in God Classes — start with App.tsx (6), config.ts (4), text-buffer.ts (2). — One of this dimension's main actionable groups (100 warning-level).
Resolve the 60 FileTooLong finding(s) in God Classes — start with config.ts (3), settingsSchema.ts, text-buffer.ts. — One of this dimension's main actionable groups (60 warning-level).
Resolve the 51 MethodTooLong finding(s) in God Classes — start with shellExecutionService.ts (3), acpSession.ts (3), geminiChat.ts (3). — One of this dimension's main actionable groups (51 warning-level).
Enforce God Classes in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d3_recommendation.md · top locations in Appendix A, every location in findings.md.
Do you agree with this assessment?
D9 · Test Distribution10.0 / 10Exemplary✓ Tool-verified
What it measures: Whether the test suite has a healthy mix of unit / integration / end-to-end tests.
Method: Test projects classified (Unit/Integration/BDD/E2E) from compiled metadata; test methods counted exhaustively across projects with placement-agnostic disk fallback. Deterministic.
14494 test methods: 14489 unit, 5 integration, 0 BDD, 0 e2e. The JavaScript/TypeScript suite contributes 14408 `it`/`test` case(s) across 973 test file(s) declaring at least one; its tier split is read from package names and paths only. The Python suite contributes 86 test function(s) across 12 file(s) declaring at least one — every `def test…` in a file pytest or unittest would collect, which is those frameworks' own definition of a case; a parametrize table counts once, so this is a floor. Its tier split is read from file names and paths only.
✓ On the Gold path — maintain.
Detailed fixes: d9_recommendation.md.
Do you agree with this assessment?
D10 · Test Quality9.9 / 10Adequategated by 1 critical finding✓ Tool-verified
What it measures: Whether the tests truly assert behaviour rather than just running the code.
Method: Per-test assertions, skips, and mock references analyzed via Roslyn; structured skip-reason tags (BUG:/ENV:) separate documented deferrals from debt. Deterministic.
40 skipped (40 with a documented reason), 67 zero-assertion, no mocking-framework packages referenced (hand-written doubles or no mocking) across 14404 tests. Measured on the JavaScript/TypeScript suite only — at least 16 test source file(s) (.py) went unread, so its test quality is unmeasured and is not in these counts.
No assertions (empty test): should set window title when hideWindowTitle is falsepackages/cli/src/gemini.test.tsx:380
No assertions: should initialize WhisperTranscriptionProvider and handle process · ×66integration-tests/voice-mode.test.ts:50
Skipped (documented): should run allowed sub-command in non-interactive mode · ×40integration-tests/run_shell_command.test.ts:169
What to do
Resolve the 1 No assertions (empty test) finding(s) in Test Quality — start with gemini.test.tsx. — One of this dimension's main actionable groups (1 issue-level).
Resolve the 66 No assertions finding(s) in Test Quality — start with SettingsDialog.test.tsx (14), perf-usage.test.ts (10), memory-usage.test.ts (7). — One of this dimension's main actionable groups (66 warning-level).
Enforce Test Quality in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d10_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether any secrets (keys, tokens, passwords) have leaked into the code.
Method: In-process native secret scanner (entropy plus signature patterns) across all tracked files; no external tool. A clean result is a measured 10, not no-data zero. Deterministic.
Resolve the 1 Leaked secret finding(s) in REDACTED Scanning — start with REDACTED. — One of this dimension's main actionable groups (1 issue-level).
Enforce REDACTED Scanning in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d13_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether the licenses of third-party packages are compatible with your policy.
Method: Third-party package licenses resolved from declared package metadata and checked against the configured policy (allow/deny/copyleft). Deterministic; clean = no incompatible license found at metadata depth.
0 of 63 shipped Python distribution(s) use a banned license. Licences were resolved from PyPI over the distributions a consumer installs — this repository's 9 declared runtime requirement(s) closed transitively over each distribution's published `requires_dist` (54 reached that way). Requirements it states ONLY under an extra, a PEP 735 dependency group, a Poetry dev group or a dev-named requirements file are excluded: pip does not install any of them for a consumer. ★ This repository commits no dependency lockfile that this pass reads, so each licence is the one PyPI publishes for the distribution's CURRENT release rather than for a pinned version. 2 of them publish no licence on PyPI this pass can read; that is missing data, not a violation, and none of them is charged. ★ COVERAGE OF THIS VERDICT: it grades this repository's Python distribution dependencies and nothing else. The repository also declares package.json, and the licences of those dependencies were NOT read by this pass — a gap in this engine's coverage, not a statement about them. So this result says the graded closure carries no banned licence; it does NOT say this repository's licensing is clear.
What it measures: Files that change often and are also complex — the riskiest hotspots.
Method: Per production file churn times cyclomatic complexity over a rolling window, computed from git and Roslyn/JS/Razor analysis. Exhaustive, deterministic per commit date.
Resolve the 29 Hotspot finding(s) in Churn × Complexity Hotspots — start with config.ts (2), github.ts (2), useGeminiStream.ts. — One of this dimension's main actionable groups (29 warning-level).
Detailed fixes: d15_recommendation.md · top locations in Appendix A, every location in findings.md.
Do you agree with this assessment?
D16 · Bus Factor9.0 / 10Strong✓ Tool-verified
What it measures: Whether knowledge is concentrated in too few people (the "bus factor").
Method: Living knowledge per author via time-decayed commit attribution (6-month half-life, focus weighting) across largest source files. Deterministic, avoids blame's mechanical-refactor false positives.
77 source file(s) have their living knowledge concentrated in one author (≥90% of recent, decayed contribution). The largest is packages/cli/src/ui/components/InboxDialog.tsx. Counted over 770 of the 1202 production source files in this repository: the rest are under the ~2,400-byte size floor this dimension measures over.
Off-boarding risk: anonymized user #1 · ×9
Further sole-owners (lower concentration)
What to do
Resolve the 9 Off-boarding risk finding(s) in Bus Factor. — One of this dimension's main actionable groups (9 recommendation-level).
Resolve the 1 Further sole-owners (lower concentration) finding(s) in Bus Factor. — One of this dimension's main actionable groups (1 recommendation-level).
Detailed fixes: d16_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Acknowledged debt left in the code — TODOs, dead code, suppressed warnings.
Method: Roslyn syntactic debt markers (suppressions/TODO/FIXME/HACK/empty-catch/commented-code/Obsolete) plus SymbolFinder dead-code analysis; weighted-debt-per-KLoC density deducted 2.0x per unit. Deterministic, exhaustive.
79 deducted task-comment markers across 262773 LoC (0.0/KLoC) → score 9.9. Task comments only: this repository's language is read without a compiler, so D17's suppression, dead-code and commented-out-code arms did not run and this score counts fewer marker kinds than a .NET repository's would.
Resolve the 77 TodoComment finding(s) in Explicit Debt — start with config.ts (5), types.ts (5), useAgentStream.ts (3). — One of this dimension's main actionable groups (77 warning-level).
Resolve the 2 HackComment finding(s) in Explicit Debt — start with config.ts, run-test.ts. — One of this dimension's main actionable groups (2 warning-level).
Enforce Explicit Debt in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d17_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether the project's documentation is clear, complete, and useful.
Method: Judged by language model at low temperature (0.0-0.1) on a deterministic doc sample (READMEs plus first 25 architecture docs), with two-pass stability filtering. Advisory, sampled.
The Gemini CLI project is well documented across a mix of READMEs, architecture/design docs, and release notes. The main documentation is an extensive README that covers the product (why Gemini CLI), installation, usage examples, contributor guidance, licensing, and detailed test-harness material for CPU performance integration tests, behavioral evaluations, and the ACP implementation. There are also dedicated architecture/Docs markdown files covering the dual-layer execution model, MCP server example, and release process. The documentation is comprehensive and well-structured: a single README (docs/index.md) gives an overview of what Gemini CLI does, install instructions, and links to user-focused guides plus features; architecture/design docs cover release confidence strategy, monorepo structure, local development tracing, PR triage automation, integration tests, behavioral evaluations, and the full CONTRIBUTING.md process; every document in the set is named and present in the outline. The content is clear, complete, and well-organized. The project's documentation is clear and complete for a toolset: the README lists 11 documents (with the first two showing full content), architecture/Docs markdown files are explicitly named at 97 entries, and each of the four main tools (`web_fetch`, `tracker_*`, `write_todos`, `run_shell_command`) has its own detailed technical reference plus usage notes. The coverage is strong with a visible outline for every document present.
Documentation: no installation or build instructions · ×4README.md
✓ On the Gold path — maintain.
Detailed fixes: d19_recommendation.md · top locations in Appendix A, every location in findings.md.
Do you agree with this assessment?
D20 · ADR Quality0.0 / 10Critical✓ Tool-verified
What it measures: Whether architecture decisions are recorded well (context, decision, consequences).
Method: Per-ADR judgment by language model at low temperature with two-pass stability; confidence is share of ADRs evaluated; enforcement-field presence detected deterministically. Advisory.
What it measures: Whether names — types, methods, variables — are clear and consistent.
Method: Judged by language model at low temperature (0.0-0.1) on a deterministic random symbol sample (fixed size, not exhaustive), with disclosed confidence band. Advisory, sampled.
What it measures: Whether any secrets were ever committed — scanned across the full git history, not just now.
Method: REDACTED scan via TWO gitleaks detect passes in an isolated checkout — the full git history, then a second --no-git pass over the working tree as it stands — merged and de-duplicated by (rule, file, line); each match flagged REDACTED. Both invocations are recorded in the audit trail. Exhaustive; when the tool is absent, or when its output cannot be parsed into the expected shape, the dimension is WITHHELD as an explicit measurement gap on our side — unscored and excluded from the lens, never a hedged middling score.
1 finding(s): 0 critical, 1 high, 0 medium, 0 low. Remediation for historically-committed secrets is credential rotation — they remain in history regardless of later deletion.
REDACTED
REDACTED
What to do
Resolve the 1 REDACTED finding(s) in Secrets (history) — start with REDACTED. — One of this dimension's main actionable groups (1 issue-level).
Resolve the 1 Rotate the exposed credentials finding(s) in Secrets (history). — One of this dimension's main actionable groups (1 recommendation-level).
Detailed fixes: d28_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Real static-analysis (SAST) findings — likely security bugs in the code, any language.
Method: Polyglot static analysis via semgrep across the repo using the pinned, image-baked p/security-audit + p/owasp-top-ten rulesets (no scan-time registry fetch); severity rules (ERROR/WARNING/INFO) map to a full-band severity-weighted score. Exhaustive, deterministic; degrades on parse failure.
Coverage: semgrep pattern rules over all files — exhaustive for the rule set, blind to classes of bug without a rule (clean = no rule matched).
24 finding(s): 0 critical, 13 high, 10 medium, 1 low. semgrep hit a parse error in 31 file(s) — `.github/scripts/pr-triage.sh` (line 25, line 26), `packages/cli/src/config/settings.ts` (line 1320, line 1331), `packages/cli/src/config/settingsSchema.ts` (line 3028), `packages/cli/src/nonInteractiveCliAgentSession.ts` (line 687), `packages/cli/src/ui/AppContainer.tsx`, … (+26 more) — so no absence of findings in the named regions is evidence of anything; rows reported elsewhere in those files are real. Fix the syntax error (or exclude the file deliberately) and re-scan to cover them. Separately, one or more rules could not re-parse an embedded snippet in 16 file(s) (e.g. a workflow `run:` block read as shell). Those files WERE scanned and their other rows are unaffected; only those rules' view of those snippets is missing.
REDACTED
REDACTED
REDACTED
What to do
Resolve the 13 REDACTED finding(s) in Static Analysis (SAST) — start with REDACTED (2), REDACTED (2), REDACTED (2). — One of this dimension's main actionable groups (13 issue-level).
Resolve the 10 REDACTED finding(s) in Static Analysis (SAST) — start with REDACTED (3), REDACTED (2), REDACTED. — One of this dimension's main actionable groups (10 warning-level).
Resolve the 1 REDACTED finding(s) in Static Analysis (SAST) — start with REDACTED. — One of this dimension's main actionable groups (1 recommendation-level).
Detailed fixes: d29_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether any dependency has a known published vulnerability (CVE), direct or transitive, in ANY ecosystem the repository declares — Dart pub, Elixir/Hex, Go modules, Java and Kotlin via Maven/Gradle, JavaScript/npm, .NET/NuGet, PHP/Composer, Python/PyPI, RubyGems, Rust/Cargo and Swift.
Method: Dependency-CVE scan across every ecosystem the repository declares, scored ONCE. Three sources are unioned and deduplicated by advisory identity (rule id + alias closure, CVE<->GHSA) scoped to package+version, keeping the worst severity: `osv-scanner --recursive` over osv.dev for Dart pub, Elixir/Hex, Go, Java and Kotlin via Maven/Gradle, npm, PHP/Composer, Python/PyPI, RubyGems, Rust/Cargo and Swift; `trivy fs --scanners vuln` for npm lockfiles; and `dotnet list package --vulnerable --include-transitive` for NuGet (with per-advisory collapse of the project x target-framework fan-out), plus a DECLARED-dependency arm that resolves a published gem's gemspec against rubygems.org where no Gemfile.lock is committed. `SeverityScore(c,h,m,l, normalizer 8.0)`. NotApplicable only when NO ecosystem is readable; if any applicable ecosystem could not be scanned the findings are REPORTED and the score is withheld. Supersedes the npm and OSV arms, retired 2026-09-05.
+ 1 more group(s) — more in Appendix A; the complete list is findings.md.
What to do
Resolve the 29 REDACTED CVE finding(s) in Dependency Vulnerabilities — start with REDACTED (29). — One of this dimension's main actionable groups (29 issue-level).
Resolve the 14 REDACTED CVE finding(s) in Dependency Vulnerabilities — start with REDACTED (14). — One of this dimension's main actionable groups (14 warning-level).
Resolve the 5 Critical CVE finding(s) in Dependency Vulnerabilities — start with REDACTED (5). — One of this dimension's main actionable groups (5 issue-level).
Detailed fixes: d30_recommendation.md · top locations in Appendix A, every location in findings.md.
Resolve the 19 REDACTED IaC finding(s) in IaC & Container Security — start with REDACTED (10), REDACTED (5), REDACTED.development (2). — One of this dimension's main actionable groups (19 warning-level).
Resolve the 14 REDACTED IaC finding(s) in IaC & Container Security — start with REDACTED.gemini-code-builder (6), REDACTED (6), REDACTED.development. — One of this dimension's main actionable groups (14 issue-level).
Resolve the 3 REDACTED IaC finding(s) in IaC & Container Security — start with REDACTED (2), REDACTED. — One of this dimension's main actionable groups (3 recommendation-level).
Detailed fixes: d31_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether anyone still has living knowledge of each file, or it has been orphaned — last understood long ago by someone now gone quiet. The sibling of the bus factor: D16 asks who owns it, D34 asks whether anyone still knows it.
Method: File orphaning as total living-knowledge decay below one focused-commit's worth within a year, computed per-file from the D16 decay model. Exhaustive, deterministic over fixed history.
84 of 770 significant source file(s) are orphaned — their living knowledge has decayed to nothing, so no one currently understands them. The largest is packages/core/src/context/contextCompressionService.ts. Counted over 770 of the 1202 production source files in this repository: the rest are under the ~2,400-byte size floor this dimension measures over.
Orphaned files with no living knowledge
What to do
Resolve the 1 Orphaned files with no living knowledge finding(s) in Knowledge Freshness. — One of this dimension's main actionable groups (1 recommendation-level).
Detailed fixes: d34_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether files that change together actually belong together — pairs that repeatedly co-change in git history despite having no explicit code dependency, surfacing the hidden/logical coupling (and boundaries in the wrong place) a static scan can't see.
Method: Pairwise co-occurrence over the per-commit file sets in git history (production source only — tests and generated dropped): Degree-of-Coupling = shared ÷ min individual revisions, reported above noise floors (each file ≥10 revisions, ≥5 shared commits, ≥50% strength); sweeping commits excluded. Deterministic over fixed history.
Coverage: Population: PRODUCTION source files only — test and generated files are dropped before pairing, so a class co-changing with its own test (trivially ~100%) can't drown the real production↔production coupling. Pairs ranked by Degree-of-Coupling. A non-source file is never a coupling PARTICIPANT either: documentation, schemas, config and data files are dropped with the rest, so a code↔docs pair — a command and the reference page that restates it — is not reported however strongly the two co-change; nor is coupling that runs THROUGH a build step or config file.
Resolve the 20 Change coupling finding(s) in Change Coupling — start with event-metadata-key.ts (2), config.ts (2), default-legacy.ts. — One of this dimension's main actionable groups (20 warning-level).
Resolve the 1 Change-coupling hub finding(s) in Change Coupling — start with AppContainer.tsx. — One of this dimension's main actionable groups (1 warning-level).
Detailed fixes: d35_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether the build pipeline provides supply-chain integrity — generated provenance/attestation, signed artifacts (cosign/sigstore), an SBOM, and pinned build actions. Presence of the configuration, not a runtime guarantee.
Method: Supply-chain provenance/signing read deterministically from CI/build config (.github/workflows, .gitlab-ci.yml, azure-pipelines, Jenkinsfile, .circleci) + the release surface: four signals — generated provenance/attestation (SLSA/in-toto/actions-attest), artifact signing (cosign/sigstore/gitsign), an SBOM (syft/sbom-action/*.spdx.json/*.cdx.json), and SHA-pinned build actions — scored 10·present/denom. NotApplicable without a build pipeline. Detects configuration presence, not runtime enforcement.
What it measures: Whether the repository publishes a coordinated-vulnerability-disclosure policy (SECURITY.md or security.txt) with a reporting contact, so finders know how to report a vulnerability. Presence of a policy file with a contact, not whether the policy is adequate or honoured.
Method: Vulnerability-disclosure policy read deterministically from the repo: a SECURITY.md (root/.github/docs) or .well-known/security.txt / security.txt, regex-checked for a reporting contact (email / URL / mailto). Present + contact → 10; present without a contact → 4; NotApplicable when no policy file exists (it may live off-repo). Detects the policy file's presence + contact, not its adequacy.
What it measures: Whether any dependency the repository declares is published as MALICIOUS rather than merely vulnerable — a package that is an attacker's work, in any ecosystem osv-scanner reads. Scored apart from D30 because the answer is binary: there is no safe version to upgrade to, and the fix is to remove the package and rotate every credential it could have read.
Method: The same dependency scan D30 reads, partitioned on the scanner's own classification rather than rescanned: a row is MALICIOUS when its id is in the `MAL-` space (the ossf/malicious-packages feed) OR its `database_specific.cwe_ids` carries `CWE-506` ("Embedded Malicious Code"). Both channels are structural; the summary text is deliberately NOT read, because a malicious-package record whose summary says only "Critical severity vulnerability" is a real shape ([GHSA redacted]) and a text matcher misses it. Scored BINARY: any surviving row is 0, whatever its severity and however many CVEs sit beside it — a hostile dependency is not a quantity. Applicability and degradation are D30's: NotApplicable only when no ecosystem is readable, and an unscannable ecosystem degrades rather than reading clean. SCORED, not informational.
What it measures: Whether anyone still ships security patches for the platform this repository RUNS ON — the runtime it pins and the framework majors its own constraints hold it to. Separate from D12 because the question differs: a current Django on an end-of-life Python is perfectly up to date and completely unsupported, and the fix is a migration rather than a version bump. What the repository says it merely SUPPORTS is never charged.
Method: End-of-life PLATFORM read from the repository's own declarations and graded against a FROZEN, dated table of vendor support dates — no network, no feed, no API, so this dimension answers identically inside a closed scan fence. Two subjects: a RUNTIME the project pins (a single or all-end-of-life TargetFramework, a .nvmrc or .python-version, a requires-python CAP) and a FRAMEWORK major a dependency constraint cannot move off (a caret, tilde or exact version; `vue@^2.7.16` pins Vue 2). A FLOOR is deliberately never charged — `requires-python = ">=3.8"` states what a package SUPPORTS, not what it runs on — and a multi-target project is charged only when EVERY target is out of support. Runtime 4.0/product capped 8.0, framework 1.5 capped 4.5. The table is safe to freeze because a statement about support that ended in the past cannot become false: it loses recall as it ages, never precision, and a test asserts every entry predates the freeze date. Disjoint from D31 (a container image's OS layer) and D29 (the toolchain a CI workflow installs). Abstains when the repository declares no platform this pass reads — never scores it clean.
1 end-of-life runtime(s) and 0 end-of-life framework(s), read from 1 platform declaration(s) and 15 dependency declaration(s). This dimension reads what the repository says about ITSELF — a pinned target framework, a version file, a capped requires-python, a framework major a constraint cannot move off. A FLOOR is deliberately never charged: `requires-python = ">=3.8"` states what the package SUPPORTS, not what it runs on, and a well-maintained library declares exactly that while running its own CI on a current release. The end-of-life facts are FROZEN and dated, so this dimension needs no network and answers identically inside a closed scan fence; as the table ages it loses recall and never precision, because a statement about support that ended in the past cannot become false. The OS layer of a container image is D31's question and the toolchain a CI workflow installs is D29's; this row is neither.
End-of-life runtime: Node.js 20
What to do
Resolve the 1 End-of-life runtime finding(s) in Platform End-of-Life. — One of this dimension's main actionable groups (1 warning-level).
Detailed fixes: d44_recommendation.md · top locations in Appendix A, every location in findings.md.
Do you agree with this assessment?
Frontend & cross-cutting dimensions
R = React/JS · M = Maturity · P = Readiness.
AC2 · Forms & labels5.4 / 10Adequate✓ Tool-verified
Other · Accessibility — Whether form controls have a programmatic label (an associated label, aria-label or aria-labelledby), buttons have text, links have an accessible name, a click handler on a plain element names the control it declares, fieldsets have a non-empty legend, known UI-library field components carry a label prop, and a placeholder isn't used as the only label. Static markup readiness, not a WCAG conformance claim.
Method: Static markup-model scan: inputs/selects/textareas checked for an associated label[for]/wrapping label/aria-label/aria-labelledby (per document), buttons for accessible text, fieldsets for a legend; placeholder-only labelling flagged. Deterministic, hard fact per control.
Coverage: Population: form controls, buttons, links, fieldsets and known UI-library field components in the PARSED MARKUP files only (.html/.htm/.cshtml/.razor/.vue/.svelte/.jsx/.tsx); components, hidden subtrees and spread/dynamic-attribute elements are skipped, so a control whose label arrives through a spread or a runtime expression is deliberately not judged. Markup built in script — tagged-template (html`…`) UIs and hyperscript DOM factories — is not read at all.
This control has no associated label. Add a <label htmlFor> / wrapping <label> / aria-label / aria-labelledby so assistive tech can name it. — packages/devtools/client/src/App.tsx:406
This control has only a placeholder — a placeholder is not a label (it vanishes on input and many AT ignore it). Add a <label htmlFor>, a wrapping <label>, or aria-label. — packages/devtools/client/src/App.tsx:1047
What to do
Give every control a programmatic label (a <label for> / wrapping <label> / aria-label) and every button text — a placeholder is not a label.
Other · Accessibility — Whether pages declare a language (well-formed BCP-47) and a non-empty title, expose exactly one main landmark and a sane heading order with non-empty headings, keep zoom enabled, title their iframes, give data tables header cells, and avoid meta-refresh. Static markup readiness, not a WCAG conformance claim.
Method: Static markup-model scan: html lang, document <title>, a main landmark and heading order on full documents only, plus zoom-disabling viewports, untitled iframes and meta-refresh anywhere. Deterministic, per structural checkpoint.
Coverage: Population: the PARSED MARKUP documents (.html/.htm/.cshtml/.razor/.vue/.svelte/.jsx/.tsx). The page-level checks — lang, title, single main landmark — fire ONCE PER FULL DOCUMENT (an <html> root) and never on a partial or component fragment, so a repo of fragments is assessed only on the per-element checks (heading order, table headers, iframe titles, meta-refresh, zoom). Markup built in script — tagged-template (html`…`) UIs and hyperscript DOM factories — is not read at all.
No <main> (or role="main") means no "skip to content" target and a weaker landmark map. This document's body is only the mount point <div id="root">, so there is no content here to wrap — render the <main> from the component mounted into it. — packages/devtools/client/index.html:2
What to do
Declare <html lang>, a document <title> and a <main> landmark, keep headings in order, leave zoom enabled, title iframes and drop meta-refresh.
Other · Accessibility — Whether interactive behaviour is keyboard-reachable — no click handler on a non-interactive element lacking a role, tabindex and key handler, no element the repo's own CSS styles `cursor: pointer` without giving it any of the three, no unfocusable element whose only binding is a mouse enter/leave pair or a double-click, no positive tabindex, no href-less anchor, no placeholder-href (#/javascript) link acting as a button. Static markup readiness, not a WCAG conformance claim.
Method: Static markup-model scan: click handlers on non-interactive elements lacking role+tabindex+key handler, positive tabindex values, and href-less anchors. Components skipped, spreads suppressed. Deterministic, hard fact per element.
Coverage: Population: interactive elements plus elements the markup gives a click/key handler or the repo's own CSS styles `cursor: pointer`, in the PARSED MARKUP files only (.html/.htm/.cshtml/.razor/.vue/.svelte/.jsx/.tsx). Keyboard reachability is judged from the markup, never from a rendered page. ★ An interactive element declared in a tagged-template (html`…`) or hyperscript frontend is NOT in this population — no producer reads either — so an empty population is reported as an analyzer gap, never as "this repository has no interactive elements".
A click handler on a plain element with no role and no tabindex: even where another element's key handler can reach it, assistive tech can neither focus it nor announce what it is. Use a <button>, or add role + tabIndex={0}. (×8) — packages/devtools/client/src/App.tsx:584, packages/devtools/client/src/App.tsx:706, packages/devtools/client/src/App.tsx:953, …
What to do
Make custom controls keyboard-operable (role + tabindex + key handler), drop positive tabindex, and give anchors a real href.
Other · Accessibility — Whether focus outlines aren't removed without a replacement, motion respects prefers-reduced-motion, and literal CSS colour pairs meet contrast — PARTIAL: inline styles, in-repo <style> blocks, in-repo .css files, var() tokens, Tailwind neutral utilities and CSS-in-JS literals are read (hex/rgb/hsl/named), never computed/runtime/external-CDN colour. Static markup readiness, not a WCAG conformance claim.
Method: Static markup/CSS scan: inline outline:none/0, literal inline colour/background contrast against the 4.5:1 AA floor, and <style>-block animation without a prefers-reduced-motion guard. Deterministic but PARTIAL — only inline styles and in-repo CSS literals are visible.
Coverage: Population: styled elements in the PARSED MARKUP files (.html/.htm/.cshtml/.razor/.vue/.svelte/.jsx/.tsx), plus in-repo <style> blocks, in-repo .css files and CSS-in-JS literals. Colour contrast is computed from LITERAL colour pairs only (hex/rgb/hsl/named, including var() tokens and Tailwind neutral utilities) — computed, runtime-themed and external-CDN colour is never resolved, so this is a partial read of contrast by construction. Markup built in script — tagged-template (html`…`) UIs and hyperscript DOM factories — is not read at all.
Do you agree with this assessment?
AC7 · A11y enforcement4.0 / 10Weak✓ Tool-verified
Other · Accessibility — Whether accessibility is ENFORCED in the toolchain — an accessibility checker configured over the markup (an a11y lint rule set, e.g. eslint-plugin-jsx-a11y or vuejs-accessibility where the project lints JavaScript) and an automated accessibility assertion wired into tests or CI (axe/pa11y/Lighthouse or an equivalent) — on the Documented→Verified→Prevented ladder.
Method: Repo config/CI scan: an accessibility checker configured over the markup (an a11y lint rule set such as eslint-plugin-jsx-a11y / vuejs-accessibility where JavaScript is linted) and an automated accessibility assertion in tests or CI (axe/pa11y/Lighthouse or equivalent), graded on the Documented→Verified→Prevented rungs. Deterministic, presence/rung detection.
Coverage: Population: the repository's own tooling configuration — lint config, test and CI files — NOT the markup. It is read for a configured accessibility checker and an automated accessibility assertion (axe/pa11y/Lighthouse, or a native-toolkit equivalent), and it credits an INVOCATION, never a mention: a licence filename, an import comment or a doc reference earns no rung. Enforcement configured entirely outside the repository leaves no evidence here and cannot be credited.
No accessibility enforcement found — no a11y linter (eslint-plugin-jsx-a11y) and no axe/pa11y/Lighthouse in tests or CI. Start with the linter to catch issues at author time. What was searched, so you can tell an absence from a miss: the 20 markup file(s) this pass actually assessed, the linter configuration checked in beside them, and this repository's test and CI files — matched by name against the accessibility checkers this dimension carries. An audit run outside the repository, a hosted scanner, or a check whose name is not one of those, is not seen here.
What to do
Enforce accessibility in the toolchain: add eslint-plugin-jsx-a11y, then assert with vitest-axe in tests, then gate axe/pa11y/Lighthouse in CI.
Other · Architecture — How the codebase splits by code ROLE — domain, application, infrastructure, test, generated. The significance map behind the knowledge/coupling weighting, and a DDD signal in its own right: a thin domain core under fat infrastructure is the anemic-domain smell, quantified. How each file's role is decided, because the split is only as good as that: a generated name or a build-output tree makes it Generated, a test project makes it Test, and otherwise the file's NAMESPACE and PATH words are matched against fixed vocabularies in a fixed ORDER — domain, then infrastructure, then application — so a file whose words hit two layers is counted under the earlier one. A production file matching none of them counts as application, so that share reads 'application or unclassified' rather than a measured application layer. Roles come from naming convention, never from what the code does. On this repository the split was taken from the source tree on disk rather than from a loaded .NET workspace, so a file's role is decided by its PATH segments alone — no declared namespace was available to add to the evidence — and generated output is excluded from the census entirely rather than counted as a generated share.
Method: Roslyn line-count by code ROLE: every source file classified Domain/Application/Infrastructure/Test/Generated by namespace + path convention (the shared CodeRoleClassifier), then significant lines summed per role. Deterministic; the advisory score is the business-logic (domain+application) share of production code.
Coverage: Population: ALL source files, each bucketed into ONE of five roles (Domain/Application/Infrastructure/Test/Generated) by namespace + path convention — a file whose layer isn't named in the convention falls to Application (the neutral default), and the split is line-count, not semantic depth or business value.
What to do
The domain core is a small share of production code, but most of the rest matched no layer vocabulary at all — so this is not yet an anemic-domain finding. The namespace/path convention could not place that code, which makes the composition above a statement about the naming, not about the design. Name the layers (or check that the repository's conventions differ from the ones this check knows) before reading a thin domain into it.
Other · Architecture — Whether the codebase has a recognisable, scale-appropriate structure (a named architectural style, or modular enough for its size) rather than being an ad-hoc ball of mud.
Method: Roslyn plus csproj analysis: architecture style detection (DDD, clean, vertical-slice, CQRS) and structure fitness for repo size. Deterministic.
Other · Code Health — Unreviewed-generation residue: shipped members still throwing NotImplementedException, and placeholder string literals left in non-test, non-generated code. Scored as a quality signature, never as a claim about authorship.
Method: Roslyn syntax scan: NotImplementedException throws and placeholder string literals in non-test, non-generated shipped code. Deterministic, code-shape signature.
Other · Code Health — Unfinished work detected by code SHAPE, not keywords: members that only throw a "not implemented" exception, methods that take inputs and return a constant, async methods that never await, dead `if (false)` / `#if false` branches, and skeleton types most of whose members are holes. A real, objective slice of technical debt.
Method: Roslyn syntax scan: incompleteness by code shape (constant-returning methods, async-never-await, #if false branches, guards that return what the code already falls through to, tests an earlier guard already decided, comparisons against NaN, skeleton types), not keyword-gated. Deterministic, code-shape heuristic.
Maturity · Maturity — Whether the repo and its projects have a README, and whether it's substantive and current.
Method: Filesystem scan: README presence, word count, and headings for depth; git history for staleness. Exhaustive across root and project dirs, deterministic.
What to do
Add a 'Testing' section to the root README — how to run the test suite.
Add an 'Architecture' / 'How it works' section to the root README — the high-level shape.
Add a README to the 6 of 10 project(s) that lack one — worth up to 1.2 pts.
Maturity · Maturity — Whether key decisions (ADRs) and the high-level shape (C4/diagrams) are written down.
Method: Filesystem scan: ADR folder/naming conventions or content, plus Mermaid/PlantUML/C4/architecture.md discovery. Exhaustive, deterministic.
No Architecture Decision Records found — no conventional ADR directory, no numbered `NNNN-title` documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer.
What to do
Record significant decisions one document per decision — dated, stating the context, the decision and its consequences — and keep them together wherever your design docs already live (a conventional `docs/adr/` tree, with each file named `NNNN-title` in whatever markup those docs already use, is the most discoverable form).
Maturity · Maturity — Whether the README actually describes the code that exists (LLM-judged, advisory).
Method: Judged by language model at low temperature: README accuracy versus actual projects, within a disclosed tolerance. Advisory, not a measured number.
Readiness · Readiness — Whether SAST, secret/dependency scanning and performance benchmarking are wired in (presence, not runtime).
Method: Filesystem scan: SAST configuration, dependency-update automation, secret scanning, and a benchmark harness or benchmark step — in this repository's own ecosystem. Exhaustive, deterministic.
What to do
Dependabot is configured but does not watch `pip` — add that `package-ecosystem` entry to .github/dependabot.yml so those dependencies get the same automatic update and advisory pressure as the ones it already covers.
Add gitleaks/trufflehog in CI to block PRs that introduce committed secrets.
Readiness · Readiness — Whether releases are automated and safely reversible (probes, rolling updates, approval gates) — from manifests/pipeline files, not the live environment.
Method: Filesystem scan: deployment manifests/IaC (K8s YAML, Helm, Terraform) for rolling updates, probes, approval gates, migration hooks. Exhaustive, deterministic.
Readiness · Readiness — Whether releases are traceable — a maintained changelog and explicit version stamping.
Method: Filesystem scan: changelog file presence and version tags in csproj or git tags. Exhaustive, deterministic.
Do you agree with this assessment?
R1 · Type Safety9.7 / 10Exemplary✓ Tool-verified
React / JS · Code Health — How much of the frontend is typed TypeScript vs untyped JavaScript.
Method: Frontend file inventory: the share of typed TypeScript vs untyped JavaScript across the source tree. Deterministic, exhaustive over frontend files.
What to do
Migrate the remaining .js/.jsx files to TypeScript.
React / JS · Code Health — Near-exact copy-pasted blocks of substantial extent across the frontend (the D4 clone algorithm over JS/TS tokens, D-386): a block is reported only where its copies still agree on most of their own identifiers and literals, or were renamed as they were pasted but kept most of their constants, and where the copies carry enough code to stand on their own or the copied extent reaches 30 lines — so a re-implementation sharing neither names nor values, and a small pasted declaration, are both found and deliberately not reported, and a clean R10 is not a claim that nothing was copied.
Method: Near-exact copy-pasted blocks of substantial extent across the frontend (the D4 clone algorithm run over JS/TS tokens). Masking finds the candidates; a block is reported when its copies still agree on most of their own identifiers and literals, or when a renamed copy still agrees on most of its constants, AND the copies carry enough code to stand on their own — or when the copied extent reaches 30 lines. So a re-implementation sharing neither names nor values, and a small pasted declaration, are deliberately not counted. Deterministic.
27 duplicated blocks under packages/ have copies in at least two of the sibling directories a2a-server, cli, core, devtools — 20 of them are reported below, and 7 are counted here but not reported individually: those copies match on shape but no longer clear R10's bar for an individually reported row — either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 27 and which does not depend on how exactly each block's copies still match. That concentration is one structural fact, not 27 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module — a common library every sibling imports — rather than 27 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on. — packages/a2a-server/src/commands/restore.ts:66
22 duplicated blocks under packages/core/src/ have copies in at least two of the sibling directories agent, agents, code_assist, commands, config, context (+12 more sibling(s) not listed) — 11 of them are reported below, and 11 are counted here but not reported individually: those copies match on shape but no longer clear R10's bar for an individually reported row — either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 22 and which does not depend on how exactly each block's copies still match. That concentration is one structural fact, not 22 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module — a common library every sibling imports — rather than 22 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on. — packages/core/src/agent/legacy-agent-session.ts:400
16 duplicated blocks under packages/cli/src/ have copies in at least two of the sibling directories acp, commands, config, core, services, ui (+1 more sibling(s) not listed) — 10 of them are reported below, and 6 are counted here but not reported individually: those copies match on shape but no longer clear R10's bar for an individually reported row — either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 16 and which does not depend on how exactly each block's copies still match. That concentration is one structural fact, not 16 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module — a common library every sibling imports — rather than 16 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on. — packages/cli/src/ui/hooks/useExtensionUpdates.ts:176
15 duplicated blocks under packages/cli/src/ui/ have copies in at least two of the sibling directories auth, commands, components, hooks, privacy — 5 of them are reported below, and 10 are counted here but not reported individually: those copies match on shape but no longer clear R10's bar for an individually reported row — either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 15 and which does not depend on how exactly each block's copies still match. That concentration is one structural fact, not 15 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module — a common library every sibling imports — rather than 15 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on. — packages/cli/src/ui/auth/ApiAuthDialog.tsx:94
6 duplicated blocks under the repository root have copies in at least two of the sibling directories evals, packages, scripts — 1 of them are reported below, and 5 are counted here but not reported individually: those copies match on shape but no longer clear R10's bar for an individually reported row — either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 6 and which does not depend on how exactly each block's copies still match. That concentration is one structural fact, not 6 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module — a common library every sibling imports — rather than 6 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on. — packages/core/src/code_assist/experiments/client_metadata.ts:19
packages/core/src/tools/definitions/model-family-sets/default-legacy.ts:12 · packages/core/src/tools/definitions/model-family-sets/gemini-3.ts:12 — these 2 files are line-for-line copies of one another — 285 lines are identical, in the same order, in every one of them — so this is one fact about the file set, not a block to extract. An edit made to one file and not the others changes behaviour silently, which is the failure a wholesale copy guarantees. Pick one file as the single source and derive the others from it (re-export it, spread it into the local overrides each variant genuinely needs, or generate the copies at build time) — the few lines that differ between the files are exactly the part each variant should still own. Check first whether the copies are deliberately standalone deliverables (a translation file seeded from its sibling and waiting to be translated); where they are, the duplication is the design, and the honest move is to mark the seeded file as untranslated rather than to let it pass as done. — packages/core/src/tools/definitions/model-family-sets/default-legacy.ts:12
packages/core/src/tools/grep.ts:153 · packages/core/src/tools/ripGrep.ts:189 — the two spans are one implementation copied and then locally edited — 1149 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/tools/grep.ts:153
packages/core/src/agents/local-invocation.ts:71 · packages/core/src/agents/local-session-invocation.ts:82 — the two spans are one implementation copied and then locally edited — 1241 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/agents/local-invocation.ts:71
packages/core/src/prompts/snippets.legacy.ts:32 · packages/core/src/prompts/snippets.ts:43 — the two spans are one implementation copied and then locally edited — 995 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/prompts/snippets.legacy.ts:32
packages/cli/src/ui/components/triage/TriageDuplicates.tsx:25 · packages/cli/src/ui/components/triage/TriageIssues.tsx:25 — the two spans are one implementation copied and then locally edited — 710 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/cli/src/ui/components/triage/TriageDuplicates.tsx:25
REDACTED:36 · REDACTED:174 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. — REDACTED:36
packages/cli/src/nonInteractiveCli.ts:85 · packages/cli/src/nonInteractiveCliAgentSession.ts:82 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — packages/cli/src/nonInteractiveCli.ts:85
packages/cli/src/ui/components/shared/text-buffer.ts:3731 · packages/cli/src/ui/components/shared/text-buffer.ts:3837 — all 2 copies are in the same file, and what repeats is a LIST OF ENTRIES rather than behaviour — the same entries written out more than once. Extract them into one shared, exported constant and spread that constant into each site, rather than into a function the sites call: a list like this often lives in declarative metadata (a decorator's options object, a static configuration table) that a build step must be able to read statically, where a function call is not allowed. Adding an entry to one copy and not the other is the failure this prevents. — packages/cli/src/ui/components/shared/text-buffer.ts:3731
scripts/aggregate_evals.js:18 · scripts/eval_utils.js:15 — the two spans are one implementation copied and then locally edited — 478 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — scripts/aggregate_evals.js:18
packages/core/src/context/processors/rollingSummaryProcessor.ts:24 · packages/core/src/context/processors/stateSnapshotProcessor.ts:25 — the two spans are one implementation copied and then locally edited — 338 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/context/processors/rollingSummaryProcessor.ts:24
packages/cli/src/ui/components/shared/vim-buffer-actions.ts:194 · packages/cli/src/ui/components/shared/vim-buffer-actions.ts:377 — the two spans are one implementation copied and then locally edited — 245 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/cli/src/ui/components/shared/vim-buffer-actions.ts:194
packages/core/src/telemetry/clearcut-logger/clearcut-logger.ts:1515 · packages/core/src/telemetry/clearcut-logger/clearcut-logger.ts:1656 — the two spans are one implementation copied and then locally edited — 272 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/telemetry/clearcut-logger/clearcut-logger.ts:1515
packages/cli/src/commands/extensions/disable.ts:23 · packages/cli/src/commands/extensions/enable.ts:28 — the two spans are one implementation copied and then locally edited — 271 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/cli/src/commands/extensions/disable.ts:23
packages/core/src/routing/strategies/classifierStrategy.ts:130 · packages/core/src/routing/strategies/numericalClassifierStrategy.ts:102 — the two spans are one implementation copied and then locally edited — 292 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/routing/strategies/classifierStrategy.ts:130
packages/cli/src/ui/components/shared/text-buffer.ts:420 · packages/cli/src/ui/components/shared/text-buffer.ts:521 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — packages/cli/src/ui/components/shared/text-buffer.ts:420
packages/core/src/tools/list-mcp-resources.ts:25 · packages/core/src/tools/read-mcp-resource.ts:26 — the two spans are one implementation copied and then locally edited — 184 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/tools/list-mcp-resources.ts:25
packages/core/src/agents/local-subagent-protocol.ts:143 · packages/core/src/agents/remote-subagent-protocol.ts:129 — the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it. — packages/core/src/agents/local-subagent-protocol.ts:143
packages/cli/src/utils/agentSettings.ts:15 · packages/cli/src/utils/skillSettings.ts:18 — the two spans are one implementation copied and then locally edited — 222 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/cli/src/utils/agentSettings.ts:15
packages/a2a-server/src/commands/restore.ts:66 · packages/cli/src/acp/commands/restore.ts:62 — the two spans are one implementation copied and then locally edited — 280 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/a2a-server/src/commands/restore.ts:66
packages/core/src/agents/remote-invocation.ts:63 · packages/core/src/agents/remote-session-invocation.ts:74 — the two spans are one implementation copied and then locally edited — 240 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/agents/remote-invocation.ts:63
packages/core/src/tools/web-fetch.ts:835 · packages/core/src/tools/web-search.ts:130 — the two spans are one implementation copied and then locally edited — 227 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/tools/web-fetch.ts:835
packages/core/src/context/config/profiles.ts:82 · packages/core/src/context/config/profiles.ts:224 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — packages/core/src/context/config/profiles.ts:82
packages/a2a-server/src/commands/memory.ts:18 · packages/cli/src/acp/commands/memory.ts:21 — the two spans are one implementation copied and then locally edited — 247 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/a2a-server/src/commands/memory.ts:18
packages/cli/src/utils/featureToggleUtils.ts:83 · packages/cli/src/utils/hookSettings.ts:36 — the two spans are one implementation copied and then locally edited — 257 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/cli/src/utils/featureToggleUtils.ts:83
packages/core/src/mcp/google-auth-provider.ts:60 · packages/core/src/mcp/sa-impersonation-provider.ts:65 — the two spans are one implementation copied and then locally edited — 192 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/mcp/google-auth-provider.ts:60
packages/core/src/services/sandboxedFileSystemService.ts:50 · packages/core/src/services/sandboxedFileSystemService.ts:114 — the two spans are one implementation copied and then locally edited — 234 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/services/sandboxedFileSystemService.ts:50
packages/core/src/commands/memory.ts:839 · packages/core/src/commands/memory.ts:1256 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — packages/core/src/commands/memory.ts:839
packages/core/src/agents/browser/browserAgentInvocation.ts:166 · packages/core/src/agents/local-invocation.ts:121 — the two spans are one implementation copied and then locally edited — 254 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/agents/browser/browserAgentInvocation.ts:166
packages/core/src/utils/extensionLoader.ts:51 · packages/core/src/utils/extensionLoader.ts:159 — the two spans are one implementation copied and then locally edited — 221 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/core/src/utils/extensionLoader.ts:51
evals/plan_mode.eval.ts:227 · evals/plan_mode.eval.ts:308 — the two spans are one implementation copied and then locally edited — 194 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — evals/plan_mode.eval.ts:227
packages/cli/src/utils/agentUtils.ts:18 · packages/cli/src/utils/skillUtils.ts:29 — the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it. — packages/cli/src/utils/agentUtils.ts:18
packages/core/src/agents/local-subagent-protocol.ts:384 · packages/core/src/agents/remote-subagent-protocol.ts:375 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — packages/core/src/agents/local-subagent-protocol.ts:384
packages/cli/src/ui/components/shared/vim-buffer-actions.ts:640 · packages/cli/src/ui/components/shared/vim-buffer-actions.ts:688 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — packages/cli/src/ui/components/shared/vim-buffer-actions.ts:640
packages/cli/src/ui/components/triage/TriageDuplicates.tsx:872 · packages/cli/src/ui/components/triage/TriageIssues.tsx:564 — the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it. — packages/cli/src/ui/components/triage/TriageDuplicates.tsx:872
packages/cli/src/ui/hooks/shell-completions/gitProvider.ts:29 · packages/cli/src/ui/hooks/shell-completions/npmProvider.ts:24 — the two spans are one implementation copied and then locally edited — 202 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — packages/cli/src/ui/hooks/shell-completions/gitProvider.ts:29
What to do
Act on each finding's own remediation rather than one rule: the move depends on what recurs. Where the copies are executable blocks, give the shared part one home and call it from each site; where they are declarations, a listing, a specialisation already delegating to its base, or one shape repeated per entity, there is no call site and the move is a shared type, a generated set or a factory — sometimes there is nothing to extract.
React / JS · Architecture — Conformance to the detected frontend architecture layout (feature-sliced / layered src) plus cross-package deep-import rules (D-386).
Method: Conformance to the detected frontend layout (feature-sliced / layered src) plus cross-package deep-import rules, over the module graph. Deterministic.
evals/app-test-helper.ts:7 reaches into another package with a relative path (../packages/cli/src/test-utils/AppRig.js) — import the package by name instead. — evals/app-test-helper.ts:7
evals/app-test-helper.ts:7 imports packages/cli/src/test-utils/AppRig.tsx, a module inside the test suite — test helpers carry no compatibility contract and are maintained for the suite, not as an API, so production code that depends on one is coupled to a module nobody keeps stable. Move the shared helper into a source directory both layers may depend on. — evals/app-test-helper.ts:7
evals/auto_memory_modes.eval.ts:12 reaches into another package with a relative path (../packages/core/src/services/chatRecordingService.js) — import the package by name instead. — evals/auto_memory_modes.eval.ts:12
evals/auto_memory_modes.eval.ts:332 reaches into another package with a relative path (../packages/core/src/services/memoryService.js) — import the package by name instead. — evals/auto_memory_modes.eval.ts:332
evals/auto_memory_modes.eval.ts:389 reaches into another package with a relative path (../packages/core/src/services/memoryService.js) — import the package by name instead. — evals/auto_memory_modes.eval.ts:389
evals/component-test-helper.ts:31 reaches into another package with a relative path (../packages/cli/src/test-utils/settings.js) — import the package by name instead. — evals/component-test-helper.ts:31
evals/component-test-helper.ts:31 imports packages/cli/src/test-utils/settings.ts, a module inside the test suite — test helpers carry no compatibility contract and are maintained for the suite, not as an API, so production code that depends on one is coupled to a module nobody keeps stable. Move the shared helper into a source directory both layers may depend on. — evals/component-test-helper.ts:31
integration-tests/globalSetup.ts:15 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/tools/ripGrep.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead. — integration-tests/globalSetup.ts:15
integration-tests/google_web_search.test.ts:7 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/tools/tool-names.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead. — integration-tests/google_web_search.test.ts:7
integration-tests/ripgrep-real.test.ts:11 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/tools/ripGrep.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead. — integration-tests/ripgrep-real.test.ts:11
integration-tests/ripgrep-real.test.ts:15 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/config/config.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead. — integration-tests/ripgrep-real.test.ts:15
integration-tests/ripgrep-real.test.ts:16 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/utils/workspaceContext.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead. — integration-tests/ripgrep-real.test.ts:16
integration-tests/run_shell_command.test.ts:14 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/utils/shell-utils.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead. — integration-tests/run_shell_command.test.ts:14
memory-tests/globalSetup.ts:10 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/tools/ripGrep.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead. — memory-tests/globalSetup.ts:10
packages/cli/src/utils/devtoolsService.ts:63 imports @google/gemini-cli-devtools, a package this repository publishes, but this package's own package.json does not list it in dependencies (or peer/optional dependencies) — it resolves only through the workspace link, so an installed copy of this package is missing it. Add it to this package's dependencies. — packages/cli/src/utils/devtoolsService.ts:63
packages/core/src/utils/schemaValidator.ts:10 imports ajv/dist/2020.js, reaching past a declared dependency's public entry into its build output — that path is the package's toolchain layout, not its API, and a minor version bump can relocate it with no semver signal. Import from the package's documented entry point instead. — packages/core/src/utils/schemaValidator.ts:10
packages/vscode-ide-companion/src/diff-manager.ts:7 imports @google/gemini-cli-core/src/ide/types.js, a package this repository publishes, but this package's own package.json does not list it in dependencies (or peer/optional dependencies) — it resolves only through the workspace link, so an installed copy of this package is missing it. Add it to this package's dependencies. — packages/vscode-ide-companion/src/diff-manager.ts:7
packages/vscode-ide-companion/src/extension.ts:12 imports @google/gemini-cli-core/src/ide/detect-ide.js, a package this repository publishes, but this package's own package.json does not list it in dependencies (or peer/optional dependencies) — it resolves only through the workspace link, so an installed copy of this package is missing it. Add it to this package's dependencies. — packages/vscode-ide-companion/src/extension.ts:12
packages/vscode-ide-companion/src/ide-server.ts:8 imports @google/gemini-cli-core/src/ide/types.js, a package this repository publishes, but this package's own package.json does not list it in dependencies (or peer/optional dependencies) — it resolves only through the workspace link, so an installed copy of this package is missing it. Add it to this package's dependencies. — packages/vscode-ide-companion/src/ide-server.ts:8
packages/vscode-ide-companion/src/ide-server.ts:26 imports @google/gemini-cli-core, a package this repository publishes, but this package's own package.json does not list it in dependencies (or peer/optional dependencies) — it resolves only through the workspace link, so an installed copy of this package is missing it. Add it to this package's dependencies. — packages/vscode-ide-companion/src/ide-server.ts:26
perf-tests/globalSetup.ts:10 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/tools/ripGrep.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead. — perf-tests/globalSetup.ts:10
scripts/build_sandbox.js:32 reaches into another package with a relative path (../packages/cli/package.json) — import the package by name instead. — scripts/build_sandbox.js:32
scripts/generate-keybindings-doc.ts:12 reaches into another package with a relative path (../packages/cli/src/ui/key/keyBindings.js) — import the package by name instead. — scripts/generate-keybindings-doc.ts:12
scripts/generate-keybindings-doc.ts:30 reaches into another package with a relative path (../packages/cli/src/ui/key/keybindingUtils.js) — import the package by name instead. — scripts/generate-keybindings-doc.ts:30
scripts/generate-settings-schema.ts:11 reaches into another package with a relative path (../packages/cli/src/config/settingsSchema.js) — import the package by name instead. — scripts/generate-settings-schema.ts:11
scripts/tests/generate-keybindings-doc.test.ts:13 reaches past another workspace package's public entry into its internals with a relative path (../../packages/cli/src/ui/key/keyBindings.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead. — scripts/tests/generate-keybindings-doc.test.ts:13
What to do
Fix the listed violations: import through the target package's declared public entry rather than a deep path into its internals or a relative path into its directory (19 rows); declare the workspace packages these files import in the importing package's own package.json dependencies (5 rows) — those imports are already bare package specifiers, so the import statements do not change, only the manifest; move the shared test helper into a source directory production code may depend on (2 rows).
React / JS · Code Health — Per-function cyclomatic/cognitive complexity from the token-level function scanner (D-386) — real branching, not a regex heuristic.
Method: Per-function cyclomatic/cognitive complexity from a token-level function scanner (real branching, not a regex heuristic), computed over every frontend function. Deterministic.
handleVimAction has cyclomatic complexity 246 and cognitive complexity 407; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/ui/components/shared/vim-buffer-actions.ts:164
(anonymous) has cyclomatic complexity 204 and cognitive complexity 312; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/ui/components/InputPrompt.tsx:686
textBufferReducerLogic has cyclomatic complexity 194 and cognitive complexity 212; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/ui/components/shared/text-buffer.ts:1787
constructor has cyclomatic complexity 150 and cognitive complexity 146; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/core/src/config/config.ts:993
(anonymous) has cyclomatic complexity 136 and cognitive complexity 274; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/ui/hooks/vim.ts:660
start_sandbox has cyclomatic complexity 131 and cognitive complexity 225; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/utils/sandbox.ts:55
loadCliConfig has cyclomatic complexity 125 and cognitive complexity 132; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/config/config.ts:583
emitKeys has cyclomatic complexity 95 and cognitive complexity 197; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/ui/contexts/KeypressContext.tsx:380
isSafeToCallWithExec has cyclomatic complexity 91 and cognitive complexity 284; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/core/src/sandbox/utils/commandSafety.ts:230
(anonymous) has cyclomatic complexity 87 and cognitive complexity 169; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/nonInteractiveCliAgentSession.ts:82
#resolvePrompt has cyclomatic complexity 84 and cognitive complexity 199; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/acp/acpSession.ts:969
(anonymous) has cyclomatic complexity 80 and cognitive complexity 173; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/nonInteractiveCli.ts:85
loadConversationRecord has cyclomatic complexity 74 and cognitive complexity 178; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/core/src/services/chatRecordingService.ts:133
installOrUpdateExtension has cyclomatic complexity 72 and cognitive complexity 93; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/config/extension-manager.ts:180
AppContainer has cyclomatic complexity 70 and cognitive complexity 27; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/ui/AppContainer.tsx:223
main has cyclomatic complexity 69 and cognitive complexity 100; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/gemini.tsx:466
processStreamResponse has cyclomatic complexity 67 and cognitive complexity 155; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/core/src/core/geminiChat.ts:1354
classifyGoogleError has cyclomatic complexity 66 and cognitive complexity 98; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/core/src/utils/googleQuotaErrors.ts:223
createCustomTheme has cyclomatic complexity 63 and cognitive complexity 39; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/cli/src/ui/themes/theme.ts:394
check has cyclomatic complexity 59 and cognitive complexity 109; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — packages/core/src/policy/policy-engine.ts:600
What to do
Break down the listed branch-heavy functions; aim P95 cyclomatic ≤ 5.
Do you agree with this assessment?
R3 · Large Files4.9 / 10Adequate✓ Tool-verified
React / JS · Code Health — How many source files exceed the large-file threshold.
Method: Components/modules exceeding the large-file threshold, counted exhaustively across the frontend source tree. Deterministic.
155 file(s) over 400 lines (counted as significant lines — blank lines excluded — over production source only, tests excluded), largest first: packages/cli/src/ui/components/shared/text-buffer.ts (3821), packages/core/src/config/config.ts (3737), packages/cli/src/config/settingsSchema.ts (3573), packages/cli/src/ui/AppContainer.tsx (2641), packages/core/src/tools/mcp-client.ts (2237), packages/core/src/telemetry/types.ts (2233) (+149 more).
What to do
Split each oversized file along the responsibilities already in it, into smaller focused modules in the same package.
Do you agree with this assessment?
R4 · Test Coverage9.4 / 10Exemplary✓ Tool-verified
React / JS · Readiness — Static test reachability (D-386): the share of production files reachable from any test via the import graph — measured without running anything.
Method: Static test reachability: the share of production files reachable from any test via the import graph — measured without running anything. Deterministic.
No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one. (×40) — scripts/lint.js, scripts/build_binary.js, scripts/releasing/patch-trigger.js, …
What to do
Add tests that import the unreached modules (directly or through their public entry).
React / JS · Readiness — How outdated the npm dependencies are (a maturity signal). JS/npm CVEs are scored separately in D30 (JS/npm Dependency Vulnerabilities).
Method: npm dependency staleness from manifest/registry metadata (a maturity signal; JS/npm CVEs are scored separately in D30, which answers dependency vulnerabilities for every ecosystem). Deterministic.
What to do
Bump outdated dependencies to current versions to limit upgrade debt.
Do you agree with this assessment?
R6 · Tooling10.0 / 10Exemplary✓ Tool-verified
React / JS · Readiness — Whether the project wires up test, lint and typecheck — detected from each package.json script's COMMAND (eslint / tsc / vitest / jest / playwright), not just its name, and corroborated against CI-workflow invocations so a tool run only in CI still counts.
Method: package.json scanned for test/lint/typecheck script wiring. Deterministic presence check.
Do you agree with this assessment?
R7 · Dead Code8.8 / 10Exemplary✓ Tool-verified
React / JS · Code Health — Files unreachable from every application/tooling/test entry point, and exports nothing imports (module-graph reachability, D-386).
Method: Dead code: files unreachable from every application/tooling/test entry point plus exports nothing imports, via module-graph reachability. Deterministic, exhaustive over the import graph.
Unreachable from the 226 application, 49 tooling and 1064 test entry point(s) detected in this repo. Gate removals on `npm run build` — an undetected custom entry would make these reachable.
no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make (×23) — scripts/sync_project_dry_run.js, scripts/cleanup-branches.ts, scripts/close_duplicate_issues.js, …
no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), but 9 in-repo import(s) from 9 other file(s) do name it (tools/gemini-cli-bot/metrics/scripts/backlog_age.ts, tools/gemini-cli-bot/metrics/scripts/domain_expertise.ts, tools/gemini-cli-bot/metrics/scripts/latency.ts and 6 more) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — tools/gemini-cli-bot/metrics/types.ts
Nothing imports this binding — it is safe to review for removal. (×15) — packages/cli/src/ui/components/AsciiArt.ts:40, packages/cli/src/ui/components/AsciiArt.ts:54, packages/cli/src/ui/contexts/AskUserActionsContext.tsx:30, …
What to do
Delete the dead files and unused exports — every line is maintenance cost and rebuild-estimate inflation with zero runtime value.
React / JS · Readiness — npm dependency truthfulness (D-386): unused dependencies, imports not declared anywhere, and type-/test-only packages shipped as production deps.
Method: npm dependency truthfulness: unused dependencies, imports declared nowhere, and type-/test-only packages shipped as production deps — from the manifest + import graph. Deterministic.
Imported but not declared in any reachable package.json — installs work only by hoisting accident. (×3) — packages/cli/src/config/config.ts:11, packages/cli/src/ui/themes/theme.ts:18, packages/core/src/voice/geminiLiveTranscriptionProvider.ts:7
Declared in the root package.json but never imported anywhere in that package or its workspace members — no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it. (×3)
Only test files import it — move it to devDependencies. — packages/core/src/utils/memoryImportProcessor.test.ts:12
What to do
Remove unused dependencies, declare unlisted imports explicitly, and demote type-/test-only packages to devDependencies.
React / JS · Architecture — Import cycles in the module graph (D-386) — files that can only be understood and changed together.
Method: Import cycles in the module graph, detected exhaustively over JS/TS imports (the same cycle detection as the .NET coupling dimension). Deterministic.
packages/cli/src/acp/acpRpcDispatcher.ts → packages/cli/src/acp/acpSessionManager.ts → packages/cli/src/config/config.ts → packages/cli/src/commands/extensions.tsx → packages/cli/src/gemini.tsx → packages/cli/src/acp/acpStdioTransport.ts → packages/cli/src/acp/acpRpcDispatcher.ts (one verified cycle inside a mutually-dependent group of 11 files) — packages/cli/src/acp/acpRpcDispatcher.ts
Other · Code Health — Whether the code avoids sync-over-async (deadlock-prone blocking on tasks) and async void.
Method: Roslyn syntax scan: async methods scanned for .Wait()/.GetAwaiter().GetResult() and async-void outside event handlers. Deterministic, hard fact per invocation.
Other · Code Health — Whether any branch is dead by construction — a switch arm whose label can never equal a case-normalised subject, or an `else if` whose predicate the arm above has already swallowed.
Method: Roslyn syntax + semantics: switch labels compared against the subject's own case normaliser, and if/else-if chains checked for a literal an earlier arm's containment test already swallows. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X13 · Undrained process stream10.0 / 10Exemplary○ Nothing flagged
Other · Code Health — Whether a child process that has BOTH standard streams redirected drains both — reading one to the end while the other is never read deadlocks once the child fills the unread pipe.
Method: Roslyn syntax + semantics: ProcessStartInfo launches with both streams redirected, checked for a drain of each stream across the enclosing type. Deterministic, provable per finding. Advisory.
Other · Security — Whether a hand-rolled public/private IP check can be walked past — a method that unwraps IPv4-mapped IPv6 but returns the opposite verdict for the same host written as IPv4-compatible, 6to4 or NAT64.
Method: Roslyn syntax + semantics: methods that unwrap IPv4-mapped IPv6 and hand-roll IPv4 range carve-outs, checked for whether the IPv6 branch also accounts for the IPv4-compatible, 6to4 and NAT64 embeddings. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X15 · Unvalidated length from an untrusted reader10.0 / 10Exemplary○ Nothing flagged
Other · Security — Whether a length read out of the stream being parsed is bounded before it is allocated or read — an unchecked count taken from the input lets the input choose the allocation.
Method: Roslyn syntax + semantics: integer lengths read from a BinaryReader and spent on a bulk read or an array allocation, checked for any comparison or bounding call on the value anywhere in the method. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a loop that shortens a string until it fits a length budget has a floor — one with none grinds the value down to the empty string, or past it into a negative-length `Substring`.
Method: Roslyn syntax + semantics: while/do loops whose body's only effect on a string is to drop its last character, checked for whether anything — a direct comparison on the length, a body guard, a break — bounds that length below. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X17 · Uncapped recursion over a caller-supplied document10.0 / 10Exemplary○ Nothing flagged
Other · Security — Whether a walk that recurses through a JSON/XML tree handed in by its caller bounds how deep it will go — an uncapped walk lets the document's nesting choose the stack depth, and the resulting StackOverflowException cannot be caught.
Method: Roslyn syntax + semantics: methods that take a JSON/XML document node and call themselves with a child of it, reachable from an externally-callable member of the same type that accepts a document, checked for any depth parameter, descent counter or threaded arithmetic anywhere in the walk. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a type's disposal matches what it OWNS — releasing what it created, leaving alone what it was handed, and not declaring a finalizer for state that has nothing unmanaged to finalize.
Method: Roslyn syntax + semantics: every assignment to a disposable field is read to decide whether the type CREATED the value or was handed it, and the type's disposal is checked against that answer — an injected interface it disposes, a value it constructed and never releases, a finalizer on a type holding nothing unmanaged, and a disposable local whose every reference is a plain member read. A value handed to a container that disposes its contents (a parent control's `Controls` collection, a component `IContainer`) is released by that container and is not reported; generated code is out of population. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a method that temporarily changes state belonging to the whole process — the working directory, an environment variable — puts it back on EVERY path: a restore reached only when nothing throws leaks the change to the rest of the process.
Method: Roslyn syntax + semantics: method bodies that write the process working directory or an environment variable and write it back in the same body, checked for whether that restore sits in a `finally`/`catch` or only on the straight-line path. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether an argument guard throws the exception its own condition describes — a guard that rejects a value for being EMPTY and reports it as `ArgumentNullException` tells the caller a parameter was null when it provably was not.
Method: Roslyn syntax: `throw new ArgumentNullException(nameof(p))` statements controlled by an `if`, whose condition is read for a test that is true of a NON-null `p` — an emptiness test that dereferences it (`p.Count == 0`, `!p.Any()`) or a BCL predicate documented true of the empty value (`string.IsNullOrEmpty(p)`). Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a `when` guard is free of side effects — a guard that increments a counter or assigns while deciding whether its arm matches applies that change during PATTERN MATCHING, on an arm that may not be selected, and skips it entirely when a short-circuit to its left answers first.
Method: Roslyn syntax: `when` guards on case labels and switch-expression arms, read for a mutation (`++`/`--`/assignment) sitting in a position the guard's own `&&`/`||`/`??`/`?:`/`?.` can skip. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a method that TAKES a lock or semaphore and gives it back from a flag-guarded `finally` returns the value that flag implies — reporting success while the guard hands the primitive back admits a second caller the exclusion was there to keep out, and reporting failure while the guard keeps it leaves nothing to ever give it back.
Method: Roslyn syntax: `try` statements whose `finally` releases a synchronisation primitive under a bare local-bool guard, where the method also TOOK that same primitive before the `try`, checked for a `return` of a bool literal whose value disagrees with the flag state the method's own straight-line assignments put it in. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether the work a diagnostic log line costs is paid only when that line is wanted — C# evaluates a call's arguments BEFORE the call, so a trace/debug message joined or projected out of a collection is built in full on every pass, and then discarded by a sink the shipped configuration leaves switched off.
Method: Roslyn syntax: log calls at a diagnostic level (a `Log`-prefixed method naming Trace/Debug/Verbose, or a bare `Debug`/`Trace`/`Verbose` on a receiver named for a logger), whose argument list is read for a call whose cost scales with a sequence — a LINQ operator, a materialisation, `string.Join`, a serializer — with no enclosing level check or conditional-compilation region. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a value the caller is invited to supply is the value the type actually uses — a constructor parameter stored in a private field that nothing ever reads while the default it was given is spelled out a second time at the site that should have read it, a keyed lookup that falls back to a different setting than the one its key names while the same type falls back to the matching one for that same key, or a culture-sensitive parse given no format provider by a type that feeds its own settable culture to the same kind of parse elsewhere. Either way, every caller who supplies a value silently gets something else.
Method: Roslyn syntax: private instance fields of a non-partial type assigned in a constructor from one of its own parameters with a `??` fallback, checked for whether anything in the type body reads the field and whether that same fallback expression is spelled out again outside the constructor; and `??` fallbacks onto a member access from a lookup call carrying exactly one string literal, grouped by that key across the type and checked for a fallback member whose folded name disagrees with the key while a sibling site for the same key agrees with it. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a value handed from a callback to the body that waits on it crosses on something built to be crossed — a `Queue<T>`/`List<T>`/`Dictionary<K,V>` written inside an event handler and read back outside it is mutated by two flows at once, and the semaphore or completion source beside it orders how MANY items exist while leaving the collection's own head, tail and backing array unprotected.
Method: Roslyn syntax: method, accessor, local-function and lambda bodies that declare BOTH a non-thread-safe generic collection (`Queue`/`Stack`/`List`/`Dictionary`/`HashSet`/`Sorted*`/`LinkedList`) and a synchronisation primitive (`SemaphoreSlim`/`TaskCompletionSource`/`ManualResetEvent(Slim)`/`AutoResetEvent`/`CountdownEvent`) as locals, then read for a `+=`-registered lambda that raises that primitive while the body outside every lambda waits on it — and, in that scope, a mutating call on the collection inside the lambda paired with a mention of it outside. Any `lock` in the scope abstains it. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X28 · Index access outside its own emptiness guard10.0 / 10Exemplary○ Nothing flagged
Other · Code Health — Whether a condition that tests a value for emptiness indexes that same value only where the test holds — an `||` written one parenthesis too far to the left leaves an index access outside the guard beside it, so the empty case the guard exists to anticipate reaches the index and throws.
Method: Roslyn syntax only, no semantic model: the OUTERMOST `&&`/`||` of every boolean condition, read for a symbol the condition tests for emptiness (`string.IsNullOrEmpty`/`IsNullOrWhiteSpace`, a `Length`/`Count` comparison against a literal, `Any()`, a `Length`/`Count` pattern, or a comparison against `""`) and ALSO indexes. Each `symbol[...]` access is placed by a boolean-reachability walk from the access up to the outermost connective: an access is COVERED when some enclosing step has it in the right operand and the left operand, under the truth value that step forces, proves the symbol non-empty — a recursion over `&&`/`||` whose true- and false-directions are asymmetric. A finding needs BOTH an uncovered access and a covered one on the same symbol in the same condition, which is the agreeing twin that separates a misplaced parenthesis from an unrelated length test. Bare index accesses with no emptiness test in the condition are neither counted nor reported; a non-identifier receiver and a lambda nested inside the condition are outside the population. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X29 · Per-element action decided by a fixed element10.0 / 10Exemplary○ Nothing flagged
Other · Code Health — Whether a decision taken once per element is taken ABOUT that element — a test inside a counted loop that reads a fixed subscript of the very collection its guarded statement indexes by the loop variable applies element zero's answer to all of them, so the elements that differ from it are all handled wrongly, and in the same direction.
Method: Roslyn syntax only, no semantic model: every `for` statement declaring exactly ONE loop variable, and every `if` inside its body that is not under a nested loop or a lambda. A site enters the population when the `if`’s condition never mentions the loop variable while the statement it guards indexes some collection by that variable ALONE (`c[i]`; `c[i + 1]` and `c[i, j]` are outside it). A finding additionally needs the AGREEING TWIN at the same-collection grain: the condition must read THAT SAME collection at a subscript that does not move — written into the condition, or reached through a local declared BEFORE the loop, so an alias bound inside the body is not followed. Both collection expressions must be simple identifiers. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether exceptions are handled rather than silently swallowed or rethrown with lost stack traces.
Method: Roslyn syntax scan: every catch clause counted; empty catches and bare rethrows flagged. Population is all catch clauses, not estimated. Deterministic, hard fact.
Do you agree with this assessment?
X30 · Support guard that admits what it rejects10.0 / 10Exemplary○ Nothing flagged
Other · Code Health — Whether a guard written as a NEGATED `||` says what its author meant — `!(a || b || x != k)` is `!a && !b && x == k` by De Morgan, so a bail-out that mixes capabilities the code needs with a fault it refuses turns inside out: it fires only where the capabilities are ABSENT, and lets every value the fault term names walk straight into the body that cannot handle it.
Method: Roslyn syntax only, no semantic model: every logical-not whose operand is a parenthesised `||` chain of two or more disjuncts, flattened (a left-nested `a || b || c` read once would see `(a || b)` as one disjunct). A site enters the population on that shape alone. A finding additionally needs the disjuncts to DISAGREE in polarity: at least one bare boolean read — an identifier or member access, never an invocation, which is a predicate rather than a capability flag — and at least one `x != <constant>`, the only form that negates into an exact-value pin (`== null` negates into a looser requirement and is outside the fault set). Consistently-polarised disjunctions, all-fault or all-capability, are counted and never reported; a negated `&&` is outside the population entirely. No same-receiver gate: it was measured to cost a real defect and remove no false positive. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X32 · Type resolved by simple name across every loaded assembly10.0 / 10Exemplary○ Nothing flagged
Other · Code Health — Whether a plugin lookup names the type it means — searching every assembly loaded into the process for a candidate whose SIMPLE name equals a string supplied at runtime, and taking the first one found, is decided by assembly LOAD ORDER rather than by this source, so the same name can resolve to a different type on the next run.
Method: Roslyn syntax only, no semantic model: every invocation of `First`/`FirstOrDefault`/`Single`/`SingleOrDefault` whose OWN expression subtree contains both a `GetAssemblies()` call and a `GetTypes()`/`GetExportedTypes()` call — a single-element pick out of every type loaded into the process. A nested selector in the same chain sees no `GetAssemblies()` in its own subtree and is outside the population, so one lookup counts once however many links its chain has. A finding additionally needs both remaining halves: the selector must be `First`/`FirstOrDefault` (`Single`/`SingleOrDefault` reports the ambiguity rather than resolving it, and is counted and never reported), and the chain must carry an `==` comparison of `<lambda parameter>.Name` against something that is not a literal. The receiver must be a plain identifier bound by one of the chain’s own lambdas, which places `assembly.GetName().Name == "X"` outside the rule by construction. One exemption: a `.Name` test joined by `&&` to a `FullName`/`AssemblyQualifiedName` test on the same identifier is spared; joined by `||` it is not. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether log calls use message templates (queryable) rather than interpolated strings.
Method: Roslyn syntax scan: every log call-site counted; interpolated-string first-argument violations flagged. Population is all log calls, not estimated. Deterministic.
Do you agree with this assessment?
WCAG coverage — what static analysis assessed
Statically assessed 12 of 55 WCAG 2.2 Level A/AA success criteria (22%; ≈24% of the 50 WCAG 2.1 AA criteria for EN 301 549). The other 43 require runtime or manual evaluation. Partial signal only (a clean result is necessary, not sufficient; static analysis fully verifies none). This is accessibility readiness, not a conformance claim — a WCAG conformance claim requires manual evaluation (WCAG-EM 1.0).
The score is the rank-weighted fold of these lenses (worst-heaviest), each including its meta-dimensions; a lens with a Critical contributor is capped at Fair (its band reads "gated by …") and is never the strongest area however high its average.
Capped at Fair by a Critical contributor — resolve it before relying on this lens.
Not evidenced — 4 control(s) we could not find positive evidence for
These checks grade a working control, and the repository shows no evidence of one. That is deliberately not scored as a zero: a repository cannot show an ops runbook, a database TTL or an infrastructure-side audit log, so absence of evidence here is not evidence the control is missing. It is also not a statement that the check is irrelevant to this codebase — the thing it grades applies; we just could not see it. Excluded from the score either way.
C3 Audit Trail — Not assessed: these audit controls are read from a source model (declarative annotations, request middleware, entity/column names, guard methods) that was not loaded for this repository — because the repository is written in a language this check does not yet model, or because its projects failed to load. Absence of an idiom this check recognises is NOT evidence that this repository lacks audit controls: it may implement them entirely in its own ecosystem. This is a gap in the analyzer's language coverage, not a finding about this repository.
C4 Data Retention — Not assessed: these retention controls are read from a source model (declarative annotations, request middleware, entity/column names, guard methods) that was not loaded for this repository — because the repository is written in a language this check does not yet model, or because its projects failed to load. Absence of an idiom this check recognises is NOT evidence that this repository lacks retention controls: it may implement them entirely in its own ecosystem. This is a gap in the analyzer's language coverage, not a finding about this repository.
C5 Data-Subject Rights — Not assessed: these data-subject rights controls are read from a source model (declarative annotations, request middleware, entity/column names, guard methods) that was not loaded for this repository — because the repository is written in a language this check does not yet model, or because its projects failed to load. Absence of an idiom this check recognises is NOT evidence that this repository lacks data-subject rights controls: it may implement them entirely in its own ecosystem. This is a gap in the analyzer's language coverage, not a finding about this repository.
P5 DR & Backup — not evidenced — repo shows no backup/RTO/RPO controls; absence of evidence is not evidence of a working control
Not included — 57 check(s) not relevant to this codebase
These checks had nothing to measure here (no tests, no git history, the codebase is small, or the architecture style doesn't apply), so they're omitted above rather than scored low.
AC1 Text alternatives — No image/media element found in the parsed markup — AC1 not applicable here.
AC5 ARIA correctness — No ARIA usage found in the parsed markup — AC5 not applicable here.
AX1 Captive dependencies — no DI registrations detected
AX2 Stateful singletons — no singleton implementations detected
AX3 Project dependency cycles — not assessed — project cycles and dependency direction are computed over a project-reference graph that was not loaded for this repository, because the repository is written in a language this check does not yet model, or because its projects failed to load. This is a gap in the analyzer, not a finding about this repository
AX4 Dependency direction — not applicable to a transaction-script/CRUD architecture (the inward-dependency rule is for layered/clean styles)
AX6 Interface segregation — no public interfaces
AX7 Slice cohesion — not applicable — not a vertical-slice architecture
AX8 Test isolation — not assessed — test isolation is computed from a project graph (which projects are test projects, and what they reference) that was not loaded for this repository, because the repository is written in a language this check does not yet model, or because its projects failed to load. This is a gap in the analyzer, not a finding about this repository
AX9 CQS / query purity — no CQRS query handlers detected — query purity is not applicable to this codebase
AXB2 Runtime readiness — Advisory — this card reports evidence and never carries a score, so there is nothing missing here.
C1 Data Protection — Not assessed: these personal data controls are read from a source model (declarative annotations, request middleware, entity/column names, guard methods) that was not loaded for this repository — because the repository is written in a language this check does not yet model, or because its projects failed to load. Absence of an idiom this check recognises is NOT evidence that this repository lacks personal data controls: it may implement them entirely in its own ecosystem. This is a gap in the analyzer's language coverage, not a finding about this repository.
C2 Access Controls — Not assessed: these authorization controls are read from a source model (declarative annotations, request middleware, entity/column names, guard methods) that was not loaded for this repository — because the repository is written in a language this check does not yet model, or because its projects failed to load. Absence of an idiom this check recognises is NOT evidence that this repository lacks authorization controls: it may implement them entirely in its own ecosystem. This is a gap in the analyzer's language coverage, not a finding about this repository.
D11 Test Reliability — Test reliability not included
D12 Dependency Hygiene — Not scored — 9 shipped Python distribution(s) were read, but the outdated signal needs pypi.org, and no declaration here carries an exact pin to ask about — a floor or a range installs the newest release it admits and cannot be behind one, so this dimension's own question is only partly answered. NOT a finding that these dependencies are current or healthy.
D18 Solution Shape — D18 scores the shape of a .NET solution; this repository has no .NET solution or project files, so the dimension does not apply.
D22 Internal API Consistency — The exposed public-API surface could not be collected — no C#/VB projects loaded.
D23 Boundary Type-Coupling — Production source is present (.cs, .py, .ts, .tsx) but bounded contexts are resolved over the C#/VB project set, which exposed none, so context scope could not be assessed. Not scored — this is a gap in the analyzer, not a verdict about this repository. Declaring the codebase's bounded contexts (≥2) would let cross-boundary type coupling be assessed — see the recommendation on this dimension for where. Declare them in `.codehealth/config.yaml` at the repository root (create it if absent), mapping each context name to the module-path or namespace prefixes that belong to it — e.g. `architecture:` → `contexts:` → `Billing: ["src/billing", "Acme.Billing"]`, `Catalog: ["src/catalog", "Acme.Catalog"]`.
D24 Comment Value — No inline comments to assess — comment value is not applicable here.
D25 ADR Conformance — no ADRs to check
D26 Project Cohesion — Project cohesion is assessed over the .NET project set; this target exposed no projects, so project size and spread could not be assessed. Not scored — this is a gap in the analyzer's reach, not a verdict about this repository.
D27 Navigability — symbol resolution incomplete — navigability not assessed
D32 Data Compliance (PII/GDPR) — 16 file(s) were not parsed by semgrep — the PII/GDPR ruleset never ran over them
D39 IL Efficiency — D39 measures the IL emitted by a .NET build; this repository has no .NET solution or project files, so the dimension does not apply.
D4 Code Duplication — Duplication not measured — .cs, .py not exposed to the token comparison
D40 Network Egress Confinement — No Kubernetes/orchestration workloads found in the repository manifests; network egress policy is a cluster-native control that may live at the platform/firewall layer, so there is nothing to assess here.
D41 Kernel & Syscall Confinement — No Kubernetes/orchestration workloads found in the repository manifests; seccomp/AppArmor/SELinux confinement is a workload-level control, so there is nothing to assess here.
D42 Runtime Threat Enforcement — No Kubernetes/orchestration workloads found in the repository manifests; runtime threat-detection and admission-control policy are cluster-level controls, so there is nothing to assess here.
D5 Coupling — Inter-project coupling could not be assessed — no analyzable project graph was found for this repository. Not scored: a gap in the analyzer's reach, not a verdict about this repository. (Coupling here is Martin afferent/efferent/instability plus reference cycles across a project-reference graph, read today from .NET project files; other ecosystems' module graphs are not read yet.)
D6 Cohesion (LCOM4) — Cohesion (LCOM4) is measured over a CS/VB/GO/SCALA/SWIFT/DART class graph, and this repository's production source is mostly .py, .ts, .tsx, which this pass does not read, so cohesion was not assessed for this repository. Not scored — this is a gap in the analyzer, not a finding about this repository.
D7 Architectural Integrity — no checkable ADRs, and no project-reference graph for the cycle pass to read — so this dimension makes no claim about dependency cycles in either direction (where this repository's language has an import-cycle lens, cycles are reported there). Architectural integrity not assessed
D8 Code Coverage — Coverage NOT MEASURED: the JavaScript/TypeScript half could not be measured — the vitest suite in the repository root ran and passed but wrote no lcov report. Coverage is excluded from the score rather than counted as a near-zero. The named suite step is one the repository's maintainers can perform; once it passes, the real number is measured on the next scan. Alternatively, commit the lcov/Cobertura report your CI produces and it is read without a re-run.
DM1 Aggregate boundaries — not scored for TypeScript: a class holding another class reads the same whether the inner type is an aggregate or a value object, so this cannot be decided from source without guessing — reported as guidance rather than measured
DM2 Strongly-typed ids — not scored for TypeScript: branded ids (`type Id = string & { __brand }`) are an uncommon idiom, so a bare-string id is not on its own evidence of a missing typed id — reported as guidance rather than measured
DM3 Integration-event coupling — not scored for TypeScript: a domain type used across packages is indistinguishable in source from a deliberate shared-kernel package, so this is reported as guidance rather than measured
DM4 Rich vs anemic model — not scored for TypeScript: telling a rich domain entity from an anemic data holder needs the behaviour a source-only read cannot always attribute (components, DTOs and readonly value objects are all legitimately data-shaped), so this is reported as guidance rather than measured
DM5 Encapsulated state — not scored for TypeScript: the language already steers state behind #private/private/readonly, so a mutable public field is rare enough that we report this as guidance rather than measuring it
DM6 Domain ↔ infrastructure boundary — this TypeScript/JavaScript repository maps no type to a persistence framework (TypeORM/Prisma/MikroORM/Sequelize/Mongoose), so DM6's domain↔infrastructure fusion read has no population to be taken over
DM7 Repository granularity — not scored for TypeScript: deciding whether a repository belongs to an aggregate root needs the aggregate structure, which source alone does not state — reported as guidance rather than measured
ED1 Event-Driven — not scored — this repository shows none of the 3 signals this lens looks for
ED5 Idempotency — no mutating command handlers or message consumers detected — idempotency check not applicable (this repository commits no MSBuild project, so its C# was read as syntax-only projects — a handler marked ONLY by an interface from a package is not visible without a build)
ES1 Event Sourcing — not scored — this repository shows none of the 3 signals this lens looks for
P12 CI test-gate honesty — Reported, not scored — this card publishes what the CI gate does with the test inventory rather than grading it. The findings above are its output.
P2 Observability — Observability was not assessed: this check reads a source model that does not carry this repository's product — because the repository is written in a language this check does not yet model, or because its projects failed to load. Absence of a logging idiom this check recognises is NOT evidence that this repo lacks structured logging (it may log through its own ecosystem's logger). This is a gap in the analyzer, not a finding about this repository.
P7 Outbound HTTP resilience — not measured — the application kind could not be determined for this repo
P8 Schema migrations — not assessed — schema-migration practice is read from a source model that was not loaded for this repository, because the repository is written in a language this check does not yet model or because its projects failed to load. This is a gap in the analyzer, not a finding about this repository
P9 Domain vs controller coverage — no coverage report found on disk — produce a coverage report in a standard format (lcov — `vitest --coverage --coverage.reporter=lcovonly`) and commit it — a hosted scan measures a clone of the repository, so a report that exists only in a working tree, a CI runner's or your own, never reaches it; the artefact is commonly gitignored, so `git add -f` that one file (or un-ignore its path) and commit it alongside the code it measures, or wire coverage collection into CI, to enable this cross-layer check
PF1 Benchmark discipline — Performance was not assessed: this lens reads a source model that was not loaded for this repository, because the repository is written in a language this lens does not yet model or because its projects failed to load. This is a gap in the analyzer, not a finding about this repository — in particular it is NOT a statement that this repo is unpackaged or performance-careless.
PF2 Allocation hygiene — Performance was not assessed: this lens reads a source model that was not loaded for this repository, because the repository is written in a language this lens does not yet model or because its projects failed to load. This is a gap in the analyzer, not a finding about this repository — in particular it is NOT a statement that this repo is unpackaged or performance-careless.
PF3 Async & latency hygiene — Performance was not assessed: this lens reads a source model that was not loaded for this repository, because the repository is written in a language this lens does not yet model or because its projects failed to load. This is a gap in the analyzer, not a finding about this repository — in particular it is NOT a statement that this repo is unpackaged or performance-careless.
S1 Web-Security Posture — Not assessed: these web-security controls are read from a source model (declarative annotations, request middleware, entity/column names, guard methods) that was not loaded for this repository — because the repository is written in a language this check does not yet model, or because its projects failed to load. Absence of an idiom this check recognises is NOT evidence that this repository lacks web-security controls: it may implement them entirely in its own ecosystem. This is a gap in the analyzer's language coverage, not a finding about this repository.
SC1 Supply-chain hygiene — Advisory — this card reports evidence and never carries a score, so there is nothing missing here.
X2 Cancellation propagation — no async methods found
X24 Document value interpolated into markup unescaped — This check needs a compiled C# program and this repository commits no project file to compile, so only its syntax could be read. That is a limit of the analyzer, not a finding about your code.
X27 Collection changed while being enumerated — This check needs a compiled C# program and this repository commits no project file to compile, so only its syntax could be read. That is a limit of the analyzer, not a finding about your code.
X5 Nullable reference types — This check needs a compiled C# program and this repository commits no project file to compile, so only its syntax could be read. That is a limit of the analyzer, not a finding about your code.
X9 Subsumed condition operand — Advisory — this card reports evidence and never carries a score, so there is nothing missing here.
Appendix A — Findings (grouped)
The findings behind the scores, grouped by severity, then by dimension and kind. The high-severity issues are enumerated in full below; items per group are capped at 25 with any overflow stated explicitly per group, never silently truncated. The complete machine-readable list of every finding (all severities) is the companion findings.md in this report's bundle.
AC4 · Keyboard semantics· Click handler on a non-interactive <div> · ×7
Click handler on a non-interactive <div> packages/devtools/client/src/App.tsx:584— A click handler on a plain element with no role and no tabindex: even where another element's key handler can reach it, assistive tech can neither focus it nor announce what it is. Use a <button>, or add role + tabIndex={0}.
Click handler on a non-interactive <div> packages/devtools/client/src/App.tsx:706— A click handler on a plain element with no role and no tabindex: even where another element's key handler can reach it, assistive tech can neither focus it nor announce what it is. Use a <button>, or add role + tabIndex={0}.
Click handler on a non-interactive <div> packages/devtools/client/src/App.tsx:953— A click handler on a plain element with no role and no tabindex: even where another element's key handler can reach it, assistive tech can neither focus it nor announce what it is. Use a <button>, or add role + tabIndex={0}.
Click handler on a non-interactive <div> packages/devtools/client/src/App.tsx:1083— A click handler on a plain element with no role and no tabindex: even where another element's key handler can reach it, assistive tech can neither focus it nor announce what it is. Use a <button>, or add role + tabIndex={0}.
Click handler on a non-interactive <div> packages/devtools/client/src/App.tsx:1266— A click handler on a plain element with no role and no tabindex: even where another element's key handler can reach it, assistive tech can neither focus it nor announce what it is. Use a <button>, or add role + tabIndex={0}.
Click handler on a non-interactive <div> packages/devtools/client/src/App.tsx:1345— A click handler on a plain element with no role and no tabindex: even where another element's key handler can reach it, assistive tech can neither focus it nor announce what it is. Use a <button>, or add role + tabIndex={0}.
Click handler on a non-interactive <div> packages/devtools/client/src/App.tsx:1922— A click handler on a plain element with no role and no tabindex: even where another element's key handler can reach it, assistive tech can neither focus it nor announce what it is. Use a <button>, or add role + tabIndex={0}.
Import cycle (3 files) packages/cli/src/ui/hooks/shell-completions/gitProvider.ts— packages/cli/src/ui/hooks/shell-completions/gitProvider.ts → packages/cli/src/ui/hooks/useShellCompletion.ts → packages/cli/src/ui/hooks/shell-completions/index.ts → packages/cli/src/ui/hooks/shell-completions/gitProvider.ts (one verified cycle inside a mutually-dependent group of 4 files)
Import cycle (3 files) packages/core/src/services/sandboxManager.ts— packages/core/src/services/sandboxManager.ts → packages/core/src/sandbox/utils/commandSafety.ts → packages/core/src/utils/shell-utils.ts → packages/core/src/services/sandboxManager.ts (one verified cycle inside a mutually-dependent group of 14 files)
AC2 · Forms & labels· <select> without a programmatic label · ×1
<select> without a programmatic label packages/devtools/client/src/App.tsx:406— This control has no associated label. Add a <label htmlFor> / wrapping <label> / aria-label / aria-labelledby so assistive tech can name it.
AC2 · Forms & labels· <input> without a programmatic label · ×1
<input> without a programmatic label packages/devtools/client/src/App.tsx:1047— This control has only a placeholder — a placeholder is not a label (it vanishes on input and many AT ignore it). Add a <label htmlFor>, a wrapping <label>, or aria-label.
AC4 · Keyboard semantics· Click handler on a non-interactive <span> · ×1
Click handler on a non-interactive <span> packages/devtools/client/src/App.tsx:1809— A click handler on a plain element with no role and no tabindex: even where another element's key handler can reach it, assistive tech can neither focus it nor announce what it is. Use a <button>, or add role + tabIndex={0}.
D10 · Test Quality· No assertions (empty test) · ×1
No assertions (empty test): should set window title when hideWindowTitle is false packages/cli/src/gemini.test.tsx:380— Test method has an empty body — it asserts nothing and exercises no code.
Unlisted import 'execa' packages/cli/src/config/config.ts:11— Imported but not declared in any reachable package.json — installs work only by hoisting accident.
Unlisted import 'tinycolor2' packages/cli/src/ui/themes/theme.ts:18— Imported but not declared in any reachable package.json — installs work only by hoisting accident.
Unlisted import 'ws' packages/core/src/voice/geminiLiveTranscriptionProvider.ts:7— Imported but not declared in any reachable package.json — installs work only by hoisting accident.
FunctionTooLong: AppContainer.AppContainer packages/cli/src/ui/AppContainer.tsx:223— FunctionTooLong — AppContainer runs 1975 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 1875 over it, 19.75× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: useGeminiStream.useGeminiStream packages/cli/src/ui/hooks/useGeminiStream.ts:224— FunctionTooLong — useGeminiStream runs 1387 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 1287 over it, 13.87× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: vim-buffer-actions.handleVimAction packages/cli/src/ui/components/shared/vim-buffer-actions.ts:164— FunctionTooLong — handleVimAction runs 1187 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 1087 over it, 11.87× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: vim.useVim packages/cli/src/ui/hooks/vim.ts:187— FunctionTooLong — useVim runs 846 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 746 over it, 8.46× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: text-buffer.useTextBuffer packages/cli/src/ui/components/shared/text-buffer.ts:2832— FunctionTooLong — useTextBuffer runs 747 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 647 over it, 7.47× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: sandbox.start_sandbox packages/cli/src/utils/sandbox.ts:55— FunctionTooLong — start_sandbox runs 587 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 487 over it, 5.87× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: slashCommandProcessor.useSlashCommandProcessor packages/cli/src/ui/hooks/slashCommandProcessor.ts:97— FunctionTooLong — useSlashCommandProcessor runs 474 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 374 over it, 4.74× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: VirtualizedList.VirtualizedList packages/cli/src/ui/components/shared/VirtualizedList.tsx:129— FunctionTooLong — VirtualizedList runs 453 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 353 over it, 4.53× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: nonInteractiveCliAgentSession.runNonInteractive packages/cli/src/nonInteractiveCliAgentSession.ts:75— FunctionTooLong — runNonInteractive runs 435 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 335 over it, 4.35× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: App.App packages/devtools/client/src/App.tsx:28— FunctionTooLong — App runs 434 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 334 over it, 4.34× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: useExecutionLifecycle.useExecutionLifecycle packages/cli/src/ui/hooks/useExecutionLifecycle.ts:75— FunctionTooLong — useExecutionLifecycle runs 426 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 326 over it, 4.26× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: nonInteractiveCli.runNonInteractive packages/cli/src/nonInteractiveCli.ts:72— FunctionTooLong — runNonInteractive runs 380 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 280 over it, 3.80× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: BaseSettingsDialog.BaseSettingsDialog packages/cli/src/ui/components/shared/BaseSettingsDialog.tsx:128— FunctionTooLong — BaseSettingsDialog runs 363 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 263 over it, 3.63× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: gemini.main packages/cli/src/gemini.tsx:466— FunctionTooLong — main runs 309 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 209 over it, 3.09× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: config.parseArguments packages/cli/src/config/config.ts:161— FunctionTooLong — parseArguments runs 299 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 199 over it, 2.99× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: useCommandCompletion.useCommandCompletion packages/cli/src/ui/hooks/useCommandCompletion.tsx:77— FunctionTooLong — useCommandCompletion runs 295 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 195 over it, 2.95× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: App.NetworkView packages/devtools/client/src/App.tsx:831— FunctionTooLong — NetworkView runs 286 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 186 over it, 2.86× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: useVoiceMode.useVoiceMode packages/cli/src/ui/hooks/useVoiceMode.ts:33— FunctionTooLong — useVoiceMode runs 281 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 181 over it, 2.81× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: patch-create-comment.main scripts/releasing/patch-create-comment.js:17— FunctionTooLong — main runs 251 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 151 over it, 2.51× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: toml-loader.loadPoliciesFromToml packages/core/src/policy/toml-loader.ts:323— FunctionTooLong — loadPoliciesFromToml runs 248 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 148 over it, 2.48× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: ModelDialog.ModelDialog packages/cli/src/ui/components/ModelDialog.tsx:41— FunctionTooLong — ModelDialog runs 247 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 147 over it, 2.47× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: ThemeDialog.ThemeDialog packages/cli/src/ui/components/ThemeDialog.tsx:90— FunctionTooLong — ThemeDialog runs 235 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 135 over it, 2.35× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: SettingsDialog.SettingsDialog packages/cli/src/ui/components/SettingsDialog.tsx:100— FunctionTooLong — SettingsDialog runs 225 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 125 over it, 2.25× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: useQuotaAndFallback.useQuotaAndFallback packages/cli/src/ui/hooks/useQuotaAndFallback.ts:51— FunctionTooLong — useQuotaAndFallback runs 225 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 125 over it, 2.25× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: memoryService.startMemoryService packages/core/src/services/memoryService.ts:1133— FunctionTooLong — startMemoryService runs 221 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 121 over it, 2.21× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
TodoComment integration-tests/stdin-context.test.ts:39— // TODO: This test currently fails in sandbox mode (Docker/Podman) because — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment integration-tests/skill-creator-scripts.test.ts:69— // More aggressive global replace for all TODO patterns — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment integration-tests/run_shell_command.test.ts:329— // TODO(#11062): Un-skip this once we can make it reliable by using hard coded
TodoComment integration-tests/run_shell_command.test.ts:447— // TODO(#11966): Deflake this test and re-enable once the underlying race is resolved.
TodoComment integration-tests/extensions-reload.test.ts:26— // TODO(#14527): Re-enable this once fixed
TodoComment integration-tests/context-compress-interactive.test.ts:63— // TODO: Context compression is broken and doesn't include the system — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/a2a-server/src/config/settings.ts:25— // TODO: Ensure full compatibility with V2 nested settings structure (settings.schema.json). — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/gemini.tsx:473— // TODO: Cache settings in sandbox mode as well. — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/gemini.tsx:692— // TODO(jacobr): refactor loadCliConfig so there is a minimal version — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/config/trustedFolders.test.ts:508— // TODO: issue 19387 - Enable symlink tests on Windows — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/config/extension-manager.ts:450— // TODO: Gracefully handle this call failing, we should back up the old — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/config/config.ts:620— // TODO(b/343434939): This is a bit of a hack. The contextFileName should ideally be passed — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/config/config.ts:942— // TODO(joshualitt): Clean this up alongside removal of the legacy config. — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/config/config.ts:1110— // TODO: loading of hooks based on workspace trust — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/config/config.integration.test.ts:32— // TODO(richieforeman): Consider moving this to test setup globally. — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/core/src/telemetry/clearcut-logger/clearcut-logger.test.ts:162— // TODO(richieforeman): Consider moving this to test setup globally. — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/ui/AppContainer.tsx:769— // TODO: Consider handling other auth types that should also skip the blocking screen — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/ui/commands/types.ts:41— // TODO(abhipatel12): Ensure that config is never null. — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/ui/commands/types.ts:229— // TODO: Remove args. CommandContext now contains the complete invocation. — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/ui/components/ShellInputPrompt.tsx:60— // TODO: Check pty service actually scrolls (request)[https://github.com/google-gemini/gemini-cli/pull/17438/changes/c9fdaf8967da0036bfef43592fcab5a69537df35#r2776479023].
TodoComment packages/cli/src/ui/components/MainContent.tsx:248— // TODO(jacobr): we should return true for all messages that are not — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/ui/components/MainContent.tsx:276— // TODO(jacobr): consider adding stableScrollback={!config.getUseAlternateBuffer()} — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/ui/components/InputPrompt.tsx:736— // TODO(jacobr): this special case is likely not needed anymore. — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/ui/components/messages/ToolGroupMessage.tsx:79— // TODO(24053): Usage of type guards makes this class too aware of internals — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment packages/cli/src/ui/components/messages/ToolConfirmationMessage.tsx:267— // TODO(#23009): Remove this hack once we migrate to the new renderer.
No assertions: should initialize WhisperTranscriptionProvider and handle process integration-tests/voice-mode.test.ts:50— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: should run a command in the background, list it, and read its output integration-tests/shell-background.test.ts:24— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: $name integration-tests/policy-headless.test.ts:203— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: mcp tool list should include tool with cyclic tool schema integration-tests/mcp_server_cyclic_schema.test.ts:177— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: should be able to list a directory integration-tests/list_directory.test.ts:27— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: should not emit any deprecation warnings when $description integration-tests/deprecation-warnings.test.ts:23— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: should clean up browser processes after completion integration-tests/browser-agent.test.ts:180— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: should handle tool confirmation for write_file without crashing integration-tests/browser-agent.test.ts:288— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: idle-session-startup: memory usage within baseline memory-tests/memory-usage.test.ts:58— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: simple-prompt-response: memory usage within baseline memory-tests/memory-usage.test.ts:88— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: multi-turn-conversation: memory remains stable over turns memory-tests/memory-usage.test.ts:118— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: multi-function-call-repo-search: memory after tool use memory-tests/memory-usage.test.ts:162— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: large-chat: memory usage within baseline memory-tests/memory-usage.test.ts:238— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: resume-large-chat: memory usage within baseline memory-tests/memory-usage.test.ts:268— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: resume-large-chat-with-messages: memory usage within baseline memory-tests/memory-usage.test.ts:315— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: should use $desc packages/cli/src/acp/acpFileSystemService.test.ts:151— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: should not prompt for settings if promptForSettings is false packages/cli/src/config/extension.test.ts:1685— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: should extract zip using extract-zip packages/cli/src/config/extensions/github.test.ts:642— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: should not throw if deleting a non-existent sensitive setting with empty value packages/cli/src/config/extensions/extensionSettings.test.ts:849— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: should steer the model using a hint during a tool turn packages/cli/src/integration-tests/modelSteering.test.tsx:22— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: should render the app and handle a simple message packages/cli/src/test-utils/AppRig.test.tsx:63— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: handles debug mode state packages/cli/src/ui/AppContainer.test.tsx:918— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: handles config methods that might throw packages/cli/src/ui/AppContainer.test.tsx:1002— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: establishes correct provider nesting order packages/cli/src/ui/AppContainer.test.tsx:1027— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: handles resumed session data correctly packages/cli/src/ui/AppContainer.test.tsx:1037— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
FileTooLong: config/settingsSchema.ts packages/cli/src/config/settingsSchema.ts— FileTooLong — 3049 significant lines (blank, comment-only and punctuation-only lines excluded), about 82% of them inside a single declaration: SETTINGS_SCHEMA (159-3028). The bar is 500 significant lines; this is 2549 over it, 6.10× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: shared/text-buffer.ts packages/cli/src/ui/components/shared/text-buffer.ts— FileTooLong — 2701 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 2201 over it, 5.40× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: config/config.ts packages/core/src/config/config.ts— FileTooLong — 2674 significant lines (blank, comment-only and punctuation-only lines excluded), about 78% of them inside a single declaration: Config (753-4203). The bar is 500 significant lines; this is 2174 over it, 5.35× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: ui/AppContainer.tsx packages/cli/src/ui/AppContainer.tsx— FileTooLong — 2176 significant lines (blank, comment-only and punctuation-only lines excluded), about 91% of them inside a single declaration: AppContainer (223-2869). The bar is 500 significant lines; this is 1676 over it, 4.35× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: telemetry/types.ts packages/core/src/telemetry/types.ts— FileTooLong — 1845 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 1345 over it, 3.69× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: hooks/useGeminiStream.ts packages/cli/src/ui/hooks/useGeminiStream.ts— FileTooLong — 1557 significant lines (blank, comment-only and punctuation-only lines excluded), about 89% of them inside a single declaration: useGeminiStream (224-2299). The bar is 500 significant lines; this is 1057 over it, 3.11× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: src/App.tsx packages/devtools/client/src/App.tsx— FileTooLong — 1535 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 1035 over it, 3.07× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: tools/mcp-client.ts packages/core/src/tools/mcp-client.ts— FileTooLong — 1443 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 943 over it, 2.89× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: components/InputPrompt.tsx packages/cli/src/ui/components/InputPrompt.tsx— FileTooLong — 1396 significant lines (blank, comment-only and punctuation-only lines excluded), about 89% of them inside a single declaration: InputPrompt (207-1933). The bar is 500 significant lines; this is 896 over it, 2.79× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: services/shellExecutionService.ts packages/core/src/services/shellExecutionService.ts— FileTooLong — 1288 significant lines (blank, comment-only and punctuation-only lines excluded), about 82% of them inside a single declaration: ShellExecutionService (374-2021). The bar is 500 significant lines; this is 788 over it, 2.58× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: telemetry/metrics.ts packages/core/src/telemetry/metrics.ts— FileTooLong — 1260 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 760 over it, 2.52× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: shared/vim-buffer-actions.ts packages/cli/src/ui/components/shared/vim-buffer-actions.ts— FileTooLong — 1255 significant lines (blank, comment-only and punctuation-only lines excluded), about 95% of them inside a single declaration: handleVimAction (164-1849). The bar is 500 significant lines; this is 755 over it, 2.51× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: clearcut-logger/clearcut-logger.ts packages/core/src/telemetry/clearcut-logger/clearcut-logger.ts— FileTooLong — 1233 significant lines (blank, comment-only and punctuation-only lines excluded), about 83% of them inside a single declaration: ClearcutLogger (294-2205). The bar is 500 significant lines; this is 733 over it, 2.47× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: core/geminiChat.ts packages/core/src/core/geminiChat.ts— FileTooLong — 1139 significant lines (blank, comment-only and punctuation-only lines excluded), about 73% of them inside a single declaration: GeminiChat (372-1745). The bar is 500 significant lines; this is 639 over it, 2.28× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: acp/acpSession.ts packages/cli/src/acp/acpSession.ts— FileTooLong — 1048 significant lines (blank, comment-only and punctuation-only lines excluded), about 95% of them inside a single declaration: Session (65-1551). The bar is 500 significant lines; this is 548 over it, 2.10× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: components/InboxDialog.tsx packages/cli/src/ui/components/InboxDialog.tsx— FileTooLong — 1008 significant lines (blank, comment-only and punctuation-only lines excluded), about 79% of them inside a single declaration: InboxDialog (331-1446). The bar is 500 significant lines; this is 508 over it, 2.02× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: tools/edit.ts packages/core/src/tools/edit.ts— FileTooLong — 992 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 492 over it, 1.98× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: config/extension-manager.ts packages/cli/src/config/extension-manager.ts— FileTooLong — 982 significant lines (blank, comment-only and punctuation-only lines excluded), about 77% of them inside a single declaration: ExtensionManager (105-1243). The bar is 500 significant lines; this is 482 over it, 1.96× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: agents/local-executor.ts packages/core/src/agents/local-executor.ts— FileTooLong — 975 significant lines (blank, comment-only and punctuation-only lines excluded), about 90% of them inside a single declaration: LocalAgentExecutor (120-1525). The bar is 500 significant lines; this is 475 over it, 1.95× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: hooks/vim.ts packages/cli/src/ui/hooks/vim.ts— FileTooLong — 974 significant lines (blank, comment-only and punctuation-only lines excluded), about 87% of them inside a single declaration: useVim (187-1536). The bar is 500 significant lines; this is 474 over it, 1.95× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: services/memoryService.ts packages/core/src/services/memoryService.ts— FileTooLong — 928 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 428 over it, 1.86× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: components/AskUserDialog.tsx packages/cli/src/ui/components/AskUserDialog.tsx— FileTooLong — 919 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 419 over it, 1.84× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: agent/task.ts packages/a2a-server/src/agent/task.ts— FileTooLong — 906 significant lines (blank, comment-only and punctuation-only lines excluded), about 93% of them inside a single declaration: Task (74-1305). The bar is 500 significant lines; this is 406 over it, 1.81× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: utils/sandbox.ts packages/cli/src/utils/sandbox.ts— FileTooLong — 885 significant lines (blank, comment-only and punctuation-only lines excluded), about 66% of them inside a single declaration: start_sandbox (55-1031). The bar is 500 significant lines; this is 385 over it, 1.77× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: config/config.ts packages/cli/src/config/config.ts— FileTooLong — 880 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 380 over it, 1.76× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
MethodTooLong: ShellToolInvocation.execute packages/core/src/tools/shell.ts:523— MethodTooLong — execute runs 458 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 358 over it, 4.58× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: ShellExecutionService.executeWithPty packages/core/src/services/shellExecutionService.ts:1103— MethodTooLong — executeWithPty runs 421 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 321 over it, 4.21× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: Session.#resolvePrompt packages/cli/src/acp/acpSession.ts:969— MethodTooLong — #resolvePrompt runs 392 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 292 over it, 3.92× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: Config.constructor packages/core/src/config/config.ts:993— MethodTooLong — constructor runs 350 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 250 over it, 3.50× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: CoderAgentExecutor.execute packages/a2a-server/src/agent/executor.ts:439— MethodTooLong — execute runs 347 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 247 over it, 3.47× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: ExtensionManager.installOrUpdateExtension packages/cli/src/config/extension-manager.ts:180— MethodTooLong — installOrUpdateExtension runs 261 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 161 over it, 2.61× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: BrowserAgentInvocation.execute packages/core/src/agents/browser/browserAgentInvocation.ts:111— MethodTooLong — execute runs 242 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 142 over it, 2.42× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: ShellExecutionService.childProcessFallback packages/core/src/services/shellExecutionService.ts:652— MethodTooLong — childProcessFallback runs 236 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 136 over it, 2.36× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: GeminiChat.sendMessageStream packages/core/src/core/geminiChat.ts:480— MethodTooLong — sendMessageStream runs 225 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 125 over it, 2.25× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: ReadManyFilesToolInvocation.execute packages/core/src/tools/read-many-files.ts:179— MethodTooLong — execute runs 222 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 122 over it, 2.22× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: Session.runTool packages/cli/src/acp/acpSession.ts:659— MethodTooLong — runTool runs 220 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 120 over it, 2.20× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: LocalAgentExecutor.runInternal packages/core/src/agents/local-executor.ts:571— MethodTooLong — runInternal runs 218 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 118 over it, 2.18× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: PolicyEngine.check packages/core/src/policy/policy-engine.ts:600— MethodTooLong — check runs 214 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 114 over it, 2.14× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: LocalSessionInvocation.execute packages/core/src/agents/local-session-invocation.ts:111— MethodTooLong — execute runs 211 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 111 over it, 2.11× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: Session.prompt packages/cli/src/acp/acpSession.ts:311— MethodTooLong — prompt runs 199 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 99 over it, 1.99× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: GeminiChat.processStreamResponse packages/core/src/core/geminiChat.ts:1354— MethodTooLong — processStreamResponse runs 197 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 97 over it, 1.97× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: GeminiClient.processTurn packages/core/src/core/client.ts:614— MethodTooLong — processTurn runs 194 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 94 over it, 1.94× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: ExtensionManager._buildExtension packages/cli/src/config/extension-manager.ts:708— MethodTooLong — _buildExtension runs 192 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 92 over it, 1.92× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: LocalSubagentInvocation.execute packages/core/src/agents/local-invocation.ts:102— MethodTooLong — execute runs 192 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 92 over it, 1.92× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: PromptProvider.getCoreSystemPrompt packages/core/src/prompts/promptProvider.ts:47— MethodTooLong — getCoreSystemPrompt runs 186 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 86 over it, 1.86× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: GeminiChat.makeApiCallAndProcessStream packages/core/src/core/geminiChat.ts:870— MethodTooLong — makeApiCallAndProcessStream runs 183 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 83 over it, 1.83× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: MCPOAuthProvider.authenticate packages/core/src/mcp/oauth-provider.ts:304— MethodTooLong — authenticate runs 174 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 74 over it, 1.74× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: ActivityLogger.patchNodeHttp packages/cli/src/utils/activityLogger.ts:441— MethodTooLong — patchNodeHttp runs 173 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 73 over it, 1.73× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: GrepToolInvocation.performGrepSearch packages/core/src/tools/grep.ts:413— MethodTooLong — performGrepSearch runs 169 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 69 over it, 1.69× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: IDEServer.start packages/vscode-ide-companion/src/ide-server.ts:138— MethodTooLong — start runs 166 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 66 over it, 1.66× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
+ 26 more in this group — see findings.md.
R4 · Test Coverage· No test reaches this file · ×40
No test reaches this file scripts/lint.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/build_binary.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/releasing/patch-trigger.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/run_regression_check.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/releasing/create-patch-pr.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/aggregate_evals.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/sync_project_dry_run.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/seed-test-inbox.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/releasing/patch-comment.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/local_telemetry.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/build_sandbox.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file packages/vscode-ide-companion/scripts/generate-notices.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/cleanup-branches.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file tools/gemini-cli-bot/metrics/index.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/close_duplicate_issues.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/check-build-status.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file tools/gemini-cli-bot/metrics/scripts/domain_expertise.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/download-ripgrep-binaries.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file packages/core/scripts/bundle-browser-mcp.mjs— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/compare_evals.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file tools/gemini-cli-bot/metrics/scripts/time_to_first_response.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/eval_utils.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/deflake.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/sandbox_command.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/get_trustworthy_evals.js— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
ClassTooLong: Config packages/core/src/config/config.ts:753— ClassTooLong — 2090 significant lines (blank, comment-only and punctuation-only lines excluded), 273 methods. The bar is 400 significant lines; this is 1690 over it, 5.23× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: AppContainer packages/cli/src/ui/AppContainer.tsx:1— ClassTooLong — 1975 significant lines (blank, comment-only and punctuation-only lines excluded), 1 methods. The bar is 400 significant lines; this is 1575 over it, 4.94× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: useGeminiStream packages/cli/src/ui/hooks/useGeminiStream.ts:1— ClassTooLong — 1387 significant lines (blank, comment-only and punctuation-only lines excluded), 6 methods. The bar is 400 significant lines; this is 987 over it, 3.47× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: InputPrompt packages/cli/src/ui/components/InputPrompt.tsx:1— ClassTooLong — 1240 significant lines (blank, comment-only and punctuation-only lines excluded), 5 methods. The bar is 400 significant lines; this is 840 over it, 3.10× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: ShellExecutionService packages/core/src/services/shellExecutionService.ts:374— ClassTooLong — 1062 significant lines (blank, comment-only and punctuation-only lines excluded), 23 methods. The bar is 400 significant lines; this is 662 over it, 2.66× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: ClearcutLogger packages/core/src/telemetry/clearcut-logger/clearcut-logger.ts:294— ClassTooLong — 1027 significant lines (blank, comment-only and punctuation-only lines excluded), 71 methods. The bar is 400 significant lines; this is 627 over it, 2.57× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: Session packages/cli/src/acp/acpSession.ts:65— ClassTooLong — 993 significant lines (blank, comment-only and punctuation-only lines excluded), 17 methods. The bar is 400 significant lines; this is 593 over it, 2.48× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: LocalAgentExecutor packages/core/src/agents/local-executor.ts:120— ClassTooLong — 878 significant lines (blank, comment-only and punctuation-only lines excluded), 18 methods. The bar is 400 significant lines; this is 478 over it, 2.20× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: Task packages/a2a-server/src/agent/task.ts:74— ClassTooLong — 841 significant lines (blank, comment-only and punctuation-only lines excluded), 31 methods. The bar is 400 significant lines; this is 441 over it, 2.10× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: GeminiChat packages/core/src/core/geminiChat.ts:372— ClassTooLong — 833 significant lines (blank, comment-only and punctuation-only lines excluded), 23 methods. The bar is 400 significant lines; this is 433 over it, 2.08× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: ToolConfirmationMessage packages/cli/src/ui/components/messages/ToolConfirmationMessage.tsx:1— ClassTooLong — 811 significant lines (blank, comment-only and punctuation-only lines excluded), 1 methods. The bar is 400 significant lines; this is 411 over it, 2.03× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: InboxDialog packages/cli/src/ui/components/InboxDialog.tsx:1— ClassTooLong — 801 significant lines (blank, comment-only and punctuation-only lines excluded), 9 methods. The bar is 400 significant lines; this is 401 over it, 2.00× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: GeminiClient packages/core/src/core/client.ts:93— ClassTooLong — 788 significant lines (blank, comment-only and punctuation-only lines excluded), 34 methods. The bar is 400 significant lines; this is 388 over it, 1.97× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: ExtensionManager packages/cli/src/config/extension-manager.ts:105— ClassTooLong — 754 significant lines (blank, comment-only and punctuation-only lines excluded), 21 methods. The bar is 400 significant lines; this is 354 over it, 1.89× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: ShellToolInvocation packages/core/src/tools/shell.ts:102— ClassTooLong — 733 significant lines (blank, comment-only and punctuation-only lines excluded), 12 methods. The bar is 400 significant lines; this is 333 over it, 1.83× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: TriageDuplicates packages/cli/src/ui/components/triage/TriageDuplicates.tsx:1— ClassTooLong — 720 significant lines (blank, comment-only and punctuation-only lines excluded), 3 methods. The bar is 400 significant lines; this is 320 over it, 1.80× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: CoderAgentExecutor packages/a2a-server/src/agent/executor.ts:101— ClassTooLong — 583 significant lines (blank, comment-only and punctuation-only lines excluded), 10 methods. The bar is 400 significant lines; this is 183 over it, 1.46× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: Scheduler packages/core/src/scheduler/scheduler.ts:99— ClassTooLong — 559 significant lines (blank, comment-only and punctuation-only lines excluded), 19 methods. The bar is 400 significant lines; this is 159 over it, 1.40× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: PolicyEngine packages/core/src/policy/policy-engine.ts:242— ClassTooLong — 509 significant lines (blank, comment-only and punctuation-only lines excluded), 22 methods. The bar is 400 significant lines; this is 109 over it, 1.27× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: TriageIssues packages/cli/src/ui/components/triage/TriageIssues.tsx:1— ClassTooLong — 470 significant lines (blank, comment-only and punctuation-only lines excluded), 2 methods. The bar is 400 significant lines; this is 70 over it, 1.18× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: BrowserManager packages/core/src/agents/browser/browserManager.ts:113— ClassTooLong — 464 significant lines (blank, comment-only and punctuation-only lines excluded), 22 methods. The bar is 400 significant lines; this is 64 over it, 1.16× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: WebFetchToolInvocation packages/core/src/tools/web-fetch.ts:222— ClassTooLong — 460 significant lines (blank, comment-only and punctuation-only lines excluded), 12 methods. The bar is 400 significant lines; this is 60 over it, 1.15× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: VirtualizedList packages/cli/src/ui/components/shared/VirtualizedList.tsx:1— ClassTooLong — 453 significant lines (blank, comment-only and punctuation-only lines excluded), 3 methods. The bar is 400 significant lines; this is 53 over it, 1.13× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: EditToolInvocation packages/core/src/tools/edit.ts:459— ClassTooLong — 446 significant lines (blank, comment-only and punctuation-only lines excluded), 9 methods. The bar is 400 significant lines; this is 46 over it, 1.12× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: App packages/devtools/client/src/App.tsx:1— ClassTooLong — 434 significant lines (blank, comment-only and punctuation-only lines excluded), 16 methods. The bar is 400 significant lines; this is 34 over it, 1.09× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
Hotspot: packages/cli/src/ui/hooks/useGeminiStream.ts packages/cli/src/ui/hooks/useGeminiStream.ts:224— packages/cli/src/ui/hooks/useGeminiStream.ts changed 3 times in last 90 days, max cyclomatic complexity 261 in useGeminiStream.useGeminiStream at line 224. 3 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/cli/src/ui/hooks/useGeminiStream.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/core/geminiChat.ts packages/core/src/core/geminiChat.ts:1354— packages/core/src/core/geminiChat.ts changed 9 times in last 90 days, max cyclomatic complexity 68 in GeminiChat.processStreamResponse at line 1354. 9 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/core/geminiChat.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/cli/src/utils/sandbox.ts packages/cli/src/utils/sandbox.ts:55— packages/cli/src/utils/sandbox.ts changed 4 times in last 90 days, max cyclomatic complexity 146 in sandbox.start_sandbox at line 55. 4 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/cli/src/utils/sandbox.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/services/shellExecutionService.ts packages/core/src/services/shellExecutionService.ts:1103— packages/core/src/services/shellExecutionService.ts changed 6 times in last 90 days, max cyclomatic complexity 79 in ShellExecutionService.executeWithPty at line 1103. 5 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/services/shellExecutionService.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/tools/shell.ts packages/core/src/tools/shell.ts:523— packages/core/src/tools/shell.ts changed 3 times in last 90 days, max cyclomatic complexity 130 in ShellToolInvocation.execute at line 523. 3 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/tools/shell.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/cli/src/ui/components/messages/ToolConfirmationMessage.tsx packages/cli/src/ui/components/messages/ToolConfirmationMessage.tsx:65— packages/cli/src/ui/components/messages/ToolConfirmationMessage.tsx changed 2 times in last 90 days, max cyclomatic complexity 156 in ToolConfirmationMessage.ToolConfirmationMessage at line 65. 2 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/cli/src/ui/components/messages/ToolConfirmationMessage.tsx`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/cli/src/acp/acpSession.ts packages/cli/src/acp/acpSession.ts:969— packages/cli/src/acp/acpSession.ts changed 3 times in last 90 days, max cyclomatic complexity 91 in Session.#resolvePrompt at line 969. 3 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/cli/src/acp/acpSession.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/a2a-server/src/agent/executor.ts packages/a2a-server/src/agent/executor.ts:439— packages/a2a-server/src/agent/executor.ts changed 4 times in last 90 days, max cyclomatic complexity 65 in CoderAgentExecutor.execute at line 439. 4 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/a2a-server/src/agent/executor.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/policy/policy-engine.ts packages/core/src/policy/policy-engine.ts:600— packages/core/src/policy/policy-engine.ts changed 3 times in last 90 days, max cyclomatic complexity 61 in PolicyEngine.check at line 600. 3 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/policy/policy-engine.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/utils/googleQuotaErrors.ts packages/core/src/utils/googleQuotaErrors.ts:223— packages/core/src/utils/googleQuotaErrors.ts changed 3 times in last 90 days, max cyclomatic complexity 57 in googleQuotaErrors.classifyGoogleError at line 223. 2 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/utils/googleQuotaErrors.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/mcp/oauth-provider.ts packages/core/src/mcp/oauth-provider.ts:304— packages/core/src/mcp/oauth-provider.ts changed 4 times in last 90 days, max cyclomatic complexity 39 in MCPOAuthProvider.authenticate at line 304. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/mcp/oauth-provider.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/config/config.ts packages/core/src/config/config.ts:993— packages/core/src/config/config.ts changed 7 times in last 90 days, max cyclomatic complexity 20 in Config.constructor at line 993. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/config/config.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/cli/src/ui/hooks/useQuotaAndFallback.ts packages/cli/src/ui/hooks/useQuotaAndFallback.ts:51— packages/cli/src/ui/hooks/useQuotaAndFallback.ts changed 3 times in last 90 days, max cyclomatic complexity 42 in useQuotaAndFallback.useQuotaAndFallback at line 51. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/cli/src/ui/hooks/useQuotaAndFallback.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/a2a-server/src/agent/task.ts packages/a2a-server/src/agent/task.ts:821— packages/a2a-server/src/agent/task.ts changed 5 times in last 90 days, max cyclomatic complexity 25 in Task.acceptAgentMessage at line 821. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/a2a-server/src/agent/task.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/utils/retry.ts packages/core/src/utils/retry.ts:258— packages/core/src/utils/retry.ts changed 2 times in last 90 days, max cyclomatic complexity 55 in retry.retryWithBackoff at line 258. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/utils/retry.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/tools/write-file.ts packages/core/src/tools/write-file.ts:370— packages/core/src/tools/write-file.ts changed 4 times in last 90 days, max cyclomatic complexity 27 in WriteFileToolInvocation.execute at line 370. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/tools/write-file.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/core/contentGenerator.ts packages/core/src/core/contentGenerator.ts:210— packages/core/src/core/contentGenerator.ts changed 2 times in last 90 days, max cyclomatic complexity 50 in contentGenerator.createContentGenerator at line 210. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/core/contentGenerator.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/tools/grep.ts packages/core/src/tools/grep.ts:413— packages/core/src/tools/grep.ts changed 2 times in last 90 days, max cyclomatic complexity 47 in GrepToolInvocation.performGrepSearch at line 413. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/tools/grep.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/utils/paths.ts packages/core/src/utils/paths.ts:54— packages/core/src/utils/paths.ts changed 3 times in last 90 days, max cyclomatic complexity 31 in paths.shortenPath at line 54. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/utils/paths.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/tools/edit.ts packages/core/src/tools/edit.ts:904— packages/core/src/tools/edit.ts changed 4 times in last 90 days, max cyclomatic complexity 23 in EditToolInvocation.execute at line 904. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/tools/edit.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/cli/src/utils/sandboxUtils.ts packages/cli/src/utils/sandboxUtils.ts:151— packages/cli/src/utils/sandboxUtils.ts changed 3 times in last 90 days, max cyclomatic complexity 30 in sandboxUtils.isSensitiveHostPath at line 151. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/cli/src/utils/sandboxUtils.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/utils/oauth-flow.ts packages/core/src/utils/oauth-flow.ts:485— packages/core/src/utils/oauth-flow.ts changed 3 times in last 90 days, max cyclomatic complexity 25 in oauth-flow.parseTokenEndpointResponse at line 485. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/utils/oauth-flow.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/a2a-server/src/config/config.ts packages/a2a-server/src/config/config.ts:469— packages/a2a-server/src/config/config.ts changed 3 times in last 90 days, max cyclomatic complexity 23 in config.setTargetDir at line 469. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/a2a-server/src/config/config.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: packages/core/src/agent/legacy-agent-session.ts packages/core/src/agent/legacy-agent-session.ts:174— packages/core/src/agent/legacy-agent-session.ts changed 2 times in last 90 days, max cyclomatic complexity 34 in LegacyAgentProtocol._runLoop at line 174. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- packages/core/src/agent/legacy-agent-session.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: REDACTED REDACTED:129— REDACTED changed 2 times in last 90 days, max cyclomatic complexity 32 in oauth2.initOauthClient at line 129. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-23..2026-09-21, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-06-23 20:36:40 +00:00' --until='2026-09-21 20:36:40 +00:00' --full-history --no-merges -- REDACTED`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Boundary violation [package:relative-cross-package] evals/app-test-helper.ts:7— evals/app-test-helper.ts:7 reaches into another package with a relative path (../packages/cli/src/test-utils/AppRig.js) — import the package by name instead.
Boundary violation [package:test-suite-dependency] evals/app-test-helper.ts:7— evals/app-test-helper.ts:7 imports packages/cli/src/test-utils/AppRig.tsx, a module inside the test suite — test helpers carry no compatibility contract and are maintained for the suite, not as an API, so production code that depends on one is coupled to a module nobody keeps stable. Move the shared helper into a source directory both layers may depend on.
Boundary violation [package:relative-cross-package] evals/auto_memory_modes.eval.ts:12— evals/auto_memory_modes.eval.ts:12 reaches into another package with a relative path (../packages/core/src/services/chatRecordingService.js) — import the package by name instead.
Boundary violation [package:relative-cross-package] evals/auto_memory_modes.eval.ts:332— evals/auto_memory_modes.eval.ts:332 reaches into another package with a relative path (../packages/core/src/services/memoryService.js) — import the package by name instead.
Boundary violation [package:relative-cross-package] evals/auto_memory_modes.eval.ts:389— evals/auto_memory_modes.eval.ts:389 reaches into another package with a relative path (../packages/core/src/services/memoryService.js) — import the package by name instead.
Boundary violation [package:relative-cross-package] evals/component-test-helper.ts:31— evals/component-test-helper.ts:31 reaches into another package with a relative path (../packages/cli/src/test-utils/settings.js) — import the package by name instead.
Boundary violation [package:test-suite-dependency] evals/component-test-helper.ts:31— evals/component-test-helper.ts:31 imports packages/cli/src/test-utils/settings.ts, a module inside the test suite — test helpers carry no compatibility contract and are maintained for the suite, not as an API, so production code that depends on one is coupled to a module nobody keeps stable. Move the shared helper into a source directory both layers may depend on.
Boundary violation [package:test-cross-package-internals] integration-tests/globalSetup.ts:15— integration-tests/globalSetup.ts:15 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/tools/ripGrep.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead.
Boundary violation [package:test-cross-package-internals] integration-tests/google_web_search.test.ts:7— integration-tests/google_web_search.test.ts:7 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/tools/tool-names.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead.
Boundary violation [package:test-cross-package-internals] integration-tests/ripgrep-real.test.ts:11— integration-tests/ripgrep-real.test.ts:11 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/tools/ripGrep.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead.
Boundary violation [package:test-cross-package-internals] integration-tests/ripgrep-real.test.ts:15— integration-tests/ripgrep-real.test.ts:15 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/config/config.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead.
Boundary violation [package:test-cross-package-internals] integration-tests/ripgrep-real.test.ts:16— integration-tests/ripgrep-real.test.ts:16 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/utils/workspaceContext.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead.
Boundary violation [package:test-cross-package-internals] integration-tests/run_shell_command.test.ts:14— integration-tests/run_shell_command.test.ts:14 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/utils/shell-utils.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead.
Boundary violation [package:test-cross-package-internals] memory-tests/globalSetup.ts:10— memory-tests/globalSetup.ts:10 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/tools/ripGrep.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead.
Boundary violation [package:undeclared-workspace-dep] packages/cli/src/utils/devtoolsService.ts:63— packages/cli/src/utils/devtoolsService.ts:63 imports @google/gemini-cli-devtools, a package this repository publishes, but this package's own package.json does not list it in dependencies (or peer/optional dependencies) — it resolves only through the workspace link, so an installed copy of this package is missing it. Add it to this package's dependencies.
Boundary violation [package:third-party-deep-import] packages/core/src/utils/schemaValidator.ts:10— packages/core/src/utils/schemaValidator.ts:10 imports ajv/dist/2020.js, reaching past a declared dependency's public entry into its build output — that path is the package's toolchain layout, not its API, and a minor version bump can relocate it with no semver signal. Import from the package's documented entry point instead.
Boundary violation [package:undeclared-workspace-dep] packages/vscode-ide-companion/src/diff-manager.ts:7— packages/vscode-ide-companion/src/diff-manager.ts:7 imports @google/gemini-cli-core/src/ide/types.js, a package this repository publishes, but this package's own package.json does not list it in dependencies (or peer/optional dependencies) — it resolves only through the workspace link, so an installed copy of this package is missing it. Add it to this package's dependencies.
Boundary violation [package:undeclared-workspace-dep] packages/vscode-ide-companion/src/extension.ts:12— packages/vscode-ide-companion/src/extension.ts:12 imports @google/gemini-cli-core/src/ide/detect-ide.js, a package this repository publishes, but this package's own package.json does not list it in dependencies (or peer/optional dependencies) — it resolves only through the workspace link, so an installed copy of this package is missing it. Add it to this package's dependencies.
Boundary violation [package:undeclared-workspace-dep] packages/vscode-ide-companion/src/ide-server.ts:8— packages/vscode-ide-companion/src/ide-server.ts:8 imports @google/gemini-cli-core/src/ide/types.js, a package this repository publishes, but this package's own package.json does not list it in dependencies (or peer/optional dependencies) — it resolves only through the workspace link, so an installed copy of this package is missing it. Add it to this package's dependencies.
Boundary violation [package:undeclared-workspace-dep] packages/vscode-ide-companion/src/ide-server.ts:26— packages/vscode-ide-companion/src/ide-server.ts:26 imports @google/gemini-cli-core, a package this repository publishes, but this package's own package.json does not list it in dependencies (or peer/optional dependencies) — it resolves only through the workspace link, so an installed copy of this package is missing it. Add it to this package's dependencies.
Boundary violation [package:test-cross-package-internals] perf-tests/globalSetup.ts:10— perf-tests/globalSetup.ts:10 reaches past another workspace package's public entry into its internals with a relative path (../packages/core/src/tools/ripGrep.js) — the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead.
Boundary violation [package:relative-cross-package] scripts/build_sandbox.js:32— scripts/build_sandbox.js:32 reaches into another package with a relative path (../packages/cli/package.json) — import the package by name instead.
Boundary violation [package:relative-cross-package] scripts/generate-keybindings-doc.ts:12— scripts/generate-keybindings-doc.ts:12 reaches into another package with a relative path (../packages/cli/src/ui/key/keyBindings.js) — import the package by name instead.
Boundary violation [package:relative-cross-package] scripts/generate-keybindings-doc.ts:30— scripts/generate-keybindings-doc.ts:30 reaches into another package with a relative path (../packages/cli/src/ui/key/keybindingUtils.js) — import the package by name instead.
Boundary violation [package:relative-cross-package] scripts/generate-settings-schema.ts:11— scripts/generate-settings-schema.ts:11 reaches into another package with a relative path (../packages/cli/src/config/settingsSchema.js) — import the package by name instead.
Change coupling: default-legacy.ts ↔ gemini-3.ts packages/core/src/tools/definitions/model-family-sets/default-legacy.ts— `packages/core/src/tools/definitions/model-family-sets/default-legacy.ts` and `packages/core/src/tools/definitions/model-family-sets/gemini-3.ts` change together 100% of the time (15 of the 15 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module — a sibling reference still needs an import — so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 15 shared commits counted here, the most recent 3 are `120dfc72` fix(core): update read_file schema for v1 compatibility (#22183) (#26…; `f16f1cce` feat(core): add tools to list and read MCP resources (#25395); `e7f8d9cf` Revert "feat: Introduce an AI-driven interactive shell mode with new" — run `git show` on any of them.
Change coupling: AboutBox.tsx ↔ types.ts packages/cli/src/ui/components/AboutBox.tsx— `packages/cli/src/ui/components/AboutBox.tsx` and `packages/cli/src/ui/types.ts` change together 80% of the time (8 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 8 shared commits counted here, the most recent 3 are `bee1267e` feat(cli): add user identity info to stats command (#17612); `5c649d8d` feat(ui): display user tier in about command (#17400); `43d6dc36` Add User email detail to about box (#13459) — run `git show` on any of them.
Change coupling: event-metadata-key.ts ↔ types.ts packages/core/src/telemetry/clearcut-logger/event-metadata-key.ts— `packages/core/src/telemetry/clearcut-logger/event-metadata-key.ts` and `packages/core/src/telemetry/types.ts` change together 72% of the time (49 of the 68 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 49 shared commits counted here, the most recent 3 are `397ff84b` Refine onboarding metrics to log the duration explicitly and use the …; `244a6081` feat(core): set up onboarding telemetry (#23118); `b459e1a1` feat(telemetry): track if session is running in a Git worktree (#23265) — run `git show` on any of them.
Change coupling: useGeminiStream.ts ↔ useLoadingIndicator.ts packages/cli/src/ui/hooks/useGeminiStream.ts— `packages/cli/src/ui/hooks/useGeminiStream.ts` and `packages/cli/src/ui/hooks/useLoadingIndicator.ts` change together 67% of the time (8 of the 12 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module — a sibling reference still needs an import — so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 8 shared commits counted here, the most recent 3 are `77027dff` fix(cli): clear stale retry/loading state after cancellation (#21096)…; `8303edbb` Code review fixes as a pr (#20612); `7f8ce865` Add low/full CLI error verbosity mode for cleaner UI (#20399) — run `git show` on any of them.
Change coupling: snippets.ts ↔ dynamic-declaration-helpers.ts packages/core/src/prompts/snippets.ts— `packages/core/src/prompts/snippets.ts` and `packages/core/src/tools/definitions/dynamic-declaration-helpers.ts` change together 64% of the time (7 of the 11 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 7 shared commits counted here, the most recent 3 are `e7f8d9cf` Revert "feat: Introduce an AI-driven interactive shell mode with new"; `651ad63e` feat: Introduce an AI-driven interactive shell mode with new `read-sh…; `ca43f8c2` feat(core): prioritize discussion before formal plan approval (#24423) — run `git show` on any of them.
Change coupling: constants.ts ↔ types.ts packages/core/src/telemetry/constants.ts— `packages/core/src/telemetry/constants.ts` and `packages/core/src/telemetry/types.ts` change together 63% of the time (19 of the 30 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module — a sibling reference still needs an import — so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 19 shared commits counted here, the most recent 3 are `83075b28` refactor: make log/event structure clear (#10467); `70610c74` feat(telemetry): Add telemetry for web_fetch fallback attempts (#10749); `c0552ceb` feat(core): add telemetry for subagent execution (#10456) — run `git show` on any of them.
Change coupling: shell.ts ↔ tool-utils.ts packages/core/src/tools/shell.ts— `packages/core/src/tools/shell.ts` and `packages/core/src/utils/tool-utils.ts` change together 60% of the time (6 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 6 shared commits counted here, the most recent 3 are `f3bbe6e7` fix(core): send shell output to model on cancel (#20501); `7ca3a33f` Subagent activity UX. (#17570); `2e6d69c9` Fix --allowed-tools in non-interactive mode to do substring matching … — run `git show` on any of them.
Change coupling: auth.ts ↔ AuthDialog.tsx packages/cli/src/config/auth.ts— `packages/cli/src/config/auth.ts` and `packages/cli/src/ui/auth/AuthDialog.tsx` change together 59% of the time (10 of the 17 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 10 shared commits counted here, the most recent 3 are `1e7063bb` fix(cli): allow keychain auth for --list-sessions and non-interactive…; `9d74b7c0` feat(auth): Add option for metadata server application default creden…; `06035d5d` feat(auth): improve API key authentication flow (#11760) — run `git show` on any of them.
Change coupling: errorParsing.ts ↔ retry.ts packages/core/src/utils/errorParsing.ts— `packages/core/src/utils/errorParsing.ts` and `packages/core/src/utils/retry.ts` change together 58% of the time (7 of the 12 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module — a sibling reference still needs an import — so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 7 shared commits counted here, the most recent 3 are `ee92db75` fix: handle request retries and model fallback correctly (#11624); `996c9f59` Revert "fix: handle request retries and model fallback correctly" (#1…; `319f43fa` fix: handle request retries and model fallback correctly (#9407) — run `git show` on any of them.
Change coupling: event-metadata-key.ts ↔ loggers.ts packages/core/src/telemetry/clearcut-logger/event-metadata-key.ts— `packages/core/src/telemetry/clearcut-logger/event-metadata-key.ts` and `packages/core/src/telemetry/loggers.ts` change together 56% of the time (38 of the 68 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 38 shared commits counted here, the most recent 3 are `4c5e8877` feat(telemetry): add browser agent clearcut metrics (#24688); `397ff84b` Refine onboarding metrics to log the duration explicitly and use the …; `244a6081` feat(core): set up onboarding telemetry (#23118) — run `git show` on any of them.
Change coupling: App.tsx ↔ ContextSummaryDisplay.tsx packages/cli/src/ui/App.tsx— `packages/cli/src/ui/App.tsx` and `packages/cli/src/ui/components/ContextSummaryDisplay.tsx` change together 56% of the time (10 of the 18 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 10 shared commits counted here, the most recent 3 are `4f2974db` feat(ui): Improve UI layout adaptation for narrow terminals (#5651); `e2754416` Updates schema, UX and prompt for IDE context (#5046); `1d3ad9d0` Add drawer for active files in IDE mode (#4682) — run `git show` on any of them.
Change coupling: config.ts ↔ dynamic-declaration-helpers.ts packages/core/src/config/config.ts— `packages/core/src/config/config.ts` and `packages/core/src/tools/definitions/dynamic-declaration-helpers.ts` change together 55% of the time (6 of the 11 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 6 shared commits counted here, the most recent 3 are `e7f8d9cf` Revert "feat: Introduce an AI-driven interactive shell mode with new"; `651ad63e` feat: Introduce an AI-driven interactive shell mode with new `read-sh…; `f5103947` Implement background process monitoring and inspection tools (#23799) — run `git show` on any of them.
Change coupling: config.ts ↔ memoryCommand.ts packages/cli/src/config/config.ts— `packages/cli/src/config/config.ts` and `packages/cli/src/ui/commands/memoryCommand.ts` change together 53% of the time (9 of the 17 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 9 shared commits counted here, the most recent 3 are `85736502` feat(config): split memoryManager flag into autoMemory (#25601); `2e229d3b` feat(core): Implement JIT context memory loading and UI sync (#14469); `47603ef8` Reload gemini memory on extension load/unload + memory refresh refact… — run `git show` on any of them.
Change coupling: policy-engine.ts ↔ toml-loader.ts packages/core/src/policy/policy-engine.ts— `packages/core/src/policy/policy-engine.ts` and `packages/core/src/policy/toml-loader.ts` change together 53% of the time (10 of the 19 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module — a sibling reference still needs an import — so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 10 shared commits counted here, the most recent 3 are `b35c12d8` fix(core)!: Force policy config to specify toolName (#23330); `1725ec34` feat(plan): support plan mode in non-interactive mode (#22670); `527074b5` feat(policy): support subagent-specific policies in TOML (#21431) — run `git show` on any of them.
Change coupling: registry.ts ↔ remote-invocation.ts packages/core/src/agents/registry.ts— `packages/core/src/agents/registry.ts` and `packages/core/src/agents/remote-invocation.ts` change together 50% of the time (7 of the 14 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module — a sibling reference still needs an import — so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 7 shared commits counted here, the most recent 3 are `0c919857` feat(core): support inline agentCardJson for remote agents (#23743); `7ae39fd6` feat(a2a): add agent acknowledgment command and enhance registry disc…; `4b76fe00` feat(core): add google credentials provider for remote agents (#21024) — run `git show` on any of them.
Change coupling: extensions.tsx ↔ extension.ts packages/cli/src/commands/extensions.tsx— `packages/cli/src/commands/extensions.tsx` and `packages/cli/src/config/extension.ts` change together 50% of the time (6 of the 12 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 6 shared commits counted here, the most recent 3 are `6a581a69` Add `gemini extensions link` command (#7241); `51bb624d` Add extensions enable command (#7042); `f32a54fe` [extensions] Add extensions update command (#6878) — run `git show` on any of them.
Change coupling: GeminiMessage.tsx ↔ ToolMessage.tsx packages/cli/src/ui/components/messages/GeminiMessage.tsx— `packages/cli/src/ui/components/messages/GeminiMessage.tsx` and `packages/cli/src/ui/components/messages/ToolMessage.tsx` change together 50% of the time (6 of the 12 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module — a sibling reference still needs an import — so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 6 shared commits counted here, the most recent 3 are `6ded45e5` feat: Add markdown toggle (alt+m) to switch between rendered and raw……; `fe5bb669` Screen reader updates (#7307); `b0bc7c3d` Fix flicker issues by ensuring all actively changing content fits in … — run `git show` on any of them.
Change coupling: aboutCommand.ts ↔ AboutBox.tsx packages/cli/src/ui/commands/aboutCommand.ts— `packages/cli/src/ui/commands/aboutCommand.ts` and `packages/cli/src/ui/components/AboutBox.tsx` change together 50% of the time (5 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 5 shared commits counted here, the most recent 3 are `5c649d8d` feat(ui): display user tier in about command (#17400); `43d6dc36` Add User email detail to about box (#13459); `925d747b` Revert "feat: add explicit license selection and status visibility (#… — run `git show` on any of them.
Change coupling: ProQuotaDialog.tsx ↔ useQuotaAndFallback.ts packages/cli/src/ui/components/ProQuotaDialog.tsx— `packages/cli/src/ui/components/ProQuotaDialog.tsx` and `packages/cli/src/ui/hooks/useQuotaAndFallback.ts` change together 50% of the time (5 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 5 shared commits counted here, the most recent 3 are `188e255b` fix(core,cli): resolve false model capacity exhaustion and fix core q…; `edb1fdea` fix(cli): support quota error fallbacks for all authentication types …; `d8a3d08f` fallback to flash for TerminalQuota errors (#13791) — run `git show` on any of them.
Change coupling: UIStateContext.tsx ↔ nonInteractiveUi.ts packages/cli/src/ui/contexts/UIStateContext.tsx— `packages/cli/src/ui/contexts/UIStateContext.tsx` and `packages/cli/src/ui/noninteractive/nonInteractiveUi.ts` change together 50% of the time (5 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 5 shared commits counted here, the most recent 3 are `1f1cf756` Add shortcuts hint and panel for discoverability (#18035); `902e5d6d` feat(cli): Add state management and plumbing for agent configuration …; `9786c4dc` Check folder trust before allowing add directory (#12652) — run `git show` on any of them.
TooManyMethods: Config packages/core/src/config/config.ts:753— TooManyMethods — 273 methods. The bar is 30 methods; this is 243 over it, 9.10× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: ClearcutLogger packages/core/src/telemetry/clearcut-logger/clearcut-logger.ts:294— TooManyMethods — 71 methods. The bar is 30 methods; this is 41 over it, 2.37× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: Storage packages/core/src/config/storage.ts:30— TooManyMethods — 62 methods. The bar is 30 methods; this is 32 over it, 2.07× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: SchedulerStateManager packages/core/src/scheduler/state-manager.ts:47— TooManyMethods — 35 methods. The bar is 30 methods; this is 5 over it, 1.17× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: GeminiClient packages/core/src/core/client.ts:93— TooManyMethods — 34 methods. The bar is 30 methods; this is 4 over it, 1.13× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: Task packages/a2a-server/src/agent/task.ts:74— TooManyMethods — 31 methods. The bar is 30 methods; this is 1 over it, 1.03× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
R10 · Code Duplication· Duplicated block with local edits (50 matched lines × 2 locations) · ×3
Duplicated block with local edits (50 matched lines × 2 locations) packages/a2a-server/src/commands/restore.ts:66— packages/a2a-server/src/commands/restore.ts:66 · packages/cli/src/acp/commands/restore.ts:62 — the two spans are one implementation copied and then locally edited — 280 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block with local edits (50 matched lines × 2 locations) packages/core/src/agents/remote-invocation.ts:63— packages/core/src/agents/remote-invocation.ts:63 · packages/core/src/agents/remote-session-invocation.ts:74 — the two spans are one implementation copied and then locally edited — 240 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block with local edits (50 matched lines × 2 locations) packages/core/src/tools/web-fetch.ts:835— packages/core/src/tools/web-fetch.ts:835 · packages/core/src/tools/web-search.ts:130 — the two spans are one implementation copied and then locally edited — 227 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Dead file (~120 LoC) tools/gemini-cli-bot/history/sync.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~120 LoC) tools/gemini-cli-bot/metrics/scripts/latency.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~120 LoC) tools/gemini-cli-bot/metrics/scripts/throughput.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
HackComment packages/core/src/config/config.ts:1149— // HACK: The settings loading logic doesn't currently merge the default — a workaround marked in source: record what it is compensating for and what would allow its removal (the upstream fix, the API it is waiting on, the invariant it restores), so the next reader can judge whether it is still needed rather than rediscovering why it is there.
HackComment packages/vscode-ide-companion/src/integration-tests/run-test.ts:25— // Hack: Intercept require('vscode') globally in this process — a workaround marked in source: record what it is compensating for and what would allow its removal (the upstream fix, the API it is waiting on, the invariant it restores), so the next reader can judge whether it is still needed rather than rediscovering why it is there.
R10 · Code Duplication· Duplicated block with local edits (56 matched lines × 2 locations) · ×2
Duplicated block with local edits (56 matched lines × 2 locations) packages/cli/src/commands/extensions/disable.ts:23— packages/cli/src/commands/extensions/disable.ts:23 · packages/cli/src/commands/extensions/enable.ts:28 — the two spans are one implementation copied and then locally edited — 271 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block with local edits (56 matched lines × 2 locations) packages/core/src/routing/strategies/classifierStrategy.ts:130— packages/core/src/routing/strategies/classifierStrategy.ts:130 · packages/core/src/routing/strategies/numericalClassifierStrategy.ts:102 — the two spans are one implementation copied and then locally edited — 292 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
R10 · Code Duplication· Duplicated block with local edits (46 matched lines × 2 locations) · ×2
Duplicated block with local edits (46 matched lines × 2 locations) packages/a2a-server/src/commands/memory.ts:18— packages/a2a-server/src/commands/memory.ts:18 · packages/cli/src/acp/commands/memory.ts:21 — the two spans are one implementation copied and then locally edited — 247 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block with local edits (46 matched lines × 2 locations) packages/cli/src/utils/featureToggleUtils.ts:83— packages/cli/src/utils/featureToggleUtils.ts:83 · packages/cli/src/utils/hookSettings.ts:36 — the two spans are one implementation copied and then locally edited — 257 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
R10 · Code Duplication· Duplicated block with local edits (45 matched lines × 2 locations) · ×2
Duplicated block with local edits (45 matched lines × 2 locations) packages/core/src/mcp/google-auth-provider.ts:60— packages/core/src/mcp/google-auth-provider.ts:60 · packages/core/src/mcp/sa-impersonation-provider.ts:65 — the two spans are one implementation copied and then locally edited — 192 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block with local edits (45 matched lines × 2 locations) packages/core/src/services/sandboxedFileSystemService.ts:50— packages/core/src/services/sandboxedFileSystemService.ts:50 · packages/core/src/services/sandboxedFileSystemService.ts:114 — the two spans are one implementation copied and then locally edited — 234 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block (40 lines × 2 locations) packages/cli/src/utils/agentUtils.ts:18— packages/cli/src/utils/agentUtils.ts:18 · packages/cli/src/utils/skillUtils.ts:29 — the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it.
Duplicated block (40 lines × 2 locations) packages/core/src/agents/local-subagent-protocol.ts:384— packages/core/src/agents/local-subagent-protocol.ts:384 · packages/core/src/agents/remote-subagent-protocol.ts:375 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (39 lines × 2 locations) packages/cli/src/ui/components/shared/vim-buffer-actions.ts:640— packages/cli/src/ui/components/shared/vim-buffer-actions.ts:640 · packages/cli/src/ui/components/shared/vim-buffer-actions.ts:688 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (39 lines × 2 locations) packages/cli/src/ui/components/triage/TriageDuplicates.tsx:872— packages/cli/src/ui/components/triage/TriageDuplicates.tsx:872 · packages/cli/src/ui/components/triage/TriageIssues.tsx:564 — the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it.
Dead file (~32 LoC) tools/gemini-cli-bot/metrics/scripts/open_issues.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~32 LoC) tools/gemini-cli-bot/metrics/scripts/open_prs.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
AC3 · Page structure· Page without a main landmark · ×1
Page without a main landmark packages/devtools/client/index.html:2— No <main> (or role="main") means no "skip to content" target and a weaker landmark map. This document's body is only the mount point <div id="root">, so there is no content here to wrap — render the <main> from the component mounted into it.
AC7 · A11y enforcement· Accessibility enforcement below the top rung · ×1
Accessibility enforcement below the top rung — No accessibility enforcement found — no a11y linter (eslint-plugin-jsx-a11y) and no axe/pa11y/Lighthouse in tests or CI. Start with the linter to catch issues at author time. What was searched, so you can tell an absence from a miss: the 20 markup file(s) this pass actually assessed, the linter configuration checked in beside them, and this repository's test and CI files — matched by name against the accessibility checkers this dimension carries. An audit run outside the repository, a hosted scanner, or a check whose name is not one of those, is not seen here.
InputPrompt.InputPrompt (cyclomatic 350) packages/cli/src/ui/components/InputPrompt.tsx:207— InputPrompt.InputPrompt has cyclomatic complexity 350 (threshold 15). Of this number, 41 points are the body's own statements and 309 belong to 21 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
AppContainer.AppContainer (cyclomatic 276) packages/cli/src/ui/AppContainer.tsx:223— AppContainer.AppContainer has cyclomatic complexity 276 (threshold 15). Of this number, 71 points are the body's own statements and 205 belong to 53 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
useGeminiStream.useGeminiStream (cyclomatic 261) packages/cli/src/ui/hooks/useGeminiStream.ts:224— useGeminiStream.useGeminiStream has cyclomatic complexity 261 (threshold 15). Most of this is not in the body itself: 2 of the 261 points are its own statements and the rest belongs to 45 function literals inside it that branch (lines 452, 1973, 1534, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
vim-buffer-actions.handleVimAction (cyclomatic 246) packages/cli/src/ui/components/shared/vim-buffer-actions.ts:164— vim-buffer-actions.handleVimAction has cyclomatic complexity 246 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
vim.useVim (cyclomatic 213) packages/cli/src/ui/hooks/vim.ts:187— vim.useVim has cyclomatic complexity 213 (threshold 15). Most of this is not in the body itself: 1 of the 213 points is its own statement and the rest belongs to 6 function literals inside it that branch (lines 660, 230, 473, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
text-buffer.textBufferReducerLogic (cyclomatic 182) packages/cli/src/ui/components/shared/text-buffer.ts:1787— text-buffer.textBufferReducerLogic has cyclomatic complexity 182 (threshold 15). Of this number, 176 points are the body's own statements and 6 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ToolConfirmationMessage.ToolConfirmationMessage (cyclomatic 156) packages/cli/src/ui/components/messages/ToolConfirmationMessage.tsx:65— ToolConfirmationMessage.ToolConfirmationMessage has cyclomatic complexity 156 (threshold 15). Of this number, 20 points are the body's own statements and 136 belong to 14 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
sandbox.start_sandbox (cyclomatic 146) packages/cli/src/utils/sandbox.ts:55— sandbox.start_sandbox has cyclomatic complexity 146 (threshold 15). Of this number, 131 points are the body's own statements and 15 belong to 6 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ShellToolInvocation.execute (cyclomatic 130) packages/core/src/tools/shell.ts:523— ShellToolInvocation.execute has cyclomatic complexity 130 (threshold 15). Of this number, 106 points are the body's own statements and 24 belong to 8 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
TriageDuplicates.TriageDuplicates (cyclomatic 124) packages/cli/src/ui/components/triage/TriageDuplicates.tsx:105— TriageDuplicates.TriageDuplicates has cyclomatic complexity 124 (threshold 15). Of this number, 31 points are the body's own statements and 93 belong to 22 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
nonInteractiveCliAgentSession.runNonInteractive (cyclomatic 118) packages/cli/src/nonInteractiveCliAgentSession.ts:75— nonInteractiveCliAgentSession.runNonInteractive has cyclomatic complexity 118 (threshold 15). Most of this is not in the body itself: 1 of the 118 points is its own statement and the rest belongs to 10 function literals inside it that branch (lines 82, 371, 151, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
InboxDialog.InboxDialog (cyclomatic 118) packages/cli/src/ui/components/InboxDialog.tsx:331— InboxDialog.InboxDialog has cyclomatic complexity 118 (threshold 15). Of this number, 41 points are the body's own statements and 77 belong to 24 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
VirtualizedList.VirtualizedList (cyclomatic 106) packages/cli/src/ui/components/shared/VirtualizedList.tsx:129— VirtualizedList.VirtualizedList has cyclomatic complexity 106 (threshold 15). Of this number, 24 points are the body's own statements and 82 belong to 19 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
config.loadCliConfig (cyclomatic 101) packages/cli/src/config/config.ts:583— config.loadCliConfig has cyclomatic complexity 101 (threshold 15). Of this number, 98 points are the body's own statements and 3 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
nonInteractiveCli.runNonInteractive (cyclomatic 94) packages/cli/src/nonInteractiveCli.ts:72— nonInteractiveCli.runNonInteractive has cyclomatic complexity 94 (threshold 15). Most of this is not in the body itself: 2 of the 94 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 85, 154, 105, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
Session.#resolvePrompt (cyclomatic 91) packages/cli/src/acp/acpSession.ts:969— Session.#resolvePrompt has cyclomatic complexity 91 (threshold 15). Of this number, 83 points are the body's own statements and 8 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
KeypressContext.emitKeys (cyclomatic 91) packages/cli/src/ui/contexts/KeypressContext.tsx:380— KeypressContext.emitKeys has cyclomatic complexity 91 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
AskUserDialog.ChoiceQuestionView (cyclomatic 87) packages/cli/src/ui/components/AskUserDialog.tsx:520— AskUserDialog.ChoiceQuestionView has cyclomatic complexity 87 (threshold 15). Most of this is not in the body itself: 15 of the 87 points are its own statements and the rest belongs to 14 function literals inside it that branch (lines 921, 673, 796, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ToolGroupMessage.ToolGroupMessage (cyclomatic 83) packages/cli/src/ui/components/messages/ToolGroupMessage.tsx:110— ToolGroupMessage.ToolGroupMessage has cyclomatic complexity 83 (threshold 15). Most of this is not in the body itself: 15 of the 83 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 353, 182, 163, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ShellExecutionService.executeWithPty (cyclomatic 79) packages/core/src/services/shellExecutionService.ts:1103— ShellExecutionService.executeWithPty has cyclomatic complexity 79 (threshold 15). Of this number, 22 points are the body's own statements and 57 belong to 20 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
chatRecordingService.loadConversationRecord (cyclomatic 78) packages/core/src/services/chatRecordingService.ts:133— chatRecordingService.loadConversationRecord has cyclomatic complexity 78 (threshold 15). Of this number, 74 points are the body's own statements and 4 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
useExecutionLifecycle.useExecutionLifecycle (cyclomatic 76) packages/cli/src/ui/hooks/useExecutionLifecycle.ts:75— useExecutionLifecycle.useExecutionLifecycle has cyclomatic complexity 76 (threshold 15). Most of this is not in the body itself: 2 of the 76 points are its own statements and the rest belongs to 16 function literals inside it that branch (lines 365, 425, 113, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
slashCommandProcessor.useSlashCommandProcessor (cyclomatic 75) packages/cli/src/ui/hooks/slashCommandProcessor.ts:97— slashCommandProcessor.useSlashCommandProcessor has cyclomatic complexity 75 (threshold 15). Most of this is not in the body itself: 1 of the 75 points is its own statement and the rest belongs to 13 function literals inside it that branch (lines 355, 159, 585, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useCommandCompletion.useCommandCompletion (cyclomatic 74) packages/cli/src/ui/hooks/useCommandCompletion.tsx:77— useCommandCompletion.useCommandCompletion has cyclomatic complexity 74 (threshold 15). Most of this is not in the body itself: 14 of the 74 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 121, 405, 253, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
gemini.main (cyclomatic 71) packages/cli/src/gemini.tsx:466— gemini.main has cyclomatic complexity 71 (threshold 15). Of this number, 66 points are the body's own statements and 5 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
BaseSettingsDialog.BaseSettingsDialog (cyclomatic 71) packages/cli/src/ui/components/shared/BaseSettingsDialog.tsx:128— BaseSettingsDialog.BaseSettingsDialog has cyclomatic complexity 71 (threshold 15). Of this number, 18 points are the body's own statements and 53 belong to 5 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
StatusRow.StatusRow (cyclomatic 70) packages/cli/src/ui/components/StatusRow.tsx:158— StatusRow.StatusRow has cyclomatic complexity 70 (threshold 15). Of this number, 50 points are the body's own statements and 20 belong to 5 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
text-buffer.useTextBuffer (cyclomatic 69) packages/cli/src/ui/components/shared/text-buffer.ts:2832— text-buffer.useTextBuffer has cyclomatic complexity 69 (threshold 15). Most of this is not in the body itself: 4 of the 69 points are its own statements and the rest belongs to 8 function literals inside it that branch (lines 3372, 2948, 3552, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useVoiceMode.useVoiceMode (cyclomatic 68) packages/cli/src/ui/hooks/useVoiceMode.ts:33— useVoiceMode.useVoiceMode has cyclomatic complexity 68 (threshold 15). Most of this is not in the body itself: 1 of the 68 points is its own statement and the rest belongs to 12 function literals inside it that branch (lines 319, 131, 189, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
GeminiChat.processStreamResponse (cyclomatic 68) packages/core/src/core/geminiChat.ts:1354— GeminiChat.processStreamResponse has cyclomatic complexity 68 (threshold 15). Of this number, 66 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
CoderAgentExecutor.execute (cyclomatic 65) packages/a2a-server/src/agent/executor.ts:439— CoderAgentExecutor.execute has cyclomatic complexity 65 (threshold 15). Most of this is not in the body itself: 12 of the 65 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 490, 565, 524, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useAgentStream.useAgentStream (cyclomatic 64) packages/cli/src/ui/hooks/useAgentStream.ts:56— useAgentStream.useAgentStream has cyclomatic complexity 64 (threshold 15). Most of this is not in the body itself: 2 of the 64 points are its own statements and the rest belongs to 14 function literals inside it that branch (lines 149, 485, 412, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
PolicyEngine.check (cyclomatic 61) packages/core/src/policy/policy-engine.ts:600— PolicyEngine.check has cyclomatic complexity 61 (threshold 15). Of this number, 58 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ExtensionManager.installOrUpdateExtension (cyclomatic 60) packages/cli/src/config/extension-manager.ts:180— ExtensionManager.installOrUpdateExtension has cyclomatic complexity 60 (threshold 15). Of this number, 58 points are the body's own statements and 2 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
LocalSessionInvocation.execute (cyclomatic 60) packages/core/src/agents/local-session-invocation.ts:111— LocalSessionInvocation.execute has cyclomatic complexity 60 (threshold 15). Of this number, 21 points are the body's own statements and 39 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Footer.Footer (cyclomatic 59) packages/cli/src/ui/components/Footer.tsx:179— Footer.Footer has cyclomatic complexity 59 (threshold 15). Of this number, 47 points are the body's own statements and 12 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ContextCompressionService.compressHistory (cyclomatic 57) packages/core/src/context/contextCompressionService.ts:108— ContextCompressionService.compressHistory has cyclomatic complexity 57 (threshold 15). Of this number, 56 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
googleQuotaErrors.classifyGoogleError (cyclomatic 57) packages/core/src/utils/googleQuotaErrors.ts:223— googleQuotaErrors.classifyGoogleError has cyclomatic complexity 57 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
TriageIssues.TriageIssues (cyclomatic 56) packages/cli/src/ui/components/triage/TriageIssues.tsx:66— TriageIssues.TriageIssues has cyclomatic complexity 56 (threshold 15). Of this number, 20 points are the body's own statements and 36 belong to 13 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
App.App (cyclomatic 56) packages/devtools/client/src/App.tsx:28— App.App has cyclomatic complexity 56 (threshold 15). Of this number, 16 points are the body's own statements and 40 belong to 15 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
BrowserAgentInvocation.execute (cyclomatic 55) packages/core/src/agents/browser/browserAgentInvocation.ts:111— BrowserAgentInvocation.execute has cyclomatic complexity 55 (threshold 15). Of this number, 23 points are the body's own statements and 32 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
retry.retryWithBackoff (cyclomatic 55) packages/core/src/utils/retry.ts:258— retry.retryWithBackoff has cyclomatic complexity 55 (threshold 15). Of this number, 54 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
LocalSubagentInvocation.execute (cyclomatic 54) packages/core/src/agents/local-invocation.ts:102— LocalSubagentInvocation.execute has cyclomatic complexity 54 (threshold 15). Of this number, 19 points are the body's own statements and 35 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
patch-create-comment.main (cyclomatic 54) scripts/releasing/patch-create-comment.js:17— patch-create-comment.main has cyclomatic complexity 54 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
McpStatus.McpStatus (cyclomatic 53) packages/cli/src/ui/components/views/McpStatus.tsx:35— McpStatus.McpStatus has cyclomatic complexity 53 (threshold 15). Most of this is not in the body itself: 4 of the 53 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 89, 284, 220, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useSlashCompletion.useCommandSuggestions (cyclomatic 52) packages/cli/src/ui/hooks/useSlashCompletion.ts:145— useSlashCompletion.useCommandSuggestions has cyclomatic complexity 52 (threshold 15). Most of this is not in the body itself: 1 of the 52 points is its own statement and the rest belongs to 7 function literals inside it that branch (lines 278, 229, 173, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
Session.prompt (cyclomatic 51) packages/cli/src/acp/acpSession.ts:311— Session.prompt has cyclomatic complexity 51 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
GeminiClient.processTurn (cyclomatic 51) packages/core/src/core/client.ts:614— GeminiClient.processTurn has cyclomatic complexity 51 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
contentGenerator.createContentGenerator (cyclomatic 50) packages/core/src/core/contentGenerator.ts:210— contentGenerator.createContentGenerator has cyclomatic complexity 50 (threshold 15). Most of this is not in the body itself: 2 of the 50 points are its own statements and the rest belongs to one function literal inside it that branches (line 215). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
GeminiChat.sendMessageStream (cyclomatic 50) packages/core/src/core/geminiChat.ts:480— GeminiChat.sendMessageStream has cyclomatic complexity 50 (threshold 15). Of this number, 21 points are the body's own statements and 29 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ExtensionManager._buildExtension (cyclomatic 48) packages/cli/src/config/extension-manager.ts:708— ExtensionManager._buildExtension has cyclomatic complexity 48 (threshold 15). Of this number, 47 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
BackgroundTaskDisplay.BackgroundTaskDisplay (cyclomatic 48) packages/cli/src/ui/components/BackgroundTaskDisplay.tsx:64— BackgroundTaskDisplay.BackgroundTaskDisplay has cyclomatic complexity 48 (threshold 15). Most of this is not in the body itself: 7 of the 48 points are its own statements and the rest belongs to 14 function literals inside it that branch (lines 146, 228, 111, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
GrepToolInvocation.performGrepSearch (cyclomatic 47) packages/core/src/tools/grep.ts:413— GrepToolInvocation.performGrepSearch has cyclomatic complexity 47 (threshold 15). Of this number, 41 points are the body's own statements and 6 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
consent.extensionConsentString (cyclomatic 46) packages/cli/src/config/extensions/consent.ts:189— consent.extensionConsentString has cyclomatic complexity 46 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ScrollProvider.ScrollProvider (cyclomatic 46) packages/cli/src/ui/contexts/ScrollProvider.tsx:94— ScrollProvider.ScrollProvider has cyclomatic complexity 46 (threshold 15). Most of this is not in the body itself: 1 of the 46 points is its own statement and the rest belongs to 7 function literals inside it that branch (lines 258, 190, 360, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ActivityLogger.patchNodeHttp (cyclomatic 46) packages/cli/src/utils/activityLogger.ts:441— ActivityLogger.patchNodeHttp has cyclomatic complexity 46 (threshold 15). Most of this is not in the body itself: 1 of the 46 points is its own statement and the rest belongs to 9 function literals inside it that branch (lines 447, 529, 508, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
config.createPolicyEngineConfig (cyclomatic 46) packages/core/src/policy/config.ts:286— config.createPolicyEngineConfig has cyclomatic complexity 46 (threshold 15). Of this number, 35 points are the body's own statements and 11 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
memoryService.startMemoryService (cyclomatic 46) packages/core/src/services/memoryService.ts:1133— memoryService.startMemoryService has cyclomatic complexity 46 (threshold 15). Of this number, 38 points are the body's own statements and 8 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
MarkdownDisplay.MarkdownDisplayInternal (cyclomatic 44) packages/cli/src/ui/utils/MarkdownDisplay.tsx:31— MarkdownDisplay.MarkdownDisplayInternal has cyclomatic complexity 44 (threshold 15). Most of this is not in the body itself: 10 of the 44 points are its own statements and the rest belongs to one function literal inside it that branches (line 88). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
ShellExecutionService.childProcessFallback (cyclomatic 44) packages/core/src/services/shellExecutionService.ts:652— ShellExecutionService.childProcessFallback has cyclomatic complexity 44 (threshold 15). Most of this is not in the body itself: 15 of the 44 points are its own statements and the rest belongs to 8 function literals inside it that branch (lines 768, 838, 728, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
DenseToolMessage.DenseToolMessage (cyclomatic 43) packages/cli/src/ui/components/messages/DenseToolMessage.tsx:261— DenseToolMessage.DenseToolMessage has cyclomatic complexity 43 (threshold 15). Of this number, 17 points are the body's own statements and 26 belong to 5 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
useQuotaAndFallback.useQuotaAndFallback (cyclomatic 42) packages/cli/src/ui/hooks/useQuotaAndFallback.ts:51— useQuotaAndFallback.useQuotaAndFallback has cyclomatic complexity 42 (threshold 15). Most of this is not in the body itself: 1 of the 42 points is its own statement and the rest belongs to 6 function literals inside it that branch (lines 75, 293, 321, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
LocalAgentExecutor.runInternal (cyclomatic 41) packages/core/src/agents/local-executor.ts:571— LocalAgentExecutor.runInternal has cyclomatic complexity 41 (threshold 15). Of this number, 38 points are the body's own statements and 3 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
sea-launch.prepareRuntime (cyclomatic 41) sea/sea-launch.cjs:93— sea-launch.prepareRuntime has cyclomatic complexity 41 (threshold 15). Of this number, 33 points are the body's own statements and 8 belong to 2 function literals inside it that branch. To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
config.parseArguments (cyclomatic 40) packages/cli/src/config/config.ts:161— config.parseArguments has cyclomatic complexity 40 (threshold 15). Most of this is not in the body itself: 12 of the 40 points are its own statements and the rest belongs to 7 function literals inside it that branch (lines 230, 192, 183, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
SettingsDialog.SettingsDialog (cyclomatic 40) packages/cli/src/ui/components/SettingsDialog.tsx:100— SettingsDialog.SettingsDialog has cyclomatic complexity 40 (threshold 15). Most of this is not in the body itself: 6 of the 40 points are its own statements and the rest belongs to 14 function literals inside it that branch (lines 300, 222, 195, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
policy-engine.ruleMatches (cyclomatic 40) packages/core/src/policy/policy-engine.ts:129— policy-engine.ruleMatches has cyclomatic complexity 40 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
setup.handleSetup (cyclomatic 39) packages/cli/src/commands/gemma/setup.ts:159— setup.handleSetup has cyclomatic complexity 39 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
text-buffer.findWordEndInLine (cyclomatic 39) packages/cli/src/ui/components/shared/text-buffer.ts:182— text-buffer.findWordEndInLine has cyclomatic complexity 39 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
MCPOAuthProvider.authenticate (cyclomatic 39) packages/core/src/mcp/oauth-provider.ts:304— MCPOAuthProvider.authenticate has cyclomatic complexity 39 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
settings.migrateDeprecatedSettings (cyclomatic 38) packages/cli/src/config/settings.ts:1001— settings.migrateDeprecatedSettings has cyclomatic complexity 38 (threshold 15). Most of this is not in the body itself: 4 of the 38 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 1044, 1011). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
SubagentGroupDisplay.SubagentGroupDisplay (cyclomatic 38) packages/cli/src/ui/components/messages/SubagentGroupDisplay.tsx:34— SubagentGroupDisplay.SubagentGroupDisplay has cyclomatic complexity 38 (threshold 15). Of this number, 16 points are the body's own statements and 22 belong to 5 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
markdownParsingUtils.parseMarkdownToANSI (cyclomatic 38) packages/cli/src/ui/utils/markdownParsingUtils.ts:106— markdownParsingUtils.parseMarkdownToANSI has cyclomatic complexity 38 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
sessionCleanup.cleanupExpiredSessions (cyclomatic 38) packages/cli/src/utils/sessionCleanup.ts:102— sessionCleanup.cleanupExpiredSessions has cyclomatic complexity 38 (threshold 15). Of this number, 36 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
config.createPolicyUpdater (cyclomatic 38) packages/core/src/policy/config.ts:712— config.createPolicyUpdater has cyclomatic complexity 38 (threshold 15). Most of this is not in the body itself: 1 of the 38 points is its own statement and the rest belongs to 2 function literals inside it that branch (lines 796, 722). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
mcp-client.connectToMcpServer (cyclomatic 38) packages/core/src/tools/mcp-client.ts:1839— mcp-client.connectToMcpServer has cyclomatic complexity 38 (threshold 15). Of this number, 36 points are the body's own statements and 2 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
patch-trigger.main (cyclomatic 38) scripts/releasing/patch-trigger.js:56— patch-trigger.main has cyclomatic complexity 38 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
DialogManager.DialogManager (cyclomatic 37) packages/cli/src/ui/components/DialogManager.tsx:50— DialogManager.DialogManager has cyclomatic complexity 37 (threshold 15). Of this number, 36 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
HistoryItemDisplay.HistoryItemDisplay (cyclomatic 37) packages/cli/src/ui/components/HistoryItemDisplay.tsx:58— HistoryItemDisplay.HistoryItemDisplay has cyclomatic complexity 37 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
ModelDialog.ModelDialog (cyclomatic 37) packages/cli/src/ui/components/ModelDialog.tsx:41— ModelDialog.ModelDialog has cyclomatic complexity 37 (threshold 15). Most of this is not in the body itself: 4 of the 37 points are its own statements and the rest belongs to 10 function literals inside it that branch (lines 192, 75, 106, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ExtensionDetails.ExtensionDetails (cyclomatic 37) packages/cli/src/ui/components/views/ExtensionDetails.tsx:31— ExtensionDetails.ExtensionDetails has cyclomatic complexity 37 (threshold 15). Of this number, 22 points are the body's own statements and 15 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
ReadManyFilesToolInvocation.execute (cyclomatic 37) packages/core/src/tools/read-many-files.ts:179— ReadManyFilesToolInvocation.execute has cyclomatic complexity 37 (threshold 15). Of this number, 29 points are the body's own statements and 8 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
LoadingIndicator.LoadingIndicator (cyclomatic 36) packages/cli/src/ui/components/LoadingIndicator.tsx:36— LoadingIndicator.LoadingIndicator has cyclomatic complexity 36 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
usePromptCompletion.usePromptCompletion (cyclomatic 36) packages/cli/src/ui/hooks/usePromptCompletion.ts:35— usePromptCompletion.usePromptCompletion has cyclomatic complexity 36 (threshold 15). Most of this is not in the body itself: 1 of the 36 points is its own statement and the rest belongs to 6 function literals inside it that branch (lines 68, 204, 167, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ContextWorkingBufferImpl.syncPristineHistory (cyclomatic 36) packages/core/src/context/pipeline/contextWorkingBuffer.ts:184— ContextWorkingBufferImpl.syncPristineHistory has cyclomatic complexity 36 (threshold 15). Of this number, 21 points are the body's own statements and 15 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
GeminiClient.getIdeContextParts (cyclomatic 36) packages/core/src/core/client.ts:429— GeminiClient.getIdeContextParts has cyclomatic complexity 36 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
toml-loader.loadPoliciesFromToml (cyclomatic 36) packages/core/src/policy/toml-loader.ts:323— toml-loader.loadPoliciesFromToml has cyclomatic complexity 36 (threshold 15). Of this number, 24 points are the body's own statements and 12 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
SessionBrowser.useSessionBrowserInput (cyclomatic 35) packages/cli/src/ui/components/SessionBrowser.tsx:542— SessionBrowser.useSessionBrowserInput has cyclomatic complexity 35 (threshold 15). Most of this is not in the body itself: 1 of the 35 points is its own statement and the rest belongs to 3 function literals inside it that branch (lines 551, 624, 640). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
activityLogger.setupNetworkLogging (cyclomatic 35) packages/cli/src/utils/activityLogger.ts:734— activityLogger.setupNetworkLogging has cyclomatic complexity 35 (threshold 15). Most of this is not in the body itself: 1 of the 35 points is its own statement and the rest belongs to 10 function literals inside it that branch (lines 764, 877, 801, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
sandbox.start_lxc_sandbox (cyclomatic 35) packages/cli/src/utils/sandbox.ts:1039— sandbox.start_lxc_sandbox has cyclomatic complexity 35 (threshold 15). Of this number, 29 points are the body's own statements and 6 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
untrustedContextTracker.findUntrustedFlags (cyclomatic 35) packages/core/src/utils/untrustedContextTracker.ts:184— untrustedContextTracker.findUntrustedFlags has cyclomatic complexity 35 (threshold 15). Of this number, 28 points are the body's own statements and 7 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ToolResultDisplay.ToolResultDisplay (cyclomatic 34) packages/cli/src/ui/components/messages/ToolResultDisplay.tsx:59— ToolResultDisplay.ToolResultDisplay has cyclomatic complexity 34 (threshold 15). Most of this is not in the body itself: 13 of the 34 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 102, 271). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useAtCompletion.useAtCompletion (cyclomatic 34) packages/cli/src/ui/hooks/useAtCompletion.ts:206— useAtCompletion.useAtCompletion has cyclomatic complexity 34 (threshold 15). Most of this is not in the body itself: 1 of the 34 points is its own statement and the rest belongs to 11 function literals inside it that branch (lines 357, 274, 303, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
installationInfo.getInstallationInfo (cyclomatic 34) packages/cli/src/utils/installationInfo.ts:36— installationInfo.getInstallationInfo has cyclomatic complexity 34 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
LegacyAgentProtocol._runLoop (cyclomatic 34) packages/core/src/agent/legacy-agent-session.ts:174— LegacyAgentProtocol._runLoop has cyclomatic complexity 34 (threshold 15). Of this number, 33 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
models.resolveModel (cyclomatic 34) packages/core/src/config/models.ts:148— models.resolveModel has cyclomatic complexity 34 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
historyHardening.pairToolsAndEnforceSignatures (cyclomatic 34) packages/core/src/utils/historyHardening.ts:127— historyHardening.pairToolsAndEnforceSignatures has cyclomatic complexity 34 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
GeminiSandbox.Main (cyclomatic 33) packages/core/src/sandbox/windows/GeminiSandbox.cs:191— GeminiSandbox.Main has cyclomatic complexity 33 (threshold 15). Of this number, 32 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
AskUserDialog.AskUserDialog (cyclomatic 33) packages/cli/src/ui/components/AskUserDialog.tsx:1026— AskUserDialog.AskUserDialog has cyclomatic complexity 33 (threshold 15). Of this number, 16 points are the body's own statements and 17 belong to 8 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
borderStyles.getToolGroupBorderAppearance (cyclomatic 33) packages/cli/src/ui/utils/borderStyles.ts:33— borderStyles.getToolGroupBorderAppearance has cyclomatic complexity 33 (threshold 15). Of this number, 17 points are the body's own statements and 16 belong to 4 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
GeminiChat.makeApiCallAndProcessStream (cyclomatic 33) packages/core/src/core/geminiChat.ts:870— GeminiChat.makeApiCallAndProcessStream has cyclomatic complexity 33 (threshold 15). Most of this is not in the body itself: 3 of the 33 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 917, 1098, 1122). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
App.NetworkView (cyclomatic 33) packages/devtools/client/src/App.tsx:831— App.NetworkView has cyclomatic complexity 33 (threshold 15). Most of this is not in the body itself: 7 of the 33 points are its own statements and the rest belongs to 9 function literals inside it that branch (lines 931, 889, 1081, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
McpPromptLoader.loadCommands (cyclomatic 32) packages/cli/src/services/McpPromptLoader.ts:35— McpPromptLoader.loadCommands has cyclomatic complexity 32 (threshold 15). Most of this is not in the body itself: 8 of the 32 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 152, 57, 88, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
MainContent.MainContent (cyclomatic 32) packages/cli/src/ui/components/MainContent.tsx:33— MainContent.MainContent has cyclomatic complexity 32 (threshold 15). Most of this is not in the body itself: 3 of the 32 points are its own statements and the rest belongs to 9 function literals inside it that branch (lines 157, 85, 256, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ModelStatsDisplay.ModelStatsDisplay (cyclomatic 32) packages/cli/src/ui/components/ModelStatsDisplay.tsx:48— ModelStatsDisplay.ModelStatsDisplay has cyclomatic complexity 32 (threshold 15). Of this number, 20 points are the body's own statements and 12 belong to 5 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
atCommandProcessor.resolveFilePaths (cyclomatic 32) packages/cli/src/ui/hooks/atCommandProcessor.ts:224— atCommandProcessor.resolveFilePaths has cyclomatic complexity 32 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
AgentSession.stream (cyclomatic 32) packages/core/src/agent/agent-session.ts:64— AgentSession.stream has cyclomatic complexity 32 (threshold 15). Of this number, 21 points are the body's own statements and 11 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
oauth2.initOauthClient (cyclomatic 32) REDACTED:129— oauth2.initOauthClient has cyclomatic complexity 32 (threshold 15). Of this number, 29 points are the body's own statements and 3 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Turn.run (cyclomatic 32) packages/core/src/core/turn.ts:270— Turn.run has cyclomatic complexity 32 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
McpClientManager.maybeDiscoverMcpServer (cyclomatic 32) packages/core/src/tools/mcp-client-manager.ts:375— McpClientManager.maybeDiscoverMcpServer has cyclomatic complexity 32 (threshold 15). Of this number, 22 points are the body's own statements and 10 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
telemetry_utils.ensureBinary (cyclomatic 32) scripts/telemetry_utils.js:174— telemetry_utils.ensureBinary has cyclomatic complexity 32 (threshold 15). Of this number, 22 points are the body's own statements and 10 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Composer.Composer (cyclomatic 31) packages/cli/src/ui/components/Composer.tsx:32— Composer.Composer has cyclomatic complexity 31 (threshold 15). Of this number, 28 points are the body's own statements and 3 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
ConfigExtensionDialog.ConfigExtensionDialog (cyclomatic 31) packages/cli/src/ui/components/ConfigExtensionDialog.tsx:56— ConfigExtensionDialog.ConfigExtensionDialog has cyclomatic complexity 31 (threshold 15). Most of this is not in the body itself: 10 of the 31 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 126, 211, 95, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ThemeDialog.ThemeDialog (cyclomatic 31) packages/cli/src/ui/components/ThemeDialog.tsx:90— ThemeDialog.ThemeDialog has cyclomatic complexity 31 (threshold 15). Of this number, 17 points are the body's own statements and 14 belong to 6 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
useShellCompletion.useShellCompletion (cyclomatic 31) packages/cli/src/ui/hooks/useShellCompletion.ts:443— useShellCompletion.useShellCompletion has cyclomatic complexity 31 (threshold 15). Most of this is not in the body itself: 5 of the 31 points are its own statements and the rest belongs to 8 function literals inside it that branch (lines 489, 616, 458, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
toolMaskingProcessor.createToolMaskingProcessor (cyclomatic 31) packages/core/src/context/processors/toolMaskingProcessor.ts:81— toolMaskingProcessor.createToolMaskingProcessor has cyclomatic complexity 31 (threshold 15). Most of this is not in the body itself: 1 of the 31 points is its own statement and the rest belongs to 3 function literals inside it that branch (lines 92, 160, 112). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
SnapshotGenerator.synthesizeSnapshot (cyclomatic 31) packages/core/src/context/utils/snapshotGenerator.ts:128— SnapshotGenerator.synthesizeSnapshot has cyclomatic complexity 31 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ShellToolInvocation.shouldConfirmExecute (cyclomatic 31) packages/core/src/tools/shell.ts:302— ShellToolInvocation.shouldConfirmExecute has cyclomatic complexity 31 (threshold 15). Of this number, 27 points are the body's own statements and 4 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
paths.shortenPath (cyclomatic 31) packages/core/src/utils/paths.ts:54— paths.shortenPath has cyclomatic complexity 31 (threshold 15). Most of this is not in the body itself: 10 of the 31 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 71, 162, 209, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
FooterConfigDialog.FooterConfigDialog (cyclomatic 30) packages/cli/src/ui/components/FooterConfigDialog.tsx:87— FooterConfigDialog.FooterConfigDialog has cyclomatic complexity 30 (threshold 15). Most of this is not in the body itself: 5 of the 30 points are its own statements and the rest belongs to 7 function literals inside it that branch (lines 338, 185, 168, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
RewindViewer.RewindViewer (cyclomatic 30) packages/cli/src/ui/components/RewindViewer.tsx:47— RewindViewer.RewindViewer has cyclomatic complexity 30 (threshold 15). Most of this is not in the body itself: 5 of the 30 points are its own statements and the rest belongs to 9 function literals inside it that branch (lines 260, 100, 242, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
editorUtils.openFileInEditor (cyclomatic 30) packages/cli/src/ui/utils/editorUtils.ts:47— editorUtils.openFileInEditor has cyclomatic complexity 30 (threshold 15). Of this number, 27 points are the body's own statements and 3 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
sandboxUtils.isSensitiveHostPath (cyclomatic 30) packages/cli/src/utils/sandboxUtils.ts:151— sandboxUtils.isSensitiveHostPath has cyclomatic complexity 30 (threshold 15). Of this number, 27 points are the body's own statements and 3 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
policyHelpers.resolvePolicyChain (cyclomatic 30) packages/core/src/availability/policyHelpers.ts:40— policyHelpers.resolvePolicyChain has cyclomatic complexity 30 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IDEServer.start (cyclomatic 30) packages/vscode-ide-companion/src/ide-server.ts:138— IDEServer.start has cyclomatic complexity 30 (threshold 15). Most of this is not in the body itself: 1 of the 30 points is its own statement and the rest belongs to 11 function literals inside it that branch (lines 213, 295, 174, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
patch-comment.main (cyclomatic 30) scripts/releasing/patch-comment.js:17— patch-comment.main has cyclomatic complexity 30 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
useSelectionList.useSelectionList (cyclomatic 29) packages/cli/src/ui/hooks/useSelectionList.ts:283— useSelectionList.useSelectionList has cyclomatic complexity 29 (threshold 15). Most of this is not in the body itself: 2 of the 29 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 391, 352, 314, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
sessionCleanup.cleanupToolOutputFiles (cyclomatic 29) packages/cli/src/utils/sessionCleanup.ts:479— sessionCleanup.cleanupToolOutputFiles has cyclomatic complexity 29 (threshold 15). Of this number, 26 points are the body's own statements and 3 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
sdk.initializeTelemetry (cyclomatic 29) packages/core/src/telemetry/sdk.ts:165— sdk.initializeTelemetry has cyclomatic complexity 29 (threshold 15). Of this number, 28 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
googleErrors.parseGoogleApiError (cyclomatic 29) packages/core/src/utils/googleErrors.ts:151— googleErrors.parseGoogleApiError has cyclomatic complexity 29 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Orchestrator.run (cyclomatic 29) tools/caretaker-agent/cloudrun/pr-generator/workflow/orchestrator.py:145— Orchestrator.run has cyclomatic complexity 29 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
DiffRenderer.renderDiffLines (cyclomatic 28) packages/cli/src/ui/components/messages/DiffRenderer.tsx:232— DiffRenderer.renderDiffLines has cyclomatic complexity 28 (threshold 15). Most of this is not in the body itself: 9 of the 28 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 292, 250). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ToolGroupDisplay.ToolDisplayMessage (cyclomatic 28) packages/cli/src/ui/components/messages/ToolGroupDisplay.tsx:118— ToolGroupDisplay.ToolDisplayMessage has cyclomatic complexity 28 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
BrowserManager.connectMcp (cyclomatic 28) packages/core/src/agents/browser/browserManager.ts:559— BrowserManager.connectMcp has cyclomatic complexity 28 (threshold 15). Of this number, 26 points are the body's own statements and 2 belong to 2 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
render.render (cyclomatic 28) packages/core/src/context/graph/render.ts:34— render.render has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
GeminiClient.sendMessageStream (cyclomatic 28) packages/core/src/core/client.ts:910— GeminiClient.sendMessageStream has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
PolicyEngine.checkShellCommand (cyclomatic 28) packages/core/src/policy/policy-engine.ts:441— PolicyEngine.checkShellCommand has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
memoryImportProcessor.processImports (cyclomatic 28) packages/core/src/utils/memoryImportProcessor.ts:190— memoryImportProcessor.processImports has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
security.isFileAndDirectorySecureSync (cyclomatic 28) packages/core/src/utils/security.ts:591— security.isFileAndDirectorySecureSync has cyclomatic complexity 28 (threshold 15). Of this number, 22 points are the body's own statements and 6 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Session.runTool (cyclomatic 27) packages/cli/src/acp/acpSession.ts:659— Session.runTool has cyclomatic complexity 27 (threshold 15). Of this number, 25 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
sandboxConfig.getSandboxCommand (cyclomatic 27) packages/cli/src/config/sandboxConfig.ts:43— sandboxConfig.getSandboxCommand has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
MaxSizedBox.MaxSizedBox (cyclomatic 27) packages/cli/src/ui/components/shared/MaxSizedBox.tsx:36— MaxSizedBox.MaxSizedBox has cyclomatic complexity 27 (threshold 15). Of this number, 22 points are the body's own statements and 5 belong to 3 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
usePhraseCycler.usePhraseCycler (cyclomatic 27) packages/cli/src/ui/hooks/usePhraseCycler.ts:27— usePhraseCycler.usePhraseCycler has cyclomatic complexity 27 (threshold 15). Most of this is not in the body itself: 4 of the 27 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 52, 81, 113, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useShellCompletion.getTokenAtCursor (cyclomatic 27) packages/cli/src/ui/hooks/useShellCompletion.ts:59— useShellCompletion.getTokenAtCursor has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
event-translator.translateEvent (cyclomatic 27) packages/core/src/agent/event-translator.ts:97— event-translator.translateEvent has cyclomatic complexity 27 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
WriteFileToolInvocation.execute (cyclomatic 27) packages/core/src/tools/write-file.ts:370— WriteFileToolInvocation.execute has cyclomatic complexity 27 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
paths.robustRealpath (cyclomatic 27) packages/core/src/utils/paths.ts:459— paths.robustRealpath has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
summary.calc_summary (cyclomatic 27) tools/caretaker-agent/evals/triage/helpers/summary.py:221— summary.calc_summary has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ContextSummaryDisplay.ContextSummaryDisplay (cyclomatic 26) packages/cli/src/ui/components/ContextSummaryDisplay.tsx:24— ContextSummaryDisplay.ContextSummaryDisplay has cyclomatic complexity 26 (threshold 15). Most of this is not in the body itself: 9 of the 26 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 68, 57, 48, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
Notifications.Notifications (cyclomatic 26) packages/cli/src/ui/components/Notifications.tsx:37— Notifications.Notifications has cyclomatic complexity 26 (threshold 15). Most of this is not in the body itself: 11 of the 26 points are its own statements and the rest belongs to 8 function literals inside it that branch (lines 71, 55, 59, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useToolScheduler.useToolScheduler (cyclomatic 26) packages/cli/src/ui/hooks/useToolScheduler.ts:71— useToolScheduler.useToolScheduler has cyclomatic complexity 26 (threshold 15). Most of this is not in the body itself: 1 of the 26 points is its own statement and the rest belongs to 9 function literals inside it that branch (lines 256, 130, 142, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
sandboxUtils.isCredentialOrSensitivePath (cyclomatic 26) packages/cli/src/utils/sandboxUtils.ts:56— sandboxUtils.isCredentialOrSensitivePath has cyclomatic complexity 26 (threshold 15). Of this number, 22 points are the body's own statements and 4 belong to one function literal inside it that branches. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
ide-connection-utils.getConnectionConfigFromFile (cyclomatic 26) packages/core/src/ide/ide-connection-utils.ts:132— ide-connection-utils.getConnectionConfigFromFile has cyclomatic complexity 26 (threshold 15). Of this number, 18 points are the body's own statements and 8 belong to 6 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
fileUtils.processSingleFileContent (cyclomatic 26) packages/core/src/utils/fileUtils.ts:492— fileUtils.processSingleFileContent has cyclomatic complexity 26 (threshold 15). Of this number, 25 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
generateContentResponseUtilities.convertToFunctionResponse (cyclomatic 26) packages/core/src/utils/generateContentResponseUtilities.ts:49— generateContentResponseUtilities.convertToFunctionResponse has cyclomatic complexity 26 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
googleErrors.fromCauseError (cyclomatic 26) packages/core/src/utils/googleErrors.ts:389— googleErrors.fromCauseError has cyclomatic complexity 26 (threshold 15). Of this number, 22 points are the body's own statements and 4 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
process-utils.killProcessGroup (cyclomatic 26) packages/core/src/utils/process-utils.ts:38— process-utils.killProcessGroup has cyclomatic complexity 26 (threshold 15). Of this number, 24 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
sessionUtils.convertSessionToClientHistory (cyclomatic 26) packages/core/src/utils/sessionUtils.ts:110— sessionUtils.convertSessionToClientHistory has cyclomatic complexity 26 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
untrustedContextTracker.extractUntrustedContext (cyclomatic 26) packages/core/src/utils/untrustedContextTracker.ts:84— untrustedContextTracker.extractUntrustedContext has cyclomatic complexity 26 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
eval-validate.validateInventory (cyclomatic 26) scripts/utils/eval-validate.ts:357— eval-validate.validateInventory has cyclomatic complexity 26 (threshold 15). Of this number, 23 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Task.acceptAgentMessage (cyclomatic 25) packages/a2a-server/src/agent/task.ts:821— Task.acceptAgentMessage has cyclomatic complexity 25 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
Task._handleToolConfirmationPart (cyclomatic 25) packages/a2a-server/src/agent/task.ts:943— Task._handleToolConfirmationPart has cyclomatic complexity 25 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
gemini.setupUnhandledRejectionHandler (cyclomatic 25) packages/cli/src/gemini.tsx:176— gemini.setupUnhandledRejectionHandler has cyclomatic complexity 25 (threshold 15). Most of this is not in the body itself: 3 of the 25 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 225, 185, 300). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
AuthDialog.AuthDialog (cyclomatic 25) packages/cli/src/ui/auth/AuthDialog.tsx:36— AuthDialog.AuthDialog has cyclomatic complexity 25 (threshold 15). Most of this is not in the body itself: 9 of the 25 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 117, 97, 171, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useShellCompletion.resolvePathCompletions (cyclomatic 25) packages/cli/src/ui/hooks/useShellCompletion.ts:316— useShellCompletion.resolvePathCompletions has cyclomatic complexity 25 (threshold 15). Of this number, 23 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
MockAgentProtocol.send (cyclomatic 25) packages/core/src/agent/mock.ts:108— MockAgentProtocol.send has cyclomatic complexity 25 (threshold 15). Of this number, 24 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
HookRunner.executeCommandHook (cyclomatic 25) packages/core/src/hooks/hookRunner.ts:307— HookRunner.executeCommandHook has cyclomatic complexity 25 (threshold 15). Most of this is not in the body itself: 1 of the 25 points is its own statement and the rest belongs to 5 function literals inside it that branch (lines 434, 315, 385, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ToolRegistry.discoverAndRegisterToolsFromCommand (cyclomatic 25) packages/core/src/tools/tool-registry.ts:376— ToolRegistry.discoverAndRegisterToolsFromCommand has cyclomatic complexity 25 (threshold 15). Of this number, 19 points are the body's own statements and 6 belong to 3 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
oauth-flow.parseTokenEndpointResponse (cyclomatic 25) packages/core/src/utils/oauth-flow.ts:485— oauth-flow.parseTokenEndpointResponse has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
github.isGitHubWebhookPayload (cyclomatic 25) tools/caretaker-agent/cloudrun/ingestion-service/auth/github.ts:89— github.isGitHubWebhookPayload has cyclomatic complexity 25 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
github.checkForExtensionUpdate (cyclomatic 24) packages/cli/src/config/extensions/github.ts:171— github.checkForExtensionUpdate has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
AgentConfigDialog.AgentConfigDialog (cyclomatic 24) packages/cli/src/ui/components/AgentConfigDialog.tsx:190— AgentConfigDialog.AgentConfigDialog has cyclomatic complexity 24 (threshold 15). Most of this is not in the body itself: 2 of the 24 points are its own statements and the rest belongs to 8 function literals inside it that branch (lines 258, 335, 308, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
shellReducer.shellReducer (cyclomatic 24) packages/cli/src/ui/hooks/shellReducer.ts:55— shellReducer.shellReducer has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
CodeColorizer.colorizeCode (cyclomatic 24) packages/cli/src/ui/utils/CodeColorizer.tsx:155— CodeColorizer.colorizeCode has cyclomatic complexity 24 (threshold 15). Of this number, 17 points are the body's own statements and 7 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
AgentRegistry.registerRemoteAgent (cyclomatic 24) packages/core/src/agents/registry.ts:453— AgentRegistry.registerRemoteAgent has cyclomatic complexity 24 (threshold 15). Of this number, 23 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
ToolOutputMaskingService.mask (cyclomatic 24) packages/core/src/context/toolOutputMaskingService.ts:68— ToolOutputMaskingService.mask has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
mcp-client.createTransport (cyclomatic 24) packages/core/src/tools/mcp-client.ts:2265— mcp-client.createTransport has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
GrepToolInvocation.performRipgrepSearch (cyclomatic 24) packages/core/src/tools/ripGrep.ts:409— GrepToolInvocation.performRipgrepSearch has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
eval-report.summarizeReports (cyclomatic 24) scripts/utils/eval-report.ts:86— eval-report.summarizeReports has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
config.setTargetDir (cyclomatic 23) packages/a2a-server/src/config/config.ts:469— config.setTargetDir has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
HooksDialog.HooksDialog (cyclomatic 23) packages/cli/src/ui/components/HooksDialog.tsx:48— HooksDialog.HooksDialog has cyclomatic complexity 23 (threshold 15). Most of this is not in the body itself: 7 of the 23 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 176, 93, 66). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
TopicMessage.TopicMessage (cyclomatic 23) packages/cli/src/ui/components/messages/TopicMessage.tsx:32— TopicMessage.TopicMessage has cyclomatic complexity 23 (threshold 15). Of this number, 16 points are the body's own statements and 7 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
sessionUtils.getAllSessionFiles (cyclomatic 23) packages/cli/src/utils/sessionUtils.ts:237— sessionUtils.getAllSessionFiles has cyclomatic complexity 23 (threshold 15). Most of this is not in the body itself: 5 of the 23 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 253, 246, 310). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
sessionUtils.convertSessionToHistoryFormats (cyclomatic 23) packages/cli/src/utils/sessionUtils.ts:574— sessionUtils.convertSessionToHistoryFormats has cyclomatic complexity 23 (threshold 15). Of this number, 20 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
LocalAgentExecutor.create (cyclomatic 23) packages/core/src/agents/local-executor.ts:159— LocalAgentExecutor.create has cyclomatic complexity 23 (threshold 15). Most of this is not in the body itself: 11 of the 23 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 208, 192). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
LocalAgentExecutor.processFunctionCalls (cyclomatic 23) packages/core/src/agents/local-executor.ts:1105— LocalAgentExecutor.processFunctionCalls has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
memory.applyInboxPatch (cyclomatic 23) packages/core/src/commands/memory.ts:1189— memory.applyInboxPatch has cyclomatic complexity 23 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
ContextManager.renderHistory (cyclomatic 23) packages/core/src/context/contextManager.ts:90— ContextManager.renderHistory has cyclomatic complexity 23 (threshold 15). Of this number, 20 points are the body's own statements and 3 belong to 2 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
coreToolHookTriggers.executeToolWithHooks (cyclomatic 23) packages/core/src/core/coreToolHookTriggers.ts:68— coreToolHookTriggers.executeToolWithHooks has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Scheduler._processNextItem (cyclomatic 23) packages/core/src/scheduler/scheduler.ts:440— Scheduler._processNextItem has cyclomatic complexity 23 (threshold 15). Of this number, 21 points are the body's own statements and 2 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
trace.runInDevTraceSpan (cyclomatic 23) packages/core/src/telemetry/trace.ts:123— trace.runInDevTraceSpan has cyclomatic complexity 23 (threshold 15). Most of this is not in the body itself: 1 of the 23 points is its own statement and the rest belongs to 3 function literals inside it that branch (lines 152, 141, 224). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
EditToolInvocation.execute (cyclomatic 23) packages/core/src/tools/edit.ts:904— EditToolInvocation.execute has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Task.scheduleToolCalls (cyclomatic 22) packages/a2a-server/src/agent/task.ts:711— Task.scheduleToolCalls has cyclomatic complexity 22 (threshold 15). Of this number, 12 points are the body's own statements and 10 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
gemini.resolveSessionId (cyclomatic 22) packages/cli/src/gemini.tsx:319— gemini.resolveSessionId has cyclomatic complexity 22 (threshold 15). Of this number, 20 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
text-buffer.calculateLayout (cyclomatic 22) packages/cli/src/ui/components/shared/text-buffer.ts:1288— text-buffer.calculateLayout has cyclomatic complexity 22 (threshold 15). Most of this is not in the body itself: 6 of the 22 points are its own statements and the rest belongs to one function literal inside it that branches (line 1299). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
MouseContext.MouseProvider (cyclomatic 22) packages/cli/src/ui/contexts/MouseContext.tsx:63— MouseContext.MouseProvider has cyclomatic complexity 22 (threshold 15). Most of this is not in the body itself: 1 of the 22 points is its own statement and the rest belongs to 3 function literals inside it that branch (lines 102, 148, 95). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
SessionContext.areMetricsEqual (cyclomatic 22) packages/cli/src/ui/contexts/SessionContext.tsx:89— SessionContext.areMetricsEqual has cyclomatic complexity 22 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
browserAgentFactory.createBrowserAgentDefinition (cyclomatic 22) packages/core/src/agents/browser/browserAgentFactory.ts:68— browserAgentFactory.createBrowserAgentDefinition has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
loggingContentGenerator.estimateContextBreakdown (cyclomatic 22) packages/core/src/core/loggingContentGenerator.ts:79— loggingContentGenerator.estimateContextBreakdown has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
HookAggregator.mergeWithOrDecision (cyclomatic 22) packages/core/src/hooks/hookAggregator.ts:116— HookAggregator.mergeWithOrDecision has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
oauth-utils.validateOAuthEndpointUrl (cyclomatic 22) packages/core/src/mcp/oauth-utils.ts:62— oauth-utils.validateOAuthEndpointUrl has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
PromptProvider.getCoreSystemPrompt (cyclomatic 22) packages/core/src/prompts/promptProvider.ts:47— PromptProvider.getCoreSystemPrompt has cyclomatic complexity 22 (threshold 15). Of this number, 19 points are the body's own statements and 3 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ChatRecordingService.updateMessagesFromHistory (cyclomatic 22) packages/core/src/services/chatRecordingService.ts:953— ChatRecordingService.updateMessagesFromHistory has cyclomatic complexity 22 (threshold 15). Of this number, 16 points are the body's own statements and 6 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
sessionSummaryUtils.getPreviousSession (cyclomatic 22) packages/core/src/services/sessionSummaryUtils.ts:460— sessionSummaryUtils.getPreviousSession has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
GrepToolInvocation.execute (cyclomatic 22) packages/core/src/tools/grep.ts:146— GrepToolInvocation.execute has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
fileUtils.detectBOM (cyclomatic 22) packages/core/src/utils/fileUtils.ts:78— fileUtils.detectBOM has cyclomatic complexity 22 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
getFolderStructure.readFullStructure (cyclomatic 22) packages/core/src/utils/getFolderStructure.ts:71— getFolderStructure.readFullStructure has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
DevTools.start (cyclomatic 22) packages/devtools/src/index.ts:161— DevTools.start has cyclomatic complexity 22 (threshold 15). Most of this is not in the body itself: 1 of the 22 points is its own statement and the rest belongs to 4 function literals inside it that branch (lines 167, 259, 185, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
local_telemetry.main (cyclomatic 22) scripts/local_telemetry.js:71— local_telemetry.main has cyclomatic complexity 22 (threshold 15). Of this number, 21 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
create-patch-pr.main (cyclomatic 22) scripts/releasing/create-patch-pr.js:13— create-patch-pr.main has cyclomatic complexity 22 (threshold 15). Of this number, 19 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
sync_project_dry_run.run (cyclomatic 22) scripts/sync_project_dry_run.js:149— sync_project_dry_run.run has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
summary._write_markdown (cyclomatic 22) tools/caretaker-agent/evals/triage/helpers/summary.py:70— summary._write_markdown has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
config.loadConfig (cyclomatic 21) packages/a2a-server/src/config/config.ts:251— config.loadConfig has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
AppHeader.AppHeader (cyclomatic 21) packages/cli/src/ui/components/AppHeader.tsx:59— AppHeader.AppHeader has cyclomatic complexity 21 (threshold 15). Of this number, 16 points are the body's own statements and 5 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
ToolGroupDisplay.ToolGroupDisplay (cyclomatic 21) packages/cli/src/ui/components/messages/ToolGroupDisplay.tsx:25— ToolGroupDisplay.ToolGroupDisplay has cyclomatic complexity 21 (threshold 15). Of this number, 14 points are the body's own statements and 7 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Scrollable.Scrollable (cyclomatic 21) packages/cli/src/ui/components/shared/Scrollable.tsx:41— Scrollable.Scrollable has cyclomatic complexity 21 (threshold 15). Most of this is not in the body itself: 2 of the 21 points are its own statements and the rest belongs to 9 function literals inside it that branch (lines 189, 145, 76, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useRunEventNotifications.useRunEventNotifications (cyclomatic 21) packages/cli/src/ui/hooks/useRunEventNotifications.ts:39— useRunEventNotifications.useRunEventNotifications has cyclomatic complexity 21 (threshold 15). Most of this is not in the body itself: 1 of the 21 points is its own statement and the rest belongs to 2 function literals inside it that branch (lines 81, 140). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
highlight.parseInputForHighlighting (cyclomatic 21) packages/cli/src/ui/utils/highlight.ts:36— highlight.parseInputForHighlighting has cyclomatic complexity 21 (threshold 15). Of this number, 13 points are the body's own statements and 8 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
memory.applyMemoryPatchFile (cyclomatic 21) packages/core/src/commands/memory.ts:782— memory.applyMemoryPatchFile has cyclomatic complexity 21 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
ContextCompressionService.applyCompressionDecision (cyclomatic 21) packages/core/src/context/contextCompressionService.ts:332— ContextCompressionService.applyCompressionDecision has cyclomatic complexity 21 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
contentGenerator.createContentGeneratorConfig (cyclomatic 21) packages/core/src/core/contentGenerator.ts:141— contentGenerator.createContentGeneratorConfig has cyclomatic complexity 21 (threshold 15). Of this number, 19 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
ToolExecutor.execute (cyclomatic 21) packages/core/src/scheduler/tool-executor.ts:61— ToolExecutor.execute has cyclomatic complexity 21 (threshold 15). Most of this is not in the body itself: 6 of the 21 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 96, 102). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
LSToolInvocation.execute (cyclomatic 21) packages/core/src/tools/ls.ts:159— LSToolInvocation.execute has cyclomatic complexity 21 (threshold 15). Of this number, 15 points are the body's own statements and 6 belong to 3 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
tools.hasCycleInSchema (cyclomatic 21) packages/core/src/tools/tools.ts:798— tools.hasCycleInSchema has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
RecursiveFileSearch.search (cyclomatic 21) packages/core/src/utils/filesearch/fileSearch.ts:259— RecursiveFileSearch.search has cyclomatic complexity 21 (threshold 15). Of this number, 19 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
app.createApp (cyclomatic 20) packages/a2a-server/src/http/app.ts:197— app.createApp has cyclomatic complexity 20 (threshold 15). Most of this is not in the body itself: 6 of the 20 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 356, 284, 385, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
install.handleInstall (cyclomatic 20) packages/cli/src/commands/extensions/install.ts:43— install.handleInstall has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
github.downloadFromGitHubRelease (cyclomatic 20) packages/cli/src/config/extensions/github.ts:320— github.downloadFromGitHubRelease has cyclomatic complexity 20 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
ShellProcessor.processString (cyclomatic 20) packages/cli/src/services/prompt-processors/shellProcessor.ts:65— ShellProcessor.processString has cyclomatic complexity 20 (threshold 15). Of this number, 19 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
SuggestionsDisplay.SuggestionsDisplay (cyclomatic 20) packages/cli/src/ui/components/SuggestionsDisplay.tsx:38— SuggestionsDisplay.SuggestionsDisplay has cyclomatic complexity 20 (threshold 15). Most of this is not in the body itself: 7 of the 20 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 86, 73). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
SubagentProgressDisplay.formatToolArgs (cyclomatic 20) packages/cli/src/ui/components/messages/SubagentProgressDisplay.tsx:27— SubagentProgressDisplay.formatToolArgs has cyclomatic complexity 20 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
ExpandableText._ExpandableText (cyclomatic 20) packages/cli/src/ui/components/shared/ExpandableText.tsx:23— ExpandableText._ExpandableText has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ScrollableList.ScrollableList (cyclomatic 20) packages/cli/src/ui/components/shared/ScrollableList.tsx:46— ScrollableList.ScrollableList has cyclomatic complexity 20 (threshold 15). Most of this is not in the body itself: 1 of the 20 points is its own statement and the rest belongs to 4 function literals inside it that branch (lines 200, 113, 165, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
SearchableList.SearchableList (cyclomatic 20) packages/cli/src/ui/components/shared/SearchableList.tsx:77— SearchableList.SearchableList has cyclomatic complexity 20 (threshold 15). Of this number, 12 points are the body's own statements and 8 belong to 4 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
useAnimatedScrollbar.useAnimatedScrollbar (cyclomatic 20) packages/cli/src/ui/hooks/useAnimatedScrollbar.ts:12— useAnimatedScrollbar.useAnimatedScrollbar has cyclomatic complexity 20 (threshold 15). Most of this is not in the body itself: 1 of the 20 points is its own statement and the rest belongs to 5 function literals inside it that branch (lines 39, 110, 24, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useComposerStatus.useComposerStatus (cyclomatic 20) packages/cli/src/ui/hooks/useComposerStatus.ts:20— useComposerStatus.useComposerStatus has cyclomatic complexity 20 (threshold 15). Of this number, 13 points are the body's own statements and 7 belong to one function literal inside it that branches. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
TerminalCapabilityManager.detectCapabilities (cyclomatic 20) packages/cli/src/ui/utils/terminalCapabilityManager.ts:105— TerminalCapabilityManager.detectCapabilities has cyclomatic complexity 20 (threshold 15). Most of this is not in the body itself: 4 of the 20 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 151, 120, 135). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
deepMerge.mergeRecursively (cyclomatic 20) packages/cli/src/utils/deepMerge.ts:24— deepMerge.mergeRecursively has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
A2AResultReassembler.update (cyclomatic 20) packages/core/src/agents/a2aUtils.ts:35— A2AResultReassembler.update has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
AgentRegistry.loadAgents (cyclomatic 20) packages/core/src/agents/registry.ts:160— AgentRegistry.loadAgents has cyclomatic complexity 20 (threshold 15). Of this number, 14 points are the body's own statements and 6 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Config.constructor (cyclomatic 20) packages/core/src/config/config.ts:993— Config.constructor has cyclomatic complexity 20 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
geminiChat.stripToolCallIdPrefixes (cyclomatic 20) packages/core/src/core/geminiChat.ts:1756— geminiChat.stripToolCallIdPrefixes has cyclomatic complexity 20 (threshold 15). Most of this is not in the body itself: 1 of the 20 points is its own statement and the rest belongs to 5 function literals inside it that branch (lines 1759, 1795, 1787, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
sessionSummaryUtils.generateAndSaveSummary (cyclomatic 20) packages/core/src/services/sessionSummaryUtils.ts:324— sessionSummaryUtils.generateAndSaveSummary has cyclomatic complexity 20 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
terminalSerializer.serializeTerminalToObject (cyclomatic 20) packages/core/src/utils/terminalSerializer.ts:160— terminalSerializer.serializeTerminalToObject has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
changed_prompt.main (cyclomatic 20) scripts/changed_prompt.js:23— changed_prompt.main has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
cleanup-branches.main (cyclomatic 20) scripts/cleanup-branches.ts:18— cleanup-branches.main has cyclomatic complexity 20 (threshold 15). Of this number, 15 points are the body's own statements and 5 belong to 2 function literals inside it that branch. To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
eval-inventory.formatInventoryReport (cyclomatic 20) scripts/utils/eval-inventory.ts:94— eval-inventory.formatInventoryReport has cyclomatic complexity 20 (threshold 15). Of this number, 17 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline.
acpUtils.toPermissionOptions (cyclomatic 19) packages/cli/src/acp/acpUtils.ts:98— acpUtils.toPermissionOptions has cyclomatic complexity 19 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
mcpCommand.listAction (cyclomatic 19) packages/cli/src/ui/commands/mcpCommand.ts:177— mcpCommand.listAction has cyclomatic complexity 19 (threshold 15). Of this number, 18 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
FolderTrustDialog.FolderTrustDialog (cyclomatic 19) packages/cli/src/ui/components/FolderTrustDialog.tsx:45— FolderTrustDialog.FolderTrustDialog has cyclomatic complexity 19 (threshold 15). Of this number, 14 points are the body's own statements and 5 belong to 4 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
SubagentProgressDisplay.SubagentProgressDisplay (cyclomatic 19) packages/cli/src/ui/components/messages/SubagentProgressDisplay.tsx:62— SubagentProgressDisplay.SubagentProgressDisplay has cyclomatic complexity 19 (threshold 15). Most of this is not in the body itself: 8 of the 19 points are its own statements and the rest belongs to one function literal inside it that branches (line 91). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
useExtensionUpdates.useExtensionUpdates (cyclomatic 19) packages/cli/src/ui/hooks/useExtensionUpdates.ts:83— useExtensionUpdates.useExtensionUpdates has cyclomatic complexity 19 (threshold 15). Most of this is not in the body itself: 1 of the 19 points is its own statement and the rest belongs to 6 function literals inside it that branch (lines 118, 95, 94, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
CodeAssistServer.generateContentStream (cyclomatic 19) packages/core/src/code_assist/server.ts:93— CodeAssistServer.generateContentStream has cyclomatic complexity 19 (threshold 15). Most of this is not in the body itself: 6 of the 19 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 134, 172). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
setup._doSetupUser (cyclomatic 19) packages/core/src/code_assist/setup.ts:153— setup._doSetupUser has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ContextManager.evaluateTriggers (cyclomatic 19) packages/core/src/context/contextManager.ts:308— ContextManager.evaluateTriggers has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ContextWorkingBufferImpl.applyProcessorResult (cyclomatic 19) packages/core/src/context/pipeline/contextWorkingBuffer.ts:61— ContextWorkingBufferImpl.applyProcessorResult has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
stateSnapshotProcessor.createStateSnapshotProcessor (cyclomatic 19) packages/core/src/context/processors/stateSnapshotProcessor.ts:46— stateSnapshotProcessor.createStateSnapshotProcessor has cyclomatic complexity 19 (threshold 15). Most of this is not in the body itself: 1 of the 19 points is its own statement and the rest belongs to one function literal inside it that branches (line 56). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
HookTranslatorGenAIv1.fromHookLLMRequest (cyclomatic 19) packages/core/src/hooks/hookTranslator.ts:225— HookTranslatorGenAIv1.fromHookLLMRequest has cyclomatic complexity 19 (threshold 15). Of this number, 15 points are the body's own statements and 4 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
stable-stringify.stableStringify (cyclomatic 19) packages/core/src/policy/stable-stringify.ts:59— stable-stringify.stableStringify has cyclomatic complexity 19 (threshold 15). Most of this is not in the body itself: 1 of the 19 points is its own statement and the rest belongs to 2 function literals inside it that branch (lines 60, 106). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
memoryService.buildExistingSkillsSummary (cyclomatic 19) packages/core/src/services/memoryService.ts:729— memoryService.buildExistingSkillsSummary has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ShellExecutionService.closeOrphanSlaveFd (cyclomatic 19) packages/core/src/services/shellExecutionService.ts:1009— ShellExecutionService.closeOrphanSlaveFd has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
mcp-client.discoverTools (cyclomatic 19) packages/core/src/tools/mcp-client.ts:1295— mcp-client.discoverTools has cyclomatic complexity 19 (threshold 15). Of this number, 10 points are the body's own statements and 9 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
WebFetchToolInvocation.executeExperimental (cyclomatic 19) packages/core/src/tools/web-fetch.ts:595— WebFetchToolInvocation.executeExperimental has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
shell-utils.extractNameFromNode (cyclomatic 19) packages/core/src/utils/shell-utils.ts:332— shell-utils.extractNameFromNode has cyclomatic complexity 19 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
eval-coverage.computeCoverage (cyclomatic 19) scripts/utils/eval-coverage.ts:66— eval-coverage.computeCoverage has cyclomatic complexity 19 (threshold 15). Of this number, 15 points are the body's own statements and 4 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
list.listMcpServers (cyclomatic 18) packages/cli/src/commands/mcp/list.ts:194— list.listMcpServers has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
settings.migrateExperimentalSettings (cyclomatic 18) packages/cli/src/config/settings.ts:1273— settings.migrateExperimentalSettings has cyclomatic complexity 18 (threshold 15). Most of this is not in the body itself: 5 of the 18 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 1308, 1368, 1294, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
interactiveCli.startInteractiveUI (cyclomatic 18) packages/cli/src/interactiveCli.tsx:56— interactiveCli.startInteractiveUI has cyclomatic complexity 18 (threshold 15). Of this number, 15 points are the body's own statements and 3 belong to 3 function literals inside it that branch. To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
StatsDisplay.StatsDisplay (cyclomatic 18) packages/cli/src/ui/components/StatsDisplay.tsx:242— StatsDisplay.StatsDisplay has cyclomatic complexity 18 (threshold 15). Of this number, 16 points are the body's own statements and 2 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
useApprovalModeIndicator.useApprovalModeIndicator (cyclomatic 18) packages/cli/src/ui/hooks/useApprovalModeIndicator.ts:26— useApprovalModeIndicator.useApprovalModeIndicator has cyclomatic complexity 18 (threshold 15). Most of this is not in the body itself: 1 of the 18 points is its own statement and the rest belongs to one function literal inside it that branches (line 42). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
useSnowfall.useSnowfall (cyclomatic 18) packages/cli/src/ui/hooks/useSnowfall.ts:60— useSnowfall.useSnowfall has cyclomatic complexity 18 (threshold 15). Most of this is not in the body itself: 8 of the 18 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 151, 113, 69, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useTabbedNavigation.tabbedNavigationReducer (cyclomatic 18) packages/cli/src/ui/hooks/useTabbedNavigation.ts:69— useTabbedNavigation.tabbedNavigationReducer has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
TableRenderer.TableRenderer (cyclomatic 18) packages/cli/src/ui/utils/TableRenderer.tsx:66— TableRenderer.TableRenderer has cyclomatic complexity 18 (threshold 15). Most of this is not in the body itself: 1 of the 18 points is its own statement and the rest belongs to 10 function literals inside it that branch (lines 95, 183, 289, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
formatters.formatResetTime (cyclomatic 18) packages/cli/src/ui/utils/formatters.ts:101— formatters.formatResetTime has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
activityLogger.callHttpRequest (cyclomatic 18) packages/cli/src/utils/activityLogger.ts:54— activityLogger.callHttpRequest has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top. This is NOT this file's highest cyclomatic complexity: ActivityLogger.patchGlobalFetch (cyclomatic 23) is higher and carries no row of its own — it was excluded as a flat dispatcher (a long switch/match over independent cases: many branches, almost no nesting), which this dimension does not treat as a refactor obligation. It is named here so the ranking you see in this file is not mistaken for the whole of it; the excluded method is counted neither in this dimension's figures nor in its score.
AnalyzeScreenshotInvocation.execute (cyclomatic 18) packages/core/src/agents/browser/analyzeScreenshot.ts:84— AnalyzeScreenshotInvocation.execute has cyclomatic complexity 18 (threshold 15). Of this number, 16 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
RemoteSessionInvocation.execute (cyclomatic 18) packages/core/src/agents/remote-session-invocation.ts:117— RemoteSessionInvocation.execute has cyclomatic complexity 18 (threshold 15). Of this number, 15 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ChatCompressionService.compress (cyclomatic 18) packages/core/src/context/chatCompressionService.ts:240— ChatCompressionService.compress has cyclomatic complexity 18 (threshold 15). Of this number, 14 points are the body's own statements and 4 belong to 3 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
ContextGraphBuilder.processHistory (cyclomatic 18) packages/core/src/context/graph/toGraph.ts:190— ContextGraphBuilder.processHistory has cyclomatic complexity 18 (threshold 15). Of this number, 17 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
rollingSummaryProcessor.createRollingSummaryProcessor (cyclomatic 18) packages/core/src/context/processors/rollingSummaryProcessor.ts:43— rollingSummaryProcessor.createRollingSummaryProcessor has cyclomatic complexity 18 (threshold 15). Most of this is not in the body itself: 1 of the 18 points is its own statement and the rest belongs to 2 function literals inside it that branch (lines 74, 48). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ide-installer.findCommand (cyclomatic 18) REDACTED:24— ide-installer.findCommand has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
PolicyEngine.applyShellHeuristics (cyclomatic 18) packages/core/src/policy/policy-engine.ts:359— PolicyEngine.applyShellHeuristics has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
Scheduler._execute (cyclomatic 18) packages/core/src/scheduler/scheduler.ts:730— Scheduler._execute has cyclomatic complexity 18 (threshold 15). Of this number, 16 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
GrepToolInvocation.execute (cyclomatic 18) packages/core/src/tools/ripGrep.ts:182— GrepToolInvocation.execute has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
RipGrepTool.validateToolParamValues (cyclomatic 18) packages/core/src/tools/ripGrep.ts:659— RipGrepTool.validateToolParamValues has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ShellToolInvocation.getConfirmationDetails (cyclomatic 18) packages/core/src/tools/shell.ts:435— ShellToolInvocation.getConfirmationDetails has cyclomatic complexity 18 (threshold 15). Of this number, 16 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
atCommandUtils.resolveAtCommandPath (cyclomatic 18) packages/core/src/utils/atCommandUtils.ts:35— atCommandUtils.resolveAtCommandPath has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
RecursiveFileSearch.handleFileWatcherEvent (cyclomatic 18) packages/core/src/utils/filesearch/fileSearch.ts:192— RecursiveFileSearch.handleFileWatcherEvent has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
memoryDiscovery.loadJitSubdirectoryMemory (cyclomatic 18) packages/core/src/utils/memoryDiscovery.ts:512— memoryDiscovery.loadJitSubdirectoryMemory has cyclomatic complexity 18 (threshold 15). Of this number, 17 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
oauth-flow.startCallbackServer (cyclomatic 18) packages/core/src/utils/oauth-flow.ts:192— oauth-flow.startCallbackServer has cyclomatic complexity 18 (threshold 15). Most of this is not in the body itself: 1 of the 18 points is its own statement and the rest belongs to 2 function literals inside it that branch (lines 214, 210). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
sessionUtils.ensureStableToolIds (cyclomatic 18) packages/core/src/utils/sessionUtils.ts:21— sessionUtils.ensureStableToolIds has cyclomatic complexity 18 (threshold 15). Of this number, 14 points are the body's own statements and 4 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
shell-utils.execStreaming (cyclomatic 18) packages/core/src/utils/shell-utils.ts:953— shell-utils.execStreaming has cyclomatic complexity 18 (threshold 15). Most of this is not in the body itself: 8 of the 18 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 1035, 989, 1001). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
shell-utils.detectBashSubstitution (cyclomatic 18) packages/core/src/utils/shell-utils.ts:1095— shell-utils.detectBashSubstitution has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
shell-utils.detectPowerShellSubstitution (cyclomatic 18) packages/core/src/utils/shell-utils.ts:1148— shell-utils.detectPowerShellSubstitution has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
get-release-version.detectRollbackAndGetBaseline (cyclomatic 18) scripts/get-release-version.js:124— get-release-version.detectRollbackAndGetBaseline has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
AgentRunner.run_agent (cyclomatic 18) tools/caretaker-agent/cloudrun/pr-generator/workflow/agent_runner.py:123— AgentRunner.run_agent has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
index.run (cyclomatic 17) packages/cli/index.ts:54— index.run has cyclomatic complexity 17 (threshold 15). Of this number, 9 points are the body's own statements and 8 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
extensionSettings.maybePromptForSettings (cyclomatic 17) packages/cli/src/config/extensions/extensionSettings.ts:62— extensionSettings.maybePromptForSettings has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
settings._doLoadSettings (cyclomatic 17) packages/cli/src/config/settings.ts:769— settings._doLoadSettings has cyclomatic complexity 17 (threshold 15). Most of this is not in the body itself: 8 of the 17 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 781, 851). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
BuiltinCommandLoader.loadCommands (cyclomatic 17) packages/cli/src/services/BuiltinCommandLoader.ts:83— BuiltinCommandLoader.loadCommands has cyclomatic complexity 17 (threshold 15). Of this number, 13 points are the body's own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
FileCommandLoader.parseAndAdaptFile (cyclomatic 17) packages/cli/src/services/FileCommandLoader.ts:257— FileCommandLoader.parseAndAdaptFile has cyclomatic complexity 17 (threshold 15). Of this number, 12 points are the body's own statements and 5 belong to 2 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
mcpCommand.handleEnableDisable (cyclomatic 17) packages/cli/src/ui/commands/mcpCommand.ts:396— mcpCommand.handleEnableDisable has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
ColorsDisplay.ColorsDisplay (cyclomatic 17) packages/cli/src/ui/components/ColorsDisplay.tsx:80— ColorsDisplay.ColorsDisplay has cyclomatic complexity 17 (threshold 15). Most of this is not in the body itself: 4 of the 17 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 100, 193). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
EditorSettingsDialog.EditorSettingsDialog (cyclomatic 17) packages/cli/src/ui/components/EditorSettingsDialog.tsx:38— EditorSettingsDialog.EditorSettingsDialog has cyclomatic complexity 17 (threshold 15). Of this number, 11 points are the body's own statements and 6 belong to 4 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
ToolConfirmationQueue.ToolConfirmationQueue (cyclomatic 17) packages/cli/src/ui/components/ToolConfirmationQueue.tsx:52— ToolConfirmationQueue.ToolConfirmationQueue has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
ValidationDialog.ValidationDialog (cyclomatic 17) packages/cli/src/ui/components/ValidationDialog.tsx:31— ValidationDialog.ValidationDialog has cyclomatic complexity 17 (threshold 15). Most of this is not in the body itself: 7 of the 17 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 81, 55, 70). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
EnumSelector.EnumSelector (cyclomatic 17) packages/cli/src/ui/components/shared/EnumSelector.tsx:23— EnumSelector.EnumSelector has cyclomatic complexity 17 (threshold 15). Of this number, 11 points are the body's own statements and 6 belong to 2 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
rewindFileOps.revertFileChanges (cyclomatic 17) packages/cli/src/ui/utils/rewindFileOps.ts:149— rewindFileOps.revertFileChanges has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
commentJson.preserveCommentsOnPropertyDeletion (cyclomatic 17) packages/cli/src/utils/commentJson.ts:57— commentJson.preserveCommentsOnPropertyDeletion has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
agentLoader.markdownToAgentDefinition (cyclomatic 17) packages/core/src/agents/agentLoader.ts:497— agentLoader.markdownToAgentDefinition has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
handler.handleFallback (cyclomatic 17) packages/core/src/fallback/handler.ts:26— handler.handleFallback has cyclomatic complexity 17 (threshold 15). Of this number, 16 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ModelConfigService.getAvailableModelOptions (cyclomatic 17) packages/core/src/services/modelConfigService.ts:154— ModelConfigService.getAvailableModelOptions has cyclomatic complexity 17 (threshold 15). Most of this is not in the body itself: 1 of the 17 points is its own statement and the rest belongs to 4 function literals inside it that branch (lines 193, 166, 172, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ShellToolInvocation.simplifyPaths (cyclomatic 17) packages/core/src/tools/shell.ts:175— ShellToolInvocation.simplifyPaths has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
WebFetchToolInvocation.execute (cyclomatic 17) packages/core/src/tools/web-fetch.ts:771— WebFetchToolInvocation.execute has cyclomatic complexity 17 (threshold 15). Of this number, 13 points are the body's own statements and 4 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
getFolderStructure.formatStructure (cyclomatic 17) packages/core/src/utils/getFolderStructure.ts:233— getFolderStructure.formatStructure has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
memoryDiscovery.findProjectRoot (cyclomatic 17) packages/core/src/utils/memoryDiscovery.ts:150— memoryDiscovery.findProjectRoot has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
extension.activate (cyclomatic 17) packages/vscode-ide-companion/src/extension.ts:110— extension.activate has cyclomatic complexity 17 (threshold 15). Most of this is not in the body itself: 8 of the 17 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 195, 140, 126, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
telemetry_utils.manageTelemetrySettings (cyclomatic 17) scripts/telemetry_utils.js:315— telemetry_utils.manageTelemetrySettings has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
eval-coverage.formatCoverageReport (cyclomatic 17) scripts/utils/eval-coverage.ts:196— eval-coverage.formatCoverageReport has cyclomatic complexity 17 (threshold 15). Of this number, 15 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
main.main (cyclomatic 17) tools/caretaker-agent/cloudrun/triage-worker/main.py:33— main.main has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
GeminiSandbox.ApplyBulkAcls (cyclomatic 16) packages/core/src/sandbox/windows/GeminiSandbox.cs:422— GeminiSandbox.ApplyBulkAcls has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Session.streamHistory (cyclomatic 16) packages/cli/src/acp/acpSession.ts:241— Session.streamHistory has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
logs.readLastLines (cyclomatic 16) packages/cli/src/commands/gemma/logs.ts:14— logs.readLastLines has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
settings-validation.buildZodSchemaFromJsonSchema (cyclomatic 16) packages/cli/src/config/settings-validation.ts:17— settings-validation.buildZodSchemaFromJsonSchema has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
settings.loadEnvironment (cyclomatic 16) packages/cli/src/config/settings.ts:655— settings.loadEnvironment has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
useAuth.useAuthCommand (cyclomatic 16) packages/cli/src/ui/auth/useAuth.ts:41— useAuth.useAuthCommand has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 2 of the 16 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 89, 59, 68, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
extensionsCommand.restartAction (cyclomatic 16) packages/cli/src/ui/commands/extensionsCommand.ts:155— extensionsCommand.restartAction has cyclomatic complexity 16 (threshold 15). Of this number, 15 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
SessionBrowser.SessionItem (cyclomatic 16) packages/cli/src/ui/components/SessionBrowser.tsx:198— SessionBrowser.SessionItem has cyclomatic complexity 16 (threshold 15). Of this number, 14 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
VoiceModelDialog.VoiceModelDialog (cyclomatic 16) packages/cli/src/ui/components/VoiceModelDialog.tsx:52— VoiceModelDialog.VoiceModelDialog has cyclomatic complexity 16 (threshold 15). Of this number, 8 points are the body's own statements and 8 belong to 5 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ShellToolMessage.ShellToolMessage (cyclomatic 16) packages/cli/src/ui/components/messages/ShellToolMessage.tsx:44— ShellToolMessage.ShellToolMessage has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 7 of the 16 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 100, 129, 146). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
SlicingMaxSizedBox.SlicingMaxSizedBox (cyclomatic 16) packages/cli/src/ui/components/shared/SlicingMaxSizedBox.tsx:27— SlicingMaxSizedBox.SlicingMaxSizedBox has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 1 of the 16 points is its own statement and the rest belongs to one function literal inside it that branches (line 34). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
ExtensionRegistryView.ExtensionRegistryView (cyclomatic 16) packages/cli/src/ui/components/views/ExtensionRegistryView.tsx:44— ExtensionRegistryView.ExtensionRegistryView has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 6 of the 16 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 139, 72, 205). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
KeypressContext.KeypressProvider (cyclomatic 16) packages/cli/src/ui/contexts/KeypressContext.tsx:769— KeypressContext.KeypressProvider has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 1 of the 16 points is its own statement and the rest belongs to 6 function literals inside it that branch (lines 834, 790, 855, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
SessionContext.areModelMetricsEqual (cyclomatic 16) packages/cli/src/ui/contexts/SessionContext.tsx:31— SessionContext.areModelMetricsEqual has cyclomatic complexity 16 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
useHistoryManager.useHistory (cyclomatic 16) packages/cli/src/ui/hooks/useHistoryManager.ts:37— useHistoryManager.useHistory has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 1 of the 16 points is its own statement and the rest belongs to 3 function literals inside it that branch (lines 65, 74, 144). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useIncludeDirsTrust.useIncludeDirsTrust (cyclomatic 16) packages/cli/src/ui/hooks/useIncludeDirsTrust.tsx:54— useIncludeDirsTrust.useIncludeDirsTrust has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 1 of the 16 points is its own statement and the rest belongs to one function literal inside it that branches (line 62). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
useInlineEditBuffer.editBufferReducer (cyclomatic 16) packages/cli/src/ui/hooks/useInlineEditBuffer.ts:33— useInlineEditBuffer.editBufferReducer has cyclomatic complexity 16 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
useShellCompletion.scanPathExecutables (cyclomatic 16) packages/cli/src/ui/hooks/useShellCompletion.ts:183— useShellCompletion.scanPathExecutables has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 7 of the 16 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 262, 254). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useTabbedNavigation.useTabbedNavigation (cyclomatic 16) packages/cli/src/ui/hooks/useTabbedNavigation.ts:141— useTabbedNavigation.useTabbedNavigation has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 2 of the 16 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 205, 163, 179, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
clipboardUtils.saveClipboardImage (cyclomatic 16) packages/cli/src/ui/utils/clipboardUtils.ts:272— clipboardUtils.saveClipboardImage has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
sandboxUtils.entrypoint (cyclomatic 16) packages/cli/src/utils/sandboxUtils.ts:375— sandboxUtils.entrypoint has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
skillUtils.installSkill (cyclomatic 16) packages/cli/src/utils/skillUtils.ts:93— skillUtils.installSkill has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
agentLoader.guessIntendedKind (cyclomatic 16) packages/core/src/agents/agentLoader.ts:265— agentLoader.guessIntendedKind has cyclomatic complexity 16 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
McpToolInvocation.execute (cyclomatic 16) packages/core/src/agents/browser/mcpToolWrapper.ts:121— McpToolInvocation.execute has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
admin_controls.sanitizeAdminSettings (cyclomatic 16) packages/core/src/code_assist/admin/admin_controls.ts:22— admin_controls.sanitizeAdminSettings has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Config.refreshUserQuota (cyclomatic 16) packages/core/src/config/config.ts:2305— Config.refreshUserQuota has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
toGraph.getStableId (cyclomatic 16) packages/core/src/context/graph/toGraph.ts:97— toGraph.getStableId has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
nodeDistillationProcessor.createNodeDistillationProcessor (cyclomatic 16) packages/core/src/context/processors/nodeDistillationProcessor.ts:32— nodeDistillationProcessor.createNodeDistillationProcessor has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 1 of the 16 points is its own statement and the rest belongs to 2 function literals inside it that branch (lines 75, 37). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ToolOutputMaskingService.formatShellPreview (cyclomatic 16) packages/core/src/context/toolOutputMaskingService.ts:292— ToolOutputMaskingService.formatShellPreview has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
PolicyEngine.constructor (cyclomatic 16) packages/core/src/policy/policy-engine.ts:254— PolicyEngine.constructor has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
CheckerRunner.executeCheckerProcess (cyclomatic 16) packages/core/src/safety/checker-runner.ts:163— CheckerRunner.executeCheckerProcess has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 1 of the 16 points is its own statement and the rest belongs to 4 function literals inside it that branch (lines 168, 213, 255, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ChatRecordingService.recordToolCalls (cyclomatic 16) packages/core/src/services/chatRecordingService.ts:775— ChatRecordingService.recordToolCalls has cyclomatic complexity 16 (threshold 15). Of this number, 12 points are the body's own statements and 4 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
chatRecordingService.parseLegacyRecordFallback (cyclomatic 16) packages/core/src/services/chatRecordingService.ts:1041— chatRecordingService.parseLegacyRecordFallback has cyclomatic complexity 16 (threshold 15). Of this number, 12 points are the body's own statements and 4 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
sessionScratchpadUtils.tokenizeShellCommand (cyclomatic 16) packages/core/src/services/sessionScratchpadUtils.ts:15— sessionScratchpadUtils.tokenizeShellCommand has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ShellExecutionService.resizePty (cyclomatic 16) packages/core/src/services/shellExecutionService.ts:1875— ShellExecutionService.resizePty has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
validate_skill.validateSkill (cyclomatic 16) packages/core/src/skills/builtin/skill-creator/scripts/validate_skill.cjs:15— validate_skill.validateSkill has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
package_skill.main (cyclomatic 16) packages/core/src/skills/builtin/skill-creator/scripts/package_skill.cjs:20— package_skill.main has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
EditTool.validateToolParamValues (cyclomatic 16) packages/core/src/tools/edit.ts:1138— EditTool.validateToolParamValues has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
EditTool.getModifyContext (cyclomatic 16) packages/core/src/tools/edit.ts:1220— EditTool.getModifyContext has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 1 of the 16 points is its own statement and the rest belongs to 3 function literals inside it that branch (lines 1221, 1286, 1275). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
edit.calculateFuzzyReplacement (cyclomatic 16) packages/core/src/tools/edit.ts:1366— edit.calculateFuzzyReplacement has cyclomatic complexity 16 (threshold 15). Of this number, 15 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
GlobToolInvocation.execute (cyclomatic 16) packages/core/src/tools/glob.ts:137— GlobToolInvocation.execute has cyclomatic complexity 16 (threshold 15). Of this number, 15 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
grep-utils.enrichWithAutoContext (cyclomatic 16) packages/core/src/tools/grep-utils.ts:66— grep-utils.enrichWithAutoContext has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
GrepTool.validateToolParamValues (cyclomatic 16) packages/core/src/tools/grep.ts:711— GrepTool.validateToolParamValues has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
McpClient.refreshTools (cyclomatic 16) packages/core/src/tools/mcp-client.ts:696— McpClient.refreshTools has cyclomatic complexity 16 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
ReadMcpResourceToolInvocation.execute (cyclomatic 16) packages/core/src/tools/read-mcp-resource.ts:81— ReadMcpResourceToolInvocation.execute has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
WebSearchToolInvocation.execute (cyclomatic 16) packages/core/src/tools/web-search.ts:88— WebSearchToolInvocation.execute has cyclomatic complexity 16 (threshold 15). Of this number, 12 points are the body's own statements and 4 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
fetch.safeLookup (cyclomatic 16) packages/core/src/utils/fetch.ts:57— fetch.safeLookup has cyclomatic complexity 16 (threshold 15). Of this number, 8 points are the body's own statements and 8 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
markdownUtils.jsonToMarkdown (cyclomatic 16) packages/core/src/utils/markdownUtils.ts:23— markdownUtils.jsonToMarkdown has cyclomatic complexity 16 (threshold 15). Of this number, 9 points are the body's own statements and 7 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
partUtils.partToString (cyclomatic 16) packages/core/src/utils/partUtils.ts:18— partUtils.partToString has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
retry.isRetryableError (cyclomatic 16) packages/core/src/utils/retry.ts:170— retry.isRetryableError has cyclomatic complexity 16 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
security.parseWindowsBatchSecurityOutput (cyclomatic 16) packages/core/src/utils/security.ts:181— security.parseWindowsBatchSecurityOutput has cyclomatic complexity 16 (threshold 15). Of this number, 15 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
sessionOperations.deleteSessionFileAndArtifacts (cyclomatic 16) packages/core/src/utils/sessionOperations.ts:215— sessionOperations.deleteSessionFileAndArtifacts has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
App.CodeView (cyclomatic 16) packages/devtools/client/src/App.tsx:1829— App.CodeView has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 6 of the 16 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 1846, 1919, 1835). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
github.handleEgressEvent (cyclomatic 16) tools/caretaker-agent/cloudrun/egress-service/src/actions/github.ts:39— github.handleEgressEvent has cyclomatic complexity 16 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
InputPrompt.InputPrompt (cognitive 530) packages/cli/src/ui/components/InputPrompt.tsx:207— InputPrompt.InputPrompt has cognitive complexity 530 (threshold 15). Drivers by points: if/else 171 (330 pts), boolean chains 104, ternaries 37 (77 pts), loops 5 (18 pts), error handling 1 (nesting depth added 212). Of this number, 47 points are the body's own statements and 483 belong to 21 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
vim-buffer-actions.handleVimAction (cognitive 394) packages/cli/src/ui/components/shared/vim-buffer-actions.ts:164— vim-buffer-actions.handleVimAction has cognitive complexity 394 (threshold 15). Drivers by points: if/else 116 (272 pts), loops 24 (50 pts), boolean chains 49, ternaries 10 (20 pts), match/switch 2 (3 pts) (nesting depth added 193). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
useGeminiStream.useGeminiStream (cognitive 355) packages/cli/src/ui/hooks/useGeminiStream.ts:224— useGeminiStream.useGeminiStream has cognitive complexity 355 (threshold 15). Drivers by points: if/else 148 (236 pts), boolean chains 62, loops 10 (20 pts), ternaries 7 (18 pts), error handling 5 (13 pts), match/switch 2 (6 pts) (nesting depth added 121). Most of this is not in the body itself: 1 of the 355 points is its own statement and the rest belongs to 45 function literals inside it that branch (lines 452, 1973, 961, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
vim.useVim (cognitive 307) packages/cli/src/ui/hooks/vim.ts:187— vim.useVim has cognitive complexity 307 (threshold 15). Drivers by points: if/else 94 (249 pts), boolean chains 28, ternaries 5 (23 pts), loops 1 (3 pts), match/switch 2 (3 pts), error handling 1 (nesting depth added 176). Most of this is not in the body itself: 0 of the 307 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 660, 473, 230, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
AppContainer.AppContainer (cognitive 269) packages/cli/src/ui/AppContainer.tsx:223— AppContainer.AppContainer has cognitive complexity 269 (threshold 15). Drivers by points: if/else 121 (171 pts), boolean chains 65, ternaries 15 (24 pts), error handling 5 (8 pts), match/switch 1 (nesting depth added 62). Of this number, 27 points are the body's own statements and 242 belong to 53 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ShellToolInvocation.execute (cognitive 246) packages/core/src/tools/shell.ts:523— ShellToolInvocation.execute has cognitive complexity 246 (threshold 15). Drivers by points: if/else 72 (155 pts), boolean chains 35, loops 5 (24 pts), error handling 5 (18 pts), ternaries 8 (13 pts), match/switch 1 (nesting depth added 120). Of this number, 217 points are the body's own statements and 29 belong to 8 function literals inside it that branch. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
sandbox.start_sandbox (cognitive 242) packages/cli/src/utils/sandbox.ts:55— sandbox.start_sandbox has cognitive complexity 242 (threshold 15). Drivers by points: if/else 88 (166 pts), error handling 9 (23 pts), boolean chains 20, ternaries 11 (18 pts), loops 7 (15 pts) (nesting depth added 107). Of this number, 222 points are the body's own statements and 20 belong to 6 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
text-buffer.textBufferReducerLogic (cognitive 200) packages/cli/src/ui/components/shared/text-buffer.ts:1787— text-buffer.textBufferReducerLogic has cognitive complexity 200 (threshold 15). Drivers by points: if/else 66 (152 pts), boolean chains 20, ternaries 6 (14 pts), loops 2 (8 pts), match/switch 3 (6 pts) (nesting depth added 103). Of this number, 192 points are the body's own statements and 8 belong to 2 function literals inside it that branch. The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
Session.#resolvePrompt (cognitive 197) packages/cli/src/acp/acpSession.ts:969— Session.#resolvePrompt has cognitive complexity 197 (threshold 15). Drivers by points: if/else 59 (138 pts), boolean chains 17, error handling 5 (16 pts), ternaries 5 (16 pts), loops 5 (9 pts), match/switch 1 (nesting depth added 105). Of this number, 192 points are the body's own statements and 5 belong to 2 function literals inside it that branch. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
nonInteractiveCliAgentSession.runNonInteractive (cognitive 197) packages/cli/src/nonInteractiveCliAgentSession.ts:75— nonInteractiveCliAgentSession.runNonInteractive has cognitive complexity 197 (threshold 15). Drivers by points: if/else 62 (132 pts), ternaries 14 (41 pts), boolean chains 15, loops 2 (5 pts), match/switch 2 (3 pts), error handling 1 (nesting depth added 101). Most of this is not in the body itself: 0 of the 197 points are its own statements and the rest belongs to 10 function literals inside it that branch (lines 82, 371, 102, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
KeypressContext.emitKeys (cognitive 192) packages/cli/src/ui/contexts/KeypressContext.tsx:380— KeypressContext.emitKeys has cognitive complexity 192 (threshold 15). Drivers by points: if/else 50 (134 pts), boolean chains 28, loops 6 (25 pts), error handling 1 (5 pts) (nesting depth added 107). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
nonInteractiveCli.runNonInteractive (cognitive 188) packages/cli/src/nonInteractiveCli.ts:72— nonInteractiveCli.runNonInteractive has cognitive complexity 188 (threshold 15). Drivers by points: if/else 64 (123 pts), ternaries 10 (37 pts), boolean chains 18, loops 3 (6 pts), error handling 2 (4 pts) (nesting depth added 91). Most of this is not in the body itself: 1 of the 188 points is its own statement and the rest belongs to 6 function literals inside it that branch (lines 85, 105, 154, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ToolConfirmationMessage.ToolConfirmationMessage (cognitive 181) packages/cli/src/ui/components/messages/ToolConfirmationMessage.tsx:65— ToolConfirmationMessage.ToolConfirmationMessage has cognitive complexity 181 (threshold 15). Drivers by points: if/else 63 (98 pts), boolean chains 52, ternaries 14 (25 pts), error handling 2 (4 pts), loops 1 (2 pts) (nesting depth added 49). Of this number, 20 points are the body's own statements and 161 belong to 14 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
chatRecordingService.loadConversationRecord (cognitive 177) packages/core/src/services/chatRecordingService.ts:133— chatRecordingService.loadConversationRecord has cognitive complexity 177 (threshold 15). Drivers by points: if/else 43 (131 pts), loops 6 (23 pts), boolean chains 15, ternaries 5, error handling 2 (3 pts) (nesting depth added 106). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
GeminiChat.processStreamResponse (cognitive 162) packages/core/src/core/geminiChat.ts:1354— GeminiChat.processStreamResponse has cognitive complexity 162 (threshold 15). Drivers by points: if/else 47 (126 pts), loops 8 (18 pts), boolean chains 13, ternaries 2 (5 pts) (nesting depth added 92). Of this number, 154 points are the body's own statements and 8 belong to one function literal inside it that branches. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
TriageDuplicates.TriageDuplicates (cognitive 159) packages/cli/src/ui/components/triage/TriageDuplicates.tsx:105— TriageDuplicates.TriageDuplicates has cognitive complexity 159 (threshold 15). Drivers by points: if/else 56 (77 pts), boolean chains 38, ternaries 20 (38 pts), error handling 4, loops 2 (nesting depth added 39). Of this number, 29 points are the body's own statements and 130 belong to 22 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
retry.retryWithBackoff (cognitive 159) packages/core/src/utils/retry.ts:258— retry.retryWithBackoff has cognitive complexity 159 (threshold 15). Drivers by points: if/else 31 (106 pts), ternaries 5 (21 pts), error handling 4 (19 pts), boolean chains 12, loops 1 (nesting depth added 106). Of this number, 158 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
ContextCompressionService.compressHistory (cognitive 131) packages/core/src/context/contextCompressionService.ts:108— ContextCompressionService.compressHistory has cognitive complexity 131 (threshold 15). Drivers by points: if/else 29 (96 pts), loops 10 (20 pts), boolean chains 15 (nesting depth added 77). Of this number, 130 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
VirtualizedList.VirtualizedList (cognitive 129) packages/cli/src/ui/components/shared/VirtualizedList.tsx:129— VirtualizedList.VirtualizedList has cognitive complexity 129 (threshold 15). Drivers by points: if/else 42 (65 pts), boolean chains 34, ternaries 18 (25 pts), loops 5 (nesting depth added 30). Of this number, 22 points are the body's own statements and 107 belong to 19 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
CoderAgentExecutor.execute (cognitive 117) packages/a2a-server/src/agent/executor.ts:439— CoderAgentExecutor.execute has cognitive complexity 117 (threshold 15). Drivers by points: if/else 45 (79 pts), error handling 10 (20 pts), ternaries 3 (7 pts), boolean chains 6, loops 3 (5 pts) (nesting depth added 50). Most of this is not in the body itself: 10 of the 117 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 490, 565, 524, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
toml-loader.loadPoliciesFromToml (cognitive 115) packages/core/src/policy/toml-loader.ts:323— toml-loader.loadPoliciesFromToml has cognitive complexity 115 (threshold 15). Drivers by points: if/else 16 (55 pts), ternaries 6 (22 pts), loops 7 (20 pts), error handling 5 (16 pts), boolean chains 2 (nesting depth added 79). Of this number, 78 points are the body's own statements and 37 belong to 4 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
InboxDialog.InboxDialog (cognitive 114) packages/cli/src/ui/components/InboxDialog.tsx:331— InboxDialog.InboxDialog has cognitive complexity 114 (threshold 15). Drivers by points: if/else 38 (47 pts), ternaries 16 (26 pts), boolean chains 25, error handling 9 (11 pts), loops 3 (5 pts) (nesting depth added 23). Of this number, 24 points are the body's own statements and 90 belong to 24 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
slashCommandProcessor.useSlashCommandProcessor (cognitive 113) packages/cli/src/ui/hooks/slashCommandProcessor.ts:97— slashCommandProcessor.useSlashCommandProcessor has cognitive complexity 113 (threshold 15). Drivers by points: if/else 36 (75 pts), ternaries 4 (13 pts), boolean chains 9, match/switch 2 (9 pts), error handling 2 (7 pts) (nesting depth added 60). Most of this is not in the body itself: 0 of the 113 points are its own statements and the rest belongs to 13 function literals inside it that branch (lines 355, 159, 474, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
config.loadCliConfig (cognitive 110) packages/cli/src/config/config.ts:583— config.loadCliConfig has cognitive complexity 110 (threshold 15). Drivers by points: if/else 35 (49 pts), boolean chains 38, ternaries 14 (18 pts), error handling 2 (3 pts), match/switch 1 (2 pts) (nesting depth added 20). Of this number, 105 points are the body's own statements and 5 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
consent.extensionConsentString (cognitive 105) packages/cli/src/config/extensions/consent.ts:189— consent.extensionConsentString has cognitive complexity 105 (threshold 15). Drivers by points: if/else 26 (57 pts), ternaries 5 (23 pts), loops 4 (14 pts), boolean chains 11 (nesting depth added 59). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sessionCleanup.cleanupExpiredSessions (cognitive 105) packages/cli/src/utils/sessionCleanup.ts:102— sessionCleanup.cleanupExpiredSessions has cognitive complexity 105 (threshold 15). Drivers by points: if/else 21 (58 pts), ternaries 5 (21 pts), error handling 5 (16 pts), boolean chains 6, loops 2 (4 pts) (nesting depth added 66). Of this number, 103 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PolicyEngine.check (cognitive 105) packages/core/src/policy/policy-engine.ts:600— PolicyEngine.check has cognitive complexity 105 (threshold 15). Drivers by points: if/else 31 (65 pts), boolean chains 17, loops 5 (12 pts), ternaries 3 (7 pts), error handling 1 (4 pts) (nesting depth added 48). Of this number, 102 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
useVoiceMode.useVoiceMode (cognitive 104) packages/cli/src/ui/hooks/useVoiceMode.ts:33— useVoiceMode.useVoiceMode has cognitive complexity 104 (threshold 15). Drivers by points: if/else 50 (87 pts), boolean chains 10, ternaries 3 (6 pts), error handling 1 (nesting depth added 40). Most of this is not in the body itself: 0 of the 104 points are its own statements and the rest belongs to 12 function literals inside it that branch (lines 319, 131, 189, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
gemini.main (cognitive 101) packages/cli/src/gemini.tsx:466— gemini.main has cognitive complexity 101 (threshold 15). Drivers by points: if/else 43 (70 pts), boolean chains 17, error handling 2 (5 pts), ternaries 4 (5 pts), loops 2 (4 pts) (nesting depth added 33). Of this number, 90 points are the body's own statements and 11 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
useExecutionLifecycle.useExecutionLifecycle (cognitive 101) packages/cli/src/ui/hooks/useExecutionLifecycle.ts:75— useExecutionLifecycle.useExecutionLifecycle has cognitive complexity 101 (threshold 15). Drivers by points: if/else 54 (72 pts), boolean chains 13, ternaries 5 (11 pts), error handling 2 (3 pts), loops 1, match/switch 1 (nesting depth added 25). Most of this is not in the body itself: 1 of the 101 points is its own statement and the rest belongs to 16 function literals inside it that branch (lines 365, 425, 113, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
GeminiChat.sendMessageStream (cognitive 101) packages/core/src/core/geminiChat.ts:480— GeminiChat.sendMessageStream has cognitive complexity 101 (threshold 15). Drivers by points: if/else 30 (67 pts), boolean chains 15, ternaries 4 (13 pts), error handling 2 (3 pts), loops 2 (3 pts) (nesting depth added 48). Of this number, 37 points are the body's own statements and 64 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ExtensionManager._buildExtension (cognitive 100) packages/cli/src/config/extension-manager.ts:708— ExtensionManager._buildExtension has cognitive complexity 100 (threshold 15). Drivers by points: if/else 31 (64 pts), loops 7 (22 pts), boolean chains 6, error handling 3 (4 pts), ternaries 1 (4 pts) (nesting depth added 52). Of this number, 98 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
useSlashCompletion.useCommandSuggestions (cognitive 98) packages/cli/src/ui/hooks/useSlashCompletion.ts:145— useSlashCompletion.useCommandSuggestions has cognitive complexity 98 (threshold 15). Drivers by points: if/else 28 (70 pts), boolean chains 22, error handling 2 (6 pts) (nesting depth added 46). Most of this is not in the body itself: 0 of the 98 points are its own statements and the rest belongs to 7 function literals inside it that branch (lines 229, 278, 173, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
BaseSettingsDialog.BaseSettingsDialog (cognitive 97) packages/cli/src/ui/components/shared/BaseSettingsDialog.tsx:128— BaseSettingsDialog.BaseSettingsDialog has cognitive complexity 97 (threshold 15). Drivers by points: if/else 32 (54 pts), boolean chains 22, ternaries 13 (21 pts) (nesting depth added 30). Most of this is not in the body itself: 13 of the 97 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 290, 489, 163, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
mcp-client.connectToMcpServer (cognitive 97) packages/core/src/tools/mcp-client.ts:1839— mcp-client.connectToMcpServer has cognitive complexity 97 (threshold 15). Drivers by points: if/else 27 (75 pts), error handling 5 (10 pts), boolean chains 8, ternaries 1 (3 pts), loops 1 (nesting depth added 55). Of this number, 95 points are the body's own statements and 2 belong to 2 function literals inside it that branch. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
LocalSessionInvocation.execute (cognitive 94) packages/core/src/agents/local-session-invocation.ts:111— LocalSessionInvocation.execute has cognitive complexity 94 (threshold 15). Drivers by points: if/else 23 (46 pts), ternaries 13 (27 pts), boolean chains 11, loops 3 (8 pts), error handling 1, match/switch 1 (nesting depth added 42). Of this number, 33 points are the body's own statements and 61 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
text-buffer.useTextBuffer (cognitive 91) packages/cli/src/ui/components/shared/text-buffer.ts:2832— text-buffer.useTextBuffer has cognitive complexity 91 (threshold 15). Drivers by points: if/else 48 (71 pts), boolean chains 8, loops 4 (5 pts), ternaries 4, error handling 3 (nesting depth added 24). Most of this is not in the body itself: 3 of the 91 points are its own statements and the rest belongs to 8 function literals inside it that branch (lines 3372, 2948, 3552, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
untrustedContextTracker.extractUntrustedContext (cognitive 91) packages/core/src/utils/untrustedContextTracker.ts:84— untrustedContextTracker.extractUntrustedContext has cognitive complexity 91 (threshold 15). Drivers by points: if/else 16 (64 pts), loops 6 (25 pts), boolean chains 2 (nesting depth added 67). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
GrepToolInvocation.performGrepSearch (cognitive 90) packages/core/src/tools/grep.ts:413— GrepToolInvocation.performGrepSearch has cognitive complexity 90 (threshold 15). Drivers by points: if/else 25 (65 pts), boolean chains 10, error handling 4 (7 pts), loops 4 (7 pts), ternaries 1 (nesting depth added 46). Of this number, 82 points are the body's own statements and 8 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
historyHardening.pairToolsAndEnforceSignatures (cognitive 89) packages/core/src/utils/historyHardening.ts:127— historyHardening.pairToolsAndEnforceSignatures has cognitive complexity 89 (threshold 15). Drivers by points: if/else 18 (56 pts), loops 6 (20 pts), boolean chains 13 (nesting depth added 52). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
ToolGroupMessage.ToolGroupMessage (cognitive 88) packages/cli/src/ui/components/messages/ToolGroupMessage.tsx:110— ToolGroupMessage.ToolGroupMessage has cognitive complexity 88 (threshold 15). Drivers by points: if/else 18 (34 pts), boolean chains 28, ternaries 12 (18 pts), loops 5 (8 pts) (nesting depth added 25). Of this number, 18 points are the body's own statements and 70 belong to 4 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
atCommandProcessor.resolveFilePaths (cognitive 87) packages/cli/src/ui/hooks/atCommandProcessor.ts:224— atCommandProcessor.resolveFilePaths has cognitive complexity 87 (threshold 15). Drivers by points: if/else 13 (32 pts), ternaries 7 (29 pts), error handling 2 (12 pts), boolean chains 9, loops 2 (5 pts) (nesting depth added 54). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
AskUserDialog.ChoiceQuestionView (cognitive 86) packages/cli/src/ui/components/AskUserDialog.tsx:520— AskUserDialog.ChoiceQuestionView has cognitive complexity 86 (threshold 15). Drivers by points: if/else 34 (44 pts), boolean chains 28, ternaries 11 (14 pts) (nesting depth added 13). Most of this is not in the body itself: 14 of the 86 points are its own statements and the rest belongs to 14 function literals inside it that branch (lines 921, 796, 673, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
BrowserAgentInvocation.execute (cognitive 86) packages/core/src/agents/browser/browserAgentInvocation.ts:111— BrowserAgentInvocation.execute has cognitive complexity 86 (threshold 15). Drivers by points: if/else 20 (36 pts), ternaries 11 (21 pts), loops 5 (13 pts), error handling 4 (8 pts), boolean chains 7, match/switch 1 (nesting depth added 38). Of this number, 36 points are the body's own statements and 50 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
settings.migrateDeprecatedSettings (cognitive 85) packages/cli/src/config/settings.ts:1001— settings.migrateDeprecatedSettings has cognitive complexity 85 (threshold 15). Drivers by points: if/else 30 (72 pts), ternaries 2 (6 pts), boolean chains 5, loops 1 (2 pts) (nesting depth added 47). Most of this is not in the body itself: 6 of the 85 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 1044, 1011). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useCommandCompletion.useCommandCompletion (cognitive 85) packages/cli/src/ui/hooks/useCommandCompletion.tsx:77— useCommandCompletion.useCommandCompletion has cognitive complexity 85 (threshold 15). Drivers by points: if/else 27 (43 pts), boolean chains 26, loops 4 (12 pts), ternaries 3 (4 pts) (nesting depth added 25). Most of this is not in the body itself: 9 of the 85 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 121, 405, 253, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
googleQuotaErrors.classifyGoogleError (cognitive 84) packages/core/src/utils/googleQuotaErrors.ts:223— googleQuotaErrors.classifyGoogleError has cognitive complexity 84 (threshold 15). Drivers by points: if/else 31 (66 pts), boolean chains 14, loops 2 (4 pts) (nesting depth added 37). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
config.createPolicyEngineConfig (cognitive 83) packages/core/src/policy/config.ts:286— config.createPolicyEngineConfig has cognitive complexity 83 (threshold 15). Drivers by points: if/else 21 (35 pts), loops 10 (21 pts), ternaries 9 (21 pts), boolean chains 4, error handling 1 (2 pts) (nesting depth added 38). Of this number, 55 points are the body's own statements and 28 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
LocalSubagentInvocation.execute (cognitive 82) packages/core/src/agents/local-invocation.ts:102— LocalSubagentInvocation.execute has cognitive complexity 82 (threshold 15). Drivers by points: if/else 19 (38 pts), ternaries 11 (23 pts), boolean chains 11, loops 3 (8 pts), error handling 1, match/switch 1 (nesting depth added 36). Of this number, 29 points are the body's own statements and 53 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ExtensionManager.installOrUpdateExtension (cognitive 80) packages/cli/src/config/extension-manager.ts:180— ExtensionManager.installOrUpdateExtension has cognitive complexity 80 (threshold 15). Drivers by points: if/else 36 (50 pts), boolean chains 19, error handling 3 (6 pts), ternaries 3 (5 pts) (nesting depth added 19). Of this number, 77 points are the body's own statements and 3 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ShellExecutionService.executeWithPty (cognitive 79) packages/core/src/services/shellExecutionService.ts:1103— ShellExecutionService.executeWithPty has cognitive complexity 79 (threshold 15). Drivers by points: if/else 33 (44 pts), error handling 10 (16 pts), boolean chains 12, ternaries 6, loops 1 (nesting depth added 17). Of this number, 30 points are the body's own statements and 49 belong to 20 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
sessionUtils.convertSessionToClientHistory (cognitive 77) packages/core/src/utils/sessionUtils.ts:110— sessionUtils.convertSessionToClientHistory has cognitive complexity 77 (threshold 15). Drivers by points: if/else 15 (47 pts), loops 4 (16 pts), ternaries 2 (9 pts), boolean chains 5 (nesting depth added 51). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
ScrollProvider.ScrollProvider (cognitive 76) packages/cli/src/ui/contexts/ScrollProvider.tsx:94— ScrollProvider.ScrollProvider has cognitive complexity 76 (threshold 15). Drivers by points: if/else 32 (55 pts), boolean chains 11, ternaries 2 (6 pts), loops 3 (4 pts) (nesting depth added 28). Most of this is not in the body itself: 0 of the 76 points are its own statements and the rest belongs to 7 function literals inside it that branch (lines 258, 190, 139, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
policy-engine.ruleMatches (cognitive 76) packages/core/src/policy/policy-engine.ts:129— policy-engine.ruleMatches has cognitive complexity 76 (threshold 15). Drivers by points: if/else 29 (64 pts), boolean chains 10, loops 1 (2 pts) (nesting depth added 36). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
ShellExecutionService.childProcessFallback (cognitive 74) packages/core/src/services/shellExecutionService.ts:652— ShellExecutionService.childProcessFallback has cognitive complexity 74 (threshold 15). Drivers by points: if/else 30 (57 pts), boolean chains 9, ternaries 4 (5 pts), error handling 2 (3 pts) (nesting depth added 29). Of this number, 26 points are the body's own statements and 48 belong to 8 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
setup.handleSetup (cognitive 72) packages/cli/src/commands/gemma/setup.ts:159— setup.handleSetup has cognitive complexity 72 (threshold 15). Drivers by points: if/else 23 (33 pts), error handling 8 (20 pts), ternaries 6 (14 pts), boolean chains 5 (nesting depth added 30). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Footer.Footer (cognitive 71) packages/cli/src/ui/components/Footer.tsx:179— Footer.Footer has cognitive complexity 71 (threshold 15). Drivers by points: if/else 19 (35 pts), ternaries 14 (22 pts), boolean chains 7, loops 3 (5 pts), match/switch 1 (2 pts) (nesting depth added 27). Of this number, 61 points are the body's own statements and 10 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
useAgentStream.useAgentStream (cognitive 70) packages/cli/src/ui/hooks/useAgentStream.ts:56— useAgentStream.useAgentStream has cognitive complexity 70 (threshold 15). Drivers by points: if/else 24 (38 pts), boolean chains 16, ternaries 5 (9 pts), loops 2 (5 pts), error handling 1, match/switch 1 (nesting depth added 21). Most of this is not in the body itself: 1 of the 70 points is its own statement and the rest belongs to 14 function literals inside it that branch (lines 149, 485, 412, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
GeminiClient.processTurn (cognitive 69) packages/core/src/core/client.ts:614— GeminiClient.processTurn has cognitive complexity 69 (threshold 15). Drivers by points: if/else 31 (48 pts), boolean chains 16, ternaries 2 (4 pts), loops 1 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
memoryService.startMemoryService (cognitive 69) packages/core/src/services/memoryService.ts:1133— memoryService.startMemoryService has cognitive complexity 69 (threshold 15). Drivers by points: if/else 27 (40 pts), ternaries 5 (13 pts), error handling 5 (8 pts), boolean chains 5, loops 3 (nesting depth added 24). Of this number, 59 points are the body's own statements and 10 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ReadManyFilesToolInvocation.execute (cognitive 69) packages/core/src/tools/read-many-files.ts:179— ReadManyFilesToolInvocation.execute has cognitive complexity 69 (threshold 15). Drivers by points: if/else 27 (46 pts), loops 6 (8 pts), ternaries 3 (7 pts), error handling 3 (5 pts), boolean chains 3 (nesting depth added 27). Of this number, 60 points are the body's own statements and 9 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
toolMaskingProcessor.createToolMaskingProcessor (cognitive 67) packages/core/src/context/processors/toolMaskingProcessor.ts:81— toolMaskingProcessor.createToolMaskingProcessor has cognitive complexity 67 (threshold 15). Drivers by points: if/else 22 (54 pts), loops 3 (7 pts), boolean chains 6 (nesting depth added 36). Most of this is not in the body itself: 0 of the 67 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 92, 160, 112). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
patch-create-comment.main (cognitive 67) scripts/releasing/patch-create-comment.js:17— patch-create-comment.main has cognitive complexity 67 (threshold 15). Drivers by points: if/else 28 (46 pts), boolean chains 13, error handling 2 (6 pts), ternaries 2 (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
BackgroundTaskDisplay.BackgroundTaskDisplay (cognitive 66) packages/cli/src/ui/components/BackgroundTaskDisplay.tsx:64— BackgroundTaskDisplay.BackgroundTaskDisplay has cognitive complexity 66 (threshold 15). Drivers by points: if/else 29 (41 pts), ternaries 14 (19 pts), boolean chains 5, loops 1 (nesting depth added 17). Most of this is not in the body itself: 6 of the 66 points are its own statements and the rest belongs to 14 function literals inside it that branch (lines 146, 228, 111, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
contentGenerator.createContentGenerator (cognitive 66) packages/core/src/core/contentGenerator.ts:210— contentGenerator.createContentGenerator has cognitive complexity 66 (threshold 15). Drivers by points: if/else 20 (32 pts), boolean chains 19, ternaries 6 (15 pts) (nesting depth added 21). Most of this is not in the body itself: 1 of the 66 points is its own statement and the rest belongs to one function literal inside it that branches (line 215). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
TriageIssues.TriageIssues (cognitive 65) packages/cli/src/ui/components/triage/TriageIssues.tsx:66— TriageIssues.TriageIssues has cognitive complexity 65 (threshold 15). Drivers by points: if/else 30 (34 pts), ternaries 11 (18 pts), boolean chains 10, error handling 3 (nesting depth added 11). Of this number, 20 points are the body's own statements and 45 belong to 13 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
Session.prompt (cognitive 64) packages/cli/src/acp/acpSession.ts:311— Session.prompt has cognitive complexity 64 (threshold 15). Drivers by points: if/else 16 (38 pts), boolean chains 11, loops 4 (6 pts), ternaries 1 (4 pts), match/switch 1 (3 pts), error handling 1 (2 pts) (nesting depth added 30). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
McpPromptLoader.loadCommands (cognitive 64) packages/cli/src/services/McpPromptLoader.ts:35— McpPromptLoader.loadCommands has cognitive complexity 64 (threshold 15). Drivers by points: if/else 13 (40 pts), boolean chains 9, loops 3 (6 pts), ternaries 2 (6 pts), error handling 1 (3 pts) (nesting depth added 36). Most of this is not in the body itself: 8 of the 64 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 152, 57, 88, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
LegacyAgentProtocol._runLoop (cognitive 64) packages/core/src/agent/legacy-agent-session.ts:174— LegacyAgentProtocol._runLoop has cognitive complexity 64 (threshold 15). Drivers by points: if/else 14 (35 pts), ternaries 5 (15 pts), loops 3 (5 pts), boolean chains 4, match/switch 1 (3 pts), error handling 1 (2 pts) (nesting depth added 36). Of this number, 63 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
prepareRuntime (cognitive 64) sea/sea-launch.cjs:93— prepareRuntime has cognitive complexity 64 (threshold 15). Drivers by points: if/else 16 (25 pts), error handling 8 (21 pts), boolean chains 14, loops 1 (3 pts), ternaries 1 (nesting depth added 24). Of this number, 54 points are the body's own statements and 10 belong to 2 function items inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
LocalAgentExecutor.runInternal (cognitive 63) packages/core/src/agents/local-executor.ts:571— LocalAgentExecutor.runInternal has cognitive complexity 63 (threshold 15). Drivers by points: if/else 25 (44 pts), error handling 3 (9 pts), boolean chains 7, ternaries 2, loops 1 (nesting depth added 25). Of this number, 59 points are the body's own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
eval-report.summarizeReports (cognitive 63) scripts/utils/eval-report.ts:86— eval-report.summarizeReports has cognitive complexity 63 (threshold 15). Drivers by points: if/else 9 (35 pts), loops 6 (14 pts), ternaries 3 (8 pts), boolean chains 4, error handling 1 (2 pts) (nesting depth added 40). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ShellToolInvocation.shouldConfirmExecute (cognitive 62) packages/core/src/tools/shell.ts:302— ShellToolInvocation.shouldConfirmExecute has cognitive complexity 62 (threshold 15). Drivers by points: if/else 14 (48 pts), boolean chains 14 (nesting depth added 34). Of this number, 55 points are the body's own statements and 7 belong to 3 function literals inside it that branch. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
oauth2.initOauthClient (cognitive 61) REDACTED:129— oauth2.initOauthClient has cognitive complexity 61 (threshold 15). Drivers by points: if/else 19 (37 pts), error handling 6 (17 pts), boolean chains 4, loops 2 (3 pts) (nesting depth added 30). Of this number, 58 points are the body's own statements and 3 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ContextWorkingBufferImpl.syncPristineHistory (cognitive 61) packages/core/src/context/pipeline/contextWorkingBuffer.ts:184— ContextWorkingBufferImpl.syncPristineHistory has cognitive complexity 61 (threshold 15). Drivers by points: if/else 17 (34 pts), loops 11 (18 pts), boolean chains 6, ternaries 1 (3 pts) (nesting depth added 26). Of this number, 39 points are the body's own statements and 22 belong to 4 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
rewindFileOps.revertFileChanges (cognitive 60) packages/cli/src/ui/utils/rewindFileOps.ts:149— rewindFileOps.revertFileChanges has cognitive complexity 60 (threshold 15). Drivers by points: if/else 14 (43 pts), error handling 2 (10 pts), loops 2 (4 pts), boolean chains 3 (nesting depth added 39). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
untrustedContextTracker.findUntrustedFlags (cognitive 59) packages/core/src/utils/untrustedContextTracker.ts:184— untrustedContextTracker.findUntrustedFlags has cognitive complexity 59 (threshold 15). Drivers by points: if/else 16 (42 pts), boolean chains 9, loops 2 (6 pts), error handling 1, ternaries 1 (nesting depth added 30). Of this number, 50 points are the body's own statements and 9 belong to one function literal inside it that branches. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
eval-validate.validateInventory (cognitive 58) scripts/utils/eval-validate.ts:357— eval-validate.validateInventory has cognitive complexity 58 (threshold 15). Drivers by points: if/else 18 (47 pts), loops 4 (6 pts), ternaries 2 (3 pts), boolean chains 2 (nesting depth added 32). Of this number, 52 points are the body's own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
SubagentGroupDisplay.SubagentGroupDisplay (cognitive 57) packages/cli/src/ui/components/messages/SubagentGroupDisplay.tsx:34— SubagentGroupDisplay.SubagentGroupDisplay has cognitive complexity 57 (threshold 15). Drivers by points: if/else 24 (37 pts), boolean chains 7, ternaries 4 (6 pts), match/switch 2 (5 pts), loops 1 (2 pts) (nesting depth added 19). Of this number, 27 points are the body's own statements and 30 belong to 5 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
MarkdownDisplay.MarkdownDisplayInternal (cognitive 57) packages/cli/src/ui/utils/MarkdownDisplay.tsx:31— MarkdownDisplay.MarkdownDisplayInternal has cognitive complexity 57 (threshold 15). Drivers by points: if/else 27 (36 pts), boolean chains 10, ternaries 3 (7 pts), loops 1 (2 pts), match/switch 1 (2 pts) (nesting depth added 15). Most of this is not in the body itself: 10 of the 57 points are its own statements and the rest belongs to one function literal inside it that branches (line 88). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
GeminiClient.getIdeContextParts (cognitive 57) packages/core/src/core/client.ts:429— GeminiClient.getIdeContextParts has cognitive complexity 57 (threshold 15). Drivers by points: if/else 19 (40 pts), boolean chains 13, loops 2 (4 pts) (nesting depth added 23). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
useQuotaAndFallback.useQuotaAndFallback (cognitive 56) packages/cli/src/ui/hooks/useQuotaAndFallback.ts:51— useQuotaAndFallback.useQuotaAndFallback has cognitive complexity 56 (threshold 15). Drivers by points: if/else 20 (26 pts), ternaries 9 (19 pts), boolean chains 11 (nesting depth added 16). Most of this is not in the body itself: 0 of the 56 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 75, 293, 321, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
PolicyEngine.checkShellCommand (cognitive 56) packages/core/src/policy/policy-engine.ts:441— PolicyEngine.checkShellCommand has cognitive complexity 56 (threshold 15). Drivers by points: if/else 21 (48 pts), boolean chains 5, ternaries 2, loops 1 (nesting depth added 27). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
patch-trigger.main (cognitive 56) scripts/releasing/patch-trigger.js:56— patch-trigger.main has cognitive complexity 56 (threshold 15). Drivers by points: if/else 13 (17 pts), boolean chains 15, ternaries 7 (13 pts), error handling 4 (11 pts) (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
useShellCompletion.getTokenAtCursor (cognitive 55) packages/cli/src/ui/hooks/useShellCompletion.ts:59— useShellCompletion.getTokenAtCursor has cognitive complexity 55 (threshold 15). Drivers by points: if/else 12 (33 pts), loops 6 (13 pts), boolean chains 7, ternaries 2 (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
MCPOAuthProvider.authenticate (cognitive 54) packages/core/src/mcp/oauth-provider.ts:304— MCPOAuthProvider.authenticate has cognitive complexity 54 (threshold 15). Drivers by points: if/else 20 (37 pts), boolean chains 10, error handling 3 (4 pts), ternaries 2 (3 pts) (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Orchestrator.run (cognitive 54) tools/caretaker-agent/cloudrun/pr-generator/workflow/orchestrator.py:145— Orchestrator.run has cognitive complexity 54 (threshold 15). Drivers by points: if/else 13 (25 pts), error handling 10 (19 pts), ternaries 2 (5 pts), boolean chains 4, loops 1 (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sandbox.start_lxc_sandbox (cognitive 53) packages/cli/src/utils/sandbox.ts:1039— sandbox.start_lxc_sandbox has cognitive complexity 53 (threshold 15). Drivers by points: if/else 14 (25 pts), error handling 5 (9 pts), ternaries 3 (8 pts), loops 4 (6 pts), boolean chains 5 (nesting depth added 22). Of this number, 48 points are the body's own statements and 5 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
GeminiClient.sendMessageStream (cognitive 52) packages/core/src/core/client.ts:910— GeminiClient.sendMessageStream has cognitive complexity 52 (threshold 15). Drivers by points: if/else 18 (39 pts), boolean chains 7, ternaries 1 (5 pts), error handling 1 (nesting depth added 25). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
RewindViewer.RewindViewer (cognitive 51) packages/cli/src/ui/components/RewindViewer.tsx:47— RewindViewer.RewindViewer has cognitive complexity 51 (threshold 15). Drivers by points: if/else 20 (34 pts), ternaries 6 (11 pts), boolean chains 6 (nesting depth added 19). Most of this is not in the body itself: 6 of the 51 points are its own statements and the rest belongs to 9 function literals inside it that branch (lines 260, 100, 242, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
SettingsDialog.SettingsDialog (cognitive 51) packages/cli/src/ui/components/SettingsDialog.tsx:100— SettingsDialog.SettingsDialog has cognitive complexity 51 (threshold 15). Drivers by points: if/else 21 (28 pts), boolean chains 11, ternaries 5 (8 pts), loops 3 (4 pts) (nesting depth added 11). Most of this is not in the body itself: 5 of the 51 points are its own statements and the rest belongs to 14 function literals inside it that branch (lines 300, 195, 222, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
Turn.run (cognitive 51) packages/core/src/core/turn.ts:270— Turn.run has cognitive complexity 51 (threshold 15). Drivers by points: if/else 16 (37 pts), loops 4 (7 pts), boolean chains 4, ternaries 1 (2 pts), error handling 1 (nesting depth added 25). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
memoryImportProcessor.processImports (cognitive 51) packages/core/src/utils/memoryImportProcessor.ts:190— memoryImportProcessor.processImports has cognitive complexity 51 (threshold 15). Drivers by points: if/else 14 (30 pts), boolean chains 7, ternaries 2 (6 pts), error handling 2 (5 pts), loops 2 (3 pts) (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
config.parseArguments (cognitive 49) packages/cli/src/config/config.ts:161— config.parseArguments has cognitive complexity 49 (threshold 15). Drivers by points: if/else 26 (29 pts), boolean chains 10, loops 2 (6 pts), ternaries 3, error handling 1 (nesting depth added 7). Most of this is not in the body itself: 13 of the 49 points are its own statements and the rest belongs to 7 function literals inside it that branch (lines 192, 230, 183, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
getFolderStructure.readFullStructure (cognitive 49) packages/core/src/utils/getFolderStructure.ts:71— getFolderStructure.readFullStructure has cognitive complexity 49 (threshold 15). Drivers by points: if/else 11 (37 pts), boolean chains 5, loops 3 (5 pts), error handling 1 (2 pts) (nesting depth added 29). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
editorUtils.openFileInEditor (cognitive 48) packages/cli/src/ui/utils/editorUtils.ts:47— editorUtils.openFileInEditor has cognitive complexity 48 (threshold 15). Drivers by points: if/else 17 (31 pts), ternaries 4 (11 pts), boolean chains 6 (nesting depth added 21). Of this number, 43 points are the body's own statements and 5 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sessionCleanup.cleanupToolOutputFiles (cognitive 48) packages/cli/src/utils/sessionCleanup.ts:479— sessionCleanup.cleanupToolOutputFiles has cognitive complexity 48 (threshold 15). Drivers by points: if/else 12 (20 pts), ternaries 4 (10 pts), error handling 6 (9 pts), loops 4 (7 pts), boolean chains 2 (nesting depth added 20). Of this number, 44 points are the body's own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
AgentSession.stream (cognitive 48) packages/core/src/agent/agent-session.ts:64— AgentSession.stream has cognitive complexity 48 (threshold 15). Drivers by points: if/else 22 (33 pts), loops 5 (9 pts), boolean chains 6 (nesting depth added 15). Of this number, 36 points are the body's own statements and 12 belong to 4 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
GeminiChat.makeApiCallAndProcessStream (cognitive 48) packages/core/src/core/geminiChat.ts:870— GeminiChat.makeApiCallAndProcessStream has cognitive complexity 48 (threshold 15). Drivers by points: if/else 19 (34 pts), boolean chains 7, ternaries 4, loops 1 (3 pts) (nesting depth added 17). Most of this is not in the body itself: 2 of the 48 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 917, 1098, 1122). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
mcp-client.createTransport (cognitive 48) packages/core/src/tools/mcp-client.ts:2265— mcp-client.createTransport has cognitive complexity 48 (threshold 15). Drivers by points: if/else 15 (35 pts), boolean chains 5, loops 2 (5 pts), ternaries 1 (3 pts) (nesting depth added 25). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
googleErrors.parseGoogleApiError (cognitive 48) packages/core/src/utils/googleErrors.ts:151— googleErrors.parseGoogleApiError has cognitive complexity 48 (threshold 15). Drivers by points: if/else 14 (33 pts), boolean chains 7, error handling 2 (4 pts), loops 2 (4 pts) (nesting depth added 23). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
App.App (cognitive 48) packages/devtools/client/src/App.tsx:28— App.App has cognitive complexity 48 (threshold 15). Drivers by points: ternaries 22 (25 pts), if/else 12, boolean chains 11 (nesting depth added 3). Most of this is not in the body itself: 13 of the 48 points are its own statements and the rest belongs to 15 function literals inside it that branch (lines 78, 103, 223, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
GeminiSandbox.Main (cognitive 47) packages/core/src/sandbox/windows/GeminiSandbox.cs:191— GeminiSandbox.Main has cognitive complexity 47 (threshold 15). Of this number, 45 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
Session.streamHistory (cognitive 47) packages/cli/src/acp/acpSession.ts:241— Session.streamHistory has cognitive complexity 47 (threshold 15). Drivers by points: if/else 9 (27 pts), ternaries 2 (10 pts), loops 3 (9 pts), boolean chains 1 (nesting depth added 32). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
process-utils.killProcessGroup (cognitive 47) packages/core/src/utils/process-utils.ts:38— process-utils.killProcessGroup has cognitive complexity 47 (threshold 15). Drivers by points: error handling 11 (26 pts), if/else 7 (12 pts), loops 3 (5 pts), boolean chains 2, ternaries 1 (2 pts) (nesting depth added 23). Of this number, 45 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ToolResultDisplay.ToolResultDisplay (cognitive 46) packages/cli/src/ui/components/messages/ToolResultDisplay.tsx:59— ToolResultDisplay.ToolResultDisplay has cognitive complexity 46 (threshold 15). Drivers by points: if/else 21 (28 pts), ternaries 5 (10 pts), boolean chains 8 (nesting depth added 12). Of this number, 25 points are the body's own statements and 21 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
text-buffer.calculateLayout (cognitive 46) packages/cli/src/ui/components/shared/text-buffer.ts:1288— text-buffer.calculateLayout has cognitive complexity 46 (threshold 15). Drivers by points: if/else 13 (35 pts), boolean chains 6, loops 2 (5 pts) (nesting depth added 25). Most of this is not in the body itself: 8 of the 46 points are its own statements and the rest belongs to one function literal inside it that branches (line 1299). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
ContextManager.evaluateTriggers (cognitive 45) packages/core/src/context/contextManager.ts:308— ContextManager.evaluateTriggers has cognitive complexity 45 (threshold 15). Drivers by points: if/else 14 (37 pts), boolean chains 4, loops 2 (4 pts) (nesting depth added 25). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
telemetry_utils.ensureBinary (cognitive 45) scripts/telemetry_utils.js:174— telemetry_utils.ensureBinary has cognitive complexity 45 (threshold 15). Drivers by points: if/else 16 (24 pts), ternaries 6 (9 pts), boolean chains 8, loops 2 (4 pts) (nesting depth added 13). Of this number, 30 points are the body's own statements and 15 belong to 4 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ModelDialog.ModelDialog (cognitive 44) packages/cli/src/ui/components/ModelDialog.tsx:41— ModelDialog.ModelDialog has cognitive complexity 44 (threshold 15). Drivers by points: if/else 19 (21 pts), ternaries 10 (16 pts), boolean chains 7 (nesting depth added 8). Most of this is not in the body itself: 3 of the 44 points are its own statements and the rest belongs to 10 function literals inside it that branch (lines 192, 75, 106, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
SessionBrowser.useSessionBrowserInput (cognitive 44) packages/cli/src/ui/components/SessionBrowser.tsx:542— SessionBrowser.useSessionBrowserInput has cognitive complexity 44 (threshold 15). Drivers by points: if/else 24 (34 pts), boolean chains 6, ternaries 1 (4 pts) (nesting depth added 13). Most of this is not in the body itself: 0 of the 44 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 551, 624, 640). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
StatusRow.StatusRow (cognitive 44) packages/cli/src/ui/components/StatusRow.tsx:158— StatusRow.StatusRow has cognitive complexity 44 (threshold 15). Drivers by points: boolean chains 28, if/else 9 (12 pts), ternaries 3 (4 pts) (nesting depth added 4). Of this number, 23 points are the body's own statements and 21 belong to 5 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
render.render (cognitive 44) packages/core/src/context/graph/render.ts:34— render.render has cognitive complexity 44 (threshold 15). Drivers by points: if/else 11 (20 pts), ternaries 6 (10 pts), boolean chains 7, loops 4 (7 pts) (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
trace.runInDevTraceSpan (cognitive 44) packages/core/src/telemetry/trace.ts:123— trace.runInDevTraceSpan has cognitive complexity 44 (threshold 15). Drivers by points: if/else 16 (35 pts), error handling 3 (4 pts), loops 2 (4 pts), boolean chains 1 (nesting depth added 22). Most of this is not in the body itself: 0 of the 44 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 152, 141, 224). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
text-buffer.findWordEndInLine (cognitive 43) packages/cli/src/ui/components/shared/text-buffer.ts:182— text-buffer.findWordEndInLine has cognitive complexity 43 (threshold 15). Drivers by points: boolean chains 17, if/else 8 (15 pts), loops 6 (11 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
admin_controls.sanitizeAdminSettings (cognitive 43) packages/core/src/code_assist/admin/admin_controls.ts:22— admin_controls.sanitizeAdminSettings has cognitive complexity 43 (threshold 15). Drivers by points: if/else 11 (32 pts), loops 2 (8 pts), error handling 1 (2 pts), boolean chains 1 (nesting depth added 28). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
ContextWorkingBufferImpl.applyProcessorResult (cognitive 43) packages/core/src/context/pipeline/contextWorkingBuffer.ts:61— ContextWorkingBufferImpl.applyProcessorResult has cognitive complexity 43 (threshold 15). Drivers by points: if/else 11 (24 pts), loops 8 (19 pts) (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ToolOutputMaskingService.mask (cognitive 43) packages/core/src/context/toolOutputMaskingService.ts:68— ToolOutputMaskingService.mask has cognitive complexity 43 (threshold 15). Drivers by points: if/else 16 (32 pts), boolean chains 6, loops 3 (4 pts), ternaries 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
coreToolHookTriggers.executeToolWithHooks (cognitive 42) packages/core/src/core/coreToolHookTriggers.ts:68— coreToolHookTriggers.executeToolWithHooks has cognitive complexity 42 (threshold 15). Drivers by points: if/else 18 (30 pts), ternaries 2 (6 pts), error handling 1 (4 pts), boolean chains 2 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
loggingContentGenerator.estimateContextBreakdown (cognitive 42) packages/core/src/core/loggingContentGenerator.ts:79— loggingContentGenerator.estimateContextBreakdown has cognitive complexity 42 (threshold 15). Drivers by points: if/else 12 (26 pts), loops 4 (9 pts), boolean chains 7 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
HookTranslatorGenAIv1.fromHookLLMRequest (cognitive 42) packages/core/src/hooks/hookTranslator.ts:225— HookTranslatorGenAIv1.fromHookLLMRequest has cognitive complexity 42 (threshold 15). Drivers by points: if/else 11 (22 pts), ternaries 6 (16 pts), loops 2 (4 pts) (nesting depth added 23). Of this number, 38 points are the body's own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
summary._write_markdown (cognitive 42) tools/caretaker-agent/evals/triage/helpers/summary.py:70— summary._write_markdown has cognitive complexity 42 (threshold 15). Drivers by points: if/else 12 (18 pts), ternaries 5 (15 pts), loops 2 (6 pts), boolean chains 3 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
McpStatus.McpStatus (cognitive 41) packages/cli/src/ui/components/views/McpStatus.tsx:35— McpStatus.McpStatus has cognitive complexity 41 (threshold 15). Drivers by points: boolean chains 21, if/else 10, ternaries 5 (8 pts), match/switch 1 (2 pts) (nesting depth added 4). Most of this is not in the body itself: 3 of the 41 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 89, 322, 220, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
LocalAgentExecutor.processFunctionCalls (cognitive 41) packages/core/src/agents/local-executor.ts:1105— LocalAgentExecutor.processFunctionCalls has cognitive complexity 41 (threshold 15). Drivers by points: if/else 13 (30 pts), boolean chains 5, loops 3 (4 pts), error handling 1 (2 pts) (nesting depth added 19). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
policyHelpers.resolvePolicyChain (cognitive 41) packages/core/src/availability/policyHelpers.ts:40— policyHelpers.resolvePolicyChain has cognitive complexity 41 (threshold 15). Drivers by points: if/else 13 (22 pts), ternaries 4 (10 pts), boolean chains 9 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
chatCompressionService.truncateHistoryToBudget (cognitive 41) packages/core/src/context/chatCompressionService.ts:137— chatCompressionService.truncateHistoryToBudget has cognitive complexity 41 (threshold 15). Drivers by points: if/else 11 (28 pts), error handling 1 (6 pts), loops 2 (4 pts), boolean chains 3 (nesting depth added 24). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
mcp-client.discoverTools (cognitive 41) packages/core/src/tools/mcp-client.ts:1295— mcp-client.discoverTools has cognitive complexity 41 (threshold 15). Drivers by points: if/else 9 (24 pts), error handling 3 (6 pts), loops 2 (4 pts), ternaries 1 (4 pts), boolean chains 3 (nesting depth added 23). Of this number, 18 points are the body's own statements and 23 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
terminalSerializer.serializeTerminalToObject (cognitive 41) packages/core/src/utils/terminalSerializer.ts:160— terminalSerializer.serializeTerminalToObject has cognitive complexity 41 (threshold 15). Drivers by points: ternaries 4 (16 pts), if/else 6 (14 pts), boolean chains 7, loops 3 (4 pts) (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ThemeDialog.ThemeDialog (cognitive 40) packages/cli/src/ui/components/ThemeDialog.tsx:90— ThemeDialog.ThemeDialog has cognitive complexity 40 (threshold 15). Drivers by points: ternaries 14 (22 pts), if/else 8 (11 pts), boolean chains 7 (nesting depth added 11). Of this number, 20 points are the body's own statements and 20 belong to 6 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
DenseToolMessage.DenseToolMessage (cognitive 40) packages/cli/src/ui/components/messages/DenseToolMessage.tsx:261— DenseToolMessage.DenseToolMessage has cognitive complexity 40 (threshold 15). Drivers by points: if/else 17 (18 pts), boolean chains 16, ternaries 4 (6 pts) (nesting depth added 3). Most of this is not in the body itself: 10 of the 40 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 324, 422, 390, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useShellCompletion.useShellCompletion (cognitive 40) packages/cli/src/ui/hooks/useShellCompletion.ts:443— useShellCompletion.useShellCompletion has cognitive complexity 40 (threshold 15). Drivers by points: if/else 22 (30 pts), boolean chains 5, ternaries 2 (4 pts), error handling 1 (nesting depth added 10). Most of this is not in the body itself: 3 of the 40 points are its own statements and the rest belongs to 8 function literals inside it that branch (lines 489, 616, 458, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
SnapshotGenerator.synthesizeSnapshot (cognitive 40) packages/core/src/context/utils/snapshotGenerator.ts:128— SnapshotGenerator.synthesizeSnapshot has cognitive complexity 40 (threshold 15). Drivers by points: if/else 21 (31 pts), boolean chains 3, error handling 2 (3 pts), loops 2 (3 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sessionUtils.ensureStableToolIds (cognitive 40) packages/core/src/utils/sessionUtils.ts:21— sessionUtils.ensureStableToolIds has cognitive complexity 40 (threshold 15). Drivers by points: if/else 8 (32 pts), boolean chains 5, loops 2 (3 pts) (nesting depth added 25). Of this number, 38 points are the body's own statements and 2 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
install.handleInstall (cognitive 39) packages/cli/src/commands/extensions/install.ts:43— install.handleInstall has cognitive complexity 39 (threshold 15). Drivers by points: if/else 8 (17 pts), loops 4 (17 pts), boolean chains 2, ternaries 2, error handling 1 (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
useAtCompletion.useAtCompletion (cognitive 39) packages/cli/src/ui/hooks/useAtCompletion.ts:206— useAtCompletion.useAtCompletion has cognitive complexity 39 (threshold 15). Drivers by points: if/else 23 (29 pts), boolean chains 5, error handling 3, loops 2 (nesting depth added 6). Most of this is not in the body itself: 0 of the 39 points are its own statements and the rest belongs to 11 function literals inside it that branch (lines 357, 274, 303, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ActivityLogger.patchNodeHttp (cognitive 39) packages/cli/src/utils/activityLogger.ts:441— ActivityLogger.patchNodeHttp has cognitive complexity 39 (threshold 15). Drivers by points: ternaries 9 (14 pts), if/else 13, boolean chains 12 (nesting depth added 5). Most of this is not in the body itself: 0 of the 39 points are its own statements and the rest belongs to 9 function literals inside it that branch (lines 447, 586, 636, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
LocalAgentExecutor.create (cognitive 39) packages/core/src/agents/local-executor.ts:159— LocalAgentExecutor.create has cognitive complexity 39 (threshold 15). Drivers by points: if/else 14 (22 pts), loops 6 (15 pts), boolean chains 2 (nesting depth added 17). Of this number, 17 points are the body's own statements and 22 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
security.isFileAndDirectorySecureSync (cognitive 39) packages/core/src/utils/security.ts:591— security.isFileAndDirectorySecureSync has cognitive complexity 39 (threshold 15). Drivers by points: if/else 14 (25 pts), loops 4 (5 pts), error handling 3 (4 pts), boolean chains 3, ternaries 2 (nesting depth added 13). Of this number, 32 points are the body's own statements and 7 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sync_project_dry_run.run (cognitive 39) scripts/sync_project_dry_run.js:149— sync_project_dry_run.run has cognitive complexity 39 (threshold 15). Drivers by points: if/else 10 (20 pts), loops 6 (9 pts), ternaries 2 (6 pts), boolean chains 4 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
gemini.setupUnhandledRejectionHandler (cognitive 38) packages/cli/src/gemini.tsx:176— gemini.setupUnhandledRejectionHandler has cognitive complexity 38 (threshold 15). Drivers by points: if/else 10 (19 pts), boolean chains 10, error handling 2 (5 pts), ternaries 2 (4 pts) (nesting depth added 14). Most of this is not in the body itself: 2 of the 38 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 225, 185, 300). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
atCommandProcessor.readLocalFiles (cognitive 38) packages/cli/src/ui/hooks/atCommandProcessor.ts:505— atCommandProcessor.readLocalFiles has cognitive complexity 38 (threshold 15). Drivers by points: if/else 9 (24 pts), loops 2 (8 pts), boolean chains 3, ternaries 1 (2 pts), error handling 1 (nesting depth added 22). Of this number, 34 points are the body's own statements and 4 belong to 2 function literals inside it that branch. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
shellReducer.shellReducer (cognitive 38) packages/cli/src/ui/hooks/shellReducer.ts:55— shellReducer.shellReducer has cognitive complexity 38 (threshold 15). Drivers by points: if/else 13 (31 pts), ternaries 2 (5 pts), boolean chains 1, match/switch 1 (nesting depth added 21). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
AgentRegistry.loadAgents (cognitive 38) packages/core/src/agents/registry.ts:160— AgentRegistry.loadAgents has cognitive complexity 38 (threshold 15). Drivers by points: if/else 9 (15 pts), ternaries 3 (9 pts), error handling 3 (6 pts), loops 4 (6 pts), boolean chains 2 (nesting depth added 17). Of this number, 23 points are the body's own statements and 15 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ChatRecordingService.updateMessagesFromHistory (cognitive 38) packages/core/src/services/chatRecordingService.ts:953— ChatRecordingService.updateMessagesFromHistory has cognitive complexity 38 (threshold 15). Drivers by points: if/else 9 (25 pts), boolean chains 8, loops 2 (3 pts), error handling 1, ternaries 1 (nesting depth added 17). Of this number, 31 points are the body's own statements and 7 belong to 2 function literals inside it that branch. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
github.checkForExtensionUpdate (cognitive 37) packages/cli/src/config/extensions/github.ts:171— github.checkForExtensionUpdate has cognitive complexity 37 (threshold 15). Drivers by points: if/else 17 (29 pts), boolean chains 5, error handling 2 (3 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
usePromptCompletion.usePromptCompletion (cognitive 37) packages/cli/src/ui/hooks/usePromptCompletion.ts:35— usePromptCompletion.usePromptCompletion has cognitive complexity 37 (threshold 15). Drivers by points: if/else 19 (23 pts), boolean chains 10, ternaries 1 (3 pts), error handling 1 (nesting depth added 6). Most of this is not in the body itself: 0 of the 37 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 68, 167, 204, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ContextGraphBuilder.processHistory (cognitive 37) packages/core/src/context/graph/toGraph.ts:190— ContextGraphBuilder.processHistory has cognitive complexity 37 (threshold 15). Drivers by points: ternaries 5 (17 pts), if/else 4 (9 pts), loops 3 (7 pts), boolean chains 4 (nesting depth added 21). Of this number, 36 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
EditTool.validateToolParamValues (cognitive 37) packages/core/src/tools/edit.ts:1138— EditTool.validateToolParamValues has cognitive complexity 37 (threshold 15). Drivers by points: ternaries 4 (14 pts), if/else 8 (11 pts), error handling 4 (10 pts), loops 1 (2 pts) (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
McpClientManager.maybeDiscoverMcpServer (cognitive 37) packages/core/src/tools/mcp-client-manager.ts:375— McpClientManager.maybeDiscoverMcpServer has cognitive complexity 37 (threshold 15). Drivers by points: if/else 21 (28 pts), boolean chains 5, error handling 2, ternaries 1 (2 pts) (nesting depth added 8). Of this number, 28 points are the body's own statements and 9 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
index.run (cognitive 36) packages/cli/index.ts:54— index.run has cognitive complexity 36 (threshold 15). Drivers by points: if/else 9 (17 pts), ternaries 2 (7 pts), error handling 2 (5 pts), loops 2 (4 pts), boolean chains 3 (nesting depth added 18). Of this number, 18 points are the body's own statements and 18 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ConfigExtensionDialog.ConfigExtensionDialog (cognitive 36) packages/cli/src/ui/components/ConfigExtensionDialog.tsx:56— ConfigExtensionDialog.ConfigExtensionDialog has cognitive complexity 36 (threshold 15). Drivers by points: if/else 18 (22 pts), boolean chains 8, ternaries 2 (5 pts), error handling 1 (nesting depth added 7). Most of this is not in the body itself: 9 of the 36 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 126, 211, 95, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
DialogManager.DialogManager (cognitive 36) packages/cli/src/ui/components/DialogManager.tsx:50— DialogManager.DialogManager has cognitive complexity 36 (threshold 15). Drivers by points: if/else 30 (31 pts), boolean chains 3, ternaries 1 (2 pts) (nesting depth added 2). Of this number, 34 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
useShellCompletion.resolvePathCompletions (cognitive 36) packages/cli/src/ui/hooks/useShellCompletion.ts:316— useShellCompletion.resolvePathCompletions has cognitive complexity 36 (threshold 15). Drivers by points: if/else 14 (22 pts), ternaries 5 (8 pts), boolean chains 4, error handling 1, loops 1 (nesting depth added 11). Of this number, 33 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
installationInfo.getInstallationInfo (cognitive 36) packages/cli/src/utils/installationInfo.ts:36— installationInfo.getInstallationInfo has cognitive complexity 36 (threshold 15). Drivers by points: if/else 16 (18 pts), ternaries 5 (9 pts), boolean chains 6, error handling 2 (3 pts) (nesting depth added 7). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
nodeDistillationProcessor.createNodeDistillationProcessor (cognitive 36) packages/core/src/context/processors/nodeDistillationProcessor.ts:32— nodeDistillationProcessor.createNodeDistillationProcessor has cognitive complexity 36 (threshold 15). Drivers by points: if/else 7 (24 pts), error handling 2 (6 pts), boolean chains 3, match/switch 1 (2 pts), loops 1 (nesting depth added 22). Most of this is not in the body itself: 0 of the 36 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 75, 37). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
HookRunner.executeCommandHook (cognitive 36) packages/core/src/hooks/hookRunner.ts:307— HookRunner.executeCommandHook has cognitive complexity 36 (threshold 15). Drivers by points: if/else 14 (20 pts), error handling 4 (9 pts), boolean chains 7 (nesting depth added 11). Most of this is not in the body itself: 0 of the 36 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 434, 315, 385, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
paths.shortenPath (cognitive 36) packages/core/src/utils/paths.ts:54— paths.shortenPath has cognitive complexity 36 (threshold 15). Drivers by points: if/else 26 (32 pts), loops 3, boolean chains 1 (nesting depth added 6). Most of this is not in the body itself: 12 of the 36 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 71, 162, 209, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
App.NetworkView (cognitive 36) packages/devtools/client/src/App.tsx:831— App.NetworkView has cognitive complexity 36 (threshold 15). Drivers by points: ternaries 15 (18 pts), if/else 8 (9 pts), boolean chains 6, error handling 2 (3 pts) (nesting depth added 5). Most of this is not in the body itself: 6 of the 36 points are its own statements and the rest belongs to 9 function literals inside it that branch (lines 931, 889, 1081, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
cleanup-branches.main (cognitive 36) scripts/cleanup-branches.ts:18— cleanup-branches.main has cognitive complexity 36 (threshold 15). Drivers by points: error handling 7 (14 pts), if/else 8 (13 pts), loops 2 (6 pts), boolean chains 3 (nesting depth added 16). Of this number, 31 points are the body's own statements and 5 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
summary.calc_summary (cognitive 36) tools/caretaker-agent/evals/triage/helpers/summary.py:221— summary.calc_summary has cognitive complexity 36 (threshold 15). Drivers by points: if/else 14 (22 pts), ternaries 7, boolean chains 3, error handling 1 (2 pts), loops 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
AskUserDialog.AskUserDialog (cognitive 35) packages/cli/src/ui/components/AskUserDialog.tsx:1026— AskUserDialog.AskUserDialog has cognitive complexity 35 (threshold 15). Drivers by points: if/else 17 (18 pts), ternaries 7 (9 pts), boolean chains 8 (nesting depth added 3). Of this number, 16 points are the body's own statements and 19 belong to 8 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
useSelectionList.useSelectionList (cognitive 35) packages/cli/src/ui/hooks/useSelectionList.ts:283— useSelectionList.useSelectionList has cognitive complexity 35 (threshold 15). Drivers by points: if/else 20 (26 pts), boolean chains 9 (nesting depth added 6). Most of this is not in the body itself: 1 of the 35 points is its own statement and the rest belongs to 6 function literals inside it that branch (lines 391, 352, 314, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
models.resolveModel (cognitive 35) packages/core/src/config/models.ts:148— models.resolveModel has cognitive complexity 35 (threshold 15). Drivers by points: if/else 12 (23 pts), boolean chains 6, match/switch 2 (3 pts), ternaries 2 (3 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Scheduler._processNextItem (cognitive 35) packages/core/src/scheduler/scheduler.ts:440— Scheduler._processNextItem has cognitive complexity 35 (threshold 15). Drivers by points: if/else 13 (22 pts), boolean chains 7, loops 3 (6 pts) (nesting depth added 12). Of this number, 33 points are the body's own statements and 2 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sdk.initializeTelemetry (cognitive 35) packages/core/src/telemetry/sdk.ts:165— sdk.initializeTelemetry has cognitive complexity 35 (threshold 15). Drivers by points: if/else 18 (24 pts), boolean chains 8, ternaries 1 (2 pts), error handling 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
grep-utils.enrichWithAutoContext (cognitive 35) packages/core/src/tools/grep-utils.ts:66— grep-utils.enrichWithAutoContext has cognitive complexity 35 (threshold 15). Drivers by points: if/else 6 (21 pts), loops 3 (11 pts), ternaries 1 (2 pts), boolean chains 1 (nesting depth added 24). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
generateContentResponseUtilities.convertToFunctionResponse (cognitive 35) packages/core/src/utils/generateContentResponseUtilities.ts:49— generateContentResponseUtilities.convertToFunctionResponse has cognitive complexity 35 (threshold 15). Drivers by points: if/else 18 (25 pts), boolean chains 7, loops 2, ternaries 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
googleErrors.fromApiError (cognitive 35) packages/core/src/utils/googleErrors.ts:333— googleErrors.fromApiError has cognitive complexity 35 (threshold 15). Drivers by points: if/else 8 (23 pts), error handling 2 (9 pts), boolean chains 3 (nesting depth added 22). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
googleErrors.fromCauseError (cognitive 35) packages/core/src/utils/googleErrors.ts:389— googleErrors.fromCauseError has cognitive complexity 35 (threshold 15). Drivers by points: if/else 11 (22 pts), boolean chains 7, ternaries 5 (6 pts) (nesting depth added 12). Of this number, 31 points are the body's own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
changed_prompt.main (cognitive 35) scripts/changed_prompt.js:23— changed_prompt.main has cognitive complexity 35 (threshold 15). Drivers by points: if/else 9 (23 pts), boolean chains 5, loops 2 (4 pts), ternaries 2, error handling 1 (nesting depth added 16). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
eval-coverage.formatCoverageReport (cognitive 35) scripts/utils/eval-coverage.ts:196— eval-coverage.formatCoverageReport has cognitive complexity 35 (threshold 15). Drivers by points: if/else 9 (14 pts), loops 6 (13 pts), ternaries 2 (6 pts), boolean chains 2 (nesting depth added 16). Of this number, 32 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
markdownParsingUtils.parseMarkdownToANSI (cognitive 34) packages/cli/src/ui/utils/markdownParsingUtils.ts:106— markdownParsingUtils.parseMarkdownToANSI has cognitive complexity 34 (threshold 15). Drivers by points: if/else 13 (19 pts), boolean chains 12, error handling 1 (2 pts), loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
setup._doSetupUser (cognitive 34) packages/core/src/code_assist/setup.ts:153— setup._doSetupUser has cognitive complexity 34 (threshold 15). Drivers by points: if/else 13 (26 pts), boolean chains 3, loops 2 (3 pts), error handling 1 (2 pts) (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
rollingSummaryProcessor.createRollingSummaryProcessor (cognitive 34) packages/core/src/context/processors/rollingSummaryProcessor.ts:43— rollingSummaryProcessor.createRollingSummaryProcessor has cognitive complexity 34 (threshold 15). Drivers by points: if/else 13 (25 pts), loops 2 (5 pts), boolean chains 3, error handling 1 (nesting depth added 15). Most of this is not in the body itself: 0 of the 34 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 74, 48). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
GrepToolInvocation.execute (cognitive 34) packages/core/src/tools/grep.ts:146— GrepToolInvocation.execute has cognitive complexity 34 (threshold 15). Drivers by points: if/else 13 (20 pts), error handling 4 (6 pts), ternaries 2 (4 pts), boolean chains 3, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
create-patch-pr.main (cognitive 34) scripts/releasing/create-patch-pr.js:13— create-patch-pr.main has cognitive complexity 34 (threshold 15). Drivers by points: if/else 17 (22 pts), error handling 4 (9 pts), boolean chains 3 (nesting depth added 10). Of this number, 33 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
eval-coverage.computeCoverage (cognitive 34) scripts/utils/eval-coverage.ts:66— eval-coverage.computeCoverage has cognitive complexity 34 (threshold 15). Drivers by points: if/else 10 (21 pts), loops 7 (11 pts), boolean chains 1, ternaries 1 (nesting depth added 15). Of this number, 30 points are the body's own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Task.scheduleToolCalls (cognitive 33) packages/a2a-server/src/agent/task.ts:711— Task.scheduleToolCalls has cognitive complexity 33 (threshold 15). Drivers by points: if/else 10 (22 pts), loops 3 (8 pts), boolean chains 3 (nesting depth added 17). Of this number, 25 points are the body's own statements and 8 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
MainContent.MainContent (cognitive 33) packages/cli/src/ui/components/MainContent.tsx:33— MainContent.MainContent has cognitive complexity 33 (threshold 15). Drivers by points: boolean chains 15, if/else 10 (11 pts), ternaries 5 (6 pts), loops 1 (nesting depth added 2). Most of this is not in the body itself: 2 of the 33 points are its own statements and the rest belongs to 9 function literals inside it that branch (lines 157, 85, 256, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
DiffRenderer.renderDiffLines (cognitive 33) packages/cli/src/ui/components/messages/DiffRenderer.tsx:232— DiffRenderer.renderDiffLines has cognitive complexity 33 (threshold 15). Drivers by points: ternaries 10 (17 pts), if/else 7 (9 pts), boolean chains 5, loops 1, match/switch 1 (nesting depth added 9). Most of this is not in the body itself: 10 of the 33 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 292, 250). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useToolScheduler.useToolScheduler (cognitive 33) packages/cli/src/ui/hooks/useToolScheduler.ts:71— useToolScheduler.useToolScheduler has cognitive complexity 33 (threshold 15). Drivers by points: if/else 10 (16 pts), boolean chains 7, loops 3 (5 pts), error handling 1 (3 pts), ternaries 2 (nesting depth added 10). Most of this is not in the body itself: 0 of the 33 points are its own statements and the rest belongs to 9 function literals inside it that branch (lines 256, 290, 130, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
deepMerge.mergeRecursively (cognitive 33) packages/cli/src/utils/deepMerge.ts:24— deepMerge.mergeRecursively has cognitive complexity 33 (threshold 15). Drivers by points: if/else 9 (18 pts), ternaries 3 (9 pts), boolean chains 5, loops 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ChatRecordingService.initialize (cognitive 33) packages/core/src/services/chatRecordingService.ts:418— ChatRecordingService.initialize has cognitive complexity 33 (threshold 15). Drivers by points: if/else 12 (24 pts), loops 1 (4 pts), boolean chains 2, ternaries 1 (2 pts), error handling 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
UiTelemetryService.hydrate (cognitive 33) packages/core/src/telemetry/uiTelemetry.ts:222— UiTelemetryService.hydrate has cognitive complexity 33 (threshold 15). Drivers by points: if/else 8 (25 pts), loops 2 (5 pts), boolean chains 3 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
WriteFileToolInvocation.execute (cognitive 33) packages/core/src/tools/write-file.ts:370— WriteFileToolInvocation.execute has cognitive complexity 33 (threshold 15). Drivers by points: if/else 13 (18 pts), ternaries 7 (8 pts), boolean chains 5, error handling 2 (nesting depth added 6). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
Session.runTool (cognitive 32) packages/cli/src/acp/acpSession.ts:659— Session.runTool has cognitive complexity 32 (threshold 15). Drivers by points: ternaries 9 (16 pts), if/else 7 (10 pts), boolean chains 3, match/switch 1 (2 pts), error handling 1 (nesting depth added 11). Of this number, 30 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
settings.migrateExperimentalSettings (cognitive 32) packages/cli/src/config/settings.ts:1273— settings.migrateExperimentalSettings has cognitive complexity 32 (threshold 15). Drivers by points: if/else 13 (28 pts), boolean chains 4 (nesting depth added 15). Most of this is not in the body itself: 7 of the 32 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 1308, 1368, 1294, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
AuthDialog.AuthDialog (cognitive 32) packages/cli/src/ui/auth/AuthDialog.tsx:36— AuthDialog.AuthDialog has cognitive complexity 32 (threshold 15). Drivers by points: if/else 18 (23 pts), boolean chains 5, ternaries 3 (4 pts) (nesting depth added 6). Most of this is not in the body itself: 9 of the 32 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 117, 171, 97, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
HistoryItemDisplay.HistoryItemDisplay (cognitive 32) packages/cli/src/ui/components/HistoryItemDisplay.tsx:58— HistoryItemDisplay.HistoryItemDisplay has cognitive complexity 32 (threshold 15). Drivers by points: boolean chains 31, ternaries 1. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
ExtensionDetails.ExtensionDetails (cognitive 32) packages/cli/src/ui/components/views/ExtensionDetails.tsx:31— ExtensionDetails.ExtensionDetails has cognitive complexity 32 (threshold 15). Drivers by points: boolean chains 20, if/else 9 (11 pts), ternaries 1 (nesting depth added 2). Of this number, 19 points are the body's own statements and 13 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
clipboardUtils.saveClipboardImage (cognitive 32) packages/cli/src/ui/utils/clipboardUtils.ts:272— clipboardUtils.saveClipboardImage has cognitive complexity 32 (threshold 15). Drivers by points: if/else 10 (22 pts), error handling 4 (9 pts), loops 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
EditToolInvocation.execute (cognitive 32) packages/core/src/tools/edit.ts:904— EditToolInvocation.execute has cognitive complexity 32 (threshold 15). Drivers by points: if/else 11 (13 pts), ternaries 5 (10 pts), error handling 3 (5 pts), boolean chains 4 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
RecursiveFileSearch.search (cognitive 32) packages/core/src/utils/filesearch/fileSearch.ts:259— RecursiveFileSearch.search has cognitive complexity 32 (threshold 15). Drivers by points: if/else 13 (23 pts), boolean chains 5, error handling 1 (3 pts), loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
partUtils.partToString (cognitive 32) packages/core/src/utils/partUtils.ts:18— partUtils.partToString has cognitive complexity 32 (threshold 15). Drivers by points: if/else 12 (20 pts), ternaries 3 (12 pts) (nesting depth added 17). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
IDEServer.start (cognitive 32) packages/vscode-ide-companion/src/ide-server.ts:138— IDEServer.start has cognitive complexity 32 (threshold 15). Drivers by points: if/else 15 (18 pts), boolean chains 7, ternaries 2 (4 pts), error handling 2, loops 1 (nesting depth added 5). Most of this is not in the body itself: 0 of the 32 points are its own statements and the rest belongs to 11 function literals inside it that branch (lines 213, 295, 174, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
settings.loadEnvironment (cognitive 31) packages/cli/src/config/settings.ts:655— settings.loadEnvironment has cognitive complexity 31 (threshold 15). Drivers by points: if/else 7 (22 pts), boolean chains 4, error handling 1 (2 pts), loops 1 (2 pts), ternaries 1 (nesting depth added 17). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
Scrollable.Scrollable (cognitive 31) packages/cli/src/ui/components/shared/Scrollable.tsx:41— Scrollable.Scrollable has cognitive complexity 31 (threshold 15). Drivers by points: if/else 15 (25 pts), boolean chains 5, ternaries 1 (nesting depth added 10). Most of this is not in the body itself: 1 of the 31 points is its own statement and the rest belongs to 9 function literals inside it that branch (lines 189, 145, 76, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
activityLogger.setupNetworkLogging (cognitive 31) packages/cli/src/utils/activityLogger.ts:734— activityLogger.setupNetworkLogging has cognitive complexity 31 (threshold 15). Drivers by points: if/else 11 (13 pts), boolean chains 10, ternaries 2 (3 pts), error handling 2, loops 2, match/switch 1 (nesting depth added 3). Most of this is not in the body itself: 0 of the 31 points are its own statements and the rest belongs to 10 function literals inside it that branch (lines 764, 855, 877, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
MockAgentProtocol.send (cognitive 31) packages/core/src/agent/mock.ts:108— MockAgentProtocol.send has cognitive complexity 31 (threshold 15). Drivers by points: if/else 13 (18 pts), boolean chains 5, ternaries 3 (5 pts), loops 2 (3 pts) (nesting depth added 8). Of this number, 29 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
A2AResultReassembler.update (cognitive 31) packages/core/src/agents/a2aUtils.ts:35— A2AResultReassembler.update has cognitive complexity 31 (threshold 15). Drivers by points: if/else 10 (21 pts), loops 2 (7 pts), boolean chains 2, match/switch 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
browserAgentFactory.createBrowserAgentDefinition (cognitive 31) packages/core/src/agents/browser/browserAgentFactory.ts:68— browserAgentFactory.createBrowserAgentDefinition has cognitive complexity 31 (threshold 15). Drivers by points: if/else 13 (22 pts), loops 2 (4 pts), boolean chains 3, error handling 1, ternaries 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
BrowserManager.connectMcp (cognitive 31) packages/core/src/agents/browser/browserManager.ts:559— BrowserManager.connectMcp has cognitive complexity 31 (threshold 15). Drivers by points: if/else 15 (18 pts), boolean chains 5, error handling 2 (4 pts), ternaries 3 (4 pts) (nesting depth added 6). Of this number, 29 points are the body's own statements and 2 belong to 2 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
ProjectRegistry.claimNewSlug (cognitive 31) packages/core/src/config/projectRegistry.ts:304— ProjectRegistry.claimNewSlug has cognitive complexity 31 (threshold 15). Drivers by points: if/else 5 (14 pts), error handling 2 (6 pts), ternaries 2 (5 pts), boolean chains 3, loops 2 (3 pts) (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
HookAggregator.mergeWithOrDecision (cognitive 31) packages/core/src/hooks/hookAggregator.ts:116— HookAggregator.mergeWithOrDecision has cognitive complexity 31 (threshold 15). Drivers by points: if/else 15 (26 pts), boolean chains 4, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ide-connection-utils.getConnectionConfigFromFile (cognitive 31) packages/core/src/ide/ide-connection-utils.ts:132— ide-connection-utils.getConnectionConfigFromFile has cognitive complexity 31 (threshold 15). Drivers by points: if/else 17 (24 pts), boolean chains 4, error handling 3 (nesting depth added 7). Of this number, 24 points are the body's own statements and 7 belong to 6 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
GrepToolInvocation.performRipgrepSearch (cognitive 31) packages/core/src/tools/ripGrep.ts:409— GrepToolInvocation.performRipgrepSearch has cognitive complexity 31 (threshold 15). Drivers by points: if/else 16 (24 pts), loops 2 (3 pts), boolean chains 2, error handling 1, ternaries 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
AgentRunner.run_agent (cognitive 31) tools/caretaker-agent/cloudrun/pr-generator/workflow/agent_runner.py:123— AgentRunner.run_agent has cognitive complexity 31 (threshold 15). Drivers by points: if/else 12 (22 pts), loops 4 (7 pts), boolean chains 1, error handling 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
gemini.resolveSessionId (cognitive 30) packages/cli/src/gemini.tsx:319— gemini.resolveSessionId has cognitive complexity 30 (threshold 15). Drivers by points: if/else 8 (14 pts), boolean chains 5, ternaries 2 (5 pts), error handling 2 (3 pts), loops 1 (3 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
FooterConfigDialog.FooterConfigDialog (cognitive 30) packages/cli/src/ui/components/FooterConfigDialog.tsx:87— FooterConfigDialog.FooterConfigDialog has cognitive complexity 30 (threshold 15). Drivers by points: if/else 13 (15 pts), ternaries 8 (9 pts), boolean chains 6 (nesting depth added 3). Most of this is not in the body itself: 4 of the 30 points are its own statements and the rest belongs to 7 function literals inside it that branch (lines 185, 338, 168, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
clipboardUtils.splitDragAndDropPaths (cognitive 30) packages/cli/src/ui/utils/clipboardUtils.ts:442— clipboardUtils.splitDragAndDropPaths has cognitive complexity 30 (threshold 15). Drivers by points: if/else 15 (28 pts), boolean chains 1, loops 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
stateSnapshotProcessor.createStateSnapshotProcessor (cognitive 30) packages/core/src/context/processors/stateSnapshotProcessor.ts:46— stateSnapshotProcessor.createStateSnapshotProcessor has cognitive complexity 30 (threshold 15). Drivers by points: if/else 17 (24 pts), loops 2 (3 pts), boolean chains 1, error handling 1, ternaries 1 (nesting depth added 8). Most of this is not in the body itself: 0 of the 30 points are its own statements and the rest belongs to one function literal inside it that branches (line 56). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
PolicyEngine.getExcludedTools (cognitive 30) packages/core/src/policy/policy-engine.ts:1027— PolicyEngine.getExcludedTools has cognitive complexity 30 (threshold 15). Drivers by points: if/else 9 (24 pts), loops 2 (3 pts), ternaries 1 (2 pts), boolean chains 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
AllowedPathChecker.check (cognitive 30) packages/core/src/safety/built-in.ts:33— AllowedPathChecker.check has cognitive complexity 30 (threshold 15). Drivers by points: if/else 8 (21 pts), loops 4 (8 pts), boolean chains 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
memoryService.buildExistingSkillsSummary (cognitive 30) packages/core/src/services/memoryService.ts:729— memoryService.buildExistingSkillsSummary has cognitive complexity 30 (threshold 15). Drivers by points: if/else 13 (21 pts), error handling 3 (4 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
download-ripgrep-binaries.downloadBinary (cognitive 30) scripts/download-ripgrep-binaries.ts:50— download-ripgrep-binaries.downloadBinary has cognitive complexity 30 (threshold 15). Drivers by points: if/else 13 (27 pts), ternaries 1 (2 pts), loops 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
telemetry_utils.manageTelemetrySettings (cognitive 30) scripts/telemetry_utils.js:315— telemetry_utils.manageTelemetrySettings has cognitive complexity 30 (threshold 15). Drivers by points: if/else 16 (27 pts), ternaries 1 (2 pts), boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sandboxConfig.getSandboxCommand (cognitive 29) packages/cli/src/config/sandboxConfig.ts:43— sandboxConfig.getSandboxCommand has cognitive complexity 29 (threshold 15). Drivers by points: if/else 14 (19 pts), boolean chains 10 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
mcpCommand.listAction (cognitive 29) packages/cli/src/ui/commands/mcpCommand.ts:177— mcpCommand.listAction has cognitive complexity 29 (threshold 15). Drivers by points: if/else 11 (19 pts), boolean chains 7, loops 3 (nesting depth added 8). Of this number, 28 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
useExtensionUpdates.useExtensionUpdates (cognitive 29) packages/cli/src/ui/hooks/useExtensionUpdates.ts:83— useExtensionUpdates.useExtensionUpdates has cognitive complexity 29 (threshold 15). Drivers by points: if/else 14 (21 pts), boolean chains 2, error handling 1 (2 pts), loops 2, ternaries 1 (2 pts) (nesting depth added 9). Most of this is not in the body itself: 0 of the 29 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 118, 95, 94, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
borderStyles.getToolGroupBorderAppearance (cognitive 29) packages/cli/src/ui/utils/borderStyles.ts:33— borderStyles.getToolGroupBorderAppearance has cognitive complexity 29 (threshold 15). Drivers by points: boolean chains 15, if/else 7, ternaries 4 (7 pts) (nesting depth added 3). Of this number, 18 points are the body's own statements and 11 belong to 4 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
highlight.parseInputForHighlighting (cognitive 29) packages/cli/src/ui/utils/highlight.ts:36— highlight.parseInputForHighlighting has cognitive complexity 29 (threshold 15). Drivers by points: if/else 9 (13 pts), ternaries 5 (9 pts), loops 3 (4 pts), boolean chains 3 (nesting depth added 9). Of this number, 15 points are the body's own statements and 14 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
atCommandUtils.resolveAtCommandPath (cognitive 29) packages/core/src/utils/atCommandUtils.ts:35— atCommandUtils.resolveAtCommandPath has cognitive complexity 29 (threshold 15). Drivers by points: if/else 9 (18 pts), boolean chains 4, error handling 2 (4 pts), loops 2 (3 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
paths.robustRealpath (cognitive 29) packages/core/src/utils/paths.ts:459— paths.robustRealpath has cognitive complexity 29 (threshold 15). Drivers by points: if/else 8 (17 pts), boolean chains 6, error handling 2 (4 pts), ternaries 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
shell-utils.detectBashSubstitution (cognitive 29) packages/core/src/utils/shell-utils.ts:1095— shell-utils.detectBashSubstitution has cognitive complexity 29 (threshold 15). Drivers by points: if/else 10 (22 pts), boolean chains 6, loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
get-release-version.detectRollbackAndGetBaseline (cognitive 29) scripts/get-release-version.js:124— get-release-version.detectRollbackAndGetBaseline has cognitive complexity 29 (threshold 15). Drivers by points: if/else 12 (18 pts), error handling 2 (6 pts), boolean chains 3, loops 1, ternaries 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
eval-inventory.formatInventoryReport (cognitive 29) scripts/utils/eval-inventory.ts:94— eval-inventory.formatInventoryReport has cognitive complexity 29 (threshold 15). Drivers by points: loops 10 (19 pts), if/else 6 (8 pts), boolean chains 2 (nesting depth added 11). Of this number, 26 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline.
config.refreshAuthentication (cognitive 28) packages/a2a-server/src/config/config.ts:644— config.refreshAuthentication has cognitive complexity 28 (threshold 15). Drivers by points: ternaries 3 (12 pts), if/else 5 (10 pts), error handling 2 (5 pts), boolean chains 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
SlicingMaxSizedBox.SlicingMaxSizedBox (cognitive 28) packages/cli/src/ui/components/shared/SlicingMaxSizedBox.tsx:27— SlicingMaxSizedBox.SlicingMaxSizedBox has cognitive complexity 28 (threshold 15). Drivers by points: if/else 10 (20 pts), ternaries 2 (6 pts), boolean chains 2 (nesting depth added 14). Most of this is not in the body itself: 0 of the 28 points are its own statements and the rest belongs to one function literal inside it that branches (line 34). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
sessionUtils.formatRelativeTime (cognitive 28) packages/cli/src/utils/sessionUtils.ts:193— sessionUtils.formatRelativeTime has cognitive complexity 28 (threshold 15). Drivers by points: if/else 11 (17 pts), ternaries 4 (11 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
telemetry.summarizeToolCalls (cognitive 28) packages/core/src/code_assist/telemetry.ts:117— telemetry.summarizeToolCalls has cognitive complexity 28 (threshold 15). Drivers by points: if/else 7 (22 pts), boolean chains 4, loops 1, ternaries 1 (nesting depth added 15). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
memory.listInboxMemoryPatches (cognitive 28) packages/core/src/commands/memory.ts:449— memory.listInboxMemoryPatches has cognitive complexity 28 (threshold 15). Drivers by points: if/else 5 (14 pts), error handling 2 (6 pts), loops 3 (6 pts), boolean chains 2 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
config.createPolicyUpdater (cognitive 28) packages/core/src/policy/config.ts:712— config.createPolicyUpdater has cognitive complexity 28 (threshold 15). Drivers by points: if/else 7 (12 pts), boolean chains 8, ternaries 3 (6 pts), loops 1 (2 pts) (nesting depth added 9). Most of this is not in the body itself: 0 of the 28 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 722, 796). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
sessionSummaryUtils.getPreviousSession (cognitive 28) packages/core/src/services/sessionSummaryUtils.ts:460— sessionSummaryUtils.getPreviousSession has cognitive complexity 28 (threshold 15). Drivers by points: if/else 9 (16 pts), error handling 3 (4 pts), ternaries 2 (4 pts), boolean chains 3, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ToolRegistry.discoverAndRegisterToolsFromCommand (cognitive 28) packages/core/src/tools/tool-registry.ts:376— ToolRegistry.discoverAndRegisterToolsFromCommand has cognitive complexity 28 (threshold 15). Drivers by points: if/else 16 (20 pts), boolean chains 3, loops 2, ternaries 1 (2 pts), error handling 1 (nesting depth added 5). Of this number, 22 points are the body's own statements and 6 belong to 3 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
tools.hasCycleInSchema (cognitive 28) packages/core/src/tools/tools.ts:798— tools.hasCycleInSchema has cognitive complexity 28 (threshold 15). Drivers by points: if/else 11 (20 pts), boolean chains 4, loops 3 (4 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
memoryDiscovery.readGeminiMdFiles (cognitive 28) packages/core/src/utils/memoryDiscovery.ts:209— memoryDiscovery.readGeminiMdFiles has cognitive complexity 28 (threshold 15). Drivers by points: if/else 5 (12 pts), ternaries 2 (9 pts), loops 2 (3 pts), boolean chains 2, error handling 1 (2 pts) (nesting depth added 16). Most of this is not in the body itself: 11 of the 28 points are its own statements and the rest belongs to one function literal inside it that branches (line 221). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
oauth-flow.parseTokenEndpointResponse (cognitive 28) packages/core/src/utils/oauth-flow.ts:485— oauth-flow.parseTokenEndpointResponse has cognitive complexity 28 (threshold 15). Drivers by points: boolean chains 10, ternaries 5 (9 pts), if/else 5 (6 pts), error handling 2 (3 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
aggregate_evals.generateMarkdown (cognitive 28) scripts/aggregate_evals.js:147— aggregate_evals.generateMarkdown has cognitive complexity 28 (threshold 15). Drivers by points: if/else 6 (13 pts), loops 5 (10 pts), ternaries 2 (5 pts) (nesting depth added 15). Of this number, 26 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
config.loadConfig (cognitive 27) packages/a2a-server/src/config/config.ts:251— config.loadConfig has cognitive complexity 27 (threshold 15). Drivers by points: if/else 10 (17 pts), boolean chains 7, ternaries 3 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ShellProcessor.processString (cognitive 27) packages/cli/src/services/prompt-processors/shellProcessor.ts:65— ShellProcessor.processString has cognitive complexity 27 (threshold 15). Drivers by points: if/else 14 (22 pts), boolean chains 3, loops 2 (nesting depth added 8). Of this number, 26 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
AgentConfigDialog.AgentConfigDialog (cognitive 27) packages/cli/src/ui/components/AgentConfigDialog.tsx:190— AgentConfigDialog.AgentConfigDialog has cognitive complexity 27 (threshold 15). Drivers by points: if/else 13 (16 pts), ternaries 6, boolean chains 4, loops 1 (nesting depth added 3). Most of this is not in the body itself: 1 of the 27 points is its own statement and the rest belongs to 8 function literals inside it that branch (lines 258, 335, 308, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
LoadingIndicator.LoadingIndicator (cognitive 27) packages/cli/src/ui/components/LoadingIndicator.tsx:36— LoadingIndicator.LoadingIndicator has cognitive complexity 27 (threshold 15). Drivers by points: boolean chains 16, ternaries 7 (9 pts), if/else 2 (nesting depth added 2). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
SubagentProgressDisplay.SubagentProgressDisplay (cognitive 27) packages/cli/src/ui/components/messages/SubagentProgressDisplay.tsx:62— SubagentProgressDisplay.SubagentProgressDisplay has cognitive complexity 27 (threshold 15). Drivers by points: ternaries 6 (15 pts), boolean chains 6, if/else 6 (nesting depth added 9). Most of this is not in the body itself: 7 of the 27 points are its own statements and the rest belongs to one function literal inside it that branches (line 91). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
ToolGroupDisplay.ToolGroupDisplay (cognitive 27) packages/cli/src/ui/components/messages/ToolGroupDisplay.tsx:25— ToolGroupDisplay.ToolGroupDisplay has cognitive complexity 27 (threshold 15). Drivers by points: ternaries 9 (17 pts), boolean chains 8, if/else 2 (nesting depth added 8). Of this number, 20 points are the body's own statements and 7 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
AgentRegistry.registerRemoteAgent (cognitive 27) packages/core/src/agents/registry.ts:453— AgentRegistry.registerRemoteAgent has cognitive complexity 27 (threshold 15). Drivers by points: if/else 18 (22 pts), boolean chains 4, error handling 1 (nesting depth added 4). Of this number, 26 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
ContextManager.renderHistory (cognitive 27) packages/core/src/context/contextManager.ts:90— ContextManager.renderHistory has cognitive complexity 27 (threshold 15). Drivers by points: if/else 11 (15 pts), boolean chains 6, loops 3 (4 pts), ternaries 2 (nesting depth added 5). Of this number, 23 points are the body's own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
HookRunner.applyHookOutputToInput (cognitive 27) packages/core/src/hooks/hookRunner.ts:172— HookRunner.applyHookOutputToInput has cognitive complexity 27 (threshold 15). Drivers by points: if/else 7 (22 pts), boolean chains 3, match/switch 1 (2 pts) (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
HookTranslatorGenAIv1.toHookLLMRequest (cognitive 27) packages/core/src/hooks/hookTranslator.ts:163— HookTranslatorGenAIv1.toHookLLMRequest has cognitive complexity 27 (threshold 15). Drivers by points: ternaries 4 (15 pts), if/else 4 (9 pts), loops 1 (2 pts), boolean chains 1 (nesting depth added 17). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
ide-installer.findCommand (cognitive 27) REDACTED:24— ide-installer.findCommand has cognitive complexity 27 (threshold 15). Drivers by points: if/else 13 (22 pts), boolean chains 3, error handling 1, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
oauth-utils.validateOAuthEndpointUrl (cognitive 27) packages/core/src/mcp/oauth-utils.ts:62— oauth-utils.validateOAuthEndpointUrl has cognitive complexity 27 (threshold 15). Drivers by points: if/else 11 (15 pts), error handling 4 (6 pts), boolean chains 5, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
AskUserTool.validateToolParamValues (cognitive 27) packages/core/src/tools/ask-user.ts:45— AskUserTool.validateToolParamValues has cognitive complexity 27 (threshold 15). Drivers by points: if/else 7 (19 pts), boolean chains 4, loops 2 (4 pts) (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
RipGrepTool.validateToolParamValues (cognitive 27) packages/core/src/tools/ripGrep.ts:659— RipGrepTool.validateToolParamValues has cognitive complexity 27 (threshold 15). Drivers by points: if/else 8 (12 pts), error handling 4 (8 pts), boolean chains 4, ternaries 1 (3 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
memoryDiscovery.findProjectRoot (cognitive 27) packages/core/src/utils/memoryDiscovery.ts:150— memoryDiscovery.findProjectRoot has cognitive complexity 27 (threshold 15). Drivers by points: if/else 6 (16 pts), boolean chains 5, error handling 1 (3 pts), loops 2 (3 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
shell-utils.detectPowerShellSubstitution (cognitive 27) packages/core/src/utils/shell-utils.ts:1148— shell-utils.detectPowerShellSubstitution has cognitive complexity 27 (threshold 15). Drivers by points: if/else 9 (20 pts), boolean chains 6, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
get_trustworthy_evals.main (cognitive 27) scripts/get_trustworthy_evals.js:26— get_trustworthy_evals.main has cognitive complexity 27 (threshold 15). Drivers by points: if/else 11 (21 pts), loops 3 (4 pts), boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
local_telemetry.main (cognitive 27) scripts/local_telemetry.js:71— local_telemetry.main has cognitive complexity 27 (threshold 15). Drivers by points: if/else 13 (19 pts), error handling 6, boolean chains 2 (nesting depth added 6). Of this number, 26 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
app.createApp (cognitive 26) packages/a2a-server/src/http/app.ts:197— app.createApp has cognitive complexity 26 (threshold 15). Drivers by points: if/else 11 (13 pts), ternaries 3 (6 pts), error handling 4, boolean chains 2, loops 1 (nesting depth added 5). Most of this is not in the body itself: 7 of the 26 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 356, 284, 385, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ModelStatsDisplay.ModelStatsDisplay (cognitive 26) packages/cli/src/ui/components/ModelStatsDisplay.tsx:48— ModelStatsDisplay.ModelStatsDisplay has cognitive complexity 26 (threshold 15). Drivers by points: if/else 13 (14 pts), boolean chains 8, ternaries 4 (nesting depth added 1). Most of this is not in the body itself: 12 of the 26 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 304, 102, 256, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ValidationDialog.ValidationDialog (cognitive 26) packages/cli/src/ui/components/ValidationDialog.tsx:31— ValidationDialog.ValidationDialog has cognitive complexity 26 (threshold 15). Drivers by points: if/else 11 (14 pts), boolean chains 5, ternaries 1 (4 pts), error handling 1 (3 pts) (nesting depth added 8). Most of this is not in the body itself: 6 of the 26 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 81, 55, 70). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ExpandableText._ExpandableText (cognitive 26) packages/cli/src/ui/components/shared/ExpandableText.tsx:23— ExpandableText._ExpandableText has cognitive complexity 26 (threshold 15). Drivers by points: if/else 13 (23 pts), boolean chains 2, ternaries 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
MouseContext.MouseProvider (cognitive 26) packages/cli/src/ui/contexts/MouseContext.tsx:63— MouseContext.MouseProvider has cognitive complexity 26 (threshold 15). Drivers by points: if/else 12 (19 pts), loops 3 (5 pts), boolean chains 2 (nesting depth added 9). Most of this is not in the body itself: 0 of the 26 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 102, 148, 95). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
CodeColorizer.colorizeCode (cognitive 26) packages/cli/src/ui/utils/CodeColorizer.tsx:155— CodeColorizer.colorizeCode has cognitive complexity 26 (threshold 15). Drivers by points: ternaries 7 (10 pts), if/else 6 (9 pts), boolean chains 6, error handling 1 (nesting depth added 6). Of this number, 20 points are the body's own statements and 6 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
TerminalCapabilityManager.detectCapabilities (cognitive 26) packages/cli/src/ui/utils/terminalCapabilityManager.ts:105— TerminalCapabilityManager.detectCapabilities has cognitive complexity 26 (threshold 15). Drivers by points: if/else 16 (22 pts), boolean chains 3, error handling 1 (nesting depth added 6). Most of this is not in the body itself: 3 of the 26 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 151, 120, 135). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
sandboxUtils.safeResolveToRealPath (cognitive 26) packages/cli/src/utils/sandboxUtils.ts:106— sandboxUtils.safeResolveToRealPath has cognitive complexity 26 (threshold 15). Drivers by points: if/else 4 (14 pts), error handling 2 (6 pts), boolean chains 3, ternaries 1 (2 pts), loops 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sessionUtils.convertSessionToHistoryFormats (cognitive 26) packages/cli/src/utils/sessionUtils.ts:574— sessionUtils.convertSessionToHistoryFormats has cognitive complexity 26 (threshold 15). Drivers by points: if/else 4 (8 pts), boolean chains 6, ternaries 2 (5 pts), loops 2 (4 pts), match/switch 1 (3 pts) (nesting depth added 11). Of this number, 21 points are the body's own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
LocalAgentExecutor.callModel (cognitive 26) packages/core/src/agents/local-executor.ts:955— LocalAgentExecutor.callModel has cognitive complexity 26 (threshold 15). Drivers by points: if/else 8 (17 pts), boolean chains 5, error handling 1 (3 pts), loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PromptProvider.getCoreSystemPrompt (cognitive 26) packages/core/src/prompts/promptProvider.ts:47— PromptProvider.getCoreSystemPrompt has cognitive complexity 26 (threshold 15). Drivers by points: if/else 8 (11 pts), ternaries 6 (10 pts), boolean chains 5 (nesting depth added 7). Of this number, 22 points are the body's own statements and 4 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sessionSummaryUtils.generateAndSaveSummary (cognitive 26) packages/core/src/services/sessionSummaryUtils.ts:324— sessionSummaryUtils.generateAndSaveSummary has cognitive complexity 26 (threshold 15). Drivers by points: if/else 17 (22 pts), boolean chains 3, ternaries 1 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
compare_evals.main (cognitive 26) scripts/compare_evals.js:22— compare_evals.main has cognitive complexity 26 (threshold 15). Drivers by points: if/else 8 (13 pts), ternaries 2 (6 pts), loops 3 (5 pts), boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
settings-validation.buildZodSchemaFromJsonSchema (cognitive 25) packages/cli/src/config/settings-validation.ts:17— settings-validation.buildZodSchemaFromJsonSchema has cognitive complexity 25 (threshold 15). Drivers by points: if/else 14 (21 pts), loops 1 (3 pts), boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
settings.findEnvFile (cognitive 25) packages/cli/src/config/settings.ts:561— settings.findEnvFile has cognitive complexity 25 (threshold 15). Drivers by points: if/else 8 (22 pts), boolean chains 2, loops 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
HooksDialog.HooksDialog (cognitive 25) packages/cli/src/ui/components/HooksDialog.tsx:48— HooksDialog.HooksDialog has cognitive complexity 25 (threshold 15). Drivers by points: boolean chains 10, if/else 6 (9 pts), ternaries 4 (6 pts) (nesting depth added 5). Most of this is not in the body itself: 6 of the 25 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 176, 93, 66). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
Notifications.Notifications (cognitive 25) packages/cli/src/ui/components/Notifications.tsx:37— Notifications.Notifications has cognitive complexity 25 (threshold 15). Drivers by points: boolean chains 12, if/else 10 (12 pts), error handling 1 (nesting depth added 2). Most of this is not in the body itself: 8 of the 25 points are its own statements and the rest belongs to 8 function literals inside it that branch (lines 71, 55, 59, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
VoiceModelDialog.VoiceModelDialog (cognitive 25) packages/cli/src/ui/components/VoiceModelDialog.tsx:52— VoiceModelDialog.VoiceModelDialog has cognitive complexity 25 (threshold 15). Drivers by points: ternaries 8 (13 pts), if/else 7 (8 pts), boolean chains 2, error handling 1 (2 pts) (nesting depth added 7). Most of this is not in the body itself: 10 of the 25 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 113, 76, 93, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
activityLogger.callHttpRequest (cognitive 25) packages/cli/src/utils/activityLogger.ts:54— activityLogger.callHttpRequest has cognitive complexity 25 (threshold 15). Drivers by points: if/else 11 (20 pts), boolean chains 5 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
agentLoader.markdownToAgentDefinition (cognitive 25) packages/core/src/agents/agentLoader.ts:497— agentLoader.markdownToAgentDefinition has cognitive complexity 25 (threshold 15). Drivers by points: if/else 7 (14 pts), boolean chains 5, ternaries 3 (4 pts), loops 1 (2 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
RemoteSessionInvocation.execute (cognitive 25) packages/core/src/agents/remote-session-invocation.ts:117— RemoteSessionInvocation.execute has cognitive complexity 25 (threshold 15). Drivers by points: if/else 9 (13 pts), ternaries 4 (8 pts), boolean chains 3, error handling 1 (nesting depth added 8). Of this number, 21 points are the body's own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
CodeAssistServer.generateContentStream (cognitive 25) packages/core/src/code_assist/server.ts:93— CodeAssistServer.generateContentStream has cognitive complexity 25 (threshold 15). Drivers by points: if/else 6 (12 pts), boolean chains 7, loops 2 (4 pts), ternaries 2 (nesting depth added 8). Most of this is not in the body itself: 5 of the 25 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 134, 172). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ContextCompressionService.applyCompressionDecision (cognitive 25) packages/core/src/context/contextCompressionService.ts:332— ContextCompressionService.applyCompressionDecision has cognitive complexity 25 (threshold 15). Drivers by points: if/else 17 (20 pts), boolean chains 5 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
ToolExecutor.execute (cognitive 25) packages/core/src/scheduler/tool-executor.ts:61— ToolExecutor.execute has cognitive complexity 25 (threshold 15). Drivers by points: if/else 10 (12 pts), ternaries 4 (7 pts), boolean chains 5, error handling 1 (nesting depth added 5). Most of this is not in the body itself: 4 of the 25 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 96, 102). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
GlobToolInvocation.execute (cognitive 25) packages/core/src/tools/glob.ts:137— GlobToolInvocation.execute has cognitive complexity 25 (threshold 15). Drivers by points: if/else 11 (15 pts), error handling 4 (5 pts), ternaries 1 (3 pts), boolean chains 1, loops 1 (nesting depth added 7). Of this number, 24 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
LSToolInvocation.execute (cognitive 25) packages/core/src/tools/ls.ts:159— LSToolInvocation.execute has cognitive complexity 25 (threshold 15). Drivers by points: if/else 12 (14 pts), ternaries 3 (5 pts), error handling 2 (3 pts), boolean chains 2, loops 1 (nesting depth added 5). Of this number, 19 points are the body's own statements and 6 belong to 3 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
ShellToolInvocation.simplifyPaths (cognitive 25) packages/core/src/tools/shell.ts:175— ShellToolInvocation.simplifyPaths has cognitive complexity 25 (threshold 15). Drivers by points: if/else 10 (17 pts), loops 5 (7 pts), boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
fileUtils.processSingleFileContent (cognitive 25) packages/core/src/utils/fileUtils.ts:492— fileUtils.processSingleFileContent has cognitive complexity 25 (threshold 15). Drivers by points: if/else 11 (18 pts), boolean chains 3, ternaries 1 (2 pts), error handling 1, match/switch 1 (nesting depth added 8). Of this number, 23 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
memoryDiscovery.loadJitSubdirectoryMemory (cognitive 25) packages/core/src/utils/memoryDiscovery.ts:512— memoryDiscovery.loadJitSubdirectoryMemory has cognitive complexity 25 (threshold 15). Drivers by points: if/else 9 (14 pts), error handling 2 (4 pts), loops 3 (4 pts), boolean chains 2, ternaries 1 (nesting depth added 8). Of this number, 22 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
shell-utils.collectCommandDetails (cognitive 25) packages/core/src/utils/shell-utils.ts:381— shell-utils.collectCommandDetails has cognitive complexity 25 (threshold 15). Drivers by points: if/else 5 (17 pts), loops 3 (7 pts), boolean chains 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
shell-utils.execStreaming (cognitive 25) packages/core/src/utils/shell-utils.ts:953— shell-utils.execStreaming has cognitive complexity 25 (threshold 15). Drivers by points: if/else 14 (16 pts), boolean chains 3, ternaries 1 (3 pts), error handling 1 (2 pts), loops 1 (nesting depth added 5). Most of this is not in the body itself: 9 of the 25 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 1035, 989, 1001). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
tool-utils.doesToolInvocationMatch (cognitive 25) packages/core/src/utils/tool-utils.ts:79— tool-utils.doesToolInvocationMatch has cognitive complexity 25 (threshold 15). Drivers by points: if/else 12 (23 pts), boolean chains 1, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
patch-comment.main (cognitive 25) scripts/releasing/patch-comment.js:17— patch-comment.main has cognitive complexity 25 (threshold 15). Drivers by points: boolean chains 14, if/else 9, ternaries 2. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
github.isGitHubWebhookPayload (cognitive 25) tools/caretaker-agent/cloudrun/ingestion-service/auth/github.ts:89— github.isGitHubWebhookPayload has cognitive complexity 25 (threshold 15). Drivers by points: if/else 14 (17 pts), boolean chains 8 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
GeminiSandbox.ApplyBulkAcls (cognitive 24) packages/core/src/sandbox/windows/GeminiSandbox.cs:422— GeminiSandbox.ApplyBulkAcls has cognitive complexity 24 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Task._handleToolConfirmationPart (cognitive 24) packages/a2a-server/src/agent/task.ts:943— Task._handleToolConfirmationPart has cognitive complexity 24 (threshold 15). Drivers by points: if/else 16, boolean chains 4, ternaries 2 (3 pts), error handling 1 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
github.downloadFromGitHubRelease (cognitive 24) packages/cli/src/config/extensions/github.ts:320— github.downloadFromGitHubRelease has cognitive complexity 24 (threshold 15). Drivers by points: if/else 11 (13 pts), error handling 4, boolean chains 3, loops 1 (3 pts), ternaries 1 (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
text-buffer.findNextWordAcrossLines (cognitive 24) packages/cli/src/ui/components/shared/text-buffer.ts:415— text-buffer.findNextWordAcrossLines has cognitive complexity 24 (threshold 15). Drivers by points: if/else 8 (17 pts), boolean chains 3, loops 2 (3 pts), ternaries 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This shape REPEATS in the file: one other method here (text-buffer.findNextBigWordAcrossLines) has the same decision points, in the same order, at the same nesting depths — so this is one pattern written twice rather than two separate problems. Splitting this body alone leaves the other exactly as it is. Where these are variations on one operation, the change that clears both is the shared one: lift the common shape into a single routine the variants call, parameterised by whatever genuinely differs between them, and keep in each method only the part that is not shared.
text-buffer.findNextBigWordAcrossLines (cognitive 24) packages/cli/src/ui/components/shared/text-buffer.ts:516— text-buffer.findNextBigWordAcrossLines has cognitive complexity 24 (threshold 15). Drivers by points: if/else 8 (17 pts), boolean chains 3, loops 2 (3 pts), ternaries 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This shape REPEATS in the file: one other method here (text-buffer.findNextWordAcrossLines) has the same decision points, in the same order, at the same nesting depths — so this is one pattern written twice rather than two separate problems. Splitting this body alone leaves the other exactly as it is. Where these are variations on one operation, the change that clears both is the shared one: lift the common shape into a single routine the variants call, parameterised by whatever genuinely differs between them, and keep in each method only the part that is not shared.
usePhraseCycler.usePhraseCycler (cognitive 24) packages/cli/src/ui/hooks/usePhraseCycler.ts:27— usePhraseCycler.usePhraseCycler has cognitive complexity 24 (threshold 15). Drivers by points: if/else 15, boolean chains 6, ternaries 3. Most of this is not in the body itself: 3 of the 24 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 52, 81, 113, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
keyBindings.loadCustomKeybindings (cognitive 24) packages/cli/src/ui/key/keyBindings.ts:717— keyBindings.loadCustomKeybindings has cognitive complexity 24 (threshold 15). Drivers by points: if/else 7 (13 pts), error handling 2 (4 pts), ternaries 1 (4 pts), loops 1 (2 pts), boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
textUtils.escapeAnsiCtrlCodes (cognitive 24) packages/cli/src/ui/utils/textUtils.ts:225— textUtils.escapeAnsiCtrlCodes has cognitive complexity 24 (threshold 15). Drivers by points: if/else 8 (17 pts), loops 2 (3 pts), ternaries 2 (3 pts), boolean chains 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
memory.applyInboxPatch (cognitive 24) packages/core/src/commands/memory.ts:1189— memory.applyInboxPatch has cognitive complexity 24 (threshold 15). Drivers by points: error handling 5 (7 pts), ternaries 3 (6 pts), if/else 5, loops 2 (3 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
memoryPatchUtils.applyParsedPatchesWithAllowedRoots (cognitive 24) packages/core/src/services/memoryPatchUtils.ts:681— memoryPatchUtils.applyParsedPatchesWithAllowedRoots has cognitive complexity 24 (threshold 15). Drivers by points: if/else 7 (13 pts), error handling 2 (6 pts), boolean chains 4, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
GrepTool.validateToolParamValues (cognitive 24) packages/core/src/tools/grep.ts:711— GrepTool.validateToolParamValues has cognitive complexity 24 (threshold 15). Drivers by points: if/else 7 (11 pts), error handling 4 (7 pts), boolean chains 3, ternaries 1 (3 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
mcp-tool.extractToolExplanation (cognitive 24) packages/core/src/tools/mcp-tool.ts:244— mcp-tool.extractToolExplanation has cognitive complexity 24 (threshold 15). Drivers by points: if/else 7 (11 pts), ternaries 2 (9 pts), boolean chains 3, loops 1 (nesting depth added 11). Of this number, 23 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
WebSearchToolInvocation.execute (cognitive 24) packages/core/src/tools/web-search.ts:88— WebSearchToolInvocation.execute has cognitive complexity 24 (threshold 15). Drivers by points: if/else 6 (11 pts), boolean chains 6, loops 2 (6 pts), error handling 1 (nesting depth added 9). Of this number, 18 points are the body's own statements and 6 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ExtensionLoader.stopExtension (cognitive 24) packages/core/src/utils/extensionLoader.ts:172— ExtensionLoader.stopExtension has cognitive complexity 24 (threshold 15). Drivers by points: if/else 7 (15 pts), loops 3 (8 pts), boolean chains 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
historyHardening.refineToolResponses (cognitive 24) packages/core/src/utils/historyHardening.ts:291— historyHardening.refineToolResponses has cognitive complexity 24 (threshold 15). Drivers by points: if/else 5 (19 pts), boolean chains 4, loops 1 (nesting depth added 14). Of this number, 14 points are the body's own statements and 10 belong to one function literal inside it that branches. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
dataset_metrics._validate_spec_integrity (cognitive 24) tools/caretaker-agent/evals/triage/tools/dataset_metrics.py:15— dataset_metrics._validate_spec_integrity has cognitive complexity 24 (threshold 15). Drivers by points: if/else 9 (19 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
GCSTaskStore.save (cognitive 23) packages/a2a-server/src/persistence/gcs.ts:94— GCSTaskStore.save has cognitive complexity 23 (threshold 15). Drivers by points: if/else 9 (16 pts), error handling 3 (7 pts) (nesting depth added 11). Of this number, 20 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
mcpCommand.handleEnableDisable (cognitive 23) packages/cli/src/ui/commands/mcpCommand.ts:396— mcpCommand.handleEnableDisable has cognitive complexity 23 (threshold 15). Drivers by points: if/else 13 (17 pts), boolean chains 3, ternaries 3 (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
ColorsDisplay.ColorsDisplay (cognitive 23) packages/cli/src/ui/components/ColorsDisplay.tsx:80— ColorsDisplay.ColorsDisplay has cognitive complexity 23 (threshold 15). Drivers by points: if/else 10 (15 pts), boolean chains 4, ternaries 2 (3 pts), loops 1 (nesting depth added 6). Most of this is not in the body itself: 3 of the 23 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 100, 193). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
sandboxUtils.entrypoint (cognitive 23) packages/cli/src/utils/sandboxUtils.ts:375— sandboxUtils.entrypoint has cognitive complexity 23 (threshold 15). Drivers by points: if/else 7 (11 pts), ternaries 4 (6 pts), loops 2 (4 pts), boolean chains 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Config.refreshUserQuota (cognitive 23) packages/core/src/config/config.ts:2305— Config.refreshUserQuota has cognitive complexity 23 (threshold 15). Drivers by points: if/else 8 (16 pts), boolean chains 4, loops 1 (2 pts), error handling 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Scheduler._execute (cognitive 23) packages/core/src/scheduler/scheduler.ts:730— Scheduler._execute has cognitive complexity 23 (threshold 15). Drivers by points: if/else 11 (13 pts), boolean chains 6, error handling 1 (2 pts), ternaries 1 (2 pts) (nesting depth added 4). Of this number, 21 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
ShellExecutionService.closeOrphanSlaveFd (cognitive 23) packages/core/src/services/shellExecutionService.ts:1009— ShellExecutionService.closeOrphanSlaveFd has cognitive complexity 23 (threshold 15). Drivers by points: if/else 7 (12 pts), error handling 4 (7 pts), boolean chains 3, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
edit.calculateFuzzyReplacement (cognitive 23) packages/core/src/tools/edit.ts:1366— edit.calculateFuzzyReplacement has cognitive complexity 23 (threshold 15). Drivers by points: if/else 9 (14 pts), loops 3 (4 pts), ternaries 1 (3 pts), boolean chains 2 (nesting depth added 8). Of this number, 22 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
McpClient.refreshTools (cognitive 23) packages/core/src/tools/mcp-client.ts:696— McpClient.refreshTools has cognitive complexity 23 (threshold 15). Drivers by points: if/else 4 (8 pts), boolean chains 6, loops 3 (6 pts), error handling 2 (3 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
tool-names.isValidToolName (cognitive 23) packages/core/src/tools/tool-names.ts:303— tool-names.isValidToolName has cognitive complexity 23 (threshold 15). Drivers by points: if/else 11 (20 pts), boolean chains 3 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
googleErrors.fromGaxiosError (cognitive 23) packages/core/src/utils/googleErrors.ts:279— googleErrors.fromGaxiosError has cognitive complexity 23 (threshold 15). Drivers by points: if/else 9 (18 pts), error handling 1 (3 pts), boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
lint.runSensitiveKeywordLinter (cognitive 23) scripts/lint.js:245— lint.runSensitiveKeywordLinter has cognitive complexity 23 (threshold 15). Drivers by points: if/else 4 (11 pts), loops 3 (7 pts), error handling 2 (3 pts), boolean chains 2 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
update.handleUpdate (cognitive 22) packages/cli/src/commands/extensions/update.ts:35— update.handleUpdate has cognitive complexity 22 (threshold 15). Drivers by points: if/else 10 (18 pts), error handling 2 (4 pts) (nesting depth added 10). Of this number, 20 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ContextSummaryDisplay.ContextSummaryDisplay (cognitive 22) packages/cli/src/ui/components/ContextSummaryDisplay.tsx:24— ContextSummaryDisplay.ContextSummaryDisplay has cognitive complexity 22 (threshold 15). Drivers by points: if/else 9 (10 pts), ternaries 6 (7 pts), boolean chains 5 (nesting depth added 2). Most of this is not in the body itself: 4 of the 22 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 68, 57, 48, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
MaxSizedBox.MaxSizedBox (cognitive 22) packages/cli/src/ui/components/shared/MaxSizedBox.tsx:36— MaxSizedBox.MaxSizedBox has cognitive complexity 22 (threshold 15). Drivers by points: boolean chains 10, if/else 6 (7 pts), ternaries 5 (nesting depth added 1). Of this number, 15 points are the body's own statements and 7 belong to 3 function literals inside it that branch. To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
useApprovalModeIndicator.useApprovalModeIndicator (cognitive 22) packages/cli/src/ui/hooks/useApprovalModeIndicator.ts:26— useApprovalModeIndicator.useApprovalModeIndicator has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (15 pts), boolean chains 3, error handling 1 (2 pts), match/switch 1 (2 pts) (nesting depth added 10). Most of this is not in the body itself: 0 of the 22 points are its own statements and the rest belongs to one function literal inside it that branches (line 42). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
formatters.formatResetTime (cognitive 22) packages/cli/src/ui/utils/formatters.ts:101— formatters.formatResetTime has cognitive complexity 22 (threshold 15). Drivers by points: if/else 8 (10 pts), ternaries 4 (9 pts), boolean chains 3 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sandboxUtils.isSensitiveHostPath (cognitive 22) packages/cli/src/utils/sandboxUtils.ts:151— sandboxUtils.isSensitiveHostPath has cognitive complexity 22 (threshold 15). Drivers by points: if/else 8 (10 pts), boolean chains 8, ternaries 3, error handling 1 (nesting depth added 2). Of this number, 19 points are the body's own statements and 3 belong to 2 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
content-utils.geminiPartsToContentParts (cognitive 22) packages/core/src/agent/content-utils.ts:16— content-utils.geminiPartsToContentParts has cognitive complexity 22 (threshold 15). Drivers by points: if/else 8 (11 pts), boolean chains 6, ternaries 1 (4 pts), loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
A2AAuthProviderFactory.findMatchingScheme (cognitive 22) packages/core/src/agents/auth-provider/factory.ts:156— A2AAuthProviderFactory.findMatchingScheme has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (18 pts), match/switch 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
truncation.normalizeFunctionResponse (cognitive 22) packages/core/src/context/truncation.ts:81— truncation.normalizeFunctionResponse has cognitive complexity 22 (threshold 15). Drivers by points: if/else 9 (18 pts), boolean chains 3, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
TrustedHooksManager.getUntrustedHooks (cognitive 22) packages/core/src/hooks/trustedHooks.ts:68— TrustedHooksManager.getUntrustedHooks has cognitive complexity 22 (threshold 15). Drivers by points: if/else 4 (13 pts), loops 3 (6 pts), boolean chains 3 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
stable-stringify.stableStringify (cognitive 22) packages/core/src/policy/stable-stringify.ts:59— stable-stringify.stableStringify has cognitive complexity 22 (threshold 15). Drivers by points: if/else 11 (16 pts), boolean chains 3, error handling 1 (2 pts), loops 1 (nesting depth added 6). Most of this is not in the body itself: 0 of the 22 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 60, 106). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
confirmation.resolveConfirmation (cognitive 22) packages/core/src/scheduler/confirmation.ts:109— confirmation.resolveConfirmation has cognitive complexity 22 (threshold 15). Drivers by points: if/else 8 (16 pts), boolean chains 3, ternaries 1 (2 pts), loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
shellExecutionService.getFullBufferText (cognitive 22) packages/core/src/services/shellExecutionService.ts:252— shellExecutionService.getFullBufferText has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (13 pts), ternaries 2 (5 pts), boolean chains 3, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
RecursiveFileSearch.handleFileWatcherEvent (cognitive 22) packages/core/src/utils/filesearch/fileSearch.ts:192— RecursiveFileSearch.handleFileWatcherEvent has cognitive complexity 22 (threshold 15). Drivers by points: if/else 5 (9 pts), boolean chains 4, loops 2 (4 pts), ternaries 2 (4 pts), match/switch 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
memoryDiscovery.deduplicatePathsByFileIdentity (cognitive 22) packages/core/src/utils/memoryDiscovery.ts:54— memoryDiscovery.deduplicatePathsByFileIdentity has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (12 pts), loops 3 (4 pts), ternaries 1 (3 pts), error handling 1 (2 pts), boolean chains 1 (nesting depth added 9). Of this number, 17 points are the body's own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
pathReader.readPathFromWorkspace (cognitive 22) packages/core/src/utils/pathReader.ts:23— pathReader.readPathFromWorkspace has cognitive complexity 22 (threshold 15). Drivers by points: if/else 9 (15 pts), loops 2 (4 pts), error handling 1 (3 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
shell-utils.hasRedirection (cognitive 22) packages/core/src/utils/shell-utils.ts:751— shell-utils.hasRedirection has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (12 pts), loops 2 (5 pts), boolean chains 3, ternaries 1 (2 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
shell-utils.stripShellWrapper (cognitive 22) packages/core/src/utils/shell-utils.ts:842— shell-utils.stripShellWrapper has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (12 pts), boolean chains 6, error handling 1 (4 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
main.main (cognitive 22) tools/caretaker-agent/cloudrun/triage-worker/main.py:33— main.main has cognitive complexity 22 (threshold 15). Drivers by points: if/else 10 (13 pts), error handling 5 (6 pts), ternaries 1 (2 pts), boolean chains 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
config.setTargetDir (cognitive 21) packages/a2a-server/src/config/config.ts:469— config.setTargetDir has cognitive complexity 21 (threshold 15). Drivers by points: if/else 9 (13 pts), boolean chains 5, error handling 3 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
logs.readLastLines (cognitive 21) packages/cli/src/commands/gemma/logs.ts:14— logs.readLastLines has cognitive complexity 21 (threshold 15). Drivers by points: if/else 8 (12 pts), boolean chains 4, loops 2 (3 pts), ternaries 1 (2 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
extensionSettings.maybePromptForSettings (cognitive 21) packages/cli/src/config/extensions/extensionSettings.ts:62— extensionSettings.maybePromptForSettings has cognitive complexity 21 (threshold 15). Drivers by points: if/else 8 (12 pts), boolean chains 5, loops 4 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ToolGroupDisplay.ToolDisplayMessage (cognitive 21) packages/cli/src/ui/components/messages/ToolGroupDisplay.tsx:118— ToolGroupDisplay.ToolDisplayMessage has cognitive complexity 21 (threshold 15). Drivers by points: boolean chains 17, if/else 4. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
useSuspend.useSuspend (cognitive 21) packages/cli/src/ui/hooks/useSuspend.ts:32— useSuspend.useSuspend has cognitive complexity 21 (threshold 15). Drivers by points: if/else 13 (21 pts) (nesting depth added 8). Most of this is not in the body itself: 0 of the 21 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 55, 85, 42). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
memory.applyMemoryPatchFile (cognitive 21) packages/core/src/commands/memory.ts:782— memory.applyMemoryPatchFile has cognitive complexity 21 (threshold 15). Drivers by points: error handling 5 (7 pts), ternaries 3 (5 pts), if/else 4, loops 2 (3 pts), match/switch 1 (2 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
toGraph.getStableId (cognitive 21) packages/core/src/context/graph/toGraph.ts:97— toGraph.getStableId has cognitive complexity 21 (threshold 15). Drivers by points: if/else 17 (20 pts), boolean chains 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
GeminiChat.ensureActiveLoopHasThoughtSignatures (cognitive 21) packages/core/src/core/geminiChat.ts:1262— GeminiChat.ensureActiveLoopHasThoughtSignatures has cognitive complexity 21 (threshold 15). Drivers by points: if/else 5 (14 pts), loops 3 (5 pts), boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
handler.handleFallback (cognitive 21) packages/core/src/fallback/handler.ts:26— handler.handleFallback has cognitive complexity 21 (threshold 15). Drivers by points: if/else 8 (11 pts), boolean chains 5, ternaries 2 (4 pts), error handling 1 (nesting depth added 5). Of this number, 20 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ChatRecordingService.recordToolCalls (cognitive 21) packages/core/src/services/chatRecordingService.ts:775— ChatRecordingService.recordToolCalls has cognitive complexity 21 (threshold 15). Drivers by points: if/else 8 (13 pts), boolean chains 5, loops 1 (2 pts), error handling 1 (nesting depth added 6). Of this number, 18 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
McpClient.refreshPrompts (cognitive 21) packages/core/src/tools/mcp-client.ts:597— McpClient.refreshPrompts has cognitive complexity 21 (threshold 15). Drivers by points: if/else 4 (8 pts), loops 3 (6 pts), boolean chains 4, error handling 2 (3 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
GrepToolInvocation.execute (cognitive 21) packages/core/src/tools/ripGrep.ts:182— GrepToolInvocation.execute has cognitive complexity 21 (threshold 15). Drivers by points: if/else 8 (10 pts), boolean chains 4, error handling 4, ternaries 2 (3 pts) (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
WriteFileTool.validateToolParamValues (cognitive 21) packages/core/src/tools/write-file.ts:616— WriteFileTool.validateToolParamValues has cognitive complexity 21 (threshold 15). Drivers by points: if/else 7 (8 pts), ternaries 3 (8 pts), error handling 3 (5 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
fileUtils.detectFileType (cognitive 21) packages/core/src/utils/fileUtils.ts:414— fileUtils.detectFileType has cognitive complexity 21 (threshold 15). Drivers by points: if/else 11 (17 pts), ternaries 1 (3 pts), boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
lint.runGithubActionsPinningLinter (cognitive 21) scripts/lint.js:397— lint.runGithubActionsPinningLinter has cognitive complexity 21 (threshold 15). Drivers by points: if/else 6 (15 pts), loops 2 (3 pts), boolean chains 2, error handling 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
CommandExecutor.run (cognitive 21) tools/caretaker-agent/cloudrun/pr-generator/workflow/command_executor.py:75— CommandExecutor.run has cognitive complexity 21 (threshold 15). Drivers by points: if/else 9 (14 pts), boolean chains 2, loops 1 (2 pts), ternaries 2, error handling 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
GeminiSandbox.QuoteArgument (cognitive 20) packages/core/src/sandbox/windows/GeminiSandbox.cs:526— GeminiSandbox.QuoteArgument has cognitive complexity 20 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
validate.validateExtension (cognitive 20) packages/cli/src/commands/extensions/validate.ts:36— validate.validateExtension has cognitive complexity 20 (threshold 15). Drivers by points: if/else 7 (12 pts), loops 3 (6 pts), ternaries 1 (2 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
extensionSettings.updateSetting (cognitive 20) packages/cli/src/config/extensions/extensionSettings.ts:230— extensionSettings.updateSetting has cognitive complexity 20 (threshold 15). Drivers by points: if/else 11 (14 pts), error handling 1 (3 pts), boolean chains 2, loops 1 (nesting depth added 5). Of this number, 19 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
McpPromptLoader.parseArgs (cognitive 20) packages/cli/src/services/McpPromptLoader.ts:231— McpPromptLoader.parseArgs has cognitive complexity 20 (threshold 15). Drivers by points: if/else 9 (14 pts), loops 4 (5 pts), boolean chains 1 (nesting depth added 6). Of this number, 19 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
useAuth.useAuthCommand (cognitive 20) packages/cli/src/ui/auth/useAuth.ts:41— useAuth.useAuthCommand has cognitive complexity 20 (threshold 15). Drivers by points: if/else 14 (17 pts), boolean chains 1, error handling 1, ternaries 1 (nesting depth added 3). Most of this is not in the body itself: 1 of the 20 points is its own statement and the rest belongs to 4 function literals inside it that branch (lines 89, 59, 68, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
extensionsCommand.restartAction (cognitive 20) packages/cli/src/ui/commands/extensionsCommand.ts:155— extensionsCommand.restartAction has cognitive complexity 20 (threshold 15). Drivers by points: if/else 11 (14 pts), boolean chains 2, error handling 1 (2 pts), ternaries 2 (nesting depth added 4). Of this number, 19 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
Composer.Composer (cognitive 20) packages/cli/src/ui/components/Composer.tsx:32— Composer.Composer has cognitive complexity 20 (threshold 15). Drivers by points: boolean chains 16, if/else 3, ternaries 1. Of this number, 17 points are the body's own statements and 3 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
ScrollableList.ScrollableList (cognitive 20) packages/cli/src/ui/components/shared/ScrollableList.tsx:46— ScrollableList.ScrollableList has cognitive complexity 20 (threshold 15). Drivers by points: if/else 10 (11 pts), ternaries 3 (5 pts), boolean chains 4 (nesting depth added 3). Most of this is not in the body itself: 0 of the 20 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 200, 113, 102, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
SearchableList.SearchableList (cognitive 20) packages/cli/src/ui/components/shared/SearchableList.tsx:77— SearchableList.SearchableList has cognitive complexity 20 (threshold 15). Drivers by points: boolean chains 8, if/else 6, ternaries 5 (6 pts) (nesting depth added 1). Of this number, 11 points are the body's own statements and 9 belong to 4 function literals inside it that branch. To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
text-buffer.calculateTransformedLine (cognitive 20) packages/cli/src/ui/components/shared/text-buffer.ts:1170— text-buffer.calculateTransformedLine has cognitive complexity 20 (threshold 15). Drivers by points: loops 5 (10 pts), ternaries 2 (6 pts), if/else 2 (3 pts), boolean chains 1 (nesting depth added 10). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline.
KeypressContext.KeypressProvider (cognitive 20) packages/cli/src/ui/contexts/KeypressContext.tsx:769— KeypressContext.KeypressProvider has cognitive complexity 20 (threshold 15). Drivers by points: if/else 10 (14 pts), loops 2 (3 pts), ternaries 2 (3 pts) (nesting depth added 6). Most of this is not in the body itself: 0 of the 20 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 834, 790, 816, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useSelectionList.findNextValidIndex (cognitive 20) packages/cli/src/ui/hooks/useSelectionList.ts:84— useSelectionList.findNextValidIndex has cognitive complexity 20 (threshold 15). Drivers by points: if/else 7 (14 pts), boolean chains 4, loops 1, ternaries 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
useShellCompletion.scanPathExecutables (cognitive 20) packages/cli/src/ui/hooks/useShellCompletion.ts:183— useShellCompletion.scanPathExecutables has cognitive complexity 20 (threshold 15). Drivers by points: if/else 7 (10 pts), loops 3 (5 pts), boolean chains 2, error handling 2, ternaries 1 (nesting depth added 5). Of this number, 10 points are the body's own statements and 10 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
useTabbedNavigation.tabbedNavigationReducer (cognitive 20) packages/cli/src/ui/hooks/useTabbedNavigation.ts:69— useTabbedNavigation.tabbedNavigationReducer has cognitive complexity 20 (threshold 15). Drivers by points: if/else 8 (16 pts), ternaries 1 (2 pts), boolean chains 1, match/switch 1 (nesting depth added 9). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
TableRenderer.TableRenderer (cognitive 20) packages/cli/src/ui/utils/TableRenderer.tsx:66— TableRenderer.TableRenderer has cognitive complexity 20 (threshold 15). Drivers by points: boolean chains 8, if/else 4 (5 pts), ternaries 3 (4 pts), loops 3 (nesting depth added 2). Most of this is not in the body itself: 0 of the 20 points are its own statements and the rest belongs to 10 function literals inside it that branch (lines 95, 183, 289, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
logCleanup.cleanupBackgroundLogs (cognitive 20) packages/cli/src/utils/logCleanup.ts:19— logCleanup.cleanupBackgroundLogs has cognitive complexity 20 (threshold 15). Drivers by points: if/else 5 (12 pts), error handling 3 (5 pts), boolean chains 2, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
AnalyzeScreenshotInvocation.execute (cognitive 20) packages/core/src/agents/browser/analyzeScreenshot.ts:84— AnalyzeScreenshotInvocation.execute has cognitive complexity 20 (threshold 15). Drivers by points: ternaries 6 (8 pts), if/else 4 (6 pts), boolean chains 3, loops 1 (2 pts), error handling 1 (nesting depth added 5). Of this number, 18 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
BrowserManager.callTool (cognitive 20) packages/core/src/agents/browser/browserManager.ts:321— BrowserManager.callTool has cognitive complexity 20 (threshold 15). Drivers by points: if/else 11 (16 pts), boolean chains 2, error handling 1 (2 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IdeClient.connect (cognitive 20) packages/core/src/ide/ide-client.ts:125— IdeClient.connect has cognitive complexity 20 (threshold 15). Drivers by points: if/else 11 (19 pts), ternaries 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
OAuthUtils.discoverOAuthConfig (cognitive 20) packages/core/src/mcp/oauth-utils.ts:404— OAuthUtils.discoverOAuthConfig has cognitive complexity 20 (threshold 15). Drivers by points: if/else 10 (17 pts), boolean chains 2, error handling 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
FolderTrustDiscoveryService.discoverSettings (cognitive 20) packages/core/src/services/FolderTrustDiscoveryService.ts:133— FolderTrustDiscoveryService.discoverSettings has cognitive complexity 20 (threshold 15). Drivers by points: if/else 6 (11 pts), loops 2 (5 pts), ternaries 1 (2 pts), boolean chains 1, error handling 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
memoryService.validatePatches (cognitive 20) packages/core/src/services/memoryService.ts:856— memoryService.validatePatches has cognitive complexity 20 (threshold 15). Drivers by points: if/else 5 (9 pts), error handling 3 (6 pts), match/switch 1 (4 pts), loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sessionScratchpadUtils.tokenizeShellCommand (cognitive 20) packages/core/src/services/sessionScratchpadUtils.ts:15— sessionScratchpadUtils.tokenizeShellCommand has cognitive complexity 20 (threshold 15). Drivers by points: if/else 7 (16 pts), boolean chains 3, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ShellToolInvocation.getConfirmationDetails (cognitive 20) packages/core/src/tools/shell.ts:435— ShellToolInvocation.getConfirmationDetails has cognitive complexity 20 (threshold 15). Drivers by points: boolean chains 8, if/else 6 (8 pts), ternaries 3 (4 pts) (nesting depth added 3). Of this number, 17 points are the body's own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
errorReporting.reportError (cognitive 20) packages/core/src/utils/errorReporting.ts:26— errorReporting.reportError has cognitive complexity 20 (threshold 15). Drivers by points: error handling 5 (11 pts), if/else 6 (8 pts), boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
fetch.fetchWithTimeout (cognitive 20) packages/core/src/utils/fetch.ts:443— fetch.fetchWithTimeout has cognitive complexity 20 (threshold 15). Drivers by points: if/else 10 (18 pts), boolean chains 1, error handling 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
security.parseWindowsBatchSecurityOutput (cognitive 20) packages/core/src/utils/security.ts:181— security.parseWindowsBatchSecurityOutput has cognitive complexity 20 (threshold 15). Drivers by points: if/else 11 (15 pts), loops 3 (4 pts), boolean chains 1 (nesting depth added 5). Of this number, 19 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sessionOperations.deleteSessionFileAndArtifacts (cognitive 20) packages/core/src/utils/sessionOperations.ts:215— sessionOperations.deleteSessionFileAndArtifacts has cognitive complexity 20 (threshold 15). Drivers by points: if/else 8 (12 pts), error handling 4 (6 pts), boolean chains 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
App.CodeView (cognitive 20) packages/devtools/client/src/App.tsx:1829— App.CodeView has cognitive complexity 20 (threshold 15). Drivers by points: if/else 6 (8 pts), boolean chains 6, ternaries 4 (5 pts), loops 1 (nesting depth added 3). Most of this is not in the body itself: 7 of the 20 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 1846, 1919, 1835). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
eval-validate.getNewEvalFiles (cognitive 20) scripts/utils/eval-validate.ts:261— eval-validate.getNewEvalFiles has cognitive complexity 20 (threshold 15). Drivers by points: if/else 6 (11 pts), error handling 3 (4 pts), boolean chains 3, loops 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Orchestrator._submit_pull_request (cognitive 20) tools/caretaker-agent/cloudrun/pr-generator/workflow/orchestrator.py:598— Orchestrator._submit_pull_request has cognitive complexity 20 (threshold 15). Drivers by points: if/else 7 (9 pts), error handling 4 (7 pts), ternaries 2 (4 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
status.formatGemmaStatus (cognitive 19) packages/cli/src/commands/gemma/status.ts:62— status.formatGemmaStatus has cognitive complexity 19 (threshold 15). Drivers by points: if/else 14 (16 pts), ternaries 2 (3 pts) (nesting depth added 3). Of this number, 18 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
migrate.migrateClaudeHooks (cognitive 19) packages/cli/src/commands/hooks/migrate.ts:108— migrate.migrateClaudeHooks has cognitive complexity 19 (threshold 15). Drivers by points: if/else 7 (12 pts), boolean chains 6, loops 1 (nesting depth added 5). Most of this is not in the body itself: 8 of the 19 points are its own statements and the rest belongs to one function literal inside it that branches (line 133). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
FileCommandLoader.parseAndAdaptFile (cognitive 19) packages/cli/src/services/FileCommandLoader.ts:257— FileCommandLoader.parseAndAdaptFile has cognitive complexity 19 (threshold 15). Drivers by points: if/else 8 (9 pts), ternaries 2 (4 pts), error handling 3, boolean chains 2, loops 1 (nesting depth added 3). Of this number, 13 points are the body's own statements and 6 belong to 2 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
StatusRow.StatusNode (cognitive 19) packages/cli/src/ui/components/StatusRow.tsx:67— StatusRow.StatusNode has cognitive complexity 19 (threshold 15). Drivers by points: if/else 9 (13 pts), boolean chains 3, ternaries 1 (3 pts) (nesting depth added 6). Of this number, 10 points are the body's own statements and 9 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
SessionContext.areMetricsEqual (cognitive 19) packages/cli/src/ui/contexts/SessionContext.tsx:89— SessionContext.areMetricsEqual has cognitive complexity 19 (threshold 15). Drivers by points: if/else 9 (11 pts), boolean chains 6, loops 2 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
commentJson.preserveCommentsOnPropertyDeletion (cognitive 19) packages/cli/src/utils/commentJson.ts:57— commentJson.preserveCommentsOnPropertyDeletion has cognitive complexity 19 (threshold 15). Drivers by points: if/else 10 (12 pts), boolean chains 5, ternaries 2 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
envVarResolver.resolveEnvVarsInObjectInternal (cognitive 19) packages/cli/src/utils/envVarResolver.ts:94— envVarResolver.resolveEnvVarsInObjectInternal has cognitive complexity 19 (threshold 15). Drivers by points: if/else 9 (16 pts), loops 1 (2 pts), boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sessionCleanup.identifySessionsToDelete (cognitive 19) packages/cli/src/utils/sessionCleanup.ts:302— sessionCleanup.identifySessionsToDelete has cognitive complexity 19 (threshold 15). Drivers by points: if/else 7 (14 pts), error handling 1 (2 pts), boolean chains 1, loops 1, ternaries 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sessionUtils.getAllSessionFiles (cognitive 19) packages/cli/src/utils/sessionUtils.ts:237— sessionUtils.getAllSessionFiles has cognitive complexity 19 (threshold 15). Drivers by points: if/else 6 (7 pts), boolean chains 6, ternaries 4, error handling 2 (nesting depth added 1). Most of this is not in the body itself: 4 of the 19 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 253, 246, 310). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
validateNonInterActiveAuth.validateNonInteractiveAuth (cognitive 19) packages/cli/src/validateNonInterActiveAuth.ts:20— validateNonInterActiveAuth.validateNonInteractiveAuth has cognitive complexity 19 (threshold 15). Drivers by points: if/else 6 (8 pts), ternaries 3 (8 pts), boolean chains 2, error handling 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
compile-windows-sandbox.compileWindowsSandbox (cognitive 19) packages/core/scripts/compile-windows-sandbox.js:22— compile-windows-sandbox.compileWindowsSandbox has cognitive complexity 19 (threshold 15). Drivers by points: if/else 11 (17 pts), boolean chains 1, loops 1 (nesting depth added 6). Of this number, 18 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Config._initialize (cognitive 19) packages/core/src/config/config.ts:1450— Config._initialize has cognitive complexity 19 (threshold 15). Drivers by points: if/else 7 (10 pts), error handling 2 (4 pts), ternaries 1 (3 pts), boolean chains 1, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ChatCompressionService.compress (cognitive 19) packages/core/src/context/chatCompressionService.ts:240— ChatCompressionService.compress has cognitive complexity 19 (threshold 15). Drivers by points: if/else 9 (11 pts), boolean chains 5, ternaries 3 (nesting depth added 2). Of this number, 16 points are the body's own statements and 3 belong to 3 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
HookEventHandler.logHookExecution (cognitive 19) packages/core/src/hooks/hookEventHandler.ts:390— HookEventHandler.logHookExecution has cognitive complexity 19 (threshold 15). Drivers by points: if/else 8 (15 pts), loops 2, ternaries 1 (2 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PolicyEngine.constructor (cognitive 19) packages/core/src/policy/policy-engine.ts:254— PolicyEngine.constructor has cognitive complexity 19 (threshold 15). Drivers by points: if/else 5 (10 pts), boolean chains 7, loops 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PolicyEngine.applyShellHeuristics (cognitive 19) packages/core/src/policy/policy-engine.ts:359— PolicyEngine.applyShellHeuristics has cognitive complexity 19 (threshold 15). Drivers by points: if/else 8 (11 pts), boolean chains 5, ternaries 2, error handling 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
CheckerRunner.executeCheckerProcess (cognitive 19) packages/core/src/safety/checker-runner.ts:163— CheckerRunner.executeCheckerProcess has cognitive complexity 19 (threshold 15). Drivers by points: if/else 10 (11 pts), ternaries 3 (6 pts), error handling 2 (nesting depth added 4). Most of this is not in the body itself: 0 of the 19 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 168, 213, 255, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
chatRecordingService.parseLegacyRecordFallback (cognitive 19) packages/core/src/services/chatRecordingService.ts:1041— chatRecordingService.parseLegacyRecordFallback has cognitive complexity 19 (threshold 15). Drivers by points: if/else 5 (11 pts), boolean chains 7, error handling 1 (nesting depth added 6). Of this number, 17 points are the body's own statements and 2 belong to 3 function literals inside it that branch. To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
memoryService.scanEligibleSessions (cognitive 19) packages/core/src/services/memoryService.ts:577— memoryService.scanEligibleSessions has cognitive complexity 19 (threshold 15). Drivers by points: if/else 4 (8 pts), error handling 3 (5 pts), boolean chains 2, loops 2, ternaries 1 (2 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sessionSummaryUtils.collectPathsFromValue (cognitive 19) packages/core/src/services/sessionSummaryUtils.ts:138— sessionSummaryUtils.collectPathsFromValue has cognitive complexity 19 (threshold 15). Drivers by points: if/else 8 (13 pts), boolean chains 3, loops 2 (3 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ShellExecutionService.resizePty (cognitive 19) packages/core/src/services/shellExecutionService.ts:1875— ShellExecutionService.resizePty has cognitive complexity 19 (threshold 15). Drivers by points: if/else 8 (11 pts), boolean chains 5, error handling 2 (3 pts) (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
shellExecutionService.writeBufferToLogStream (cognitive 19) packages/core/src/services/shellExecutionService.ts:306— shellExecutionService.writeBufferToLogStream has cognitive complexity 19 (threshold 15). Drivers by points: if/else 9 (17 pts), boolean chains 1, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
package_skill.main (cognitive 19) packages/core/src/skills/builtin/skill-creator/scripts/package_skill.cjs:20— package_skill.main has cognitive complexity 19 (threshold 15). Drivers by points: if/else 10 (13 pts), boolean chains 4, error handling 1, ternaries 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
semantic.getStringReferences (cognitive 19) packages/core/src/telemetry/semantic.ts:34— semantic.getStringReferences has cognitive complexity 19 (threshold 15). Drivers by points: if/else 9 (16 pts), boolean chains 2, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
grep-utils.formatGrepResults (cognitive 19) packages/core/src/tools/grep-utils.ts:139— grep-utils.formatGrepResults has cognitive complexity 19 (threshold 15). Drivers by points: ternaries 8 (13 pts), if/else 4 (5 pts), loops 1 (nesting depth added 6). Of this number, 15 points are the body's own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ReadMcpResourceToolInvocation.execute (cognitive 19) packages/core/src/tools/read-mcp-resource.ts:81— ReadMcpResourceToolInvocation.execute has cognitive complexity 19 (threshold 15). Drivers by points: if/else 7 (9 pts), boolean chains 4, ternaries 2 (3 pts), loops 1 (2 pts), error handling 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
WebFetchToolInvocation.executeExperimental (cognitive 19) packages/core/src/tools/web-fetch.ts:595— WebFetchToolInvocation.executeExperimental has cognitive complexity 19 (threshold 15). Drivers by points: if/else 10 (13 pts), boolean chains 4, error handling 2 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
bfsFileSearch.bfsFileSearch (cognitive 19) packages/core/src/utils/bfsFileSearch.ts:38— bfsFileSearch.bfsFileSearch has cognitive complexity 19 (threshold 15). Drivers by points: if/else 4 (10 pts), loops 3 (5 pts), boolean chains 2, error handling 1 (2 pts) (nesting depth added 9). Of this number, 14 points are the body's own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
errorParsing.parseAndFormatApiError (cognitive 19) packages/core/src/utils/errorParsing.ts:35— errorParsing.parseAndFormatApiError has cognitive complexity 19 (threshold 15). Drivers by points: if/else 7 (14 pts), error handling 2 (5 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
fetch.safeLookup (cognitive 19) packages/core/src/utils/fetch.ts:57— fetch.safeLookup has cognitive complexity 19 (threshold 15). Drivers by points: if/else 9 (12 pts), boolean chains 3, ternaries 2 (3 pts), loops 1 (nesting depth added 4). Most of this is not in the body itself: 8 of the 19 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 101, 131). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
fileUtils.detectBOM (cognitive 19) packages/core/src/utils/fileUtils.ts:78— fileUtils.detectBOM has cognitive complexity 19 (threshold 15). Drivers by points: if/else 8 (13 pts), boolean chains 6 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
markdownUtils.jsonToMarkdown (cognitive 19) packages/core/src/utils/markdownUtils.ts:23— markdownUtils.jsonToMarkdown has cognitive complexity 19 (threshold 15). Drivers by points: if/else 10 (15 pts), boolean chains 2, ternaries 1 (2 pts) (nesting depth added 6). Of this number, 11 points are the body's own statements and 8 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
oauth-flow.startCallbackServer (cognitive 19) packages/core/src/utils/oauth-flow.ts:192— oauth-flow.startCallbackServer has cognitive complexity 19 (threshold 15). Drivers by points: if/else 11 (14 pts), boolean chains 4, error handling 1 (nesting depth added 3). Most of this is not in the body itself: 0 of the 19 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 214, 210). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
GeminiCliSession.initialize (cognitive 19) packages/sdk/src/session.ts:112— GeminiCliSession.initialize has cognitive complexity 19 (threshold 15). Drivers by points: if/else 9 (13 pts), error handling 1 (2 pts), ternaries 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 6). Of this number, 10 points are the body's own statements and 9 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
aggregate_evals.getStats (cognitive 19) scripts/aggregate_evals.js:50— aggregate_evals.getStats has cognitive complexity 19 (threshold 15). Drivers by points: if/else 4 (11 pts), loops 3 (6 pts), error handling 1 (2 pts) (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
actions_spend.getWorkflowMinutes (cognitive 19) tools/gemini-cli-bot/metrics/scripts/actions_spend.ts:9— actions_spend.getWorkflowMinutes has cognitive complexity 19 (threshold 15). Drivers by points: if/else 4 (10 pts), boolean chains 4, loops 2 (3 pts), error handling 1 (2 pts) (nesting depth added 8). Most of this is not in the body itself: 1 of the 19 points is its own statement and the rest belongs to one function literal inside it that branches (line 45). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
acpUtils.toToolCallContent (cognitive 18) packages/cli/src/acp/acpUtils.ts:47— acpUtils.toToolCallContent has cognitive complexity 18 (threshold 15). Drivers by points: if/else 6 (9 pts), ternaries 2 (9 pts) (nesting depth added 10). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
ExtensionManager.toOutputString (cognitive 18) packages/cli/src/config/extension-manager.ts:1109— ExtensionManager.toOutputString has cognitive complexity 18 (threshold 15). Drivers by points: if/else 10 (15 pts), boolean chains 2, ternaries 1 (nesting depth added 5). Of this number, 13 points are the body's own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
injectionParser.extractInjections (cognitive 18) packages/cli/src/services/prompt-processors/injectionParser.ts:31— injectionParser.extractInjections has cognitive complexity 18 (threshold 15). Drivers by points: if/else 5 (12 pts), loops 2 (3 pts), ternaries 1 (3 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
AskUserDialog.choiceQuestionReducer (cognitive 18) packages/cli/src/ui/components/AskUserDialog.tsx:437— AskUserDialog.choiceQuestionReducer has cognitive complexity 18 (threshold 15). Drivers by points: if/else 5 (8 pts), ternaries 3 (6 pts), loops 1 (3 pts), match/switch 1 (nesting depth added 8). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
SubagentProgressDisplay.formatToolArgs (cognitive 18) packages/cli/src/ui/components/messages/SubagentProgressDisplay.tsx:27— SubagentProgressDisplay.formatToolArgs has cognitive complexity 18 (threshold 15). Drivers by points: if/else 9, boolean chains 8, error handling 1. To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
useAnimatedScrollbar.useAnimatedScrollbar (cognitive 18) packages/cli/src/ui/hooks/useAnimatedScrollbar.ts:12— useAnimatedScrollbar.useAnimatedScrollbar has cognitive complexity 18 (threshold 15). Drivers by points: if/else 10 (11 pts), boolean chains 4, ternaries 3 (nesting depth added 1). Most of this is not in the body itself: 0 of the 18 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 39, 66, 110, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useIncludeDirsTrust.useIncludeDirsTrust (cognitive 18) packages/cli/src/ui/hooks/useIncludeDirsTrust.tsx:54— useIncludeDirsTrust.useIncludeDirsTrust has cognitive complexity 18 (threshold 15). Drivers by points: if/else 11 (13 pts), boolean chains 4, loops 1 (nesting depth added 2). Most of this is not in the body itself: 0 of the 18 points are its own statements and the rest belongs to one function literal inside it that branches (line 62). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
useTabbedNavigation.useTabbedNavigation (cognitive 18) packages/cli/src/ui/hooks/useTabbedNavigation.ts:141— useTabbedNavigation.useTabbedNavigation has cognitive complexity 18 (threshold 15). Drivers by points: if/else 12 (16 pts), boolean chains 2 (nesting depth added 4). Most of this is not in the body itself: 1 of the 18 points is its own statement and the rest belongs to 6 function literals inside it that branch (lines 205, 163, 179, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
updateCheck.checkForUpdates (cognitive 18) packages/cli/src/ui/utils/updateCheck.ts:56— updateCheck.checkForUpdates has cognitive complexity 18 (threshold 15). Drivers by points: if/else 9 (13 pts), boolean chains 4, error handling 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
skillUtils.installSkill (cognitive 18) packages/cli/src/utils/skillUtils.ts:93— skillUtils.installSkill has cognitive complexity 18 (threshold 15). Drivers by points: if/else 10 (13 pts), ternaries 2 (3 pts), boolean chains 1, loops 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
McpToolInvocation.execute (cognitive 18) packages/core/src/agents/browser/mcpToolWrapper.ts:121— McpToolInvocation.execute has cognitive complexity 18 (threshold 15). Drivers by points: if/else 7 (9 pts), boolean chains 6, ternaries 1 (2 pts), error handling 1 (nesting depth added 3). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
snapshotSuperseder.supersedeStaleSnapshots (cognitive 18) packages/core/src/agents/browser/snapshotSuperseder.ts:41— snapshotSuperseder.supersedeStaleSnapshots has cognitive complexity 18 (threshold 15). Drivers by points: if/else 7 (12 pts), loops 3 (4 pts), boolean chains 1, ternaries 1 (nesting depth added 6). Of this number, 17 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Config.constructor (cognitive 18) packages/core/src/config/config.ts:993— Config.constructor has cognitive complexity 18 (threshold 15). Drivers by points: if/else 11, boolean chains 5, error handling 1 (2 pts) (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
ProjectRegistry.ensureOwnershipMarkers (cognitive 18) packages/core/src/config/projectRegistry.ts:372— ProjectRegistry.ensureOwnershipMarkers has cognitive complexity 18 (threshold 15). Drivers by points: if/else 5 (14 pts), error handling 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
StaticTokenCalculator.calculateTokenBreakdown (cognitive 18) packages/core/src/context/utils/contextTokenCalculator.ts:117— StaticTokenCalculator.calculateTokenBreakdown has cognitive complexity 18 (threshold 15). Drivers by points: if/else 7 (13 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
geminiChat.extractCuratedHistory (cognitive 18) packages/core/src/core/geminiChat.ts:213— geminiChat.extractCuratedHistory has cognitive complexity 18 (threshold 15). Drivers by points: if/else 5 (11 pts), loops 2 (4 pts), boolean chains 3 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
toml-loader.validateMcpPolicyToolNames (cognitive 18) packages/core/src/policy/toml-loader.ts:699— toml-loader.validateMcpPolicyToolNames has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (14 pts), ternaries 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
diff-utils.getDiffContextSnippet (cognitive 18) packages/core/src/tools/diff-utils.ts:12— diff-utils.getDiffContextSnippet has cognitive complexity 18 (threshold 15). Drivers by points: if/else 10 (14 pts), loops 3 (4 pts) (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
EditTool.getModifyContext (cognitive 18) packages/core/src/tools/edit.ts:1220— EditTool.getModifyContext has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (11 pts), error handling 4, boolean chains 3 (nesting depth added 3). Most of this is not in the body itself: 0 of the 18 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 1221, 1286, 1275). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
McpClient.refreshResources (cognitive 18) packages/core/src/tools/mcp-client.ts:498— McpClient.refreshResources has cognitive complexity 18 (threshold 15). Drivers by points: if/else 4 (8 pts), boolean chains 4, error handling 2 (3 pts), loops 2 (3 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
atCommandUtils.tryExtractPath (cognitive 18) packages/core/src/utils/atCommandUtils.ts:153— atCommandUtils.tryExtractPath has cognitive complexity 18 (threshold 15). Drivers by points: if/else 5 (11 pts), loops 2 (3 pts), boolean chains 2, ternaries 1 (2 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
shell-utils.hasPromptCommandTransform (cognitive 18) packages/core/src/utils/shell-utils.ts:432— shell-utils.hasPromptCommandTransform has cognitive complexity 18 (threshold 15). Drivers by points: if/else 4 (11 pts), loops 3 (6 pts), boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
App.highlightLine (cognitive 18) packages/devtools/client/src/App.tsx:1700— App.highlightLine has cognitive complexity 18 (threshold 15). Drivers by points: if/else 10 (14 pts), error handling 1 (3 pts), loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
close_duplicate_issues.run (cognitive 18) scripts/close_duplicate_issues.js:69— close_duplicate_issues.run has cognitive complexity 18 (threshold 15). Drivers by points: if/else 7 (13 pts), error handling 2 (3 pts), boolean chains 1, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
eval_utils.getStatsFromReports (cognitive 18) scripts/eval_utils.js:56— eval_utils.getStatsFromReports has cognitive complexity 18 (threshold 15). Drivers by points: if/else 3 (10 pts), loops 3 (6 pts), error handling 1 (2 pts) (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
autogen.formatDefaultValue (cognitive 18) scripts/utils/autogen.ts:33— autogen.formatDefaultValue has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (10 pts), error handling 3 (5 pts), ternaries 1 (2 pts), boolean chains 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
LLMJudge.judgeYesNo (cognitive 17) evals/llm-judge.ts:37— LLMJudge.judgeYesNo has cognitive complexity 17 (threshold 15). Drivers by points: if/else 8 (11 pts), boolean chains 4, error handling 1, loops 1 (nesting depth added 3). Of this number, 15 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Task.handleEventDrivenToolCall (cognitive 17) packages/a2a-server/src/agent/task.ts:462— Task.handleEventDrivenToolCall has cognitive complexity 17 (threshold 15). Drivers by points: if/else 8 (10 pts), boolean chains 5, ternaries 1 (2 pts) (nesting depth added 3). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
settings._doLoadSettings (cognitive 17) packages/cli/src/config/settings.ts:769— settings._doLoadSettings has cognitive complexity 17 (threshold 15). Drivers by points: if/else 11 (13 pts), boolean chains 2, error handling 1, ternaries 1 (nesting depth added 2). Most of this is not in the body itself: 7 of the 17 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 781, 851). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
interactiveCli.startInteractiveUI (cognitive 17) packages/cli/src/interactiveCli.tsx:56— interactiveCli.startInteractiveUI has cognitive complexity 17 (threshold 15). Drivers by points: error handling 6 (7 pts), if/else 6, boolean chains 3, ternaries 1 (nesting depth added 1). Of this number, 14 points are the body's own statements and 3 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
BuiltinCommandLoader.loadCommands (cognitive 17) packages/cli/src/services/BuiltinCommandLoader.ts:83— BuiltinCommandLoader.loadCommands has cognitive complexity 17 (threshold 15). Drivers by points: ternaries 13 (14 pts), if/else 3 (nesting depth added 1). Of this number, 13 points are the body's own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
extensionsCommand.configAction (cognitive 17) packages/cli/src/ui/commands/extensionsCommand.ts:673— extensionsCommand.configAction has cognitive complexity 17 (threshold 15). Drivers by points: if/else 9 (14 pts), boolean chains 3 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
DiffRenderer.DiffRenderer (cognitive 17) packages/cli/src/ui/components/messages/DiffRenderer.tsx:100— DiffRenderer.DiffRenderer has cognitive complexity 17 (threshold 15). Drivers by points: ternaries 4 (8 pts), if/else 6, boolean chains 3 (nesting depth added 4). Most of this is not in the body itself: 1 of the 17 points is its own statement and the rest belongs to 2 function literals inside it that branch (lines 125, 116). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
ShellToolMessage.ShellToolMessage (cognitive 17) packages/cli/src/ui/components/messages/ShellToolMessage.tsx:44— ShellToolMessage.ShellToolMessage has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (9 pts), boolean chains 6, error handling 1 (2 pts) (nesting depth added 4). Most of this is not in the body itself: 4 of the 17 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 100, 129, 146). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
TopicMessage.TopicMessage (cognitive 17) packages/cli/src/ui/components/messages/TopicMessage.tsx:32— TopicMessage.TopicMessage has cognitive complexity 17 (threshold 15). Drivers by points: boolean chains 11, if/else 3, ternaries 3. Of this number, 11 points are the body's own statements and 6 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
useRunEventNotifications.useRunEventNotifications (cognitive 17) packages/cli/src/ui/hooks/useRunEventNotifications.ts:39— useRunEventNotifications.useRunEventNotifications has cognitive complexity 17 (threshold 15). Drivers by points: boolean chains 10, if/else 6, ternaries 1. Most of this is not in the body itself: 0 of the 17 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 81, 140). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
sessionCleanup.validateRetentionConfig (cognitive 17) packages/cli/src/utils/sessionCleanup.ts:414— sessionCleanup.validateRetentionConfig has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (11 pts), error handling 2 (4 pts), boolean chains 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
a2a-errors.collectErrorMessages (cognitive 17) packages/core/src/agents/a2a-errors.ts:122— a2a-errors.collectErrorMessages has cognitive complexity 17 (threshold 15). Drivers by points: if/else 8 (15 pts), boolean chains 1, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
value-resolver.resolveAuthValue (cognitive 17) packages/core/src/agents/auth-provider/value-resolver.ts:26— value-resolver.resolveAuthValue has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (12 pts), boolean chains 3, error handling 1 (2 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
RemoteAgentInvocation.execute (cognitive 17) packages/core/src/agents/remote-invocation.ts:130— RemoteAgentInvocation.execute has cognitive complexity 17 (threshold 15). Drivers by points: if/else 9 (13 pts), ternaries 1 (2 pts), error handling 1, loops 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
geminiChat.stripToolCallIdPrefixes (cognitive 17) packages/core/src/core/geminiChat.ts:1756— geminiChat.stripToolCallIdPrefixes has cognitive complexity 17 (threshold 15). Drivers by points: boolean chains 9, if/else 6 (8 pts) (nesting depth added 2). Most of this is not in the body itself: 0 of the 17 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 1759, 1795, 1757, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
TrustedHooksManager.trustHooks (cognitive 17) packages/core/src/hooks/trustedHooks.ts:99— TrustedHooksManager.trustHooks has cognitive complexity 17 (threshold 15). Drivers by points: if/else 3 (9 pts), loops 3 (6 pts), boolean chains 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ModelConfigService.resolveAliasChain (cognitive 17) packages/core/src/services/modelConfigService.ts:432— ModelConfigService.resolveAliasChain has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (13 pts), loops 2 (4 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
sandboxManager.resolveSandboxPaths (cognitive 17) packages/core/src/services/sandboxManager.ts:371— sandboxManager.resolveSandboxPaths has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (12 pts), boolean chains 2, ternaries 2, error handling 1 (nesting depth added 6). Of this number, 12 points are the body's own statements and 5 belong to 3 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
SessionSummaryService.generateSummary (cognitive 17) packages/core/src/services/sessionSummaryService.ts:54— SessionSummaryService.generateSummary has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (8 pts), ternaries 3 (5 pts), boolean chains 3, error handling 1 (nesting depth added 3). Of this number, 13 points are the body's own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
validate_skill.validateSkill (cognitive 17) packages/core/src/skills/builtin/skill-creator/scripts/validate_skill.cjs:15— validate_skill.validateSkill has cognitive complexity 17 (threshold 15). Drivers by points: if/else 10 (11 pts), ternaries 2 (3 pts), boolean chains 2, loops 1 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
ClearcutLogger.logToolCallEvent (cognitive 17) packages/core/src/telemetry/clearcut-logger/clearcut-logger.ts:756— ClearcutLogger.logToolCallEvent has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (11 pts), loops 2 (5 pts), boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
WebFetchToolInvocation.execute (cognitive 17) packages/core/src/tools/web-fetch.ts:771— WebFetchToolInvocation.execute has cognitive complexity 17 (threshold 15). Drivers by points: boolean chains 8, if/else 7 (8 pts), error handling 1 (nesting depth added 1). Of this number, 12 points are the body's own statements and 5 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
write-file.getCorrectedFileContent (cognitive 17) packages/core/src/tools/write-file.ts:114— write-file.getCorrectedFileContent has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (7 pts), error handling 3 (5 pts), ternaries 1 (3 pts), boolean chains 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
getFolderStructure.formatStructure (cognitive 17) packages/core/src/utils/getFolderStructure.ts:233— getFolderStructure.formatStructure has cognitive complexity 17 (threshold 15). Drivers by points: ternaries 5 (8 pts), boolean chains 4, if/else 3, loops 2 (nesting depth added 3). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
App.ConsoleLogEntry (cognitive 17) packages/devtools/client/src/App.tsx:610— App.ConsoleLogEntry has cognitive complexity 17 (threshold 15). Drivers by points: ternaries 6 (9 pts), boolean chains 4, if/else 3 (4 pts) (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
extension.activate (cognitive 17) packages/vscode-ide-companion/src/extension.ts:110— extension.activate has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (8 pts), boolean chains 5, ternaries 2 (3 pts), error handling 1 (nesting depth added 2). Most of this is not in the body itself: 8 of the 17 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 195, 140, 126, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
generate-settings-doc.collectEntries (cognitive 17) scripts/generate-settings-doc.ts:113— generate-settings-doc.collectEntries has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (11 pts), boolean chains 5, loops 1 (nesting depth added 6). Most of this is not in the body itself: 0 of the 17 points are its own statements and the rest belongs to one function literal inside it that branches (line 119). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
lint.runTSConfigLinter (cognitive 17) scripts/lint.js:331— lint.runTSConfigLinter has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (13 pts), error handling 2 (3 pts), loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
run_eval_regression.main (cognitive 17) scripts/run_eval_regression.js:22— run_eval_regression.main has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (13 pts), error handling 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
tool-log-formatter.formatToolLogChain (cognitive 17) scripts/utils/tool-log-formatter.ts:55— tool-log-formatter.formatToolLogChain has cognitive complexity 17 (threshold 15). Drivers by points: ternaries 4 (10 pts), boolean chains 3, if/else 2 (3 pts), loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
history-helper.getHistoricalAverage (cognitive 17) tools/gemini-cli-bot/metrics/history-helper.ts:21— history-helper.getHistoricalAverage has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (15 pts), error handling 1, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
index.processOutputLine (cognitive 17) tools/gemini-cli-bot/metrics/index.ts:41— index.processOutputLine has cognitive complexity 17 (threshold 15). Drivers by points: if/else 10 (14 pts), boolean chains 2, error handling 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
db_interface._release_lock_tx (cognitive 17) tools/caretaker-agent/cloudrun/pr-generator/workflow/db/db_interface.py:271— db_interface._release_lock_tx has cognitive complexity 17 (threshold 15). Drivers by points: if/else 10 (13 pts), boolean chains 2, ternaries 1 (2 pts) (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
config.loadEnvironment (cognitive 16) packages/a2a-server/src/config/config.ts:557— config.loadEnvironment has cognitive complexity 16 (threshold 15). Drivers by points: error handling 3 (7 pts), if/else 4 (6 pts), loops 1 (2 pts), boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
acpUtils.toPermissionOptions (cognitive 16) packages/cli/src/acp/acpUtils.ts:98— acpUtils.toPermissionOptions has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (13 pts), match/switch 2 (3 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
settings-validation.buildZodSchemaFromDefinition (cognitive 16) packages/cli/src/config/settings-validation.ts:167— settings-validation.buildZodSchemaFromDefinition has cognitive complexity 16 (threshold 15). Drivers by points: if/else 9 (14 pts), boolean chains 1, match/switch 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
restoreCommand.restoreAction (cognitive 16) packages/cli/src/ui/commands/restoreCommand.ts:39— restoreCommand.restoreAction has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (12 pts), boolean chains 1, error handling 1, loops 1, ternaries 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
skillsCommand.reloadAction (cognitive 16) packages/cli/src/ui/commands/skillsCommand.ts:247— skillsCommand.reloadAction has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (9 pts), ternaries 3 (6 pts), error handling 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
AppHeader.AppHeader (cognitive 16) packages/cli/src/ui/components/AppHeader.tsx:59— AppHeader.AppHeader has cognitive complexity 16 (threshold 15). Drivers by points: boolean chains 11, if/else 2 (3 pts), ternaries 2 (nesting depth added 1). Of this number, 11 points are the body's own statements and 5 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
ConfigInitDisplay.ConfigInitDisplay (cognitive 16) packages/cli/src/ui/components/ConfigInitDisplay.tsx:18— ConfigInitDisplay.ConfigInitDisplay has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (6 pts), ternaries 3 (6 pts), boolean chains 3, loops 1 (nesting depth added 4). Most of this is not in the body itself: 0 of the 16 points are its own statements and the rest belongs to one function literal inside it that branches (line 26). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
EditorSettingsDialog.EditorSettingsDialog (cognitive 16) packages/cli/src/ui/components/EditorSettingsDialog.tsx:38— EditorSettingsDialog.EditorSettingsDialog has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7, ternaries 6 (7 pts), boolean chains 2 (nesting depth added 1). Of this number, 9 points are the body's own statements and 7 belong to 4 function literals inside it that branch. To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
ToastDisplay.ToastDisplay (cognitive 16) packages/cli/src/ui/components/ToastDisplay.tsx:29— ToastDisplay.ToastDisplay has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (9 pts), ternaries 2 (4 pts), boolean chains 3 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
ToolConfirmationQueue.ToolConfirmationQueue (cognitive 16) packages/cli/src/ui/components/ToolConfirmationQueue.tsx:52— ToolConfirmationQueue.ToolConfirmationQueue has cognitive complexity 16 (threshold 15). Drivers by points: boolean chains 8, ternaries 5 (6 pts), if/else 2 (nesting depth added 1). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
EnumSelector.EnumSelector (cognitive 16) packages/cli/src/ui/components/shared/EnumSelector.tsx:23— EnumSelector.EnumSelector has cognitive complexity 16 (threshold 15). Drivers by points: ternaries 7, boolean chains 6, if/else 3. Of this number, 10 points are the body's own statements and 6 belong to 2 function literals inside it that branch. To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
text-buffer.findNextWordStartInLine (cognitive 16) packages/cli/src/ui/components/shared/text-buffer.ts:96— text-buffer.findNextWordStartInLine has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (6 pts), loops 3 (5 pts), boolean chains 4, ternaries 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
text-buffer.findPrevWordStartInLine (cognitive 16) packages/cli/src/ui/components/shared/text-buffer.ts:140— text-buffer.findPrevWordStartInLine has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (7 pts), loops 3 (5 pts), boolean chains 4 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ExtensionRegistryView.ExtensionRegistryView (cognitive 16) packages/cli/src/ui/components/views/ExtensionRegistryView.tsx:44— ExtensionRegistryView.ExtensionRegistryView has cognitive complexity 16 (threshold 15). Drivers by points: ternaries 7 (8 pts), boolean chains 6, if/else 2 (nesting depth added 1). Most of this is not in the body itself: 5 of the 16 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 139, 72, 205). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useBanner.useBanner (cognitive 16) packages/cli/src/ui/hooks/useBanner.ts:29— useBanner.useBanner has cognitive complexity 16 (threshold 15). Drivers by points: boolean chains 8, if/else 4 (6 pts), ternaries 2 (nesting depth added 2). Of this number, 9 points are the body's own statements and 7 belong to 2 function literals inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
useInputHistory.useInputHistory (cognitive 16) packages/cli/src/ui/hooks/useInputHistory.ts:25— useInputHistory.useInputHistory has cognitive complexity 16 (threshold 15). Drivers by points: if/else 11 (12 pts), boolean chains 2, ternaries 1 (2 pts) (nesting depth added 2). Most of this is not in the body itself: 0 of the 16 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 63, 110, 121, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
useSlashCompletion.useCommandParser (cognitive 16) packages/cli/src/ui/hooks/useSlashCompletion.ts:60— useSlashCompletion.useCommandParser has cognitive complexity 16 (threshold 15). Drivers by points: if/else 6 (10 pts), boolean chains 5, loops 1 (nesting depth added 4). Most of this is not in the body itself: 0 of the 16 points are its own statements and the rest belongs to one function literal inside it that branches (line 64). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal's work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest.
mouse.parseX11MouseEvent (cognitive 16) packages/cli/src/ui/utils/mouse.ts:131— mouse.parseX11MouseEvent has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (10 pts), match/switch 2 (5 pts), boolean chains 1 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
terminalSetup.detectTerminal (cognitive 16) packages/cli/src/ui/utils/terminalSetup.ts:147— terminalSetup.detectTerminal has cognitive complexity 16 (threshold 15). Drivers by points: if/else 6 (10 pts), boolean chains 4, error handling 1 (2 pts) (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ActivityLogger.sanitizeNetworkLog (cognitive 16) packages/cli/src/utils/activityLogger.ts:223— ActivityLogger.sanitizeNetworkLog has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (9 pts), loops 2 (4 pts), boolean chains 3 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
agentLoader.authConfigSchema (cognitive 16) packages/core/src/agents/agentLoader.ts:170— agentLoader.authConfigSchema has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (16 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
GoogleCredentialsAuthProvider.headers (cognitive 16) packages/core/src/agents/auth-provider/google-credentials-provider.ts:83— GoogleCredentialsAuthProvider.headers has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (7 pts), ternaries 2 (5 pts), error handling 2 (3 pts), boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
BrowserManager.checkNavigationRestrictions (cognitive 16) packages/core/src/agents/browser/browserManager.ts:907— BrowserManager.checkNavigationRestrictions has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (10 pts), error handling 2 (3 pts), boolean chains 2, loops 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ProjectRegistry.save (cognitive 16) packages/core/src/config/projectRegistry.ts:103— ProjectRegistry.save has cognitive complexity 16 (threshold 15). Drivers by points: error handling 3 (5 pts), if/else 3 (5 pts), ternaries 1 (3 pts), boolean chains 2, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
formatNodesForLlm.formatNodesForLlm (cognitive 16) packages/core/src/context/utils/formatNodesForLlm.ts:39— formatNodesForLlm.formatNodesForLlm has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (13 pts), boolean chains 2, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
contentGenerator.createContentGeneratorConfig (cognitive 16) packages/core/src/core/contentGenerator.ts:141— contentGenerator.createContentGeneratorConfig has cognitive complexity 16 (threshold 15). Drivers by points: boolean chains 11, if/else 5. Of this number, 14 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators.
hook-utils.evaluateBeforeToolHook (cognitive 16) packages/core/src/scheduler/hook-utils.ts:28— hook-utils.evaluateBeforeToolHook has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (8 pts), ternaries 1 (4 pts), error handling 1 (3 pts), boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
environmentSanitization.shouldRedactEnvironmentVariable (cognitive 16) packages/core/src/services/environmentSanitization.ts:143— environmentSanitization.shouldRedactEnvironmentVariable has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10 (13 pts), loops 2 (3 pts) (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
ExecutionLifecycleService.settleExecution (cognitive 16) packages/core/src/services/executionLifecycleService.ts:409— ExecutionLifecycleService.settleExecution has cognitive complexity 16 (threshold 15). Drivers by points: if/else 3 (4 pts), ternaries 2 (4 pts), boolean chains 3, error handling 1 (3 pts), loops 1 (2 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
LoopDetectionService.checkForLoopWithLLM (cognitive 16) packages/core/src/services/loopDetectionService.ts:563— LoopDetectionService.checkForLoopWithLLM has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (8 pts), ternaries 5, boolean chains 3 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
memoryPatchUtils.validateParsedSkillPatchHeaders (cognitive 16) packages/core/src/services/memoryPatchUtils.ts:139— memoryPatchUtils.validateParsedSkillPatchHeaders has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (9 pts), ternaries 2 (4 pts), boolean chains 2, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
memoryPatchUtils.validateInboxMemoryPatchFile (cognitive 16) packages/core/src/services/memoryPatchUtils.ts:529— memoryPatchUtils.validateInboxMemoryPatchFile has cognitive complexity 16 (threshold 15). Drivers by points: ternaries 3 (7 pts), if/else 3 (4 pts), error handling 2, match/switch 1 (2 pts), loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ModelConfigService.getAvailableModelOptions (cognitive 16) packages/core/src/services/modelConfigService.ts:154— ModelConfigService.getAvailableModelOptions has cognitive complexity 16 (threshold 15). Drivers by points: if/else 11, boolean chains 5. Most of this is not in the body itself: 0 of the 16 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 193, 166, 172, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
EditToolInvocation.constructor (cognitive 16) packages/core/src/tools/edit.ts:465— EditToolInvocation.constructor has cognitive complexity 16 (threshold 15). Drivers by points: error handling 4 (10 pts), if/else 5 (6 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ReadFileToolInvocation.execute (cognitive 16) packages/core/src/tools/read-file.ts:123— ReadFileToolInvocation.execute has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (8 pts), boolean chains 4, ternaries 3 (4 pts) (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
ReadBackgroundOutputInvocation.execute (cognitive 16) packages/core/src/tools/shellBackgroundTools.ts:133— ReadBackgroundOutputInvocation.execute has cognitive complexity 16 (threshold 15). Drivers by points: if/else 6 (7 pts), boolean chains 4, ternaries 2 (3 pts), error handling 2 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
ToolRegistry.isActiveTool (cognitive 16) packages/core/src/tools/tool-registry.ts:605— ToolRegistry.isActiveTool has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (11 pts), boolean chains 5 (nesting depth added 3). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ignorePathUtils.getNormalizedRelativePath (cognitive 16) packages/core/src/utils/ignorePathUtils.ts:16— ignorePathUtils.getNormalizedRelativePath has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (8 pts), boolean chains 4, error handling 1 (2 pts), ternaries 1 (2 pts) (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
security.isPathSecureSync (cognitive 16) packages/core/src/utils/security.ts:499— security.isPathSecureSync has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (11 pts), error handling 3, boolean chains 2 (nesting depth added 3). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Cell.update (cognitive 16) packages/core/src/utils/terminalSerializer.ts:59— Cell.update has cognitive complexity 16 (threshold 15). Drivers by points: if/else 16. To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
GeminiCliSession.sendStream (cognitive 16) packages/sdk/src/session.ts:211— GeminiCliSession.sendStream has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (12 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
OpenFilesManager.constructor (cognitive 16) packages/vscode-ide-companion/src/open-files-manager.ts:25— OpenFilesManager.constructor has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (12 pts), boolean chains 2, loops 2 (nesting depth added 4). Most of this is not in the body itself: 2 of the 16 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 60, 51, 27, …). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals' work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest.
build_binary.signFile (cognitive 16) scripts/build_binary.js:101— build_binary.signFile has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (12 pts), boolean chains 2, error handling 1 (2 pts) (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
eval-validate-cli.main (cognitive 16) scripts/eval-validate-cli.ts:28— eval-validate-cli.main has cognitive complexity 16 (threshold 15). Drivers by points: if/else 9 (11 pts), loops 1 (2 pts), ternaries 2, boolean chains 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
generate-settings-doc.renderSections (cognitive 16) scripts/generate-settings-doc.ts:189— generate-settings-doc.renderSections has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (12 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
run_regression_check.processResults (cognitive 16) scripts/run_regression_check.js:228— run_regression_check.processResults has cognitive complexity 16 (threshold 15). Drivers by points: if/else 6 (10 pts), loops 3 (5 pts), boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
eval-inventory.formatInventoryJson (cognitive 16) scripts/utils/eval-inventory.ts:228— eval-inventory.formatInventoryJson has cognitive complexity 16 (threshold 15). Drivers by points: if/else 6 (9 pts), loops 4, boolean chains 3 (nesting depth added 3). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
github.handleEgressEvent (cognitive 16) tools/caretaker-agent/cloudrun/egress-service/src/actions/github.ts:39— github.handleEgressEvent has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (9 pts), boolean chains 4, loops 1 (2 pts), match/switch 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Change-coupling hub: AppContainer.tsx → render.tsx, Composer.tsx, DialogManager.tsx, nonInteractiveUi.ts packages/cli/src/ui/AppContainer.tsx— `packages/cli/src/ui/AppContainer.tsx` changes together with 4 other files — `packages/cli/src/test-utils/render.tsx`, `packages/cli/src/ui/components/Composer.tsx`, `packages/cli/src/ui/components/DialogManager.tsx`, `packages/cli/src/ui/noninteractive/nonInteractiveUi.ts` — none of which declares a dependency on it: one file is the hub of 4 separate couplings, not 4 unrelated pairs. Read the hub first: if the others each duplicate a part of what it does, the shared concern belongs in ONE unit and extracting it clears every edge at once; if the hub is a registry, dispatcher or barrel that must name each of them, the coupling is structural and the question is whether that list can be discovered instead of enumerated. Fixing the hub is one change; breaking the couplings one pair at a time is 4.
End-of-life runtime: Node.js 20 — .nvmrc declares Node.js 20 as this project's version file, and Node.js 20, support ended 2026-04-30. An unsupported runtime receives no security patches, so every vulnerability disclosed in it since 2026-04-30 is present and unfixable without moving off it. This is a migration rather than an upgrade: there is no newer release of a runtime that has ended.
Coverage not measured — JavaScript/TypeScript suite — Coverage NOT MEASURED: the JavaScript/TypeScript half could not be measured — the vitest suite in the repository root ran and passed but wrote no lcov report. Coverage is excluded from the score rather than counted as a near-zero. The named suite step is one the repository's maintainers can perform; once it passes, the real number is measured on the next scan. Alternatively, commit the lcov/Cobertura report your CI produces and it is read without a re-run.
Duplication concentrated across 4 sibling directories (27 clone groups) packages/a2a-server/src/commands/restore.ts:66— 27 duplicated blocks under packages/ have copies in at least two of the sibling directories a2a-server, cli, core, devtools — 20 of them are reported below, and 7 are counted here but not reported individually: those copies match on shape but no longer clear R10's bar for an individually reported row — either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 27 and which does not depend on how exactly each block's copies still match. That concentration is one structural fact, not 27 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module — a common library every sibling imports — rather than 27 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on.
Duplication concentrated across 18 sibling directories (22 clone groups) packages/core/src/agent/legacy-agent-session.ts:400— 22 duplicated blocks under packages/core/src/ have copies in at least two of the sibling directories agent, agents, code_assist, commands, config, context (+12 more sibling(s) not listed) — 11 of them are reported below, and 11 are counted here but not reported individually: those copies match on shape but no longer clear R10's bar for an individually reported row — either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 22 and which does not depend on how exactly each block's copies still match. That concentration is one structural fact, not 22 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module — a common library every sibling imports — rather than 22 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on.
Duplication concentrated across 7 sibling directories (16 clone groups) packages/cli/src/ui/hooks/useExtensionUpdates.ts:176— 16 duplicated blocks under packages/cli/src/ have copies in at least two of the sibling directories acp, commands, config, core, services, ui (+1 more sibling(s) not listed) — 10 of them are reported below, and 6 are counted here but not reported individually: those copies match on shape but no longer clear R10's bar for an individually reported row — either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 16 and which does not depend on how exactly each block's copies still match. That concentration is one structural fact, not 16 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module — a common library every sibling imports — rather than 16 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on.
Duplication concentrated across 5 sibling directories (15 clone groups) packages/cli/src/ui/auth/ApiAuthDialog.tsx:94— 15 duplicated blocks under packages/cli/src/ui/ have copies in at least two of the sibling directories auth, commands, components, hooks, privacy — 5 of them are reported below, and 10 are counted here but not reported individually: those copies match on shape but no longer clear R10's bar for an individually reported row — either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 15 and which does not depend on how exactly each block's copies still match. That concentration is one structural fact, not 15 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module — a common library every sibling imports — rather than 15 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on.
Duplication concentrated across 3 sibling directories (6 clone groups) packages/core/src/code_assist/experiments/client_metadata.ts:19— 6 duplicated blocks under the repository root have copies in at least two of the sibling directories evals, packages, scripts — 1 of them are reported below, and 5 are counted here but not reported individually: those copies match on shape but no longer clear R10's bar for an individually reported row — either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 6 and which does not depend on how exactly each block's copies still match. That concentration is one structural fact, not 6 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module — a common library every sibling imports — rather than 6 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on.
Wholesale file copy (285 identical lines × 2 files) packages/core/src/tools/definitions/model-family-sets/default-legacy.ts:12— packages/core/src/tools/definitions/model-family-sets/default-legacy.ts:12 · packages/core/src/tools/definitions/model-family-sets/gemini-3.ts:12 — these 2 files are line-for-line copies of one another — 285 lines are identical, in the same order, in every one of them — so this is one fact about the file set, not a block to extract. An edit made to one file and not the others changes behaviour silently, which is the failure a wholesale copy guarantees. Pick one file as the single source and derive the others from it (re-export it, spread it into the local overrides each variant genuinely needs, or generate the copies at build time) — the few lines that differ between the files are exactly the part each variant should still own. Check first whether the copies are deliberately standalone deliverables (a translation file seeded from its sibling and waiting to be translated); where they are, the duplication is the design, and the honest move is to mark the seeded file as untranslated rather than to let it pass as done.
R10 · Code Duplication· Duplicated block with local edits (248 matched lines × 2 locations) · ×1
Duplicated block with local edits (248 matched lines × 2 locations) packages/core/src/tools/grep.ts:153— packages/core/src/tools/grep.ts:153 · packages/core/src/tools/ripGrep.ts:189 — the two spans are one implementation copied and then locally edited — 1149 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
R10 · Code Duplication· Duplicated block with local edits (228 matched lines × 2 locations) · ×1
Duplicated block with local edits (228 matched lines × 2 locations) packages/core/src/agents/local-invocation.ts:71— packages/core/src/agents/local-invocation.ts:71 · packages/core/src/agents/local-session-invocation.ts:82 — the two spans are one implementation copied and then locally edited — 1241 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
R10 · Code Duplication· Duplicated block with local edits (199 matched lines × 2 locations) · ×1
Duplicated block with local edits (199 matched lines × 2 locations) packages/core/src/prompts/snippets.legacy.ts:32— packages/core/src/prompts/snippets.legacy.ts:32 · packages/core/src/prompts/snippets.ts:43 — the two spans are one implementation copied and then locally edited — 995 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
R10 · Code Duplication· Duplicated block with local edits (130 matched lines × 2 locations) · ×1
Duplicated block with local edits (130 matched lines × 2 locations) packages/cli/src/ui/components/triage/TriageDuplicates.tsx:25— packages/cli/src/ui/components/triage/TriageDuplicates.tsx:25 · packages/cli/src/ui/components/triage/TriageIssues.tsx:25 — the two spans are one implementation copied and then locally edited — 710 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block (110 lines × 2 locations) REDACTED:36— REDACTED:36 · REDACTED:174 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (101 lines × 2 locations) packages/cli/src/nonInteractiveCli.ts:85— packages/cli/src/nonInteractiveCli.ts:85 · packages/cli/src/nonInteractiveCliAgentSession.ts:82 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (71 lines × 2 locations) packages/cli/src/ui/components/shared/text-buffer.ts:3731— packages/cli/src/ui/components/shared/text-buffer.ts:3731 · packages/cli/src/ui/components/shared/text-buffer.ts:3837 — all 2 copies are in the same file, and what repeats is a LIST OF ENTRIES rather than behaviour — the same entries written out more than once. Extract them into one shared, exported constant and spread that constant into each site, rather than into a function the sites call: a list like this often lives in declarative metadata (a decorator's options object, a static configuration table) that a build step must be able to read statically, where a function call is not allowed. Adding an entry to one copy and not the other is the failure this prevents.
R10 · Code Duplication· Duplicated block with local edits (70 matched lines × 2 locations) · ×1
Duplicated block with local edits (70 matched lines × 2 locations) scripts/aggregate_evals.js:18— scripts/aggregate_evals.js:18 · scripts/eval_utils.js:15 — the two spans are one implementation copied and then locally edited — 478 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
R10 · Code Duplication· Duplicated block with local edits (67 matched lines × 2 locations) · ×1
Duplicated block with local edits (67 matched lines × 2 locations) packages/core/src/context/processors/rollingSummaryProcessor.ts:24— packages/core/src/context/processors/rollingSummaryProcessor.ts:24 · packages/core/src/context/processors/stateSnapshotProcessor.ts:25 — the two spans are one implementation copied and then locally edited — 338 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
R10 · Code Duplication· Duplicated block with local edits (66 matched lines × 2 locations) · ×1
Duplicated block with local edits (66 matched lines × 2 locations) packages/cli/src/ui/components/shared/vim-buffer-actions.ts:194— packages/cli/src/ui/components/shared/vim-buffer-actions.ts:194 · packages/cli/src/ui/components/shared/vim-buffer-actions.ts:377 — the two spans are one implementation copied and then locally edited — 245 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
R10 · Code Duplication· Duplicated block with local edits (57 matched lines × 2 locations) · ×1
Duplicated block with local edits (57 matched lines × 2 locations) packages/core/src/telemetry/clearcut-logger/clearcut-logger.ts:1515— packages/core/src/telemetry/clearcut-logger/clearcut-logger.ts:1515 · packages/core/src/telemetry/clearcut-logger/clearcut-logger.ts:1656 — the two spans are one implementation copied and then locally edited — 272 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block (55 lines × 2 locations) packages/cli/src/ui/components/shared/text-buffer.ts:420— packages/cli/src/ui/components/shared/text-buffer.ts:420 · packages/cli/src/ui/components/shared/text-buffer.ts:521 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
R10 · Code Duplication· Duplicated block with local edits (53 matched lines × 2 locations) · ×1
Duplicated block with local edits (53 matched lines × 2 locations) packages/core/src/tools/list-mcp-resources.ts:25— packages/core/src/tools/list-mcp-resources.ts:25 · packages/core/src/tools/read-mcp-resource.ts:26 — the two spans are one implementation copied and then locally edited — 184 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block (52 lines × 2 locations) packages/core/src/agents/local-subagent-protocol.ts:143— packages/core/src/agents/local-subagent-protocol.ts:143 · packages/core/src/agents/remote-subagent-protocol.ts:129 — the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it.
R10 · Code Duplication· Duplicated block with local edits (51 matched lines × 2 locations) · ×1
Duplicated block with local edits (51 matched lines × 2 locations) packages/cli/src/utils/agentSettings.ts:15— packages/cli/src/utils/agentSettings.ts:15 · packages/cli/src/utils/skillSettings.ts:18 — the two spans are one implementation copied and then locally edited — 222 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block (49 lines × 2 locations) packages/core/src/context/config/profiles.ts:82— packages/core/src/context/config/profiles.ts:82 · packages/core/src/context/config/profiles.ts:224 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (43 lines × 2 locations) packages/core/src/commands/memory.ts:839— packages/core/src/commands/memory.ts:839 · packages/core/src/commands/memory.ts:1256 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
R10 · Code Duplication· Duplicated block with local edits (42 matched lines × 2 locations) · ×1
Duplicated block with local edits (42 matched lines × 2 locations) packages/core/src/agents/browser/browserAgentInvocation.ts:166— packages/core/src/agents/browser/browserAgentInvocation.ts:166 · packages/core/src/agents/local-invocation.ts:121 — the two spans are one implementation copied and then locally edited — 254 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
R10 · Code Duplication· Duplicated block with local edits (41 matched lines × 2 locations) · ×1
Duplicated block with local edits (41 matched lines × 2 locations) packages/core/src/utils/extensionLoader.ts:51— packages/core/src/utils/extensionLoader.ts:51 · packages/core/src/utils/extensionLoader.ts:159 — the two spans are one implementation copied and then locally edited — 221 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
R10 · Code Duplication· Duplicated block with local edits (40 matched lines × 2 locations) · ×1
Duplicated block with local edits (40 matched lines × 2 locations) evals/plan_mode.eval.ts:227— evals/plan_mode.eval.ts:227 · evals/plan_mode.eval.ts:308 — the two spans are one implementation copied and then locally edited — 194 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
R10 · Code Duplication· Duplicated block with local edits (39 matched lines × 2 locations) · ×1
Duplicated block with local edits (39 matched lines × 2 locations) packages/cli/src/ui/hooks/shell-completions/gitProvider.ts:29— packages/cli/src/ui/hooks/shell-completions/gitProvider.ts:29 · packages/cli/src/ui/hooks/shell-completions/npmProvider.ts:24 — the two spans are one implementation copied and then locally edited — 202 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Complex function handleVimAction (cyclomatic 246, cognitive 407) packages/cli/src/ui/components/shared/vim-buffer-actions.ts:164— handleVimAction has cyclomatic complexity 246 and cognitive complexity 407; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function (anonymous) (cyclomatic 204, cognitive 312) packages/cli/src/ui/components/InputPrompt.tsx:686— (anonymous) has cyclomatic complexity 204 and cognitive complexity 312; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function textBufferReducerLogic (cyclomatic 194, cognitive 212) packages/cli/src/ui/components/shared/text-buffer.ts:1787— textBufferReducerLogic has cyclomatic complexity 194 and cognitive complexity 212; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function constructor (cyclomatic 150, cognitive 146) packages/core/src/config/config.ts:993— constructor has cyclomatic complexity 150 and cognitive complexity 146; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function (anonymous) (cyclomatic 136, cognitive 274) packages/cli/src/ui/hooks/vim.ts:660— (anonymous) has cyclomatic complexity 136 and cognitive complexity 274; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function start_sandbox (cyclomatic 131, cognitive 225) packages/cli/src/utils/sandbox.ts:55— start_sandbox has cyclomatic complexity 131 and cognitive complexity 225; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function loadCliConfig (cyclomatic 125, cognitive 132) packages/cli/src/config/config.ts:583— loadCliConfig has cyclomatic complexity 125 and cognitive complexity 132; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function emitKeys (cyclomatic 95, cognitive 197) packages/cli/src/ui/contexts/KeypressContext.tsx:380— emitKeys has cyclomatic complexity 95 and cognitive complexity 197; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function isSafeToCallWithExec (cyclomatic 91, cognitive 284) packages/core/src/sandbox/utils/commandSafety.ts:230— isSafeToCallWithExec has cyclomatic complexity 91 and cognitive complexity 284; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function (anonymous) (cyclomatic 87, cognitive 169) packages/cli/src/nonInteractiveCliAgentSession.ts:82— (anonymous) has cyclomatic complexity 87 and cognitive complexity 169; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function #resolvePrompt (cyclomatic 84, cognitive 199) packages/cli/src/acp/acpSession.ts:969— #resolvePrompt has cyclomatic complexity 84 and cognitive complexity 199; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function (anonymous) (cyclomatic 80, cognitive 173) packages/cli/src/nonInteractiveCli.ts:85— (anonymous) has cyclomatic complexity 80 and cognitive complexity 173; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function loadConversationRecord (cyclomatic 74, cognitive 178) packages/core/src/services/chatRecordingService.ts:133— loadConversationRecord has cyclomatic complexity 74 and cognitive complexity 178; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function installOrUpdateExtension (cyclomatic 72, cognitive 93) packages/cli/src/config/extension-manager.ts:180— installOrUpdateExtension has cyclomatic complexity 72 and cognitive complexity 93; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function AppContainer (cyclomatic 70, cognitive 27) packages/cli/src/ui/AppContainer.tsx:223— AppContainer has cyclomatic complexity 70 and cognitive complexity 27; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
R2 · Cyclomatic Complexity· Complex function main (cyclomatic 69, cognitive 100) · ×1
Complex function main (cyclomatic 69, cognitive 100) packages/cli/src/gemini.tsx:466— main has cyclomatic complexity 69 and cognitive complexity 100; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function processStreamResponse (cyclomatic 67, cognitive 155) packages/core/src/core/geminiChat.ts:1354— processStreamResponse has cyclomatic complexity 67 and cognitive complexity 155; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function classifyGoogleError (cyclomatic 66, cognitive 98) packages/core/src/utils/googleQuotaErrors.ts:223— classifyGoogleError has cyclomatic complexity 66 and cognitive complexity 98; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function createCustomTheme (cyclomatic 63, cognitive 39) packages/cli/src/ui/themes/theme.ts:394— createCustomTheme has cyclomatic complexity 63 and cognitive complexity 39; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function check (cyclomatic 59, cognitive 109) packages/core/src/policy/policy-engine.ts:600— check has cyclomatic complexity 59 and cognitive complexity 109; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Dead file (~251 LoC) scripts/sync_project_dry_run.js— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~180 LoC) scripts/cleanup-branches.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~151 LoC) scripts/close_duplicate_issues.js— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~148 LoC) tools/gemini-cli-bot/metrics/scripts/domain_expertise.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~141 LoC) tools/gemini-cli-bot/metrics/scripts/time_to_first_response.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~125 LoC) tools/gemini-cli-bot/metrics/scripts/actions_spend.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~121 LoC) packages/core/scripts/compile-windows-sandbox.js— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~99 LoC) packages/vscode-ide-companion/scripts/check-vscode-release.js— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~86 LoC) tools/gemini-cli-bot/metrics/scripts/user_touches.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~77 LoC) tools/gemini-cli-bot/metrics/scripts/review_distribution.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~68 LoC) scripts/prepare-github-release.js— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~67 LoC) scripts/prepare-npm-release.js— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~62 LoC) packages/a2a-server/src/utils/path_utils.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~59 LoC) tools/gemini-cli-bot/metrics/scripts/backlog_age.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~51 LoC) scripts/test-windows-paths.js— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~45 LoC) packages/cli/src/ui/utils/terminalUtils.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~14 LoC) tools/gemini-cli-bot/metrics/types.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), but 9 in-repo import(s) from 9 other file(s) do name it (tools/gemini-cli-bot/metrics/scripts/backlog_age.ts, tools/gemini-cli-bot/metrics/scripts/domain_expertise.ts, tools/gemini-cli-bot/metrics/scripts/latency.ts and 6 more) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~10 LoC) packages/core/src/policy/index.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~8 LoC) packages/core/src/confirmation-bus/index.ts— no import path from any entry point (226 application, 49 tooling, 1064 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Unused dependency 'depcheck' — Declared in the root package.json but never imported anywhere in that package or its workspace members — no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it.
Unused dependency 'domexception' — Declared in the root package.json but never imported anywhere in that package or its workspace members — no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it.
Unused dependency 'node-fetch-native' — Declared in the root package.json but never imported anywhere in that package or its workspace members — no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it.
Off-boarding risk: anonymized user #1 — If anonymized user #1 becomes unavailable, 16 significant file(s) lose their only recent owner: tools/caretaker-agent/evals/triage/helpers/summary.py, REDACTED, tools/caretaker-agent/cloudrun/triage-worker/db/issues_store.py, tools/caretaker-agent/evals/triage/runner.py, tools/caretaker-agent/cloudrun/triage-worker/main.py, tools/caretaker-agent/evals/triage/judge.py, tools/caretaker-agent/cloudrun/triage-worker/utils/agent_logger.py, tools/caretaker-agent/evals/triage/tools/dataset_metrics.py (+8 more). Pair on, review, or document these before any departure.
Off-boarding risk: anonymized user #2 — If anonymized user #2 becomes unavailable, 14 significant file(s) lose their only recent owner: packages/core/src/context/utils/snapshotGenerator.ts, packages/core/src/context/pipeline/contextWorkingBuffer.ts, packages/core/src/context/testing/contextTestUtils.ts, packages/core/src/context/config/profiles.ts, packages/core/src/context/graph/toGraph.ts, packages/core/src/context/graph/render.ts, packages/core/src/context/processors/stateSnapshotProcessor.ts, packages/core/src/context/utils/contextTokenCalculator.ts (+6 more). Pair on, review, or document these before any departure.
Off-boarding risk: anonymized user #3 — If anonymized user #3 becomes unavailable, 7 significant file(s) lose their only recent owner: scripts/utils/eval-analysis.ts, scripts/utils/eval-validate.ts, scripts/utils/eval-inventory.ts, scripts/utils/eval-report.ts, scripts/utils/eval-coverage.ts, scripts/utils/tool-registry.ts, scripts/eval-validate-cli.ts. Pair on, review, or document these before any departure.
Off-boarding risk: anonymized user #4 — If anonymized user #4 becomes unavailable, 7 significant file(s) lose their only recent owner: packages/cli/src/ui/components/InboxDialog.tsx, packages/core/src/services/memoryService.ts, evals/skill_extraction.eval.ts, packages/core/src/agents/skill-extraction-agent.ts, packages/core/src/services/memoryPatchUtils.ts, packages/cli/src/utils/devtoolsService.ts, packages/core/src/config/scoped-config.ts. Pair on, review, or document these before any departure.
Off-boarding risk: anonymized user #5 — If anonymized user #5 becomes unavailable, 6 significant file(s) lose their only recent owner: evals/frugalReads.eval.ts, evals/answer-vs-act.eval.ts, evals/automated-tool-use.eval.ts, tools/gemini-cli-bot/metrics/scripts/actions_spend.ts, evals/frugalSearch.eval.ts, evals/edit-locations-eval.eval.ts. Pair on, review, or document these before any departure.
Off-boarding risk: anonymized user #6 — If anonymized user #6 becomes unavailable, 4 significant file(s) lose their only recent owner: packages/core/src/agents/remote-subagent-protocol.ts, packages/core/src/agents/local-subagent-protocol.ts, packages/core/src/agents/local-session-invocation.ts, packages/core/src/agents/remote-session-invocation.ts. Pair on, review, or document these before any departure.
Off-boarding risk: anonymized user #7 — If anonymized user #7 becomes unavailable, 3 significant file(s) lose their only recent owner: tools/caretaker-agent/cloudrun/pr-generator/workflow/orchestrator.py, tools/caretaker-agent/cloudrun/pr-generator/workflow/db/db_interface.py, tools/caretaker-agent/cloudrun/pr-generator/workflow/agent_runner.py. Pair on, review, or document these before any departure.
Off-boarding risk: anonymized user #8 — If anonymized user #8 becomes unavailable, 3 significant file(s) lose their only recent owner: packages/core/src/tools/trackerTools.ts, packages/core/src/services/trackerService.ts, packages/core/src/tools/definitions/trackerTools.ts. Pair on, review, or document these before any departure.
Off-boarding risk: anonymized user #9 — If anonymized user #9 becomes unavailable, 3 significant file(s) lose their only recent owner: packages/cli/src/ui/utils/mouse.ts, scripts/cleanup-branches.ts, packages/cli/src/ui/hooks/useAnimatedScrollbar.ts. Pair on, review, or document these before any departure.
Documentation: no installation or build instructions README.md— The README installs via npx but there is no build or setup section for developers who need to install the CLI globally with npm, Homebrew/macPorts/Anaconda, or create a new environment. Add an Install Globally section covering each supported package manager and environment setup.
Documentation: no usage examples README.md— The README describes npx usage but there are no runnable examples showing how to run the CLI from the command line or interactively in the editor. Add a short Usage section with an example of running Gemini CLI and a quick interactive demo (e.g. `gemini` + `/theme`).
Documentation: no project overview docs/index.md— The README gives a high-level overview of what Gemini CLI does but lacks an explicit project description or purpose that explains why it matters to users. Add a one-line 'What is Gemini CLI?' section in the README summarizing its role as a model-integrated terminal tool for code understanding, automation, and workflows.
Documentation: no installation or build instructions docs/index.md— The install section only shows the global install command (`npm install -g @google/gemini-cli`) without any setup or prerequisites. Expand the Install guide to add prerequisites (node/npm version, required dependencies), a quick start, and links to authentication, CLI cheatsheet, and tutorials.
D16 · Bus Factor· Further sole-owners (lower concentration) · ×1
Further sole-owners (lower concentration) — 12 other contributor(s) are each the sole owner of a small amount of code below the off-boarding threshold — folded into the bus-factor score and metrics (77 single-owned of 770 analysed files in total, counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 770 of the 1202 production source files in this repository met that bar). They are anonymized user #10 (2 file(s)), anonymized user #11 (2 file(s)), anonymized user #12 (1 file(s)), anonymized user #13 (1 file(s)), anonymized user #14 (1 file(s)), anonymized user #15 (1 file(s)) (+6 more) — spread or document their files in the same way, at lower priority than the named off-boarding risks above.
No ADRs found — No ADRs found. No recognised ADR directory (`docs/adr/`, `docs/decisions/`, `adr/`, `docs/rfcs/`, an `ADR0001/` folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (`docs/adr/use-postgres.md`, `docs/adr/2024/0001-x.md`); or a file anywhere whose name is ADR-shaped (`0001-use-postgres.md`, `adr-012-caching.md`); or, when neither turned anything up, a document carrying the decision-record signature (an "Architecture Decision Record" heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these — unnumbered files outside any recognised directory, without those headings — is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in `docs/adr/`.
D28 · Secrets (history)· Rotate the exposed credentials · ×1
D34 · Knowledge Freshness· Orphaned files with no living knowledge · ×1
Orphaned files with no living knowledge — 84 of 770 analysed file(s) have no living knowledge left — their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 770 of the 1202 production source files in this repository met that bar). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each — most significant first: packages/core/src/context/contextCompressionService.ts, packages/cli/src/commands/gemma/setup.ts, packages/core/src/context/toolDistillationService.ts, packages/cli/src/ui/components/ColorsDisplay.tsx, packages/core/src/tools/shellBackgroundTools.ts, packages/cli/src/commands/gemma/platform.ts, packages/core/src/telemetry/billingEvents.ts, packages/cli/src/ui/components/messages/ToolGroupDisplay.tsx (and 76 more). Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway.
No ADRs — No Architecture Decision Records found — no conventional ADR directory, no numbered `NNNN-title` documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer.
R7 · Dead Code· Unused export 'shortAsciiLogoCompactText' · ×1
Unused export 'shortAsciiLogoCompactText' packages/cli/src/ui/components/AsciiArt.ts:40— Nothing imports this binding — it is safe to review for removal.
R7 · Dead Code· Unused export 'tinyAsciiLogoCompactText' · ×1
Unused export 'tinyAsciiLogoCompactText' packages/cli/src/ui/components/AsciiArt.ts:54— Nothing imports this binding — it is safe to review for removal.
R7 · Dead Code· Unused export 'useAskUserActions' · ×1
Unused export 'useAskUserActions' packages/cli/src/ui/contexts/AskUserActionsContext.tsx:30— Nothing imports this binding — it is safe to review for removal.
R7 · Dead Code· Unused export 'REDIRECTION_WARNING_NOTE_LABEL' · ×1
Unused export 'REDIRECTION_WARNING_NOTE_LABEL' packages/cli/src/ui/textConstants.ts:15— Nothing imports this binding — it is safe to review for removal.
R7 · Dead Code· Unused export 'REDIRECTION_WARNING_NOTE_TEXT' · ×1
Unused export 'REDIRECTION_WARNING_NOTE_TEXT' packages/cli/src/ui/textConstants.ts:16— Nothing imports this binding — it is safe to review for removal.
R7 · Dead Code· Unused export 'REDIRECTION_WARNING_TIP_LABEL' · ×1
Unused export 'REDIRECTION_WARNING_TIP_LABEL' packages/cli/src/ui/textConstants.ts:18— Nothing imports this binding — it is safe to review for removal.
R7 · Dead Code· Unused export 'getRedirectionWarningTipText' · ×1
Unused export 'getRedirectionWarningTipText' packages/cli/src/ui/textConstants.ts:19— Nothing imports this binding — it is safe to review for removal.
R7 · Dead Code· Unused export 'getSafeLowColorBackground' · ×1
Unused export 'getSafeLowColorBackground' packages/cli/src/ui/themes/color-utils.ts:62— Nothing imports this binding — it is safe to review for removal.
R7 · Dead Code· Unused export 'LIGHT_THEME_LUMINANCE_THRESHOLD' · ×1
Unused export 'LIGHT_THEME_LUMINANCE_THRESHOLD' packages/cli/src/ui/themes/color-utils.ts:85— Nothing imports this binding — it is safe to review for removal.
R7 · Dead Code· Unused export 'DARK_THEME_LUMINANCE_THRESHOLD' · ×1
Unused export 'DARK_THEME_LUMINANCE_THRESHOLD' packages/cli/src/ui/themes/color-utils.ts:86— Nothing imports this binding — it is safe to review for removal.
Unused export 'isAnsiOutput' packages/cli/src/ui/types.ts:105— Nothing imports this binding — it is safe to review for removal.
R7 · Dead Code· Unused export 'QUOTA_THRESHOLD_HIGH' · ×1
Unused export 'QUOTA_THRESHOLD_HIGH' packages/cli/src/ui/utils/displayUtils.ts:19— Nothing imports this binding — it is safe to review for removal.
R7 · Dead Code· Unused export 'QUOTA_THRESHOLD_MEDIUM' · ×1
Unused export 'QUOTA_THRESHOLD_MEDIUM' packages/cli/src/ui/utils/displayUtils.ts:20— Nothing imports this binding — it is safe to review for removal.
R8 · Dependency Hygiene· Test-only dependency 'marked' in production deps · ×1
Test-only dependency 'marked' in production deps packages/core/src/utils/memoryImportProcessor.test.ts:12— Only test files import it — move it to devDependencies.
Skipped (documented): should run allowed sub-command in non-interactive mode integration-tests/run_shell_command.test.ts:169— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should succeed with no parens in non-interactive mode integration-tests/run_shell_command.test.ts:213— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should work with ShellTool alias integration-tests/run_shell_command.test.ts:286— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should combine multiple --allowed-tools flags integration-tests/run_shell_command.test.ts:331— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should reject chained commands when only the first segment is allowlisted in non-interactive mode integration-tests/run_shell_command.test.ts:448— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should run a platform-specific file listing command integration-tests/run_shell_command.test.ts:559— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should handle $ literally when replacing text ending with $ integration-tests/replace.test.ts:39— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should insert a multi-line block of text integration-tests/replace.test.ts:61— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should delete a block of text integration-tests/replace.test.ts:81— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should be able to read multiple files integration-tests/read_many_files.test.ts:24— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should switch from a pro model to a flash model after exiting plan mode integration-tests/plan-mode.test.ts:235— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): (unnamed test) integration-tests/hooks-system.test.ts:583— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skipIf
Skipped (documented): should replace multiple instances of a string integration-tests/file-system.test.ts:178— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): installs a local extension, updates it, checks it was reloaded properly integration-tests/extensions-reload.test.ts:27— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should handle compression failure on token inflation integration-tests/context-compress-interactive.test.ts:66— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): (unnamed test) integration-tests/browser-policy.test.ts:67— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skipIf
Skipped (documented): should log error when cleanupExpiredSessions fails packages/cli/src/gemini_cleanup.test.tsx:203— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should log error when cleanupExpiredSessions fails packages/cli/src/gemini.test.tsx:945— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): should combine and resolve paths from settings and CLI arguments packages/cli/src/config/config.test.ts:2031— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): (unnamed test) packages/cli/src/utils/sessionCleanup.test.ts:669— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skipIf
Skipped (documented): (unnamed test) packages/cli/src/utils/sessionCleanup.test.ts:699— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skipIf
Skipped (documented): should replace an existing dynamic policy when an agent is overwritten packages/core/src/agents/registry.test.ts:1117— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
Skipped (documented): (unnamed test) packages/core/src/commands/memory.test.ts:526— Skipped with a documented reason — a deferral, not lazy debt: declared with no body — a pending test the runner lists but never runs
Skipped (documented): (unnamed test) packages/core/src/commands/memory.test.ts:753— Skipped with a documented reason — a deferral, not lazy debt: declared with no body — a pending test the runner lists but never runs
Skipped (documented): will not attempt to compress context after a failure packages/core/src/core/client.test.ts:573— Skipped with a documented reason — a deferral, not lazy debt: switched off by it.skip
+ 15 more in this group — see findings.md.
Appendix B — Reproduction & audit trail
Every external tool invocation behind a deep-scan dimension — the tool, its captured version, the exact command, how many findings it yielded, and a link to the retained raw output. To reproduce any finding: check out the same commit and run the command shown (repo-relative — never an absolute scratch path). The complete raw scanner output is retained verbatim under artifacts/raw/ (indexed in artifacts/raw/index.json); per-invocation exit codes and wall-clock durations are in sidecar.json — kept out of this table so the rendered report stays byte-identical across runs of the same commit.
semgrep: not applicable — No personal data was found crossing a boundary the PII/GDPR ruleset checks — nothing written to a log or console sink, placed in a URL or query string, or persisted to browser storage. That is a clean result for the LEAK surface only: this ruleset detects personal data escaping, it does not inventory the personal data a repository holds, so it is not evidence that this repository has no personal-data surface. The personal-data map (Appendix C) and the C1-C5 compliance cards are what speak to that. semgrep could not parse 16 file(s) — `packages/cli/src/config/settings.ts`, `packages/cli/src/config/settingsSchema.ts`, `packages/cli/src/nonInteractiveCliAgentSession.ts`, `packages/cli/src/ui/hooks/useAgentStream.ts`, `packages/cli/src/ui/hooks/useAtCompletion.ts`, … (+11 more) — so the PII/GDPR sweep did not cover the unparsed regions of them; rows reported elsewhere in those files are real.
runtime-hardening: not applicable — No Kubernetes/orchestration workloads found in the repository manifests; network egress policy is a cluster-native control that may live at the platform/firewall layer, so there is nothing to assess here.
runtime-hardening: not applicable — No Kubernetes/orchestration workloads found in the repository manifests; seccomp/AppArmor/SELinux confinement is a workload-level control, so there is nothing to assess here.
runtime-hardening: not applicable — No Kubernetes/orchestration workloads found in the repository manifests; runtime threat-detection and admission-control policy are cluster-level controls, so there is nothing to assess here.
Run 01a0cb1d-e856-73b3-8716-97b7af2447eb · every finding is also locatable in findings.md, and the complete scoring record (with exit codes + durations) in sidecar.json.
Issues: 86 · Warnings: 1549 · Recommendations: 45 · Info: 40 — Appendix A · all findings · full markdown report.
Generated by Watchdog — deterministic code-health analysis. 22-09-2026 @ 21:55 UTC.
Downloadable artifacts
Machine-readable and reproducible from this commit + frozen rubric — drop them straight into a contract appendix, a CRA dossier, or a downstream SCA / VEX tool.