Clear out what the AI left behind.

Each prompt adds a layer. The old auth path stays “just in case”, the previous version is commented out, and a file nobody imports keeps getting edited.

npx @neuralaxis/vibedoctor scan

What it looks like

It compiles. It ships. It’s wrong.

Leftovers are where the next bug hides: the legacy branch still runs when a flag is unset.

They also mislead your next prompt. The agent reads the dead code and builds on it.

src/auth.ts
// TODO remove old auth fallback laterexport function legacyAuthFallback() {  // const oldClient = createClient()  return legacyAuthFallback();

Example: fixtures/leftovers in the VibeDoctor repository.

What VibeDoctor reports

A ranked finding with the exact location.

  • Built-in detectors run with no extra install, in any language VibeDoctor supports.
FindingSeverityEvidenceFrom
Legacy fallback path appears present
A fallback or compatibility branch that still runs.
medium observed built-in
Commented-out code
Code that was disabled instead of deleted.
low observed built-in
Legacy flag or env toggle
Flags like LEGACY_AUTH_ENABLED that keep an old path alive.
low observed built-in
Dead chain candidate
A cluster of files that only import each other, starting from unused files and exports.
low heuristic built-in + knip / vulture

Evidence grades say how sure the finding is. What verified, observed and heuristic mean →

How to fix it

  1. Confirm the old path is unused, then delete it and its tests together.
  2. Remove commented-out code. Git already has it.
  3. Re-run the scan so the agent's next prompt starts from a cleaner tree.

What this check can’t see

  • These are hints, ranked low on purpose. Confirm behaviour before deleting anything.

Fixing it, and the limits of this check

Run it

Check your repo now.

npx @neuralaxis/vibedoctor scan

Runs locally on JavaScript, TypeScript and Python repos. Hand the result to Cursor, Claude Code, Codex or Copilot with agent-plan. Agent setup →