How to fix it
- Confirm the old path is unused, then delete it and its tests together.
- Remove commented-out code. Git already has it.
- Re-run the scan so the agent's next prompt starts from a cleaner tree.
Each prompt adds a layer. The old auth path stays “just in case”, the previous version is commented out, and a file nobody imports keeps getting edited.
npx @neuralaxis/vibedoctor scan What it looks like
Leftovers are where the next bug hides: the legacy branch still runs when a flag is unset.
They also mislead your next prompt. The agent reads the dead code and builds on it.
// TODO remove old auth fallback laterexport function legacyAuthFallback() { // const oldClient = createClient() return legacyAuthFallback(); Example: fixtures/leftovers in the VibeDoctor repository.
What VibeDoctor reports
| Finding | Severity | Evidence | From |
|---|---|---|---|
| Legacy fallback path appears present A fallback or compatibility branch that still runs. | medium | observed | built-in |
| Commented-out code Code that was disabled instead of deleted. | low | observed | built-in |
| Legacy flag or env toggle Flags like LEGACY_AUTH_ENABLED that keep an old path alive. | low | observed | built-in |
| Dead chain candidate A cluster of files that only import each other, starting from unused files and exports. | low | heuristic | built-in + knip / vulture |
Evidence grades say how sure the finding is. What verified, observed and heuristic mean →
How to fix it
What this check can’t see
Run it
npx @neuralaxis/vibedoctor scan
Runs locally on JavaScript, TypeScript and Python repos. Hand the result to Cursor,
Claude Code, Codex or Copilot with agent-plan.
Agent setup →