---
name: scan-hardcoded-strings
description: Inventory hardcoded (non-localized) UI text across vscode-extension/src/webview/** and the webview-HTML-producing code in vscode-extension/src/extension.ts — string/template literals rendered as UI text that never go through localize()/localizeFormat()/t()/vscode.l10n.t(). Produces a human-triageable report; never fails the build. Use after a UI change, before a release, or periodically as a localization audit.
---
# Scan Hardcoded Strings Skill
Scans the VS Code extension's webview UI code for candidate hardcoded
(non-localized) UI strings and writes a triage report. This is an
**informational inventory tool**, not a CI gate — it never exits non-zero and
never modifies source files.
## When to Use This Skill
Use this skill when you need to:
- Audit UI text after adding or changing a webview panel or a section of
`extension.ts`'s `get*Html` methods, to catch strings that were typed
directly instead of routed through localization
- Build or refresh a localization backlog before a release
- Periodically re-run as a maintenance/audit pass to see whether the backlog
of non-localized strings is growing or shrinking
- Investigate a specific UI surface (e.g. a webview panel) that appears not
to translate correctly under a non-English locale
It complements two existing scripts that only check *consistency* of strings
already wired through localization (`scripts/validate-localization.js` /
`npm --prefix vscode-extension run lint:l10n`, and
`vscode-extension/scripts/validate-l10n.mjs` /
`npm --prefix vscode-extension run validate:l10n`) — neither of those, nor anything else in the repo,
detects a plain string literal that never calls `localize(`/`t(`/
`vscode.l10n.t(` in the first place. A separate, stricter AST-based CI gate
for *new* instances of this may exist as an independent effort; this skill is
not that gate — it is a full-codebase inventory for manual triage.
## Running the Check
```bash
node .github/skills/scan-hardcoded-strings/scan-hardcoded-strings.js
# Machine-readable JSON output
node .github/skills/scan-hardcoded-strings/scan-hardcoded-strings.js --json
```
The script will:
1. Recursively scan every `*.ts` file (excluding `*.test.ts`) under
`vscode-extension/src/webview/`, plus only the `get*Html(...)` method
bodies in `vscode-extension/src/extension.ts` (not the whole
file — this keeps out unrelated string literals like GitHub issue
Markdown templates or VS Code panel titles), after blanking out `/* ... */`
block/JSDoc comments so example markup in a doc comment isn't mistaken
for real UI text
2. Flag string/template literals in UI-rendering positions — assignments to
`.textContent`/`.innerText`/`.innerHTML`/`.title`/`.placeholder` (a direct
literal or a conditional/ternary RHS whose branches are literals),
`aria-label="..."`/`title="..."`/`placeholder="..."` HTML attributes (or
the same three set via `.setAttribute('title', '...')`), a literal
`document.createTextNode('...')` argument, text inside `