--- name: scan-hardcoded-strings description: Inventory hardcoded (non-localized) UI text across vscode-extension/src/webview/** and the webview-HTML-producing code in vscode-extension/src/extension.ts — string/template literals rendered as UI text that never go through localize()/localizeFormat()/t()/vscode.l10n.t(). Produces a human-triageable report; never fails the build. Use after a UI change, before a release, or periodically as a localization audit. --- # Scan Hardcoded Strings Skill Scans the VS Code extension's webview UI code for candidate hardcoded (non-localized) UI strings and writes a triage report. This is an **informational inventory tool**, not a CI gate — it never exits non-zero and never modifies source files. ## When to Use This Skill Use this skill when you need to: - Audit UI text after adding or changing a webview panel or a section of `extension.ts`'s `get*Html` methods, to catch strings that were typed directly instead of routed through localization - Build or refresh a localization backlog before a release - Periodically re-run as a maintenance/audit pass to see whether the backlog of non-localized strings is growing or shrinking - Investigate a specific UI surface (e.g. a webview panel) that appears not to translate correctly under a non-English locale It complements two existing scripts that only check *consistency* of strings already wired through localization (`scripts/validate-localization.js` / `npm --prefix vscode-extension run lint:l10n`, and `vscode-extension/scripts/validate-l10n.mjs` / `npm --prefix vscode-extension run validate:l10n`) — neither of those, nor anything else in the repo, detects a plain string literal that never calls `localize(`/`t(`/ `vscode.l10n.t(` in the first place. A separate, stricter AST-based CI gate for *new* instances of this may exist as an independent effort; this skill is not that gate — it is a full-codebase inventory for manual triage. ## Running the Check ```bash node .github/skills/scan-hardcoded-strings/scan-hardcoded-strings.js # Machine-readable JSON output node .github/skills/scan-hardcoded-strings/scan-hardcoded-strings.js --json ``` The script will: 1. Recursively scan every `*.ts` file (excluding `*.test.ts`) under `vscode-extension/src/webview/`, plus only the `get*Html(...)` method bodies in `vscode-extension/src/extension.ts` (not the whole file — this keeps out unrelated string literals like GitHub issue Markdown templates or VS Code panel titles), after blanking out `/* ... */` block/JSDoc comments so example markup in a doc comment isn't mistaken for real UI text 2. Flag string/template literals in UI-rendering positions — assignments to `.textContent`/`.innerText`/`.innerHTML`/`.title`/`.placeholder` (a direct literal or a conditional/ternary RHS whose branches are literals), `aria-label="..."`/`title="..."`/`placeholder="..."` HTML attributes (or the same three set via `.setAttribute('title', '...')`), a literal `document.createTextNode('...')` argument, text inside `
`, `