madge-deps
Run Madge against a JS/TS production source tree to detect circular dependencies, find orphan modules, and visualize the module graph. Scoped to production code via `excludeRegExp` for test files. Use when a build compiles but throws `Cannot read property X of undefined` on a module that is clearly imported, or when a repo needs a CI gate that blocks new import cycles.
Install with skills.sh (any agent)
npx skills add testland/qa --skill madge-depsmadge-deps
Madge analyzes JavaScript module graphs (AMD, CommonJS, ES6) and CSS preprocessor imports (Sass, Stylus, Less) per the Madge README (opens in new window). NPM deps and Node core modules are excluded by default.
When to use
Step 1 - Install
npm install -g madge
# or per-project
npm install -D madgeOptional Graphviz for visual graphs:
| OS | Install |
|---|---|
| macOS | brew install graphviz |
| Ubuntu | apt-get install graphviz |
| Windows | choco install graphviz |
Per the Madge README (opens in new window).
Step 2 - Detect circular dependencies
# Single entry point
madge --circular src/index.ts
# Whole directory
madge --circular src/Exit code: 0 if none found, 1 if any circular path exists. Use directly in CI.
Step 3 - Find orphans + leaves
# Files imported by nothing
madge --orphans src/
# Files that import nothing (terminal modules)
madge --leaves src/Orphans are deletion candidates; verify usage outside source tree (scripts, configs, side-effect imports) before removal.
Step 4 - Visualize
# Render full graph as SVG (requires Graphviz)
madge --image graph.svg src/
# Show what depends on a specific file
madge --depends src/config/db.ts src/
# Export raw DOT for custom rendering
madge --dot src/ > graph.gvStep 5 - Configure for production-only scope
.madgerc in project root:
{
"fileExtensions": ["ts", "tsx", "js", "jsx"],
"excludeRegExp": [
"\\.test\\.(ts|tsx|js|jsx)$",
"\\.spec\\.(ts|tsx|js|jsx)$",
"__tests__/",
"__mocks__/",
"node_modules/",
"dist/",
"build/"
],
"tsConfig": "tsconfig.json"
}Test files are excluded so tests can intentionally import production modules without flagging the production tree.
Step 6 - CI gate
# GitHub Actions
- name: Block circular deps
run: npx madge --circular --extensions ts,tsx src/
- name: Detect new orphans (advisory)
run: npx madge --orphans --extensions ts,tsx src/ || trueThe first step fails on any circular path; the second is informational only (orphans require human judgment - could be webpack entry, dynamic import, etc.).
Anti-patterns
| Anti-pattern | Why it fails | Fix |
|---|---|---|
Scan whole repo including node_modules/ | OOM on large workspaces | excludeRegExp: ["node_modules/"] (Step 5) - actually default behavior, but verify |
| Treat orphans as "always delete" | Webpack/Vite entry points + dynamic imports look orphaned | Manual review per orphan; use --depends to verify (Step 4) |
| Allow circular deps in non-prod with "we'll fix later" | Cycles compound; mid-project untangling is brutal | Block on first cycle (Step 6); waiver template if scope-exclusion needed |
Forget tsconfig.json for path aliases | Madge can't resolve @/foo imports; reports false positives | "tsConfig": "tsconfig.json" in .madgerc (Step 5) |
Run with default extensions (js only) for TS project | Misses 100% of TS files | fileExtensions: ["ts", "tsx", "js", "jsx"] (Step 5) |
Limitations
References
Related skills
codeclimate-config
Configure Code Climate Quality (now Qlty) for repository-wide quality gates - duplication, complexity, similar-code, exclude_patterns. Covers both legacy `.codeclimate.yml` (Code Climate Velocity / GitHub integration) and the new `.qlty/qlty.toml` per the Qlty platform migration. Use when a repo needs duplication and complexity thresholds enforced on PRs, or when an existing `.codeclimate.yml` must be migrated to Qlty without losing its plugin and exclude settings.
knip-dead-code
Run Knip against a JS/TS project to detect unused files, unused dependencies, unused exports, and unused class/enum members. Scoped to production code; tests are entry-point-aware via Knip's framework plugins. Use after a feature or route is deleted and the project still compiles, or when `package.json` has accumulated dependencies nobody can account for.
lizard-complexity
Run Lizard against production source to enforce per-function cyclomatic complexity (CCN), NLOC, and parameter-count thresholds - language-agnostic (30+ languages). Scoped to production code via `-x"./tests/*"`; test complexity is reviewed separately. Use when a codebase spans several languages and needs one complexity gate across all of them, or when a function has grown unreviewable and the team wants a numeric threshold in CI.
sonarqube-maintainability-gate
Run SonarQube/SonarCloud against production code to surface Code Smells, Bugs, and Maintainability ratings - the maintainability lens rather than the security lens. Production-only scope via sonar.exclusions; test code is reviewed separately. Use when a team wants maintainability and technical-debt ratings gating PRs, or when an existing SonarQube project reports numbers nobody has tied to a quality gate.