Anonymized project
Code forensics for AI-assisted software delivery
The assessment combined code and repository forensics with defect, delivery, and AI workflow data. It created a clear baseline for the technical roadmap: working practices remained visible, risks became verifiable, and the next improvements became concrete work items.
Starting point
A development team was already using AI actively with human approval and delivering small, reviewable changes. The assessment set out to determine which practices were working, where defects originated, and what evidence was needed to expand AI-assisted development in a controlled way.
What mattered
- The analysis needed to identify proven practices as clearly as risks and opportunities for improvement.
- Technical findings needed to be prioritized and evidenced so they could feed directly into the existing technical roadmap.
- Further use of AI required verifiable criteria for specifications, tests, permissions, approvals, and failure cases.
My contribution
I combined classical code forensics with an evaluation of reusable AI task instructions, or skills, and the spec-driven development workflow. During the handover, the findings were placed in the team's operating context and translated into decisions and next verification steps.
My approach
- Repository history, dependency graphs, scanner results, defect data, and delivery evidence were analyzed with reproducible calculations.
- The analysis confirmed small changes, low duplication, and largely manageable complexity. Frequently changed areas and other technical risks received a deeper review.
- The path from specifications through acceptance examples, tests, implementation, and quality checks to release was evaluated for traceability.
- AI skills were evaluated for tests and clear boundaries around tools, files, credentials, approvals, and failure cases. This defined criteria for a limited, measurable pilot workflow.
Outcome achieved
- The assessment confirmed a good technical starting point: small reviewable changes, low duplication, largely manageable complexity, and human control in the AI workflow. This made clear what was already working and where targeted improvements should begin.
- The analysis identified acceptance criteria as a central quality lever. Expected behavior can be translated into examples and tests before implementation, creating a shared basis for development, QA, and the use of AI.
- Credential, security, and dependency signals were turned into concrete validation and update steps. The customer could separate immediate checks, planned updates, and items requiring deeper investigation.
- The customer received a clear path for advancing AI-assisted development: describe behavior in specifications, prove it with tests, evaluate skills systematically, and measure the workflow in a limited pilot. The handover showed how these work items could feed directly into the technical roadmap.
What this can mean for your project
- The approach separates existing strengths, verifiable risks, and open assumptions. This helps you see where technical investment and process changes should start.
- Clear acceptance criteria, linked tests, and evaluated AI skills create the foundation for expanding AI-assisted development in a controlled and measurable way.