SlopScore for Code

Patterns / Debug output left in

Debug output left in

Agents debug the way people do: print things. Unlike people, they rarely clean up, and they decorate the output with ✅ and 🚀. In a server, that's noise in your logs at best and leaked customer data at worst.

What it looks like

console.log("✅ fetched invoices", rows)
print("loaded config")
debugger;
breakpoint()

Why it matters

Debug prints often include whole objects: tokens, emails, request bodies.

Before and after

Before
const rows = await db.query(sql, [id]);
console.log("✅ fetched invoices", rows);
After
const rows = await db.query(sql, [id]);
logger.debug({ count: rows.length, id }, "fetched invoices");

How to fix it

  1. Use the project logger with levels.
  2. Flag console.log/print in app code only. SlopScore for Code allows them in scripts/, bin/, cli/, examples/ and tests.

When it's fine

CLIs and scripts whose job is printing.

Catch this automatically. SlopScore for Code checks every pull request for this pattern (rule debug-leftover) and 11 others. Score a public PR or add the free GitHub Action.

Related