Skip to content
Back to skills

Build Script Path Rot

ASecurity

Hardcoded paths in build scripts break when directory structure changes:

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 3, 2026
ai-agentsjavascriptjava

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add fabioc-aloha/Alex_Skill_Mall --skill build-script-path-rot --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Build Script Path Rot?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Build Script Path Rot
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/fabioc-aloha-build-script-path-rot/badge)](https://www.skillsdirectory.com/skills/fabioc-aloha-build-script-path-rot)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: build-script-path-rot
description: "Hardcoded paths in build scripts break when directory structure changes:"
lastReviewed: 2026-04-30
---

# Build Script Path Rot

## The Problem

Hardcoded paths in build scripts break when directory structure changes:

```javascript
// Bad: hardcoded path
const srcDir = './src/components';
const outDir = './dist/components';

// After restructure: src/components → packages/ui/src
// Script breaks silently or with confusing errors
```

## The Solution

### Option 1: Resolve Relative to Manifest

```javascript
const path = require('path');
const pkg = require('./package.json');

// Paths defined in package.json
const srcDir = path.resolve(__dirname, pkg.directories?.src || 'src');
const outDir = path.resolve(__dirname, pkg.directories?.dist || 'dist');
```

```json
// package.json
{
  "directories": {
    "src": "packages/ui/src",
    "dist": "dist"
  }
}
```

### Option 2: Config File

```javascript
// build.config.js
module.exports = {
  srcDir: './packages/ui/src',
  outDir: './dist',
  assets: './assets'
};
```

```javascript
// build.cjs
const config = require('./build.config.js');
const srcDir = path.resolve(__dirname, config.srcDir);
```

### Option 3: Auto-Discover

```javascript
// Find src directory by looking for markers
function findSrcDir() {
  const candidates = ['src', 'packages/ui/src', 'lib'];
  for (const dir of candidates) {
    if (fs.existsSync(path.join(dir, 'index.ts'))) {
      return dir;
    }
  }
  throw new Error('Could not find source directory');
}
```

## Red Flags

| Pattern | Risk |
|---------|------|
| `'./src/'` hardcoded | Will break on restructure |
| `process.cwd() + '/src'` | Breaks if script run from different dir |
| Relative paths without `path.resolve` | Platform-specific issues |

## Safe Patterns

```javascript
// Always resolve from script location
const scriptDir = __dirname;
const projectRoot = path.resolve(scriptDir, '..');
const srcDir = path.resolve(projectRoot, 'src');

// Or from package.json location
const pkgPath = require.resolve('./package.json');
const projectRoot = path.dirname(pkgPath);
```

## Verification

1. Move a directory → script still works (reads from config)
2. Run script from different working directory → still works
3. Paths in config match actual structure

## When to Apply

- Any build script with file paths
- After directory restructure
- When script "mysteriously" breaks in CI

## Tags

`build` `paths` `configuration` `portability`

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…