Agent skill

04 Audit

by ai-driven-dev in ai-driven-dev/framework

Audit a codebase read-only across seven quality pillars into one ranked report.

MITAuto-check passedDevelopment

Install 04 Audit

skills CLI
$ npx skills add ai-driven-dev/framework --skill 04-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ai-driven-dev/framework 04-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ai-driven-dev/framework.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/aidd-dev/skills/04-audit .claude/skills/04-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
04-audit
GitHub stars
510
Token cost
~672 tokens
SKILL.md length
277 words
Files
9 (incl. assets)
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Audit a codebase read-only across seven quality pillars into one ranked report.

  • The user wants to assess
  • SKILL.md covers Actions, Transversal rules and Assets
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Audit a codebase

What it does

04 Audit is an agent skill from ai-driven-dev/framework. Audit a codebase read-only across seven quality pillars into one ranked report. Use when the user wants to assess, health-check, or audit a codebase or one pillar. Not for fixing findings, reviewing a change, or checking a feature works.

Its SKILL.md is about 670 tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including assets (for example `actions/01-code-quality.md`, `actions/02-architecture.md` and `actions/03-security.md`).

It sits in Development. The repository describes itself as: Marketplace Framework AI-Driven Dev : Context Engineering, Plugins, Agents, Skills, Hooks, Templates, SDLC. The licence is MIT.

When your agent uses it

  • The user wants to assess
  • Audit a codebase

Example prompts

  • “/04-audit”

What it can do on your machine

Read from SKILL.md and the folder at commit 6e30640. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

04 Audit loads about 672 tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 277 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~672

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ai-driven-dev/framework at commit 6e30640, republished under its MIT licence (© ai-driven-dev). 277 words, ~672 tokens.

Download SKILL.mdSave it as .claude/skills/04-audit/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
04-audit
description
Audit a codebase read-only across seven quality pillars into one ranked report. Use when the user wants to assess, health-check, or audit a codebase or one pillar. Not for fixing findings, reviewing a change, or checking a feature works.
argument-hint
scope | pillar
model
opus

Skill: audit

Diagnose a codebase against quality pillars and emit one ranked findings report. Read-only: it identifies and ranks problems, never changes code.

Actions

#ActionPillarLens
01code-qualitycode-qualityClean code (naming, SOLID, DRY, readability, smells) and tech debt (dead code, complexity, file/function size, error handling)
02architecturearchitectureConformance to C4 / ADRs, coupling, boundaries, layering
03securitysecurityOWASP risks, authz, input validation, secrets in code
04dependenciesdependenciesCVEs, licenses, outdated and unused deps, supply chain
05performanceperformanceN+1 queries, hot paths, bundle size, heavy operations
06teststestsCritical-path coverage, flakiness, test pyramid balance
07uiuiLoading/error/empty states, visual hierarchy, design-system drift, responsive, a11y

Run the one pillar named, or offer all seven when the request is unscoped. Before running an action, read its file in actions/, not only the table or assets.

Transversal rules

  • Read-only: diagnose and rank, never edit code.
  • Scope: run the one named pillar, or for an unscoped request ask once "all seven pillars, or one?" before running. Never silently default to one pillar, never blind-run all without offering the choice.
  • One folder per run, aidd_docs/tasks/<yyyy_mm>/<yyyy_mm_dd>_audit/, like a feature folder. Every pillar that runs always writes its own <pillar>.md there, alone or in a full run. A full run additionally writes a merged report.md: one Findings table (category = pillar, severity-first), one Top-actions list, and one Coverage section over all seven pillars.
  • Unscannable pillar: skip it, record it under Coverage > Skipped with the reason, and never invent findings for it.
  • Every finding row carries a severity, its pillar, a concrete file:line, the issue, a suggested fix, and an effort.

Assets

  • assets/audit-template.md: the report structure both run modes fill.

© ai-driven-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (assets) in plugins/aidd-dev/skills/04-audit of ai-driven-dev/framework.

  • SKILL.md
  • actions/01-code-quality.md
  • actions/02-architecture.md
  • actions/03-security.md
  • actions/04-dependencies.md
  • actions/05-performance.md
  • actions/06-tests.md
  • actions/07-ui.md
  • assets/audit-template.md

Open the folder on GitHubat commit 6e30640

Compare with similar skills

04 Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

04 Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
04 Audit this skillai-driven-dev/framework510—~672Automated safety check: PassMIT
Flowsint Enricher Builderreconurge/flowsint9.3k—~2.6kAutomated safety check: PassApache-2.0
Native Feel Cross Platform Desktopyetone/native-feel-skill1.9k1 repos~1.5kAutomated safety check: PassMIT
YugabyteDB Phorge Diff Creatoryugabyte/yugabyte-db11k—~3.1kAutomated safety check: PassCustom licence
Code Graph Mermaid Diagramstrailofbits/skills7.4k—~1.7kAutomated safety check: PassCC-BY-SA-4.0
Code Review Specialistluongnv89/claude-howto42k—~764Automated safety check: PassMIT

Similar skills

  • Flowsint Enricher Builder

    reconurge/flowsint

    Guides building Flowsint enrichers and types: where definitions live, how the base class and vault work, and when a new type is warranted.

    9.3k GitHub stars~2.6k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Native Feel Cross Platform Desktop

    yetone/native-feel-skill

    A skill your agent uses when the user is designing, prototyping, or rewriting a desktop app that must run on multiple OSes (macOS + Windows, optionally Linux) AND feel indistinguishable from a…

    1.9k GitHub starsUsed in 1 repo~1.5k tokens
    DevelopmentAuto-check passed
  • YugabyteDB Phorge Diff Creator

    yugabyte/yugabyte-db

    Creates a Phorge code review diff for the current branch with arc diff, while applying public-repo confidentiality rules since Phorge content later lands verbatim on the public GitHub repo.

    11k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Code Review Specialist

    luongnv89/claude-howto

    Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

    42k GitHub stars~764 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • New Rule for sonar-java

    SonarSource/sonar-java

    Official

    Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

    1.2k GitHub stars~833 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from ai-driven-dev/framework

All 52 skills in this repo
  • 00 Async Dev

    ai-driven-dev/framework

    Drive the async-dev pipeline from one entry point, whether setup, run, or review.

    510 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • 01 Plan

    ai-driven-dev/framework

    Turn a request, ticket, or file into a phased implementation plan.

    510 GitHub stars~517 tokensUpdated today
    Auto-check passed
  • 01 Sdlc

    ai-driven-dev/framework

    Autonomously orchestrates a request from framing to a draft pull request, isolating implementation, independent review, and final outcome challenge.

    510 GitHub stars~583 tokensUpdated today
    Auto-check passed
  • 02 Backlog

    ai-driven-dev/framework

    Orchestrates a product backlog end to end. An agent skill from ai-driven-dev/framework.

    510 GitHub stars~613 tokensUpdated today
    Auto-check passed
  • 00 Onboard

    ai-driven-dev/framework

    Guide a project's journey through AIDD, from first setup to shipping a feature.

    510 GitHub stars~242 tokensUpdated today
    Auto-check passed
  • 01 Acceptance QA

    ai-driven-dev/framework

    Validate a reviewed candidate's observable behavior against its acceptance criteria and record short named videos as reviewer evidence.

    510 GitHub stars~434 tokensUpdated today
    Auto-check passed

Questions about 04 Audit

What does 04 Audit do?

Audit a codebase read-only across seven quality pillars into one ranked report. 04 Audit is an agent skill from ai-driven-dev/framework. Audit a codebase read-only across seven quality pillars into one ranked report.

When should I use 04 Audit?

04 Audit fits situations like: the user wants to assess; audit a codebase.

How do I install 04 Audit in Claude Code?

Run `npx skills add ai-driven-dev/framework --skill 04-audit -a claude-code`. Or copy the skill folder (plugins/aidd-dev/skills/04-audit in ai-driven-dev/framework) into .claude/skills/04-audit in your project. Claude Code loads it when a task matches its description.

How do I install 04 Audit in Codex?

Run `npx skills add ai-driven-dev/framework --skill 04-audit -a codex`. Or copy the skill folder (plugins/aidd-dev/skills/04-audit in ai-driven-dev/framework) into .agents/skills/04-audit in your project. Codex loads it when a task matches its description.

Can I use 04 Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ai-driven-dev/framework --skill 04-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/04-audit, .gemini/skills/04-audit, .github/skills/04-audit and .opencode/skills/04-audit in your project.

What does 04 Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: 04 Audit is instructions for the agent only.

Does 04 Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is 04 Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does 04 Audit use?

04 Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does 04 Audit use?

About 672 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to 04 Audit?

Skills that share tags, products or a category with 04 Audit: Flowsint Enricher Builder (reconurge/flowsint, 9.3k stars), Native Feel Cross Platform Desktop (yetone/native-feel-skill, 1.9k stars), YugabyteDB Phorge Diff Creator (yugabyte/yugabyte-db, 11k stars) and Code Graph Mermaid Diagrams (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 04 Audit?

ai-driven-dev (a GitHub organization) maintains it in ai-driven-dev/framework, which has 510 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.

Source: ai-driven-dev/framework on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.