Agent skill

Iss Audit

by akitaonrails in akitaonrails/my-skills

Audit GitHub issues before implementation, including skeptical claim verification, safe reproduction, prompt-injection resistance, malicious-link and attachment handling, root-cause analysis…

No licenceAuto-check passedDevelopment

Install Iss Audit

skills CLI
$ npx skills add akitaonrails/my-skills --skill iss-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install akitaonrails/my-skills iss-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/akitaonrails/my-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/iss-audit .claude/skills/iss-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iss-audit
GitHub stars
216
Token cost
~4.1k tokens
SKILL.md length
2,031 words
Files
2
Skills in repo
18
Repo updated
First seen
Licence
None found

At a glance

Audit GitHub issues before implementation, including skeptical claim verification, safe reproduction, prompt-injection resistance, malicious-link and attachment handling, root-cause analysis…

  • Works in 7 steps: Inventory and Trusted Context → Separate Claims → Verify Against the Project → …
  • Tasks that involve Root cause analysis
  • SKILL.md covers Trust Boundary, Phase 0: Inventory and Trusted…, Phase 1: Separate Claims and Phase 2: Verify Against the…, plus 5 more sections
  • Calls gh and git

What it does

Iss Audit is an agent skill from akitaonrails/my-skills. Audit GitHub issues before implementation, including skeptical claim verification, safe reproduction, prompt-injection resistance, malicious-link and attachment handling, root-cause analysis, security impact, product fit, regression planning, and one-at-a-time resolution. Use when asked to audit, triage, validate, prioritize, fix, or close one or more issues.

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Root cause analysis, Fact-checking and source verification and Prompt injection and agent security. It works with GitHub. The repository describes itself as: akitaonrails' personal skills (not tailored for general usage).

When your agent uses it

  • Tasks that involve Root cause analysis
  • Tasks that involve Fact-checking and source verification
  • Tasks that involve Prompt injection and agent security

Example prompts

  • “/iss-audit”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Inventory and Trusted Context
  2. Separate Claims
  3. Verify Against the Project
  4. Reproduce Safely
  5. Decide Whether and How to Resolve
  6. Root Cause and Fix Plan
  7. Output

What it can do on your machine

Read from SKILL.md and the folder at commit 285ca82. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Iss Audit loads about 4.1k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 2,031 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 2,031 words (~4,080 tokens).

“Decide what is true before deciding what to build. Be skeptical but constructive: the reporter's pain can be real while their diagnosis, severity, or proposed fix is wrong.”

— opening of SKILL.md by akitaonrails
name
iss-audit

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in iss-audit of akitaonrails/my-skills.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 285ca82

Compare with similar skills

Iss Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Iss Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Iss Audit this skillakitaonrails/my-skills216—~4.1kAutomated safety check: PassNone
OpenROAD Bug FixerThe-OpenROAD-Project/OpenROAD3.2k—~784Automated safety check: PassBSD-3-Clause
Octocode Code Researchbgauryy/octocode949—~1.5kAutomated safety check: PassMIT
Triagebot Action Bug Triagewithastro/astro63k—~639Automated safety check: PassCustom licence
Buddhist Methodnai0om/buddhist-method294—~2.4kAutomated safety check: PassMIT
CI TriageMentra-Community/MentraOS2.4k—~582Automated safety check: PassApache-2.0

Similar skills

  • OpenROAD Bug Fixer

    The-OpenROAD-Project/OpenROAD

    Fixes an OpenROAD bug from a GitHub issue or error code: finds the root cause, implements the fix, adds a regression test and prepares a signed-off commit.

    3.2k GitHub stars~784 tokensUpdated today
    DevelopmentAuto-check passed
  • Octocode Code Research

    bgauryy/octocode

    Researches code with evidence: traces callers, imports and cross-repo links, diagnoses failures and reports findings with exact file and line references and a confidence label.

    949 GitHub stars~1.5k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Official

    Takes a bug report for the triagebot-action GitHub Action through reproduction, root-cause diagnosis, an intended-behavior check and a fix attempt.

    63k GitHub stars~639 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Buddhist Method

    nai0om/buddhist-method

    Apply Buddhist epistemic and decision-making principles as practical work disciplines to improve reasoning quality, anti-hallucination, debugging discipline, and steadiness under pressure.

    294 GitHub stars~2.4k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • CI Triage

    Mentra-Community/MentraOS

    Triage failing GitHub PR checks: list failures with gh, fetch capped Actions logs, skip non-Actions checks, and summarize root cause.

    2.4k GitHub stars~582 tokensUpdated today
    DevelopmentAuto-check passed
  • Stereopy Issue Responder

    STOmics/Stereopy

    Generates professional maintainer-grade responses for Stereopy GitHub issues.

    293 GitHub stars~1.3k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from akitaonrails/my-skills

All 18 skills in this repo
  • Fact Check

    akitaonrails/my-skills

    Adversarial fact-checking of the user's articles and essays (typically blog posts from akitaonrails-hugo, any markdown/text file), verifying every claim against online primary sources via cheap…

    220 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Blog Cost Charts

    akitaonrails/my-skills

    Generate dark-themed cost-vs-score bubble scatter charts and score/(costtime) value-ranking bar charts for a blog post comparing LLM benchmark results (or any dataset with a score/cost/time shape)…

    220 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Codemap

    akitaonrails/my-skills

    Generate comprehensive hierarchical codemaps for UNFAMILIAR repositories.

    220 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Clonedeps

    akitaonrails/my-skills

    Clone important project dependency source code into an ignored local workspace so OpenCode can inspect library internals.

    220 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • GitHub Resolution

    akitaonrails/my-skills

    Execute the approved outcomes of a pr-audit and/or iss-audit — fix or adjust everything the audit found necessary before merging, verify no regressions, cover every new behavior with unit tests…

    220 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Post Refactor

    akitaonrails/my-skills

    Post-refactor clean-code check after recent refactors or a few merged PRs.

    220 GitHub stars~1.5k tokensUpdated today
    Auto-check: notes

Works with

Questions about Iss Audit

What does Iss Audit do?

Audit GitHub issues before implementation, including skeptical claim verification, safe reproduction, prompt-injection resistance, malicious-link and attachment handling, root-cause analysis…. Iss Audit is an agent skill from akitaonrails/my-skills. Audit GitHub issues before implementation, including skeptical claim verification, safe reproduction, prompt-injection resistance, malicious-link and attachment handling, root-cause analysis, security impact, product fit, regression planning, and one-at-a-time resolution.

When should I use Iss Audit?

Iss Audit fits situations like: tasks that involve Root cause analysis; tasks that involve Fact-checking and source verification; tasks that involve Prompt injection and agent security.

How do I install Iss Audit in Claude Code?

Run `npx skills add akitaonrails/my-skills --skill iss-audit -a claude-code`. Or copy the skill folder (iss-audit in akitaonrails/my-skills) into .claude/skills/iss-audit in your project. Claude Code loads it when a task matches its description.

How do I install Iss Audit in Codex?

Run `npx skills add akitaonrails/my-skills --skill iss-audit -a codex`. Or copy the skill folder (iss-audit in akitaonrails/my-skills) into .agents/skills/iss-audit in your project. Codex loads it when a task matches its description.

Can I use Iss Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add akitaonrails/my-skills --skill iss-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iss-audit, .gemini/skills/iss-audit, .github/skills/iss-audit and .opencode/skills/iss-audit in your project.

What does Iss Audit need to run?

Going by SKILL.md and its folder, Iss Audit needs the command-line tools its instructions call (gh and git).

Does Iss Audit access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Iss Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Iss Audit use?

No licence was found for Iss Audit or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Iss Audit use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Iss Audit?

Skills that share tags, products or a category with Iss Audit: OpenROAD Bug Fixer (The-OpenROAD-Project/OpenROAD, 3.2k stars), Octocode Code Research (bgauryy/octocode, 949 stars), Triagebot Action Bug Triage (withastro/astro, 63k stars) and Buddhist Method (nai0om/buddhist-method, 294 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Iss Audit?

akitaonrails (a GitHub user) maintains it in akitaonrails/my-skills, which has 216 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on September 23, 2026.

Source: akitaonrails/my-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.