Agent skill

UI Audit

by bagofwords1 in bagofwords1/bagofwords

Exhaustively audit the UI control by control and role by role — enumerate every button, link, and input on a set of pages, write down what each is supposed to do (derived from the handler code and…

Custom licenceAuto-check passedBackend & APIs

Install UI Audit

skills CLI
$ npx skills add bagofwords1/bagofwords --skill ui-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bagofwords1/bagofwords ui-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bagofwords1/bagofwords.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ui-audit .claude/skills/ui-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ui-audit
GitHub stars
459
Token cost
~2.9k tokens
SKILL.md length
1,441 words
Files
6 (incl. scripts, references)
Skills in repo
13
Repo updated
First seen
Licence
Custom licence

At a glance

Exhaustively audit the UI control by control and role by role — enumerate every button, link, and input on a set of pages, write down what each is supposed to do (derived from the handler code and…

  • Works in 5 steps: Scope, roles, and boot → Inventory (browser, read-only) → Expectation (code, no browser) → …
  • The user wants to hunt UI bugs broadly rather than fix one known bug — go through every page and every button
  • SKILL.md covers Which skill is this?, Why the phases are ordered the…, Phase 0 — Scope, roles, and boot and Phase 1 — Inventory (browser,…, plus 4 more sections
  • Runs JavaScript scripts from its folder; calls node and uv; needs ANTHROPIC_API_KEY and ANTHROPIC_KEY

What it does

UI Audit is an agent skill from bagofwords1/bagofwords. Exhaustively audit the UI control by control and role by role — enumerate every button, link, and input on a set of pages, write down what each is supposed to do (derived from the handler code and the RBAC matrix), then drive a real browser as each role and record what it actually does, filing every mismatch as a finding. Use whenever the user wants to hunt UI bugs broadly rather than fix one known bug — "go through every page and every button", "we have lots of weird UI bugs", "sweep the app for breakage"…

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `references/bow-surface.md`, `references/findings-format.md` and `references/roles.md`).

It sits in Backend & APIs, covering Authorization and RBAC. The repository describes itself as: Chat with your data - with memory, rules, and observability built in. Deploy in 2 minutes.

When your agent uses it

  • The user wants to hunt UI bugs broadly rather than fix one known bug — go through every page and every button
  • We have lots of weird UI bugs
  • Sweep the app for breakage
  • Check that these controls actually work

Example prompts

  • “go through every page and every button”
  • “we have lots of weird UI bugs”
  • “sweep the app for breakage”
  • “/ui-audit”

Requirements

  • Python 3
  • Node.js
  • A credential in ANTHROPIC_API_KEY
  • A credential in ANTHROPIC_KEY

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Scope, roles, and boot
  2. Inventory (browser, read-only)
  3. Expectation (code, no browser)
  4. Reality (browser, clicking)
  5. Findings

What it can do on your machine

Read from SKILL.md and the folder at commit f227059. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANTHROPIC_API_KEY
    • ANTHROPIC_KEY
    • BOW_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

UI Audit loads about 2.9k tokens when it runs, and up to ~8.1k if it reads all its reference files. Until then it costs about 163 tokens; SKILL.md has 1,441 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~163
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,441 words (~2,890 tokens).

“Compare intent to behavior, one control at a time, and write down both.”

— opening of SKILL.md by bagofwords1, Custom licence
name
ui-audit

Read the full SKILL.md on GitHub

Files

SKILL.md and 5 other files (scripts, references) in .agents/skills/ui-audit of bagofwords1/bagofwords.

  • SKILL.md
  • references/bow-surface.md
  • references/findings-format.md
  • references/roles.md
  • scripts/diff-roles.mjs
  • scripts/sweep.mjs

Open the folder on GitHubat commit f227059

Compare with similar skills

UI Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

UI Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
UI Audit this skillbagofwords1/bagofwords459—~2.9kAutomated safety check: PassCustom licence
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
K8s Security PoliciesCybereason-Public/owLSM28012 repos~2kAutomated safety check: PassGPL-2.0
Payloadpayloadcms/payload45k5 repos~6.2kAutomated safety check: PassMIT
Convex Setup Authspokvulcan/poker-planning1148 repos~1.8kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • K8s Security Policies

    Cybereason-Public/owLSM

    Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

    280 GitHub starsUsed in 12 repos~2k tokens
    Backend & APIsAuto-check passed
  • Payload

    payloadcms/payload

    A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

    45k GitHub starsUsed in 5 repos~6.2k tokens
    Backend & APIsAuto-check passed
  • Convex Setup Auth

    spokvulcan/poker-planning

    Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning.

    114 GitHub starsUsed in 8 repos~1.8k tokens
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Abp Authorization

    abpframework/abp

    ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

    14k GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed

More from bagofwords1/bagofwords

All 13 skills in this repo
  • Add Connection Type

    bagofwords1/bagofwords

    Add a new data source / connection type (e.g. An agent skill from bagofwords1/bagofwords.

    459 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Add LLM Provider Or Model

    bagofwords1/bagofwords

    Add a new LLM model to the preset catalog, or a whole new LLM provider — with the mandatory pre-flight verification of model id, pricing, and context window against the provider's official docs.

    459 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Docs Update

    bagofwords1/bagofwords

    Update the product docs at docs.bagofwords.com (Mintlify) with text and fresh screenshots after a user-facing change ships.

    459 GitHub stars~746 tokensUpdated today
    Auto-check passed
  • Localization

    bagofwords1/bagofwords

    The locale/i18n architecture of bagofwords — catalogs, resolution order, RTL, backend contracts — and the procedures for adding strings, adding a locale, or translating UI.

    459 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • QA

    bagofwords1/bagofwords

    Run a live QA pass over the app — first map all user-facing functionality, then boot the full stack and manually exercise flows with Playwright, recording pass/fail evidence and filing a QA report.

    459 GitHub stars~824 tokensUpdated today
    Auto-check passed
  • Release Notes

    bagofwords1/bagofwords

    Bump the version and write a CHANGELOG.md release-notes entry after a user-facing change ships.

    459 GitHub stars~857 tokensUpdated today
    Auto-check passed

Categories

Questions about UI Audit

What does UI Audit do?

Exhaustively audit the UI control by control and role by role — enumerate every button, link, and input on a set of pages, write down what each is supposed to do (derived from the handler code and…. UI Audit is an agent skill from bagofwords1/bagofwords. Exhaustively audit the UI control by control and role by role — enumerate every button, link, and input on a set of pages, write down what each is supposed to do (derived from the handler code and the RBAC matrix), then drive a real browser as each role and record what it actually does, filing every mismatch as a finding.

When should I use UI Audit?

UI Audit fits situations like: the user wants to hunt UI bugs broadly rather than fix one known bug — go through every page and every button; we have lots of weird UI bugs; sweep the app for breakage; check that these controls actually work.

How do I install UI Audit in Claude Code?

Run `npx skills add bagofwords1/bagofwords --skill ui-audit -a claude-code`. Or copy the skill folder (.agents/skills/ui-audit in bagofwords1/bagofwords) into .claude/skills/ui-audit in your project. Claude Code loads it when a task matches its description.

How do I install UI Audit in Codex?

Run `npx skills add bagofwords1/bagofwords --skill ui-audit -a codex`. Or copy the skill folder (.agents/skills/ui-audit in bagofwords1/bagofwords) into .agents/skills/ui-audit in your project. Codex loads it when a task matches its description.

Can I use UI Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bagofwords1/bagofwords --skill ui-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ui-audit, .gemini/skills/ui-audit, .github/skills/ui-audit and .opencode/skills/ui-audit in your project.

What does UI Audit need to run?

Going by SKILL.md and its folder, UI Audit needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and uv) and credentials named ANTHROPIC_API_KEY, ANTHROPIC_KEY and BOW_PASSWORD. Our summary lists: Python 3; Node.js; A credential in ANTHROPIC_API_KEY; A credential in ANTHROPIC_KEY.

Does UI Audit access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is UI Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does UI Audit use?

UI Audit has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does UI Audit use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.2k tokens, read only when the agent opens those files.

What are the alternatives to UI Audit?

Skills that share tags, products or a category with UI Audit: Configuring Horizon (coollabsio/coolify, 63k stars), K8s Security Policies (Cybereason-Public/owLSM, 280 stars), Payload (payloadcms/payload, 45k stars) and Convex Setup Auth (spokvulcan/poker-planning, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains UI Audit?

bagofwords1 (a GitHub organization) maintains it in bagofwords1/bagofwords, which has 459 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 9, 2026.

Source: bagofwords1/bagofwords on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.