Agent skill

Audit

by ccch1mneyyy in ccch1mneyyy/dsh-TUI

Audit the repository or a broad subsystem for security, correctness, and maintainability risks.

MITAuto-check passedDevelopment

Install Audit

skills CLI
$ npx skills add ccch1mneyyy/dsh-TUI --skill audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccch1mneyyy/dsh-TUI audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccch1mneyyy/dsh-TUI.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/audit .claude/skills/audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit
GitHub stars
4.2k
Token cost
~405 tokens
SKILL.md length
201 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Audit the repository or a broad subsystem for security, correctness, and maintainability risks.

  • Works in 5 steps: Identify entry points, state owners,… → Follow inputs through validation and… → Confirm suspected defects against… → …
  • Use review for a specific change and vuln-check for a security-only assessment
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit is an agent skill from ccch1mneyyy/dsh-TUI. Audit the repository or a broad subsystem for security, correctness, and maintainability risks. Use for audit requests or /audit; use review for a specific change and vuln-check for a security-only assessment.

Its SKILL.md is about 410 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with DeepSeek. The repository describes itself as: DSH's officially top-recommended TUI plugin — high performance, low overhead, cute pixel whale, smooth mouse interaction. One-command install via npm. / DSH 官方首推的 TUI…. The licence is MIT.

When your agent uses it

  • Use review for a specific change and vuln-check for a security-only assessment

Example prompts

  • “/audit”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Identify entry points, state owners, external inputs, and teardown paths within the requested scope.
  2. Follow inputs through validation and consumers. In this TUI, inspect applicable session projections, plugin capabilities, file access…
  3. Confirm suspected defects against callers, existing guards, and focused regressions. Check exports, registries, and supported…
  4. Report confirmed findings by severity with location, trigger, impact, and a concrete remedy. Keep unverified leads separate. For a…
  5. State the areas examined, checks actually run, and material gaps. No findings means none found in that scope, not proof that the whole…

What it can do on your machine

Read from SKILL.md and the folder at commit 601cc61. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit loads about 405 tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 201 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~405

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccch1mneyyy/dsh-TUI at commit 601cc61, republished under its MIT licence (© ccch1mneyyy). 201 words, ~405 tokens.

Download SKILL.mdSave it as .claude/skills/audit/SKILL.md (or your agent's skills folder).
name
audit
description
Audit the repository or a broad subsystem for security, correctness, and maintainability risks. Use for audit requests or /audit; use review for a specific change and vuln-check for a security-only assessment.

Establish the audit scope, then trace the relevant runtime paths. For a findings-only request, leave code unchanged; carry out fixes when the user has requested them.

  1. Identify entry points, state owners, external inputs, and teardown paths within the requested scope.
  2. Follow inputs through validation and consumers. In this TUI, inspect applicable session projections, plugin capabilities, file access, terminal escape handling, and long-session resource bounds. Prioritize paths whose failure can lose state, cross a trust boundary, or leave the terminal unusable. Check dependencies and lockfiles for known vulnerabilities against advisory data.
  3. Confirm suspected defects against callers, existing guards, and focused regressions. Check exports, registries, and supported compatibility paths before declaring code dead. Explain a simplification in terms of current requirements and the behavior it preserves.
  4. Report confirmed findings by severity with location, trigger, impact, and a concrete remedy. Keep unverified leads separate. For a cross-layer failure, a short input → boundary → effect trace may be enough to explain it.
  5. State the areas examined, checks actually run, and material gaps. No findings means none found in that scope, not proof that the whole project is safe. An audit can finish without findings or a forced list of healthy areas.

© ccch1mneyyy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/audit of ccch1mneyyy/dsh-TUI.

Open the folder on GitHubat commit 601cc61

Compare with similar skills

Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit this skillccch1mneyyy/dsh-TUI4.2k—~405Automated safety check: PassMIT
Roo Conflict Resolutionzgsm-ai/costrict4.4k—~2.3kAutomated safety check: PassApache-2.0
Deepseek Automationzhu1090093659/deepseek-pp1.9k—~2.1kAutomated safety check: NotesApache-2.0
Deep Reviewdyad-sh/dyad22k—~1.4kAutomated safety check: PassCustom licence
Readable Verilog GeneratorEriemon/verilog-generator312—~5.4kAutomated safety check: PassApache-2.0
Dsh Upgrade AuditNanmiCoder/dsh-auto-mode1641 repos~2.5kAutomated safety check: PassMIT

Similar skills

  • Roo Conflict Resolution

    zgsm-ai/costrict

    Provides comprehensive guidelines for resolving merge conflicts intelligently using git history and commit context.

    4.4k GitHub stars~2.3k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • Deepseek Automation

    zhu1090093659/deepseek-pp

    A skill your agent uses when implementing, resuming, reviewing, or verifying the DeepSeek++ Codex-style automation feature in this repository.

    1.9k GitHub stars~2.1k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Deep Review

    dyad-sh/dyad

    Deep multi-agent code review run locally — a fleet of parallel finder agents reviews the diff from independent angles, then adversarial verifier agents reproduce each finding before it is reported.

    22k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Readable Verilog Generator

    Eriemon/verilog-generator

    A skill your agent uses when creating, writing, reviewing, annotating, repairing, refactoring, or validating readable Verilog RTL, including synthesizable Verilog-2001 .v files, existing-RTL…

    312 GitHub stars~5.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Dsh Upgrade Audit

    NanmiCoder/dsh-auto-mode

    Audit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm…

    164 GitHub starsUsed in 1 repo~2.5k tokens
    DevelopmentAuto-check passed
  • Skillhone

    Tencent/SkillHone

    Local Issue, pull-request, and Wiki workbench for agent skills.

    168 GitHub stars~3.4k tokensUpdated 19 days ago
    DevelopmentAuto-check passed

More from ccch1mneyyy/dsh-TUI

All 9 skills in this repo
  • Review

    ccch1mneyyy/dsh-TUI

    Review or de-slop concrete changes in ccch1mneyyy/dsh-TUI at maintainer level: PR numbers or URLs, branches, commit ranges, patch files, staged or unstaged worktrees, and scoped repository-hygiene…

    4.2k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Dsh Tui Guide

    ccch1mneyyy/dsh-TUI

    A skill your agent uses when the user asks about dsh-tui itself (usage, shortcuts, config, themes, migration, VS Code).

    4.2k GitHub stars~323 tokensUpdated today
    Auto-check passed
  • PR

    ccch1mneyyy/dsh-TUI

    Open or update a pull request in this repository, including writing or rewriting its description.

    4.2k GitHub stars~601 tokensUpdated today
    Auto-check passed
  • Vuln Check

    ccch1mneyyy/dsh-TUI

    Check resolved dependencies and relevant code paths for security vulnerabilities.

    4.2k GitHub stars~467 tokensUpdated today
    Auto-check passed
  • Bug

    ccch1mneyyy/dsh-TUI

    Turn a reported defect into an actionable bug report or issue draft.

    4.2k GitHub stars~342 tokensUpdated today
    Auto-check passed
  • PR Comments

    ccch1mneyyy/dsh-TUI

    Read and triage existing pull request review comments, or address them when requested.

    4.2k GitHub stars~353 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Audit

What does Audit do?

Audit the repository or a broad subsystem for security, correctness, and maintainability risks. Audit is an agent skill from ccch1mneyyy/dsh-TUI. Audit the repository or a broad subsystem for security, correctness, and maintainability risks.

When should I use Audit?

Audit fits situations like: use review for a specific change and vuln-check for a security-only assessment.

How do I install Audit in Claude Code?

Run `npx skills add ccch1mneyyy/dsh-TUI --skill audit -a claude-code`. Or copy the skill folder (.agents/skills/audit in ccch1mneyyy/dsh-TUI) into .claude/skills/audit in your project. Claude Code loads it when a task matches its description.

How do I install Audit in Codex?

Run `npx skills add ccch1mneyyy/dsh-TUI --skill audit -a codex`. Or copy the skill folder (.agents/skills/audit in ccch1mneyyy/dsh-TUI) into .agents/skills/audit in your project. Codex loads it when a task matches its description.

Can I use Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccch1mneyyy/dsh-TUI --skill audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit, .gemini/skills/audit, .github/skills/audit and .opencode/skills/audit in your project.

What does Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit is instructions for the agent only.

Does Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit use?

Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit use?

About 405 tokens (SKILL.md is roughly 1.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit?

Skills that share tags, products or a category with Audit: Roo Conflict Resolution (zgsm-ai/costrict, 4.4k stars), Deepseek Automation (zhu1090093659/deepseek-pp, 1.9k stars), Deep Review (dyad-sh/dyad, 22k stars) and Readable Verilog Generator (Eriemon/verilog-generator, 312 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit?

ccch1mneyyy (a GitHub user) maintains it in ccch1mneyyy/dsh-TUI, which has 4,208 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 9, 2026.

Source: ccch1mneyyy/dsh-TUI on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.