A skill your agent uses when the user asks for a code review, "review this change", "review my PR", "review the diff", or wants quality/spec/security/perf feedback on recent changes.

Apache-2.0Auto-check passedDevelopment

Install Audit

skills CLI
$ npx skills add ccplugins/awesome-claude-code-plugins --skill audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccplugins/awesome-claude-code-plugins audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/hyperflow/skills/audit .claude/skills/audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit
GitHub stars
967
Token cost
~719 tokens
SKILL.md length
244 words
Files
1
Skills in repo
68
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user asks for a code review, "review this change", "review my PR", "review the diff", or wants quality/spec/security/perf feedback on recent changes.

  • Works in 6 steps: Resolve scope — use provided target or… → Dispatch Searcher — gathering context… → Dispatch Reviewer — reviewing at level L… → …
  • The user asks for a code review
  • SKILL.md covers Inputs, Review Levels, Flow and Output Format, plus 2 more sections
  • Calls git

What it does

Audit is an agent skill from ccplugins/awesome-claude-code-plugins. Use when the user asks for a code review, "review this change", "review my PR", "review the diff", or wants quality/spec/security/perf feedback on recent changes. Triggers a multi-level review with a thinking-tier reviewer agent. Standalone — does not auto-chain.

Its SKILL.md is about 720 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests. It works with Git. The repository describes itself as: Awesome Claude Code plugins — a curated list of slash commands, subagents, MCP servers, and hooks for Claude Code. The licence is Apache-2.0.

When your agent uses it

  • The user asks for a code review
  • Review this change
  • Review the diff
  • Wants quality/spec/security/perf feedback on recent changes

Example prompts

  • “review this change”
  • “review my PR”
  • “review the diff”
  • “/audit”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Resolve scope — use provided target or run git diff HEAD + git diff --staged.
  2. Dispatch Searcher — gathering context for review (Sonnet 4.6) to map referenced files and load relevant project context.
  3. Dispatch Reviewer — reviewing at level L — Opus 4.7 (thinking-tier, non-negotiable).
  4. Reviewer uses reviewer-prompt.md template with the diff, level definition, and any applicable spec.
  5. Aggregate findings into structured output (see below).
  6. Append durable patterns/gotchas to .hyperflow/memory/learnings.md per memory-system.md.

What it can do on your machine

Read from SKILL.md and the folder at commit 5bd4f16. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit loads about 719 tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 244 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~719

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccplugins/awesome-claude-code-plugins at commit 5bd4f16, republished under its Apache-2.0 licence (© ccplugins). 244 words, ~719 tokens.

Download SKILL.mdSave it as .claude/skills/audit/SKILL.md (or your agent's skills folder).
name
audit
description
Use when the user asks for a code review, "review this change", "review my PR", "review the diff", or wants quality/spec/security/perf feedback on recent changes. Triggers a multi-level review with a thinking-tier reviewer agent. Standalone — does not auto-chain.

Audit

Standalone multi-level code review. Dispatcher — Opus 4.7 (thinking-tier). Workers — Sonnet 4.6.

Inputs

  • Target — file path, line range, commit SHA, branch, or PR number provided by the user
  • Default (no target) — git diff HEAD + git diff --staged
  • Level flag — --level 1 through --level 5 (default — L2)

Review Levels

Adapted from review-levels.md:

LNameChecks
1QuickSyntax, obvious bugs, formatting
2StandardL1 + spec compliance, naming, edge cases
3ThoroughL2 + cross-file consistency, integration risks, security
4DeepL3 + architecture, scalability, accessibility
5ExhaustiveL4 + adversarial probing, perf profiling, alternatives

Security scan (hardcoded secrets, injection, path traversal, XSS, missing validation) is mandatory at L3+. See security.md.

Flow

  1. Resolve scope — use provided target or run git diff HEAD + git diff --staged.
  2. Dispatch Searcher — gathering context for review (Sonnet 4.6) to map referenced files and load relevant project context.
  3. Dispatch **Reviewer** — reviewing <scope> at level L<n> — Opus 4.7 (thinking-tier, non-negotiable).
  4. Reviewer uses reviewer-prompt.md template with the diff, level definition, and any applicable spec.
  5. Aggregate findings into structured output (see below).
  6. Append durable patterns/gotchas to .hyperflow/memory/learnings.md per memory-system.md.

If any security issue found → emit SECURITY_VIOLATION: halt marker immediately.

Output Format

── Review Result ──────────────────────
Scope: <files / range / commit>
Level: L<n>
Verdict: PASS | NEEDS_FIX | SECURITY_VIOLATION

[Critical]
- file:line — issue + required fix

[Important]
- file:line — issue + recommended fix

[Suggestions]
- file:line — optional improvement

[Praise]
- file:line — what's done well
───────────────────────────────────────
Agents: 1 searcher (sonnet) · 1 reviewer (opus)

Hand-off (no auto-chain)

  • PASS — suggest /hyperflow:deploy if the user is ready to release. Do not auto-ship.
  • NEEDS_FIX — print the finding list and suggest /hyperflow:trace (for root-cause bugs) or manual edits. Do not auto-fix.
  • SECURITY_VIOLATION — halt; do not transition. User decides remediation path.

Doctrine

Full rules in DOCTRINE.md. Output style in output-style.md.

© ccplugins, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/hyperflow/skills/audit of ccplugins/awesome-claude-code-plugins.

Open the folder on GitHubat commit 5bd4f16

Compare with similar skills

Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit this skillccplugins/awesome-claude-code-plugins967—~719Automated safety check: PassApache-2.0
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Pull Request Title and Body Writer

    openinterpreter/openinterpreter

    Rewrites the title and body of one or more pull requests with gh, leading with why the change was made, then what changed, and describing only the net result.

    69k GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check passed

More from ccplugins/awesome-claude-code-plugins

All 68 skills in this repo
  • AI Meeting

    ccplugins/awesome-claude-code-plugins

    Run structured AI meetings for plans, product ideas, technical designs, business decisions, feature proposals, and strategy choices.

    967 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check: notes
  • Fastapi App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new FastAPI backend with async SQLAlchemy 2.0, asyncpg, Alembic, Pydantic v2, and no deprecated APIs.

    967 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Flutter App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new Flutter mobile app with clean architecture, Riverpod, FVM-pinned SDK, current packages, and no deprecated APIs.

    967 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Nextjs App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new Next.js (App Router, TypeScript) web app with current packages and no deprecated APIs.

    967 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Dev Report

    ccplugins/awesome-claude-code-plugins

    Write up a coding session for a non-technical stakeholder — the context, what was built, and the engineering reasoning behind it — the way a senior engineer briefs a product manager who does not…

    967 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Difesa Attacchi

    ccplugins/awesome-claude-code-plugins

    Aggiunge a un sito/app un agente di difesa che rileva e blocca richieste malevole (SQL injection, XSS, path traversal, brute force, bot) con rate limiting, blocklist IP e modalità lockdown che…

    967 GitHub stars~781 tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Audit

What does Audit do?

A skill your agent uses when the user asks for a code review, "review this change", "review my PR", "review the diff", or wants quality/spec/security/perf feedback on recent changes. Audit is an agent skill from ccplugins/awesome-claude-code-plugins. Use when the user asks for a code review, "review this change", "review my PR", "review the diff", or wants quality/spec/security/perf feedback on recent changes.

When should I use Audit?

Audit fits situations like: the user asks for a code review; review this change; review the diff; wants quality/spec/security/perf feedback on recent changes.

How do I install Audit in Claude Code?

Run `npx skills add ccplugins/awesome-claude-code-plugins --skill audit -a claude-code`. Or copy the skill folder (plugins/hyperflow/skills/audit in ccplugins/awesome-claude-code-plugins) into .claude/skills/audit in your project. Claude Code loads it when a task matches its description.

How do I install Audit in Codex?

Run `npx skills add ccplugins/awesome-claude-code-plugins --skill audit -a codex`. Or copy the skill folder (plugins/hyperflow/skills/audit in ccplugins/awesome-claude-code-plugins) into .agents/skills/audit in your project. Codex loads it when a task matches its description.

Can I use Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccplugins/awesome-claude-code-plugins --skill audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit, .gemini/skills/audit, .github/skills/audit and .opencode/skills/audit in your project.

What does Audit need to run?

Going by SKILL.md and its folder, Audit needs the command-line tools its instructions call (git).

Does Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit use?

Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit use?

About 719 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit?

Skills that share tags, products or a category with Audit: Finishing a Development Branch (obra/superpowers, 296k stars), Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars) and Open Code Review CLI (alibaba/open-code-review, 44k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit?

ccplugins (a GitHub organization) maintains it in ccplugins/awesome-claude-code-plugins, which has 967 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on August 12, 2026.

Source: ccplugins/awesome-claude-code-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.