Agent skill

Audit Context Building

by CraftOS-dev in CraftOS-dev/CraftBot

Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.

MITAuto-check passed

Install Audit Context Building

skills CLI
$ npx skills add CraftOS-dev/CraftBot --skill audit-context-building -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CraftOS-dev/CraftBot audit-context-building --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CraftOS-dev/CraftBot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-context-building .claude/skills/audit-context-building && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-context-building
GitHub stars
392
Used in
3 other repos
Token cost
~2.4k tokens
SKILL.md length
1,115 words
Files
4
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.

  • Works in 10 steps: Purpose → When to Use This Skill → How This Skill Behaves → …
  • SKILL.md covers 1. Purpose, 2. When to Use This Skill, 3. How This Skill Behaves and Rationalizations (Do Not Skip), plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Context Building is an agent skill from CraftOS-dev/CraftBot. Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `resources/COMPLETENESS_CHECKLIST.md`, `resources/FUNCTION_MICRO_ANALYSIS_EXAMPLE.md` and `resources/OUTPUT_REQUIREMENTS.md`).

The repository describes itself as: One agent. Every kind of work. The licence is MIT.

Example prompts

  • “Use the audit-context-building skill to enable ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability…”
  • “/audit-context-building”

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Purpose
  2. When to Use This Skill
  3. How This Skill Behaves
  4. Phase 1 — Initial Orientation (Bottom-Up Scan)
  5. Phase 2 — Ultra-Granular Function Analysis (Default Mode)
  6. Phase 3 — Global System Understanding
  7. Stability & Consistency Rules
  8. Subagent Usage
  9. Relationship to Other Phases
  10. Non-Goals

What it can do on your machine

Read from SKILL.md and the folder at commit b50970c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Context Building loads about 2.4k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 1,115 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from CraftOS-dev/CraftBot at commit b50970c, republished under its MIT licence (© CraftOS-dev). 1,115 words, ~2,448 tokens.

Download SKILL.mdSave it as .claude/skills/audit-context-building/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
audit-context-building
description
Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.

Deep Context Builder Skill (Ultra-Granular Pure Context Mode)

1. Purpose

This skill governs how CraftBot thinks during the context-building phase of an audit.

When active, CraftBot will:

  • Perform line-by-line / block-by-block code analysis by default.
  • Apply First Principles, 5 Whys, and 5 Hows at micro scale.
  • Continuously link insights → functions → modules → entire system.
  • Maintain a stable, explicit mental model that evolves with new evidence.
  • Identify invariants, assumptions, flows, and reasoning hazards.

This skill defines a structured analysis format (see Example: Function Micro-Analysis below) and runs before the vulnerability-hunting phase.


2. When to Use This Skill

Use when:

  • Deep comprehension is needed before bug or vulnerability discovery.
  • You want bottom-up understanding instead of high-level guessing.
  • Reducing hallucinations, contradictions, and context loss is critical.
  • Preparing for security auditing, architecture review, or threat modeling.

Do not use for:

  • Vulnerability findings
  • Fix recommendations
  • Exploit reasoning
  • Severity/impact rating

3. How This Skill Behaves

When active, CraftBot will:

  • Default to ultra-granular analysis of each block and line.
  • Apply micro-level First Principles, 5 Whys, and 5 Hows.
  • Build and refine a persistent global mental model.
  • Update earlier assumptions when contradicted ("Earlier I thought X; now Y.").
  • Periodically anchor summaries to maintain stable context.
  • Avoid speculation; express uncertainty explicitly when needed.

Goal: deep, accurate understanding, not conclusions.


Rationalizations (Do Not Skip)

RationalizationWhy It's WrongRequired Action
"I get the gist"Gist-level understanding misses edge casesLine-by-line analysis required
"This function is simple"Simple functions compose into complex bugsApply 5 Whys anyway
"I'll remember this invariant"You won't. Context degrades.Write it down explicitly
"External call is probably fine"External = adversarial until proven otherwiseJump into code or model as hostile
"I can skip this helper"Helpers contain assumptions that propagateTrace the full call chain
"This is taking too long"Rushed context = hallucinated vulnerabilities laterSlow is fast

4. Phase 1 — Initial Orientation (Bottom-Up Scan)

Before deep analysis, CraftBot performs a minimal mapping:

  1. Identify major modules/files/contracts.
  2. Note obvious public/external entrypoints.
  3. Identify likely actors (users, owners, relayers, oracles, other contracts).
  4. Identify important storage variables, dicts, state structs, or cells.
  5. Build a preliminary structure without assuming behavior.

This establishes anchors for detailed analysis.


5. Phase 2 — Ultra-Granular Function Analysis (Default Mode)

Every non-trivial function receives full micro analysis.

5.1 Per-Function Microstructure Checklist

For each function:

  1. Purpose

    • Why the function exists and its role in the system.
  2. Inputs & Assumptions

    • Parameters and implicit inputs (state, sender, env).
    • Preconditions and constraints.
  3. Outputs & Effects

    • Return values.
    • State/storage writes.
    • Events/messages.
    • External interactions.
  4. Block-by-Block / Line-by-Line Analysis For each logical block:

    • What it does.
    • Why it appears here (ordering logic).
    • What assumptions it relies on.
    • What invariants it establishes or maintains.
    • What later logic depends on it.

    Apply per-block:

    • First Principles
    • 5 Whys
    • 5 Hows

5.2 Cross-Function & External Flow Analysis

(Full Integration of Jump-Into-External-Code Rule)

When encountering calls, continue the same micro-first analysis across boundaries.

Internal Calls
  • Jump into the callee immediately.
  • Perform block-by-block analysis of relevant code.
  • Track flow of data, assumptions, and invariants: caller → callee → return → caller.
  • Note if callee logic behaves differently in this specific call context.
External Calls — Two Cases

Case A — External Call to a Contract Whose Code Exists in the Codebase Treat as an internal call:

  • Jump into the target contract/function.
  • Continue block-by-block micro-analysis.
  • Propagate invariants and assumptions seamlessly.
  • Consider edge cases based on the actual code, not a black-box guess.

Case B — External Call Without Available Code (True External / Black Box) Analyze as adversarial:

  • Describe payload/value/gas or parameters sent.
  • Identify assumptions about the target.
  • Consider all outcomes:
    • revert
    • incorrect/strange return values
    • unexpected state changes
    • misbehavior
    • reentrancy (if applicable)
Continuity Rule

Treat the entire call chain as one continuous execution flow. Never reset context. All invariants, assumptions, and data dependencies must propagate across calls.


5.3 Complete Analysis Example

See FUNCTION_MICRO_ANALYSIS_EXAMPLE.md for a complete walkthrough demonstrating:

  • Full micro-analysis of a DEX swap function
  • Application of First Principles, 5 Whys, and 5 Hows
  • Block-by-block analysis with invariants and assumptions
  • Cross-function dependency mapping
  • Risk analysis for external interactions

This example demonstrates the level of depth and structure required for all analyzed functions.


Show full SKILL.md (437 more words)Show less
5.4 Output Requirements

When performing ultra-granular analysis, CraftBot MUST structure output following the format defined in OUTPUT_REQUIREMENTS.md.

Key requirements:

  • Purpose (2-3 sentences minimum)
  • Inputs & Assumptions (all parameters, preconditions, trust assumptions)
  • Outputs & Effects (returns, state writes, external calls, events, postconditions)
  • Block-by-Block Analysis (What, Why here, Assumptions, First Principles/5 Whys/5 Hows)
  • Cross-Function Dependencies (internal calls, external calls with risk analysis, shared state)

Quality thresholds:

  • Minimum 3 invariants per function
  • Minimum 5 assumptions documented
  • Minimum 3 risk considerations for external interactions
  • At least 1 First Principles application
  • At least 3 combined 5 Whys/5 Hows applications

5.5 Completeness Checklist

Before concluding micro-analysis of a function, verify against the COMPLETENESS_CHECKLIST.md:

  • Structural Completeness: All required sections present (Purpose, Inputs, Outputs, Block-by-Block, Dependencies)
  • Content Depth: Minimum thresholds met (invariants, assumptions, risk analysis, First Principles)
  • Continuity & Integration: Cross-references, propagated assumptions, invariant couplings
  • Anti-Hallucination: Line number citations, no vague statements, evidence-based claims

Analysis is complete when all checklist items are satisfied and no unresolved "unclear" items remain.


6. Phase 3 — Global System Understanding

After sufficient micro-analysis:

  1. State & Invariant Reconstruction

    • Map reads/writes of each state variable.
    • Derive multi-function and multi-module invariants.
  2. Workflow Reconstruction

    • Identify end-to-end flows (deposit, withdraw, lifecycle, upgrades).
    • Track how state transforms across these flows.
    • Record assumptions that persist across steps.
  3. Trust Boundary Mapping

    • Actor → entrypoint → behavior.
    • Identify untrusted input paths.
    • Privilege changes and implicit role expectations.
  4. Complexity & Fragility Clustering

    • Functions with many assumptions.
    • High branching logic.
    • Multi-step dependencies.
    • Coupled state changes across modules.

These clusters help guide the vulnerability-hunting phase.


7. Stability & Consistency Rules

(Anti-Hallucination, Anti-Contradiction)

CraftBot must:

  • Never reshape evidence to fit earlier assumptions. When contradicted:

    • Update the model.
    • State the correction explicitly.
  • Periodically anchor key facts Summarize core:

    • invariants
    • state relationships
    • actor roles
    • workflows
  • Avoid vague guesses Use:

    • "Unclear; need to inspect X." instead of:
    • "It probably…"
  • Cross-reference constantly Connect new insights to previous state, flows, and invariants to maintain global coherence.


8. Subagent Usage

CraftBot may spawn subagents for:

  • Dense or complex functions.
  • Long data-flow or control-flow chains.
  • Cryptographic / mathematical logic.
  • Complex state machines.
  • Multi-module workflow reconstruction.

Use the function-analyzer agent for per-function deep analysis. It follows the full microstructure checklist, cross-function flow rules, and quality thresholds defined in this skill, and enforces the pure-context-building constraint.

Subagents must:

  • Follow the same micro-first rules.
  • Return summaries that CraftBot integrates into its global model.

9. Relationship to Other Phases

This skill runs before:

  • Vulnerability discovery
  • Classification / triage
  • Report writing
  • Impact modeling
  • Exploit reasoning

It exists solely to build:

  • Deep understanding
  • Stable context
  • System-level clarity

10. Non-Goals

While active, CraftBot should NOT:

  • Identify vulnerabilities
  • Propose fixes
  • Generate proofs-of-concept
  • Model exploits
  • Assign severity or impact

This is pure context building only.

© CraftOS-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in skills/audit-context-building of CraftOS-dev/CraftBot.

  • SKILL.md
  • resources/COMPLETENESS_CHECKLIST.md
  • resources/FUNCTION_MICRO_ANALYSIS_EXAMPLE.md
  • resources/OUTPUT_REQUIREMENTS.md

Open the folder on GitHubat commit b50970c

Used in 3 other repositories

We found 12 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in CraftOS-dev/CraftBot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Audit Context Building next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Context Building compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Context Building this skillCraftOS-dev/CraftBot3923 repos~2.4kAutomated safety check: PassMIT
Sales Enablement Kitaaron-he-zhu/aaron-marketing-skills2.9k—~3.3kAutomated safety check: PassApache-2.0
Sales Enablementrevfactory/harness-1001.3k—~1.7kAutomated safety check: PassApache-2.0
Eol Internal Enablementdeanpeters/Product-Manager-Skills7.2k—~3.1kAutomated safety check: PassCustom licence
Sales Enablementcbrock84/headcount2k—~783Automated safety check: PassMIT
Sales Enablement Kitmohitagw15856/pm-claude-skills1.4k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Sales Enablement Kit

    aaron-he-zhu/aaron-marketing-skills

    A skill your agent uses when the user asks to "build battle cards", "prep the sales team for launch", or "write the internal launch FAQ"; produces the internal enablement kit for a sales-led launch…

    2.9k GitHub stars~3.3k tokensUpdated today
    Sales & SupportAuto-check passed
  • Sales Enablement

    revfactory/harness-100

    A full B2B sales enablement pipeline. An agent skill from revfactory/harness-100.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Sales & SupportAuto-check passed
  • Eol Internal Enablement

    deanpeters/Product-Manager-Skills

    Build the support FAQ, sales talking points, and objection handling teams need before an EOL announcement.

    7.2k GitHub stars~3.1k tokensUpdated 1 mo ago
    Sales & SupportAuto-check passed
  • Sales Enablement

    cbrock84/headcount

    Builds what a sales team needs to sell — pitch decks, one-pagers, objection handling, competitive battlecards, demo scripts, and case studies.

    2k GitHub stars~783 tokensUpdated 20 days ago
    Sales & SupportAuto-check passed
  • Sales Enablement Kit

    mohitagw15856/pm-claude-skills

    Build a sales enablement kit so reps can sell a product, feature, or launch confidently.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Sales & SupportAuto-check passed
  • Nemotron Ultra

    NVIDIA-NeMo/Nemotron

    Reference desk for NVIDIA Nemotron 3 Ultra (550B-A55B) — architecture, NVFP4 pretraining, SFT, MOPD (multi-teacher on-policy distillation), MTP boosting, quantization, inference.

    2.1k GitHub stars~1.8k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed

More from CraftOS-dev/CraftBot

All 89 skills in this repo
  • Self Improvement

    CraftOS-dev/CraftBot

    Captures learnings, errors, and corrections to enable continuous improvement.

    392 GitHub starsUsed in 5 repos~4.9k tokens
    Auto-check passed
  • Bbc News

    CraftOS-dev/CraftBot

    Fetch and display BBC News stories from various sections and regions via RSS feeds.

    392 GitHub starsUsed in 2 repos~555 tokens
    Auto-check passed
  • Outlook

    CraftOS-dev/CraftBot

    Read, search, and manage Outlook emails and calendar via Microsoft Graph API.

    392 GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • Nano Banana Pro

    CraftOS-dev/CraftBot

    Generate/edit images with Nano Banana Pro (Gemini 3 Pro Image).

    392 GitHub starsUsed in 6 repos~1.4k tokens
    Auto-check passed
  • Airweave

    CraftOS-dev/CraftBot

    Context retrieval layer for AI agents across users' applications.

    392 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Telegram Bot Manager

    CraftOS-dev/CraftBot

    Manage and configure Telegram bots for OpenClaw. An agent skill from CraftOS-dev/CraftBot.

    392 GitHub stars~836 tokensUpdated today
    Auto-check passed

Questions about Audit Context Building

What does Audit Context Building do?

Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding. Audit Context Building is an agent skill from CraftOS-dev/CraftBot. Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.

How do I install Audit Context Building in Claude Code?

Run `npx skills add CraftOS-dev/CraftBot --skill audit-context-building -a claude-code`. Or copy the skill folder (skills/audit-context-building in CraftOS-dev/CraftBot) into .claude/skills/audit-context-building in your project. Claude Code loads it when a task matches its description.

How do I install Audit Context Building in Codex?

Run `npx skills add CraftOS-dev/CraftBot --skill audit-context-building -a codex`. Or copy the skill folder (skills/audit-context-building in CraftOS-dev/CraftBot) into .agents/skills/audit-context-building in your project. Codex loads it when a task matches its description.

Can I use Audit Context Building in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CraftOS-dev/CraftBot --skill audit-context-building -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-context-building, .gemini/skills/audit-context-building, .github/skills/audit-context-building and .opencode/skills/audit-context-building in your project.

What does Audit Context Building need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Context Building is instructions for the agent only.

Does Audit Context Building access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Context Building safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Context Building use?

Audit Context Building is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Context Building use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Context Building?

Skills that share tags, products or a category with Audit Context Building: Sales Enablement Kit (aaron-he-zhu/aaron-marketing-skills, 2.9k stars), Sales Enablement (revfactory/harness-100, 1.3k stars), Eol Internal Enablement (deanpeters/Product-Manager-Skills, 7.2k stars) and Sales Enablement (cbrock84/headcount, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Context Building?

CraftOS-dev (a GitHub user) maintains it in CraftOS-dev/CraftBot, which has 392 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on October 7, 2026.

Source: CraftOS-dev/CraftBot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.