Agent skill

Audit Code

by danielvm-git in danielvm-git/bigpowers

Self-review checklist for the coding agent to run before dispatching a reviewer.

MITAuto-check: notesTesting & QA

Install Audit Code

skills CLI
$ npx skills add danielvm-git/bigpowers --skill audit-code -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install danielvm-git/bigpowers audit-code --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/danielvm-git/bigpowers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-code .claude/skills/audit-code && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-code
GitHub stars
256
Token cost
~1.6k tokens
SKILL.md length
774 words
Files
2
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

Self-review checklist for the coding agent to run before dispatching a reviewer.

  • Asks for a code quality check
  • SKILL.md covers Look-here-first (churn…, Modes, Checklist and Output, plus 2 more sections
  • Calls bash and gh
  • Tasks that involve Test coverage

What it does

Audit Code is an agent skill from danielvm-git/bigpowers. Self-review checklist for the coding agent to run before dispatching a reviewer. Checks CONVENTIONS.md compliance, Boy Scout Rule, test coverage, types, and SOLID. Produces a pass/fail checklist. Use before request-review, before committing, or when user asks for a code quality check.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `HEURISTICS.md`).

It sits in Testing & QA, covering Test coverage and Code quality. The repository describes itself as: Agent skills synthesizing years of software engineering discipline into a prescriptive methodology for solo developers. The licence is MIT.

When your agent uses it

  • Asks for a code quality check
  • Tasks that involve Test coverage
  • Tasks that involve Code quality

Example prompts

  • “/audit-code”

What it can do on your machine

Read from SKILL.md and the folder at commit 812d57a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Code loads about 1.6k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 774 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:47
    secrets in diff (`sk-`, `ghp_`, `AKIA`, `.env` values) — see `guard-git` patterns

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from danielvm-git/bigpowers at commit 812d57a, republished under its MIT licence (© danielvm-git). 774 words, ~1,604 tokens.

Download SKILL.mdSave it as .claude/skills/audit-code/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
audit-code
description
Self-review checklist for the coding agent to run before dispatching a reviewer. Checks CONVENTIONS.md compliance, Boy Scout Rule, test coverage, types, and SOLID. Produces a pass/fail checklist. Use before request-review, before committing, or when user asks for a code quality check.
model
haiku
effort
standard

Audit Code

HARD GATE — HARD GATE — Audit must check for: bugs (correctness), security, performance, and clarity. Do NOT skip security review if the code touches user data, auth, or external APIs.

Run this self-review before asking anyone else to look at the code. The goal is to catch everything that is clearly wrong or missing — so the reviewer can focus on design and architecture, not hygiene.

Distinct from request-review: This is the coding agent checking its own work. No second agent is involved. Run this first; run request-review after this passes.

Look-here-first (churn heuristic)

Before the checklist, rank changed files by git churn and review high-churn hotspots first — they carry the most latent risk regardless of diff size.

bash
bash scripts/bp-churn-rank.sh --since 90.days --limit 15

Apply the full checklist to churn-ranked files in descending order. Files with zero recent commits but large diffs still get reviewed; churn only sets priority, not scope.

Modes

  • Default: full checklist
  • --quick: Run only Supply Chain and Test Coverage. Use for changes under 50 LOC.
  • --gate: Non-interactive mode for automated CI gating (used by build-epic step 6). Exit with non-zero status code (exit 1) on ANY checklist failure; exit 0 only if ALL items pass. Produces a compact pass/fail summary to stderr. On failure, list every ✗ item with reason.
  • --parallel: Run checklist sections in isolated git worktrees (e45s18) so concurrent checks cannot corrupt each other's working tree:
bash
bash scripts/lib/parallel-review-worktrees.sh audit-code

Checklist

Supply Chain & Security
  • slopcheck run for new dependencies; packages tagged in plan-work: [OK], [SUS], or [SLOP]
  • No [SLOP] packages without documented human approval
  • No secrets in diff (sk-, ghp_, AKIA, .env values) — see guard-git patterns
  • OWASP Top 10 spot-check: injection, broken auth, sensitive data exposure, misconfiguration (see docs/references/security-threats.md)
  • Security: diff scanned — no unaddressed HIGH findings (or deviations documented in specs/security/EXCEPTIONS.md)
Provenance & Metadata
  • New plan artefacts include type: and context: metadata
  • Implementation steps reference ADR or commit SHA where decisions were made
Law of Demeter
  • No method chains through unrelated objects (e.g. a.getB().getC().doX())
  • Collaborators talk to immediate neighbors only; law violations need explicit justification
CONVENTIONS.md Compliance
  • All output files are in specs/ (no docs written to project root)
  • No gh issue create calls anywhere in new/modified skills or scripts
  • gh used only for PRs and repo clone operations
  • No GitHub REST API called directly (no curl/fetch to api.github.com)
Scope
  • Changes are limited to what was asked — nothing extra refactored or reorganized
  • No speculative features added
  • No files touched outside the stated scope
  • Discovered defects: Reproducible gate failures (Preflight, CI, golden suite) require fix-or-log — quick-fix or fix-bug — even when "outside" the story scope. Scope-minimization does not waive Always Green.
  • Boy Scout Rule applies to files opened to fix a gate failure; it does not excuse skipping red Preflight
Boy Scout Rule
  • Every file I touched is cleaner than when I found it
  • No dead code left behind
  • No commented-out code blocks
Show full SKILL.md (315 more words)Show less
Types and Safety
  • No any types introduced (TypeScript) or untyped public functions (Python/Go/etc.)
  • No @ts-ignore or // eslint-disable added
  • No as unknown as X casts that bypass type safety
Test Coverage
  • Every new function has at least one test
  • Every bug fix has a regression test
  • Tests verify behavior through public interfaces (not implementation details)
  • Tests are F.I.R.S.T compliant (per CONVENTIONS.md §Tests; use enforce-first if unsure)
SOLID and Heuristics
  • Single Responsibility: no function or module doing two unrelated things
  • Open/Closed: extended through interfaces, not by modifying stable code
  • Dependency Inversion: dependencies injected, not imported globally where avoidable
  • Chapter 17 Heuristics: Code is free of smells documented in audit-code/HEURISTICS.md (G, N, C, T)
Refactoring Smells (Fowler)

Explicitly name any detected smells: Mysterious Name, Duplicated Code, Feature Envy, Data Clumps, Primitive Obsession, Message Chains, Middle Man.

Code Style (CONVENTIONS.md)
  • Functions: 4–20 lines; split if longer
  • Functions: descend exactly one level of abstraction (The Stepdown Rule / G34)
  • Files: under 300 lines (ideally 200–300)
  • Names: specific and unique (grep returns < 5 hits for each name)
  • No duplication — shared logic extracted (DRY / G5)
  • Early returns over nested ifs; max 2 levels of indentation
  • Conditionals: expressed as positives (G29)
  • Comments explain WHY, not WHAT
Red Flags

Before reporting, name any rationalization you caught yourself making for skipping a checklist item. Silence is not acceptable — if you skipped an item, state the reason explicitly.

Output

Report the checklist with ✓ / ✗ per item. For each ✗, describe what needs to be fixed.

If all items pass: suggest running request-review for an independent second opinion. If any items fail: fix them before proceeding.

In --gate mode, print one summary line per checklist section (PASS Supply Chain / FAIL Provenance (2 items)). Exit 0 only if all PASS. Write full report to specs/verifications/AUDIT-<epic>-<story>.md.

Verify

→ verify: test -f CONVENTIONS.md && test -d skills/enforce-first && test -d skills/request-review

Handoff

Gate: READY -> next: commit-message Writes: state.yaml handoff.next_skill = commit-message

<!-- story: e01s02 -->
<!-- story: e06s03 -->
<!-- story: e07s01 -->

© danielvm-git, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/audit-code of danielvm-git/bigpowers.

  • SKILL.md
  • HEURISTICS.md

Open the folder on GitHubat commit 812d57a

Compare with similar skills

Audit Code next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Code compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Code this skilldanielvm-git/bigpowers256—~1.6kAutomated safety check: NotesMIT
Supercovsupercorp-ai/supercov1481 repos~415Automated safety check: PassMIT
Dev ReviewFHIR/fhir-codegen154—~5kAutomated safety check: PassMIT
Coverage Analysis for .NETdotnet/skills5.6k1 repos~2.8kAutomated safety check: PassMIT
Mcaf Dotnet Quality CImanagedcode/Storage138—~1.7kAutomated safety check: PassMIT
Quality CImanagedcode/dotnet-skills486—~2.1kAutomated safety check: PassMIT

Similar skills

  • Supercov

    supercorp-ai/supercov

    Measures test coverage and code quality in a repository with the supercov CLI, and turns what it finds into small, focused tests or fixes.

    148 GitHub starsUsed in 1 repo~415 tokens
    Testing & QAAuto-check passed
  • Dev Review

    FHIR/fhir-codegen

    Performs a two-track code-quality and QA review in the roles of a staff-level Engineering Lead and QA Lead, then synthesizes both critiques into a single analysis.md.

    154 GitHub stars~5k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Official

    Interprets .NET coverage reports to explain line and branch gaps, target arithmetic and, on request, CRAP-based risk hotspots, without rerunning tests.

    5.6k GitHub starsUsed in 1 repo~2.8k tokens
    Testing & QAAuto-check passed
  • Mcaf Dotnet Quality CI

    managedcode/Storage

    Set up or refine open-source .NET code-quality gates for CI: formatting, .editorconfig, SDK analyzers, third-party analyzers, coverage, mutation testing, architecture tests, and security scanning.

    138 GitHub stars~1.7k tokensUpdated today
    Testing & QAAuto-check passed
  • Quality CI

    managedcode/dotnet-skills

    Set up or refine open-source .NET code-quality gates for CI: formatting, .editorconfig, SDK analyzers, third-party analyzers, coverage, mutation testing, architecture tests, and security scanning.

    486 GitHub stars~2.1k tokensUpdated today
    Testing & QAAuto-check passed
  • Code Quality Crap

    macalbert/envilder

    CRAP score quality gate for code complexity and test coverage.

    138 GitHub stars~468 tokensUpdated 2 days ago
    Testing & QAAuto-check passed

More from danielvm-git/bigpowers

All 39 skills in this repo
  • Extract Design

    danielvm-git/bigpowers

    Extract a Google DESIGN.md file from an HTML prototype (claude.ai/design or any styled page) using Puppeteer, producing machine-readable tokens and AI-generated prose.

    256 GitHub stars~1k tokensUpdated 16 days ago
    Auto-check passed
  • Align Grid

    danielvm-git/bigpowers

    Build editorial/magazine/report webpages on a GENUINE Müller-Brockmann modular grid (International Typographic Style) — not a decorative one.

    256 GitHub stars~3k tokensUpdated 16 days ago
    Auto-check passed
  • Assess Impact

    danielvm-git/bigpowers

    Analyze the blast radius of a proposed change before any code is written.

    256 GitHub stars~766 tokensUpdated 16 days ago
    Auto-check passed
  • Audit Plan

    danielvm-git/bigpowers

    Evaluate an incoming project plan against bigpowers principles and conventions, surface gaps, and produce a READY/NOT READY verdict before engagement begins.

    256 GitHub stars~880 tokensUpdated 16 days ago
    Auto-check passed
  • Compose Workflow

    danielvm-git/bigpowers

    Chain multiple bigpowers skills into a custom workflow recipe saved in specs/.

    256 GitHub stars~723 tokensUpdated 16 days ago
    Auto-check passed
  • Context7 MCP

    danielvm-git/bigpowers

    Fetch current library docs via Context7 MCP instead of training data.

    256 GitHub stars~603 tokensUpdated 16 days ago
    Auto-check passed

Questions about Audit Code

What does Audit Code do?

Self-review checklist for the coding agent to run before dispatching a reviewer. Audit Code is an agent skill from danielvm-git/bigpowers. Self-review checklist for the coding agent to run before dispatching a reviewer.

When should I use Audit Code?

Audit Code fits situations like: asks for a code quality check; tasks that involve Test coverage; tasks that involve Code quality.

How do I install Audit Code in Claude Code?

Run `npx skills add danielvm-git/bigpowers --skill audit-code -a claude-code`. Or copy the skill folder (skills/audit-code in danielvm-git/bigpowers) into .claude/skills/audit-code in your project. Claude Code loads it when a task matches its description.

How do I install Audit Code in Codex?

Run `npx skills add danielvm-git/bigpowers --skill audit-code -a codex`. Or copy the skill folder (skills/audit-code in danielvm-git/bigpowers) into .agents/skills/audit-code in your project. Codex loads it when a task matches its description.

Can I use Audit Code in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add danielvm-git/bigpowers --skill audit-code -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-code, .gemini/skills/audit-code, .github/skills/audit-code and .opencode/skills/audit-code in your project.

What does Audit Code need to run?

Going by SKILL.md and its folder, Audit Code needs the command-line tools its instructions call (bash and gh).

Does Audit Code access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Code safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Audit Code use?

Audit Code is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Code use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Code?

Skills that share tags, products or a category with Audit Code: Supercov (supercorp-ai/supercov, 148 stars), Dev Review (FHIR/fhir-codegen, 154 stars), Coverage Analysis for .NET (dotnet/skills, 5.6k stars) and Mcaf Dotnet Quality CI (managedcode/Storage, 138 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Code?

danielvm-git (a GitHub user) maintains it in danielvm-git/bigpowers, which has 256 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on September 21, 2026.

Source: danielvm-git/bigpowers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.