Agent skill

Hk Slop Audit

by deepklarity in deepklarity/harness-kit

Run a codebase hygiene audit. An agent skill from deepklarity/harness-kit.

MITAuto-check: notesDevelopment

Install Hk Slop Audit

skills CLI
$ npx skills add deepklarity/harness-kit --skill hk-slop-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install deepklarity/harness-kit hk-slop-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/deepklarity/harness-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/hk-slop-audit .claude/skills/hk-slop-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hk-slop-audit
GitHub stars
100
Token cost
~1.2k tokens
SKILL.md length
493 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

Run a codebase hygiene audit. An agent skill from deepklarity/harness-kit.

  • Works in 4 steps: Map the project structure → Scan each category → Verify before reporting → …
  • : audit the codebase
  • SKILL.md covers Scope, What is slop?, Process and Output
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Hk Slop Audit is an agent skill from deepklarity/harness-kit. Run a codebase hygiene audit. Scans for misplaced files, dead code, temp files, security issues, structural problems, dependency slop, and git slop. Outputs a prioritized report with P0-P4 findings. Use periodically or before releases. Triggers on: 'audit the codebase', 'find slop', 'hygiene check', 'clean up', or /hk-slop-audit.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with Git. The repository describes itself as: A kit for building with AI agents and also the engineering patterns around it. The licence is MIT.

When your agent uses it

  • : audit the codebase

Example prompts

  • “audit the codebase”
  • “find slop”
  • “hygiene check”
  • “/hk-slop-audit”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Bash, Read, Edit, Write, Task, Grep, Glob

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Map the project structure
  2. Scan each category
  3. Verify before reporting
  4. Grade each finding

What it can do on your machine

Read from SKILL.md and the folder at commit 87305cd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Edit
    • Write
    • Task
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hk Slop Audit loads about 1.2k tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 493 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:38
    alhost URLs/ports/credentials. Committed .env files, API keys, tokens. Default passwords in non-example files. Overly pe
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Edit, Write, Task, Grep, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from deepklarity/harness-kit at commit 87305cd, republished under its MIT licence (© deepklarity). 493 words, ~1,249 tokens.

Download SKILL.mdSave it as .claude/skills/hk-slop-audit/SKILL.md (or your agent's skills folder).
name
hk-slop-audit
description
Run a codebase hygiene audit. Scans for misplaced files, dead code, temp files, security issues, structural problems, dependency slop, and git slop. Outputs a prioritized report with P0-P4 findings. Use periodically or before releases. Triggers on: 'audit the codebase', 'find slop', 'hygiene check', 'clean up', or /hk-slop-audit.
allowed-tools
Bash, Read, Edit, Write, Task, Grep, Glob
argument-hint
[optional: directory or category to focus on]

/hk-slop-audit — Codebase Hygiene Auditor

Systematically scan the codebase for slop — code that degrades quality through misplacement, abandonment, inconsistency, or negligence. Produce a prioritized, actionable report.

Scope

<audit_scope> $ARGUMENTS </audit_scope>

If a scope is provided, focus on that directory or category. Otherwise, audit the entire repository.

What is slop?

Slop is anything that makes a developer say "wait, why is this here?" or "is this still used?" It's the entropy that accumulates when people add things but never clean up.

Process

Step 1: Map the project structure

Use Glob and Bash (ls) to understand the directory layout, build systems, and language boundaries. Read the root CLAUDE.md and any project-level CLAUDE.md files to understand intentional patterns — things that look unusual but are deliberate are not slop.

Step 2: Scan each category

Work through each category using parallel subagents where possible. Each subagent scans one category and returns findings.

Category 1 — Misplaced Files: Files in the wrong directory. A Python script in a frontend dir. A test file in src. A config file at the wrong level.

Category 2 — Dead & Orphaned Code: Unused imports, functions nothing calls, commented-out code blocks, orphaned tests for deleted functionality, stale feature flags.

Category 3 — Temp & Scratch Files: Files named temp_*, scratch_*, debug_*, old_*, backup_*. One-off scripts (populate_data, fix_migration, quick_test). Log files or build artifacts committed to git.

Category 4 — Security & Config Slop: Hardcoded localhost URLs/ports/credentials. Committed .env files, API keys, tokens. Default passwords in non-example files. Overly permissive CORS/auth settings.

Category 5 — Structural Slop: Duplicate logic across files. Inconsistent naming conventions. God files (>500 lines doing multiple things). Circular imports. Docs describing behavior the code no longer has.

Category 6 — Dependency Slop: Unused dependencies. Pinned versions with known vulnerabilities. Multiple packages doing the same thing. Dev dependencies in production lists.

Category 7 — Git & Project Slop: Files that should be in .gitignore. TODO/FIXME/HACK comments older than 6 months (check git blame). Stale branches referenced in configs.

Show full SKILL.md (175 more words)Show less
Step 3: Verify before reporting

Do not flag something as dead code without checking for dynamic imports, reflection, or framework magic. Do not flag a file as misplaced without understanding the project's conventions. Do not flag test fixtures, example files, or template files — they exist for a purpose.

Step 4: Grade each finding
  • P0 — Critical: Active security risk. Committed secrets, exposed credentials, hardcoded tokens.
  • P1 — High: Actively misleading. Files in wrong directories, dead code developers waste time reading, docs describing wrong behavior.
  • P2 — Medium: Technical debt that compounds. Duplicated logic, unused dependencies inflating builds, stale configs.
  • P3 — Low: Code quality friction. Naming inconsistency, oversized files, minor convention violations.
  • P4 — Trivial: Cosmetic. Extra whitespace, old comments, minor style nits.

Output

Create slops/all_slops.md
markdown
# Slop Audit — harness-kit

**Audited**: [date]
**Scope**: [directories audited]
**Total findings**: [N] (P0: [n], P1: [n], P2: [n], P3: [n], P4: [n])

## Summary by Priority

### P0 — Critical
| # | Finding | File(s) | Category |
|---|---------|---------|----------|

[...repeat for each priority level...]

## Findings by Category

### Misplaced Files
- SLOP-001 — P1 — `path/to/file` — [short description]

[...repeat for each category with findings...]
Create detail files for P0-P2

For findings P0, P1, and P2, create slops/SLOP-NNN-<slug>.md:

markdown
# SLOP-NNN: [Short Title]

**Priority**: P[0-2]
**Category**: [category name]
**File(s)**: `path/to/file`
**Age**: [git blame date or estimate]

## What's Wrong
[2-3 sentences]

## Evidence
[Code snippets, grep results, or structural observations]

## Suggested Fix
[Concrete action]

## Risk of Fixing
[Low/Medium/High — could fixing this break something?]

P3 and P4 findings go in the summary only — no individual detail files.

Print summary

After creating all files, print:

  • Total findings per priority
  • Top 5 most impactful fixes (best effort-to-impact ratio)
  • Any categories with zero findings (confirms they were checked)

© deepklarity, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/hk-slop-audit of deepklarity/harness-kit.

Open the folder on GitHubat commit 87305cd

Compare with similar skills

Hk Slop Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hk Slop Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hk Slop Audit this skilldeepklarity/harness-kit100—~1.2kAutomated safety check: NotesMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Finishing A Development Branchfarm-fe/farm5.6k35 repos~1.8kAutomated safety check: PassMIT
Migrate Internal Package into GhostTryGhost/Ghost56k—~3.8kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • A skill your agent uses when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for…

    5.6k GitHub starsUsed in 35 repos~1.8k tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    56k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Doc Sync

    JetBrains/ideavim

    Official

    Keeps IdeaVim documentation in sync with code changes. An agent skill from JetBrains/ideavim.

    10k GitHub starsUsed in 2 repos~2.6k tokens
    DevelopmentAuto-check passed

More from deepklarity/harness-kit

All 18 skills in this repo
  • Hk Skill Creator

    deepklarity/harness-kit

    Create new skills, modify and improve existing skills, and measure skill performance.

    100 GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Hk Arch Audit

    deepklarity/harness-kit

    Run comprehensive agent-native architecture review with scored principles.

    100 GitHub stars~1.1k tokensUpdated 2 mo ago
    Auto-check: notes
  • Hk Mock First

    deepklarity/harness-kit

    Mock-first, layer-by-layer feature development. An agent skill from deepklarity/harness-kit.

    100 GitHub stars~3.9k tokensUpdated 2 mo ago
    Auto-check: notes
  • Hk Autonomy Audit

    deepklarity/harness-kit

    Audit whether an AI agent can autonomously close the loop on problems in a given area — from discovering a symptom to verifying a fix — without human intervention.

    100 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check: notes
  • Hk Breadcrumb Creator

    deepklarity/harness-kit

    Traces a workflow end-to-end through the harness-kit monorepo and creates a breadcrumb analysis doc in docs/breadcrumbanalysis/.

    100 GitHub stars~3k tokensUpdated 2 mo ago
    Auto-check: notes
  • Hk Changelog

    deepklarity/harness-kit

    Generate changelog entries from git diffs, prepend to CHANGELOG.md, and optionally commit + PR.

    100 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check: notes

Works with

Categories

Questions about Hk Slop Audit

What does Hk Slop Audit do?

Run a codebase hygiene audit. An agent skill from deepklarity/harness-kit. Hk Slop Audit is an agent skill from deepklarity/harness-kit. Run a codebase hygiene audit.

When should I use Hk Slop Audit?

Hk Slop Audit fits situations like: : audit the codebase.

How do I install Hk Slop Audit in Claude Code?

Run `npx skills add deepklarity/harness-kit --skill hk-slop-audit -a claude-code`. Or copy the skill folder (.claude/skills/hk-slop-audit in deepklarity/harness-kit) into .claude/skills/hk-slop-audit in your project. Claude Code loads it when a task matches its description.

How do I install Hk Slop Audit in Codex?

Run `npx skills add deepklarity/harness-kit --skill hk-slop-audit -a codex`. Or copy the skill folder (.claude/skills/hk-slop-audit in deepklarity/harness-kit) into .agents/skills/hk-slop-audit in your project. Codex loads it when a task matches its description.

Can I use Hk Slop Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add deepklarity/harness-kit --skill hk-slop-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hk-slop-audit, .gemini/skills/hk-slop-audit, .github/skills/hk-slop-audit and .opencode/skills/hk-slop-audit in your project.

What does Hk Slop Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Hk Slop Audit is instructions for the agent only. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash, Read, Edit, Write, Task, Grep, Glob.

Does Hk Slop Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hk Slop Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Hk Slop Audit use?

Hk Slop Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hk Slop Audit use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hk Slop Audit?

Skills that share tags, products or a category with Hk Slop Audit: Finishing a Development Branch (obra/superpowers, 297k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars) and Finishing A Development Branch (farm-fe/farm, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hk Slop Audit?

deepklarity (a GitHub organization) maintains it in deepklarity/harness-kit, which has 100 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on July 15, 2026.

Source: deepklarity/harness-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.