Agent skill

Audit Project

by devcodex-labs in devcodex-labs/devcodex

项目工程审查维度 PE-1~PE-12 — 代码质量/项目结构/依赖安全/资源泄漏专属审查层. An agent skill from devcodex-labs/devcodex.

AGPL-3.0Auto-check passed

Install Audit Project

skills CLI
$ npx skills add devcodex-labs/devcodex --skill audit-project -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install devcodex-labs/devcodex audit-project --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/audit-project .claude/skills/audit-project && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-project
GitHub stars
439
Token cost
~872 tokens
SKILL.md length
259 words
Files
2
Skills in repo
70
Repo updated
First seen
Licence
AGPL-3.0

At a glance

项目工程审查维度 PE-1~PE-12 — 代码质量/项目结构/依赖安全/资源泄漏专属审查层. An agent skill from devcodex-labs/devcodex.

  • SKILL.md covers 适用范围, 维度总览(PE-1~PE-12), 核心检查维度 and N/A 规则
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Project is an agent skill from devcodex-labs/devcodex. 项目工程审查维度 PE-1~PE-12 — 代码质量/项目结构/依赖安全/资源泄漏专属审查层

Its SKILL.md is about 870 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `intent.json`).

The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.

Example prompts

  • “/audit-project”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Project loads about 872 tokens when it runs. Until then it costs about 15 tokens; SKILL.md has 259 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~15
When it runs · the whole SKILL.md, loaded when a task matches
~872

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 259 words, ~872 tokens.

Download SKILL.mdSave it as .claude/skills/audit-project/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
audit-project
description
项目工程审查维度 PE-1~PE-12 — 代码质量/项目结构/依赖安全/资源泄漏专属审查层

Audit Project Skill

适用范围

审查目标为项目工程(源码质量、目录结构、依赖健康、测试覆盖)时,叠加本 Skill(在 G1~G5 之后)。

维度总览(PE-1~PE-12)

分组维度优先级
A — 结构与可维护性PE-1 项目结构合理性 · PE-5 可维护性🔴/🟡
B — 健壮性PE-2 错误处理完整性 · PE-3 安全性 · PE-4 性能隐患 · PE-12 资源生命周期与泄漏风险🔴/🟡
C — 接口与配置PE-8 接口一致性 · PE-10 配置管理🔴/🟡
D — 质量保障PE-6 测试覆盖 · PE-7 依赖健康度🟡/💡
E — 可观测性与数据PE-9 日志与可观测性 · PE-11 数据层质量🟡

核心检查维度

PE-0 Profile Freshness 衔接 🔴

  • 先执行 audit-common 的 Profile Freshness Check(PFresh)
  • 不只检查“项目是否符合 Profile”,还要反向检查 Profile 是否仍符合当前 package、目录结构、脚本清单、发布状态、宿主能力和当前任务现实
  • 若 Profile 过期,项目工程审查结论不得直接标注收敛;需先记录漂移或同步要求

PE-1 项目结构合理性 🔴

  • 目录结构与 profile 02-架构约束.md 一致
  • 模块/文件职责单一(不混合路由/业务/数据层)
  • 函数/方法长度 ≤50 行,嵌套深度 ≤4 层
  • 无循环依赖
  • 简单业务 service 不重复 route validate、model/schema、数据导入或框架已承担的校验、归一化、配置兜底和二次治理

PE-2 错误处理完整性 🔴

  • 异步操作有 catch 处理
  • 外部依赖调用有超时和重试策略
  • 错误信息不暴露内部细节

PE-3 安全性 🔴

  • 敏感信息、密钥、密码和硬编码处理符合用户 / 项目显式策略;未指定禁止时不把直写本身列为问题
  • 输入验证覆盖边界条件
  • SQL/NoSQL 查询无注入风险
  • 用户自有/明确授权的本地安全审查执行 security-threat-modeling 的 AuthorizedLocalSecurityAuditPresentationGate:核对 authorizationContext、defensiveObjective、用户可见最小证据、隔离探针、SafetyInterruptionCard 与恢复路线;禁止把“优化表达”写成绕过宿主安全控制

PE-4 性能隐患 🟡

  • 算法复杂度、查询次数、同步阻塞、重复序列化或大对象复制不会在目标数据规模下造成明显退化
  • 缓存、队列、批处理和并发限制有边界,避免把性能优化变成无界内存占用
  • 若性能风险来自资源生命周期或清理缺失,必须同时按 PE-12 判定

PE-6 测试覆盖与验证门禁 🟡

  • 从 ../spec-governance/gate-registry.json 选择与变更事实匹配的 gateGroup,核对 Owner Skill 的必需证据和 test-router 生成的路线;本维度不复制 coverage、runtime/plugin、fingerprint、风险簇或派生消费者的完整门禁正文
  • 审查必须区分“测试断言通过”“覆盖率/跨边界路线通过”“跳过但有权威替代证据”;不满足时按实际状态降级

PE-7 依赖健康度 🟡

  • Node.js 项目默认 engines.node、CI matrix、Profile 与 README 不低于 >=18;低于 v18 有业务理由、风险和验证证据
  • 依赖升级 / 兼容修复已区分 业务源码平滑性 与 依赖层落地条件
  • 根因位于内部共享库、中间件、SDK 或 adapter 抽象层时,已评估“修共享库 + 消费项目升级”是否优于单项目补丁

PE-8 接口一致性 🔴

  • provider / connector / SDK 接入具备 provider metadata、内部 payload、上游 request 映射、标准化 result、错误 detail 字段级合同
  • JavaScript / Node.js 中命中必要注释的导出函数、核心业务函数、类、复杂对象契约、参数/返回/异常说明使用标准 JSDoc

PE-12 资源生命周期与泄漏风险 🔴

  • 必查内存泄露 / 资源泄漏风险:长生命周期集合、缓存、队列、订阅表、全局单例或闭包引用不得无界增长
  • 连接、事务、文件句柄、流、游标、socket、worker、定时器、interval、事件监听器和外部 SDK client 必须有明确释放、取消订阅或关闭路径
  • 前端 / UI 代码必须在组件卸载、路由切换、effect 重新执行或异步任务取消时清理监听器、定时器、订阅、AbortController 和外部引用
  • 异常分支、早返回、重试失败、超时、取消和测试 teardown 场景必须同样释放资源;不能只检查 happy path
  • 若项目语言或框架提供专用工具(heap snapshot、profiler、leak detector、lint rule、test teardown hook 等),审查报告应说明是否执行或标注 N/A + skipReason
  • 高风险资源泄漏修复、公开库/adapter/SDK、连接池、监听器、定时器、worker、cache 或公开方法生命周期风险命中时,应检查 MethodLevelLeakPressureProbe 是否有重复调用/生命周期压测证据;低风险纯函数可写 N/A + skipReason

条件 Owner 审查索引

  • 涉及前端/UI、发布、数据、安全、文档、外部消费者、性能、资源生命周期或治理控制面时,读取 ../spec-governance/gate-registry.json,按 gateGroup 触发对应 Owner Skill
  • 本 Skill 只核对项目工程事实、Owner 是否正确触发、证据是否存在、TestRoute 是否充分以及报告结果是否与证据一致;专属字段和执行语义归 Owner
  • 未命中的分组写 N/A + skipReason;命中却缺少 Owner 证据时不得用通用审查表述代替

N/A 规则

  • 纯前端项目无 DB:PE-11 标 N/A
  • 纯库项目无日志需求:PE-9 标 N/A
  • 无长生命周期资源、订阅、连接、定时器、缓存或 UI 生命周期的纯静态内容变更:PE-12 可标 N/A + skipReason
  • 无用户可见 UI、交互流或视觉呈现的后端 / CLI / 文档变更:FrontendExperienceQualityGate 可标 N/A + skipReason
  • 未触发跨项目已吸纳守门时,CrossProjectLearnedGuards 可标 N/A + skipReason
  • 未涉及代码/文档/示例/fixture/quick start/技术方案/报告产物,且用户未指出“不专业 / 像初级 / 示例误导”时,ExpertOutputQualityGate 可标 N/A + skipReason
  • 未触发审查发现 intake 时,ReviewFindingIntakeGate 可标 N/A + skipReason
  • 未触发资源生命周期或公开方法泄漏风险时,MethodLevelLeakPressureProbe 可标 N/A + skipReason

© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in content/skills/audit-project of devcodex-labs/devcodex.

  • SKILL.md
  • intent.json

Open the folder on GitHubat commit 1dd4525

Compare with similar skills

Audit Project next to the 2 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Project compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Project this skilldevcodex-labs/devcodex439—~872Automated safety check: PassAGPL-3.0
Maafwkqcoxn/MaaPipelineEditor408—~1.1kAutomated safety check: PassMIT
Code Review ExpertProgrammerAnthony/Expert-Coding-Harness235—~806Automated safety check: PassMIT

Similar skills

  • Maafw

    kqcoxn/MaaPipelineEditor

    MaaFramework 开发与集成指南。当任务涉及 MaaFramework 项目结构、Pipeline 协议、ProjectInterface V2 协议、自定义识别/动作(Custom/Agent)、Python/NodeJS/CSharp 等语言 Binding 集成、控制器配置、回调协议或运行时行为时使用。

    408 GitHub stars~1.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Code Review Expert

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查。

    235 GitHub stars~806 tokensUpdated 4 mo ago
    DevelopmentAuto-check passed

More from devcodex-labs/devcodex

All 70 skills in this repo
  • Accessibility I18n

    devcodex-labs/devcodex

    无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。

    439 GitHub stars~718 tokensUpdated 21 days ago
    Auto-check passed
  • AI Agent System Architecture

    devcodex-labs/devcodex

    AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。

    439 GitHub stars~2.4k tokensUpdated 21 days ago
    Auto-check passed
  • API Contract Architecture

    devcodex-labs/devcodex

    API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。

    439 GitHub stars~865 tokensUpdated 21 days ago
    Auto-check passed
  • Architecture Design

    devcodex-labs/devcodex

    架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。

    439 GitHub stars~1.1k tokensUpdated 21 days ago
    Auto-check passed
  • Audit Common

    devcodex-labs/devcodex

    审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层

    439 GitHub stars~4.1k tokensUpdated 21 days ago
    Auto-check passed
  • Audit Session

    devcodex-labs/devcodex

    审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复

    439 GitHub stars~1.8k tokensUpdated 21 days ago
    Auto-check passed

Questions about Audit Project

What does Audit Project do?

项目工程审查维度 PE-1~PE-12 — 代码质量/项目结构/依赖安全/资源泄漏专属审查层. An agent skill from devcodex-labs/devcodex. Audit Project is an agent skill from devcodex-labs/devcodex.

How do I install Audit Project in Claude Code?

Run `npx skills add devcodex-labs/devcodex --skill audit-project -a claude-code`. Or copy the skill folder (content/skills/audit-project in devcodex-labs/devcodex) into .claude/skills/audit-project in your project. Claude Code loads it when a task matches its description.

How do I install Audit Project in Codex?

Run `npx skills add devcodex-labs/devcodex --skill audit-project -a codex`. Or copy the skill folder (content/skills/audit-project in devcodex-labs/devcodex) into .agents/skills/audit-project in your project. Codex loads it when a task matches its description.

Can I use Audit Project in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill audit-project -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-project, .gemini/skills/audit-project, .github/skills/audit-project and .opencode/skills/audit-project in your project.

What does Audit Project need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Project is instructions for the agent only. Our summary lists: Node.js.

Does Audit Project access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Project safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Project use?

Audit Project is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Project use?

About 872 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Project?

Skills that share tags, products or a category with Audit Project: Maafw (kqcoxn/MaaPipelineEditor, 408 stars) and Code Review Expert (ProgrammerAnthony/Expert-Coding-Harness, 235 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Project?

devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.

Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.