Maafw
kqcoxn/MaaPipelineEditor
MaaFramework 开发与集成指南。当任务涉及 MaaFramework 项目结构、Pipeline 协议、ProjectInterface V2 协议、自定义识别/动作(Custom/Agent)、Python/NodeJS/CSharp 等语言 Binding 集成、控制器配置、回调协议或运行时行为时使用。
项目工程审查维度 PE-1~PE-12 — 代码质量/项目结构/依赖安全/资源泄漏专属审查层. An agent skill from devcodex-labs/devcodex.
$ npx skills add devcodex-labs/devcodex --skill audit-project -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install devcodex-labs/devcodex audit-project --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/audit-project .claude/skills/audit-project && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-project" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-project into .claude/skills/audit-project/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-project", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-projectType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add devcodex-labs/devcodex --skill audit-project -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install devcodex-labs/devcodex audit-project --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .agents/skills && cp -r skills-src/content/skills/audit-project .agents/skills/audit-project && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-project" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-project into .agents/skills/audit-project/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-project", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add devcodex-labs/devcodex --skill audit-project -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install devcodex-labs/devcodex audit-project --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/content/skills/audit-project .cursor/skills/audit-project && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-project" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-project into .cursor/skills/audit-project/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-project", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/devcodex-labs/devcodex.git --path content/skills/audit-project--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add devcodex-labs/devcodex --skill audit-project -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install devcodex-labs/devcodex audit-project --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/content/skills/audit-project .gemini/skills/audit-project && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-project" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-project into .gemini/skills/audit-project/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-project", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install devcodex-labs/devcodex audit-projectInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add devcodex-labs/devcodex --skill audit-project -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .github/skills && cp -r skills-src/content/skills/audit-project .github/skills/audit-project && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-project" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-project into .github/skills/audit-project/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-project", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add devcodex-labs/devcodex --skill audit-project -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install devcodex-labs/devcodex audit-project --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/content/skills/audit-project .opencode/skills/audit-project && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-project" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-project into .opencode/skills/audit-project/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-project", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-project项目工程审查维度 PE-1~PE-12 — 代码质量/项目结构/依赖安全/资源泄漏专属审查层. An agent skill from devcodex-labs/devcodex.
Audit Project is an agent skill from devcodex-labs/devcodex. 项目工程审查维度 PE-1~PE-12 — 代码质量/项目结构/依赖安全/资源泄漏专属审查层
Its SKILL.md is about 870 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `intent.json`).
The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.
Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Audit Project loads about 872 tokens when it runs. Until then it costs about 15 tokens; SKILL.md has 259 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 259 words, ~872 tokens.
.claude/skills/audit-project/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.审查目标为项目工程(源码质量、目录结构、依赖健康、测试覆盖)时,叠加本 Skill(在 G1~G5 之后)。
| 分组 | 维度 | 优先级 |
|---|---|---|
| A — 结构与可维护性 | PE-1 项目结构合理性 · PE-5 可维护性 | 🔴/🟡 |
| B — 健壮性 | PE-2 错误处理完整性 · PE-3 安全性 · PE-4 性能隐患 · PE-12 资源生命周期与泄漏风险 | 🔴/🟡 |
| C — 接口与配置 | PE-8 接口一致性 · PE-10 配置管理 | 🔴/🟡 |
| D — 质量保障 | PE-6 测试覆盖 · PE-7 依赖健康度 | 🟡/💡 |
| E — 可观测性与数据 | PE-9 日志与可观测性 · PE-11 数据层质量 | 🟡 |
PE-0 Profile Freshness 衔接 🔴
audit-common 的 Profile Freshness Check(PFresh)PE-1 项目结构合理性 🔴
02-架构约束.md 一致PE-2 错误处理完整性 🔴
PE-3 安全性 🔴
security-threat-modeling 的 AuthorizedLocalSecurityAuditPresentationGate:核对 authorizationContext、defensiveObjective、用户可见最小证据、隔离探针、SafetyInterruptionCard 与恢复路线;禁止把“优化表达”写成绕过宿主安全控制PE-4 性能隐患 🟡
PE-12 判定PE-6 测试覆盖与验证门禁 🟡
../spec-governance/gate-registry.json 选择与变更事实匹配的 gateGroup,核对 Owner Skill 的必需证据和 test-router 生成的路线;本维度不复制 coverage、runtime/plugin、fingerprint、风险簇或派生消费者的完整门禁正文PE-7 依赖健康度 🟡
engines.node、CI matrix、Profile 与 README 不低于 >=18;低于 v18 有业务理由、风险和验证证据业务源码平滑性 与 依赖层落地条件PE-8 接口一致性 🔴
PE-12 资源生命周期与泄漏风险 🔴
N/A + skipReasonMethodLevelLeakPressureProbe 是否有重复调用/生命周期压测证据;低风险纯函数可写 N/A + skipReason条件 Owner 审查索引
../spec-governance/gate-registry.json,按 gateGroup 触发对应 Owner SkillN/A + skipReason;命中却缺少 Owner 证据时不得用通用审查表述代替N/A + skipReasonFrontendExperienceQualityGate 可标 N/A + skipReasonCrossProjectLearnedGuards 可标 N/A + skipReasonExpertOutputQualityGate 可标 N/A + skipReasonReviewFindingIntakeGate 可标 N/A + skipReasonMethodLevelLeakPressureProbe 可标 N/A + skipReason© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in content/skills/audit-project of devcodex-labs/devcodex.
Open the folder on GitHubat commit 1dd4525
Audit Project next to the 2 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Audit Project this skilldevcodex-labs/devcodex | 439 | — | ~872 | Automated safety check: Pass | AGPL-3.0 | |
| Maafwkqcoxn/MaaPipelineEditor | 408 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Code Review ExpertProgrammerAnthony/Expert-Coding-Harness | 235 | — | ~806 | Automated safety check: Pass | MIT |
kqcoxn/MaaPipelineEditor
MaaFramework 开发与集成指南。当任务涉及 MaaFramework 项目结构、Pipeline 协议、ProjectInterface V2 协议、自定义识别/动作(Custom/Agent)、Python/NodeJS/CSharp 等语言 Binding 集成、控制器配置、回调协议或运行时行为时使用。
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查。
devcodex-labs/devcodex
无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。
devcodex-labs/devcodex
AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。
devcodex-labs/devcodex
API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。
devcodex-labs/devcodex
架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。
devcodex-labs/devcodex
审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层
devcodex-labs/devcodex
审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复
项目工程审查维度 PE-1~PE-12 — 代码质量/项目结构/依赖安全/资源泄漏专属审查层. An agent skill from devcodex-labs/devcodex. Audit Project is an agent skill from devcodex-labs/devcodex.
Run `npx skills add devcodex-labs/devcodex --skill audit-project -a claude-code`. Or copy the skill folder (content/skills/audit-project in devcodex-labs/devcodex) into .claude/skills/audit-project in your project. Claude Code loads it when a task matches its description.
Run `npx skills add devcodex-labs/devcodex --skill audit-project -a codex`. Or copy the skill folder (content/skills/audit-project in devcodex-labs/devcodex) into .agents/skills/audit-project in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill audit-project -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-project, .gemini/skills/audit-project, .github/skills/audit-project and .opencode/skills/audit-project in your project.
SKILL.md names no scripts, command-line tools or credentials: Audit Project is instructions for the agent only. Our summary lists: Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Audit Project is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 872 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Audit Project: Maafw (kqcoxn/MaaPipelineEditor, 408 stars) and Code Review Expert (ProgrammerAnthony/Expert-Coding-Harness, 235 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.
Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.