Agent skill

Ponytail Audit

by DietrichGebert in DietrichGebert/ponytail

Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split.

MITAuto-check passedWriting & Content

Install Ponytail Audit

skills CLI
$ npx skills add DietrichGebert/ponytail --skill ponytail-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DietrichGebert/ponytail ponytail-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DietrichGebert/ponytail.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ponytail-audit .claude/skills/ponytail-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ponytail-audit
GitHub stars
160k
Token cost
~1.4k tokens
SKILL.md length
809 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split.

  • Works in 4 steps: Map first → Look for → Check before you report → …
  • Audit this codebase
  • SKILL.md covers 1. Map first, 2. Look for, 3. Check before you report and 4. Output
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ponytail Audit is an agent skill from DietrichGebert/ponytail. Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split. Ranked, each finding explained in plain English. One-shot report, changes nothing. Use for "audit this codebase", "review the whole repo", "find bloat", "what can I delete", /ponytail-audit.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Writing & Content, covering Plain language and style rules. The repository describes itself as: Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote. The licence is MIT.

When your agent uses it

  • Audit this codebase
  • Review the whole repo
  • What can I delete
  • /ponytail-audit

Example prompts

  • “audit this codebase”
  • “review the whole repo”
  • “find bloat”
  • “/ponytail-audit”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Map first
  2. Look for
  3. Check before you report
  4. Output

What it can do on your machine

Read from SKILL.md and the folder at commit 9b58c1f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ponytail Audit loads about 1.4k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 809 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from DietrichGebert/ponytail at commit 9b58c1f, republished under its MIT licence (© DietrichGebert). 809 words, ~1,355 tokens.

Download SKILL.mdSave it as .claude/skills/ponytail-audit/SKILL.md (or your agent's skills folder).
name
ponytail-audit
description
Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split. Ranked, each finding explained in plain English. One-shot report, changes nothing. Use for "audit this codebase", "review the whole repo", "find bloat", "what can I delete", /ponytail-audit.

Audit the whole repo like the senior developer who just inherited it and will be paged when it breaks. Order of importance: correct, safe, holds under load, tested, fast, lean. Lean still matters: every extra line must be read, tested and fixed later. This is a report the user asked for, so give it in full.

1. Map first

  • Audit what the user names: a folder, a package, or the whole repo. Nothing named: the whole repo.
  • Read the README, the deploy and build config, the dependency list, the entry points (main, routes, handlers, jobs, CLI commands) and the tests.
  • Find the expected load: one person running a script, or many users and processes at once. Judge scale against that, and say which load you assumed.
  • Trace the main flows end to end: where data comes in, what is stored, what goes out. Read those paths fully: input from users, money, auth, data writes, background jobs, anything shared between processes.
  • Big repo: go deep where a mistake costs the most, not file by file. Say which parts you did not read.

2. Look for

  1. Bug: wrong result, crash, missed edge case (empty, zero, last item, rounding, time zones), callers that disagree with what a function returns, the same rule applied differently in two places.
  2. Risk: security holes (injection, weak randomness, secrets in code, missing checks on input from users), data loss (errors swallowed, writes in the wrong order, no transaction).
  3. Scale: fine for one user, wrong for many: check-then-write races, the same work done by every process, memory or lists that only grow, a query per item, O(n^2) on big input, per-process state that must be shared.
  4. Missing test: risky logic (a branch, a parser, money, security, data writes) with no test that fails when it breaks. One good test, not coverage.
  5. Speed: big slowdowns are problems. Small wins (work repeated in a hot loop) are suggestions; some software counts every millisecond.
  6. Lean: code that should not exist or should be smaller.
    • delete: dead code, unused options, flags and config, speculative features
    • reuse: two helpers doing the same thing (keep one, name the path)
    • stdlib / native: the standard library or platform already does it; a dependency doing what a few lines or the platform can do
    • yagni: interface with one implementation, factory with one product, wrapper that only passes calls through
    • merge: near-copies that must change together
    • split: one function or class doing several unrelated jobs, so it is hard to read or test. Split by job, never by line count, and never into helpers that exist only to make a function shorter.
Show full SKILL.md (370 more words)Show less

3. Check before you report

  • Every finding needs a concrete case: "this input or situation leads to this wrong result". No case, no finding.
  • Before calling code unused, grep the whole tree for it, including tests, fixtures, config, and string or dynamic references.
  • A shortcut marked with a shortcut: (or older ponytail:) comment that names its limit is a decision, not a finding, unless the expected load already crosses it.
  • Propose the smallest fix that works. Prefer fixes that delete code. Never add layers, frameworks or config the problem does not need.
  • No style taste, no "consider", no vague worries.

4. Output

Very simple English: short sentences, everyday words. Explain a technical term the first time you use it. The reader may never have seen this code.

Start with What this repo does: in two or three sentences, and the load you assumed.

Then the findings in three groups, most important first, skip empty groups:

  • Must fix: bug, security, data loss, breaks at the expected load.
  • Should fix: risky code without a test, real slowness, duplication, a function that mixes jobs, code that should not exist.
  • Nice to have: small speed-ups, shorter forms.

Number findings across all groups, so the user can say "fix 2 and 5". At most 20 findings; if you left smaller ones out, say how many. Every finding has all four parts, each one or two short sentences:

  1. Orders land on the wrong day (billing/close_day.py:L40-52)
    • What this is: At midnight this job closes the day and bills all orders of that day.
    • Problem: It takes "today" from the server clock, which runs in UTC. An order placed at 00:30 in Berlin is billed on the day before.
    • Fix: Compute the day once in the shop's time zone: datetime.now(ZoneInfo("Europe/Berlin")).date(). One line, nothing else changes.
    • If we skip it: Late orders show the wrong date, and accounting fixes them by hand.

End with:

  • Verdict: one line: healthy, or what to fix first.
  • Lean: -<N> lines, -<M> dependencies possible. when lean findings exist.
  • Not checked: the parts you did not read or could not run.

Nothing found: What this repo does:, then Healthy. Nothing to fix. and one line on what you checked.

One-shot report, changes no code.

© DietrichGebert, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ponytail-audit of DietrichGebert/ponytail.

Open the folder on GitHubat commit 9b58c1f

Compare with similar skills

Ponytail Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ponytail Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ponytail Audit this skillDietrichGebert/ponytail160k—~1.4kAutomated safety check: PassMIT
Asd Ste100danyuchn/asd-ste100-skill4.3k—~4.1kAutomated safety check: PassMIT
Technical Writing Standardcursor/plugins11k10 repos~2.4kAutomated safety check: PassNone
Natural Japanese Business Writingcoji/natural-japanese1.9k—~2.1kAutomated safety check: PassMIT
PgjevrealZachi/pg-jev1.1k—~2.9kAutomated safety check: PassCustom licence
Defensive Writing Editorlennney/stop-that-shit2.5k1 repos~1.2kAutomated safety check: PassMIT

Similar skills

  • Asd Ste100

    danyuchn/asd-ste100-skill

    A skill your agent uses when English text must be parsed without a human to resolve ambiguity — tool descriptions, error messages, inter-agent instructions, system prompts, status reports — and…

    4.3k GitHub stars~4.1k tokensUpdated 6 days ago
    Writing & ContentAuto-check passed
  • Official

    Applies four layers of technical-writing rules to docs, RFCs, readmes, PR descriptions and commit messages so a tired engineer follows them on the first read.

    11k GitHub starsUsed in 10 repos~2.4k tokens
    Writing & ContentAuto-check passed
  • Writes and edits Japanese business documents so they read clearly and naturally, removes AI-sounding phrasing and can score how AI-like a text reads.

    1.9k GitHub stars~2.1k tokensUpdated 1 mo ago
    Writing & ContentAuto-check passed
  • Pgjev

    realZachi/pg-jev

    Install, configure, query and explain pgjev (the jev PostgreSQL extension that filters, ranks and classifies rows with plain-language conditions via TypeSafe's Jev model).

    1.1k GitHub stars~2.9k tokensUpdated 4 days ago
    Writing & ContentAuto-check passed
  • Defensive Writing Editor

    lennney/stop-that-shit

    Cuts defensive disclaimers, stacked hedging and self-protective narration from proposals and summaries, keeping only limits that affect the reader's decision.

    2.5k GitHub starsUsed in 1 repo~1.2k tokens
    Writing & ContentAuto-check passed
  • UX Writing

    content-designer/ux-writing-skill

    Applies UX writing practice to interface copy such as buttons, errors, forms and onboarding, using four quality standards and accessibility guidance.

    224 GitHub starsUsed in 1 repo~3.8k tokens
    Writing & ContentAuto-check passed

More from DietrichGebert/ponytail

  • Ponytail Gain Scoreboard

    DietrichGebert/ponytail

    Show ponytail's measured savings (code, cost, speed) from the benchmark. One-shot display. Use for /ponytail-gain, "what does ponytail save", "ponytail impact".

    160k GitHub stars~507 tokensUpdated today
    Auto-check passed
  • Ponytail Lazy Developer Mode

    DietrichGebert/ponytail

    Makes the agent pick the laziest solution that works: skip unneeded work, reuse what exists, prefer the standard library and platform features, and keep diffs small.

    160k GitHub starsUsed in 1 repo~873 tokens
    Auto-check passed
  • Ponytail Help Card

    DietrichGebert/ponytail

    Shows a one-shot quick-reference card for the ponytail skills: intensity levels, the six commands, and how to turn it off, set a default mode and update.

    160k GitHub stars~726 tokensUpdated today
    Auto-check passed
  • Ponytail Debt Ledger

    DietrichGebert/ponytail

    Collects every ponytail: comment in a codebase into one debt ledger, flags shortcuts with no upgrade trigger and reports without changing any files.

    160k GitHub stars~453 tokensUpdated today
    Auto-check passed
  • Over-Engineering Review

    DietrichGebert/ponytail

    Reviews a diff only for unnecessary complexity and lists what to delete or shrink, one numbered line per finding with the location, the cut and its replacement.

    160k GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Questions about Ponytail Audit

What does Ponytail Audit do?

Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split. Ponytail Audit is an agent skill from DietrichGebert/ponytail. Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split.

When should I use Ponytail Audit?

Ponytail Audit fits situations like: audit this codebase; review the whole repo; what can I delete; /ponytail-audit.

How do I install Ponytail Audit in Claude Code?

Run `npx skills add DietrichGebert/ponytail --skill ponytail-audit -a claude-code`. Or copy the skill folder (skills/ponytail-audit in DietrichGebert/ponytail) into .claude/skills/ponytail-audit in your project. Claude Code loads it when a task matches its description.

How do I install Ponytail Audit in Codex?

Run `npx skills add DietrichGebert/ponytail --skill ponytail-audit -a codex`. Or copy the skill folder (skills/ponytail-audit in DietrichGebert/ponytail) into .agents/skills/ponytail-audit in your project. Codex loads it when a task matches its description.

Can I use Ponytail Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DietrichGebert/ponytail --skill ponytail-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ponytail-audit, .gemini/skills/ponytail-audit, .github/skills/ponytail-audit and .opencode/skills/ponytail-audit in your project.

What does Ponytail Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Ponytail Audit is instructions for the agent only.

Does Ponytail Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ponytail Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ponytail Audit use?

Ponytail Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ponytail Audit use?

About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ponytail Audit?

Skills that share tags, products or a category with Ponytail Audit: Asd Ste100 (danyuchn/asd-ste100-skill, 4.3k stars), Technical Writing Standard (cursor/plugins, 11k stars), Natural Japanese Business Writing (coji/natural-japanese, 1.9k stars) and Pgjev (realZachi/pg-jev, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ponytail Audit?

DietrichGebert (a GitHub user) maintains it in DietrichGebert/ponytail, which has 159,864 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 10, 2026.

Source: DietrichGebert/ponytail on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.