Agent skill

Code Audit

by EpicenterHQ in EpicenterHQ/epicenter

Find recurring Epicenter code smells and scope the cleanup they require.

Custom licenceAuto-check passedDevelopment

Install Code Audit

skills CLI
$ npx skills add EpicenterHQ/epicenter --skill code-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EpicenterHQ/epicenter code-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EpicenterHQ/epicenter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-audit .claude/skills/code-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-audit
GitHub stars
4.8k
Token cost
~3.3k tokens
SKILL.md length
1,673 words
Files
1
Skills in repo
65
Repo updated
First seen
Licence
Custom licence

At a glance

Find recurring Epicenter code smells and scope the cleanup they require.

  • Works in 7 steps: Duck-Typing at System Boundaries → Promise-Shape Ceremony (.then(() => {})) → Unstructured Logging in Library Code → …
  • Periodic audits
  • SKILL.md covers 1. Duck-Typing at System…, 2. Promise-Shape Ceremony…, 3. Unstructured Logging in… and 4. Exhaustive never Checks as…, plus 5 more sections
  • Calls rg

What it does

Code Audit is an agent skill from EpicenterHQ/epicenter. Find recurring Epicenter code smells and scope the cleanup they require. Use for periodic audits, cleanup PRs, post-refactor reviews, or reviews of a primitive’s consumers.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Refactoring. The repository describes itself as: Open-source, local-first apps.

When your agent uses it

  • Periodic audits
  • Post-refactor reviews
  • Reviews of a primitives consumers

Example prompts

  • “/code-audit”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Duck-Typing at System Boundaries
  2. Promise-Shape Ceremony (.then(() => {}))
  3. Unstructured Logging in Library Code
  4. Exhaustive never Checks as Union-Churn Signals
  5. Single-Method Pick Dependencies
  6. Copied TypeScript Boundary Shapes
  7. Non-Exhaustive Union Folds (if/else Where a switch Belongs)

What it can do on your machine

Read from SKILL.md and the folder at commit 9cc65c3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Audit loads about 3.3k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 1,673 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,673 words (~3,333 tokens).

“Recurring smell categories worth hunting periodically. Each category has a grep pattern, a real example from the repo (if one exists), and a "why it matters" so you know whether a hit is a real smell or expected.”

— opening of SKILL.md by EpicenterHQ, Custom licence
name
code-audit
metadata.author
epicenter
metadata.version
1.0

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/code-audit of EpicenterHQ/epicenter.

Open the folder on GitHubat commit 9cc65c3

Compare with similar skills

Code Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Audit this skillEpicenterHQ/epicenter4.8k—~3.3kAutomated safety check: PassCustom licence
Guidelinesakash-network/node1.1k22 repos~577Automated safety check: PassMIT
Component Refactoringlangflow-ai/langflow156k—~3.5kAutomated safety check: PassMIT
Migrate Core Code to Submodulestinyhumansai/openhuman42k—~2.6kAutomated safety check: PassGPL-3.0
Systematic Code Refactoringluongnv89/claude-howto42k—~3kAutomated safety check: PassMIT
Codexskills-directory/skill-codex1.5k3 repos~1.8kAutomated safety check: PassMIT

Similar skills

  • Guidelines

    akash-network/node

    Behavioral guidelines to reduce common LLM coding mistakes. An agent skill from akash-network/node.

    1.1k GitHub starsUsed in 22 repos~577 tokens
    DevelopmentAuto-check passed
  • Component Refactoring

    langflow-ai/langflow

    Refactor high-complexity React components in Langflow frontend.

    156k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Migrate Core Code to Submodules

    tinyhumansai/openhuman

    Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.

    42k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Systematic Code Refactoring

    luongnv89/claude-howto

    Guides refactoring in phases based on Martin Fowler's method: research, test coverage check, planning and small tested steps, with your approval at each phase.

    42k GitHub stars~3k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Codex

    skills-directory/skill-codex

    A skill your agent uses when the user asks to run Codex CLI (codex exec, codex resume) or references OpenAI Codex for code analysis, refactoring, or automated editing

    1.5k GitHub starsUsed in 3 repos~1.8k tokens
    DevelopmentAuto-check passed
  • Ponytail

    DavidObando/gsharp

    Forces the laziest solution that actually works, simplest, shortest, most minimal.

    565 GitHub starsUsed in 8 repos~1.7k tokens
    DevelopmentAuto-check passed

More from EpicenterHQ/epicenter

All 65 skills in this repo
  • Agent Instructions

    EpicenterHQ/epicenter

    Write and maintain repository guidance across AGENTS.md, CLAUDE.md, and .agents/skills.

    4.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Consult Claude

    EpicenterHQ/epicenter

    Assign Claude Code a read-only investigation, recommendation, or finished text draft.

    4.8k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated today
    Auto-check passed
  • Cohesion Over Testability

    EpicenterHQ/epicenter

    Collapse test-shaped production boundaries while preserving behavior and coverage.

    4.8k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Collapse Pass

    EpicenterHQ/epicenter

    Remove indirection that does not earn its boundary across a diff or package.

    4.8k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Error Handling

    EpicenterHQ/epicenter

    Apply Wellcrafted Result patterns to fallible operations and preserve failures at boundaries.

    4.8k GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Categories

Questions about Code Audit

What does Code Audit do?

Find recurring Epicenter code smells and scope the cleanup they require. Code Audit is an agent skill from EpicenterHQ/epicenter. Find recurring Epicenter code smells and scope the cleanup they require.

When should I use Code Audit?

Code Audit fits situations like: periodic audits; post-refactor reviews; reviews of a primitives consumers.

How do I install Code Audit in Claude Code?

Run `npx skills add EpicenterHQ/epicenter --skill code-audit -a claude-code`. Or copy the skill folder (.agents/skills/code-audit in EpicenterHQ/epicenter) into .claude/skills/code-audit in your project. Claude Code loads it when a task matches its description.

How do I install Code Audit in Codex?

Run `npx skills add EpicenterHQ/epicenter --skill code-audit -a codex`. Or copy the skill folder (.agents/skills/code-audit in EpicenterHQ/epicenter) into .agents/skills/code-audit in your project. Codex loads it when a task matches its description.

Can I use Code Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EpicenterHQ/epicenter --skill code-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-audit, .gemini/skills/code-audit, .github/skills/code-audit and .opencode/skills/code-audit in your project.

What does Code Audit need to run?

Going by SKILL.md and its folder, Code Audit needs the command-line tools its instructions call (rg).

Does Code Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Audit use?

Code Audit has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Code Audit use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Audit?

Skills that share tags, products or a category with Code Audit: Guidelines (akash-network/node, 1.1k stars), Component Refactoring (langflow-ai/langflow, 156k stars), Migrate Core Code to Submodules (tinyhumansai/openhuman, 42k stars) and Systematic Code Refactoring (luongnv89/claude-howto, 42k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Audit?

EpicenterHQ (a GitHub organization) maintains it in EpicenterHQ/epicenter, which has 4,819 GitHub stars. The repository holds 65 skills in this directory. The repository was last updated on October 8, 2026.

Source: EpicenterHQ/epicenter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.