Agent skill

Auditor Quiz

by forefy in forefy/.context

Quiz an auditor on a codebase's mechanics and vulnerabilities, drawn from its own code and docs.

MITAuto-check passedEducation

Install Auditor Quiz

skills CLI
$ npx skills add forefy/.context --skill auditor-quiz -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forefy/.context auditor-quiz --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunter-utils/auditor-quiz .claude/skills/auditor-quiz && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auditor-quiz
GitHub stars
152
Token cost
~1k tokens
SKILL.md length
464 words
Files
2 (incl. references)
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

Quiz an auditor on a codebase's mechanics and vulnerabilities, drawn from its own code and docs.

  • Works in 5 steps: Identify documentation sources → Analyze documentation → Generate quiz questions → …
  • Test understanding before
  • SKILL.md covers Overview, Workflow, Question Generation Guidelines and Resources, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Auditor Quiz is an agent skill from forefy/.context. Quiz an auditor on a codebase's mechanics and vulnerabilities, drawn from its own code and docs. Use to test understanding before or during a review.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/question-types.md`).

It sits in Education, covering Quizzes and assessments. The repository describes itself as: AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research. The licence is MIT.

When your agent uses it

  • Test understanding before
  • During a review

Example prompts

  • “/auditor-quiz”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Identify documentation sources
  2. Analyze documentation
  3. Generate quiz questions
  4. Run the quiz conversationally
  5. Important: Conversational Mode

What it can do on your machine

Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auditor Quiz loads about 1k tokens when it runs, and up to ~1.8k if it reads all its reference files. Until then it costs about 41 tokens; SKILL.md has 464 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 464 words, ~1,032 tokens.

Download SKILL.mdSave it as .claude/skills/auditor-quiz/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
auditor-quiz
description
Quiz an auditor on a codebase's mechanics and vulnerabilities, drawn from its own code and docs. Use to test understanding before or during a review.

Auditor Quiz Skill

Generate focused, security-oriented quizzes to test auditor understanding of codebases, protocols, and documentation.

Overview

This skill creates 8-10 question quizzes that focus on:

  • Protocol/system understanding and core mechanisms
  • Weakness points and potential vulnerabilities
  • Security considerations and attack vectors
  • Core functionality and critical code paths

Questions are generated from repository documentation (README, docs/, whitepapers, specifications, inline comments) and presented interactively with immediate feedback.

Workflow

  1. Identify documentation sources

    • Search for documentation files: *.md, README*, docs/*, *.sol (comments), *.rs (comments), etc.
    • Prioritize: security docs, architecture docs, README, specification files
    • Use grep/glob to find relevant files efficiently
  2. Analyze documentation

    • Read and synthesize key information about:
      • Core protocol/system mechanics
      • Security assumptions and trust boundaries
      • Known edge cases or limitations
      • Critical functions and state transitions
      • Potential attack vectors or vulnerability areas
  3. Generate quiz questions

    • Create 8-10 questions (mix of multiple choice, true/false)
    • Follow guidelines in references/question-types.md
    • Focus on security-critical aspects and deep understanding
    • Balance difficulty: 2-3 easy, 4-5 medium, 2-3 hard questions
    • Include specific references (line numbers, function names)
    • Store questions in memory (not in files)
  4. Run the quiz conversationally

    • Present questions ONE AT A TIME in the conversation
    • Format clearly with question number, text, and answer options
    • WAIT for the user's answer in their next message
    • After receiving answer, provide immediate feedback:
      • ✅ CORRECT or ❌ INCORRECT
      • Show correct answer if wrong
      • Provide detailed explanation
      • Show current score (e.g., "Score: 3/5")
    • Continue to next question only after user responds
    • Track score throughout
    • Display final results at the end with percentage and feedback
  5. Important: Conversational Mode

    • Do NOT use terminal scripts, bash sessions, or file-based quiz systems
    • Present each question directly in your response
    • Use the ask_user tool if helpful for getting answers
    • Keep the interaction natural and conversational
Show full SKILL.md (175 more words)Show less

Question Generation Guidelines

Focus Areas

Protocol Understanding (2-3 questions):

  • How core mechanisms work
  • State transitions and workflows
  • Design rationale

Weakness Points (2-3 questions):

  • Known edge cases
  • Potential attack vectors
  • Boundary conditions

Security Considerations (2-3 questions):

  • Access controls
  • Trust assumptions
  • Input validation
  • Privilege boundaries

Core Functionality (1-2 questions):

  • Main entry points
  • Critical algorithms
  • Key data structures
Quality Standards
  • Specific: Reference actual code (function names, line numbers)
  • Relevant: Focus on audit-critical aspects
  • Clear: Avoid ambiguity in questions and answers
  • Educational: Explanations should teach, not just confirm
  • Deep: Test understanding over memorization

Consult references/question-types.md for detailed examples and patterns.

Resources

  • references/question-types.md - Question format guidelines, examples, and best practices

Tips

  • When documentation is extensive (>10 files), prioritize security-relevant docs first
  • Include code references in explanations (e.g., "line 142", "deposit() function")
  • Present questions one at a time, waiting for user response between each
  • Keep conversational flow natural - don't use scripts or terminal sessions
  • Track score internally and display after each question
  • Don't make the correct question obvious by it being always the longer answer, or always the same choice field

© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/hunter-utils/auditor-quiz of forefy/.context.

  • SKILL.md
  • references/question-types.md

Open the folder on GitHubat commit c8ff161

Compare with similar skills

Auditor Quiz next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auditor Quiz compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auditor Quiz this skillforefy/.context152—~1kAutomated safety check: PassMIT
DeepTutor CLIHKUDS/DeepTutor41k—~2.8kAutomated safety check: PassApache-2.0
AI Engineering Placement Quizrohitg00/ai-engineering-from-scratch66k—~2kAutomated safety check: PassMIT
Codebase to Coursezarazhangrui/codebase-to-course5.7k—~4.4kAutomated safety check: PassNone
AI Engineering Phase Quizrohitg00/ai-engineering-from-scratch66k—~2.1kAutomated safety check: PassMIT
Scholar EvaluationK-Dense-AI/claude-scientific-writer2.4k2 repos~2.9kAutomated safety check: NotesMIT

Similar skills

  • DeepTutor CLI

    HKUDS/DeepTutor

    Teaches the agent to set up and run DeepTutor from the command line: chat and capabilities, knowledge bases, partners, memory, sessions, notebooks and the server or Web app.

    41k GitHub stars~2.8k tokensUpdated 2 days ago
    EducationAuto-check passed
  • AI Engineering Placement Quiz

    rohitg00/ai-engineering-from-scratch

    Runs a 10-question quiz across five areas to place a learner in the AI Engineering from Scratch curriculum, so they skip what they already know.

    66k GitHub stars~2k tokensUpdated today
    EducationAuto-check passed
  • Codebase to Course

    zarazhangrui/codebase-to-course

    Turns a codebase into an interactive single-page HTML course for non-technical learners, with scroll modules, animated diagrams, quizzes and plain-English code translations.

    5.7k GitHub stars~4.4k tokensUpdated 6 mo ago
    EducationAuto-check passed
  • AI Engineering Phase Quiz

    rohitg00/ai-engineering-from-scratch

    Quizzes you on a completed phase of the AI Engineering from Scratch course, taking a phase number or name and mapping it to that phase's directory.

    66k GitHub stars~2.1k tokensUpdated today
    EducationAuto-check passed
  • Scholar Evaluation

    K-Dense-AI/claude-scientific-writer

    Provide qualitative-first, evidence-traceable developmental review of scholarly works and audit low-stakes research-assessment rubrics with optional local quality controls.

    2.4k GitHub starsUsed in 2 repos~2.9k tokens
    EducationAuto-check: notes
  • Evaluation

    guanyang/open-agent-hub

    This skill should be used when building agent evaluation systems: deterministic checks, regression suites, multi-dimensional rubrics, quality gates, production monitoring, baseline comparison, and…

    977 GitHub starsUsed in 2 repos~4.2k tokens
    EducationAuto-check passed

More from forefy/.context

All 20 skills in this repo
  • Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.

    152 GitHub stars~951 tokensUpdated 5 days ago
    Auto-check passed
  • Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.

    152 GitHub stars~1.4k tokensUpdated 5 days ago
    Auto-check passed
  • Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.

    152 GitHub stars~1.5k tokensUpdated 5 days ago
    Auto-check passed
  • Audit Scope

    forefy/.context

    Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.

    152 GitHub stars~2.3k tokensUpdated 5 days ago
    Auto-check passed
  • External Enumeration

    forefy/.context

    Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

    152 GitHub stars~3.1k tokensUpdated 5 days ago
    Auto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    Auto-check passed

Categories

Questions about Auditor Quiz

What does Auditor Quiz do?

Quiz an auditor on a codebase's mechanics and vulnerabilities, drawn from its own code and docs. context. Quiz an auditor on a codebase's mechanics and vulnerabilities, drawn from its own code and docs.

When should I use Auditor Quiz?

Auditor Quiz fits situations like: test understanding before; during a review.

How do I install Auditor Quiz in Claude Code?

Run `npx skills add forefy/.context --skill auditor-quiz -a claude-code`. Or copy the skill folder (skills/hunter-utils/auditor-quiz in forefy/.context) into .claude/skills/auditor-quiz in your project. Claude Code loads it when a task matches its description.

How do I install Auditor Quiz in Codex?

Run `npx skills add forefy/.context --skill auditor-quiz -a codex`. Or copy the skill folder (skills/hunter-utils/auditor-quiz in forefy/.context) into .agents/skills/auditor-quiz in your project. Codex loads it when a task matches its description.

Can I use Auditor Quiz in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill auditor-quiz -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditor-quiz, .gemini/skills/auditor-quiz, .github/skills/auditor-quiz and .opencode/skills/auditor-quiz in your project.

What does Auditor Quiz need to run?

SKILL.md names no scripts, command-line tools or credentials: Auditor Quiz is instructions for the agent only.

Does Auditor Quiz access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Auditor Quiz safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auditor Quiz use?

Auditor Quiz is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auditor Quiz use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 798 tokens, read only when the agent opens those files.

What are the alternatives to Auditor Quiz?

Skills that share tags, products or a category with Auditor Quiz: DeepTutor CLI (HKUDS/DeepTutor, 41k stars), AI Engineering Placement Quiz (rohitg00/ai-engineering-from-scratch, 66k stars), Codebase to Course (zarazhangrui/codebase-to-course, 5.7k stars) and AI Engineering Phase Quiz (rohitg00/ai-engineering-from-scratch, 66k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auditor Quiz?

forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.

Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.