Agent skill

Deep App Audit

by frappe in frappe/skills

Deep audit of a Frappe app for security, correctness, and customization defects.

No licenceAuto-check passedDevelopment

Install Deep App Audit

skills CLI
$ npx skills add frappe/skills --skill deep-app-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install frappe/skills deep-app-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/frappe/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deep-app-audit .claude/skills/deep-app-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deep-app-audit
GitHub stars
147
Token cost
~5.4k tokens
SKILL.md length
3,004 words
Files
232 (incl. scripts)
Skills in repo
8
Repo updated
First seen
Licence
None found

At a glance

Deep audit of a Frappe app for security, correctness, and customization defects.

  • Works in 6 steps: Read the arguments → Confirm the target → Prepare the run → …
  • Development work in your project
  • SKILL.md covers How a run works, 1. Read the arguments, 2. Confirm the target and 3. Prepare the run, plus 5 more sections
  • Calls jq, semgrep and git; reaches github.com

What it does

Deep App Audit is an agent skill from frappe/skills. Deep audit of a Frappe app for security, correctness, and customization defects. Runs every security scope and every quality rule in a separate agent, verifies each candidate in a fresh context, and compiles one report. User-invoked only - run /deep-app-audit [app path] [options].

Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 234 other files, including scripts (for example `agents.example.json`, `prompts/check.md` and `prompts/context.md`).

It sits in Development. The repository describes itself as: Agent skills for Frappe App development.

When your agent uses it

  • Development work in your project

Example prompts

  • “/deep-app-audit”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Read the arguments
  2. Confirm the target
  3. Prepare the run
  4. Start the test site
  5. Run the tasks
  6. Tell the user

What it can do on your machine

Read from SKILL.md and the folder at commit 0bef982. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • jq
    • semgrep
    • git
    • uv
    • python
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deep App Audit loads about 5.4k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 3,004 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 3,004 words (~5,434 tokens).

“This skill audits one Frappe app checkout on three tracks and writes one report:”

— opening of SKILL.md by frappe
name
deep-app-audit
disable-model-invocation
true

Read the full SKILL.md on GitHub

Files

SKILL.md and 231 other files (scripts) in skills/deep-app-audit of frappe/skills.

  • SKILL.md
  • agents.example.json
  • prompts/check.md
  • prompts/context.md
  • prompts/report.md
  • prompts/scan.md
  • prompts/verify.md
  • quality/A-customization/A01-no-monkey-patching.md
  • quality/A-customization/A02-override-class-calls-super.md
  • quality/A-customization/A03-extend-instead-of-override.md
  • quality/A-customization/A04-regional-override-first.md
  • quality/A-customization/A05-override-whitelisted-method-contract.md
  • quality/A-customization/A06-hook-the-transaction-not-the-ledger.md
  • quality/A-customization/A07-reuse-the-existing-doctype.md
  • quality/A-customization/A08-custom-fields-in-code.md
  • quality/A-customization/A09-fixtures-overwrite-the-site.md
  • quality/A-customization/A10-remove-customizations-on-uninstall.md
  • quality/A-customization/A11-declare-required-apps.md
  • … and 214 more

Open the folder on GitHubat commit 0bef982

Compare with similar skills

Deep App Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deep App Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deep App Audit this skillfrappe/skills147—~5.4kAutomated safety check: PassNone
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from frappe/skills

All 8 skills in this repo
  • Frappe App Dev

    frappe/skills

    Builds full-stack Frappe Framework applications end-to-end. An agent skill from frappe/skills.

    147 GitHub stars~943 tokensUpdated 9 days ago
    Auto-check passed
  • Turn a vulnerability report into a publication-ready GitHub Security Advisory.

    147 GitHub stars~1.3k tokensUpdated 9 days ago
    Auto-check passed
  • Fix Issue

    frappe/skills

    Fix a bug reported in a GitHub issue or a markdown file, without letting the report's noise and guesses into the main context.

    147 GitHub stars~987 tokensUpdated 9 days ago
    Auto-check passed
  • Frappe Code Review

    frappe/skills

    Review code for any Frappe application — a checklist distilled from years of engineering practice on correctness, security, performance, concurrency, readability, API design, and testing.

    147 GitHub stars~3.8k tokensUpdated 9 days ago
    Auto-check passed
  • Resolve merge conflicts in a Mergify backport pull request. An agent skill from frappe/skills.

    147 GitHub stars~1.1k tokensUpdated 9 days ago
    Auto-check passed
  • Technical Writing

    frappe/skills

    Write prose in "Simplified Technical English". An agent skill from frappe/skills.

    147 GitHub stars~1.1k tokensUpdated 9 days ago
    Auto-check passed

Categories

Questions about Deep App Audit

What does Deep App Audit do?

Deep audit of a Frappe app for security, correctness, and customization defects. Deep App Audit is an agent skill from frappe/skills. Deep audit of a Frappe app for security, correctness, and customization defects.

When should I use Deep App Audit?

Deep App Audit fits situations like: development work in your project.

How do I install Deep App Audit in Claude Code?

Run `npx skills add frappe/skills --skill deep-app-audit -a claude-code`. Or copy the skill folder (skills/deep-app-audit in frappe/skills) into .claude/skills/deep-app-audit in your project. Claude Code loads it when a task matches its description.

How do I install Deep App Audit in Codex?

Run `npx skills add frappe/skills --skill deep-app-audit -a codex`. Or copy the skill folder (skills/deep-app-audit in frappe/skills) into .agents/skills/deep-app-audit in your project. Codex loads it when a task matches its description.

Can I use Deep App Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add frappe/skills --skill deep-app-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deep-app-audit, .gemini/skills/deep-app-audit, .github/skills/deep-app-audit and .opencode/skills/deep-app-audit in your project.

What does Deep App Audit need to run?

Going by SKILL.md and its folder, Deep App Audit needs the command-line tools its instructions call (jq, semgrep, git, uv, python and curl). Our summary lists: Python 3.

Does Deep App Audit access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Deep App Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Deep App Audit use?

No licence was found for Deep App Audit or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Deep App Audit use?

About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Deep App Audit?

Skills that share tags, products or a category with Deep App Audit: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deep App Audit?

frappe (a GitHub organization) maintains it in frappe/skills, which has 147 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on September 30, 2026.

Source: frappe/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.