Performs a deep review of the Claude Code plugin, skill, or sub-agent defined in the current project against official best practices.

MITAuto-check: notesAgent Workflows

Install Audit Plugin

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill audit-plugin -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace audit-plugin --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/productivity/claude-workflow-skills/skills/audit-plugin .claude/skills/audit-plugin && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-plugin
GitHub stars
2.8k
Token cost
~1.1k tokens
SKILL.md length
407 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Performs a deep review of the Claude Code plugin, skill, or sub-agent defined in the current project against official best practices.

  • Works in 7 steps: Pre-flight check → Identify what kind of addon this project… → Fetch current best-practice documentation → …
  • The user says audit this plugin
  • SKILL.md covers Step 0: Pre-flight check, Step 1: Identify what kind of…, Step 2: Fetch current… and Step 3: Evaluate against best…, plus 3 more sections
  • Calls gh and git; reaches code.claude.com

What it does

Audit Plugin is an agent skill from jeremylongshore/tons-of-skills-marketplace. Performs a deep review of the Claude Code plugin, skill, or sub-agent defined in the current project against official best practices. Documents findings as GitHub issues and writes a prioritised fix plan to the project CLAUDE.md. Use when the user says audit this plugin, review this skill, check this agent, or audit addon.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Subagents, Hooks and plugins and Agent instruction files. It works with GitHub. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • The user says audit this plugin
  • Review this skill
  • Check this agent

Example prompts

  • “Use the audit-plugin skill to perform a deep review of the Claude Code plugin, skill, or sub-agent defined in the current project against official…”
  • “/audit-plugin”

Requirements

  • Pre-approved tools (allowed-tools): Read, Glob, Grep, Bash, WebSearch, WebFetch

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Pre-flight check
  2. Identify what kind of addon this project defines
  3. Fetch current best-practice documentation
  4. Evaluate against best practices
  5. Generate GitHub issues
  6. Write prioritised fix plan to CLAUDE.md
  7. Report summary

What it can do on your machine

Read from SKILL.md and the folder at commit 80f86df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • Bash
    • WebSearch
    • WebFetch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • code.claude.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Plugin loads about 1.1k tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 407 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Glob, Grep, Bash, WebSearch, WebFetch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit 80f86df, republished under its MIT licence (© jeremylongshore). 407 words, ~1,146 tokens.

Download SKILL.mdSave it as .claude/skills/audit-plugin/SKILL.md (or your agent's skills folder).
name
audit-plugin
description
Performs a deep review of the Claude Code plugin, skill, or sub-agent defined in the current project against official best practices. Documents findings as GitHub issues and writes a prioritised fix plan to the project CLAUDE.md. Use when the user says audit this plugin, review this skill, check this agent, or audit addon.
allowed-tools
Read, Glob, Grep, Bash, WebSearch, WebFetch
disable-model-invocation
true

Audit Plugin

Project: !basename $(git rev-parse --show-toplevel 2>/dev/null) 2>/dev/null || basename $PWD Branch: !git branch --show-current 2>/dev/null || echo "unknown"

Reviews the Claude Code addon in the current project (plugin, skill, sub-agent, or a combination) against official Claude Code best practices. Generates actionable GitHub issues and a prioritised fix plan.

Step 0: Pre-flight check

bash
gh auth status 2>&1 || { echo "ERROR: gh is not authenticated. Run: gh auth login"; exit 1; }

Step 1: Identify what kind of addon this project defines

Scan for known Claude Code addon files:

bash
find . -not -path './.git/*' \( \
  -name 'plugin.json' -path '*/.claude-plugin/*' \
  -o -name 'SKILL.md' -path '*/skills/*' \
  -o -name '*.md' -path '*/agents/*' \
\) 2>/dev/null

Read each file found. Build a mental model of:

  • Plugin manifest (.claude-plugin/plugin.json) — name, version, declared agents/skills
  • Skills (skills/<name>/SKILL.md) — frontmatter fields, body structure, tool declarations
  • Agents (agents/<name>.md) — frontmatter fields, description examples, tool restrictions

Step 2: Fetch current best-practice documentation

Use WebFetch to retrieve up-to-date guidance from these known URLs:

  • Skills: https://code.claude.com/docs/en/skills
  • Sub-agents: https://code.claude.com/docs/en/agents
  • Plugins: https://code.claude.com/docs/en/plugins

If any URL returns an error, use WebSearch to find the current equivalent under code.claude.com. Summarise the key quality criteria from each source.

Step 3: Evaluate against best practices

For plugin.json, check:

  • Required fields present: name, version, description, author, license
  • minVersion set to a current compatible value
  • Keywords are relevant and searchable
  • description is concise and accurate

For each SKILL.md, check:

  • description is a single unbroken line under 1,536 characters (combined with when_to_use)
  • allowed-tools is set and follows least-privilege (only tools the skill actually needs)
  • Body is under 500 lines; large reference content moved to separate files
  • Shell injection blocks (!`command`) are used where live context would help
  • Step numbering is clear and actionable
  • Code blocks specify a language
  • Prose lines are ≤ 120 characters
  • No personalised language in formal content (no "you", "your" in instructions)
Show full SKILL.md (149 more words)Show less

For each agent .md, check:

  • description is a quoted single-line string with proper <example> blocks for auto-delegation
  • model, color, maxTurns, memory, tools and initialPrompt fields are present where appropriate
  • Agent body is clear, focused, and actionable
  • Description examples use current delegation language (no "Task tool" narration)
  • tools list follows least-privilege

Step 4: Generate GitHub issues

For each distinct finding, create a GitHub issue:

bash
gh issue create \
  --title "<type>: <brief description>" \
  --body "$(cat <<'EOF'
## Finding

<description of the problem>

## Expected

<what best practice requires>

## Current

<what the file actually has>

## Suggested fix

<concrete change to make>
EOF
)" \
  --label "enhancement"

Group closely related findings into a single issue where it makes sense. Use --label "bug" for broken or non-compliant fields, --label "enhancement" for improvements.

Note the issue numbers as you go.

Step 5: Write prioritised fix plan to CLAUDE.md

Append or update a section in the project CLAUDE.md under the heading ## Audit Findings — <today's date>:

markdown
## Audit Findings — YYYY-MM-DD

Issues generated from `/audit-plugin` review. Suggested fix order:

### Group 1 — Correctness (fix first)

- #N: <title>
- #N: <title>

### Group 2 — Best-Practice Compliance

- #N: <title>
- #N: <title>

### Group 3 — Quality Improvements

- #N: <title>
- #N: <title>

Order groups by: correctness blockers first, then compliance, then polish.

Step 6: Report summary

Output a brief summary:

  • Total issues created (with links)
  • Top-priority fix
  • Link to the CLAUDE.md section added

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/productivity/claude-workflow-skills/skills/audit-plugin of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit 80f86df

Compare with similar skills

Audit Plugin next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Plugin compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Plugin this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: NotesMIT
Claude Code Mastery Squadohmyjahh/xquads-squads277—~1.1kAutomated safety check: PassMIT
Legacy To AI Readynicepkg/ai-workflow285—~2.2kAutomated safety check: NotesMIT
Claude Code Agent Developmentanthropics/claude-plugins-official38k7 repos~2.8kAutomated safety check: PassApache-2.0
Task Observerrebelytics/one-skill-to-rule-them-all3.2k1 repos~12kAutomated safety check: PassCC-BY-4.0
Harness Agent Team Designerrevfactory/harness9.1k—~4.5kAutomated safety check: PassApache-2.0

Similar skills

  • Claude Code Mastery Squad

    ohmyjahh/xquads-squads

    Routes a request to one of eight specialist agents covering hooks, skills, subagents, MCP integration and context engineering for Claude Code.

    277 GitHub stars~1.1k tokensUpdated 10 days ago
    Agent WorkflowsAuto-check passed
  • Legacy To AI Ready

    nicepkg/ai-workflow

    Transform legacy codebases into AI-ready projects with Claude Code configurations.

    285 GitHub stars~2.2k tokensUpdated 8 mo ago
    Agent WorkflowsAuto-check: notes
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 7 repos~2.8k tokens
    Agent WorkflowsAuto-check passed
  • Task Observer

    rebelytics/one-skill-to-rule-them-all

    Monitors task execution for skill improvement opportunities.

    3.2k GitHub starsUsed in 1 repo~12k tokens
    Agent WorkflowsAuto-check passed
  • Harness Agent Team Designer

    revfactory/harness

    Designs a project-specific agent harness: defines specialist agents, writes the skills they follow, picks an execution mode and model for each, and keeps the setup maintained.

    9.1k GitHub stars~4.5k tokensUpdated 11 days ago
    Agent WorkflowsAuto-check passed
  • Claude Automation Recommender

    anthropics/claude-plugins-official

    Official

    Scans a codebase and suggests which Claude Code hooks, subagents, skills, plugins and MCP servers fit its stack, without changing any files.

    38k GitHub starsUsed in 3 repos~2.7k tokens
    Agent WorkflowsAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Audit Plugin

What does Audit Plugin do?

Performs a deep review of the Claude Code plugin, skill, or sub-agent defined in the current project against official best practices. Audit Plugin is an agent skill from jeremylongshore/tons-of-skills-marketplace. Performs a deep review of the Claude Code plugin, skill, or sub-agent defined in the current project against official best practices.

When should I use Audit Plugin?

Audit Plugin fits situations like: the user says audit this plugin; review this skill; check this agent.

How do I install Audit Plugin in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill audit-plugin -a claude-code`. Or copy the skill folder (plugins/productivity/claude-workflow-skills/skills/audit-plugin in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/audit-plugin in your project. Claude Code loads it when a task matches its description.

How do I install Audit Plugin in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill audit-plugin -a codex`. Or copy the skill folder (plugins/productivity/claude-workflow-skills/skills/audit-plugin in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/audit-plugin in your project. Codex loads it when a task matches its description.

Can I use Audit Plugin in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill audit-plugin -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-plugin, .gemini/skills/audit-plugin, .github/skills/audit-plugin and .opencode/skills/audit-plugin in your project.

What does Audit Plugin need to run?

Going by SKILL.md and its folder, Audit Plugin needs the command-line tools its instructions call (gh and git). Its frontmatter pre-approves these tools: Read, Glob, Grep, Bash, WebSearch, WebFetch.

Does Audit Plugin access the network?

SKILL.md names 1 domain. In commands or code: code.claude.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Audit Plugin safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Audit Plugin use?

Audit Plugin is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Plugin use?

About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Plugin?

Skills that share tags, products or a category with Audit Plugin: Claude Code Mastery Squad (ohmyjahh/xquads-squads, 277 stars), Legacy To AI Ready (nicepkg/ai-workflow, 285 stars), Claude Code Agent Development (anthropics/claude-plugins-official, 38k stars) and Task Observer (rebelytics/one-skill-to-rule-them-all, 3.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Plugin?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,825 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 9, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.