Agent skill

Production Bundle Audit

by keybase in keybase/client

Builds the desktop Vite and iOS or Android Metro production bundles and checks them for tree-shaking problems, such as mobile-only modules leaking into the desktop build.

BSD-3-ClauseAuto-check passedFrontend & Design

Install Production Bundle Audit

skills CLI
$ npx skills add keybase/client --skill prod-bundles -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install keybase/client prod-bundles --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/keybase/client.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skill/prod-bundles .claude/skills/prod-bundles && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
prod-bundles
GitHub stars
9.3k
Token cost
~620 tokens
SKILL.md length
137 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
BSD-3-Clause

At a glance

Builds the desktop Vite and iOS or Android Metro production bundles and checks them for tree-shaking problems, such as mobile-only modules leaking into the desktop build.

  • Building production bundles to look at their sizes
  • SKILL.md covers Build Commands, Tree-Shaking Audit and Key Facts
  • Calls yarn, python3 and bundle
  • Verifying that mobile-only code is absent from the desktop build

What it does

The skill lists the commands for building each platform's production bundle from the shared folder: yarn desktop:build:prod for the Vite desktop build, which writes to shared/desktop/dist, and yarn ios:jsbundle and yarn android:jsbundle for the Metro bundles, each producing a main.jsbundle. A shell filter separates production bundles from the dev and profile ones by their file-name suffixes.

The tree-shaking audit has two parts. For desktop, it loops over mobile-only packages such as expo-audio, expo-location and react-native-kb to confirm none appear in the production bundle. For iOS, a Python check confirms that the bare isMobile and isElectron globals were replaced with literals, expecting zero occurrences. Background notes explain that Vite's define block and a Babel plugin in the Metro setup inline those globals so dead branches get dropped, that native-only packages are aliased to a null module on desktop, and that Vite's dependency cache must be cleared after editing that list.

When your agent uses it

  • Building production bundles to look at their sizes
  • Verifying that mobile-only code is absent from the desktop build
  • Confirming platform flags were inlined in the iOS or Android bundle

Example prompts

  • “Build the production desktop bundle and check whether any mobile-only modules got included.”
  • “Run the iOS JS bundle build and confirm isMobile and isElectron are inlined as literals.”
  • “Compare the Android and desktop production bundle sizes after my latest change.”

Requirements

  • yarn, run from the shared folder
  • python3, for the iOS inlining check

What it can do on your machine

Read from SKILL.md and the folder at commit 349f5f4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • yarn
    • python3
    • bundle

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use yarn, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Production Bundle Audit loads about 620 tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 137 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~620

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from keybase/client at commit 349f5f4, republished under its BSD-3-Clause licence (© keybase). 137 words, ~620 tokens.

Download SKILL.mdSave it as .claude/skills/prod-bundles/SKILL.md (or your agent's skills folder).
name
prod-bundles
description
Use when the user asks to build production bundles, check bundle sizes, audit tree-shaking, or verify mobile/desktop code separation. Covers both the desktop Vite prod build and the iOS/Android Metro bundle.

Build production bundles for both platforms and analyze them for correct tree-shaking.

Build Commands

Desktop (Vite):

bash
# From shared/
yarn desktop:build:prod

Output lands in shared/desktop/dist/. Prod bundles have no .dev or .profile suffix — filter with:

bash
ls shared/desktop/dist/*.bundle.js | grep -v '\.dev\.' | grep -v '\.profile\.'

iOS (Metro):

bash
# From shared/
yarn ios:jsbundle

Output: shared/ios/dist/main.jsbundle

Android (Metro):

bash
# From shared/
yarn android:jsbundle

Output: shared/android/dist/main.jsbundle

Tree-Shaking Audit

Desktop — check mobile-only modules are absent:

bash
DIST=shared/desktop/dist
PROD=$(ls "$DIST"/*.bundle.js | grep -v '\.dev\.' | grep -v '\.profile\.')
for mod in expo-audio expo-location expo-video react-native-kb @gorhom/bottom-sheet lottie-react-native react-native-safe-area-context; do
  hits=$(echo "$PROD" | xargs grep -l "$mod" 2>/dev/null | wc -l | tr -d ' ')
  echo "$mod: $hits files"
done

iOS bundle — check bare isMobile/isElectron are inlined as literals (Babel plugin):

bash
# Should report 0 occurrences — bare globals replaced with true/false at transform time
python3 -c "
import re
bundle = open('shared/ios/dist/main.jsbundle').read()
for name in ['isMobile', 'isElectron', 'isAndroid', 'isIOS']:
    real = [m for m in re.finditer(r'(?<![.\w{,])' + name + r'(?![:\w])', bundle)]
    print(f'{name} not as property/key: {len(real)} occurrences')
"

Key Facts

  • Vite (desktop): the define block in shared/vite.config.mts (makeDefines) replaces bare globals (isMobile, isElectron, etc.) with literals, and the prod minifier drops the dead branches.
  • Metro (iOS/Android): The makePlatformPlugin Babel plugin in babel.config.js inlines the same globals at transform time, enabling Metro's constant-folding-plugin to DCE dead branches.
  • Native-only module aliasing (desktop): packages in shared/native-only-modules.js are aliased to shared/null-module.js by the resolve config in shared/vite.config.mts, and pre-bundled through optimizeDeps. After changing that file, clear Vite's dep cache: rm -rf shared/node_modules/.vite.

© keybase, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skill/prod-bundles of keybase/client.

Open the folder on GitHubat commit 349f5f4

Compare with similar skills

Production Bundle Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Production Bundle Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Production Bundle Audit this skillkeybase/client9.3k—~620Automated safety check: PassBSD-3-Clause
React Best Practicesryokun6/ryos1.3k—~2kAutomated safety check: PassMIT
Mobilerun Docs Referencedroidrun/mobilerun9.6k—~943Automated safety check: PassMIT
jscpd Code Migration Trackerkucherenko/jscpd6.4k—~5kAutomated safety check: PassMIT
Phoneagentrounak/PhoneAgent798—~2.2kAutomated safety check: PassMIT
AccessibilityGetStream/stream-chat-react-native1.2k—~6.5kAutomated safety check: PassCustom licence

Similar skills

  • React performance optimization guidelines from Vercel Engineering (vercel-labs/agent-skills).

    1.3k GitHub stars~2k tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Mobilerun Docs Reference

    droidrun/mobilerun

    Answers questions about Mobilerun, the LLM-agent framework for automating Android and iOS devices, by pointing the agent to the right page of its v5 documentation.

    9.6k GitHub stars~943 tokensUpdated 3 days ago
    MobileAuto-check passed
  • Measures a code port between languages or frameworks with jscpd's function-level comparison, porting tests before code and tracking what is left unmatched.

    6.4k GitHub stars~5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Phoneagent

    rounak/PhoneAgent

    Control a connected iPhone, iOS simulator, Android emulator, or Android device from macOS through PhoneAgent's JSON-RPC bridge.

    798 GitHub stars~2.2k tokensUpdated 1 mo ago
    MobileAuto-check passed
  • Accessibility

    GetStream/stream-chat-react-native

    Maintain VoiceOver/TalkBack-focused accessibility in stream-chat-react-native.

    1.2k GitHub stars~6.5k tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Ipaship Audit

    atharvnaik1/ipaship-audit

    A skill your agent uses when auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines or Google Play Developer Policies.

    108 GitHub stars~1.5k tokensUpdated 4 mo ago
    MobileAuto-check: notes

More from keybase/client

All 14 skills in this repo
  • Analyzes V8, Chrome and Electron .heapsnapshot files with Node scripts to find memory leaks, detached DOM nodes and the retainer paths that keep objects alive.

    9.3k GitHub stars~875 tokensUpdated yesterday
    Auto-check passed
  • Analyzes Chrome or Electron DevTools Performance trace exports with Python scripts to find where render time actually goes, without opening DevTools.

    9.3k GitHub stars~809 tokensUpdated yesterday
    Auto-check passed
  • Captures a clean Keybase service log and analyzes it for redundant, duplicated or looping RPCs, then checks whether a caching fix reduced the calls.

    9.3k GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Parses a React DevTools Profiler JSON export with Python scripts to find re-render storms, commit fan-out and why a component rendered, without opening the DevTools UI.

    9.3k GitHub stars~978 tokensUpdated yesterday
    Auto-check passed
  • Address PR Feedback

    keybase/client

    Fetches GitHub Copilot review feedback from inline threads and review bodies, checks each finding against the code and fixes the valid ones.

    9.3k GitHub stars~657 tokensUpdated yesterday
    Auto-check passed
  • Takes a screenshot of a running Electron desktop app through playwright-cli over remote debugging, shrinks it and shows it so you can check the UI visually.

    9.3k GitHub stars~476 tokensUpdated yesterday
    Auto-check passed

Questions about Production Bundle Audit

What does Production Bundle Audit do?

Builds the desktop Vite and iOS or Android Metro production bundles and checks them for tree-shaking problems, such as mobile-only modules leaking into the desktop build. jsbundle. A shell filter separates production bundles from the dev and profile ones by their file-name suffixes.

When should I use Production Bundle Audit?

Production Bundle Audit fits situations like: building production bundles to look at their sizes; verifying that mobile-only code is absent from the desktop build; confirming platform flags were inlined in the iOS or Android bundle.

How do I install Production Bundle Audit in Claude Code?

Run `npx skills add keybase/client --skill prod-bundles -a claude-code`. Or copy the skill folder (skill/prod-bundles in keybase/client) into .claude/skills/prod-bundles in your project. Claude Code loads it when a task matches its description.

How do I install Production Bundle Audit in Codex?

Run `npx skills add keybase/client --skill prod-bundles -a codex`. Or copy the skill folder (skill/prod-bundles in keybase/client) into .agents/skills/prod-bundles in your project. Codex loads it when a task matches its description.

Can I use Production Bundle Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add keybase/client --skill prod-bundles -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/prod-bundles, .gemini/skills/prod-bundles, .github/skills/prod-bundles and .opencode/skills/prod-bundles in your project.

What does Production Bundle Audit need to run?

Going by SKILL.md and its folder, Production Bundle Audit needs the command-line tools its instructions call (yarn, python3 and bundle). Our summary lists: yarn, run from the shared folder; python3, for the iOS inlining check.

Does Production Bundle Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Production Bundle Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Production Bundle Audit use?

Production Bundle Audit is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Production Bundle Audit use?

About 620 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Production Bundle Audit?

Skills that share tags, products or a category with Production Bundle Audit: React Best Practices (ryokun6/ryos, 1.3k stars), Mobilerun Docs Reference (droidrun/mobilerun, 9.6k stars), jscpd Code Migration Tracker (kucherenko/jscpd, 6.4k stars) and Phoneagent (rounak/PhoneAgent, 798 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Production Bundle Audit?

keybase (a GitHub organization) maintains it in keybase/client, which has 9,256 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 7, 2026.

Source: keybase/client on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.