Agent skill

Code Auditing

by LIDR-academy in LIDR-academy/AI4Devs-LTI-extended

“Task-focused project skill.”

— description from SKILL.md by LIDR-academy
MITAuto-check passedDevelopment

Install Code Auditing

skills CLI
$ npx skills add LIDR-academy/AI4Devs-LTI-extended --skill code-auditing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LIDR-academy/AI4Devs-LTI-extended code-auditing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LIDR-academy/AI4Devs-LTI-extended.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-specs/skills/code-auditing .claude/skills/code-auditing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-auditing
GitHub stars
278
Token cost
~1.1k tokens
SKILL.md length
497 words
Files
3 (incl. references)
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

  • Works in 7 steps: Pre-Analysis Setup → Discovery → File-by-File Analysis → …
  • SKILL.md covers When to Use, Audit Phases, Issue Priority Levels and Analysis Categories, plus 2 more sections
  • Calls npx

About this skill

Code Auditing is a skill in LIDR-academy/AI4Devs-LTI-extended (278 stars). Its SKILL.md is about 1.1k tokens, with 2 other files in the folder (references). Licence: MIT.

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Pre-Analysis Setup
  2. Discovery
  3. File-by-File Analysis
  4. Best Practices Verification
  5. Pattern Detection
  6. Library Recommendations
  7. Comprehensive Report

What it can do on your machine

Read from SKILL.md and the folder at commit 9ff9a80. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Auditing loads about 1.1k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 10 tokens; SKILL.md has 497 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~10
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LIDR-academy/AI4Devs-LTI-extended at commit 9ff9a80, republished under its MIT licence (© LIDR-academy). 497 words, ~1,091 tokens.

Download SKILL.mdSave it as .claude/skills/code-auditing/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
code-auditing
description
Task-focused project skill.
version
1.0.0

Code Auditing Skill

Comprehensive methodology for systematic code quality audits.

When to Use

  • Comprehensive code quality audits
  • Security vulnerability assessments
  • Technical debt identification
  • Pre-release code reviews
  • Best practices verification
  • Library and dependency audits

Audit Phases

Phase 0: Pre-Analysis Setup
  1. Check for project configuration files (package.json, tsconfig.json, etc.)
  2. Identify tech stack and main libraries
  3. Check for linting/formatting configs
  4. Run existing linting/testing commands as baseline
  5. Load documentation for identified core libraries
Phase 1: Discovery
  1. Find all code files by type
  2. Create tracking list for each file
  3. Group files by module/feature for contextual analysis
Phase 2: File-by-File Analysis

For each file, analyze for:

  • Dead code (unused functions, variables, imports)
  • Code smells and anti-patterns
  • Custom implementations that could use established libraries
  • Security vulnerabilities
  • Performance issues
  • Outdated patterns or deprecated APIs
  • Missing error handling
  • Overly complex functions
  • Duplicate code
Phase 3: Best Practices Verification

For every library and framework:

  1. Retrieve official documentation
  2. Compare implementation against official patterns
  3. Identify deviations from recommendations
  4. Note outdated usage patterns
  5. Flag discouraged anti-patterns
Phase 4: Pattern Detection

Look for recurring issues:

  • Common anti-patterns across files
  • Duplicated logic that could be abstracted
  • Inconsistent coding styles
  • Missing error handling patterns
Phase 5: Library Recommendations

For custom implementations:

  1. Check if current libraries provide the functionality
  2. Search for mature ecosystem packages
  3. Verify library health (commits, issues, activity)
  4. Check compatibility with project setup
Phase 6: Comprehensive Report

Generate detailed report with:

  • Executive summary
  • Critical issues requiring immediate attention
  • File-by-file findings
  • Prioritized action plan
  • Effort estimates
  • Library recommendations

Issue Priority Levels

  • Critical - Security vulnerabilities, broken functionality
  • High Priority - Performance bottlenecks, unmaintainable code
  • Medium Priority - Code quality, best practices deviations
  • Low Priority - Style, minor improvements
  • Quick Wins - Less than 30 minutes to fix

Analysis Categories

Show full SKILL.md (202 more words)Show less
Security
  • Hardcoded secrets
  • SQL injection risks
  • XSS vulnerabilities
  • Missing input validation
  • Exposed sensitive data
Performance
  • Inefficient algorithms
  • Blocking operations
  • Memory leaks
  • Missing caching opportunities
  • N+1 query patterns
TypeScript/Type Safety
  • Missing type annotations
  • Use of any type
  • Custom types duplicating official types
  • Missing @types packages
Async/Promise Issues
  • Missing await keywords
  • Unhandled promise rejections
  • Callback hell
Dead Code
  • Unused imports and exports
  • Unused functions, classes, and methods
  • Unused variables and types
  • Unreachable code blocks
  • Unused files (not imported anywhere)
  • Unused dependencies

Tools:

  • JavaScript/TypeScript: npx knip --reporter json
  • Python: deadcode . --dry

Important: Always verify tool findings before reporting. Check for:

  • Dynamic imports (import(variable))
  • Framework patterns (React components, decorators)
  • Re-exports for public API
  • Entry points (CLI scripts, serverless handlers)

Resources

See the reference documents for complete methodologies:

  • references/audit-methodology.md - Full 6-phase audit process with detailed checklists
  • references/dead-code-methodology.md - Dead code detection tools, verification, and cleanup workflows

Quick Reference

Before Starting
  • Read project configuration files
  • Identify tech stack and libraries
  • Run existing linters as baseline
  • Create file tracking list
During Audit
  • Mark files as in-progress
  • Analyze each category systematically
  • Note specific line numbers
  • Document before/after examples
  • Mark files as completed
After Audit
  • Categorize all findings by priority
  • Generate comprehensive report
  • Save report to project root
  • Provide brief console summary

© LIDR-academy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in ai-specs/skills/code-auditing of LIDR-academy/AI4Devs-LTI-extended.

  • SKILL.md
  • references/audit-methodology.md
  • references/dead-code-methodology.md

Open the folder on GitHubat commit 9ff9a80

Compare with similar skills

Code Auditing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Auditing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Auditing this skillLIDR-academy/AI4Devs-LTI-extended278—~1.1kAutomated safety check: PassMIT
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from LIDR-academy/AI4Devs-LTI-extended

All 9 skills in this repo
  • Owasp Security Audit

    LIDR-academy/AI4Devs-LTI-extended

    A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a…

    278 GitHub stars~4.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Show Spec Working

    LIDR-academy/AI4Devs-LTI-extended

    A skill your agent uses when the user asks "show me X", "demo X", "walk me through X", "how X works" or requests a live feature demonstration from a spec, feature or ticket.

    278 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Sync Agent Symlinks

    LIDR-academy/AI4Devs-LTI-extended

    Analyze and synchronize agent skill exposure after ai-specs skill changes (additions, removals, renames).

    278 GitHub stars~1k tokensUpdated 4 mo ago
    Auto-check passed
  • Run Parallel Tasks

    LIDR-academy/AI4Devs-LTI-extended

    Run N feature tasks in parallel, each in its own worktree, following the full specboot pipeline (enrich → new → ff → apply → verify).

    278 GitHub stars~1.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Commit

    LIDR-academy/AI4Devs-LTI-extended

    Create focused commits and pull requests following repository standards.

    278 GitHub stars~1.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Explain

    LIDR-academy/AI4Devs-LTI-extended

    Teach underlying concepts with clear mental models to close skill gaps behind user questions.

    278 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Code Auditing

How do I install Code Auditing in Claude Code?

Run `npx skills add LIDR-academy/AI4Devs-LTI-extended --skill code-auditing -a claude-code`. Or copy the skill folder (ai-specs/skills/code-auditing in LIDR-academy/AI4Devs-LTI-extended) into .claude/skills/code-auditing in your project. Claude Code loads it when a task matches its description.

How do I install Code Auditing in Codex?

Run `npx skills add LIDR-academy/AI4Devs-LTI-extended --skill code-auditing -a codex`. Or copy the skill folder (ai-specs/skills/code-auditing in LIDR-academy/AI4Devs-LTI-extended) into .agents/skills/code-auditing in your project. Codex loads it when a task matches its description.

Can I use Code Auditing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LIDR-academy/AI4Devs-LTI-extended --skill code-auditing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-auditing, .gemini/skills/code-auditing, .github/skills/code-auditing and .opencode/skills/code-auditing in your project.

What does Code Auditing need to run?

Going by SKILL.md and its folder, Code Auditing needs the command-line tools its instructions call (npx).

Does Code Auditing access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Auditing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Auditing use?

Code Auditing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Auditing use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4k tokens, read only when the agent opens those files.

What are the alternatives to Code Auditing?

Skills that share tags, products or a category with Code Auditing: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Auditing?

LIDR-academy (a GitHub organization) maintains it in LIDR-academy/AI4Devs-LTI-extended, which has 278 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on June 9, 2026.

Source: LIDR-academy/AI4Devs-LTI-extended on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.