Agent skill

Deep Audit

by LunCoSim in LunCoSim/lunco-sim

Run a multi-domain audit of the workspace (USD compliance, performance, DRY/reinvention, legacy/shims, robotics-sim best practices, resilience, UX) with parallel read-only reviewers, then execute…

Apache-2.0Auto-check passedDevelopment

Install Deep Audit

skills CLI
$ npx skills add LunCoSim/lunco-sim --skill deep-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LunCoSim/lunco-sim deep-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LunCoSim/lunco-sim.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deep-audit .claude/skills/deep-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deep-audit
GitHub stars
107
Token cost
~1.9k tokens
SKILL.md length
956 words
Files
1
Skills in repo
40
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run a multi-domain audit of the workspace (USD compliance, performance, DRY/reinvention, legacy/shims, robotics-sim best practices, resilience, UX) with parallel read-only reviewers, then execute…

  • Works in 3 steps: One reviewer per domain, launched in… → Dedup against prior reviews. Every… → The audit dimensions (adjust per run,…
  • Periodic health audits
  • SKILL.md covers Phase A — parallel read-only…, Phase B — the report, Phase C — batched execution and Definition of done
  • Calls git and python3

What it does

Deep Audit is an agent skill from LunCoSim/lunco-sim. Run a multi-domain audit of the workspace (USD compliance, performance, DRY/reinvention, legacy/shims, robotics-sim best practices, resilience, UX) with parallel read-only reviewers, then execute fixes as a no-shim migration plan. Use for periodic health audits or before large refactors.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Refactoring. The repository describes itself as: Collaborative Multiphysics Cosimulator For Space Missions 🌎🚀🌚. The licence is Apache-2.0.

When your agent uses it

  • Periodic health audits
  • Before large refactors

Example prompts

  • “/deep-audit”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. One reviewer per domain, launched in parallel, all read-only. Every prompt contains
  2. Dedup against prior reviews. Every reviewer first skims docs/reviews/*.md (and
  3. The audit dimensions (adjust per run, but these are the standing set)

What it can do on your machine

Read from SKILL.md and the folder at commit d1c6f00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deep Audit loads about 1.9k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 956 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LunCoSim/lunco-sim at commit d1c6f00, republished under its Apache-2.0 licence (© LunCoSim). 956 words, ~1,921 tokens.

Download SKILL.mdSave it as .claude/skills/deep-audit/SKILL.md (or your agent's skills folder).
name
deep-audit
description
Run a multi-domain audit of the workspace (USD compliance, performance, DRY/reinvention, legacy/shims, robotics-sim best practices, resilience, UX) with parallel read-only reviewers, then execute fixes as a no-shim migration plan. Use for periodic health audits or before large refactors.

Deep audit — multi-domain review → no-shim migration plan → batched execution

Workflow for auditing the whole workspace or a subsystem and converting findings into an ordered, executable remediation plan.

Reports live in docs/reviews/. A closed report is deleted once its findings land — git keeps it, and a stale report reads as an open problem list. A finding that will not be fixed soon graduates to its own docs/reviews/open-<name>.md, which stays.

Phase A — parallel read-only review

  1. One reviewer per domain, launched in parallel, all read-only. Every prompt contains: "Do NOT run cargo, builds, or tests; do not edit files." Reviewers return RAW structured findings (file:line | severity | dimension | defect | evidence), max ~30, prioritized, plus a 5-line maturity verdict — data for the coordinator, not prose for a human.
  2. Dedup against prior reviews. Every reviewer first skims docs/reviews/*.md (and git log -- docs/reviews/ for closed ones) and reports only NEW or still-unfixed issues. Have reviewers explicitly re-verify known lore (memory items, fixed-bug patterns) and mark each ✅ fixed / ❌ still open — verified-fixed findings are as valuable as new ones.
  3. The audit dimensions (adjust per run, but these are the standing set):
    • USD compliance — follow OpenUSD conventions, not parallel inventions: composition arcs, defaultPrim, UsdPhysics/UsdGeom/UsdLux names with their real semantics. Minimize custom lunco: schema surface: before declaring a new lunco: attribute, check whether a USD-native concept already expresses it (kind, purpose, variants, payloads, doc, existing applied APIs, physics schemas). Every lunco: attr that IS authored must be declared in schema.usda (the staleness gate python3 scripts/gen_schema.py enforces generatedSchema sync). Name-squatting check: places that adopt Pixar/Omniverse NAMES but diverge semantically.
    • Modelica/cosim conformance — flattening, connect semantics, initialization, events; master-algorithm honesty (declared ZOH/Jacobi contract vs. actual behavior); input-strip coverage at EVERY source seam; solver claims in comments match the code.
    • Performance — per-frame allocations, systems without run conditions/change detection, O(n²)/full-set rebuilds, per-sample virtual dispatch in bake/solve inner loops, main-thread work that belongs on AsyncComputeTaskPool, caches whose cap is below the resident set (a defeated cache reads as "working" in a profile of an idle scene — always check cap vs. resident bound), missing AssetId dedup on shared assets, unconditional component writes that dirty change detection.
    • DRY / reinvented wheels — hand-rolled code where a workspace dep or the openusd fork already provides it (REUSE openusd — fix the FORK); duplicate numeric cores for the same concept (two spline evaluators, two force laws); dead dependencies; a fix applied to one of two parallel code paths (the OTHER path still has the bug — always grep for the twin).
    • Legacy & shims — dual APIs, back-compat aliases, "temporary" bridges, advertised surfaces with no implementation, comments describing architecture that was never built (the "cached DAE" lie pattern). The rule is ONE FORM: the migration plan must delete the superseded path in the same phase that lands the new one.
    • Robotics-industry best practices — fixed-timestep discipline, determinism (peer-identical bakes/sums, no hash-order iteration into physics), frame safety (grid-absolute vs render frame typed via lunco_core::coords::{GridPos,RenderPos} — new pose-carrying APIs must use them), unit/precision hygiene (no f32 downcasts of grid-absolute values), tire/terramechanics fidelity honestly stated, joint lifecycle (attach in avian Prepare, born-disabled collision), readiness gating.
    • Resilience — wedge states (in-flight flags with an early-return that never clears them; every guard must fail visibly at its owning boundary), panics on malformed input (checked arithmetic on header-controlled sizes), all-or-nothing loads (one bad asset must skip +report, not stall the scene), infinite per-frame retries with no give-up, failures that never reach the UI (warn! is not surfacing — trigger an Error-severity TelemetryEvent; the StatusBus observer fans it to the status bar and Diagnostics).
    • UX for robotics engineers — inspector derives from schema (never hardcodes), disabled controls carry on_disabled_hover_text saying what would enable them, no literal RGB (DesignTokens), change-driven panels, and the operate-and-observe set: TF/frame gizmos, joint-state, CoM/inertia/forces gizmo, telemetry browser → plot.
    • Mission-modeling capability — what system-level domains exist and at what fidelity (power, thermal, comms/link budget, orbits, timelines-with-resources), measured against STK/GMAT/Basilisk-class expectations; rank gaps with the cheapest credible path (reuse: anise/hifitime, rhai over existing query substrate, pure asset changes).
Show full SKILL.md (303 more words)Show less

Phase B — the report

One file: docs/reviews/YYYY-MM-DD-<name>.md. Findings tabulated per domain with stable IDs (U1…, P1…, T1…, C1…, A1…, X1…, M1…, W1…, S1…) — the IDs are how fix agents are tasked later, so keep them stable. End with the migration plan: ordered phases, each phase deleting the superseded form in the same phase (no shim survives a phase boundary), with a sequencing rationale (correctness before perf; change-granularity before profiling — idle churn drowns measurements; schema before inspector; substrate types before mechanical sweeps). Record execution state in the memory file as phases land.

Phase C — batched execution

Follow skills/subagent-batches exactly: disjoint file lots, agents NEVER run cargo, and the coordinator runs focused checks with -j 4 after the batches land. Run a broader suite only when the audit scope requires it; set CARGO_PROFILE_TEST_STRIP=debuginfo when large Bevy test binaries make disk usage material. Additional rules:

  • Attribute every test failure before fixing. Preserve the working tree and rerun the failing target when needed. Separate failures caused by the current change, asset/test drift, and intentional negative fixtures before deciding code-fix versus test-update.
  • Substrate first, consumers fanned out. For a cross-cutting type change, land the core types yourself (Lot 0), then launch consumer lots in parallel against the new signatures; compile breaks between lots are expected and resolved by the single end check.
  • Cross-file handoffs are the coordinator's job. Agents report edits they couldn't make outside their lot (a caller in another lot's file, a cache-version bump); apply them yourself between batches — never let one drop.
  • Findings discovered DURING execution go back into the report as an addendum section, not into the void.

Definition of done

Every phase: checks cover the touched owners, failures are attributed and dispositioned, superseded forms are deleted, and the report is updated. Rerunning Phase A against a clean tree must not reproduce fixed findings.

© LunCoSim, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/deep-audit of LunCoSim/lunco-sim.

Open the folder on GitHubat commit d1c6f00

Compare with similar skills

Deep Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deep Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deep Audit this skillLunCoSim/lunco-sim107—~1.9kAutomated safety check: PassApache-2.0
Guidelinesakash-network/node1.1k20 repos~577Automated safety check: PassMIT
Component Refactoringlangflow-ai/langflow155k—~3.5kAutomated safety check: PassMIT
Migrate Core Code to Submodulestinyhumansai/openhuman42k—~2.6kAutomated safety check: PassGPL-3.0
ast-grep Structural Searchcode-yeongyu/oh-my-openagent70k—~3.3kAutomated safety check: PassMIT
Systematic Code Refactoringluongnv89/claude-howto42k—~3kAutomated safety check: PassMIT

Similar skills

  • Guidelines

    akash-network/node

    Behavioral guidelines to reduce common LLM coding mistakes. An agent skill from akash-network/node.

    1.1k GitHub starsUsed in 20 repos~577 tokens
    DevelopmentAuto-check passed
  • Component Refactoring

    langflow-ai/langflow

    Refactor high-complexity React components in Langflow frontend.

    155k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Migrate Core Code to Submodules

    tinyhumansai/openhuman

    Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.

    42k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • ast-grep Structural Search

    code-yeongyu/oh-my-openagent

    Searches and rewrites code by syntax-tree shape across 25 languages with ast-grep, for codemods, structural queries and YAML lint rules, using a Python wrapper script.

    70k GitHub stars~3.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Systematic Code Refactoring

    luongnv89/claude-howto

    Guides refactoring in phases based on Martin Fowler's method: research, test coverage check, planning and small tested steps, with your approval at each phase.

    42k GitHub stars~3k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • Codex

    skills-directory/skill-codex

    A skill your agent uses when the user asks to run Codex CLI (codex exec, codex resume) or references OpenAI Codex for code analysis, refactoring, or automated editing

    1.5k GitHub starsUsed in 3 repos~1.8k tokens
    DevelopmentAuto-check passed

More from LunCoSim/lunco-sim

All 40 skills in this repo
  • Nightly Changelog

    LunCoSim/lunco-sim

    Generate concise LunCoSim nightly GitHub release notes with platform downloads, installation guidance, an AI-agent mission prompt, and a changelog link.

    107 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Build or repair a reusable scene component through a live LunCoSim Editor session.

    107 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Assembly Quality

    LunCoSim/lunco-sim

    Build or review a componentized LunCoSim USD assembly with a realistic, dimensionally checkable presentation.

    107 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Author Rhai Tests

    LunCoSim/lunco-sim

    Author and review LunCoSim behavioral, asset-backed, component, mission, visual, and requirements-verification tests.

    107 GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Author Rhai Tool

    LunCoSim/lunco-sim

    Create, extend, register, or debug a reusable LunCoSim Rhai tool library for live USD authoring, component linting, inspection, or test support.

    107 GitHub stars~5.2k tokensUpdated today
    Auto-check passed
  • Author Tutorial

    LunCoSim/lunco-sim

    Author an interactive tutorial, guided lesson, onboarding flow, coach-mark tour, or objectives checklist in LunCoSim.

    107 GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Categories

Questions about Deep Audit

What does Deep Audit do?

Run a multi-domain audit of the workspace (USD compliance, performance, DRY/reinvention, legacy/shims, robotics-sim best practices, resilience, UX) with parallel read-only reviewers, then execute…. Deep Audit is an agent skill from LunCoSim/lunco-sim. Run a multi-domain audit of the workspace (USD compliance, performance, DRY/reinvention, legacy/shims, robotics-sim best practices, resilience, UX) with parallel read-only reviewers, then execute fixes as a no-shim migration plan.

When should I use Deep Audit?

Deep Audit fits situations like: periodic health audits; before large refactors.

How do I install Deep Audit in Claude Code?

Run `npx skills add LunCoSim/lunco-sim --skill deep-audit -a claude-code`. Or copy the skill folder (skills/deep-audit in LunCoSim/lunco-sim) into .claude/skills/deep-audit in your project. Claude Code loads it when a task matches its description.

How do I install Deep Audit in Codex?

Run `npx skills add LunCoSim/lunco-sim --skill deep-audit -a codex`. Or copy the skill folder (skills/deep-audit in LunCoSim/lunco-sim) into .agents/skills/deep-audit in your project. Codex loads it when a task matches its description.

Can I use Deep Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LunCoSim/lunco-sim --skill deep-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deep-audit, .gemini/skills/deep-audit, .github/skills/deep-audit and .opencode/skills/deep-audit in your project.

What does Deep Audit need to run?

Going by SKILL.md and its folder, Deep Audit needs the command-line tools its instructions call (git and python3). Our summary lists: Python 3.

Does Deep Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Deep Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Deep Audit use?

Deep Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deep Audit use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Deep Audit?

Skills that share tags, products or a category with Deep Audit: Guidelines (akash-network/node, 1.1k stars), Component Refactoring (langflow-ai/langflow, 155k stars), Migrate Core Code to Submodules (tinyhumansai/openhuman, 42k stars) and ast-grep Structural Search (code-yeongyu/oh-my-openagent, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deep Audit?

LunCoSim (a GitHub organization) maintains it in LunCoSim/lunco-sim, which has 107 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 9, 2026.

Source: LunCoSim/lunco-sim on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.