Code Reviewer
foryourhealth111-pixel/Vibe-Skills
Default code-quality route for broad code review, PR review, maintainability, correctness, and regression-risk checks.
On-demand security and code quality audit. An agent skill from MadAppGang/claude-code.
$ npx skills add MadAppGang/claude-code --skill audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install MadAppGang/claude-code audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/MadAppGang/claude-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dev/skills/audit .claude/skills/audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit" agent skill from https://github.com/MadAppGang/claude-code/tree/main/plugins/dev/skills/audit into .claude/skills/audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/MadAppGang/claude-code/tree/main/plugins/dev/skills/auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add MadAppGang/claude-code --skill audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install MadAppGang/claude-code audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MadAppGang/claude-code.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/dev/skills/audit .agents/skills/audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit" agent skill from https://github.com/MadAppGang/claude-code/tree/main/plugins/dev/skills/audit into .agents/skills/audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MadAppGang/claude-code --skill audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install MadAppGang/claude-code audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MadAppGang/claude-code.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/dev/skills/audit .cursor/skills/audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit" agent skill from https://github.com/MadAppGang/claude-code/tree/main/plugins/dev/skills/audit into .cursor/skills/audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/MadAppGang/claude-code.git --path plugins/dev/skills/audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add MadAppGang/claude-code --skill audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install MadAppGang/claude-code audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MadAppGang/claude-code.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/dev/skills/audit .gemini/skills/audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit" agent skill from https://github.com/MadAppGang/claude-code/tree/main/plugins/dev/skills/audit into .gemini/skills/audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install MadAppGang/claude-code auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add MadAppGang/claude-code --skill audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/MadAppGang/claude-code.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/dev/skills/audit .github/skills/audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit" agent skill from https://github.com/MadAppGang/claude-code/tree/main/plugins/dev/skills/audit into .github/skills/audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MadAppGang/claude-code --skill audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install MadAppGang/claude-code audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MadAppGang/claude-code.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/dev/skills/audit .opencode/skills/audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit" agent skill from https://github.com/MadAppGang/claude-code/tree/main/plugins/dev/skills/audit into .opencode/skills/audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
auditOn-demand security and code quality audit. An agent skill from MadAppGang/claude-code.
Audit is an agent skill from MadAppGang/claude-code. On-demand security and code quality audit. Use when checking for vulnerabilities, security issues, code smells, or compliance problems. Trigger keywords - "audit", "security check", "vulnerability scan", "code quality", "compliance", "security audit".
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code quality, Refactoring and Security review. It works with Rust. The repository describes itself as: claude code plugins marketplace. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6097ad4. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmgityarnpnpmgocargoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, git, yarn and pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
STRIPE_SECRET_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Audit loads about 3.3k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 1,013 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from MadAppGang/claude-code at commit 6097ad4, republished under its MIT licence (© MadAppGang). 1,013 words, ~3,317 tokens.
.claude/skills/audit/SKILL.md (or your agent's skills folder).The audit skill provides comprehensive on-demand security and code quality audits for your codebase. It identifies vulnerabilities, security issues, code smells, outdated dependencies, exposed secrets, and compliance problems across all supported technology stacks.
When to Use:
Technology Coverage:
What Gets Checked:
Detection Methods:
What Gets Checked:
Package Managers Supported:
Tools Used:
npm audit / yarn audit / pnpm auditgo mod verify + vulnerability databasescargo auditpip-audit / safetyWhat Gets Detected:
Detection Patterns:
False Positive Reduction:
.gitignore patterns.env.example templatesWhat Gets Analyzed:
Metrics Calculated:
Run all audit categories:
Please run a full security and quality audit of this codebaseThe audit will:
Security Only:
Run a security audit focusing on OWASP top 10 vulnerabilitiesDependencies Only:
Audit all dependencies for vulnerabilities and outdated packagesSecrets Only:
Scan for exposed secrets and credentialsCode Quality Only:
Analyze code quality and identify code smellsSpecific Directory:
Audit the /src/auth directory for security issuesSpecific Files:
Audit UserController.ts and AuthService.ts for vulnerabilitiesPre-Deployment:
Run pre-deployment audit checklistReports classify findings by severity:
# Security and Quality Audit Report
**Generated**: 2026-01-28 14:32:00
**Scope**: Full codebase audit
**Files Scanned**: 247
**Duration**: 8.3 seconds
## Executive Summary
- CRITICAL: 2 findings
- HIGH: 5 findings
- MEDIUM: 12 findings
- LOW: 23 findings
- INFO: 8 findings
**Risk Score**: 7.2/10 (HIGH)
## Critical Findings
### [CRITICAL-001] SQL Injection Vulnerability
**File**: src/database/queries.ts:42
**Severity**: CRITICAL
**Category**: Security - SQL Injection
**Issue**: User input concatenated directly into SQL query without sanitization.
**Code**:
```typescript
const query = `SELECT * FROM users WHERE email = '${email}'`;Impact: Attacker can execute arbitrary SQL commands.
Recommendation: Use parameterized queries or ORM.
Fix:
const query = db.prepare('SELECT * FROM users WHERE email = ?').bind(email);File: src/config/api.ts:15 Severity: CRITICAL Category: Security - Exposed Secret
Issue: Hardcoded API key found in source code.
Code:
const STRIPE_SECRET_KEY = "sk_live_abc123xyz789";Impact: Unauthorized access to Stripe account.
Recommendation: Move to environment variable.
Fix:
const STRIPE_SECRET_KEY = process.env.STRIPE_SECRET_KEY;File: package.json:23 Severity: HIGH Category: Dependencies
Issue: lodash@4.17.15 has known vulnerability (CVE-2021-23337)
CVE Details:
Recommendation: Upgrade to lodash@4.17.21 or higher
Fix:
npm install lodash@latest[... additional findings ...]
Overall: 6/10 passing (60%)
Immediate Actions (CRITICAL/HIGH):
Short Term (MEDIUM):
Long Term (LOW/INFO):
## Integration with Dev Plugin
### With Code Analysis Agent
Use code-analysis enrichment before audit:
First enrich the codebase with claudemem, then run security audit
This provides:
- Context-aware vulnerability detection
- Better false positive filtering
- Dependency graph analysis
### With Test Architect Agent
Combine audit with test coverage:
Run audit and identify untested critical code paths
### With Optimize Skill
Security-performance trade-offs:
Audit security implications of performance optimizations
## Best Practices
### 1. Regular Audits
**Recommended Schedule**:
- Daily: Dependency vulnerability scans (CI/CD)
- Weekly: Full security audit
- Pre-deployment: Comprehensive audit
- Post-incident: Targeted security review
### 2. Incremental Audits
For large codebases:
Audit files changed in the last 7 days
This focuses on recent changes and reduces noise.
### 3. Baseline and Track
**First Audit**:Run full audit and establish security baseline
**Subsequent Audits**:Run audit and compare against baseline
Track improvements over time.
### 4. Prioritize by Risk
Focus on:
1. User-facing authentication code
2. Payment processing
3. Data storage and retrieval
4. API endpoints with PII
5. Third-party integrations
### 5. Automate in CI/CD
**GitHub Actions Example**:
```yaml
- name: Security Audit
run: |
npm audit --audit-level=high
# Run custom audit scriptPre-commit Hook:
#!/bin/bash
# Scan staged files for secrets
git diff --cached --name-only | xargs grep -E "(api_key|secret|password)"Request:
We're deploying to production tomorrow. Run a comprehensive security audit.Audit Process:
Report Highlights:
Outcome: Deployment blocked until CRITICAL/HIGH fixed
Request:
Check all npm dependencies for known vulnerabilitiesProcess:
npm audit --jsonReport:
Found 3 vulnerabilities (1 high, 2 moderate)
HIGH: axios@0.21.1 (CVE-2021-3749)
- Fix available: axios@0.21.4
- Breaking: No
- Run: npm install axios@0.21.4
MODERATE: glob-parent@5.1.1 (CVE-2020-28469)
- Fix available: glob-parent@6.0.2
- Breaking: Yes (ESM only)
- Review: Migration guide neededRequest:
Audit for GDPR compliance issuesChecks:
Report:
GDPR Compliance Audit
[PASS] Data encryption at rest
[FAIL] Missing data retention policy
[FAIL] No user data export endpoint
[PASS] Consent management implemented
[WARN] Privacy policy link outdated
[PASS] TLS 1.3 enforcedRequest:
Identify code quality issues and technical debtAnalysis:
Top Issues:
1. UserService.ts - Complexity 28 (threshold: 15)
Recommendation: Extract validation logic
2. utils/helpers.ts - 234 lines duplicated in 3 files
Recommendation: Create shared utility module
3. api/routes.ts - 847 lines (threshold: 500)
Recommendation: Split into feature-based modulesSecurity Focus:
Quality Focus:
Security Focus:
Quality Focus:
Security Focus:
Quality Focus:
[Developer] → Request audit
↓
[Audit Skill] → Scan codebase
↓
[Generate Report] → Categorize findings
↓
[Prioritize] → CRITICAL → HIGH → MEDIUM → LOW
↓
[Fix Critical] → Apply fixes
↓
[Re-audit] → Verify fixes
↓
[Update Baseline] → Track progressThe audit skill provides comprehensive security and quality analysis on-demand. Use it regularly to maintain code health, catch vulnerabilities early, and ensure compliance with industry standards.
Key Takeaways:
For performance analysis, see the optimize skill. For test coverage gaps, see the test-coverage skill.
© MadAppGang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/dev/skills/audit of MadAppGang/claude-code.
Open the folder on GitHubat commit 6097ad4
Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Audit this skillMadAppGang/claude-code | 285 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Code Reviewerforyourhealth111-pixel/Vibe-Skills | 3.6k | — | ~1.4k | Automated safety check: Notes | Apache-2.0 | |
| Code ReviewerYikai-Liao/symusic | 189 | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Code Review Excellenceandrew-yangy/gru-ai | 155 | — | ~1.7k | Automated safety check: Notes | MIT | |
| Refactortermide/termide | 171 | — | ~2.8k | Automated safety check: Pass | MIT | |
| Code Qualitystatic-web-server/static-web-server | 2.4k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 |
foryourhealth111-pixel/Vibe-Skills
Default code-quality route for broad code review, PR review, maintainability, correctness, and regression-risk checks.
Yikai-Liao/symusic
Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…
andrew-yangy/gru-ai
Provides comprehensive code review guidance for React 19, Vue 3, Rust, TypeScript, Java, Python, and C/C++.
termide/termide
Full-workspace code quality analysis and refactoring with validation
static-web-server/static-web-server
Review or self-check a change to the Static Web Server (SWS) project before it is called done — correctness, invariants, API design, concurrency, maintainability, and an SWS-specific review checklist.
GulajavaMinistudio/Mayukai-Theme
Language-agnostic workflow for code reviews and security audits against Clean Code/SOLID principles, generating formal refactoring plans.
MadAppGang/claude-code
Content brief template and creation methodology for SEO-optimized content.
MadAppGang/claude-code
A skill your agent uses when detecting project technology stack from files/configs/directory structure, auto-loading framework-specific skills, or analyzing multi-stack fullstack projects (e.g…
MadAppGang/claude-code
On-page SEO optimization techniques including keyword density, meta tags, heading structure, and readability.
MadAppGang/claude-code
Techniques for expanding seed keywords and clustering by topic and intent.
MadAppGang/claude-code
SERP analysis techniques for intent classification, feature identification, and competitive intelligence.
MadAppGang/claude-code
A skill your agent uses when deciding whether to launch an agent, selecting which agent to use, or coordinating multiple agents.
Works with
Categories
On-demand security and code quality audit. An agent skill from MadAppGang/claude-code. Audit is an agent skill from MadAppGang/claude-code. On-demand security and code quality audit.
Audit fits situations like: checking for vulnerabilities; security issues; compliance problems; keywords - audit.
Run `npx skills add MadAppGang/claude-code --skill audit -a claude-code`. Or copy the skill folder (plugins/dev/skills/audit in MadAppGang/claude-code) into .claude/skills/audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add MadAppGang/claude-code --skill audit -a codex`. Or copy the skill folder (plugins/dev/skills/audit in MadAppGang/claude-code) into .agents/skills/audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MadAppGang/claude-code --skill audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit, .gemini/skills/audit, .github/skills/audit and .opencode/skills/audit in your project.
Going by SKILL.md and its folder, Audit needs the command-line tools its instructions call (npm, git, yarn, pnpm, go and cargo) and credentials named STRIPE_SECRET_KEY. Our summary lists: Python 3; Node.js; A credential in STRIPE_SECRET_KEY.
SKILL.md contains no URLs. Its commands use npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Audit: Code Reviewer (foryourhealth111-pixel/Vibe-Skills, 3.6k stars), Code Reviewer (Yikai-Liao/symusic, 189 stars), Code Review Excellence (andrew-yangy/gru-ai, 155 stars) and Refactor (termide/termide, 171 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
MadAppGang (a GitHub organization) maintains it in MadAppGang/claude-code, which has 285 GitHub stars. The repository holds 69 skills in this directory. The repository was last updated on March 15, 2026.
Source: MadAppGang/claude-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.