Agent skill

Audit

by MadAppGang in MadAppGang/claude-code

On-demand security and code quality audit. An agent skill from MadAppGang/claude-code.

MITAuto-check passedDevelopment

Install Audit

skills CLI
$ npx skills add MadAppGang/claude-code --skill audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MadAppGang/claude-code audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MadAppGang/claude-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dev/skills/audit .claude/skills/audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit
GitHub stars
285
Token cost
~3.3k tokens
SKILL.md length
1,013 words
Files
1
Skills in repo
69
Repo updated
First seen
Licence
MIT

At a glance

On-demand security and code quality audit. An agent skill from MadAppGang/claude-code.

  • Works in 4 steps: Security Vulnerabilities (OWASP Top 10) → Dependency Vulnerabilities → Exposed Secrets and Credentials → …
  • Checking for vulnerabilities
  • SKILL.md covers Overview, Audit Categories, Running Audits and Audit Report Format, plus 6 more sections
  • Calls npm, git and yarn; needs STRIPE_SECRET_KEY

What it does

Audit is an agent skill from MadAppGang/claude-code. On-demand security and code quality audit. Use when checking for vulnerabilities, security issues, code smells, or compliance problems. Trigger keywords - "audit", "security check", "vulnerability scan", "code quality", "compliance", "security audit".

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code quality, Refactoring and Security review. It works with Rust. The repository describes itself as: claude code plugins marketplace. The licence is MIT.

When your agent uses it

  • Checking for vulnerabilities
  • Security issues
  • Compliance problems
  • Keywords - audit

Example prompts

  • “security check”
  • “vulnerability scan”
  • “code quality”
  • “/audit”

Requirements

  • Python 3
  • Node.js
  • A credential in STRIPE_SECRET_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Security Vulnerabilities (OWASP Top 10)
  2. Dependency Vulnerabilities
  3. Exposed Secrets and Credentials
  4. Code Quality Issues

What it can do on your machine

Read from SKILL.md and the folder at commit 6097ad4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git
    • yarn
    • pnpm
    • go
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, git, yarn and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • STRIPE_SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit loads about 3.3k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 1,013 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MadAppGang/claude-code at commit 6097ad4, republished under its MIT licence (© MadAppGang). 1,013 words, ~3,317 tokens.

Download SKILL.mdSave it as .claude/skills/audit/SKILL.md (or your agent's skills folder).
name
audit
description
On-demand security and code quality audit. Use when checking for vulnerabilities, security issues, code smells, or compliance problems. Trigger keywords - "audit", "security check", "vulnerability scan", "code quality", "compliance", "security audit".
version
0.1.0
tags
dev, audit, security, quality, compliance
keywords
audit, security, vulnerability, code-quality, compliance, scan, check
plugin
dev
updated
2026-01-28

Audit Skill

Overview

The audit skill provides comprehensive on-demand security and code quality audits for your codebase. It identifies vulnerabilities, security issues, code smells, outdated dependencies, exposed secrets, and compliance problems across all supported technology stacks.

When to Use:

  • Security audits and vulnerability scans
  • Pre-deployment security checks
  • Compliance verification (GDPR, HIPAA, SOC2)
  • Code quality assessment
  • Dependency vulnerability scanning
  • Secret exposure detection
  • Third-party license compliance

Technology Coverage:

  • React/TypeScript/JavaScript projects
  • Go applications
  • Rust projects
  • Python codebases
  • Full-stack applications
  • Monorepos and microservices

Audit Categories

1. Security Vulnerabilities (OWASP Top 10)

What Gets Checked:

  • SQL injection vulnerabilities
  • Cross-site scripting (XSS)
  • Authentication and session management flaws
  • Security misconfigurations
  • Sensitive data exposure
  • XML external entities (XXE)
  • Broken access control
  • Cross-site request forgery (CSRF)
  • Using components with known vulnerabilities
  • Insufficient logging and monitoring

Detection Methods:

  • Static code analysis
  • Pattern matching for common vulnerabilities
  • Framework-specific security checks
  • API endpoint security validation
  • Input validation analysis
2. Dependency Vulnerabilities

What Gets Checked:

  • Outdated packages with known CVEs
  • Unmaintained dependencies
  • License compatibility issues
  • Transitive dependency risks
  • Version conflicts

Package Managers Supported:

  • npm/yarn/pnpm (JavaScript/TypeScript)
  • go.mod (Go)
  • Cargo.toml (Rust)
  • requirements.txt/pyproject.toml (Python)
  • Gemfile (Ruby)

Tools Used:

  • npm audit / yarn audit / pnpm audit
  • go mod verify + vulnerability databases
  • cargo audit
  • pip-audit / safety
3. Exposed Secrets and Credentials

What Gets Detected:

  • Hardcoded API keys and tokens
  • Database credentials
  • Private keys and certificates
  • OAuth tokens and secrets
  • AWS/GCP/Azure credentials
  • JWT secrets
  • Encryption keys

Detection Patterns:

  • Regex patterns for common secret formats
  • Environment variable misuse
  • Configuration file analysis
  • Git history scanning (if requested)
  • Common secret naming patterns

False Positive Reduction:

  • Ignore test fixtures and mocks
  • Respect .gitignore patterns
  • Check for proper environment variable usage
  • Validate against .env.example templates
4. Code Quality Issues

What Gets Analyzed:

  • Code complexity (cyclomatic complexity)
  • Code duplication
  • Dead code and unused exports
  • Large functions and files
  • Naming convention violations
  • Magic numbers and hardcoded values
  • Lack of error handling
  • Poor separation of concerns

Metrics Calculated:

  • Cyclomatic complexity per function
  • Duplication percentage
  • Lines of code (LOC) per file/function
  • Comment-to-code ratio
  • Test-to-code ratio

Running Audits

Full Audit

Run all audit categories:

Please run a full security and quality audit of this codebase

The audit will:

  1. Scan all source files for vulnerabilities
  2. Check dependencies for known CVEs
  3. Search for exposed secrets
  4. Analyze code quality metrics
  5. Generate comprehensive report
Category-Specific Audits

Security Only:

Run a security audit focusing on OWASP top 10 vulnerabilities

Dependencies Only:

Audit all dependencies for vulnerabilities and outdated packages

Secrets Only:

Scan for exposed secrets and credentials

Code Quality Only:

Analyze code quality and identify code smells
Targeted Audits

Specific Directory:

Audit the /src/auth directory for security issues

Specific Files:

Audit UserController.ts and AuthService.ts for vulnerabilities

Pre-Deployment:

Run pre-deployment audit checklist

Audit Report Format

Severity Levels

Reports classify findings by severity:

  • CRITICAL: Immediate security risk, exploitable vulnerability
  • HIGH: Significant security or quality issue
  • MEDIUM: Moderate issue that should be addressed
  • LOW: Minor issue or code smell
  • INFO: Informational finding, best practice suggestion
Report Structure
markdown
# Security and Quality Audit Report

**Generated**: 2026-01-28 14:32:00
**Scope**: Full codebase audit
**Files Scanned**: 247
**Duration**: 8.3 seconds

## Executive Summary

- CRITICAL: 2 findings
- HIGH: 5 findings
- MEDIUM: 12 findings
- LOW: 23 findings
- INFO: 8 findings

**Risk Score**: 7.2/10 (HIGH)

## Critical Findings

### [CRITICAL-001] SQL Injection Vulnerability
**File**: src/database/queries.ts:42
**Severity**: CRITICAL
**Category**: Security - SQL Injection

**Issue**: User input concatenated directly into SQL query without sanitization.

**Code**:
```typescript
const query = `SELECT * FROM users WHERE email = '${email}'`;

Impact: Attacker can execute arbitrary SQL commands.

Recommendation: Use parameterized queries or ORM.

Fix:

typescript
const query = db.prepare('SELECT * FROM users WHERE email = ?').bind(email);

[CRITICAL-002] Exposed API Key

File: src/config/api.ts:15 Severity: CRITICAL Category: Security - Exposed Secret

Issue: Hardcoded API key found in source code.

Code:

typescript
const STRIPE_SECRET_KEY = "sk_live_abc123xyz789";

Impact: Unauthorized access to Stripe account.

Recommendation: Move to environment variable.

Fix:

typescript
const STRIPE_SECRET_KEY = process.env.STRIPE_SECRET_KEY;

High Priority Findings

[HIGH-001] Outdated Dependency with Known CVE

File: package.json:23 Severity: HIGH Category: Dependencies

Issue: lodash@4.17.15 has known vulnerability (CVE-2021-23337)

CVE Details:

  • CVE-2021-23337: Command injection in template
  • Published: 2021-02-15
  • CVSS Score: 7.2

Recommendation: Upgrade to lodash@4.17.21 or higher

Fix:

bash
npm install lodash@latest

[... additional findings ...]

Compliance Checks

OWASP Top 10 Coverage
  • [FAIL] A1: Injection - 2 SQL injection vulnerabilities found
  • [PASS] A2: Broken Authentication
  • [FAIL] A3: Sensitive Data Exposure - 1 exposed secret
  • [PASS] A4: XML External Entities
  • [PASS] A5: Broken Access Control
  • [FAIL] A6: Security Misconfiguration - CORS too permissive
  • [PASS] A7: Cross-Site Scripting
  • [PASS] A8: Insecure Deserialization
  • [FAIL] A9: Using Components with Known Vulnerabilities - 3 outdated deps
  • [WARN] A10: Insufficient Logging - Limited audit logging

Overall: 6/10 passing (60%)

Show full SKILL.md (427 more words)Show less

Recommendations

  1. Immediate Actions (CRITICAL/HIGH):

    • Fix SQL injection in queries.ts
    • Remove hardcoded API key
    • Upgrade vulnerable dependencies
  2. Short Term (MEDIUM):

    • Improve error handling consistency
    • Add input validation to all API endpoints
    • Configure stricter CORS policy
  3. Long Term (LOW/INFO):

    • Reduce code duplication (12% current)
    • Refactor complex functions (8 functions >15 complexity)
    • Improve test coverage (currently 67%)

## Integration with Dev Plugin

### With Code Analysis Agent

Use code-analysis enrichment before audit:

First enrich the codebase with claudemem, then run security audit


This provides:
- Context-aware vulnerability detection
- Better false positive filtering
- Dependency graph analysis

### With Test Architect Agent

Combine audit with test coverage:

Run audit and identify untested critical code paths


### With Optimize Skill

Security-performance trade-offs:

Audit security implications of performance optimizations


## Best Practices

### 1. Regular Audits

**Recommended Schedule**:
- Daily: Dependency vulnerability scans (CI/CD)
- Weekly: Full security audit
- Pre-deployment: Comprehensive audit
- Post-incident: Targeted security review

### 2. Incremental Audits

For large codebases:

Audit files changed in the last 7 days


This focuses on recent changes and reduces noise.

### 3. Baseline and Track

**First Audit**:

Run full audit and establish security baseline


**Subsequent Audits**:

Run audit and compare against baseline


Track improvements over time.

### 4. Prioritize by Risk

Focus on:
1. User-facing authentication code
2. Payment processing
3. Data storage and retrieval
4. API endpoints with PII
5. Third-party integrations

### 5. Automate in CI/CD

**GitHub Actions Example**:
```yaml
- name: Security Audit
  run: |
    npm audit --audit-level=high
    # Run custom audit script

Pre-commit Hook:

bash
#!/bin/bash
# Scan staged files for secrets
git diff --cached --name-only | xargs grep -E "(api_key|secret|password)"

Examples

Example 1: Pre-Deployment Security Audit

Request:

We're deploying to production tomorrow. Run a comprehensive security audit.

Audit Process:

  1. Scan all source files for OWASP top 10
  2. Check all dependencies for CVEs
  3. Search for exposed secrets
  4. Verify CORS and authentication config
  5. Check logging and monitoring setup

Report Highlights:

  • 1 CRITICAL: Exposed database password
  • 2 HIGH: Outdated dependencies with CVEs
  • 5 MEDIUM: Missing input validation
  • Compliance: 8/10 OWASP categories passing

Outcome: Deployment blocked until CRITICAL/HIGH fixed

Example 2: Dependency Vulnerability Scan

Request:

Check all npm dependencies for known vulnerabilities

Process:

  1. Run npm audit --json
  2. Parse vulnerability reports
  3. Check for available fixes
  4. Identify breaking changes

Report:

Found 3 vulnerabilities (1 high, 2 moderate)

HIGH: axios@0.21.1 (CVE-2021-3749)
- Fix available: axios@0.21.4
- Breaking: No
- Run: npm install axios@0.21.4

MODERATE: glob-parent@5.1.1 (CVE-2020-28469)
- Fix available: glob-parent@6.0.2
- Breaking: Yes (ESM only)
- Review: Migration guide needed
Example 3: Compliance Check (GDPR)

Request:

Audit for GDPR compliance issues

Checks:

  • Data retention policies
  • User consent mechanisms
  • Right to erasure implementation
  • Data export functionality
  • Encryption at rest and in transit
  • Privacy policy references
  • Third-party data sharing

Report:

GDPR Compliance Audit

[PASS] Data encryption at rest
[FAIL] Missing data retention policy
[FAIL] No user data export endpoint
[PASS] Consent management implemented
[WARN] Privacy policy link outdated
[PASS] TLS 1.3 enforced
Example 4: Code Quality Audit

Request:

Identify code quality issues and technical debt

Analysis:

  • Complexity: 8 functions exceed threshold
  • Duplication: 15% code duplication
  • Dead code: 23 unused exports
  • Large files: 4 files over 500 lines
  • Magic numbers: 47 instances

Top Issues:

1. UserService.ts - Complexity 28 (threshold: 15)
   Recommendation: Extract validation logic

2. utils/helpers.ts - 234 lines duplicated in 3 files
   Recommendation: Create shared utility module

3. api/routes.ts - 847 lines (threshold: 500)
   Recommendation: Split into feature-based modules

Stack-Specific Audit Patterns

React/TypeScript

Security Focus:

  • XSS via dangerouslySetInnerHTML
  • Insecure refs and DOM manipulation
  • Exposed environment variables in client code
  • CORS misconfigurations

Quality Focus:

  • Prop types and TypeScript coverage
  • Component complexity
  • Hook dependencies
  • Re-render performance
Go

Security Focus:

  • SQL injection in database/sql
  • Command injection in exec
  • Path traversal
  • Goroutine leaks

Quality Focus:

  • Error handling consistency
  • Context propagation
  • Resource cleanup (defer)
  • Race conditions
Rust

Security Focus:

  • Unsafe blocks
  • Integer overflow
  • Memory leaks in FFI
  • Dependency vulnerabilities

Quality Focus:

  • Error propagation patterns
  • Clippy warnings
  • Documentation coverage
  • Panic usage

Audit Workflow Integration

[Developer] → Request audit
    ↓
[Audit Skill] → Scan codebase
    ↓
[Generate Report] → Categorize findings
    ↓
[Prioritize] → CRITICAL → HIGH → MEDIUM → LOW
    ↓
[Fix Critical] → Apply fixes
    ↓
[Re-audit] → Verify fixes
    ↓
[Update Baseline] → Track progress

Conclusion

The audit skill provides comprehensive security and quality analysis on-demand. Use it regularly to maintain code health, catch vulnerabilities early, and ensure compliance with industry standards.

Key Takeaways:

  • Run audits frequently (daily in CI/CD)
  • Prioritize CRITICAL and HIGH findings
  • Establish baselines and track progress
  • Integrate with other dev skills for comprehensive analysis
  • Automate where possible

For performance analysis, see the optimize skill. For test coverage gaps, see the test-coverage skill.

© MadAppGang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/dev/skills/audit of MadAppGang/claude-code.

Open the folder on GitHubat commit 6097ad4

Compare with similar skills

Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit this skillMadAppGang/claude-code285—~3.3kAutomated safety check: PassMIT
Code Reviewerforyourhealth111-pixel/Vibe-Skills3.6k—~1.4kAutomated safety check: NotesApache-2.0
Code ReviewerYikai-Liao/symusic1891 repos~1.3kAutomated safety check: PassMIT
Code Review Excellenceandrew-yangy/gru-ai155—~1.7kAutomated safety check: NotesMIT
Refactortermide/termide171—~2.8kAutomated safety check: PassMIT
Code Qualitystatic-web-server/static-web-server2.4k—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Code Reviewer

    foryourhealth111-pixel/Vibe-Skills

    Default code-quality route for broad code review, PR review, maintainability, correctness, and regression-risk checks.

    3.6k GitHub stars~1.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Code Reviewer

    Yikai-Liao/symusic

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

    189 GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed
  • Code Review Excellence

    andrew-yangy/gru-ai

    Provides comprehensive code review guidance for React 19, Vue 3, Rust, TypeScript, Java, Python, and C/C++.

    155 GitHub stars~1.7k tokensUpdated 7 mo ago
    DevelopmentAuto-check: notes
  • Refactor

    termide/termide

    Full-workspace code quality analysis and refactoring with validation

    171 GitHub stars~2.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Quality

    static-web-server/static-web-server

    Review or self-check a change to the Static Web Server (SWS) project before it is called done — correctness, invariants, API design, concurrency, maintainability, and an SWS-specific review checklist.

    2.4k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Expert Code Reviewer

    GulajavaMinistudio/Mayukai-Theme

    Language-agnostic workflow for code reviews and security audits against Clean Code/SOLID principles, generating formal refactoring plans.

    139 GitHub stars~1.4k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed

More from MadAppGang/claude-code

All 69 skills in this repo
  • Content Brief

    MadAppGang/claude-code

    Content brief template and creation methodology for SEO-optimized content.

    285 GitHub starsUsed in 1 repo~959 tokens
    Auto-check passed
  • Context Detection

    MadAppGang/claude-code

    A skill your agent uses when detecting project technology stack from files/configs/directory structure, auto-loading framework-specific skills, or analyzing multi-stack fullstack projects (e.g…

    285 GitHub stars~5.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Content Optimizer

    MadAppGang/claude-code

    On-page SEO optimization techniques including keyword density, meta tags, heading structure, and readability.

    285 GitHub starsUsed in 1 repo~694 tokens
    Auto-check passed
  • Keyword Cluster Builder

    MadAppGang/claude-code

    Techniques for expanding seed keywords and clustering by topic and intent.

    285 GitHub starsUsed in 1 repo~674 tokens
    Auto-check passed
  • Serp Analysis

    MadAppGang/claude-code

    SERP analysis techniques for intent classification, feature identification, and competitive intelligence.

    285 GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Agent Coordination Discipline

    MadAppGang/claude-code

    A skill your agent uses when deciding whether to launch an agent, selecting which agent to use, or coordinating multiple agents.

    285 GitHub stars~3.8k tokensUpdated 6 mo ago
    Auto-check passed

Works with

Questions about Audit

What does Audit do?

On-demand security and code quality audit. An agent skill from MadAppGang/claude-code. Audit is an agent skill from MadAppGang/claude-code. On-demand security and code quality audit.

When should I use Audit?

Audit fits situations like: checking for vulnerabilities; security issues; compliance problems; keywords - audit.

How do I install Audit in Claude Code?

Run `npx skills add MadAppGang/claude-code --skill audit -a claude-code`. Or copy the skill folder (plugins/dev/skills/audit in MadAppGang/claude-code) into .claude/skills/audit in your project. Claude Code loads it when a task matches its description.

How do I install Audit in Codex?

Run `npx skills add MadAppGang/claude-code --skill audit -a codex`. Or copy the skill folder (plugins/dev/skills/audit in MadAppGang/claude-code) into .agents/skills/audit in your project. Codex loads it when a task matches its description.

Can I use Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MadAppGang/claude-code --skill audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit, .gemini/skills/audit, .github/skills/audit and .opencode/skills/audit in your project.

What does Audit need to run?

Going by SKILL.md and its folder, Audit needs the command-line tools its instructions call (npm, git, yarn, pnpm, go and cargo) and credentials named STRIPE_SECRET_KEY. Our summary lists: Python 3; Node.js; A credential in STRIPE_SECRET_KEY.

Does Audit access the network?

SKILL.md contains no URLs. Its commands use npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit use?

Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit?

Skills that share tags, products or a category with Audit: Code Reviewer (foryourhealth111-pixel/Vibe-Skills, 3.6k stars), Code Reviewer (Yikai-Liao/symusic, 189 stars), Code Review Excellence (andrew-yangy/gru-ai, 155 stars) and Refactor (termide/termide, 171 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit?

MadAppGang (a GitHub organization) maintains it in MadAppGang/claude-code, which has 285 GitHub stars. The repository holds 69 skills in this directory. The repository was last updated on March 15, 2026.

Source: MadAppGang/claude-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.