Ostack
mr-daedalium/ostack-saas
Fast headless browser for QA testing and site dogfooding. An agent skill from mr-daedalium/ostack-saas.
全面代码库审计 — 自适应并行深度分析(前后端契约、数据完整性、异常处理/安全、架构/技术债、配置/缓存),结构化 findings + 对抗验证 + 基线对比,输出按严重程度排序的统一报告和修复路线图。支持 quick 快速体检模式。Use when user asks to audit, analyze, or review an entire codebase for design…
$ npx skills add majiayu000/spellbook --skill codebase-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install majiayu000/spellbook codebase-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codebase-audit .claude/skills/codebase-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codebase-audit" agent skill from https://github.com/majiayu000/spellbook/tree/main/skills/codebase-audit into .claude/skills/codebase-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/majiayu000/spellbook/tree/main/skills/codebase-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add majiayu000/spellbook --skill codebase-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install majiayu000/spellbook codebase-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/codebase-audit .agents/skills/codebase-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codebase-audit" agent skill from https://github.com/majiayu000/spellbook/tree/main/skills/codebase-audit into .agents/skills/codebase-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add majiayu000/spellbook --skill codebase-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install majiayu000/spellbook codebase-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/codebase-audit .cursor/skills/codebase-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codebase-audit" agent skill from https://github.com/majiayu000/spellbook/tree/main/skills/codebase-audit into .cursor/skills/codebase-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/majiayu000/spellbook.git --path skills/codebase-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add majiayu000/spellbook --skill codebase-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install majiayu000/spellbook codebase-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/codebase-audit .gemini/skills/codebase-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codebase-audit" agent skill from https://github.com/majiayu000/spellbook/tree/main/skills/codebase-audit into .gemini/skills/codebase-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install majiayu000/spellbook codebase-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add majiayu000/spellbook --skill codebase-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/codebase-audit .github/skills/codebase-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codebase-audit" agent skill from https://github.com/majiayu000/spellbook/tree/main/skills/codebase-audit into .github/skills/codebase-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add majiayu000/spellbook --skill codebase-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install majiayu000/spellbook codebase-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/codebase-audit .opencode/skills/codebase-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codebase-audit" agent skill from https://github.com/majiayu000/spellbook/tree/main/skills/codebase-audit into .opencode/skills/codebase-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codebase-audit全面代码库审计 — 自适应并行深度分析(前后端契约、数据完整性、异常处理/安全、架构/技术债、配置/缓存),结构化 findings + 对抗验证 + 基线对比,输出按严重程度排序的统一报告和修复路线图。支持 quick 快速体检模式。Use when user asks to audit, analyze, or review an entire codebase for design…
Codebase Audit is an agent skill from majiayu000/spellbook. 全面代码库审计 — 自适应并行深度分析(前后端契约、数据完整性、异常处理/安全、架构/技术债、配置/缓存),结构化 findings + 对抗验证 + 基线对比,输出按严重程度排序的统一报告和修复路线图。支持 quick 快速体检模式。Use when user asks to audit, analyze, or review an entire codebase for design issues, find hidden bugs, check architecture health, or asks '全面审查', '代码库审计', '分析设计问题', 'audit codebase', 'health check', '有哪些问题', '快速体检'. Also trigger when user asks to find silent degradation, data flow breakpoints, type mismatches between frontend and backend, or wants to understand technical debt across a project.
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 24 other files, including reference files (for example `evals/README.md`, `evals/evals.json` and `evals/expected-findings.json`).
It sits in Development, covering Technical debt and Responsive design. The repository describes itself as: Cross-runtime skills for Claude Code, Codex, and multi-agent workflows. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6310f81. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (Python, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
cargonpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Codebase Audit loads about 2.8k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 133 tokens; SKILL.md has 1,201 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from majiayu000/spellbook at commit 6310f81, republished under its MIT licence (© majiayu000). 1,201 words, ~2,758 tokens.
.claude/skills/codebase-audit/SKILL.md (or your agent's skills folder). This skill also uses 20 other files; get the full folder from GitHub.Comprehensive codebase audit that adapts its agent configuration to the project's tech stack, forces structured findings, adversarially verifies Critical/High findings before they enter the report, diffs against the previous audit's ledger (resolved / still-open / new), and outputs a severity-sorted report plus a phased repair roadmap.
references/agent-prompts.md.model param on all agents so they inherit the session model (usually the strongest available). Only override upward if the session model is clearly weak for cross-file reasoning. Never hardcode a specific model name in this skill.unverified in the report.<target>/.audit/ after the user invokes this skill..gitignore, CI config, remote issues, PR state, or anything outside the requested audit/report scope.[REDACTED] in findings, reports, and ledger entries; never reproduce the literal. This redacted snippet satisfies the code-evidence requirement.{TARGET_DIR}, not the assistant's incidental cwd.evals/expected-findings.json or eval README files when auditing the planted-bug fixture.resolved.| Mode | Trigger | Agents | Verify pass | Ledger |
|---|---|---|---|---|
| full (default) | plain invocation, "全面审查" | 3–5 by stack (+ optional dims) | yes | yes |
| quick | "quick" in args, "快速体检" | 2 (Silent Degradation & Security; Data Integrity & Registry) | no — all findings labeled unverified | yes |
Optional dimensions (full mode only, enable when user asks or the repo obviously needs them):
tests — test quality: assertion strength, skip markers, coverage of critical paths (Agent 6)concurrency — races, blocking calls in async, leaked tasks/goroutines (Agent 7)package.json/tsconfig.json → TS/JS; pyproject.toml/requirements.txt → Python; Cargo.toml → Rust; go.mod → Go; multiple → full-stack.tokei <target> (fallback: find <target> -name '*.<ext>' | xargs wc -l), excluding vendored/generated code. If effective size ≥ 400K LOC, split each agent's scope by top-level directory and note the split in the report.node_modules/, vendor/, target/, dist/, build/, .git/, lockfiles, generated code.<target>/.audit/findings.json if it exists — this is the previous audit baseline (format: references/ledger-format.md).{TARGET_DIR} (never the assistant's incidental cwd), run each matching tool and feed raw output to the Error Handling & Security prompt:cargo auditnpm auditpyproject.toml / setup.py): pip-audit .requirements.txt): pip-audit -r requirements.txtpip-audit .govulncheck ./...
If a required tool is unavailable, the report must state 依赖审计降级跳过: <tool>; never omit the degradation silently.Pick the configuration by detected stack. Full prompt templates in references/agent-prompts.md; prepend the read-only preamble and inject {TARGET_DIR} / {STACK_INFO} into each.
Full-Stack (5 agents) — frontend + backend both present:
| # | Dimension | Scope (merged) |
|---|---|---|
| 1 | Frontend-Backend Contract | Type consistency + rendering pipeline + serialization boundaries. Reads BOTH sides. |
| 2 | Data Integrity & Flow | End-to-end pipeline tracing, field dropping, declaration-execution gaps, registry coverage alignment. |
| 3 | Error Handling & Security | Silent degradation, exception patterns, secrets, injection, unsafe deserialization. |
| 4 | Architecture & Code Quality | Layer violations, god objects, duplication/drift, extension cost, registry cross-reference. |
| 5 | Config & Persistence | Config completeness, cache key/integrity, DB schema, temp files, state persistence. |
Backend-Only (4 agents): replace #1 with "API Contract & Data Integrity" (which absorbs #2's data-flow/registry scope — do NOT also dispatch #2); keep #3–#5. Frontend-Only (3 agents): Component Architecture & Rendering; Error Handling & Code Quality; Config & Build. Quick mode (2 agents): Silent Degradation & Security (= #3); Data Integrity & Registry (= #2 core).
Fallback-path agent types (when using the Agent tool instead of Workflow): agent availability is environment-specific — check the subagent registry visible in the current session and use only type names that appear there. Never invent aliases (there is no generic reviewer type). If no specialized type matches, use general-purpose (or the environment's default catch-all) for every dimension; the prompts are self-contained. See the example mapping in references/agent-prompts.md.
Preferred — Workflow tool (skill invocation is the user's opt-in): use the script in references/workflow-template.md. It schema-forces every finder's output into structured findings, then pipelines each dimension's Critical/High findings straight into adversarial verify agents (no barrier — verification starts while other dimensions are still scanning).
Fallback — Agent tool (if Workflow is unavailable): launch all finder agents in a SINGLE message; prompts already demand the same JSON output. After they return, launch one verify agent per Critical/High finding (also batched in one message), using the verify prompt from references/workflow-template.md.
Dedup:
Verification results:
confirmed=false findings do NOT enter the main report; list them in an appendix "Refuted by verification" with the refutation reason (keeps the work auditable).unverified.Ledger diff (skip if no previous ledger — everything is new):
resolved; if still present but missed, re-add as still-open.new / still-open.<target>/.audit/findings.json. If the repo is tracked and .audit/ isn't ignored, suggest adding it to .gitignore (don't edit .gitignore yourself).Write the full report to <target>/audit-report-YYYY-MM-DD.md, then post a chat summary: counts per severity, top Criticals, ledger delta (N resolved / N still-open / N new), dependency-audit status, and the roadmap.
Report body requirements:
file:line; impact is an inference with confidence; repair advice is a recommendation with stated assumptions.Report structure:
# [Project] Codebase Audit Report
> Date / Target / Stack / Mode / Agents / Dependency audit / Previous audit: date or "none"
## Summary
| Level | Count | Verified | Key Areas |
## Delta vs Previous Audit (omit if first audit)
Resolved: N (list) | Still-open: N | New: N
## Critical (Fix Immediately)
Per finding: file:line, code snippet, risk, fix suggestion, verify status.
## High / P1 (Fix This Week) — grouped by category
## Medium / P2 (Plan to Fix) — labeled unverified where applicable
## Refuted by Verification — appendix: finding + refutation reason
## Repair Roadmap
| Phase | Scope | Est. Files || Level | Criteria |
|---|---|
| Critical | Data loss, rendering failure, security vulnerability, complete feature breakage affecting users NOW |
| High/P1 | Silent degradation (user sees wrong/incomplete output), type mismatches causing data truncation, missing config causing empty output, architectural violations blocking development |
| Medium/P2 | Code duplication, inconsistent patterns, suboptimal error handling, tech debt that slows development but doesn't break features |
references/agent-prompts.md — read-only preamble + prompt templates (Agents 1–7)references/stack-patterns.md — per-stack search patternsreferences/workflow-template.md — Workflow script, finding/verdict schemas, verify promptreferences/ledger-format.md — ledger JSON schema and matching rulesevals/ — planted-bug fixture; evals measure recall against evals/expected-findings.json© majiayu000, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 20 other files (references) in skills/codebase-audit of majiayu000/spellbook.
Open the folder on GitHubat commit 6310f81
Codebase Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codebase Audit this skillmajiayu000/spellbook | 286 | — | ~2.8k | Automated safety check: Pass | MIT | |
| Ostackmr-daedalium/ostack-saas | 114 | — | ~6.1k | Automated safety check: Notes | MIT | |
| Local Log DebugUniClipboard/UniClipboard | 1.9k | — | ~2.6k | Automated safety check: Pass | AGPL-3.0 | |
| Openocd Jtagmohitmishra786/low-level-dev-skills | 253 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Gearcoleco Debuggingdrhelius/Gearcoleco | 141 | — | ~3.5k | Automated safety check: Pass | GPL-3.0 | |
| Dbgtheodo-group/debug-that | 158 | — | ~2.2k | Automated safety check: Pass | MIT |
mr-daedalium/ostack-saas
Fast headless browser for QA testing and site dogfooding. An agent skill from mr-daedalium/ostack-saas.
UniClipboard/UniClipboard
Inspect and analyze uniclipboard's local JSONL logs on a SINGLE machine — query, filter, and time-merge the per-role (gui/daemon/cli) log files to answer "what just happened" or trace a symptom…
mohitmishra786/low-level-dev-skills
OpenOCD skill for embedded hardware debugging. An agent skill from mohitmishra786/low-level-dev-skills.
drhelius/Gearcoleco
Debug and trace ColecoVision and Super Game Module games using the Gearcoleco emulator MCP server.
theodo-group/debug-that
Debug applications using the dbg CLI debugger. An agent skill from theodo-group/debug-that.
JasonMa0012/MooaToon
A skill your agent uses when debugging UE C++ crashes, runtime bugs, or unexpected behavior with Rider MCP available.
majiayu000/spellbook
Audits and repairs how coding-agent Skills are owned, copied and exposed across runtimes, from canonical sources to quarantine and retirement.
majiayu000/spellbook
Scans a repository for real evidence and proposes, or on request writes, a small stack of root and scoped AGENTS.md files with validation commands and generated-file boundaries.
majiayu000/spellbook
Plans, produces or diagnoses evidence-backed product demo videos: script, capture plan, pacing checks and verified final media built on real product behavior.
majiayu000/spellbook
Single entry point that routes long or ambiguous agent tasks, checks live state, bounds autonomous loops and leaves a resumable handoff.
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
majiayu000/spellbook
Product management helpers: a RICE scoring script, an interview transcript analyzer and PRD templates for prioritizing features, synthesizing research and writing requirements.
Categories
全面代码库审计 — 自适应并行深度分析(前后端契约、数据完整性、异常处理/安全、架构/技术债、配置/缓存),结构化 findings + 对抗验证 + 基线对比,输出按严重程度排序的统一报告和修复路线图。支持 quick 快速体检模式。Use when user asks to audit, analyze, or review an entire codebase for design…. Codebase Audit is an agent skill from majiayu000/spellbook. 全面代码库审计 — 自适应并行深度分析(前后端契约、数据完整性、异常处理/安全、架构/技术债、配置/缓存),结构化 findings + 对抗验证 + 基线对比,输出按严重程度排序的统一报告和修复路线图。支持 quick 快速体检模式。Use when user asks to audit, analyze, or review an entire codebase for design issues, find hidden bugs, check architecture health, or asks '全面审查', '代码库审计', '分析设计问题', 'audit codebase', 'health check', '有哪些问题', '快速体检'.
Codebase Audit fits situations like: user asks to audit; review an entire codebase for design issues; find hidden bugs; check architecture health.
Run `npx skills add majiayu000/spellbook --skill codebase-audit -a claude-code`. Or copy the skill folder (skills/codebase-audit in majiayu000/spellbook) into .claude/skills/codebase-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add majiayu000/spellbook --skill codebase-audit -a codex`. Or copy the skill folder (skills/codebase-audit in majiayu000/spellbook) into .agents/skills/codebase-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add majiayu000/spellbook --skill codebase-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codebase-audit, .gemini/skills/codebase-audit, .github/skills/codebase-audit and .opencode/skills/codebase-audit in your project.
Going by SKILL.md and its folder, Codebase Audit needs Python for the scripts in its folder and the command-line tools its instructions call (cargo and npm). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Codebase Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Codebase Audit: Ostack (mr-daedalium/ostack-saas, 114 stars), Local Log Debug (UniClipboard/UniClipboard, 1.9k stars), Openocd Jtag (mohitmishra786/low-level-dev-skills, 253 stars) and Gearcoleco Debugging (drhelius/Gearcoleco, 141 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
majiayu000 (a GitHub user) maintains it in majiayu000/spellbook, which has 286 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 8, 2026.
Source: majiayu000/spellbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.