Agent skill

Skill Audit

by majiayu000 in majiayu000/spellbook

Audit, design, categorize, distribute, and measure agent skills using lessons from Anthropic's Lessons from building Claude Code: How we use skills.

MITAuto-check passedAgent Workflows

Install Skill Audit

skills CLI
$ npx skills add majiayu000/spellbook --skill skill-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install majiayu000/spellbook skill-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skill-audit .claude/skills/skill-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-audit
GitHub stars
287
Token cost
~1.6k tokens
SKILL.md length
834 words
Files
4 (incl. references, assets)
Skills in repo
97
Repo updated
First seen
Licence
MIT

At a glance

Audit, design, categorize, distribute, and measure agent skills using lessons from Anthropic's Lessons from building Claude Code: How we use skills.

  • Works in 7 steps: Decide Whether This Should Be A Skill → Classify The Skill → Draft A Skill Brief → …
  • Reviewing an existing skill
  • SKILL.md covers Core Principle, Workflow, Output Format and Gotchas
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Skill Audit is an agent skill from majiayu000/spellbook. Audit, design, categorize, distribute, and measure agent skills using lessons from Anthropic's Lessons from building Claude Code: How we use skills. Use when reviewing an existing skill, deciding whether a workflow deserves a skill, planning a skill library, turning team knowledge into skills, choosing skill categories, writing trigger descriptions, designing progressive disclosure, or planning skill marketplace and usage measurement.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files and assets (for example `assets/skill-brief-template.md`, `references/skill-taxonomy.md` and `references/writing-and-operations.md`).

It sits in Agent Workflows. The repository describes itself as: Cross-runtime skills for Claude Code, Codex, and multi-agent workflows. The licence is MIT.

When your agent uses it

  • Reviewing an existing skill
  • Deciding whether a workflow deserves a skill
  • Planning a skill library
  • Turning team knowledge into skills

Example prompts

  • “/skill-audit”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Decide Whether This Should Be A Skill
  2. Classify The Skill
  3. Draft A Skill Brief
  4. Design Progressive Disclosure
  5. Add Operational Design
  6. Hand Off To Implementation
  7. Check The Reliable Skill Contract

What it can do on your machine

Read from SKILL.md and the folder at commit ed52af7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • claude.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Audit loads about 1.6k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 834 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from majiayu000/spellbook at commit ed52af7, republished under its MIT licence (© majiayu000). 834 words, ~1,602 tokens.

Download SKILL.mdSave it as .claude/skills/skill-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
skill-audit
description
Audit, design, categorize, distribute, and measure agent skills using lessons from Anthropic's Lessons from building Claude Code: How we use skills. Use when reviewing an existing skill, deciding whether a workflow deserves a skill, planning a skill library, turning team knowledge into skills, choosing skill categories, writing trigger descriptions, designing progressive disclosure, or planning skill marketplace and usage measurement.

Skill Audit

Use this skill to audit existing skills, turn workflow knowledge into useful agent skills, and review skill libraries at the strategy level. It complements skill-creator: use this skill to decide what a skill should be, how it should fit a library, and what needs improvement; use skill-creator when the user wants the concrete SKILL.md implementation and eval loop.

This workflow is based on Anthropic's June 3, 2026 blog post, "Lessons from building Claude Code: How we use skills": https://claude.com/blog/lessons-from-building-claude-code-how-we-use-skills

Core Principle

A good skill is not "some markdown about a topic." It is a compact extension point that gives the agent non-obvious domain knowledge, reusable files, deterministic helpers, setup rules, verification habits, and guardrails at the moment they matter.

Workflow

1. Decide Whether This Should Be A Skill

Create or improve a skill only when at least one of these is true:

  • The workflow repeats often enough that users should not re-explain it.
  • The agent regularly makes the same domain-specific mistake.
  • The work needs local scripts, templates, examples, assets, hooks, or setup.
  • The output must follow a stable structure or verification path.
  • The knowledge is team-specific, product-specific, infrastructure-specific, or otherwise not inferable from general model knowledge.

Do not make a skill when the content only restates obvious coding behavior, generic best practices, or one-off instructions.

2. Classify The Skill

Read references/skill-taxonomy.md and classify the candidate into exactly one primary category. If it appears to span several categories, tighten the scope or split it.

Report:

  • Primary category
  • Secondary category, if truly needed
  • Why this category is the cleanest fit
  • What would make the skill too broad
3. Draft A Skill Brief

Use assets/skill-brief-template.md for the output. Fill it with:

  • Trigger description written for the model, not as a human-facing summary
  • High-signal knowledge the model would not otherwise know
  • Gotchas and failure modes
  • Autonomy boundaries: what the skill may do directly, and what must be escalated before acting
  • Evidence-backed pushback rules: when the agent should challenge the proposed path and what evidence it must cite
  • Feedback loop: where repeated corrections, false-success signals, or manual recovery steps should be promoted
  • Progressive disclosure map: SKILL.md vs references vs scripts vs assets
  • Setup requirements or config questions
  • Verification strategy
  • Reliable Skill Contract coverage for high-value workflow skills
  • Distribution path
  • Measurement plan
4. Design Progressive Disclosure

Keep SKILL.md focused on activation, decisions, and the main workflow. Move details into support files:

  • references/ for tables, API conventions, taxonomy, playbooks, and long docs
  • scripts/ for deterministic actions or repetitive checks
  • assets/ for templates, report formats, starter files, or examples
  • agents/ for specialized subagent prompts when the repo supports them
  • evals/ for realistic prompts and objective assertions

Tell the agent exactly when to read each support file.

5. Add Operational Design

Read references/writing-and-operations.md when deciding:

  • Whether a setup step or config file is needed
  • Whether the skill should remember past runs
  • Whether scripts or hooks would improve reliability
  • Whether the skill belongs in a repo, a shared plugin, or a marketplace
  • What usage signals indicate undertriggering, overtriggering, or decay
Show full SKILL.md (332 more words)Show less
6. Hand Off To Implementation

When the user wants the skill built, pass the brief into skill-creator and ask it to implement the files, generate realistic test prompts, and run validation.

If editing an existing skill, include the exact file paths and the smallest content changes needed. Do not rewrite unrelated skill behavior.

7. Check The Reliable Skill Contract

For agent-workflow, delivery, PR, automation, or high-impact skills, use skill-lifeguard or apply the same five-element score:

  • explicit negative examples
  • verification checkpoints
  • machine-checkable done conditions
  • replay or smoke hooks with a log-to-patch loop
  • drift signal detection

Report each element as present, partial, missing, or deferred. A missing element is not always a blocker, but it must be visible in the brief and patch plan.

Output Format

For advisory requests, answer with:

  1. Decision: create, improve, split, merge, or do not create
  2. Category: one primary taxonomy category
  3. Skill brief: filled from the template
  4. Implementation notes: files to create/edit and validation commands
  5. Reliable Skill Contract score, when applicable
  6. Risks: overbreadth, obviousness, missing setup, missing verification, or weak trigger description

For repository work, actually create or update the files, then run the repo's skill validation command.

Gotchas

  • Do not make a knowledge dump. Convert article or team knowledge into decisions, checklists, templates, and verification.
  • Do not put all details in SKILL.md. Long reference material belongs in support files.
  • Do not write a description as a marketing summary. It must name concrete user phrases and contexts that should trigger the skill.
  • Do not railroad the agent with brittle instructions. Provide defaults, decision criteria, and escape hatches.
  • Do not ship a skill without at least a lightweight way to tell if it worked: validation commands, example prompts, expected artifacts, or usage metrics.
  • Do not encode vague autonomy such as "be proactive." Name the direct actions, escalation boundaries, and end-state checks that should change behavior.
  • Do not call a brittle skill "reliable" without negative examples, checkpoints, done conditions, replay or smoke hooks, and drift signals.

© majiayu000, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references, assets) in skills/skill-audit of majiayu000/spellbook.

  • SKILL.md
  • assets/skill-brief-template.md
  • references/skill-taxonomy.md
  • references/writing-and-operations.md

Open the folder on GitHubat commit ed52af7

Compare with similar skills

Skill Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Audit this skillmajiayu000/spellbook287—~1.6kAutomated safety check: PassMIT
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
Hook Development for Claude Code Pluginsanthropics/claude-plugins-official38k10 repos~4.1kAutomated safety check: NotesApache-2.0
Using Superpowersfarm-fe/farm5.6k36 repos~1.4kAutomated safety check: PassMIT
Executing Plans Inlineobra/superpowers297k2 repos~5.1kAutomated safety check: PassMIT
Skill CreatorAzure/azqr79689 repos~8.2kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 10 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes
  • Using Superpowers

    farm-fe/farm

    A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions

    5.6k GitHub starsUsed in 36 repos~1.4k tokens
    Agent WorkflowsAuto-check passed
  • Executing Plans Inline

    obra/superpowers

    Has the agent carry out an implementation plan itself, task by task in the current session, keeping a ledger, proving each step with a test and ending with one whole-branch review.

    297k GitHub starsUsed in 2 repos~5.1k tokens
    Agent WorkflowsAuto-check passed
  • Skill Creator

    Azure/azqr

    Official

    Create new skills, modify and improve existing skills, and measure skill performance.

    796 GitHub starsUsed in 89 repos~8.2k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 7 repos~2.8k tokens
    Agent WorkflowsAuto-check passed

More from majiayu000/spellbook

All 97 skills in this repo
  • Skill Ecosystem Doctor

    majiayu000/spellbook

    Audits and repairs how coding-agent Skills are owned, copied and exposed across runtimes, from canonical sources to quarantine and retirement.

    287 GitHub stars~3k tokensUpdated 2 days ago
    Auto-check passed
  • AGENTS.md Scaffold

    majiayu000/spellbook

    Scans a repository for real evidence and proposes, or on request writes, a small stack of root and scoped AGENTS.md files with validation commands and generated-file boundaries.

    287 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Product Demo Builder

    majiayu000/spellbook

    Plans, produces or diagnoses evidence-backed product demo videos: script, capture plan, pacing checks and verified final media built on real product behavior.

    287 GitHub stars~3.3k tokensUpdated 2 days ago
    Auto-check passed
  • Flowguard Task Guard

    majiayu000/spellbook

    Single entry point that routes long or ambiguous agent tasks, checks live state, bounds autonomous loops and leaves a resumable handoff.

    287 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Product Manager Toolkit

    majiayu000/spellbook

    Product management helpers: a RICE scoring script, an interview transcript analyzer and PRD templates for prioritizing features, synthesizing research and writing requirements.

    287 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Skill Audit

What does Skill Audit do?

Audit, design, categorize, distribute, and measure agent skills using lessons from Anthropic's Lessons from building Claude Code: How we use skills. Skill Audit is an agent skill from majiayu000/spellbook. Audit, design, categorize, distribute, and measure agent skills using lessons from Anthropic's Lessons from building Claude Code: How we use skills.

When should I use Skill Audit?

Skill Audit fits situations like: reviewing an existing skill; deciding whether a workflow deserves a skill; planning a skill library; turning team knowledge into skills.

How do I install Skill Audit in Claude Code?

Run `npx skills add majiayu000/spellbook --skill skill-audit -a claude-code`. Or copy the skill folder (skills/skill-audit in majiayu000/spellbook) into .claude/skills/skill-audit in your project. Claude Code loads it when a task matches its description.

How do I install Skill Audit in Codex?

Run `npx skills add majiayu000/spellbook --skill skill-audit -a codex`. Or copy the skill folder (skills/skill-audit in majiayu000/spellbook) into .agents/skills/skill-audit in your project. Codex loads it when a task matches its description.

Can I use Skill Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add majiayu000/spellbook --skill skill-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-audit, .gemini/skills/skill-audit, .github/skills/skill-audit and .opencode/skills/skill-audit in your project.

What does Skill Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Skill Audit is instructions for the agent only.

Does Skill Audit access the network?

SKILL.md names 1 domain. As links in the text: claude.com. This is read from the text; nothing was executed.

Is Skill Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Skill Audit use?

Skill Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Audit use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.

What are the alternatives to Skill Audit?

Skills that share tags, products or a category with Skill Audit: MCP Server Builder (anthropics/skills, 180k stars), Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Using Superpowers (farm-fe/farm, 5.6k stars) and Executing Plans Inline (obra/superpowers, 297k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Audit?

majiayu000 (a GitHub user) maintains it in majiayu000/spellbook, which has 287 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 8, 2026.

Source: majiayu000/spellbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.