Agent skill

Dx Audit

by mblode in mblode/agent-skills

Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration.

MITAuto-check passed

Install Dx Audit

skills CLI
$ npx skills add mblode/agent-skills --skill dx-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mblode/agent-skills dx-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mblode/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dx-audit .claude/skills/dx-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dx-audit
GitHub stars
143
Token cost
~2.4k tokens
SKILL.md length
1,217 words
Files
44 (incl. references)
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration.

  • Works in 6 steps: Lock the public surface → Gather evidence, then stop → Dispatch rules candidate-first → …
  • Asked to audit my CLI
  • SKILL.md covers Modes, Audit progress, Reference files and Gotchas, plus 1 more section
  • Calls npx, git and node

What it does

Dx Audit is an agent skill from mblode/agent-skills. Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration. Use when asked to "audit my CLI", "review my SDK", or diagnose package type resolution.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 46 other files, including reference files (for example `evals/evals.json`, `evals/evaluation-scenarios.md` and `references/standards-map.md`).

The repository describes itself as: Nobody ships AI slop on purpose. These skills make sure you don’t. The licence is MIT.

When your agent uses it

  • Asked to audit my CLI
  • Diagnose package type resolution

Example prompts

  • “audit my CLI”
  • “review my SDK”
  • “Use the dx-audit skill to audit libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and…”
  • “/dx-audit”

Requirements

  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Lock the public surface
  2. Gather evidence, then stop
  3. Dispatch rules candidate-first
  4. Rank root causes, not instances
  5. Report or fix
  6. Verify on the same scope

What it can do on your machine

Read from SKILL.md and the folder at commit cef4cfa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • git
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dx Audit loads about 2.4k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 56 tokens; SKILL.md has 1,217 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mblode/agent-skills at commit cef4cfa, republished under its MIT licence (© mblode). 1,217 words, ~2,422 tokens.

Download SKILL.mdSave it as .claude/skills/dx-audit/SKILL.md (or your agent's skills folder). This skill also uses 43 other files; get the full folder from GitHub.
name
dx-audit
description
Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration. Use when asked to "audit my CLI", "review my SDK", or diagnose package type resolution.

DX Audit

Audit or improve what developers import, run, configure, or read when something fails.

  • IS: a bounded review of public APIs, developer-facing errors, CLI commands, exported types, install and first-run behavior, and config, with fixes only when asked.
  • IS NOT: a repo-wide quality sweep (tidy), end-user UI (ui-design Audit mode), agent trust review (ax-audit), public site or docs agent scores (agent-ready), docs prose or a README (ghostwriter), repository architecture (codebase-architecture), or building a new CLI (scaffold-cli).

Modes

Pick the narrowest mode the request supports, and write a one-line scope receipt before reading code:

ModeWhenOutput
Targeted (default)a named or changed public surfacefindings report, read-only
Fixthe user says fix, improve, simplify, or implementlocalized edits inside the receipt, then verification
Exhaustivethe user explicitly asks for the whole package or every public surfaceevery material finding, partitioned by surface
text
Scope: <mode>; surfaces: <commands/exports/config>; prefixes: <err-, cli->; excludes: <UI, docs, architecture, private internals>

"DX", "gold standard", and "review holistically" do not by themselves widen a targeted audit into exhaustive. When several skills are invoked together, this one owns only the surfaces above.

Audit progress

text
DX audit progress:
- [ ] 1. Lock the public surface and write the scope receipt
- [ ] 2. Gather local evidence and run the safe probes
- [ ] 3. Select prefixes, then open candidate rules
- [ ] 4. Rank root causes
- [ ] 5. Report, or fix when asked
- [ ] 6. Verify on the same scope
1. Lock the public surface

Start from git diff against the normal base and keep only changed files reachable from a public entry point: package.json exports or bin, a command registry, an exported type, a documented config loader, or an observed error path. With no useful diff, use the command, export, error, or config the user named. A private helper enters scope only through a public caller.

2. Gather evidence, then stop
  1. Local instructions, the manifest, and the diff or named entry point.
  2. Direct public dependencies and the nearest tests that pin behavior.
  3. Safe probes against the local build:
    • CLI: --help, --version, one success path, one invalid-input path, and the same command with stdout piped (| cat) to see non-TTY behavior. Never trigger a real mutation to test DX; use --dry-run where it exists.
    • Package: npx publint and npx @arethetypeswrong/cli --pack . after a build. These inspect packaging, but packing may invoke lifecycle scripts. Inspect those scripts first or use a disposable checkout before calling --pack.
  4. The prior release contract, only when the diff changes a public export, signature, or return shape.

Stop when the behavior is proven, disproven, private, or out of scope. External research is for an explicit comparison request or a named uncertainty local evidence cannot resolve; references/standards-map.md carries the standards this skill already leans on.

3. Dispatch rules candidate-first

Read rules/_sections.md, then select prefixes by surface:

PriorityPrefixCategoryDefault impactRules
1api-Public API and SDKCRITICAL7
2err-Developer-facing errorsCRITICAL5
3cli-CLI UX for humans and agentsHIGH13
4types-Exported type ergonomicsHIGH5
5onboard-Install and first runHIGH5
6config-Config ergonomicsMEDIUM3
SurfacePrefixes
Public API entry pointapi-, types-, reached err- paths
CLI commandcli-, reached err- paths
Exported declarationstypes-, plus api- when behavior changed
Install, package.json, first runonboard-
Config loaderconfig-, reached err- paths

Applicability outranks priority: a CLI-only audit never loads api- because API rules rank higher.

Targeted mode: list the filenames for the selected prefixes (the names are the checklist), look for concrete evidence, then open only the rule files a finding needs. Exhaustive mode: read every rule in the selected prefixes.

Capability gates, applied inside a selected prefix:

  • Structured JSON input, schema introspection, and compact polling snapshots apply when automation or agent use is promised, requested, or already supported.
  • Dry-run and confirmation apply to destructive, expensive, or hard-to-reverse mutations.
  • Progress and resume apply to operations that can block, outlive one command, or be retried after ambiguous output.
  • stdin applies when the command semantically accepts file or stream data.
  • Stable-contract comparison applies only when a public contract changed.
4. Rank root causes, not instances
  • Order CRITICAL, HIGH, MEDIUM by each cited rule's frontmatter impact, copied exactly. Impact is the rule's declared consequence, not a confidence score: exit 0 on failure in one subcommand is still HIGH, because the CI gate it defeats is the same. Open the rule file before citing it, since an id cited from memory drifts from the file, and drop the citation if no such file exists.
  • Merge repeated instances of one root cause into one finding with up to three representative locations. Missing JSDoc, error codes, or --json across a surface is one finding, not one per symbol.
  • A missing feature with no current consumer path is not a defect.
  • Targeted mode: every CRITICAL finding, then the highest-value remainder up to five total; summarize the rest by category.
Show full SKILL.md (463 more words)Show less
5. Report or fix

Audit requests are read-only. A fix request authorizes localized changes inside the receipt, not a redesign of adjacent docs, UI, or architecture.

markdown
## DX Audit

Scope: `tool status` CLI; `err-`, `cli-`; 4 files inspected.

### Findings
- [HIGH] `cli-idempotent-resume` at `src/start.ts:42`: retrying the same target creates a second job.
  Fix: return the existing job id and state unless the caller passes `--fresh`.

### Deferred
- 2 lower-impact config candidates were outside the locked CLI scope.

List only files with findings; a clean surface gets one pass line naming the surfaces and rule files checked. In fix mode, replace Deferred with Changed and Verification (the exact commands or probes that passed). Length follows findings, not the template.

6. Verify on the same scope

Re-open every touched or cited location, rerun the same probes and focused project checks, and reapply the same candidate rules. Match the evidence to the claim: a clean build does not prove CLI behavior, a runtime probe does not prove exported types, and only attw or a consumer-style tsc import proves a types resolution.

Reference files

FileRead when
rules/_sections.mdEvery audit, for prefix applicability and priority
rules/<prefix>-*.mdA candidate has evidence, or exhaustive mode
references/standards-map.mdA finding needs an external citation, the user asks why something is a rule, or a borderline call needs a tie-break
rules/_template.mdAdding or editing a rule

Gotchas

  • npx <pkg> and a global install probe the registry copy, not the working tree. --help, exit codes, and error strings then describe a released version. Build, then invoke the local entry point (node ./dist/cli.js).
  • process.stdout.isTTY is undefined under a pipe, not false. A guard written as isTTY === false never disables color or spinners when piped, so ANSI codes reach the redirected file. Probe with | cat rather than trusting the guard.
  • process.exit(1) right after console.log can truncate the output it was meant to explain. stdout writes are asynchronous when piped, so a CLI that prints usage and calls exit() can emit nothing under | cat. The fix is process.exitCode = 1 and a natural return (cli-exit-codes).
  • An exports map that reads correctly can still resolve wrong. "require" pointing at a .js file under "type": "module" masquerades as CJS, and a types condition listed after import is never reached. publint and attw catch both; reading the map does not (onboard-exports-resolve-typed).
  • ui-design Audit mode: rendered end-user frontend quality and accessibility
  • ax-audit: same files, different reader; asks whether an agent can operate and recover, where this skill asks whether a developer finds the surface ergonomic
  • scaffold-cli: builds a new CLI with these patterns already in place; this skill audits what exists
  • tidy: general correctness and structure of a diff
  • agent-ready: public HTTP/docs agent scores (AFDocs, Is Agentic, Is It Agent Ready); this skill audits the package once it exists
  • ghostwriter: documentation prose, README structure, and the first-reader narrative
  • agents-md: AGENTS.md and CLAUDE.md instruction files
  • codebase-architecture: repository structure and module contracts inside the repo, rather than the surface a package ships outward

Maintenance only: evals/evals.json and evals/evaluation-scenarios.md hold regression scenarios for changes to this skill; neither loads during a user task.

© mblode, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 43 other files (references) in skills/dx-audit of mblode/agent-skills.

  • SKILL.md
  • evals/evals.json
  • evals/evaluation-scenarios.md
  • references/standards-map.md
  • rules/_sections.md
  • rules/_template.md
  • rules/api-argument-order.md
  • rules/api-async-consistency.md
  • rules/api-naming-consistency.md
  • rules/api-no-hidden-side-effects.md
  • rules/api-predictable-return-shape.md
  • rules/api-sensible-defaults.md
  • rules/api-stable-contract.md
  • rules/cli-agent-input-hardening.md
  • rules/cli-delta-polling.md
  • rules/cli-exit-codes.md
  • rules/cli-flag-naming.md
  • rules/cli-help-and-version.md
  • … and 26 more

Open the folder on GitHubat commit cef4cfa

Compare with similar skills

Dx Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dx Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dx Audit this skillmblode/agent-skills143—~2.4kAutomated safety check: PassMIT
Soroban Contract Auditsickn33/agentic-awesome-skills47k1 repos~1.4kAutomated safety check: PassMIT
Audit Map Contractben-manes/caffeine18k—~2kAutomated safety check: PassApache-2.0
Cross Platform Contract Propagation Auditsickn33/agentic-awesome-skills47k1 repos~2.3kAutomated safety check: PassMIT
Audit Contract Driftben-manes/caffeine18k—~1.1kAutomated safety check: PassApache-2.0
Libraryasgeirtj/system_prompts_leaks69k—~4kAutomated safety check: PassCC0-1.0

Similar skills

  • Soroban Contract Audit

    sickn33/agentic-awesome-skills

    Soroban smart contract security audit register: authorization checks, panic pathways, integer overflows, and storage footprint verification for Stellar.

    47k GitHub starsUsed in 1 repo~1.4k tokens
    SecurityAuto-check passed
  • Audit Map Contract

    ben-manes/caffeine

    Audit ConcurrentMap and Map contract compliance for asMap() view

    18k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Cross Platform Contract Propagation Audit

    sickn33/agentic-awesome-skills

    A skill your agent uses when auditing whether a field, enum, flag, or API contract propagates consistently across storage, services, clients, analytics, and tests.

    47k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Audit Contract Drift

    ben-manes/caffeine

    Find places where documented API contracts and the implementation diverge

    18k GitHub stars~1.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Library

    asgeirtj/system_prompts_leaks

    Use ChatGPT Library when the user mentions their Library, asks to find or work with a Library-backed file, Site, or named file that may be in the Library, or wants to organize Library folders…

    69k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Audit Third Party Contracts

    ben-manes/caffeine

    Verify every third-party and sharp-edged JDK API usage against the contract the upstream documentation actually states

    18k GitHub stars~943 tokensUpdated 2 days ago
    Auto-check passed

More from mblode/agent-skills

All 28 skills in this repo
  • Agent Ready

    mblode/agent-skills

    Implements agent-readiness on public sites and docs from Mintlify Agent Score, AFDocs, Is Agentic, Is It Agent Ready, or url-discovery-bench reports, or from server logs of agents 404ing on guessed…

    143 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed
  • Agent Skills Creator

    mblode/agent-skills

    Creates and improves portable Agent Skills with a validator, routing scenarios, and evidence-based keep, cut, merge, or retire decisions.

    143 GitHub stars~2.8k tokensUpdated 2 days ago
    Auto-check passed
  • Chat History

    mblode/agent-skills

    Recovers decisions, previous fixes, research, and what followed a prompt from past AI conversations, with source evidence.

    143 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • CI Speedup

    mblode/agent-skills

    Cuts the wait from push to green by measuring a pipeline's critical path from run timestamps, then splitting, sharding, trimming setup and sharing test module state, with a before/after ledger.

    143 GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • PR Babysitter

    mblode/agent-skills

    Monitors or repairs an open GitHub PR: CI failures, conflicts, review threads, and merge readiness, reporting state changes.

    143 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • App Verification

    mblode/agent-skills

    Builds and maintains a repo's own verification harness (verify CLI, doctor, worktree isolation, feature map, seed data) and a reproduce-first bug handoff.

    143 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Questions about Dx Audit

What does Dx Audit do?

Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration. Dx Audit is an agent skill from mblode/agent-skills. Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration.

When should I use Dx Audit?

Dx Audit fits situations like: asked to audit my CLI; diagnose package type resolution.

How do I install Dx Audit in Claude Code?

Run `npx skills add mblode/agent-skills --skill dx-audit -a claude-code`. Or copy the skill folder (skills/dx-audit in mblode/agent-skills) into .claude/skills/dx-audit in your project. Claude Code loads it when a task matches its description.

How do I install Dx Audit in Codex?

Run `npx skills add mblode/agent-skills --skill dx-audit -a codex`. Or copy the skill folder (skills/dx-audit in mblode/agent-skills) into .agents/skills/dx-audit in your project. Codex loads it when a task matches its description.

Can I use Dx Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mblode/agent-skills --skill dx-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dx-audit, .gemini/skills/dx-audit, .github/skills/dx-audit and .opencode/skills/dx-audit in your project.

What does Dx Audit need to run?

Going by SKILL.md and its folder, Dx Audit needs the command-line tools its instructions call (npx, git and node). Our summary lists: Node.js.

Does Dx Audit access the network?

SKILL.md contains no URLs. Its commands use npx and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dx Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dx Audit use?

Dx Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dx Audit use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Dx Audit?

Skills that share tags, products or a category with Dx Audit: Soroban Contract Audit (sickn33/agentic-awesome-skills, 47k stars), Audit Map Contract (ben-manes/caffeine, 18k stars), Cross Platform Contract Propagation Audit (sickn33/agentic-awesome-skills, 47k stars) and Audit Contract Drift (ben-manes/caffeine, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dx Audit?

mblode (a GitHub user) maintains it in mblode/agent-skills, which has 143 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 6, 2026.

Source: mblode/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.