Performs comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and maintainability.

Apache-2.0Auto-check passedDevelopment

Install Code Auditor

skills CLI
$ npx skills add mhattingpete/claude-skills-marketplace --skill code-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mhattingpete/claude-skills-marketplace code-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mhattingpete/claude-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/productivity-skills-plugin/skills/code-auditor .claude/skills/code-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-auditor
GitHub stars
680
Used in
1 other repo
Token cost
~896 tokens
SKILL.md length
303 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

Performs comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and maintainability.

  • Works in 6 steps: Architecture & Design → Code Quality → Security → …
  • User wants to audit code quality
  • SKILL.md covers When to Use, What It Analyzes, Approach and Thoroughness Levels, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Auditor is an agent skill from mhattingpete/claude-skills-marketplace. Performs comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and maintainability. Use when user wants to audit code quality, identify technical debt, find security issues, assess test coverage, or get a codebase health check.

Its SKILL.md is about 900 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code quality, Technical debt and Codebase onboarding. The repository describes itself as: Claude Code Skills for software engineering workflows - Git automation, testing, and code review. The licence is Apache-2.0.

When your agent uses it

  • User wants to audit code quality
  • Identify technical debt
  • Find security issues
  • Assess test coverage

Example prompts

  • “Use the code-auditor skill to perform comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and…”
  • “/code-auditor”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Architecture & Design
  2. Code Quality
  3. Security
  4. Performance
  5. Testing
  6. Maintainability

What it can do on your machine

Read from SKILL.md and the folder at commit b5b34bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Auditor loads about 896 tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 303 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~896

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mhattingpete/claude-skills-marketplace at commit b5b34bc, republished under its Apache-2.0 licence (© mhattingpete). 303 words, ~896 tokens.

Download SKILL.mdSave it as .claude/skills/code-auditor/SKILL.md (or your agent's skills folder).
name
code-auditor
description
Performs comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and maintainability. Use when user wants to audit code quality, identify technical debt, find security issues, assess test coverage, or get a codebase health check.

Code Auditor

Comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and maintainability.

When to Use

  • "audit the code"
  • "analyze code quality"
  • "check for issues"
  • "review the codebase"
  • "find technical debt"
  • "security audit"
  • "performance review"

What It Analyzes

1. Architecture & Design
  • Overall structure and organization
  • Design patterns in use
  • Module boundaries and separation of concerns
  • Dependency management
  • Architectural decisions and trade-offs
2. Code Quality
  • Complexity hotspots (cyclomatic complexity)
  • Code duplication (DRY violations)
  • Naming conventions and consistency
  • Documentation coverage
  • Code smells and anti-patterns
3. Security
  • Common vulnerabilities (OWASP Top 10)
  • Input validation and sanitization
  • Authentication and authorization
  • Secrets management
  • Dependency vulnerabilities
4. Performance
  • Algorithmic complexity issues
  • Database query optimization
  • Memory usage patterns
  • Caching opportunities
  • Resource leaks
5. Testing
  • Test coverage assessment
  • Test quality and effectiveness
  • Missing test scenarios
  • Testing patterns and practices
  • Integration vs unit test balance
6. Maintainability
  • Technical debt assessment
  • Coupling and cohesion
  • Ease of future changes
  • Onboarding friendliness
  • Documentation quality

Approach

  1. Explore using Explore agent (thorough mode)
  2. Identify patterns with Grep and Glob
  3. Read critical files for detailed analysis
  4. Run static analysis tools if available
  5. Synthesize findings into actionable report

Thoroughness Levels

  • Quick (15-30 min): High-level, critical issues only
  • Standard (30-60 min): Comprehensive across all dimensions
  • Deep (60+ min): Exhaustive with detailed examples

Output Format

markdown
# Code Audit Report

## Executive Summary
- Overall health score
- Critical issues count
- Top 3 priorities

## Findings by Category

### Architecture & Design
#### 🔴 High Priority
- [Finding with file:line reference]
  - Impact: [description]
  - Recommendation: [action]

#### 🟡 Medium Priority
...

### [Other categories]

## Prioritized Action Plan
1. Quick wins (< 1 day)
2. Medium-term improvements (1-5 days)
3. Long-term initiatives (> 5 days)

## Metrics
- Files analyzed: X
- Lines of code: Y
- Test coverage: Z%
- Complexity hotspots: N

Tools Used

  • Task (Explore agent): Thorough codebase exploration
  • Grep: Pattern matching for issues
  • Glob: Find files by type/pattern
  • Read: Detailed file analysis
  • Bash: Run linters, coverage tools

Success Criteria

  • Comprehensive coverage of all six dimensions
  • Specific file:line references for all findings
  • Severity/priority ratings (Critical/High/Medium/Low)
  • Actionable recommendations (not just observations)
  • Estimated effort for fixes
  • Both quick wins and long-term improvements

Integration

  • feature-planning: Plan technical debt reduction
  • test-fixing: Address test gaps identified
  • project-bootstrapper: Set up quality tooling

Configuration

Can focus on specific areas:

  • Security-only audit
  • Performance-only audit
  • Testing-only assessment
  • Quick architecture review

© mhattingpete, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in productivity-skills-plugin/skills/code-auditor of mhattingpete/claude-skills-marketplace.

Open the folder on GitHubat commit b5b34bc

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in mhattingpete/claude-skills-marketplace, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Code Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Auditor this skillmhattingpete/claude-skills-marketplace6801 repos~896Automated safety check: PassApache-2.0
Systematic Code Refactoringluongnv89/claude-howto42k—~3kAutomated safety check: PassMIT
Constraint-Driven Developmentaddyosmani/agent-skills102k2 repos~5.2kAutomated safety check: PassMIT
Code Refactoring Workflowluongnv89/claude-howto42k—~3.1kAutomated safety check: PassMIT
Tech Debt Analyzerailabs-393/ai-labs-claude-skills4542 repos~3.9kAutomated safety check: PassMIT
FIXME Resolvertailcallhq/forgecode7.6k—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Systematic Code Refactoring

    luongnv89/claude-howto

    Guides refactoring in phases based on Martin Fowler's method: research, test coverage check, planning and small tested steps, with your approval at each phase.

    42k GitHub stars~3k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Constraint-Driven Development

    addyosmani/agent-skills

    Records a project's quality bar in CONSTRAINTS.md and watches diffs for signs an agent quietly weakened it, such as suppressions, skipped tests or lowered thresholds.

    102k GitHub starsUsed in 2 repos~5.2k tokens
    DevelopmentAuto-check passed
  • Code Refactoring Workflow

    luongnv89/claude-howto

    Guides systematic, test-backed refactoring in the style of Martin Fowler, moving through research, planning and small incremental changes with your approval at each phase.

    42k GitHub stars~3.1k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Tech Debt Analyzer

    ailabs-393/ai-labs-claude-skills

    This skill should be used when analyzing technical debt in a codebase, documenting code quality issues, creating technical debt registers, or assessing code maintainability.

    454 GitHub starsUsed in 2 repos~3.9k tokens
    DevelopmentAuto-check passed
  • FIXME Resolver

    tailcallhq/forgecode

    Finds every FIXME comment in a codebase, groups related ones across files into one task, implements the work they describe and removes the comments once it is done.

    7.6k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Desloppify

    Git-on-my-level/codex-autorunner

    Codebase health scanner and technical debt tracker. An agent skill from Git-on-my-level/codex-autorunner.

    875 GitHub stars~3.4k tokensUpdated 6 days ago
    DevelopmentAuto-check passed

More from mhattingpete/claude-skills-marketplace

All 16 skills in this repo
  • Conversation Analyzer

    mhattingpete/claude-skills-marketplace

    Analyzes your Claude Code conversation history to identify patterns, common mistakes, and opportunities for workflow improvement.

    680 GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Architecture Diagram Creator

    mhattingpete/claude-skills-marketplace

    Create comprehensive HTML architecture diagrams showing data flows, business objectives, features, technical architecture, and deployment.

    680 GitHub stars~676 tokensUpdated 2 mo ago
    Auto-check passed
  • Code Transfer

    mhattingpete/claude-skills-marketplace

    Transfer code between files with line-based precision. An agent skill from mhattingpete/claude-skills-marketplace.

    680 GitHub stars~1k tokensUpdated 2 mo ago
    Auto-check passed
  • Dashboard Creator

    mhattingpete/claude-skills-marketplace

    Create HTML dashboards with KPI metric cards, bar/pie/line charts, progress indicators, and data visualizations.

    680 GitHub stars~489 tokensUpdated 2 mo ago
    Auto-check passed
  • Flowchart Creator

    mhattingpete/claude-skills-marketplace

    Create HTML flowcharts and process diagrams with decision trees, color-coded stages, arrows, and swimlanes.

    680 GitHub stars~518 tokensUpdated 2 mo ago
    Auto-check passed
  • Technical Doc Creator

    mhattingpete/claude-skills-marketplace

    Create HTML technical documentation with code blocks, API workflows, system architecture diagrams, and syntax highlighting.

    680 GitHub stars~604 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Code Auditor

What does Code Auditor do?

Performs comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and maintainability. Code Auditor is an agent skill from mhattingpete/claude-skills-marketplace. Performs comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and maintainability.

When should I use Code Auditor?

Code Auditor fits situations like: user wants to audit code quality; identify technical debt; find security issues; assess test coverage.

How do I install Code Auditor in Claude Code?

Run `npx skills add mhattingpete/claude-skills-marketplace --skill code-auditor -a claude-code`. Or copy the skill folder (productivity-skills-plugin/skills/code-auditor in mhattingpete/claude-skills-marketplace) into .claude/skills/code-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Code Auditor in Codex?

Run `npx skills add mhattingpete/claude-skills-marketplace --skill code-auditor -a codex`. Or copy the skill folder (productivity-skills-plugin/skills/code-auditor in mhattingpete/claude-skills-marketplace) into .agents/skills/code-auditor in your project. Codex loads it when a task matches its description.

Can I use Code Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mhattingpete/claude-skills-marketplace --skill code-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-auditor, .gemini/skills/code-auditor, .github/skills/code-auditor and .opencode/skills/code-auditor in your project.

What does Code Auditor need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Auditor is instructions for the agent only.

Does Code Auditor access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Auditor use?

Code Auditor is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Auditor use?

About 896 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Auditor?

Skills that share tags, products or a category with Code Auditor: Systematic Code Refactoring (luongnv89/claude-howto, 42k stars), Constraint-Driven Development (addyosmani/agent-skills, 102k stars), Code Refactoring Workflow (luongnv89/claude-howto, 42k stars) and Tech Debt Analyzer (ailabs-393/ai-labs-claude-skills, 454 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Auditor?

mhattingpete (a GitHub user) maintains it in mhattingpete/claude-skills-marketplace, which has 680 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on July 25, 2026.

Source: mhattingpete/claude-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.