MCP Dependency Drift Audit
sickn33/agentic-awesome-skills
Statically audit MCP configs for mutable npm/npx package references before approval or CI, without executing discovered MCP servers.
A skill your agent uses when reviewing a bundle-plugin for structural issues, version drift, skill quality, workflow integration, or security risks — before releasing, after changes, or after adding…
$ npx skills add OdradekAI/bundles-forge --skill auditing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OdradekAI/bundles-forge auditing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OdradekAI/bundles-forge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/auditing .claude/skills/auditing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "auditing" agent skill from https://github.com/OdradekAI/bundles-forge/tree/main/skills/auditing into .claude/skills/auditing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OdradekAI/bundles-forge/tree/main/skills/auditingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OdradekAI/bundles-forge --skill auditing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OdradekAI/bundles-forge auditing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OdradekAI/bundles-forge.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/auditing .agents/skills/auditing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "auditing" agent skill from https://github.com/OdradekAI/bundles-forge/tree/main/skills/auditing into .agents/skills/auditing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OdradekAI/bundles-forge --skill auditing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OdradekAI/bundles-forge auditing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OdradekAI/bundles-forge.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/auditing .cursor/skills/auditing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "auditing" agent skill from https://github.com/OdradekAI/bundles-forge/tree/main/skills/auditing into .cursor/skills/auditing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OdradekAI/bundles-forge.git --path skills/auditing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OdradekAI/bundles-forge --skill auditing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OdradekAI/bundles-forge auditing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OdradekAI/bundles-forge.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/auditing .gemini/skills/auditing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "auditing" agent skill from https://github.com/OdradekAI/bundles-forge/tree/main/skills/auditing into .gemini/skills/auditing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OdradekAI/bundles-forge auditingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OdradekAI/bundles-forge --skill auditing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OdradekAI/bundles-forge.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/auditing .github/skills/auditing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "auditing" agent skill from https://github.com/OdradekAI/bundles-forge/tree/main/skills/auditing into .github/skills/auditing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OdradekAI/bundles-forge --skill auditing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OdradekAI/bundles-forge auditing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OdradekAI/bundles-forge.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/auditing .opencode/skills/auditing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "auditing" agent skill from https://github.com/OdradekAI/bundles-forge/tree/main/skills/auditing into .opencode/skills/auditing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
auditingA skill your agent uses when reviewing a bundle-plugin for structural issues, version drift, skill quality, workflow integration, or security risks — before releasing, after changes, or after adding…
Auditing is an agent skill from OdradekAI/bundles-forge. Use when reviewing a bundle-plugin for structural issues, version drift, skill quality, workflow integration, or security risks — before releasing, after changes, or after adding skills. Auto-detects scope (full project vs skill vs workflow)
Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files, including scripts and reference files (for example `references/audit-checks.json`, `references/input-normalization.md` and `references/plugin-checklist.md`).
The repository describes itself as: An agentic skills framework & bundle-plugin engineering toolkit that works. The licence is Apache-2.0.
11 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c1b0e10. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(bundles-forge audit-skill *)Bash(bundles-forge audit-security *)Bash(bundles-forge audit-docs *)Bash(bundles-forge audit-plugin *)Bash(bundles-forge audit-workflow *)Bash(bundles-forge checklists *)Bash(bundles-forge bump-version *)Bash(python *bundles-forge *)From allowed-tools in the SKILL.md frontmatter.
Ships 7 files in scripts/ (Python, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
pythongitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Auditing loads about 5.4k tokens when it runs, and up to ~36k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 2,599 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from OdradekAI/bundles-forge at commit c1b0e10, republished under its Apache-2.0 licence (© OdradekAI). 2,599 words, ~5,441 tokens.
.claude/skills/auditing/SKILL.md (or your agent's skills folder). This skill also uses 21 other files; get the full folder from GitHub.Systematically evaluate a bundle-plugin project or a single skill across applicable quality categories — including security scanning — score each, and produce a diagnostic report. This skill is a pure diagnostic tool: it identifies and reports issues but does not orchestrate fixes.
Core principle: Measure and report. A scored audit gives orchestrating skills (blueprinting, optimizing, releasing) the information they need to decide what to fix. When sources contradict, apply the authority hierarchy in references/source-of-truth-policy.md.
This skill includes security scanning. No need to invoke a separate security skill — see Category 10 under Full Project Audit.
Announce at start: "I'm using the auditing skill to audit [this project / this skill]."
Plugin context: When installed as a plugin, operate on the user's project ($CLAUDE_PROJECT_DIR / <target-dir>), not the plugin's own cache. Read files from and detect scope in the target; write all outputs (reports, JSON baselines) to the workspace's .bundles-forge/audits/. See references/input-normalization.md for edge-case input types, naming conventions, and security rules. <plugin-root> in commands below resolves to $CLAUDE_PLUGIN_ROOT (Claude Code), $CURSOR_PLUGIN_ROOT (Cursor), or . (local development).
The target can be a local path, a GitHub URL, or a zip file. Normalize to a local directory, then detect scope. This applies to all three audit modes.
This is a mandatory step — do not skip it or improvise paths. Resolve the target to a local directory before proceeding to Scope Detection or any audit Step 1.
$CLAUDE_PROJECT_DIR or $CURSOR_PROJECT_DIR (plugin mode), falling back to the current working directory.<owner> and <repo> from the URL. Shallow-clone to <workspace>/.bundles-forge/repos/<owner>__<repo>/ using --depth 1 --no-checkout, then run git checkout. If the directory already exists, append a __<YYYYMMDD> timestamp to avoid collisions. Do not clone to /tmp/, ~/, or any path outside .bundles-forge/repos/.<workspace>/.bundles-forge/repos/<archive-name>/.See references/input-normalization.md for the full naming convention (version/timestamp suffixes), GitHub subdirectory URLs, and security rules.
After normalization, determine the audit scope from the resolved local path:
| Target | How to Detect | Mode |
|---|---|---|
| Project root | Has skills/ directory | Full audit — all 10 categories |
| Project root + workflow request | User explicitly requests workflow audit, or specifies --focus-skills | Workflow audit — 3-layer workflow checks (W1-W11) |
| Single skill directory | Contains SKILL.md but no skills/ subdirectory | Skill audit — 4 applicable categories |
| Single SKILL.md file | Path ends in SKILL.md | Skill audit — 4 applicable categories |
If the target is a single skill, skip to the Skill Audit section below. If a workflow audit is requested, skip to the Workflow Audit section below.
audit-plugin orchestrates audit-security (security), audit-skill (skill quality), audit-workflow (workflow integration), and audit-docs (documentation consistency D1-D9), then adds structure, manifest, version-sync, hook, and testing checks.
Categories at a glance (see references/plugin-checklist.md for 60+ individual checks):
| Category | Weight |
|---|---|
| Structure | High |
| Platform Manifests | Medium |
| Version Sync | High |
| Skill Quality | Medium |
| Cross-References | Medium |
| Workflow | High |
| Hooks | Medium |
| Testing | Medium |
| Documentation | Low |
| Security | High |
Security Scan (Category 10): Scans 7 attack surfaces. See references/security-checklist.md for the full pattern list. security-checklist.md is the canonical source; the table below is a quick-reference summary.
| Target | Risk Level |
|---|---|
| SKILL.md content | High |
| Hook scripts | High |
| Hook configs (HTTP hooks) | High |
| OpenCode plugins | High |
| Agent prompts | Medium |
| Bundled scripts | Medium |
| MCP configs | Medium |
Prerequisites: Target directory resolved to a local path (via Input Normalization above) with a skills/ directory (Full audit scope confirmed).
Action:
bundles-forge audit-plugin --json --output-dir .bundles-forge/audits <target-dir>This collects the deterministic baseline — structure, manifests, version sync, skill quality, cross-references, hooks, documentation, and security patterns are verified with reproducible results regardless of agent behavior.
Expected Output: A JSON baseline file at .bundles-forge/audits/audit_plugin-<YYYYMMDD-HHmmss>.json. Verify the file exists and is valid JSON before proceeding to Step 2.
Failure Handling:
python "<plugin-root>/bin/bundles-forge" audit-plugin --json --output-dir .bundles-forge/audits <target-dir>. If both fail, check Python version (requires 3.9+), report the traceback and stop.Prerequisites: JSON baseline file from Step 1 exists at .bundles-forge/audits/.
Action: Pass the JSON baseline file contents to the auditor agent (agents/auditor.md) as input context. The auditor is the single source of truth for scoring formula, report format, and qualitative assessment criteria. It adds ±2 qualitative score adjustments, narrative evaluation, and compiles a layered report using references/plugin-report-template.md.
Full execution details — category weights, scoring formula, report format, Go/No-Go logic — are defined in agents/auditor.md and supported by checklists in references/.
When auditing a project created by bundles-forge:blueprinting, the auditor may reference the design document's "Success Criteria" section (if present in .bundles-forge/blueprints/ or project root) to evaluate whether the implementation aligns with the original project goals.
Expected Output: The auditor produces:
.bundles-forge/audits/<project-name>-v<version>-audit.<date>.md — must follow the template structure in references/plugin-report-template.mdFailure Handling:
agents/auditor.md and follow its execution instructions within this conversation context, using the JSON baseline file as input. The agent file contains the complete audit protocol. The inline execution must still produce all three expected outputs listed above..bundles-forge/audits/ is a mandatory output. If the auditor did not save it, save the report yourself following the naming convention in agents/auditor.md.Prerequisites: Step 2 complete. The audit report exists in .bundles-forge/audits/.
Action: Decide whether to run behavioral verification:
If running: dispatch evaluator agent (agents/evaluator.md) with label "chain" for each workflow chain. Append evaluator results to the audit report.
If skipping: add the following to the Behavioral Verification section of the audit report: "Not performed. Reason: <reason>. Scored as N/A (excluded from weighted average)."
Expected Output: The audit report's Behavioral Verification (W10-W11) section is filled — either with evaluation results or with an explicit N/A entry and skip reason. This section must never be left blank or omitted.
Failure Handling:
Prerequisites: Steps 1-3 complete.
Action: Verify the audit report in .bundles-forge/audits/ meets these criteria:
Present all findings grouped by severity (Critical / Warning / Info). The audit report is the final output — the calling context decides what to fix and how.
Expected Output: A complete, validated audit report file in .bundles-forge/audits/.
Failure Handling:
When the target is a single skill directory or SKILL.md file, run only the 4 categories that apply at skill scope. This is auto-detected — no special flags needed.
| Category | Checks Run | What It Catches |
|---|---|---|
| Structure | S2, S3, S9 | Skill has own directory, contains SKILL.md, directory name matches frontmatter name |
| Skill Quality | Q1–Q15 | Frontmatter validity, description conventions, token budget, allowed-tools deps, section structure, conditional block reachability |
| Cross-References | X1, X2, X3 | Outgoing project:skill-name refs resolve, relative paths exist, referenced subdirectories exist |
| Security | SC1, SC9, SC13, AG1, AG6 | Sensitive file access, safety overrides, encoding tricks, scope constraints (IDs from security-checklist.md) |
Skipped categories: Platform Manifests, Version Sync, Hooks, Testing, Documentation — these require project-level context.
Prerequisites: Target resolved to a local path (via Input Normalization above) containing SKILL.md but no skills/ subdirectory.
Action:
bundles-forge audit-skill --json --output-dir .bundles-forge/audits <skill-directory>Also accepts a SKILL.md file path directly.
Expected Output: A JSON baseline file at .bundles-forge/audits/audit_skill-<YYYYMMDD-HHmmss>.json.
Failure Handling:
python "<plugin-root>/bin/bundles-forge" audit-skill --json --output-dir .bundles-forge/audits <skill-directory>. If both fail, check Python version (requires 3.9+), report the traceback and stop.Prerequisites: JSON baseline file from Step 1 exists.
Action: Pass the JSON baseline to the auditor agent (agents/auditor.md) in Single Skill Audit Mode. The auditor runs the 4-category checks, produces a qualitative summary (Verdict, Strengths, Key Issues), scores each category, and compiles the report using references/skill-report-template.md.
Expected Output: A skill audit report saved to .bundles-forge/audits/<skill-name>-v<version>-skill-audit.<date>.md containing:
Failure Handling:
agents/auditor.md (Single Skill Audit Mode section) and follow its instructions inline. The inline execution must still produce all expected outputs.Prerequisites: Step 2 complete.
Action: Verify the skill audit report exists in .bundles-forge/audits/ and contains Decision Brief, 4 category findings, and Skill Profile.
Expected Output: A complete skill audit report file.
Failure Handling:
When auditing a skill from an external source (marketplace, git, shared file):
When the user explicitly requests a workflow audit, or when the Full audit's Cross-References category (X1-X3) or Workflow category (W1-W11) has warnings, run a dedicated workflow audit. This evaluates how skills connect, hand off artifacts, and compose into coherent chains.
When to Trigger:
--focus-skills for detailed diagnostics."Prerequisites: Target directory resolved to a local path (via Input Normalization above). User has optionally specified --focus-skills.
Action:
bundles-forge audit-workflow --json --output-dir .bundles-forge/audits <target-dir>
# or with focus:
bundles-forge audit-workflow --json --output-dir .bundles-forge/audits --focus-skills skill-a,skill-b <target-dir>Script mode covers W1-W9 (static + semantic layers). W10-W11 (behavioral layer) requires evaluator agent dispatch and is scored as N/A in script output.
Expected Output: A JSON baseline file at .bundles-forge/audits/audit_workflow-<YYYYMMDD-HHmmss>.json.
Failure Handling:
python "<plugin-root>/bin/bundles-forge" audit-workflow --json --output-dir .bundles-forge/audits <target-dir>. If both fail, check Python version (requires 3.9+), report the traceback and stop.Prerequisites: JSON baseline file from Step 1 exists.
Action: Pass the JSON baseline to the auditor agent (agents/auditor.md) in Workflow Audit Mode. The auditor handles W1-W9 (Static Structure + Semantic Interface) across three layers defined in references/workflow-checklist.md. Full workflow audit protocol, focus mode, and report format are in agents/auditor.md (Workflow Audit Mode section).
Expected Output: A workflow audit report saved to .bundles-forge/audits/<project-name>-v<version>-workflow-audit.<date>.md using references/workflow-report-template.md, containing:
Failure Handling:
agents/auditor.md (Workflow Audit Mode section) and follow its instructions inline. Must still produce all expected outputs.Prerequisites: Step 2 complete. The workflow report exists.
Action: Decide whether to run behavioral verification:
If running: dispatch evaluator agent (agents/evaluator.md) with label "chain" for each workflow chain involving focus skills. Use the chain list and focus skills from the auditor's report. Append results to the workflow report.
If skipping: add to the Behavioral Verification section: "Not performed. Reason: <reason>. Scored as N/A (excluded from weighted average)."
Why two phases: Subagents cannot dispatch other subagents, so the evaluator must be dispatched from this skill (main conversation), not from within the auditor.
Expected Output: The workflow report's Behavioral Verification (W10-W11) section is filled — either with evaluation results or an explicit N/A entry. This section must never be left blank or omitted.
Failure Handling:
Prerequisites: Steps 1-3 complete.
Action: Verify the workflow report in .bundles-forge/audits/ contains Decision Brief, all three layer findings (with Behavioral Verification filled), and Skill Integration Map.
Present workflow findings grouped by severity. The workflow-report is consumed by the calling context for targeted fixes.
Expected Output: A complete workflow audit report file.
Failure Handling:
When the user explicitly requests a security-only scan, run only Category 10 (Security) via bundles-forge audit-security. Skip Categories 1-9. Report in the same format but with only the Security category scored. This provides a quick security check without the overhead of a full 10-category audit.
| Mistake | Fix |
|---|---|
| Skipping version sync check | Always run bundles-forge bump-version --check (full audit) |
| Not checking description anti-patterns | Descriptions that summarize workflow cause agents to shortcut |
| Ignoring cross-reference resolution | Broken project:skill-name refs = broken workflow chains |
| Running full 10-category audit on a single skill | Let scope auto-detection handle it — 6 categories don't apply |
| Skipping workflow audit after adding third-party skills | New skills need workflow integration validation — use --focus-skills |
| Skipping security because "I wrote it myself" | Accidental vulnerabilities are common — always scan |
| Only scanning SKILL.md, ignoring hooks | Hooks are the highest-risk executable code (full audit) |
| Treating script output as the final report | Script output is a baseline — always dispatch auditor or read agents/auditor.md inline to produce the full report |
Bypassing --json failure without diagnosis | If --json returns empty output or unexpected exit code, retry with the direct Python call before falling back to non-JSON mode |
| Not persisting JSON baseline to disk | Always use --output-dir .bundles-forge/audits to ensure intermediate results are saved regardless of agent behavior |
| Skipping W10-W11 without marking N/A in report | If Behavioral Verification is skipped, the report must contain the section with "N/A" and the skip reason |
project-directory (required) — bundle-plugin project root, single skill directory, or SKILL.md file path (local, GitHub URL, or archive)audit-report — scored report with findings across 10 categories (full project), written to .bundles-forge/audits/ by the auditor agent. Contains per-skill breakdownsskill-report (skill mode) — 4-category scored report (Structure, Quality, Cross-Refs, Security) for a single skill, written to .bundles-forge/audits/workflow-report (workflow mode) — workflow-specific report with W1-W11 findings across static/semantic/behavioral layers, written to .bundles-forge/audits/Called by:
© OdradekAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 21 other files (scripts, references) in skills/auditing of OdradekAI/bundles-forge.
Open the folder on GitHubat commit c1b0e10
Auditing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Auditing this skillOdradekAI/bundles-forge | 229 | — | ~5.4k | Automated safety check: Pass | Apache-2.0 | |
| MCP Dependency Drift Auditsickn33/agentic-awesome-skills | 47k | 1 repos | ~2k | Automated safety check: Pass | MIT | |
| Audit Contract Driftben-manes/caffeine | 18k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Structured Datathedaviddias/Front-End-Checklist | 74k | — | ~420 | Automated safety check: Pass | MIT | |
| Production Auditaffaan-m/ECC | 274k | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Aims Auditalirezarezvani/claude-skills | 28k | — | ~1.3k | Automated safety check: Pass | MIT |
sickn33/agentic-awesome-skills
Statically audit MCP configs for mutable npm/npx package references before approval or CI, without executing discovered MCP servers.
ben-manes/caffeine
Find places where documented API contracts and the implementation diverge
thedaviddias/Front-End-Checklist
A skill your agent uses when auditing metadata, crawlability, structured data, or indexability related to Add structured data markup.
affaan-m/ECC
Local-evidence production readiness audit for shipped apps, pre-launch reviews, post-merge checks, and "what breaks in prod?" questions without sending repo data to an external audit service.
alirezarezvani/claude-skills
/cs:aims-audit <scope — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation.
sickn33/agentic-awesome-skills
Full website GEO+SEO audit with parallel subagent delegation.
OdradekAI/bundles-forge
A skill your agent uses when releasing a bundle-plugin, bumping versions, fixing version drift across manifests, setting up version sync infrastructure, updating CHANGELOG, publishing to…
OdradekAI/bundles-forge
A skill your agent uses when testing a bundle-plugin locally before release — generating dev-marketplace environments, verifying component discovery, running hook smoke tests, and validating…
OdradekAI/bundles-forge
A skill your agent uses when starting any conversation involving bundle-plugins — blueprinting, scaffolding, authoring, auditing, testing, optimizing, or releasing.
OdradekAI/bundles-forge
A skill your agent uses when optimizing a bundle-plugin or single skill — improving descriptions, reducing tokens, fixing audit findings, restructuring workflows, adding skills to fill gaps, or…
OdradekAI/bundles-forge
A skill your agent uses when generating project structure for new bundle-plugins, adding or removing platform support (Claude Code, Cursor, Codex, OpenCode, Gemini CLI, OpenClaw), updating platform…
OdradekAI/bundles-forge
A skill your agent uses when writing, completing, improving, or adapting SKILL.md and agents/.md in a bundle-plugin — integrating external skills, filling scaffolded stubs, or rewriting for better…
A skill your agent uses when reviewing a bundle-plugin for structural issues, version drift, skill quality, workflow integration, or security risks — before releasing, after changes, or after adding…. Auditing is an agent skill from OdradekAI/bundles-forge. Use when reviewing a bundle-plugin for structural issues, version drift, skill quality, workflow integration, or security risks — before releasing, after changes, or after adding skills.
Auditing fits situations like: reviewing a bundle-plugin for structural issues; workflow integration; security risks — before releasing; after adding skills.
Run `npx skills add OdradekAI/bundles-forge --skill auditing -a claude-code`. Or copy the skill folder (skills/auditing in OdradekAI/bundles-forge) into .claude/skills/auditing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OdradekAI/bundles-forge --skill auditing -a codex`. Or copy the skill folder (skills/auditing in OdradekAI/bundles-forge) into .agents/skills/auditing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OdradekAI/bundles-forge --skill auditing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing, .gemini/skills/auditing, .github/skills/auditing and .opencode/skills/auditing in your project.
Going by SKILL.md and its folder, Auditing needs Python for the scripts in its folder and the command-line tools its instructions call (python and git). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash(bundles-forge audit-skill *), Bash(bundles-forge audit-security *), Bash(bundles-forge audit-docs *), Bash(bundles-forge audit-plugin *), Bash(bundles-forge audit-workflow *), Bash(bundles-forge checklists *), Bash(bundles-forge bump-version *), Bash(python *bundles-forge *).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Auditing is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 31k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Auditing: MCP Dependency Drift Audit (sickn33/agentic-awesome-skills, 47k stars), Audit Contract Drift (ben-manes/caffeine, 18k stars), Structured Data (thedaviddias/Front-End-Checklist, 74k stars) and Production Audit (affaan-m/ECC, 274k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OdradekAI (a GitHub organization) maintains it in OdradekAI/bundles-forge, which has 229 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on April 27, 2026.
Source: OdradekAI/bundles-forge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.