Audit Prep
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner.
$ npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install oliver-kriska/claude-elixir-phoenix phx-deps-vet --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/oliver-kriska/claude-elixir-phoenix.git skills-src && mkdir -p .claude/skills && cp -r skills-src/targets/pi/skills/phx-deps-vet .claude/skills/phx-deps-vet && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "phx-deps-vet" agent skill from https://github.com/oliver-kriska/claude-elixir-phoenix/tree/main/targets/pi/skills/phx-deps-vet into .claude/skills/phx-deps-vet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phx-deps-vet", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/oliver-kriska/claude-elixir-phoenix/tree/main/targets/pi/skills/phx-deps-vetType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install oliver-kriska/claude-elixir-phoenix phx-deps-vet --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/oliver-kriska/claude-elixir-phoenix.git skills-src && mkdir -p .agents/skills && cp -r skills-src/targets/pi/skills/phx-deps-vet .agents/skills/phx-deps-vet && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "phx-deps-vet" agent skill from https://github.com/oliver-kriska/claude-elixir-phoenix/tree/main/targets/pi/skills/phx-deps-vet into .agents/skills/phx-deps-vet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phx-deps-vet", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install oliver-kriska/claude-elixir-phoenix phx-deps-vet --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/oliver-kriska/claude-elixir-phoenix.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/targets/pi/skills/phx-deps-vet .cursor/skills/phx-deps-vet && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "phx-deps-vet" agent skill from https://github.com/oliver-kriska/claude-elixir-phoenix/tree/main/targets/pi/skills/phx-deps-vet into .cursor/skills/phx-deps-vet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phx-deps-vet", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/oliver-kriska/claude-elixir-phoenix.git --path targets/pi/skills/phx-deps-vet--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install oliver-kriska/claude-elixir-phoenix phx-deps-vet --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/oliver-kriska/claude-elixir-phoenix.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/targets/pi/skills/phx-deps-vet .gemini/skills/phx-deps-vet && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "phx-deps-vet" agent skill from https://github.com/oliver-kriska/claude-elixir-phoenix/tree/main/targets/pi/skills/phx-deps-vet into .gemini/skills/phx-deps-vet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phx-deps-vet", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install oliver-kriska/claude-elixir-phoenix phx-deps-vetInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/oliver-kriska/claude-elixir-phoenix.git skills-src && mkdir -p .github/skills && cp -r skills-src/targets/pi/skills/phx-deps-vet .github/skills/phx-deps-vet && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "phx-deps-vet" agent skill from https://github.com/oliver-kriska/claude-elixir-phoenix/tree/main/targets/pi/skills/phx-deps-vet into .github/skills/phx-deps-vet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phx-deps-vet", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install oliver-kriska/claude-elixir-phoenix phx-deps-vet --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/oliver-kriska/claude-elixir-phoenix.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/targets/pi/skills/phx-deps-vet .opencode/skills/phx-deps-vet && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "phx-deps-vet" agent skill from https://github.com/oliver-kriska/claude-elixir-phoenix/tree/main/targets/pi/skills/phx-deps-vet into .opencode/skills/phx-deps-vet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phx-deps-vet", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
phx-deps-vetRecord a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner.
Phx Deps Vet is an agent skill from oliver-kriska/claude-elixir-phoenix. Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner. Use to approve a dep after /skill:phx-deps-audit findings or to initialize hexvet.exs.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/hex-vet.md` and `references/seed.md`).
It sits in Security, covering Security review and Audit readiness. The repository describes itself as: Claude Code plugin for Elixir/Phoenix/LiveView — 26 specialist agents, Iron Laws enforcement, and Tidewave MCP integration. Plan features with parallel research agents, execute… The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9767a82. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (Elixir), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Phx Deps Vet loads about 1.5k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 608 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from oliver-kriska/claude-elixir-phoenix at commit 9767a82, republished under its MIT licence (© oliver-kriska). 608 words, ~1,508 tokens.
.claude/skills/phx-deps-vet/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Review a Hex package version, run Phase 1 supply-chain rules against it,
prompt the user for a verdict, append the result to hex_vet.exs
(project-root audit ledger). Vetted versions get downgraded to INFO
on subsequent /skill:phx-deps-audit runs.
Run this AFTER /skill:phx-deps-audit to clear findings.
Run this BEFORE merging a mix.lock PR to certify new versions.
/skill:phx-deps-vet phoenix 1.7.21 # vet a single package version
/skill:phx-deps-vet --seed # import curated baseline seed (~30 pkgs)
/skill:phx-deps-vet --list # show existing ledger entries
/skill:phx-deps-vet --check # cross-check mix.lock vs ledgerAskUserQuestion
confirmation. Drive-by trust ruins the ledger's value.mix.lock has version X and the
ledger vets X-1, emit INFO and treat X as unvetted. Don't silently
trust the older entry.hex_vet.exs is a first-class
security artifact, visible in PR review. Don't move it into .claude/.inspect/2. When appending, read the file with
Code.eval_file/1, mutate the map, and write back via
inspect(term, pretty: true, limit: :infinity). Hand-rolled string
appends drift over time.:safe_to_deploy defaults.AskUserQuestion (criteria split, new/overwrite/no-op) MUST be
derived from the loaded data before prompting — e.g.
Enum.frequencies_by(seed.audits, & &1.criteria). Eyeballing the
file and approving on wrong numbers corrupts the consent.hex_vet.exsIf hex_vet.exs exists at project root:
Read it via Code.eval_file/1
Else:
Write the empty-ledger stub (see references/hex-vet.md §"Empty ledger")
Inform user: "Created hex_vet.exs at project root."<pkg> <version> → single-vet path (Step 3-7).--seed → import priv/hex_vet_seed.exs. Before prompting,
Code.eval_file/1 the seed and compute (Iron Law #6): the
criteria split (Enum.frequencies_by(seed.audits, & &1.criteria))
and, against any existing ledger, exact new / overwrite / no-op
counts. Put those computed numbers in the AskUserQuestion. Also
state up front that the seed is a provenance baseline, not
certification of your current mix.lock (per Iron Law #2, seed
versions older than the locked ones stay unvetted). Ask before
overwriting existing entries.--list → render the audits table; exit.--check → compare ledger entries with mix.lock; warn on
drift. Read the lock via Code.eval_file("mix.lock") with
2>/dev/null — modern locks have quoted keys and emit a
found quoted keyword warning per package (tens of KB of noise that
gets persisted as an oversized tool result otherwise).Run the deps-audit corpus loader. Cache lives at
~/.cache/phx-deps-audit/corpus/<pkg>/<version>/contents/. Use:
bash ../phx-deps-audit/scripts/fetch_tarball.sh \
<pkg> <version>Source the rules from ../phx-deps-audit/references/rules-impl.md.
Run run_all_rules over the cached dir. Write findings to a temp
vet-findings.jsonl. Set FINDINGS_FILE to override default path.
Print the findings table per ../phx-deps-audit/references/output-renderer.md.
On zero findings: say "No findings — vet from a clean baseline."
On any finding: show severity, file, line, snippet inline.
Call AskUserQuestion with these 4 options:
:safe_to_deploy — full trust; findings investigated and cleared.:safe_to_run — trust in non-production envs only (test deps).:does_not_implement_crypto — Mozilla-style sub-criterion.Skip — defer decision; don't write an entry.If any finding is BLOCK severity: default-highlight Skip. Require
explicit override before writing :safe_to_deploy over a BLOCK.
Read existing hex_vet.exs via Code.eval_file/1. Append the audit
map below to :audits. Write back via
Code.format_string!(inspect(...)).
%{
package: "<pkg>",
version: "<version>",
criteria: <verdict_atom>,
reviewer: "<git config user.email>",
notes: "<user-provided one-liner OR findings summary>",
reviewed_at: ~D[<today>]
}Write back via Code.format_string!(inspect(term, pretty: true)).
Confirm to user: "Added <pkg> <version> to hex_vet.exs."
/skill:phx-deps-audit to clear vetted findings.mix.lock PR to certify new versions./skill:phx-deps-vet --check to detect ledger drift vs mix.lock./skill:phx-deps-audit auto-downgrades vetted findings to INFO.policy.block_on_unvetted is enforced by the plugin's deps-audit-gate.sh
PreToolUse hook on mix deps.get / mix deps.update.references/hex-vet.md — schema, parser, lookupreferences/seed.md — --seed flag, curated baseline../phx-deps-audit/references/rules-impl.md — the
same rules /skill:phx-deps-audit runsmix phx.deps_vet to a separate Hex
package phx_deps_vet for non-CC users.imports: until
trust-chain semantics are designed.© oliver-kriska, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in targets/pi/skills/phx-deps-vet of oliver-kriska/claude-elixir-phoenix.
Open the folder on GitHubat commit 9767a82
Phx Deps Vet next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Phx Deps Vet this skilloliver-kriska/claude-elixir-phoenix | 565 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Audit PrepPlamenTSV/plamen | 303 | — | ~3.7k | Automated safety check: Pass | MIT | |
| Audit Finding Fixapache/magpie | 114 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | |
| Xray Pre Auditccashwell/evm-cortex | 131 | — | ~25k | Automated safety check: Pass | MIT | |
| Isms Audit Expertdavila7/claude-code-templates | 33k | 1 repos | ~3.1k | Automated safety check: Pass | MIT | |
| Fp Checkvibeeval/vibecosystem | 532 | — | ~1.6k | Automated safety check: Pass | MIT |
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
apache/magpie
For a batch of findings from a non-security audit tool (<audit-tool — ruff / flake8 / mypy / pylint / CodeQL / Apache Verum / Apache Caer / equivalent; full list in the body) against <upstream…
ccashwell/evm-cortex
A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.
davila7/claude-code-templates
Senior ISMS Audit Expert for internal and external information security management system auditing.
vibeeval/vibecosystem
Systematic false positive verification for security findings.
HoangNguyen0403/agent-skills-standard
OWASP LLM Top 10 (2025) audit checklist for AI applications, agent tools, RAG pipelines, and prompt construction.
oliver-kriska/claude-elixir-phoenix
Run an A/B codex review experiment — holistic codex review vs 3 focused dimension passes (security, ecto, liveview) on the branch diff, classify findings, report a panel-value verdict.
oliver-kriska/claude-elixir-phoenix
Project health audit and health check — architecture, performance, tests, dependencies, code quality.
oliver-kriska/claude-elixir-phoenix
Searchable Elixir/Phoenix/Ecto solution documentation system with; Use when consulting past solutions…
oliver-kriska/claude-elixir-phoenix
Searchable Elixir/Phoenix/Ecto solution documentation system with YAML frontmatter.
oliver-kriska/claude-elixir-phoenix
Elixir/Phoenix deployment patterns — Dockerfile, fly.toml, runtime.exs, mix release, rel/ overlays.
oliver-kriska/claude-elixir-phoenix
Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo).
Categories
Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner. Phx Deps Vet is an agent skill from oliver-kriska/claude-elixir-phoenix.exs after a security review — manages the audit ledger, not the scanner.
Phx Deps Vet fits situations like: approve a dep after /skill:phx-deps-audit findings; initialize hexvet.exs.
Run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a claude-code`. Or copy the skill folder (targets/pi/skills/phx-deps-vet in oliver-kriska/claude-elixir-phoenix) into .claude/skills/phx-deps-vet in your project. Claude Code loads it when a task matches its description.
Run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a codex`. Or copy the skill folder (targets/pi/skills/phx-deps-vet in oliver-kriska/claude-elixir-phoenix) into .agents/skills/phx-deps-vet in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phx-deps-vet, .gemini/skills/phx-deps-vet, .github/skills/phx-deps-vet and .opencode/skills/phx-deps-vet in your project.
Going by SKILL.md and its folder, Phx Deps Vet needs Elixir for the scripts in its folder.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Phx Deps Vet is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Phx Deps Vet: Audit Prep (PlamenTSV/plamen, 303 stars), Audit Finding Fix (apache/magpie, 114 stars), Xray Pre Audit (ccashwell/evm-cortex, 131 stars) and Isms Audit Expert (davila7/claude-code-templates, 33k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
oliver-kriska (a GitHub user) maintains it in oliver-kriska/claude-elixir-phoenix, which has 565 GitHub stars. The repository holds 109 skills in this directory. The repository was last updated on October 5, 2026.
Source: oliver-kriska/claude-elixir-phoenix on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.