Agent skill

Audit Prep

by PlamenTSV in PlamenTSV/plamen

Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

MITAuto-check passedSecurity

Install Audit Prep

skills CLI
$ npx skills add PlamenTSV/plamen --skill audit-prep -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen audit-prep --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-prep .claude/skills/audit-prep && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-prep
GitHub stars
303
Token cost
~3.7k tokens
SKILL.md length
1,249 words
Files
8 (incl. references)
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

  • Works in 4 steps: Header (project, framework, scope) → Phase 1–8, each as a titled section with… → Score summary table → …
  • : prepare for audit
  • SKILL.md covers Modes, Report Format, Execution and Auto-Fix (--fix), plus 1 more section
  • Runs Shell scripts from its folder; calls git

What it does

Audit Prep is an agent skill from PlamenTSV/plamen. Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project documentation checks. Generates a scored Audit Readiness Report and optionally runs static analysis. Trigger on: "prepare for audit", "audit readiness", "pre-audit check", "audit prep", "NatSpec check", or any request to review a Solidity codebase before a security review.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `evals/evals.json`, `evals/grade.sh` and `references/agents/infrastructure-agent.md`).

It sits in Security, covering Security review, Static analysis and SAST and Smart contracts. It works with Solidity. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • : prepare for audit
  • Audit readiness
  • Pre-audit check
  • Any request to review a Solidity codebase before a security review

Example prompts

  • “prepare for audit”
  • “audit readiness”
  • “pre-audit check”
  • “/audit-prep”

Requirements

  • A Bash shell

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Header (project, framework, scope)
  2. Phase 1–8, each as a titled section with a results table
  3. Score summary table
  4. Quick Wins table

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Prep loads about 3.7k tokens when it runs, and up to ~8.7k if it reads all its reference files. Until then it costs about 118 tokens; SKILL.md has 1,249 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~118
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,249 words, ~3,729 tokens.

Download SKILL.mdSave it as .claude/skills/audit-prep/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
audit-prep
description
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project documentation checks. Generates a scored Audit Readiness Report and optionally runs static analysis. Trigger on: "prepare for audit", "audit readiness", "pre-audit check", "audit prep", "NatSpec check", or any request to review a Solidity codebase before a security review.

Solidity Audit Preparation — Orchestrator

Orchestrate a parallelized audit-prep pipeline. Do NOT perform analysis — discover files, dispatch agents, compile the scored report.

Modes

  • Default: full pipeline, all 8 phases + static analysis offer.
  • Single phase: coverage | quality | docs | hygiene | deps | practices | deploy | context
  • scan: static analysis only.
  • --fix: auto-apply fixes (NatSpec stubs, console removal, pragma locking, SafeERC20 wrapping).
  • --report <path>: write markdown report to file (no ANSI codes).
  • --no-scan: skip static analysis offer.
  • --scanner <tool>: run specific tool without prompting.
  • --diff <ref>: scope to files changed since git ref.
  • --ci: JSON output. Exit 0 if score >= threshold (default 75, --min-score N).

Report Format

Clean markdown. Each phase = one table with Status, Finding, and Recommendation columns. Score summary at the end. When rendered via --report, produces a polished .md file.

The report has these sections in order:

  1. Header (project, framework, scope)
  2. Phase 1–8, each as a titled section with a results table
  3. Score summary table
  4. Quick Wins table
Banner

Print the banner from the end of this file before doing anything else — in every mode (full pipeline, single phase, scan, fix). Always use this exact banner. Never generate, invent, or substitute a different banner. Also include it at the top of --report markdown files.

Phase section template
markdown
## 1. Test Coverage

| Status | Finding | Recommendation |
|--------|---------|----------------|
| FAIL | Compiler warning — unused param in ConfigProvider:288 | Remove or rename the unused parameter |
| PASS | 4/4 contracts have test files | — |
| PASS | Branch coverage: 95.93% | — |
  • Status: PASS or FAIL
  • Finding: concise description of what was checked and the result
  • Recommendation: specific action to fix (only for FAIL rows; use — for PASS)
Score summary
markdown
## Score Summary

| Phase | Score |
|-------|-------|
| 1. Test Coverage | 87/100 |
| 2. Test Quality | 85/100 |
| ... | ... |
| **Overall** | **82/100 — Almost Ready** |
Quick Wins
markdown
## Quick Wins

| # | Action | Location |
|---|--------|----------|
| 1 | Create deployment scripts | scripts/deploy.ts |
| 2 | Create SECURITY.md with trust assumptions | project root |
| 3 | Add more assertions to thin tests | test/ |

No deduction numbers, no weights, no [-N] annotations. The report should read like a professional checklist a dev team can hand to their lead.

Execution

Turn 0 — Banner & Project Selection

First, read the VERSION file and the skill's references path in parallel:

  • Read: VERSION file from this skill's base directory
  • Glob: **/references/shared-rules.md — extract {ref_path} (the references/ directory)

Then print the banner (from the end of this file), followed by asking the user where the project is:

json
{
  "question": "Where is the project you want to prepare for audit?",
  "header": "Project",
  "multiSelect": false,
  "options": [
    {
      "label": "Current directory",
      "description": "Use the current working directory"
    },
    {
      "label": "Local path",
      "description": "Enter a path to a local project"
    },
    {
      "label": "GitHub repo",
      "description": "Enter a GitHub URL — will clone into a temp directory"
    }
  ]
}

If Current directory: use the cwd as {project_dir}. If Local path: user provides a path, use it as {project_dir}. If GitHub repo: clone with git clone <url> /tmp/audit-prep-<repo-name> and use that as {project_dir}.

Turn 1 — Discover & Prepare

Make these parallel tool calls in ONE message: a. Bash: detect framework — check for foundry.toml, hardhat.config.js, hardhat.config.ts b. Bash: find in-scope .sol files. Exclude test/, script/, lib/, node_modules/, interfaces/, mocks/. Check both src/ and contracts/. If --diff <ref>, use git diff --name-only <ref> -- '*.sol'. c. Bash: find test files — find test/ -name '*.sol' -o -name '*.ts' -o -name '*.js' d. Bash: count total lines in scope — wc -l on discovered source files g. Bash: mkdir -p .audit-prep -> {bundle_dir} = .audit-prep (project-relative, so agents can read it) h. ToolSearch: mcp__sc-auditor (for scan menu in Turn 4)

Then create agent bundles in a single Bash call:

bash
# File list (one per line)
printf '%s\n' <in-scope-files> > {bundle_dir}/files.txt

# Agent A — Testing (Phases 1+2)
# Gets: framework, project dir, test metadata, source file list, instructions
{
  printf 'framework: %s\nproject_dir: %s\n\n' "<fw>" "<dir>"
  echo "# Test files:"
  for f in <test-files>; do
    printf '%s (%s lines)\n' "$f" "$(wc -l < "$f")"
  done
  echo ""
  echo "# In-scope source files:"
  cat {bundle_dir}/files.txt
  echo ""
  cat {ref_path}/agents/testing-agent.md
  echo ""
  cat {ref_path}/shared-rules.md
} > {bundle_dir}/agent-a.md

# Agent B — Source Analysis (Phases 3+4+6)
# NO SOURCE CODE — agent uses Grep/Read directly on project files
{
  printf 'project_dir: %s\n\n' "<dir>"
  echo "# In-scope source files:"
  cat {bundle_dir}/files.txt
  echo ""
  cat {ref_path}/agents/source-analysis-agent.md
  echo ""
  cat {ref_path}/shared-rules.md
} > {bundle_dir}/agent-b.md

# Agent C — Infrastructure (Phases 5+7+8)
{
  printf 'framework: %s\nproject_dir: %s\n\n' "<fw>" "<dir>"
  cat {ref_path}/agents/infrastructure-agent.md
  echo ""
  cat {ref_path}/shared-rules.md
} > {bundle_dir}/agent-c.md

echo "=== Bundles ==="
wc -l {bundle_dir}/agent-*.md

Print: <project> | <framework> | <N> files, <M> lines

Turn 2 — Spawn

First, create 3 tasks so the user sees progress spinners:

TaskSubjectActive Form
ATest coverage & quality (Phases 1-2)Analyzing test coverage & quality
BSource code analysis (Phases 3, 4, 6)Analyzing source code
CInfrastructure checks (Phases 5, 7, 8)Checking infrastructure

Use TaskCreate for each, then immediately set all 3 to in_progress via TaskUpdate.

Then, in the SAME message, spawn 3 parallel Agent calls:

Agent A — Testing (Phases 1 + 2):

Read your full bundle at {bundle_dir}/agent-a.md.
Execute Phases 1 and 2 exactly as specified.
Output ONLY the PHASE/FAIL/PASS structured format from the shared rules.
Do NOT skip any phase. Do NOT add commentary or tables.

Agent B — Source Analysis (Phases 3 + 4 + 6):

Read your full bundle at {bundle_dir}/agent-b.md.
Execute Phases 3, 4, and 6 exactly as specified.
Use Grep and Read to analyze the source files listed in the bundle.
Do NOT read all source files at once — use targeted queries per check.
Output ONLY the PHASE/FAIL/PASS structured format from the shared rules.
Do NOT skip any phase. Do NOT perform vulnerability analysis.

Agent C — Infrastructure (Phases 5 + 7 + 8):

Read your full bundle at {bundle_dir}/agent-c.md.
Execute Phases 5, 7, and 8 exactly as specified.
Output ONLY the PHASE/FAIL/PASS structured format from the shared rules.
Do NOT skip any phase. Do NOT add commentary or tables.

As each agent completes, mark its task as completed via TaskUpdate.

Turn 3 — Score & Report

Parse each agent's output. For each phase, extract:

  • PHASE N | line → phase number, name, score
  • FAIL | lines → check name, deduction, file, then desc: and fix: on next lines
  • PASS | lines → check name, optional note:

Validate: For each expected phase (1–8):

  • Missing PHASE N marker → score = 0, add note "(not reported by agent)"
  • Missing SCORE: → compute as 100 minus sum of extracted deductions
  • No FAIL/PASS lines → flag "(no details reported)"

Compute weighted score:

PhaseWeight
1. Coverage15%
2. Quality15%
3. Documentation10%
4. Hygiene10%
5. Dependencies10%
6. Best Practices15%
7. Deployment10%
8. Project Docs15%

Verdict: 90–100 Audit Ready | 75–89 Almost Ready | 50–74 Needs Work | <50 Not Ready Override: If Phase 1 (Coverage) score < 90, verdict CANNOT be "Audit Ready" — cap at "Almost Ready" and append "(coverage below 90%)".

Render the report as clean markdown using the format from the Report Format section. The banner is already visible from Turn 1 — do NOT re-print it here. In --report files, include the banner as an uncolored code block at the top.

For each phase, build a table with Status | Finding | Recommendation columns. FAIL rows get a specific recommendation. PASS rows get — in the recommendation column. Group related PASS items into single rows where natural (e.g., "No TODOs, console imports, or commented-out code").

End with the Score Summary table and Quick Wins table. Quick Wins = top 5 most impactful FAIL findings. Each shows the fix action and where to apply it.

If --report <path>: write the markdown to the specified file path. If --ci: JSON {"score": N, "verdict": "...", "phases": [...], "findings": [...]}.

Show full SKILL.md (419 more words)Show less
Turn 4 — Scan Menu

Skip if --no-scan. If --scanner <tool>, run directly.

Detection:

  1. Local CLI tools (single Bash):
bash
echo "=== SCAN DETECTION ==="
which slither 2>/dev/null && echo "SLITHER=yes" || echo "SLITHER=no"
which aderyn 2>/dev/null && echo "ADERYN=yes" || echo "ADERYN=no"
which myth 2>/dev/null && echo "MYTHRIL=yes" || echo "MYTHRIL=no"
  1. MCP tools: check ToolSearch results from Turn 1 for mcp__sc-auditor__run-slither, mcp__sc-auditor__run-aderyn.

  2. Skills: check the available skills list for solidity-auditor (Pashov).

A tool is "installed" if ANY source is available (local CLI, MCP, or skill).

Present the scan menu using AskUserQuestion with multiSelect: true.

Always include all four options (Slither, Aderyn, Pashov Solidity Auditor, Import custom scanner). Set each tool's description dynamically to show its availability status and source. Never omit an option just because it was not detected — show it with "(not installed)" instead.

Example AskUserQuestion call:

json
{
  "question": "Which scanners do you want to run?",
  "header": "Bug Scan",
  "multiSelect": true,
  "options": [
    {
      "label": "Slither",
      "description": "Static analysis for Solidity (available via MCP)"
    },
    {
      "label": "Aderyn",
      "description": "Rust-based static analyzer (installed locally)"
    },
    {
      "label": "Pashov Solidity Auditor",
      "description": "AI-powered audit skill (available as skill)"
    },
    {
      "label": "Import custom scanner",
      "description": "Provide a CLI command to run your own scanner"
    }
  ]
}

For the description field of Slither, Aderyn, and Pashov — set dynamically based on detection:

  • Installed: "... (available via MCP)", "... (installed locally)", or "... (available as skill)"
  • Not installed: "... (not installed)"

If the user selects "Import custom scanner", follow up by asking for the CLI command to run. Execute it with the same timeout (300s) and append output to the scan results.

Findings from scanners do NOT affect the audit-prep score.

Tool execution reference:

ToolLocal CLIMCPSkill
Slitherslither . --filter-paths "test|script|lib|node_modules"mcp__sc-auditor__run-slither—
Aderynaderyn .mcp__sc-auditor__run-aderyn—
Pashov Solidity Auditor——solidity-auditor skill

Priority when multiple sources available: MCP > local CLI > skill.

Auto-Fix (--fix)

Code fixes (applied to source files)
FixAction
NatSpec stubsInsert @notice, @param, @return above undocumented functions
Console removalRemove console.sol imports and console.log calls
Pragma lockingReplace ^0.8.x with 0.8.x
SafeERC20 wrappingAdd using SafeERC20 for IERC20;, replace direct calls
SPDX headersAdd // SPDX-License-Identifier: MIT to files missing it (prompt for license)
Template generation (creates new files if missing)
FileContent
SECURITY.mdSkeleton: Roles & Permissions, Trust Assumptions, Centralization Risks, Known Risks sections. Pre-fill role names from AccessControl/Ownable usage in source.
scope.mdGenerate from discovered in-scope files: contract name, file path, line count, brief description from @title NatSpec
KNOWN_ISSUES.mdSkeleton: header + "Document any known limitations, accepted risks, or intentional design trade-offs here."

Templates are only created if the file does not already exist. The orchestrator generates these after the report, using data already collected during the pipeline (in-scope files, role names, config vars). No extra agent calls needed.

Banner

Before doing anything else, print the banner below as plain text (not inside a code block). Apply ANSI color \033[38;5;117m (light sky blue) to the entire banner (both CD and SECURITY block letters), \033[38;5;153m (pale blue) for the subtitle, and \033[0m to reset at the end.

Terminal
██████╗██████╗
██╔════╝██╔══██╗
██║     ██║  ██║
██║     ██║  ██║
╚██████╗██████╔╝
╚═════╝╚═════╝

███████╗███████╗ ██████╗██╗   ██╗██████╗ ██╗████████╗██╗   ██╗
██╔════╝██╔════╝██╔════╝██║   ██║██╔══██╗██║╚══██╔══╝╚██╗ ██╔╝
███████╗█████╗  ██║     ██║   ██║██████╔╝██║   ██║    ╚████╔╝
╚════██║██╔══╝  ██║     ██║   ██║██╔══██╗██║   ██║     ╚██╔╝
███████║███████╗╚██████╗╚██████╔╝██║  ██║██║   ██║      ██║
╚══════╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝  ╚═╝╚═╝   ╚═╝      ╚═╝

Audit Preparation v1.0
For --report markdown files

Use the same layout inside a code block (no ANSI codes):

██████╗██████╗
██╔════╝██╔══██╗
██║     ██║  ██║
██║     ██║  ██║
╚██████╗██████╔╝
╚═════╝╚═════╝

███████╗███████╗ ██████╗██╗   ██╗██████╗ ██╗████████╗██╗   ██╗
██╔════╝██╔════╝██╔════╝██║   ██║██╔══██╗██║╚══██╔══╝╚██╗ ██╔╝
███████╗█████╗  ██║     ██║   ██║██████╔╝██║   ██║    ╚████╔╝
╚════██║██╔══╝  ██║     ██║   ██║██╔══██╗██║   ██║     ╚██╔╝
███████║███████╗╚██████╗╚██████╔╝██║  ██║██║   ██║      ██║
╚══════╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝  ╚═╝╚═╝   ╚═╝      ╚═╝

Audit Preparation v1.0

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/audit-prep of PlamenTSV/plamen.

  • SKILL.md
  • VERSION
  • evals/evals.json
  • evals/grade.sh
  • references/agents/infrastructure-agent.md
  • references/agents/source-analysis-agent.md
  • references/agents/testing-agent.md
  • references/shared-rules.md

Open the folder on GitHubat commit 795962b

Compare with similar skills

Audit Prep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Prep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Prep this skillPlamenTSV/plamen303—~3.7kAutomated safety check: PassMIT
Audit Prep Assistanttrailofbits/skills7.4k—~2.5kAutomated safety check: PassCC-BY-SA-4.0
Auditsablier-labs/evm-monorepo353—~1.8kAutomated safety check: PassCustom licence
Audit Prepccashwell/evm-cortex131—~1.4kAutomated safety check: PassMIT
Audit Finding Fixapache/magpie110—~4.9kAutomated safety check: PassApache-2.0
Flounderadshao/flounder517—~9.2kAutomated safety check: PassAGPL-3.0

Similar skills

  • Audit Prep Assistant

    trailofbits/skills

    Official

    Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.

    7.4k GitHub stars~2.5k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Audit

    sablier-labs/evm-monorepo

    Security audit and code review for Solidity smart contracts.

    353 GitHub stars~1.8k tokensUpdated 13 days ago
    Backend & APIsAuto-check passed
  • Audit Prep

    ccashwell/evm-cortex

    A skill your agent uses when preparing a codebase for security audit.

    131 GitHub stars~1.4k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Audit Finding Fix

    apache/magpie

    For a batch of findings from a non-security audit tool (<audit-tool — ruff / flake8 / mypy / pylint / CodeQL / Apache Verum / Apache Caer / equivalent; full list in the body) against <upstream…

    110 GitHub stars~4.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Flounder

    adshao/flounder

    Operates Flounder, an autonomous white-hat security auditor.

    517 GitHub stars~9.2k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 7 days ago
    SecurityAuto-check passed

More from PlamenTSV/plamen

All 87 skills in this repo
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 11 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 11 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 11 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 11 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 11 days ago
    Auto-check passed
  • Auth Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Soroban audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~2.2k tokensUpdated 11 days ago
    Auto-check passed

Works with

Categories

Questions about Audit Prep

What does Audit Prep do?

Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…. Audit Prep is an agent skill from PlamenTSV/plamen. Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project documentation checks.

When should I use Audit Prep?

Audit Prep fits situations like: : prepare for audit; audit readiness; pre-audit check; any request to review a Solidity codebase before a security review.

How do I install Audit Prep in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill audit-prep -a claude-code`. Or copy the skill folder (skills/audit-prep in PlamenTSV/plamen) into .claude/skills/audit-prep in your project. Claude Code loads it when a task matches its description.

How do I install Audit Prep in Codex?

Run `npx skills add PlamenTSV/plamen --skill audit-prep -a codex`. Or copy the skill folder (skills/audit-prep in PlamenTSV/plamen) into .agents/skills/audit-prep in your project. Codex loads it when a task matches its description.

Can I use Audit Prep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill audit-prep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-prep, .gemini/skills/audit-prep, .github/skills/audit-prep and .opencode/skills/audit-prep in your project.

What does Audit Prep need to run?

Going by SKILL.md and its folder, Audit Prep needs a shell for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: A Bash shell.

Does Audit Prep access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Prep safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Prep use?

Audit Prep is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Prep use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5k tokens, read only when the agent opens those files.

What are the alternatives to Audit Prep?

Skills that share tags, products or a category with Audit Prep: Audit Prep Assistant (trailofbits/skills, 7.4k stars), Audit (sablier-labs/evm-monorepo, 353 stars), Audit Prep (ccashwell/evm-cortex, 131 stars) and Audit Finding Fix (apache/magpie, 110 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Prep?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.