Agent skill

Project Audit

by sd0xdev in sd0xdev/sd0x-harness

Project health audit with deterministic scoring. An agent skill from sd0xdev/sd0x-harness.

MITAuto-check passedDevelopment

Install Project Audit

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill project-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness project-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/project-audit .claude/skills/project-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
project-audit
GitHub stars
192
Token cost
~739 tokens
SKILL.md length
261 words
Files
4 (incl. scripts, references)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Project health audit with deterministic scoring. An agent skill from sd0xdev/sd0x-harness.

  • Works in 6 steps: Run bash scripts/run-skill.sh… → Parse the JSON output — overall_score,… → If status = Blocked (P0 findings) —… → …
  • : evaluating project quality
  • SKILL.md covers When NOT to Use, Procedure, Script Integration and Output Format, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls bash

What it does

Project Audit is an agent skill from sd0xdev/sd0x-harness. Project health audit with deterministic scoring. Use when: evaluating project quality, onboarding to new codebase, periodic health checks. Not for: runtime performance analysis, security-specific audits (use /codex-security). Output: 5-dimension score + actionable findings.

Its SKILL.md is about 740 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/check-catalog.md`, `references/output-template.md` and `scripts/audit.js`).

It sits in Development. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • : evaluating project quality
  • Onboarding to new codebase
  • Periodic health checks

Example prompts

  • “/project-audit”

Requirements

  • Node.js
  • Docker

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Run bash scripts/run-skill.sh project-audit audit.js --json to collect deterministic scores
  2. Parse the JSON output — overall_score, status, dimensions, checks, findings, next_actions
  3. If status = Blocked (P0 findings) — highlight critical gaps, suggest immediate fixes
  4. If status = Needs Work (P1 findings) — format improvement roadmap by dimension
  5. If status = Healthy — summarize strengths, note any P2 improvements
  6. Add qualitative interpretation beyond the scores (e.g., "test ratio is good but concentrated in unit tests")

What it can do on your machine

Read from SKILL.md and the folder at commit c9a2036. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Project Audit loads about 739 tokens when it runs, and up to ~1.8k if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 261 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~739
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit c9a2036, republished under its MIT licence (© sd0xdev). 261 words, ~739 tokens.

Download SKILL.mdSave it as .claude/skills/project-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
project-audit
description
Project health audit with deterministic scoring. Use when: evaluating project quality, onboarding to new codebase, periodic health checks. Not for: runtime performance analysis, security-specific audits (use /codex-security). Output: 5-dimension score + actionable findings.

Project Audit

When NOT to Use

  • Security-specific review (use /codex-security)
  • Runtime performance profiling
  • Mid-development review (use /codex-review-fast)

Procedure

  1. Run bash scripts/run-skill.sh project-audit audit.js --json to collect deterministic scores
  2. Parse the JSON output — overall_score, status, dimensions, checks, findings, next_actions
  3. If status = Blocked (P0 findings) — highlight critical gaps, suggest immediate fixes
  4. If status = Needs Work (P1 findings) — format improvement roadmap by dimension
  5. If status = Healthy — summarize strengths, note any P2 improvements
  6. Add qualitative interpretation beyond the scores (e.g., "test ratio is good but concentrated in unit tests")

Script Integration

The audit script runs 12 deterministic checks across 5 dimensions:

DimensionChecksWhat It Measures
oss2LICENSE, README quality
robustness3CI config, lint/typecheck, test ratio
scope2Declared features vs implementation, AC completion
runnability3Package manifest, scripts, env/Docker setup
stability2Lock file + audit, type configuration
Scoring Model
  • Each check: 1 (pass) / 0.5 (partial) / 0 (fail) / N/A (skipped)
  • Dimension score: applicable_sum / applicable_count * 100
  • Overall score: average of dimension scores
  • Confidence: applicable_checks / total_checks per dimension
Status Determination
StatusConditionExit Code
BlockedAny P0 finding2
Needs WorkNo P0, has P11
HealthyNo P0/P10
Script Failure Fallback

If the script fails, report the error and suggest running manually:

bash
bash scripts/run-skill.sh project-audit audit.js --json

Output Format

## Project Audit Report

| Field | Value |
|-------|-------|
| Repo | [name] |
| Score | **[N]/100** |
| Status | [icon] [status] |

### Dimensions
[table of dimension scores]

### Checks
[list of check results with suggestions]

### Next Actions
[prioritized action items]

## Gate: ✅/⛔

References

  • references/check-catalog.md — Check definitions, scoring criteria, ecosystem detection (read when investigating a specific check result)
  • references/output-template.md — Report format examples and JSON schema (read when customizing output)

Verification

  • Script ran successfully
  • All 12 checks executed (or marked N/A with reason)
  • Qualitative interpretation added beyond raw scores
  • Next actions are actionable (include commands where applicable)

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/project-audit of sd0xdev/sd0x-harness.

  • SKILL.md
  • references/check-catalog.md
  • references/output-template.md
  • scripts/audit.js

Open the folder on GitHubat commit c9a2036

Compare with similar skills

Project Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Project Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Project Audit this skillsd0xdev/sd0x-harness192—~739Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k24 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 24 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Guidelines

    akash-network/node

    Behavioral guidelines to reduce common LLM coding mistakes. An agent skill from akash-network/node.

    1.1k GitHub starsUsed in 22 repos~577 tokens
    DevelopmentAuto-check passed

More from sd0xdev/sd0x-harness

All 91 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Project Audit

What does Project Audit do?

Project health audit with deterministic scoring. An agent skill from sd0xdev/sd0x-harness. Project Audit is an agent skill from sd0xdev/sd0x-harness. Project health audit with deterministic scoring.

When should I use Project Audit?

Project Audit fits situations like: : evaluating project quality; onboarding to new codebase; periodic health checks.

How do I install Project Audit in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill project-audit -a claude-code`. Or copy the skill folder (skills/project-audit in sd0xdev/sd0x-harness) into .claude/skills/project-audit in your project. Claude Code loads it when a task matches its description.

How do I install Project Audit in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill project-audit -a codex`. Or copy the skill folder (skills/project-audit in sd0xdev/sd0x-harness) into .agents/skills/project-audit in your project. Codex loads it when a task matches its description.

Can I use Project Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill project-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/project-audit, .gemini/skills/project-audit, .github/skills/project-audit and .opencode/skills/project-audit in your project.

What does Project Audit need to run?

Going by SKILL.md and its folder, Project Audit needs JavaScript for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: Node.js; Docker.

Does Project Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Project Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Project Audit use?

Project Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Project Audit use?

About 739 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.

What are the alternatives to Project Audit?

Skills that share tags, products or a category with Project Audit: Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars) and Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Project Audit?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 6, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.