Agent skill

Infra Audit

by SethGammon in SethGammon/Citadel

Reads docker-compose, env files, ORM configs, and connection strings to map current infrastructure.

MITAuto-check: notesDatabases

Install Infra Audit

skills CLI
$ npx skills add SethGammon/Citadel --skill infra-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SethGammon/Citadel infra-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SethGammon/Citadel.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/infra-audit .claude/skills/infra-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
infra-audit
GitHub stars
923
Token cost
~2.1k tokens
SKILL.md length
739 words
Files
1
Skills in repo
48
Repo updated
First seen
Licence
MIT

At a glance

Reads docker-compose, env files, ORM configs, and connection strings to map current infrastructure.

  • Works in 5 steps: DISCOVER → TRACE CONNECTIONS → ANALYZE PATTERNS → …
  • Tasks that involve ORMs and data access
  • SKILL.md covers When to Use, Protocol, Fringe Cases and Contextual Gates, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Infra Audit is an agent skill from SethGammon/Citadel. Reads docker-compose, env files, ORM configs, and connection strings to map current infrastructure. Flags missing layers (cache, queue, analytics) based on observed access patterns. Outputs a structured infrastructure manifest.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases, covering ORMs and data access, Containers and Search implementation. It works with Docker, Prisma, Elasticsearch and Redis. The repository describes itself as: The operating layer for Claude Code + OpenAI Codex: persistent project memory, intent routing, safety hooks, cost telemetry, and parallel agent fleets. The licence is MIT.

When your agent uses it

  • Tasks that involve ORMs and data access
  • Tasks that involve Containers
  • Tasks that involve Search implementation

Example prompts

  • “Use the infra-audit skill to read docker-compose, env files, ORM configs, and connection strings to map current infrastructure”
  • “/infra-audit”

Requirements

  • Docker

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. DISCOVER
  2. TRACE CONNECTIONS
  3. ANALYZE PATTERNS
  4. WRITE MANIFEST
  5. RETURN

What it can do on your machine

Read from SKILL.md and the folder at commit e41ff1d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Infra Audit loads about 2.1k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 739 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:47
    - `.env`, `.env.*`, `.env.example`, `.env.local`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SethGammon/Citadel at commit e41ff1d, republished under its MIT licence (© SethGammon). 739 words, ~2,054 tokens.

Download SKILL.mdSave it as .claude/skills/infra-audit/SKILL.md (or your agent's skills folder).
name
infra-audit
description
Reads docker-compose, env files, ORM configs, and connection strings to map current infrastructure. Flags missing layers (cache, queue, analytics) based on observed access patterns. Outputs a structured infrastructure manifest.
license
MIT
user-invocable
true
auto-trigger
false
trigger_keywords
infra, infrastructure, what databases, what systems, docker-compose, infra audit, map infrastructure, what does this connect to
last-updated
2026-03-29

/infra-audit -- Infrastructure Auditor

When to Use

  • Before adding a new database, cache, or queue to a project
  • When onboarding to an unfamiliar codebase and need to understand its infra
  • Before planning a workspace campaign that spans multiple services
  • When someone asks "what systems does this project talk to?"

Do not use when:

  • The user already knows the infra and just wants to wire something up (use /architect)
  • The question is about code architecture, not infrastructure (use /research)

Protocol

Step 1: DISCOVER

Scan the project for infrastructure configuration files. Check each category:

Container orchestration:

  • docker-compose.yml, docker-compose.*.yml
  • Dockerfile, *.dockerfile
  • k8s/, kubernetes/, helm/, charts/

Environment and secrets:

  • .env, .env.*, .env.example, .env.local
  • *.env files in config directories

Database and ORM:

  • Prisma: prisma/schema.prisma
  • Drizzle: drizzle.config.ts, drizzle/
  • TypeORM: ormconfig.*, data-source.ts
  • Sequelize: .sequelizerc, config/database.*
  • Knex: knexfile.*
  • SQLAlchemy: alembic.ini, alembic/
  • Django: settings.py (DATABASES section)
  • Rails: config/database.yml
  • Go: look for pgx, gorm, sqlx in go.mod

Message queues and event streaming:

  • Redis: connection strings, ioredis, redis in package.json/requirements.txt/go.mod
  • RabbitMQ: amqplib, pika, amqp imports
  • Kafka: kafkajs, confluent-kafka, sarama imports
  • NATS: nats, nats.go imports
  • SQS/SNS: @aws-sdk/client-sqs, boto3 sqs references

Cache:

  • Redis (dual-use -- note if used as cache vs. pub/sub vs. primary store)
  • Memcached: memcached, pylibmc imports

Search:

  • Elasticsearch: @elastic/elasticsearch, elasticsearch-py
  • Meilisearch, Typesense, Algolia client libraries

Object storage:

  • S3: @aws-sdk/client-s3, boto3 s3 references
  • MinIO, GCS, Azure Blob client libraries

External APIs:

  • Stripe, Twilio, SendGrid, Auth0, Firebase, Supabase client libraries
  • Any NEXT_PUBLIC_* or VITE_* env vars pointing to external services

CI/CD:

  • .github/workflows/, .gitlab-ci.yml, Jenkinsfile, bitbucket-pipelines.yml

For each discovered item, record:

  • What: the system (e.g., "PostgreSQL 15")
  • Where: config file path and line
  • How: connection method (direct, pooled, ORM, SDK)
  • Role: primary store, cache, queue, search, auth, etc.
Step 2: TRACE CONNECTIONS

For each discovered system, trace how the application connects:

  1. Find connection strings in env files or config
  2. Find the client initialization code (imports, new Client(), createPool())
  3. Identify which modules/services use this connection
  4. Note connection pooling, retry logic, health checks if present

Build a connection graph:

App --> [pool: 10] --> PostgreSQL (primary store)
App --> [ioredis]  --> Redis (cache + pub/sub)
App --> [SDK]      --> Stripe (payments)
Step 3: ANALYZE PATTERNS

Based on what's connected and how it's used, identify:

Access patterns:

  • Read-heavy vs. write-heavy (look at query patterns in ORM usage)
  • Real-time vs. batch (WebSocket/SSE presence, cron jobs)
  • Request/response vs. event-driven (queue usage, webhook handlers)

Missing layers (flag only when evidence supports the need):

SignalLikely MissingEvidence Required
Repeated identical DB queries in hot pathsCache layer (Redis/Memcached)Same query in 3+ request handlers
setTimeout/setInterval for deferred workJob queue (Bull/BullMQ/Celery)Processing that doesn't need to block the response
Full-text search via LIKE '%term%'Search engine (Elasticsearch/Meilisearch)Text search on >10K rows
Large file uploads stored in DB or local diskObject storage (S3/MinIO)Binary columns or fs.writeFile for user content
Analytics queries on production tablesAnalytics DB (Snowflake/BigQuery/ClickHouse)Aggregation queries mixed with OLTP
Multiple services sharing one DBEvent bus or API gateway2+ repos writing to same schema
No connection poolingConnection pooler (PgBouncer)Direct connections in serverless/high-concurrency

Do not flag something as missing unless the evidence is in the code.

Show full SKILL.md (245 more words)Show less
Step 4: WRITE MANIFEST

Output the infrastructure manifest to .planning/infra-manifest.md:

markdown
# Infrastructure Manifest

> Generated: {ISO date}
> Project: {project name from package.json or repo name}

## Current Systems

### {System Name} -- {Role}
- **Type**: {database|cache|queue|search|storage|auth|payments|...}
- **Product**: {PostgreSQL 15|Redis 7|Stripe SDK|...}
- **Config**: `{file path}`
- **Connection**: {method -- pooled, direct, SDK, ORM}
- **Used by**: {modules/services that import the client}

(repeat for each system)

## Connection Graph

{ASCII diagram of connections -- use /ascii-diagram conventions}

## Access Patterns

- {Pattern 1}: {evidence}
- {Pattern 2}: {evidence}

## Opportunities

### {Opportunity Title}
- **Signal**: {what in the code suggests this}
- **System**: {what would address it -- e.g., "Redis as cache layer"}
- **Impact**: {what improves -- latency, scalability, separation of concerns}
- **Effort**: low | medium | high

(repeat for each opportunity)

## Multi-Repo Considerations

{If the project references other repos, APIs, or shared databases, note them here.
This section feeds directly into /workspace if the user wants to act on opportunities
that span repos.}
Step 5: RETURN

Present a summary to the user:

  • How many systems found
  • The connection graph (inline, not just in the file)
  • Top opportunities ranked by signal strength
  • Whether any opportunities would require multi-repo coordination (suggest /workspace)

Fringe Cases

  • No docker-compose or env files: Scan for hardcoded connection strings in source code. Many projects connect without formal config files. Check src/, lib/, config/ for connection patterns. Note the absence of externalized config as a finding.
  • Monorepo with multiple services: Treat each service directory as a separate scan target. Produce one manifest with sections per service. Note shared databases across services.
  • .planning/ does not exist: Create it before writing the manifest.
  • No infrastructure found: Report that the project appears to be client-only or has no external dependencies. This is a valid finding, not an error.
  • Secrets in env files: Never include actual secret values in the manifest. Record the variable name and which system it connects to, not the value.

Contextual Gates

Disclosure: "Auditing infrastructure configuration. No files modified." Reversibility: green — read-only audit; only writes .planning/infra-manifest.md; undo with rm .planning/infra-manifest.md. Trust gates:

  • Any: full audit, manifest generation, opportunity analysis.

Quality Gates

  • Every discovered system has: type, product, config path, connection method
  • Connection graph covers all discovered systems
  • Opportunities cite specific code evidence (file:line), not speculation
  • No secret values appear in the manifest
  • Manifest written to .planning/infra-manifest.md
  • Multi-repo considerations section populated if cross-repo signals exist

Exit Protocol

---HANDOFF---
- Scanned {N} config files, found {M} external systems
- Key systems: {list top 3-4}
- Top opportunity: {highest-signal opportunity}
- Multi-repo scope: {yes/no -- if yes, suggest /workspace}
- Reversibility: green — delete .planning/infra-manifest.md to undo
---

© SethGammon, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/infra-audit of SethGammon/Citadel.

Open the folder on GitHubat commit e41ff1d

Compare with similar skills

Infra Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Infra Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Infra Audit this skillSethGammon/Citadel923—~2.1kAutomated safety check: NotesMIT
Use Sealoshashgraph-online/awesome-codex-plugins1.3k—~2.2kAutomated safety check: PassApache-2.0
Tgf Server Devthkhxm/tgf128—~1.3kAutomated safety check: NotesMIT
Create Environmentgodatadriven/whirl205—~1.9kAutomated safety check: PassApache-2.0
Docker Compose Testsjillesvangurp/kt-search155—~295Automated safety check: PassMIT
Cloudrun DevelopmentTencentCloudBase/CloudBase-AI-Toolkit1.1k1 repos~7.2kAutomated safety check: PassMIT

Similar skills

  • Use Sealos

    hashgraph-online/awesome-codex-plugins

    Deploy and operate apps on Sealos Cloud: sign in to a Sealos account, deploy any project or self-hosted app (from the template store, an official Docker image, or project source code), provision…

    1.3k GitHub stars~2.2k tokensUpdated today
    DatabasesAuto-check passed
  • Tgf Server Dev

    thkhxm/tgf

    基于 tgf v2(github.com/thkhxm/tgf/v2)用确定性的 tgfctl 工作流创建、验证和维护 Go 游戏服务器项目。

    128 GitHub stars~1.3k tokensUpdated 2 mo ago
    DatabasesAuto-check: notes
  • Create Environment

    godatadriven/whirl

    Create a new Whirl environment in the envs/ directory. An agent skill from godatadriven/whirl.

    205 GitHub stars~1.9k tokensUpdated 8 days ago
    Backend & APIsAuto-check passed
  • Docker Compose Tests

    jillesvangurp/kt-search

    Use Gradle Compose tasks to prepare and recover local Elasticsearch/OpenSearch test infrastructure in kt-search.

    155 GitHub stars~295 tokensUpdated 3 mo ago
    MobileAuto-check passed
  • Cloudrun Development

    TencentCloudBase/CloudBase-AI-Toolkit

    CloudBase Run backend development rules (Function mode/Container mode).

    1.1k GitHub starsUsed in 1 repo~7.2k tokens
    DatabasesAuto-check passed
  • Bump Test Image

    redis/node-redis

    Official

    Bump the default Redis docker test image (redislabs/client-libs-test) in the shared DEFAULTDOCKERCONFIG and the CI matrix, then force-push the bump-test-image branch and open a PR against upstream.

    18k GitHub stars~1.4k tokensUpdated yesterday
    DatabasesAuto-check passed

More from SethGammon/Citadel

All 48 skills in this repo
  • Create Skill

    SethGammon/Citadel

    Creates new skills from the user's repeating patterns. An agent skill from SethGammon/Citadel.

    923 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Houseclean

    SethGammon/Citadel

    Cross-drive storage audit and cleanup. An agent skill from SethGammon/Citadel.

    923 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Loop

    SethGammon/Citadel

    Bounded foreground repetition for the current session. An agent skill from SethGammon/Citadel.

    923 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Triage

    SethGammon/Citadel

    GitHub issue and PR investigator. An agent skill from SethGammon/Citadel.

    923 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Watch

    SethGammon/Citadel

    File sentinel that monitors the working directory for changes and marker comments, then auto-triggers appropriate skills.

    923 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Archon

    SethGammon/Citadel

    Autonomous multi-session campaign agent. An agent skill from SethGammon/Citadel.

    923 GitHub stars~5.4k tokensUpdated yesterday
    Auto-check passed

Questions about Infra Audit

What does Infra Audit do?

Reads docker-compose, env files, ORM configs, and connection strings to map current infrastructure. Infra Audit is an agent skill from SethGammon/Citadel. Reads docker-compose, env files, ORM configs, and connection strings to map current infrastructure.

When should I use Infra Audit?

Infra Audit fits situations like: tasks that involve ORMs and data access; tasks that involve Containers; tasks that involve Search implementation.

How do I install Infra Audit in Claude Code?

Run `npx skills add SethGammon/Citadel --skill infra-audit -a claude-code`. Or copy the skill folder (skills/infra-audit in SethGammon/Citadel) into .claude/skills/infra-audit in your project. Claude Code loads it when a task matches its description.

How do I install Infra Audit in Codex?

Run `npx skills add SethGammon/Citadel --skill infra-audit -a codex`. Or copy the skill folder (skills/infra-audit in SethGammon/Citadel) into .agents/skills/infra-audit in your project. Codex loads it when a task matches its description.

Can I use Infra Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SethGammon/Citadel --skill infra-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/infra-audit, .gemini/skills/infra-audit, .github/skills/infra-audit and .opencode/skills/infra-audit in your project.

What does Infra Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Infra Audit is instructions for the agent only. Our summary lists: Docker.

Does Infra Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Infra Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Infra Audit use?

Infra Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Infra Audit use?

About 2.1k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Infra Audit?

Skills that share tags, products or a category with Infra Audit: Use Sealos (hashgraph-online/awesome-codex-plugins, 1.3k stars), Tgf Server Dev (thkhxm/tgf, 128 stars), Create Environment (godatadriven/whirl, 205 stars) and Docker Compose Tests (jillesvangurp/kt-search, 155 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Infra Audit?

SethGammon (a GitHub user) maintains it in SethGammon/Citadel, which has 923 GitHub stars. The repository holds 48 skills in this directory. The repository was last updated on October 8, 2026.

Source: SethGammon/Citadel on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.