Agent skill

Codebase Audit Pre Push

by sickn33 in sickn33/agentic-awesome-skills

Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues.

MITAuto-check: notesSecurity

Install Codebase Audit Pre Push

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills codebase-audit-pre-push --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codebase-audit-pre-push .claude/skills/codebase-audit-pre-push && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codebase-audit-pre-push
GitHub stars
47k
Used in
2 other repos
Token cost
~2.1k tokens
SKILL.md length
913 words
Files
1
Skills in repo
1,394
Repo updated
First seen
Licence
MIT

At a glance

Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues.

  • Works in 10 steps: Clean Up Junk Files → Fix .gitignore → Audit Every Source File → …
  • Tasks that involve Security review
  • SKILL.md covers When to Use This Skill, Your Job, Audit Process and Output Format, plus 3 more sections
  • Calls npm

What it does

Codebase Audit Pre Push is an agent skill from sickn33/agentic-awesome-skills. Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. Checks every file line-by-line for production readiness.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. It works with GitHub. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Security review

Example prompts

  • “/codebase-audit-pre-push”

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Clean Up Junk Files
  2. Fix .gitignore
  3. Audit Every Source File
  4. Security Check (Zero Tolerance)
  5. Scalability Check
  6. Architecture Check
  7. Performance
  8. Documentation
  9. Testing
  10. Final Verification

What it can do on your machine

Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codebase Audit Pre Push loads about 2.1k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 913 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:44
    - `.env` files (should never be committed)
  • NoteMentions a .env fileSKILL.md:196
    - .env (contained secrets)
  • NoteMentions a .env fileSKILL.md:210
    PI key in config.js (line 12) → moved to .env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 913 words, ~2,108 tokens.

Download SKILL.mdSave it as .claude/skills/codebase-audit-pre-push/SKILL.md (or your agent's skills folder).
name
codebase-audit-pre-push
description
Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. Checks every file line-by-line for production readiness.
category
development
risk
safe
source
community
date_added
2026-03-05

Pre-Push Codebase Audit

As a senior engineer, you're doing the final review before pushing this code to GitHub. Check everything carefully and fix problems as you find them.

When to Use This Skill

  • User requests "audit the codebase" or "review before push"
  • Before making the first push to GitHub
  • Before making a repository public
  • Pre-production deployment review
  • User asks to "clean up the code" or "optimize everything"

Your Job

Review the entire codebase file by file. Read the code carefully. Fix issues right away. Don't just note problems—make the necessary changes.

Audit Process

1. Clean Up Junk Files

Start by looking for files that shouldn't be on GitHub:

Delete these immediately:

  • OS files: .DS_Store, Thumbs.db, desktop.ini
  • Logs: *.log, npm-debug.log*, yarn-error.log*
  • Temp files: *.tmp, *.temp, *.cache, *.swp
  • Build output: dist/, build/, .next/, out/, .cache/
  • Dependencies: node_modules/, vendor/, __pycache__/, *.pyc
  • IDE files: .idea/, .vscode/ (ask user first), *.iml, .project
  • Backup files: *.bak, *_old.*, *_backup.*, *_copy.*
  • Test artifacts: coverage/, .nyc_output/, test-results/
  • Personal junk: TODO.txt, NOTES.txt, scratch.*, test123.*

Critical - Check for secrets:

  • .env files (should never be committed)
  • Files containing: password, api_key, token, secret, private_key
  • *.pem, *.key, *.cert, credentials.json, serviceAccountKey.json

If you find secrets in the code, mark it as a CRITICAL BLOCKER.

2. Fix .gitignore

Check if the .gitignore file exists and is thorough. If it’s missing or not complete, update it to include all junk file patterns above. Ensure that .env.example exists with keys but no values.

3. Audit Every Source File

Look through each code file and check:

Dead Code (remove immediately):

  • Commented-out code blocks
  • Unused imports/requires
  • Unused variables (declared but never used)
  • Unused functions (defined but never called)
  • Unreachable code (after return, inside if (false))
  • Duplicate logic (same code in multiple places—combine)

Code Quality (fix issues as you go):

  • Vague names: data, info, temp, thing → rename to be descriptive
  • Magic numbers: if (status === 3) → extract to named constant
  • Debug statements: remove console.log, print(), debugger
  • TODO/FIXME comments: either resolve them or delete them
  • TypeScript any: add proper types or explain why any is used
  • Use === instead of == in JavaScript
  • Functions longer than 50 lines: consider splitting
  • Nested code greater than 3 levels: refactor with early returns

Logic Issues (critical):

  • Missing null/undefined checks
  • Array operations on potentially empty arrays
  • Async functions that are not awaited
  • Promises without .catch() or try/catch
  • Possibilities for infinite loops
  • Missing default in switch statements
4. Security Check (Zero Tolerance)

Secrets: Search for hardcoded passwords, API keys, and tokens. They must be in environment variables.

Injection vulnerabilities:

  • SQL: No string concatenation in queries—use parameterized queries only
  • Command injection: No exec() with user-provided input
  • Path traversal: No file paths from user input without validation
  • XSS: No innerHTML or dangerouslySetInnerHTML with user data

Auth/Authorization:

  • Passwords hashed with bcrypt/argon2 (never MD5 or plain text)
  • Protected routes check for authentication
  • Authorization checks on the server side, not just in the UI
  • No IDOR: verify users own the resources they are accessing

Data exposure:

  • API responses do not leak unnecessary information
  • Error messages do not expose stack traces or database details
  • Pagination is present on list endpoints

Dependencies:

  • Run npm audit or an equivalent tool
  • Flag critically outdated or vulnerable packages
Show full SKILL.md (395 more words)Show less
5. Scalability Check

Database:

  • N+1 queries: loops with database calls inside → use JOINs or batch queries
  • Missing indexes on WHERE/ORDER BY columns
  • Unbounded queries: add LIMIT or pagination
  • Avoid SELECT *: specify columns

API Design:

  • Heavy operations (like email, reports, file processing) → move to a background queue
  • Rate limiting on public endpoints
  • Caching for data that is read frequently
  • Timeouts on external calls

Code:

  • No global mutable state
  • Clean up event listeners (to avoid memory leaks)
  • Stream large files instead of loading them into memory
6. Architecture Check

Organization:

  • Clear folder structure
  • Files are in logical locations
  • No "misc" or "stuff" folders

Separation of concerns:

  • UI layer: only responsible for rendering
  • Business logic: pure functions
  • Data layer: isolated database queries
  • No 500+ line "god files"

Reusability:

  • Duplicate code → extract to shared utilities
  • Constants defined once and imported
  • Types/interfaces reused, not redefined
7. Performance

Backend:

  • Expensive operations do not block requests
  • Batch database calls when possible
  • Set cache headers correctly

Frontend (if applicable):

  • Implement code splitting
  • Optimize images
  • Avoid massive dependencies for small utilities
  • Use lazy loading for heavy components
8. Documentation

README.md must include:

  • Description of what the project does
  • Instructions for installation and execution
  • Required environment variables
  • Guidance on running tests

Code comments:

  • Explain WHY, not WHAT
  • Provide explanations for complex logic
  • Avoid comments that merely repeat the code
9. Testing
  • Critical paths should have tests (auth, payments, core features)
  • No test.only or fdescribe should remain in the code
  • Avoid test.skip without an explanation
  • Tests should verify behavior, not implementation details
10. Final Verification

After making all changes, run the app. Ensure nothing is broken. Check that:

  • The app starts without errors
  • Main features work
  • Tests pass (if they exist)
  • No regressions have been introduced

Output Format

After auditing, provide a report:

CODEBASE AUDIT COMPLETE  

FILES REMOVED:  
- node_modules/ (build artifact)  
- .env (contained secrets)  
- old_backup.js (unused duplicate)  

CODE CHANGES:  
[src/api/users.js]  
  ✂ Removed unused import: lodash  
  ✂ Removed dead function: formatOldWay()  
  🔧 Renamed 'data' → 'userData' for clarity  
  🛡 Added try/catch around API call (line 47)  

[src/db/queries.js]  
  ⚡ Fixed N+1 query: now uses JOIN instead of loop  

SECURITY ISSUES:  
🚨 CRITICAL: Hardcoded API key in config.js (line 12) → moved to .env  
⚠️ HIGH: SQL injection risk in search.js (line 34) → fixed with parameterized query  

SCALABILITY:  
⚡ Added pagination to /api/users endpoint  
⚡ Added index on users.email column  

FINAL STATUS:  
✅ CLEAN - Ready to push to GitHub  

Scores:  
Security: 9/10 (one minor header missing)  
Code Quality: 10/10  
Scalability: 9/10  
Overall: 9/10  

Key Principles

  • Read the code thoroughly, don't skim
  • Fix issues immediately, don’t just document them
  • If uncertain about removing something, ask the user
  • Test after making changes
  • Be thorough but practical—focus on real problems
  • Security issues are blockers—nothing should ship with critical vulnerabilities
  • @security-auditor - Deeper security review
  • @systematic-debugging - Investigate specific issues
  • @git-pushing - Push code after audit

Limitations

  • Use this skill only when the task clearly matches the scope described above.
  • Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
  • Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/codebase-audit-pre-push of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 1e53ce2

Used in 2 other repositories

We found 11 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Codebase Audit Pre Push next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codebase Audit Pre Push compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codebase Audit Pre Push this skillsickn33/agentic-awesome-skills47k2 repos~2.1kAutomated safety check: NotesMIT
Agentic GitHub Actions Auditortrailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
Audit Scopeforefy/.context152—~2.3kAutomated safety check: PassMIT
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone
Hunter 22aeonfun/aeon767—~1.7kAutomated safety check: PassMIT
Repo SentinelMathews-Tom/armory327—~2.2kAutomated safety check: PassMIT

Similar skills

  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • Audit Scope

    forefy/.context

    Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.

    152 GitHub stars~2.3k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Hunter 22

    aeonfun/aeon

    Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw…

    767 GitHub stars~1.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Repo Sentinel

    Mathews-Tom/armory

    Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.

    327 GitHub stars~2.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,394 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Works with

Categories

Questions about Codebase Audit Pre Push

What does Codebase Audit Pre Push do?

Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. Codebase Audit Pre Push is an agent skill from sickn33/agentic-awesome-skills. Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues.

When should I use Codebase Audit Pre Push?

Codebase Audit Pre Push fits situations like: tasks that involve Security review.

How do I install Codebase Audit Pre Push in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a claude-code`. Or copy the skill folder (skills/codebase-audit-pre-push in sickn33/agentic-awesome-skills) into .claude/skills/codebase-audit-pre-push in your project. Claude Code loads it when a task matches its description.

How do I install Codebase Audit Pre Push in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a codex`. Or copy the skill folder (skills/codebase-audit-pre-push in sickn33/agentic-awesome-skills) into .agents/skills/codebase-audit-pre-push in your project. Codex loads it when a task matches its description.

Can I use Codebase Audit Pre Push in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill codebase-audit-pre-push -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codebase-audit-pre-push, .gemini/skills/codebase-audit-pre-push, .github/skills/codebase-audit-pre-push and .opencode/skills/codebase-audit-pre-push in your project.

What does Codebase Audit Pre Push need to run?

Going by SKILL.md and its folder, Codebase Audit Pre Push needs the command-line tools its instructions call (npm).

Does Codebase Audit Pre Push access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codebase Audit Pre Push safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Codebase Audit Pre Push use?

Codebase Audit Pre Push is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codebase Audit Pre Push use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codebase Audit Pre Push?

Skills that share tags, products or a category with Codebase Audit Pre Push: Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), Audit Scope (forefy/.context, 152 stars), Security Secrets (IgorWarzocha/Opencode-Workflows, 122 stars) and Hunter 22 (aeonfun/aeon, 767 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codebase Audit Pre Push?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.