Agent skill

Production Audit

by sickn33 in sickn33/agentic-awesome-skills

Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.

MITAuto-check passedBackend & APIs

Install Production Audit

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill production-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills production-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/production-audit .claude/skills/production-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
production-audit
GitHub stars
47k
Used in
1 other repo
Token cost
~2.7k tokens
SKILL.md length
1,221 words
Files
1
Skills in repo
1,493
Repo updated
First seen
Licence
MIT

At a glance

Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.

  • Works in 4 steps: Run the audit → Parse the envelope → Surface to the user → …
  • Tasks that involve Webhooks
  • SKILL.md covers Overview, When to Use This Skill, How It Works and Examples, plus 6 more sections
  • Calls npx, jq and git; reaches api.commit.show

What it does

Production Audit is an agent skill from sickn33/agentic-awesome-skills. Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Webhooks and Mobile UI design. It works with Stripe and GitHub. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Webhooks
  • Tasks that involve Mobile UI design

Example prompts

  • “/production-audit”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Run the audit
  2. Parse the envelope
  3. Surface to the user
  4. If the user picks a concern, scope a fix

What it can do on your machine

Read from SKILL.md and the folder at commit 680176d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • jq
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.commit.show

    Also links to:

    • github.com
    • commit.show
    • skills.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Production Audit loads about 2.7k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 1,221 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 680176d, republished under its MIT licence (© sickn33). 1,221 words, ~2,713 tokens.

Download SKILL.mdSave it as .claude/skills/production-audit/SKILL.md (or your agent's skills folder).
name
production-audit
description
Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.
category
security
risk
critical
source
community
source_repo
commitshow/production-audit
source_type
community
date_added
2026-05-04
author
commitshow
tags
security, audit, production, vibe-coding, rls, webhook, stripe, supabase, mobile
tools
claude, cursor, gemini, codex, antigravity
license
MIT

Production Audit

Overview

A skill that runs an external audit on a shipped repo's deployed state — live URL, GitHub signals, secrets exposure, RLS gaps, webhook idempotency, indexes, observability, prompt injection, and ten other failure modes that AI-assisted projects routinely miss.

This is complementary to in-session security skills (security-review, OWASP-style, VibeSec, Trail of Bits). Those scan the editor buffer at write-time. This scans the deployed product after you commit. Different timing, different inputs, different findings. Run both for serious launches.

The skill wraps the commit.show audit engine via the public CLI (npx commitshow@0.3.23 audit . --json). Stable JSON envelope (schema_version: "1", additive-only). Writes a .commitshow/audit.{md,json} sidecar so future agent sessions can read prior state without re-running the engine.

When to Use This Skill

  • Use when the user asks "is this production-ready", "what would break in prod", "score my project", "what did I miss", "audit my repo", "ready to ship".
  • Use right after merging a feature branch to main (helpful as a pre-deploy gate).
  • Use before a public launch / Show HN post / investor demo.
  • Use when git log shows >20 commits since the last .commitshow/audit.md was written.
Skip when
  • During active in-session coding — use security-review / OWASP-style for line-level patterns. This skill is for post-merge / pre-ship review.
  • For library / scaffold-form repos — the engine handles app form best; libraries get a partial-substitute score.
  • If .commitshow/audit.json already exists and is < 1 hour old, read that instead of re-running. Audit is rate-limited (anonymous: 20/IP/day · 5/repo/day · 2000/day global).
  • Inside a private / non-GitHub repo — the audit pulls public GitHub signals, so private repos return a not_found error.

How It Works

Step 1: Run the audit

From the repo root. The CLI is pinned to an exact reviewed version so future npm releases are not selected silently. Because npx downloads and runs npm package code locally with the current user's permissions, run it only after the user explicitly approves this external execution and only in a repository where local files and environment variables are safe for that process to access. The sidecar directory is created up-front, and stderr is split off so install/deprecation warnings can't corrupt the JSON envelope:

bash
mkdir -p .commitshow
npx commitshow@0.3.23 audit . --json \
  > .commitshow/audit.json \
  2> .commitshow/audit.stderr.log

This also writes a human-readable .commitshow/audit.md next to it. Subsequent invocations should diff against the prior audit.json if it exists, so you can lead with "+5 since yesterday's audit" instead of just an absolute number.

If the user pointed at a remote URL instead of ., swap . for the URL — keep the same mkdir -p + version pin + stderr split:

bash
mkdir -p .commitshow
npx commitshow@0.3.23 audit github.com/owner/repo --json \
  > .commitshow/audit.json \
  2> .commitshow/audit.stderr.log
Step 2: Parse the envelope

The JSON envelope is stable (schema_version: "1", additive-only). Read these fields:

FieldMeaning
score.total0-100 production-readiness score
score.delta_since_lastchange vs. parent snapshot · positive = improving
score.bandstrong (80+) · mid (60-79) · early (<60)
concerns[]top issues, ordered by impact · each has axis + bullet
strengths[]top 3 things that work · for context only
standingoptional · only when the project is auditioning on commit.show
snapshot.created_at / trigger_typewhen the audit ran

Concerns are sorted by decision-impact, not severity. Position 1 is the bullet to lead with.

Step 3: Surface to the user

Lead with score + trajectory in one sentence, then the top concerns. Do not dump the full JSON. Format:

Score: 82/100 (+5 since yesterday) · band: strong

Top concerns:
  ↓ [Security] No API rate limiting on /auth — IP cap missing
  ↓ [Infrastructure] webhook handler at api/stripe.ts — signature verified, but no
    idempotency-key check (replay attack window open)

Want me to fix the webhook idempotency gap first?

Rules:

  • Use the exact bullet from concerns[].bullet — the audit engine already wrote action-oriented copy.
  • Don't list strengths unless the user explicitly asks. They're not actionable in this context.
  • Always end with a follow-up question that names a specific concern. Don't ask "what do you want to do?" — ask "fix X first?".
  • If score.delta_since_last is negative or null, lead with the absolute score only.
Step 4: If the user picks a concern, scope a fix

For the chosen concern:

  1. Read the file(s) cited in the bullet.
  2. Confirm the gap matches the description (the engine occasionally over-flags when the issue is mitigated elsewhere).
  3. Propose a minimal patch — single-file when possible.
  4. Don't apply without explicit approval. Show the diff first. The user is deciding what to ship; you're a lens.

After applying a fix, suggest re-running with --refresh (same canonical form as Step 1, so audit.json stays the source of truth for delta calculations):

bash
mkdir -p .commitshow
npx commitshow@0.3.23 audit . --json --refresh \
  > .commitshow/audit.json \
  2> .commitshow/audit.stderr.log

Examples

Example 1: User asks "is this production-ready?"
bash
mkdir -p .commitshow
npx commitshow@0.3.23 audit . --json \
  > .commitshow/audit.json \
  2> .commitshow/audit.stderr.log

Then surface:

Score: 67/100 · band: mid

Top concerns:
  ↓ [Security] members table uses column-level GRANT but paid_audits_credit
    column lacks SELECT grant — silent 42501 on every read
  ↓ [Infrastructure] stripe.checkout.sessions.create called without
    idempotencyKey — duplicate-charge surface

Want me to fix the column GRANT first? Single SQL line.
Example 2: Cross-check a specific concern

User: "show me where the webhook idempotency gap is"

bash
cat .commitshow/audit.json | jq '.concerns[] | select(.axis=="Infrastructure")'

Find the file path in the bullet, read it, confirm the gap matches.

Show full SKILL.md (511 more words)Show less

Best Practices

  • ✅ Always cite the exact bullet from concerns[].bullet — they're already action-oriented
  • ✅ Lead with score + delta in a single sentence, then concerns
  • ✅ End with a specific follow-up question naming a concern
  • ✅ Read prior .commitshow/audit.json before re-running (within 1h)
  • ✅ Use --refresh after the user merges a fix so the next audit reflects it
  • ❌ Don't dump full JSON to the user
  • ❌ Don't list strengths unless the user explicitly asks
  • ❌ Don't apply fixes without approval — show diff first
  • ❌ Don't fault private repos for not auditing — explain why and suggest making public

Limitations

  • This skill does not replace environment-specific validation, testing, or expert review.
  • The audit engine is calibrated for deployed apps with a live URL. CLI / library / scaffold form gets a partial-substitute score (max ~45/50 on the audit pillar) — fair but not flattering.
  • Behind a corporate firewall blocking *.supabase.co, the API call fails. There is no offline mode — the audit relies on the public engine.
  • Cold audit takes 60-90s. Cached audits (within 7 days) return instantly. --refresh force-bypasses cache (counts against rate limits).

Security & Safety Notes

  • The skill executes npx commitshow@0.3.23 audit ..., which downloads and runs that exact npm package version locally, then calls the public API at https://api.commit.show (proxied to Supabase Edge Functions). Do not replace the exact version with latest or a semver range during normal use.
  • Treat the CLI as external code with local process privileges. It must not be run in repositories containing secrets or sensitive uncommitted files unless the user has explicitly accepted that risk. No credentials are intentionally sent to the API, but the local process can access files and environment variables available to the current user.
  • The CLI writes .commitshow/audit.{md,json} in the current working directory. These files are safe to commit (no secrets) but conventionally gitignored as transient artifacts.
  • The audit engine only reads public GitHub signals. It does not modify the user's repo or push commits.
  • All per-finding fix proposals must be shown as diffs and approved by the user before any edit. Never apply without explicit confirmation.

Common Pitfalls

  • Problem: Audit returns not_found for a private repo Solution: The engine pulls public GitHub signals only. Either make the repo public or use --no-network for local-only deterministic checks.

  • Problem: Rate limit hit (429) Solution: Wait until next day (limits reset 00:00 UTC) or sign in at commit.show for higher per-repo caps.

  • Problem: Score seems too low for a polished library / CLI Solution: The engine biases toward app form. CLI / library / scaffold gets a partial substitute score capped around 45/50 on the audit pillar. Calibration acknowledged trade-off.

  • Problem: concerns[] is empty after re-running Solution: Re-audit may have hit cache. Use --refresh to force-bypass.

  • @security-review — In-session line-level security patterns. Run alongside this skill, not in place of.
  • @vibesec — Editor-buffer security review for vibe-coded projects. Different lens.
  • @owasp-security — OWASP Top 10 coverage during coding. Companion.
  • @trail-of-bits-skills — CodeQL / Semgrep static analysis. Different layer.

Additional Resources

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/production-audit of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 680176d

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Production Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Production Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Production Audit this skillsickn33/agentic-awesome-skills47k1 repos~2.7kAutomated safety check: PassMIT
Webhook SubscriptionsTommy-yw/RunbookHermes5461 repos~1.7kAutomated safety check: NotesMIT
Webhook Subscriptionsmateaix/mateclaw1.1k—~1.7kAutomated safety check: NotesApache-2.0
Emulate Seedyonatangross/orchestkit290—~4.5kAutomated safety check: PassMIT
Webhook SubscriptionsRedWoodOG/Hermes-Desktop177—~1.4kAutomated safety check: NotesNone
Ade Webhooksarul28/ADE114—~2.1kAutomated safety check: PassAGPL-3.0

Similar skills

  • Webhook Subscriptions

    Tommy-yw/RunbookHermes

    Create and manage webhook subscriptions for event-driven agent activation, or for direct push notifications (zero LLM cost).

    546 GitHub starsUsed in 1 repo~1.7k tokens
    Backend & APIsAuto-check: notes
  • Webhook Subscriptions

    mateaix/mateclaw

    Webhook subscriptions: event-driven agent runs. An agent skill from mateaix/mateclaw.

    1.1k GitHub stars~1.7k tokensUpdated 4 days ago
    Backend & APIsAuto-check: notes
  • Emulate Seed

    yonatangross/orchestkit

    Generate emulate seed configs for stateful API emulation. An agent skill from yonatangross/orchestkit.

    290 GitHub stars~4.5k tokensUpdated today
    Backend & APIsAuto-check passed
  • Webhook Subscriptions

    RedWoodOG/Hermes-Desktop

    Create and manage webhook subscriptions for event-driven agent activation.

    177 GitHub stars~1.4k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Ade Webhooks

    arul28/ADE

    A skill your agent uses when someone wants an agent to run whenever something happens in another service — a GitHub issue or PR, a Stripe payment, a Linear issue, a Sentry error, a failed deploy…

    114 GitHub stars~2.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Trigger Registry

    evolution-foundation/evo-nexus

    Create, manage, and test reactive triggers (webhook & event-based).

    545 GitHub stars~1.4k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,493 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Works with

Questions about Production Audit

What does Production Audit do?

Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health. Production Audit is an agent skill from sickn33/agentic-awesome-skills. Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.

When should I use Production Audit?

Production Audit fits situations like: tasks that involve Webhooks; tasks that involve Mobile UI design.

How do I install Production Audit in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill production-audit -a claude-code`. Or copy the skill folder (skills/production-audit in sickn33/agentic-awesome-skills) into .claude/skills/production-audit in your project. Claude Code loads it when a task matches its description.

How do I install Production Audit in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill production-audit -a codex`. Or copy the skill folder (skills/production-audit in sickn33/agentic-awesome-skills) into .agents/skills/production-audit in your project. Codex loads it when a task matches its description.

Can I use Production Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill production-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/production-audit, .gemini/skills/production-audit, .github/skills/production-audit and .opencode/skills/production-audit in your project.

What does Production Audit need to run?

Going by SKILL.md and its folder, Production Audit needs the command-line tools its instructions call (npx, jq and git). Our summary lists: Node.js.

Does Production Audit access the network?

SKILL.md names 4 domains. In commands or code: api.commit.show; the agent is likely to contact it when it follows the instructions. As links in the text: github.com, commit.show and skills.sh. This is read from the text; nothing was executed.

Is Production Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Production Audit use?

Production Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Production Audit use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Production Audit?

Skills that share tags, products or a category with Production Audit: Webhook Subscriptions (Tommy-yw/RunbookHermes, 546 stars), Webhook Subscriptions (mateaix/mateclaw, 1.1k stars), Emulate Seed (yonatangross/orchestkit, 290 stars) and Webhook Subscriptions (RedWoodOG/Hermes-Desktop, 177 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Production Audit?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,379 GitHub stars. The repository holds 1,493 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.