Agent skill

Architecture Audit

by softspark in softspark/ai-toolkit

Audits codebase for architectural friction, shallow modules; proposes RFCs.

Apache-2.0Auto-check: notes

Install Architecture Audit

skills CLI
$ npx skills add softspark/ai-toolkit --skill architecture-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install softspark/ai-toolkit architecture-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/architecture-audit .claude/skills/architecture-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
architecture-audit
GitHub stars
179
Token cost
~1.7k tokens
SKILL.md length
841 words
Files
1
Skills in repo
112
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audits codebase for architectural friction, shallow modules; proposes RFCs.

  • Works in 5 steps: Organic Exploration → Present Candidates → Frame the Problem Space → …
  • SKILL.md covers Usage, What This Command Does, Key Concept and Process, plus 11 more sections
  • Calls gh

What it does

Architecture Audit is an agent skill from softspark/ai-toolkit. Audits codebase for architectural friction, shallow modules; proposes RFCs. Triggers: improve architecture, shallow modules, deepen modules, reduce coupling.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with GitHub. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.

Example prompts

  • “Use the architecture-audit skill to audit codebase for architectural friction, shallow modules; proposes RFCs”
  • “/architecture-audit”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, Agent

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Organic Exploration
  2. Present Candidates
  3. Frame the Problem Space
  4. Design Multiple Interfaces
  5. Create GitHub Issue RFC

What it can do on your machine

Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • Agent

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Architecture Audit loads about 1.7k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 841 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, Agent

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 841 words, ~1,722 tokens.

Download SKILL.mdSave it as .claude/skills/architecture-audit/SKILL.md (or your agent's skills folder).
name
architecture-audit
description
Audits codebase for architectural friction, shallow modules; proposes RFCs. Triggers: improve architecture, shallow modules, deepen modules, reduce coupling.
allowed-tools
Read, Grep, Glob, Bash, Agent
user-invocable
true
effort
high
argument-hint
[area to audit or 'full codebase']

Architecture Audit

$ARGUMENTS

Explore a codebase organically, surface architectural friction, and propose module-deepening refactors as GitHub issue RFCs.

Usage

/architecture-audit [area to audit or 'full codebase']

What This Command Does

  1. Explores codebase organically — friction IS the signal
  2. Presents deepening candidates to user
  3. Frames problem space for chosen candidate
  4. Spawns 3+ parallel sub-agents for radically different interface designs
  5. Compares and recommends
  6. Files RFC as GitHub issue

Key Concept

A deep module (Ousterhout) has a small interface hiding a large implementation. Deep modules enhance testability, AI navigation, and enable boundary testing.

A shallow module has a large interface with thin implementation — avoid.

Process

1. Organic Exploration

Use Agent (subagent_type=Explore) to navigate the codebase naturally. Note friction:

  • Where does understanding one concept require bouncing between many small files?
  • Where are modules so shallow the interface is nearly as complex as the implementation?
  • Where have pure functions been extracted just for testability but real bugs hide in how they're called?
  • Where do tightly-coupled modules create integration risk in the seams?
  • What is untested or hard to test?
2. Present Candidates

Numbered list. For each candidate show:

FieldContent
ClusterWhich modules/concepts are involved
Why coupledShared types, call patterns, co-ownership
Dependency categoryIn-process, Local-substitutable, Ports & Adapters, or True external (see reference/)
Test impactWhat existing tests would be replaced by boundary tests

Do NOT propose interfaces yet. Ask: "Which would you like to explore?"

3. Frame the Problem Space

For the chosen candidate, write a user-facing explanation:

  • Constraints any new interface would satisfy
  • Dependencies it would rely on
  • Rough illustrative code sketch (not a proposal — just grounding)

Show to user, then immediately proceed to step 4.

4. Design Multiple Interfaces

Spawn 3+ sub-agents in parallel via Agent tool. Each gets a different constraint:

AgentConstraint
Agent 1Minimize interface — 1-3 entry points max
Agent 2Maximize flexibility — many use cases and extension
Agent 3Optimize for most common caller — default case trivial
Agent 4Ports & adapters pattern (if cross-boundary)

Each outputs: interface signature, usage example, what it hides, dependency strategy, trade-offs.

Present sequentially, compare in prose, give opinionated recommendation.

5. Create GitHub Issue RFC

Use gh issue create with template below. Don't ask for review.

Issue Template

<issue-template>

Problem

Architectural friction:

  • Which modules are shallow and tightly coupled
  • Integration risk in the seams
  • Why this makes the codebase harder to navigate/maintain

Proposed Interface

  • Interface signature (types, methods, params)
  • Usage example
  • What complexity it hides

Dependency Strategy

  • In-process: merged directly
  • Local-substitutable: tested with [specific stand-in]
  • Ports & adapters: port definition, production adapter, test adapter
  • Mock: mock boundary for external services

Testing Strategy

  • New boundary tests to write
  • Old shallow tests to delete
  • Test environment needs

Implementation Recommendations

Durable guidance NOT coupled to file paths:

  • What the module should own
  • What it should hide
  • What it should expose
  • How callers migrate
</issue-template>

Dependency Categories

CategoryDescriptionDeepenable?
In-processPure computation, no I/OAlways
Local-substitutableHas local test stand-ins (PGLite, in-memory FS)If stand-in exists
Remote but ownedYour services across network (Ports & Adapters)Via port injection
True externalThird-party (Stripe, Twilio) — mock at boundaryVia mock injection
Show full SKILL.md (332 more words)Show less

Testing Principle

Replace, don't layer. Old unit tests on shallow modules are waste once boundary tests exist — delete them. Tests assert on observable outcomes through public interface, not internal state.

Rules

  • MUST explore the codebase organically (Explore sub-agent) before proposing deepening targets — do not anchor on what you already know
  • MUST present numbered candidates to the user and wait for selection before step 3 — auto-picking skips the product decision
  • NEVER design interfaces in step 2; interface work only happens in step 4 after the problem space is framed
  • CRITICAL: step 4 spawns parallel sub-agents with genuinely different constraints (minimize / maximize-flexibility / optimize-common / ports-adapters). Sequential variations of the same idea defeat the purpose.
  • MANDATORY: deliverable is a GitHub issue RFC created via gh issue create. Never open a PR from this skill.

Gotchas

  • "Depth" is measured against actual call patterns, not the method count. A module exporting 20 functions where callers only use 2 is effectively 2-deep — the other 18 are dead interface, not richness.
  • Shared TypeScript types and Python protocols count as coupling. A "just types" file imported by 30 modules creates a deep blast radius; deleting or renaming it is structurally significant even though no runtime code moves.
  • Parallel sub-agents collapse into echo chambers when their constraints are not sharply different. Spell out the opposing tensions ("minimize interface" vs "maximize flexibility") — soft variations produce near-identical designs.
  • gh issue create without --body or --body-file opens $EDITOR. In automated flows this hangs the skill indefinitely. Always pass the body explicitly.
  • Ports & Adapters introduces indirection that IDE "find references" and static analysis sometimes miss (dynamic dispatch via interface). Count on broken tooling during the transition period and compensate with runtime smoke tests.

When NOT to Use

  • For executing a known refactor plan — use /refactor (direct edits) or /refactor-plan (incremental)
  • For designing a single module's interface from scratch — use /design-an-interface
  • For deciding between 2-3 named architectural options — use /architecture-decision
  • For code-quality metrics (complexity, duplication, coverage) — use /analyze
  • For understanding a codebase without proposing changes — use /explore

© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in app/skills/architecture-audit of softspark/ai-toolkit.

Open the folder on GitHubat commit d64db2b

Compare with similar skills

Architecture Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Architecture Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Architecture Audit this skillsoftspark/ai-toolkit179—~1.7kAutomated safety check: NotesApache-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Diagnosing Superpowers Sessionsobra/superpowers296k3 repos~1.7kAutomated safety check: PassMIT
GitHub Deep Researchbytedance/deer-flow83k5 repos~1.3kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.

    296k GitHub starsUsed in 3 repos~1.7k tokens
    Agent WorkflowsAuto-check passed
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    83k GitHub starsUsed in 5 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Last30days

    mvanhorn/last30days-skill

    Research what people actually say about any topic in the last 30 days.

    64k GitHub stars~7.8k tokensUpdated yesterday
    Research & ScienceAuto-check: notes

More from softspark/ai-toolkit

All 112 skills in this repo
  • Prepare Test Env

    softspark/ai-toolkit

    Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.

    179 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check: notes
  • A11y Validate

    softspark/ai-toolkit

    Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.8k tokensUpdated 2 days ago
    Auto-check: notes
  • Analyze

    softspark/ai-toolkit

    Analyzes code quality, complexity, patterns across codebase.

    179 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Autonomous Dev

    softspark/ai-toolkit

    Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.

    179 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check: notes
  • Brand Voice

    softspark/ai-toolkit

    Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check: notes

Works with

Questions about Architecture Audit

What does Architecture Audit do?

Audits codebase for architectural friction, shallow modules; proposes RFCs. Architecture Audit is an agent skill from softspark/ai-toolkit. Audits codebase for architectural friction, shallow modules; proposes RFCs.

How do I install Architecture Audit in Claude Code?

Run `npx skills add softspark/ai-toolkit --skill architecture-audit -a claude-code`. Or copy the skill folder (app/skills/architecture-audit in softspark/ai-toolkit) into .claude/skills/architecture-audit in your project. Claude Code loads it when a task matches its description.

How do I install Architecture Audit in Codex?

Run `npx skills add softspark/ai-toolkit --skill architecture-audit -a codex`. Or copy the skill folder (app/skills/architecture-audit in softspark/ai-toolkit) into .agents/skills/architecture-audit in your project. Codex loads it when a task matches its description.

Can I use Architecture Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill architecture-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/architecture-audit, .gemini/skills/architecture-audit, .github/skills/architecture-audit and .opencode/skills/architecture-audit in your project.

What does Architecture Audit need to run?

Going by SKILL.md and its folder, Architecture Audit needs the command-line tools its instructions call (gh). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Agent.

Does Architecture Audit access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Architecture Audit safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Architecture Audit use?

Architecture Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Architecture Audit use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Architecture Audit?

Skills that share tags, products or a category with Architecture Audit: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Diagnosing Superpowers Sessions (obra/superpowers, 296k stars), GitHub Deep Research (bytedance/deer-flow, 83k stars) and Greploop (onyx-dot-app/onyx, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Architecture Audit?

softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.

Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.