Agent skill

Audit Codebase

by tellahq in tellahq/opensession

Audit a whole codebase for materially useful simplifications in its data structures, state representation, control flow, algorithms and ownership, using bounded waves of read-only review agents.

MITAuto-check passed

Install Audit Codebase

skills CLI
$ npx skills add tellahq/opensession --skill audit-codebase -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tellahq/opensession audit-codebase --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tellahq/opensession.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/audit-codebase .claude/skills/audit-codebase && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-codebase
GitHub stars
392
Token cost
~2k tokens
SKILL.md length
1,123 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Audit a whole codebase for materially useful simplifications in its data structures, state representation, control flow, algorithms and ownership, using bounded waves of read-only review agents.

  • Works in 5 steps: The report is the state → Establish the coverage contract → Bounded review waves → …
  • SKILL.md covers The read-only contract, Phase 0 — The report is the…, Phase 1 — Establish the… and Phase 2 — Bounded review waves, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Codebase is an agent skill from tellahq/opensession. Audit a whole codebase for materially useful simplifications in its data structures, state representation, control flow, algorithms and ownership, using bounded waves of read-only review agents. Produces a report and changes nothing.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The licence is MIT.

Example prompts

  • “/audit-codebase”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. The report is the state
  2. Establish the coverage contract
  3. Bounded review waves
  4. Validate and synthesize
  5. Audit the audit

What it can do on your machine

Read from SKILL.md and the folder at commit 80702e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • gist.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Codebase loads about 2k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 1,123 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tellahq/opensession at commit 80702e8, republished under its MIT licence (© tellahq). 1,123 words, ~1,975 tokens.

Download SKILL.mdSave it as .claude/skills/audit-codebase/SKILL.md (or your agent's skills folder).
name
audit-codebase
description
Audit a whole codebase for materially useful simplifications in its data structures, state representation, control flow, algorithms and ownership, using bounded waves of read-only review agents. Produces a report and changes nothing.
argument-hint
[<scope>] (defaults to the whole repository)

Audit codebase

/audit-codebase → inventory every subsystem → bounded waves of read-only reviewers → validate each finding → audit the audit

You are the coordinator of a read-only audit. The question is not "are there bugs" and not "is this pretty". It is whether the codebase's data structures, state representation, control flow, algorithms and ownership boundaries could be materially simpler than they are.

Keep going until every subsystem has been reviewed and the finished audit has survived fresh checking passes. Adapted from Aaron Francis's audit prompt: https://gist.github.com/aarondfrancis/8735edbe48532f97ee5ea818db4dbd47

The read-only contract

Do not edit files, run tests, implement a recommendation, commit, or push. Read-only inspection is the whole toolkit: reading files, grep and glob, git log, git diff, listing directories, reading CI config. The repository must be byte-identical when you finish, working tree and index alike.

Everything you want changed goes into the report as a recommendation. Someone else decides whether to do it, and when.

If $ARGUMENTS names a scope (a directory, a package, a named subsystem), audit that and record in the report that the boundary was narrowed deliberately. Otherwise audit the whole repository.

Phase 0 — The report is the state

One canonical report accumulates everything and you update it as you go. Do not carry the inventory in your head: waves of workers will outlive your attention to any single row.

Write it outside the checkout, or you break the read-only contract:

  • With Open Session's assets tools, write_asset to audit/report.md. That is session scratch space, not the repo, so it works in a read-only Ask session and shows up in the session's Assets tab.
  • Otherwise a file under /tmp.

The report holds:

  1. Subsystem inventory (the coverage contract)
  2. Confirmed opportunities (validated findings, one row each)
  3. Explicit skips (a subsystem reviewed and found already clear)
  4. Cross-cutting patterns (the same shape in three places)
  5. Duplicates and superseded findings (what you merged, and into what)
  6. Final priorities and dependencies
  7. Audit log (which wave covered which rows, and when)

Phase 1 — Establish the coverage contract

Inventory every identifiable subsystem before reviewing any of them. Read the build files, the directory tree, the entry points, the docs, and enough code to tell a real boundary from a folder name.

Each row gets:

  • a stable ID and a descriptive name
  • an exact ownership boundary, in paths
  • key implementation files
  • public interfaces, major call sites, tests
  • a status: queued, in review, recommend, or skip

Cover frontend, backend, shared infrastructure, platform bridges, generated or otherwise externally owned contracts, and test and tooling infrastructure where they materially matter.

A broad catch-all row is not coverage. "Utilities" or "the server" is a place to hide four unreviewed subsystems, so split until every row names a boundary a single worker can hold.

Phase 2 — Bounded review waves

Give each worker exactly one subsystem, with a non-overlapping boundary.

Launch them with the task tool using a read-only subagent (subagent_type: "explore"), putting every call for a wave in a single message so they run concurrently and you wait once. Four to six per wave: bounded by the number of lanes you can genuinely coordinate, not by how many rows are queued. Do not interrupt a worker merely for being slow. Harvest results, update the report, mark the rows, then open the next wave.

A worker sees none of your conversation. Give it the subsystem ID, the exact boundary, the key files you already found, and this brief:

Review the assigned subsystem for at most two materially useful simplifications in its data structures, state representation, or organizing model. Inspect its implementation, public interfaces, major call sites and existing tests. Stay inside the assigned boundary. Name a cross-subsystem concern if you see one, but do not widen your scope to solve it.

Look for:

  • scattered booleans or nullable fields that permit invalid combinations, and want to be a state machine or a discriminated union
  • repeated assumptions about an object's shape that want one shared typed model
  • duplicated branching a small map, registry, reducer or command model removes
  • unclear ownership of state or behaviour that a small module boundary clarifies
  • repeated scans, transformations or lookups where the right collection or index would materially simplify the behaviour, not merely speed it up
  • lifecycle, concurrency or async states whose representation permits stale or contradictory state

Do not force an abstraction. Boring local code that is already clear stays.

Do not recommend a change for stylistic consistency, hypothetical extensibility, minor line-count reduction, or to move existing branching behind a new type.

Return at most two opportunities, and return skip if nothing clears the bar. For each one give: (1) verdict, recommend or skip; (2) evidence, with exact file and line references; (3) the current complexity or the invalid states it permits; (4) the proposed representation and why it is simpler; (5) the smallest credible implementation scope, naming affected files and interfaces; (6) regression risks and migration concerns; (7) existing and additional validation required; (8) confidence: high, medium or low.

Show full SKILL.md (299 more words)Show less

Phase 3 — Validate and synthesize

Verify every finding against the repository yourself before it enters the report. A worker's confidence is not evidence: open the cited lines.

Reject, narrow, or demote a finding that is vague, duplicates another, misreads intentional semantics, or only relocates the complexity somewhere else. Say so in the report rather than deleting it silently, so the next audit does not rediscover it.

A skip is completed coverage, not a gap. Record it with a sentence on why the subsystem is already clear.

Deduplicate overlapping findings and assign each accepted one to a single authoritative subsystem. Keep opening waves until every inventory row is done.

Phase 4 — Audit the audit

Before you finish, run fresh independent passes for:

  • repository coverage — what has no subsystem row at all
  • duplication and ownership overlap — one finding wearing three IDs
  • materiality and over-abstraction — findings that add a concept to save a little typing
  • schema completeness — every finding carries all eight fields
  • priority ranking — dependency-aware, not vibes

If the coverage pass finds a real omission, add an explicit subsystem row and audit it. Do not absorb it by widening a boundary that is already marked done.

Then rank the accepted recommendations by concrete impact, confidence, implementation effort, blast radius and prerequisites, and name the best first slices: the ones that unlock others, or stand alone with a small blast radius.

Done

The audit is complete when every identifiable subsystem has been reviewed, every subsystem carries a recommendation or an explicit skip, every finding has complete evidence, scope, risk and validation, duplicates and weak abstractions are gone, priorities and dependencies are internally consistent, and the repository is unchanged.

Finish with a short summary in the session: how many subsystems, how many findings survived validation, the top few slices, and the report's path.

© tellahq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/audit-codebase of tellahq/opensession.

Open the folder on GitHubat commit 80702e8

Compare with similar skills

Audit Codebase next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Codebase compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Codebase this skilltellahq/opensession392—~2kAutomated safety check: PassMIT
Investor Materialsaffaan-m/ECC275k3 repos~268Automated safety check: PassMIT
Material Designsickn33/agentic-awesome-skills47k1 repos~2.6kAutomated safety check: PassMIT
Materialbergside/awesome-design-skills3.1k1 repos~919Automated safety check: PassMIT
Computer UseQwenLM/qwen-code28k—~3.6kAutomated safety check: PassApache-2.0
Find SimplificationsQwenLM/qwen-code28k—~11kAutomated safety check: WarnApache-2.0

Similar skills

  • Investor Materials

    affaan-m/ECC

    创建和更新宣传文稿、一页简介、投资者备忘录、加速器申请、财务模型和融资材料。当用户需要面向投资者的文件、预测、资金用途表、里程碑计划或必须在多个融资资产中保持内部一致性的材料时使用。

    275k GitHub starsUsed in 3 repos~268 tokens
    Auto-check passed
  • Material Design

    sickn33/agentic-awesome-skills

    Web and App implementation guide for Material Design. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 1 repo~2.6k tokens
    MobileAuto-check passed
  • Material

    bergside/awesome-design-skills

    Google's Material Design with layered surfaces, dynamic theming, built-in motion, and responsive cross-platform patterns.

    3.1k GitHub starsUsed in 1 repo~919 tokens
    Frontend & DesignAuto-check passed
  • Computer Use

    QwenLM/qwen-code

    Control local desktop applications through Computer Use for tasks that require reading or operating app UI.

    28k GitHub stars~3.6k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Find Simplifications

    QwenLM/qwen-code

    A skill your agent uses for a periodic repo-wide sweep of qwen-code for accumulated excess surface — dead components and files, orphaned locale keys, exports nothing consumes, added-then-removed…

    28k GitHub stars~11k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Research Material Scout

    huangruiteng/CS-Notes

    A skill your agent uses when the user asks Codex to research, find learning materials, process "素材:" links, "请你读" / "精读" a material, build a material radar, or use SenSight-like broad information…

    4k GitHub stars~8.6k tokensUpdated 2 days ago
    Research & ScienceAuto-check passed

More from tellahq/opensession

All 15 skills in this repo
  • Effect TS

    tellahq/opensession

    Write idiomatic Effect v4 TypeScript verified against the pinned effect@4.0.0-rc.112 source.

    392 GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Reflect

    tellahq/opensession

    Spawn three parallel review child sessions over the active transcript, surface learnings, and route each to a concrete edit on an existing skill.

    392 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Show Me

    tellahq/opensession

    Help the user understand the current topic visually with concise diagrams, code-shape sketches, and focused HTML artifacts.

    392 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Automate Me

    tellahq/opensession

    A skill your agent uses for "automate me", "create/update/refresh my -mode skill", "turn/capture my preferences or working style into a skill", or wanting agents to follow how the user works.

    392 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • PR Autofix

    tellahq/opensession

    Auto-fix a PR — address ALL reviewers' open feedback + failing CI, push, and reply in each addressed thread with honest attribution

    392 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Swarm

    tellahq/opensession

    Fan out N parallel workers, drain them, and return one report.

    392 GitHub stars~609 tokensUpdated today
    Auto-check passed

Questions about Audit Codebase

What does Audit Codebase do?

Audit a whole codebase for materially useful simplifications in its data structures, state representation, control flow, algorithms and ownership, using bounded waves of read-only review agents. Audit Codebase is an agent skill from tellahq/opensession. Audit a whole codebase for materially useful simplifications in its data structures, state representation, control flow, algorithms and ownership, using bounded waves of read-only review agents.

How do I install Audit Codebase in Claude Code?

Run `npx skills add tellahq/opensession --skill audit-codebase -a claude-code`. Or copy the skill folder (.agents/skills/audit-codebase in tellahq/opensession) into .claude/skills/audit-codebase in your project. Claude Code loads it when a task matches its description.

How do I install Audit Codebase in Codex?

Run `npx skills add tellahq/opensession --skill audit-codebase -a codex`. Or copy the skill folder (.agents/skills/audit-codebase in tellahq/opensession) into .agents/skills/audit-codebase in your project. Codex loads it when a task matches its description.

Can I use Audit Codebase in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tellahq/opensession --skill audit-codebase -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-codebase, .gemini/skills/audit-codebase, .github/skills/audit-codebase and .opencode/skills/audit-codebase in your project.

What does Audit Codebase need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Codebase is instructions for the agent only.

Does Audit Codebase access the network?

SKILL.md names 1 domain. As links in the text: gist.github.com. This is read from the text; nothing was executed.

Is Audit Codebase safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Codebase use?

Audit Codebase is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Codebase use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Codebase?

Skills that share tags, products or a category with Audit Codebase: Investor Materials (affaan-m/ECC, 275k stars), Material Design (sickn33/agentic-awesome-skills, 47k stars), Material (bergside/awesome-design-skills, 3.1k stars) and Computer Use (QwenLM/qwen-code, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Codebase?

tellahq (a GitHub organization) maintains it in tellahq/opensession, which has 392 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.

Source: tellahq/opensession on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.