Perform a full codebase review, categorize findings by severity, file GitHub issues, then fix each issue in an isolated git worktree and submit PRs.

MITAuto-check passedDevelopment

Install Codebase Audit

skills CLI
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebase-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codebase-audit .claude/skills/codebase-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codebase-audit
GitHub stars
1.1k
Token cost
~1.9k tokens
SKILL.md length
875 words
Files
8 (incl. references)
Skills in repo
49
Repo updated
First seen
Licence
MIT

At a glance

Perform a full codebase review, categorize findings by severity, file GitHub issues, then fix each issue in an isolated git worktree and submit PRs.

  • Works in 5 steps: Review → Analyze & Classify → Create GitHub Issues → …
  • The user asks to audit the codebase
  • SKILL.md covers When to use this skill, Workflow, Routing and Git safety rules, plus 2 more sections
  • Calls npm and gh

What it does

Codebase Audit is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Perform a full codebase review, categorize findings by severity, file GitHub issues, then fix each issue in an isolated git worktree and submit PRs. Use this skill when the user asks to audit the codebase, do a comprehensive code review, find and fix security/quality/reliability issues, or run a proactive health check across the entire repository.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/classification.md`, `references/dependency-audit.md` and `references/issue-workflow.md`).

It sits in Development, covering Git worktrees and Code review. It works with GitHub and Git. The repository describes itself as: Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP. The licence is MIT.

When your agent uses it

  • The user asks to audit the codebase
  • Do a comprehensive code review
  • Find and fix security/quality/reliability issues
  • Run a proactive health check across the entire repository

Example prompts

  • “/codebase-audit”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Review
  2. Analyze & Classify
  3. Create GitHub Issues
  4. Worktree Fix
  5. Verify & Report

What it can do on your machine

Read from SKILL.md and the folder at commit ea2c202. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codebase Audit loads about 1.9k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 875 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TencentCloudBase/CloudBase-AI-Toolkit at commit ea2c202, republished under its MIT licence (© TencentCloudBase). 875 words, ~1,888 tokens.

Download SKILL.mdSave it as .claude/skills/codebase-audit/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
codebase-audit
description
Perform a full codebase review, categorize findings by severity, file GitHub issues, then fix each issue in an isolated git worktree and submit PRs. Use this skill when the user asks to audit the codebase, do a comprehensive code review, find and fix security/quality/reliability issues, or run a proactive health check across the entire repository.
alwaysApply
false

Codebase Audit → Issue → Worktree Fix → PR

End-to-end workflow: systematically review the entire codebase, report findings as GitHub issues, fix each issue in an isolated git worktree, and submit PRs — all in one session.

When to use this skill

Use this skill when you need to:

  • Perform a full code review / audit of the codebase
  • Proactively find security vulnerabilities, logic bugs, or code quality problems
  • Turn code review findings into tracked GitHub issues
  • Fix each issue in isolation (worktree per issue) and submit PRs
  • Run a periodic codebase health check with automated follow-through
  • Audit and fix dependency security vulnerabilities (Dependabot alerts / npm audit)

Do NOT use for:

  • Reviewing or fixing a single known bug (use systematic-debugging or direct fix)
  • Triaging existing open PRs (use pr-review-fix)
  • Processing attribution issues (use mcp-attribution-worktree)
  • Feature development or refactoring unrelated to audit findings

Workflow

Phase 1 — Review
  1. Read references/review-strategy.md for the review scope and checklist.
  2. Use the code-explorer subagent to read ALL source files in the target directory (default: mcp/src/).
  3. For each file, systematically check against the review checklist:
    • Security: path traversal, injection, unvalidated input, hardcoded secrets, improper error exposure
    • Error handling: missing try-catch, swallowed errors, error messages leaking internals
    • Type safety: as any, unsafe casts, missing null checks
    • Logic bugs: race conditions, incorrect conditionals, unreachable code
    • Code quality: dead code, duplication, overly complex functions
    • Resource leaks: unclosed connections, missing cleanup
    • API design: inconsistent validation, missing required field checks
  4. Record every finding with: file path, line number(s), category, severity (Critical/High/Medium/Low), description, and suggested fix.
  5. Dependency scan: Read references/dependency-audit.md and run the Dependabot alert fetch + npm audit to discover vulnerable dependencies. Record each finding using the dependency-audit format.
Phase 2 — Analyze & Classify
  1. Read references/classification.md for severity definitions and grouping rules.
  2. Deduplicate findings — merge instances of the same pattern across files.
  3. Group findings into fix batches — related issues that should be fixed together in one PR.
  4. Assign severity and priority:
    • P0 (Critical): Security vulnerabilities, data loss risks
    • P1 (High): Logic bugs, error handling gaps that cause runtime failures
    • P2 (Medium): Type safety, code quality issues affecting maintainability
    • P3 (Low): Style, naming, minor cleanup
  5. Present a structured audit report to the user and wait for confirmation before proceeding.
Phase 3 — Create GitHub Issues
  1. Read references/issue-workflow.md for issue creation guidelines.
  2. For each fix batch (or individual Critical finding), create a GitHub issue:
    bash
    gh issue create --title "<type>(<scope>): <summary>" --body "<structured body>" --label "<severity>,<category>"
  3. Issue body must include: affected files, line numbers, problem description, expected behavior, and suggested fix approach.
  4. Link related issues when findings are connected.
  5. Present the created issues to the user.
Phase 4 — Worktree Fix
  1. Read references/worktree-fix.md for the isolation and fix procedure.
  2. For each issue (in priority order): a. Create an isolated worktree and branch:
    bash
    git worktree add ../<repo>-audit-fix-<issue-number> -b fix/<slug>-<issue-number> origin/main
    b. Work inside the worktree — never in the main checkout. c. Implement the fix, keeping changes minimal and focused. d. Verify locally: cd mcp && npm run build && npm run test e. Commit with conventional-changelog format:
    bash
    git commit -m 'fix(<scope>): 🔒 <english description>
    
    Closes #<issue-number>'
    f. Push and create PR:
    bash
    git push github fix/<slug>-<issue-number>
    gh pr create --title "fix(<scope>): 🔒 <summary>" --body "Closes #<issue-number>\n\n<description>" --base main
    g. Remove the worktree after PR is created:
    bash
    cd <original-dir>
    git worktree remove ../<repo>-audit-fix-<issue-number>
  3. One worktree per issue. Never mix fixes across worktrees.
  4. Dependency fixes: For dependency vulnerability batches, follow references/dependency-audit.md Step 4. These can be grouped into a single PR since they modify package.json / package-lock.json.
Show full SKILL.md (304 more words)Show less
Phase 5 — Verify & Report
  1. Read references/verification.md for the verification checklist.
  2. Check CI status for each PR:
    bash
    gh pr checks <number>
  3. If CI fails, re-enter the worktree, fix, and push again.
  4. Generate a final audit report summarizing:
    • Total findings by category and severity
    • Issues created (with links)
    • PRs submitted (with links)
    • Remaining items that need human decision

Routing

TaskRead
What to review and how to check each categoryreferences/review-strategy.md
Security severity classification (TSRC-style)references/security-severity-checklist.md
How to classify, deduplicate, and batch findingsreferences/classification.md
How to create well-structured GitHub issuesreferences/issue-workflow.md
How to create worktrees and fix issues in isolationreferences/worktree-fix.md
How to verify fixes and generate the final reportreferences/verification.md
How to audit and fix dependency vulnerabilitiesreferences/dependency-audit.md

Git safety rules

  • Never force-push unless explicitly asked.
  • Never amend commits that are already pushed.
  • Always work inside the worktree, not the main checkout.
  • Always verify build + test locally before pushing.
  • One worktree per issue — never mix fixes.
  • Clean up worktrees after PR creation.

Commit conventions

Follow the project's conventional-changelog format:

fix(<scope>): 🔒 <english description>

Closes #<issue-number>

Scope examples: security, deps, error-handling, type-safety, code-quality, cloudrun, database, functions

Minimum self-check

  • Did I review ALL source files in the target scope, not just a sample?
  • Did I categorize each finding with file, line, severity, and description?
  • Did I present the audit report and get user confirmation before creating issues?
  • Did I create a separate GitHub issue for each fix batch?
  • Did I use an isolated worktree for each fix, not the main checkout?
  • Did I verify build + test pass before pushing each fix?
  • Did I clean up worktrees after creating PRs?
  • Did I generate a final report with links to all issues and PRs?
  • Did I check Dependabot alerts and npm audit for dependency vulnerabilities?
  • Did I apply the correct fix strategy (upgrade / override / replace / dismiss) for each vulnerable dependency?

© TencentCloudBase, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/codebase-audit of TencentCloudBase/CloudBase-AI-Toolkit.

  • SKILL.md
  • references/classification.md
  • references/dependency-audit.md
  • references/issue-workflow.md
  • references/review-strategy.md
  • references/security-severity-checklist.md
  • references/verification.md
  • references/worktree-fix.md

Open the folder on GitHubat commit ea2c202

Compare with similar skills

Codebase Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codebase Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codebase Audit this skillTencentCloudBase/CloudBase-AI-Toolkit1.1k—~1.9kAutomated safety check: PassMIT
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0
Pre-Release PR Triagejamiepine/voicebox57k—~3.1kAutomated safety check: PassMIT
Greploop Appsmichaelshimeles/skills1.3k1 repos~3.6kAutomated safety check: PassMIT
Requesting Code ReviewHezaoHezao/poirot2505 repos~1.6kAutomated safety check: PassMIT
Ff Worktreesdamus-io/damus2.1k—~451Automated safety check: PassGPL-3.0

Similar skills

  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Pre-Release PR Triage

    jamiepine/voicebox

    Sorts a backlog of open pull requests into must-merge, candidate, superseded and deferred, writes a triage doc and works the merge loop before a release.

    57k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Greploop Apps

    michaelshimeles/skills

    Loops on a large pull request, merge request or Perforce changelist, fixing Greptile findings until it scores 5/5 with no unresolved comments.

    1.3k GitHub starsUsed in 1 repo~3.6k tokens
    DevelopmentAuto-check passed
  • Requesting Code Review

    HezaoHezao/poirot

    Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.

    250 GitHub starsUsed in 5 repos~1.6k tokens
    DevelopmentAuto-check passed
  • Ff Worktrees

    damus-io/damus

    Fast-forward master and every git worktree branch up to a target ref (default github/master), skipping any worktree with unmerged commits.

    2.1k GitHub stars~451 tokensUpdated 26 days ago
    DevelopmentAuto-check passed
  • PR Triage

    rtk-ai/rtk

    Audits a repository's open pull requests, deep-reviews chosen ones and drafts review comments that are only posted after you approve them.

    83k GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check: notes

More from TencentCloudBase/CloudBase-AI-Toolkit

All 49 skills in this repo
  • AI Model Nodejs

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.

    1.1k GitHub starsUsed in 3 repos~5k tokens
    Auto-check passed
  • HTTP API Cloudbase

    TencentCloudBase/CloudBase-AI-Toolkit

    CloudBase official HTTP API client guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.

    1.1k GitHub starsUsed in 3 repos~2.1k tokens
    Auto-check passed
  • Cloud API Recipe Authoring

    TencentCloudBase/CloudBase-AI-Toolkit

    Author or revise a cloud-api-operations recipe (config/source/skills/cloud-api-operations/references/recipes/).

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Manage Local Skills

    TencentCloudBase/CloudBase-AI-Toolkit

    Analyze, standardize, validate, and sync locally maintained skills into agent skill directories with a skills CLI-aligned workflow.

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Cloudbase Agent Python

    TencentCloudBase/CloudBase-AI-Toolkit

    Build production-ready AI agent backends using the CloudBase Agent Python SDK — create agents with LangGraph/CrewAI/LlamaIndex, serve them via FastAPI with AG-UI protocol streaming +…

    1.1k GitHub starsUsed in 2 repos~2.9k tokens
    Auto-check: notes
  • Cloudbase

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发) projects — Web, 微信小程序, 小程序, uni-app, mobile (iOS, Android…

    1.1k GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check passed

Works with

Categories

Questions about Codebase Audit

What does Codebase Audit do?

Perform a full codebase review, categorize findings by severity, file GitHub issues, then fix each issue in an isolated git worktree and submit PRs. Codebase Audit is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Perform a full codebase review, categorize findings by severity, file GitHub issues, then fix each issue in an isolated git worktree and submit PRs.

When should I use Codebase Audit?

Codebase Audit fits situations like: the user asks to audit the codebase; do a comprehensive code review; find and fix security/quality/reliability issues; run a proactive health check across the entire repository.

How do I install Codebase Audit in Claude Code?

Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a claude-code`. Or copy the skill folder (skills/codebase-audit in TencentCloudBase/CloudBase-AI-Toolkit) into .claude/skills/codebase-audit in your project. Claude Code loads it when a task matches its description.

How do I install Codebase Audit in Codex?

Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a codex`. Or copy the skill folder (skills/codebase-audit in TencentCloudBase/CloudBase-AI-Toolkit) into .agents/skills/codebase-audit in your project. Codex loads it when a task matches its description.

Can I use Codebase Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codebase-audit, .gemini/skills/codebase-audit, .github/skills/codebase-audit and .opencode/skills/codebase-audit in your project.

What does Codebase Audit need to run?

Going by SKILL.md and its folder, Codebase Audit needs the command-line tools its instructions call (npm and gh).

Does Codebase Audit access the network?

SKILL.md contains no URLs. Its commands use npm and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codebase Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Codebase Audit use?

Codebase Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codebase Audit use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Codebase Audit?

Skills that share tags, products or a category with Codebase Audit: PR Review State Fetch (prisma/orm, 48k stars), Pre-Release PR Triage (jamiepine/voicebox, 57k stars), Greploop Apps (michaelshimeles/skills, 1.3k stars) and Requesting Code Review (HezaoHezao/poirot, 250 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codebase Audit?

TencentCloudBase (a GitHub organization) maintains it in TencentCloudBase/CloudBase-AI-Toolkit, which has 1,132 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 6, 2026.

Source: TencentCloudBase/CloudBase-AI-Toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.