PR Review State Fetch
prisma/orm
Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.
Perform a full codebase review, categorize findings by severity, file GitHub issues, then fix each issue in an isolated git worktree and submit PRs.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebase-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codebase-audit .claude/skills/codebase-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codebase-audit" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebase-audit into .claude/skills/codebase-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebase-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebase-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/codebase-audit .agents/skills/codebase-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codebase-audit" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebase-audit into .agents/skills/codebase-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebase-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/codebase-audit .cursor/skills/codebase-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codebase-audit" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebase-audit into .cursor/skills/codebase-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git --path skills/codebase-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebase-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/codebase-audit .gemini/skills/codebase-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codebase-audit" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebase-audit into .gemini/skills/codebase-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebase-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/codebase-audit .github/skills/codebase-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codebase-audit" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebase-audit into .github/skills/codebase-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit codebase-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/codebase-audit .opencode/skills/codebase-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codebase-audit" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/skills/codebase-audit into .opencode/skills/codebase-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codebase-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codebase-auditPerform a full codebase review, categorize findings by severity, file GitHub issues, then fix each issue in an isolated git worktree and submit PRs.
Codebase Audit is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Perform a full codebase review, categorize findings by severity, file GitHub issues, then fix each issue in an isolated git worktree and submit PRs. Use this skill when the user asks to audit the codebase, do a comprehensive code review, find and fix security/quality/reliability issues, or run a proactive health check across the entire repository.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/classification.md`, `references/dependency-audit.md` and `references/issue-workflow.md`).
It sits in Development, covering Git worktrees and Code review. It works with GitHub and Git. The repository describes itself as: Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ea2c202. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Codebase Audit loads about 1.9k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 875 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from TencentCloudBase/CloudBase-AI-Toolkit at commit ea2c202, republished under its MIT licence (© TencentCloudBase). 875 words, ~1,888 tokens.
.claude/skills/codebase-audit/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.End-to-end workflow: systematically review the entire codebase, report findings as GitHub issues, fix each issue in an isolated git worktree, and submit PRs — all in one session.
Use this skill when you need to:
Do NOT use for:
systematic-debugging or direct fix)pr-review-fix)mcp-attribution-worktree)references/review-strategy.md for the review scope and checklist.code-explorer subagent to read ALL source files in the target directory (default: mcp/src/).as any, unsafe casts, missing null checksreferences/dependency-audit.md and run the Dependabot alert fetch + npm audit to discover vulnerable dependencies. Record each finding using the dependency-audit format.references/classification.md for severity definitions and grouping rules.references/issue-workflow.md for issue creation guidelines.gh issue create --title "<type>(<scope>): <summary>" --body "<structured body>" --label "<severity>,<category>"references/worktree-fix.md for the isolation and fix procedure.git worktree add ../<repo>-audit-fix-<issue-number> -b fix/<slug>-<issue-number> origin/maincd mcp && npm run build && npm run test
e. Commit with conventional-changelog format:git commit -m 'fix(<scope>): 🔒 <english description>
Closes #<issue-number>'git push github fix/<slug>-<issue-number>
gh pr create --title "fix(<scope>): 🔒 <summary>" --body "Closes #<issue-number>\n\n<description>" --base maincd <original-dir>
git worktree remove ../<repo>-audit-fix-<issue-number>references/dependency-audit.md Step 4. These can be grouped into a single PR since they modify package.json / package-lock.json.references/verification.md for the verification checklist.gh pr checks <number>| Task | Read |
|---|---|
| What to review and how to check each category | references/review-strategy.md |
| Security severity classification (TSRC-style) | references/security-severity-checklist.md |
| How to classify, deduplicate, and batch findings | references/classification.md |
| How to create well-structured GitHub issues | references/issue-workflow.md |
| How to create worktrees and fix issues in isolation | references/worktree-fix.md |
| How to verify fixes and generate the final report | references/verification.md |
| How to audit and fix dependency vulnerabilities | references/dependency-audit.md |
Follow the project's conventional-changelog format:
fix(<scope>): 🔒 <english description>
Closes #<issue-number>Scope examples: security, deps, error-handling, type-safety, code-quality, cloudrun, database, functions
© TencentCloudBase, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (references) in skills/codebase-audit of TencentCloudBase/CloudBase-AI-Toolkit.
Open the folder on GitHubat commit ea2c202
Codebase Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codebase Audit this skillTencentCloudBase/CloudBase-AI-Toolkit | 1.1k | — | ~1.9k | Automated safety check: Pass | MIT | |
| PR Review State Fetchprisma/orm | 48k | — | ~767 | Automated safety check: Pass | Apache-2.0 | |
| Pre-Release PR Triagejamiepine/voicebox | 57k | — | ~3.1k | Automated safety check: Pass | MIT | |
| Greploop Appsmichaelshimeles/skills | 1.3k | 1 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Requesting Code ReviewHezaoHezao/poirot | 250 | 5 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Ff Worktreesdamus-io/damus | 2.1k | — | ~451 | Automated safety check: Pass | GPL-3.0 |
prisma/orm
Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.
jamiepine/voicebox
Sorts a backlog of open pull requests into must-merge, candidate, superseded and deferred, writes a triage doc and works the merge loop before a release.
michaelshimeles/skills
Loops on a large pull request, merge request or Perforce changelist, fixing Greptile findings until it scores 5/5 with no unresolved comments.
HezaoHezao/poirot
Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.
damus-io/damus
Fast-forward master and every git worktree branch up to a target ref (default github/master), skipping any worktree with unmerged commits.
rtk-ai/rtk
Audits a repository's open pull requests, deep-reviews chosen ones and drafts review comments that are only posted after you approve them.
TencentCloudBase/CloudBase-AI-Toolkit
A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.
TencentCloudBase/CloudBase-AI-Toolkit
CloudBase official HTTP API client guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.
TencentCloudBase/CloudBase-AI-Toolkit
Author or revise a cloud-api-operations recipe (config/source/skills/cloud-api-operations/references/recipes/).
TencentCloudBase/CloudBase-AI-Toolkit
Analyze, standardize, validate, and sync locally maintained skills into agent skill directories with a skills CLI-aligned workflow.
TencentCloudBase/CloudBase-AI-Toolkit
Build production-ready AI agent backends using the CloudBase Agent Python SDK — create agents with LangGraph/CrewAI/LlamaIndex, serve them via FastAPI with AG-UI protocol streaming +…
TencentCloudBase/CloudBase-AI-Toolkit
A skill your agent uses when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发) projects — Web, 微信小程序, 小程序, uni-app, mobile (iOS, Android…
Categories
Perform a full codebase review, categorize findings by severity, file GitHub issues, then fix each issue in an isolated git worktree and submit PRs. Codebase Audit is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Perform a full codebase review, categorize findings by severity, file GitHub issues, then fix each issue in an isolated git worktree and submit PRs.
Codebase Audit fits situations like: the user asks to audit the codebase; do a comprehensive code review; find and fix security/quality/reliability issues; run a proactive health check across the entire repository.
Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a claude-code`. Or copy the skill folder (skills/codebase-audit in TencentCloudBase/CloudBase-AI-Toolkit) into .claude/skills/codebase-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a codex`. Or copy the skill folder (skills/codebase-audit in TencentCloudBase/CloudBase-AI-Toolkit) into .agents/skills/codebase-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill codebase-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codebase-audit, .gemini/skills/codebase-audit, .github/skills/codebase-audit and .opencode/skills/codebase-audit in your project.
Going by SKILL.md and its folder, Codebase Audit needs the command-line tools its instructions call (npm and gh).
SKILL.md contains no URLs. Its commands use npm and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Codebase Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Codebase Audit: PR Review State Fetch (prisma/orm, 48k stars), Pre-Release PR Triage (jamiepine/voicebox, 57k stars), Greploop Apps (michaelshimeles/skills, 1.3k stars) and Requesting Code Review (HezaoHezao/poirot, 250 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
TencentCloudBase (a GitHub organization) maintains it in TencentCloudBase/CloudBase-AI-Toolkit, which has 1,132 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 6, 2026.
Source: TencentCloudBase/CloudBase-AI-Toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.