Agent skill

Audit Hooks

by trycompai in trycompai/comp

Audit & fix hooks and API usage patterns — eliminate server actions, raw fetch, and stale patterns

AGPL-3.0Auto-check passed

Install Audit Hooks

skills CLI
$ npx skills add trycompai/comp --skill audit-hooks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trycompai/comp audit-hooks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trycompai/comp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/audit-hooks .claude/skills/audit-hooks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-hooks
GitHub stars
2k
Token cost
~444 tokens
SKILL.md length
201 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Audit & fix hooks and API usage patterns — eliminate server actions, raw fetch, and stale patterns

  • Works in 9 steps: useAction from next-safe-action →… → Server actions mutating via @db → delete… → Direct @db in client components →… → …
  • SKILL.md covers Forbidden Patterns (fix…, Required Patterns and Process
  • Calls bunx

What it does

Audit Hooks is an agent skill from trycompai/comp. Audit & fix hooks and API usage patterns — eliminate server actions, raw fetch, and stale patterns

Its SKILL.md is about 440 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: AI Native platform to get companies compliant - Vanta & Drata Alternative. The licence is AGPL-3.0.

Example prompts

  • “/audit-hooks”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. useAction from next-safe-action → replace with SWR hook or custom mutation hook
  2. Server actions mutating via @db → delete and use API hook instead
  3. Direct @db in client components → replace with apiClient via hook
  4. Direct @db in Next.js pages for mutations → replace with serverApi
  5. Raw fetch() without credentials: 'include' → use apiClient
  6. window.location.reload() after mutations → use SWR mutate()
  7. router.refresh() after mutations → use SWR mutate()
  8. useEffect + apiClient.get for data fetching → replace with useSWR
  9. Callback props for data refresh (onXxxAdded, onSuccess) → remove, rely on SWR cache sharing

What it can do on your machine

Read from SKILL.md and the folder at commit 1bf4d52. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bunx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use bunx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Hooks loads about 444 tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 201 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~444

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trycompai/comp at commit 1bf4d52, republished under its AGPL-3.0 licence (© trycompai). 201 words, ~444 tokens.

Download SKILL.mdSave it as .claude/skills/audit-hooks/SKILL.md (or your agent's skills folder).
name
audit-hooks
description
Audit & fix hooks and API usage patterns — eliminate server actions, raw fetch, and stale patterns

Audit the specified files for hook and API usage compliance. Fix every issue found immediately.

Forbidden Patterns (fix immediately)

  1. useAction from next-safe-action → replace with SWR hook or custom mutation hook
  2. Server actions mutating via @db → delete and use API hook instead
  3. Direct @db in client components → replace with apiClient via hook
  4. Direct @db in Next.js pages for mutations → replace with serverApi
  5. Raw fetch() without credentials: 'include' → use apiClient
  6. window.location.reload() after mutations → use SWR mutate()
  7. router.refresh() after mutations → use SWR mutate()
  8. useEffect + apiClient.get for data fetching → replace with useSWR
  9. Callback props for data refresh (onXxxAdded, onSuccess) → remove, rely on SWR cache sharing

Required Patterns

  • Client data fetching: useSWR with apiClient or custom hook
  • Client mutations: custom hooks wrapping apiClient with mutate() for cache invalidation
  • Server components: serverApi from apps/app/src/lib/api-server.ts
  • SWR: fallbackData for SSR data, revalidateOnMount: !initialData
  • API response: lists = response.data.data, single = response.data
  • mutate() safety: guard against undefined in optimistic update functions
  • Array.isArray() checks: when consuming SWR data that could be stale

Process

  1. Read files specified in $ARGUMENTS
  2. Find forbidden patterns and fix them
  3. Ensure all data fetching uses SWR hooks
  4. Run typecheck to verify: bunx turbo run typecheck --filter=@trycompai/app

© trycompai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/audit-hooks of trycompai/comp.

Open the folder on GitHubat commit 1bf4d52

Compare with similar skills

Audit Hooks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Hooks compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Hooks this skilltrycompai/comp2k—~444Automated safety check: PassAGPL-3.0
Elimination Researchglebis/claude-skills388—~1.6kAutomated safety check: PassMIT
Debt Elimination StrategistFerroxLabs/wayland608—~4.5kAutomated safety check: PassApache-2.0
Eliminate Visual Cluttergnurio/refactoring-ui-plugin440—~1kAutomated safety check: PassCustom licence
Routing Subtour EliminationRaidriar7170/hermes-skilleval1251 repos~2.2kAutomated safety check: PassMIT
Dead Code EliminatorArabelaTso/Skills-4-SE253—~3.3kAutomated safety check: PassApache-2.0

Similar skills

  • Elimination Research

    glebis/claude-skills

    This skill should be used for elimination-style research where the user wants to choose from a shortlist of products, tools, services, vendors, or other options using explicit criteria, numeric…

    388 GitHub stars~1.6k tokensUpdated 11 days ago
    Auto-check passed
  • Debt Elimination Strategist

    FerroxLabs/wayland

    Synthesizes Debt Snowball, Debt Avalanche, Debt Consolidation, and Balance Transfer strategies into The Debt Freedom Roadmap - a systematic approach to eliminating debt based on your financial…

    608 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Eliminate Visual Clutter

    gnurio/refactoring-ui-plugin

    Remove unnecessary borders, backgrounds, shadows, decorations

    440 GitHub stars~1k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Routing Subtour Elimination

    Raidriar7170/hermes-skilleval

    Subtour-elimination methods for TSP, VRP, pickup/dropoff routing, and routing MIPs with binary arc variables.

    125 GitHub starsUsed in 1 repo~2.2k tokens
    Data & AnalyticsAuto-check passed
  • Dead Code Eliminator

    ArabelaTso/Skills-4-SE

    Identify and analyze unused or redundant code including unused functions/methods, unused variables/imports, unreachable code, and redundant conditions.

    253 GitHub stars~3.3k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Thread-safe data persistence in Swift using actors — in-memory cache with file-backed storage, eliminating data races by design.

    274k GitHub starsUsed in 4 repos~1.2k tokens
    MobileAuto-check passed

More from trycompai/comp

All 31 skills in this repo
  • API Endpoint Contract

    trycompai/comp

    The contract every new or modified API endpoint must follow so it is correct for the public OpenAPI spec, the MCP server (npm @trycompai/mcp-server), the ValidationPipe, and the docs.

    2k GitHub stars~2.7k tokensUpdated 5 days ago
    Auto-check passed
  • Check Results Service

    trycompai/comp

    How to reuse ANY integration check's results in a feature via the universal CheckResultsService (apps/api integration-platform).

    2k GitHub stars~2.1k tokensUpdated 5 days ago
    Auto-check passed
  • Data

    trycompai/comp

    A skill your agent uses when implementing data fetching, API calls, server/client components, or SWR hooks

    2k GitHub stars~955 tokensUpdated 5 days ago
    Auto-check passed
  • A skill your agent uses when SDK generation failed or seeing errors.

    2k GitHub stars~938 tokensUpdated 5 days ago
    Auto-check passed
  • Forms

    trycompai/comp

    A skill your agent uses when building forms - covers React Hook Form, Zod validation, and form patterns

    2k GitHub stars~1k tokensUpdated 5 days ago
    Auto-check passed
  • Code

    trycompai/comp

    A skill your agent uses when writing TypeScript/React code - covers type safety, component patterns, and file organization

    2k GitHub stars~909 tokensUpdated 5 days ago
    Auto-check: warnings

Questions about Audit Hooks

What does Audit Hooks do?

Audit & fix hooks and API usage patterns — eliminate server actions, raw fetch, and stale patterns. Audit Hooks is an agent skill from trycompai/comp.

How do I install Audit Hooks in Claude Code?

Run `npx skills add trycompai/comp --skill audit-hooks -a claude-code`. Or copy the skill folder (.agents/skills/audit-hooks in trycompai/comp) into .claude/skills/audit-hooks in your project. Claude Code loads it when a task matches its description.

How do I install Audit Hooks in Codex?

Run `npx skills add trycompai/comp --skill audit-hooks -a codex`. Or copy the skill folder (.agents/skills/audit-hooks in trycompai/comp) into .agents/skills/audit-hooks in your project. Codex loads it when a task matches its description.

Can I use Audit Hooks in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trycompai/comp --skill audit-hooks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-hooks, .gemini/skills/audit-hooks, .github/skills/audit-hooks and .opencode/skills/audit-hooks in your project.

What does Audit Hooks need to run?

Going by SKILL.md and its folder, Audit Hooks needs the command-line tools its instructions call (bunx).

Does Audit Hooks access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Hooks safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Hooks use?

Audit Hooks is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Hooks use?

About 444 tokens (SKILL.md is roughly 1.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Hooks?

Skills that share tags, products or a category with Audit Hooks: Elimination Research (glebis/claude-skills, 388 stars), Debt Elimination Strategist (FerroxLabs/wayland, 608 stars), Eliminate Visual Clutter (gnurio/refactoring-ui-plugin, 440 stars) and Routing Subtour Elimination (Raidriar7170/hermes-skilleval, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Hooks?

trycompai (a GitHub organization) maintains it in trycompai/comp, which has 2,016 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 2, 2026.

Source: trycompai/comp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.