Agent skill

Audit Rbac

by trycompai in trycompai/comp

Audit & fix RBAC and audit log compliance in API endpoints and frontend components

AGPL-3.0Auto-check passedBackend & APIs

Install Audit Rbac

skills CLI
$ npx skills add trycompai/comp --skill audit-rbac -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trycompai/comp audit-rbac --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trycompai/comp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/audit-rbac .claude/skills/audit-rbac && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-rbac
GitHub stars
2k
Token cost
~659 tokens
SKILL.md length
280 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Audit & fix RBAC and audit log compliance in API endpoints and frontend components

  • Works in 6 steps: Every mutation endpoint (POST, PATCH,… → Read endpoints (GET) should have… → Self-endpoints (e.g., /me/preferences)… → …
  • Tasks that involve Authorization and RBAC
  • SKILL.md covers Rules and Process
  • Calls bunx

What it does

Audit Rbac is an agent skill from trycompai/comp. Audit & fix RBAC and audit log compliance in API endpoints and frontend components

Its SKILL.md is about 660 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC and REST APIs. The repository describes itself as: AI Native platform to get companies compliant - Vanta & Drata Alternative. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve Authorization and RBAC
  • Tasks that involve REST APIs

Example prompts

  • “/audit-rbac”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Every mutation endpoint (POST, PATCH, PUT, DELETE) MUST have @RequirePermission('resource', 'action'). If missing, add it.
  2. Read endpoints (GET) should have @RequirePermission('resource', 'read'). If missing, add it.
  3. Self-endpoints (e.g., /me/preferences) may skip @RequirePermission — authentication via HybridAuthGuard is sufficient.
  4. Controller format: Must use @Controller({ path: 'name', version: '1' }), NOT @Controller('v1/name'). If wrong, fix it.
  5. Guards: Use @UseGuards(HybridAuthGuard, PermissionGuard) at controller or endpoint level. Never skip PermissionGuard.
  6. Webhooks: External webhook endpoints use @Public() — no auth required.

What it can do on your machine

Read from SKILL.md and the folder at commit 1bf4d52. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bunx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use bunx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Rbac loads about 659 tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 280 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~659

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trycompai/comp at commit 1bf4d52, republished under its AGPL-3.0 licence (© trycompai). 280 words, ~659 tokens.

Download SKILL.mdSave it as .claude/skills/audit-rbac/SKILL.md (or your agent's skills folder).
name
audit-rbac
description
Audit & fix RBAC and audit log compliance in API endpoints and frontend components

Audit the specified files or directories for RBAC and audit log compliance. Fix every issue found immediately.

Rules

API Endpoints (NestJS — apps/api/src/)
  1. Every mutation endpoint (POST, PATCH, PUT, DELETE) MUST have @RequirePermission('resource', 'action'). If missing, add it.
  2. Read endpoints (GET) should have @RequirePermission('resource', 'read'). If missing, add it.
  3. Self-endpoints (e.g., /me/preferences) may skip @RequirePermission — authentication via HybridAuthGuard is sufficient.
  4. Controller format: Must use @Controller({ path: 'name', version: '1' }), NOT @Controller('v1/name'). If wrong, fix it.
  5. Guards: Use @UseGuards(HybridAuthGuard, PermissionGuard) at controller or endpoint level. Never skip PermissionGuard.
  6. Webhooks: External webhook endpoints use @Public() — no auth required.
Frontend Components (apps/app/src/)
  1. Every mutation element (button, form submit, toggle, switch, file upload) MUST be gated with usePermissions from @/hooks/use-permissions. If not:
    • Create/Add buttons: Wrap with {hasPermission('resource', 'create') && <Button>...
    • Edit/Delete in dropdown menus: Wrap the menu item
    • Inline form fields on detail pages: Add disabled={!canUpdate}
    • Status/property selectors: Add disabled={!canUpdate}
  2. Actions columns in tables: hide entire column when user lacks write permission.
  3. No manual role string parsing (role.includes('admin')) — use hasPermission().
  4. Nav items: gate with canAccessRoute(permissions, 'routeSegment').
  5. Page-level: call requireRoutePermission('segment', orgId) server-side.
Permission Resources

organization, member, control, evidence, policy, risk, vendor, task, framework, audit, finding, questionnaire, integration, apiKey, trust, pentest, app, compliance

Multi-Product RBAC
  • Products (compliance, pen testing) are org-level feature flags — NOT RBAC
  • app:read gates compliance dashboard; pentest:read gates security product
  • Custom roles can grant access to any combination of resources
  • Portal-only resources (policy, compliance) do NOT grant app access

Process

  1. Read files specified in $ARGUMENTS (or scan the directory)
  2. Check each rule above
  3. Fix every violation immediately — don't just report
  4. Run typecheck to verify: bunx turbo run typecheck --filter=@trycompai/api --filter=@trycompai/app

© trycompai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/audit-rbac of trycompai/comp.

Open the folder on GitHubat commit 1bf4d52

Compare with similar skills

Audit Rbac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Rbac compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Rbac this skilltrycompai/comp2k—~659Automated safety check: PassAGPL-3.0
Elysia API Routesbiersoeckli/QuickStack361—~1.1kAutomated safety check: PassGPL-3.0
API Auditbriiirussell/cybersecurity-skills412—~2.8kAutomated safety check: NotesMIT
Shadmin CLIahaodev/shadmin174—~1.1kAutomated safety check: NotesMIT
API Featuregocronx-team/gocron808—~1.2kAutomated safety check: PassMIT
Discover APIrand/cc-polymath1811 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Elysia API Routes

    biersoeckli/QuickStack

    Create and update QuickStack Elysia REST API routes using the project's established /api/v1 route conventions.

    361 GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    412 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Shadmin CLI

    ahaodev/shadmin

    A skill your agent uses when the user asks to query Shadmin admin platform resources (users, roles, menus, registered API resources) from a terminal — for example "list shadmin users", "show shadmin…

    174 GitHub stars~1.1k tokensUpdated 5 days ago
    Backend & APIsAuto-check: notes
  • API Feature

    gocronx-team/gocron

    Implement or review an end-to-end gocron HTTP API change. An agent skill from gocronx-team/gocron.

    808 GitHub stars~1.2k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Discover API

    rand/cc-polymath

    Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

    181 GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed
  • Project Map

    gjovanovicst/golang-auth-api

    Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.

    129 GitHub stars~2.6k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed

More from trycompai/comp

All 31 skills in this repo
  • API Endpoint Contract

    trycompai/comp

    The contract every new or modified API endpoint must follow so it is correct for the public OpenAPI spec, the MCP server (npm @trycompai/mcp-server), the ValidationPipe, and the docs.

    2k GitHub stars~2.7k tokensUpdated 5 days ago
    Auto-check passed
  • Check Results Service

    trycompai/comp

    How to reuse ANY integration check's results in a feature via the universal CheckResultsService (apps/api integration-platform).

    2k GitHub stars~2.1k tokensUpdated 5 days ago
    Auto-check passed
  • Data

    trycompai/comp

    A skill your agent uses when implementing data fetching, API calls, server/client components, or SWR hooks

    2k GitHub stars~955 tokensUpdated 5 days ago
    Auto-check passed
  • A skill your agent uses when SDK generation failed or seeing errors.

    2k GitHub stars~938 tokensUpdated 5 days ago
    Auto-check passed
  • Forms

    trycompai/comp

    A skill your agent uses when building forms - covers React Hook Form, Zod validation, and form patterns

    2k GitHub stars~1k tokensUpdated 5 days ago
    Auto-check passed
  • Code

    trycompai/comp

    A skill your agent uses when writing TypeScript/React code - covers type safety, component patterns, and file organization

    2k GitHub stars~909 tokensUpdated 5 days ago
    Auto-check: warnings

Categories

Questions about Audit Rbac

What does Audit Rbac do?

Audit & fix RBAC and audit log compliance in API endpoints and frontend components. Audit Rbac is an agent skill from trycompai/comp.

When should I use Audit Rbac?

Audit Rbac fits situations like: tasks that involve Authorization and RBAC; tasks that involve REST APIs.

How do I install Audit Rbac in Claude Code?

Run `npx skills add trycompai/comp --skill audit-rbac -a claude-code`. Or copy the skill folder (.agents/skills/audit-rbac in trycompai/comp) into .claude/skills/audit-rbac in your project. Claude Code loads it when a task matches its description.

How do I install Audit Rbac in Codex?

Run `npx skills add trycompai/comp --skill audit-rbac -a codex`. Or copy the skill folder (.agents/skills/audit-rbac in trycompai/comp) into .agents/skills/audit-rbac in your project. Codex loads it when a task matches its description.

Can I use Audit Rbac in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trycompai/comp --skill audit-rbac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-rbac, .gemini/skills/audit-rbac, .github/skills/audit-rbac and .opencode/skills/audit-rbac in your project.

What does Audit Rbac need to run?

Going by SKILL.md and its folder, Audit Rbac needs the command-line tools its instructions call (bunx).

Does Audit Rbac access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Rbac safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Rbac use?

Audit Rbac is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Rbac use?

About 659 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Rbac?

Skills that share tags, products or a category with Audit Rbac: Elysia API Routes (biersoeckli/QuickStack, 361 stars), API Audit (briiirussell/cybersecurity-skills, 412 stars), Shadmin CLI (ahaodev/shadmin, 174 stars) and API Feature (gocronx-team/gocron, 808 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Rbac?

trycompai (a GitHub organization) maintains it in trycompai/comp, which has 2,016 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 2, 2026.

Source: trycompai/comp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.