Agent skill

Agent Setup Health Audit

by tw93 in tw93/Waza

Audits a project's agent configuration, instruction drift, hooks, MCP and AI maintainability, then reports prioritized findings with evidence and next actions.

MITAuto-check: notesAgent Workflows

Install Agent Setup Health Audit

skills CLI
$ npx skills add tw93/Waza --skill health -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tw93/Waza health --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tw93/Waza.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/health .claude/skills/health && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
health
GitHub stars
7.2k
Token cost
~5.2k tokens
SKILL.md length
2,609 words
Files
21 (incl. scripts, references)
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Audits a project's agent configuration, instruction drift, hooks, MCP and AI maintainability, then reports prioritized findings with evidence and next actions.

  • Works in 3 steps: Establish the evidence basis → Collect data → Analyze
  • Codex or Claude setup looks wrong or its instructions contradict each other
  • SKILL.md covers Outcome Contract, Durable Context Preflight, Hard Rules and Step 0: Establish the evidence…, plus 6 more sections
  • Runs Python and Shell scripts from its folder; calls git, bash and python3

What it does

A layered framework drives the audit, running from agent config through instruction surfaces, tools and runtime, and verifiers to maintainability. The agent looks for violations and names the misaligned layer. Two lanes share one report: agent config health (Codex, Claude and Pi instruction drift, permissions, hooks, MCP, skills and memory supply chain) and AI maintainability health (non-obvious constraints, hotspot ownership, verifier coverage, generated-artifact checks and stale durable docs).

A summary audit built from the output of the bundled check scripts comes first. A deeper pass, with inspector subagents and sampled conversation extracts, starts only when you ask for a deep or complete audit or the summary exposes a critical ambiguity, and you are warned beforehand because deep audits can use significant token quota. Each finding names the layer, the concrete evidence and a copy-pasteable action or diagnostic command; otherwise the report gives a clear result with residual risk.

When your agent uses it

  • Codex or Claude setup looks wrong or its instructions contradict each other
  • Auditing hooks, MCP servers and permissions in a project
  • Checking whether verifier output points at stale paths
  • Reviewing how maintainable a repository is for AI coding agents

Example prompts

  • “Run a health check on my agent setup before I start this project.”
  • “Do a deep health audit, because my Claude and Codex instructions seem to have drifted.”
  • “Check whether the docs referenced in our AGENTS file still exist.”

Requirements

  • Python and a shell to run the bundled check scripts

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Establish the evidence basis
  2. Collect data
  3. Analyze

What it can do on your machine

Read from SKILL.md and the folder at commit 8b2c356. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 11 files in scripts/ (Python and Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • bash
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agent Setup Health Audit loads about 5.2k tokens when it runs, and up to ~8.5k if it reads all its reference files. Until then it costs about 43 tokens; SKILL.md has 2,609 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~5.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:119
    `), and pipe-to-shell installers. Treat `.env` as an explicit policy choice: either deny it at the permission layer, or

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from tw93/Waza at commit 8b2c356, republished under its MIT licence (© tw93). 2,609 words, ~5,240 tokens.

Download SKILL.mdSave it as .claude/skills/health/SKILL.md (or your agent's skills folder). This skill also uses 20 other files; get the full folder from GitHub.
name
health
description
Audits agent config, instruction drift, hooks or MCP, and AI maintainability. Use when Claude, Codex, or Pi setup looks wrong. Not for application bugs or PR review.
when_to_use
检查claude, 检查codex, 检查pi, Codex 配置, Pi 配置, agent instructions, 健康度, 配置检查, 配置对不对, AI coding 腐化, Claude ignoring instructions, Pi coding agent, check config…
dispatch_intent
Codex/Claude/Pi ignoring instructions, agent config audit, hooks/MCP broken, health token usage, AI coding code rot, risk-backed hotspot ownership…

Health: Agent-Assisted Engineering Health

Prefix your first line with 🥷 inline, not as its own paragraph.

Audit the current project's agent setup and AI coding maintainability against this framework: agent config → instruction surfaces → tools/runtime → verifiers → maintainability

Find violations. Identify the misaligned layer. Calibrate to evidence and risk, not repository size.

Outcome Contract

  • Outcome: a budget-aware health report that separates agent configuration risk from AI maintainability risk.
  • Done when: each finding names the misaligned layer, the concrete evidence, and a copy-pasteable action or diagnostic command.
  • Evidence: collected health script output, tracked project instructions, runtime config summaries, verifier logs, hooks/MCP surfaces, and read-only live probes when needed.
  • Output: prioritized findings with status, impact, and next action, or a clear clean bill with residual risk.

Two lanes share one report:

  • Agent config health: Codex/Claude/Pi instruction drift, permissions, hooks, MCP, skills, and memory supply chain.
  • AI maintainability health: non-obvious constraint reachability, risk-backed hotspot ownership, verifier coverage, generated-artifact checks, and stale or misleading durable docs.

Output language: Follow the user's current language or explicit language request. Use applicable project and global defaults only when the request does not establish a language.

Budget posture: Start with the summary audit. Escalate automatically when the user asks for a deep, full, complete, thorough, "深入", "完整", "彻底", or "继续跑完" audit, when the user explicitly mentions AI coding code rot, Codex/Claude config drift, unclear context, missing verification, verifier output that points at stale paths, or "代码变烂", when current project instructions or remembered user preference says to run deep health checks by default, or when the summary pass exposes a critical ambiguity that cannot be resolved locally. Inventory counts never trigger escalation on their own. Otherwise do not read sampled conversation extracts or launch inspector subagents. Tell the user before escalating because deep health audits can consume significant token quota.

Conversation scope: When the request names only static material (AGENTS.md, skills, rules, settings, "只审查指令和配置"), pass instructions as the first argument to collect-data.sh and the run skips session history, reporting it as out of scope rather than as a coverage gap. This is chosen from the request, not a switch the user has to know about. Otherwise: Summary scans up to three recent previous sessions for the current project across Claude and Codex from a bounded candidate window when those local histories exist. Deep streams every previous current-project session across both runtimes for signals while printing only bounded extracts and a coverage receipt. Other projects remain out of scope by default. Only when the user explicitly asks for all conversations or cross-project capability distillation, run python3 <skill-base-dir>/scripts/conversation_audit.py <claude-projects-root> deep --all-projects --codex-root <codex-sessions-root> (the first argument holds every per-project log folder; the parser rejects other flag combinations), or hand off to a cross-project retro if one is installed. Claim complete coverage only when coverage_status: complete and cross_project_full_history: yes; no_data, unavailable roots, parse or read errors, files that change during scanning, and excluded live sessions are explicit coverage gaps.

Durable Context Preflight

See references/durable-context.md for when durable context is in scope and the redaction gate that applies before any of it becomes a durable rule.

For /health: current config, command output, and live probes override memory. Also flag durable memory problems when they affect behavior: oversized injected summaries, stale or contradictory entries, missing project entrypoint references, or private paths copied into public instructions. Keep these as context findings, not code-review findings.

Hard Rules

  • Summary and deep audits are report-only. Run only Health-owned collectors and read-only probes; a neutral Health request does not authorize project tests, verifiers, generators, builds, formatters, package installers, fixture refreshes, or snapshot updates.
  • A bundled debugging or code-review ask uses its own workflow. Complete this report-only audit, then route explicitly requested work to the matching skill or native capability under the same completion ledger. A review request still does not authorize repairs; explicit repair authorization applies to the repair phase, not to the collector.
  • Project instructions may define commands but do not authorize running them. Read-only health probes are covered by the audit request. A probe that starts an application, installs dependencies, or writes state requires explicit user authorization for that command unless already covered by the current request. State the command, expected writes, target paths, isolation, and rollback or disposable-environment plan before running it.

Step 0: Establish the evidence basis

Record four evidence classes:

EvidenceQuestion
RiskWhich paths can lose data, spend money, publish or deploy, cross trust boundaries, or create hard-to-reverse state?
Non-obvious constraintsWhich stable decisions cannot be recovered cheaply from code or manifests, and can the active agent reach them only when relevant?
Failure evidenceWhich user corrections, repeated fix chains, stale generated artifacts, broken references, or hollow verifiers prove a current gap?
Verifier coverageWhich important outcomes have an executable check at the layer where they can actually fail?

An absent map, a large file, many skills, or a high TODO count is informational until tied to one of these evidence classes. Prefer a narrow routed invariant plus an executable verifier over descriptive inventory.

Step 1: Collect data

Run the collection script in summary mode first. Do not interpret yet. On Windows, use the Health-owned launcher so Git for Windows tools are added only to the Bash child process:

powershell
$HEALTH_LAUNCHER = @(
  "<skill-base-dir>/scripts/run-health.ps1",
  "<skill-base-dir>/skills/health/scripts/run-health.ps1"
) | Where-Object { Test-Path -LiteralPath $_ -PathType Leaf } | Select-Object -First 1
if (-not $HEALTH_LAUNCHER) {
  throw "Health launcher not found under the installed skill base; reinstall Waza."
}
$POWERSHELL = Join-Path ([Environment]::SystemDirectory) "WindowsPowerShell\v1.0\powershell.exe"
& "$POWERSHELL" -NoLogo -NoProfile -ExecutionPolicy Bypass -File "$HEALTH_LAUNCHER" collect

-ExecutionPolicy Bypass applies only to this PowerShell process; do not change the user's machine or account execution policy.

On Linux and macOS, keep the direct Bash flow:

bash
HEALTH_SCRIPT=""
for candidate in \
  "<skill-base-dir>/scripts/collect-data.sh" \
  "<skill-base-dir>/skills/health/scripts/collect-data.sh"; do
  [ -f "$candidate" ] && HEALTH_SCRIPT="$candidate" && break
done
if [ ! -f "${HEALTH_SCRIPT:-}" ]; then
  echo "health collect-data.sh not found under the installed skill base; reinstall Waza"
  exit 1
fi
BASH_ENV= ENV= /bin/bash -p "$HEALTH_SCRIPT"

Sections may show (unavailable) when tools are missing:

  • trusted python3 missing: conversation, MCP/hooks/allowedTools, and skill-security sections unavailable
  • settings.local.json absent: hooks/MCP may be unavailable (normal for global-only setups)

Treat (unavailable) as insufficient data, not a finding. Do not flag those areas.

The collector includes both runtime-specific and agent-agnostic surfaces:

  • AGENT CONFIG SUMMARY / AGENT CONFIG DETAIL for Codex, Claude, Pi, and project instruction files; its sections start at === AGENT INSTRUCTION SURFACE ===.
  • AI MAINTAINABILITY SUMMARY / AI MAINTAINABILITY DETAIL for project signals, verification surface, generated mirrors, wrappers, and doc links; its sections start at === PROJECT SHAPE ===.

Step 1b: Runtime Inventory and MCP Check

Inspect configured global, project, and installed-plugin sources first, retaining source and enablement. Use the runtime inventory to flag missing hook and MCP executables; unknown working directories or plugin state remain coverage gaps. Call a harmless tool only on already connected servers. Never launch an unverified GUI executable just to test MCP. Record connected, failed, disabled, pending approval, or untested separately; static presence is not live health. Never emit credentials. Compare discovered instruction bytes with the effective configured limit and state any uninspected ancestors, nested files, or runtime overrides.

Step 1c: Safety and security checks

These run after collection and before the Step 2 analysis. The first two apply to every audit; the third only to projects with long-running or autonomous agents.

Security Baseline Checks

Run these on every audit. They are the floor, not the ceiling.

Deny-list floor. Apply this only when the runtime actually enforces the rule shape being recommended: agent permission settings, hook settings, MCP settings, allowed/denied tools, or a documented autonomous-agent launcher. In that case, the settings should deny, at minimum: credential and key directories (SSH, cloud providers, GPG, gh CLI), credential-bearing files (credentials*, secrets*), and pipe-to-shell installers. Treat .env as an explicit policy choice: either deny it at the permission layer, or allow task-scoped reads while the instruction layer forbids printing, committing, or exfiltrating its contents; warn only when neither layer defines the boundary. Report missing categories as one concise WARN; let the reviewer fill in exact local paths. Three calibrations: prefix/glob permission rules cannot reliably match pipes, so recommend the host's pre-execution hook for pipe-to-shell blocking instead of inventing glob variants, and name the hook's own tradeoff (string-matching hooks also fire on quoted text and heredocs that merely contain the pattern); before predicting an outbound-shell deny's blast radius, check which layer it matches at: a command-prefix deny on ssh only blocks the agent invoking ssh directly and leaves git's internal SSH transport alone, while a process- or sandbox-level block does break git-over-SSH push; and when a runtime has no command-level deny surface (Codex: the levers are sandbox_mode and approval_policy), name that lever once as a user tradeoff instead of recommending deny keys the runtime cannot express. If no agent settings surface exists at all, report the deny-list as not applicable rather than a failure.

Permission-layer vs instruction-layer gating. An allowlist entry for a git write action (git push) next to an instruction-layer rule ("push only when the user says so") is not automatically a contradiction: instructions decide when the action happens, permissions decide whether it re-prompts, and a user who explicitly authorizes pushes every session may keep push in allow deliberately to avoid double confirmation. Calibrate by reversibility and the user's own rules: actions the instructions forbid outright (git reset --hard, git stash, force-push) belong in deny or ask; routine explicitly-authorized actions stay where the user put them, reported at most as a note. Escalate only when auto mode plus skipped prompts plus broad allow lets a write action run with zero user input in a session, and even then present the friction tradeoff for the user to choose instead of silently moving entries.

Environment override surface. Treat the following as attack surface, report when set in tracked files or shipped settings without a justification comment: API base-URL overrides (redirect all traffic to a third party), auto-trust flags for project-local MCP servers, wildcard tool allowlists (allowedTools: ["*"]), and permission-skip flags (--dangerously-skip-permissions or equivalents). Print file:line and the key name only; never print secrets.

Show full SKILL.md (1,043 more words)Show less
Memory and Skill Supply Chain

Treat agent memory and third-party skills as supply-chain artifacts. They run with the user's privileges.

Memory hygiene. Audit the project's long-term agent memory store for secrets, tokens, or credentials (Critical), and for entries written by untrusted runs (subagent invoked on attacker-controlled input, /loop iteration over external content); recommend rotation after such runs. For high-risk one-off runs (untrusted PDFs, uncontrolled scraping, third-party scripts), recommend disabling memory persistence for that session entirely.

Skill supply chain. Third-party skills, plugins, and MCP servers run with the user's privileges. For each one not authored in this repo, check: source pinned to a release tag or revision (not main, a branch, or a remote git marketplace left tracking its latest head), hook handlers do not write to credential directories, MCP servers have explicit user consent (not auto-trusted by wildcard). Report unpinned sources or unreviewed hook handlers as Structural, not Critical, unless an active exploit signal is present.

Long-Running Agent Stop Conditions

For projects that use /loop, autonomous agents, or any long-running agent flow, load references/long-running-agents.md and audit the four hard stop signals it lists. Projects without such a flow skip this check.

Step 2: Analyze

Analyze locally from the summary output by default. When Budget posture escalates, re-run collection with & "$POWERSHELL" -NoLogo -NoProfile -ExecutionPolicy Bypass -File "$HEALTH_LAUNCHER" collect auto deep on Windows, or BASH_ENV= ENV= /bin/bash -p "$HEALTH_SCRIPT" auto deep on Linux and macOS. Then launch only the relevant inspectors in parallel. Redact credentials to [REDACTED].

  • Deep inspector routing:
    • Agent 1 (Context + Security): Read agents/inspector-context.md. Feed CONVERSATION SIGNALS section.
    • Agent 2 (Control + Behavior): Read agents/inspector-control.md. Feed the relevant runtime, hook, MCP, and permission evidence.
    • Agent 3 (AI Maintainability): Read agents/inspector-maintainability.md. Feed only PROJECT SIGNALS, AI MAINTAINABILITY SUMMARY or AI MAINTAINABILITY DETAIL, and concrete verifier/drift receipts. Launch this agent only for deep health audits or explicit code-rot/AI-maintainability requests.
  • Fallback: If a subagent fails, analyze that layer locally and note "(analyzed locally)".

Before reporting a deep audit as complete, wait for every launched inspector and reconcile its assigned scope. If one remains pending or fails without a local replacement pass, list that scope as unreviewed instead of issuing a whole-scope clean bill.

Gotchas

What happenedRule
Missed the local overrideAlways read settings.local.json too; it shadows the committed file
Subagent timeout reported as MCP failureMCP failures come from the live probe, not data collection
Flagged intentionally noisy hook as brokenAsk before calling a hook "broken"
Hook seemed not to fire, but it did -- a later UI element rendered above itHook firing order is not visual order. Before re-editing the hook config: (a) confirm with --debug or by piping output, (b) check whether a diff dialog, permission prompt, or other UI element rendered on top and pushed the hook output offscreen, (c) only then suspect the hook itself.
Treated missing specs/docs as a failureDecision artifacts are optional by default. Escalate missing docs/specs only when active handoff risk, failure evidence, or the user request makes them necessary.

Output

Health Report: {project} ({summary|deep}, evidence-based)

Global findings report once. Findings in machine-global config (~/.claude, ~/.codex, global rules, skills, memory) are not project findings: label them global, report each once with its fix, and recommend one dedicated session for global cleanup instead of re-fixing per project. Before editing any global file, re-read its current state: when health runs across several projects in one day, another session may already have fixed or be mid-fix on the same file, and re-applying a variant of the same rule creates duplicate entries. Never edit the same global file from two concurrent sessions.

[PASS] Passing checks (table, max 5 rows)
Finding format
- [severity] <symptom> ({file}:{line} if known)
  Why: <one-line reason>
  Action: <exact command or edit to fix>

Action: must be copy-pasteable. Never write "investigate X" or "consider Y". If the fix is unknown, name the diagnostic command.

A finding refuted in the same breath (a TODO count that turns out to be vendored code or false positives) is not a finding; drop it or fold it into the passing table.

[!] Critical -- fix now

Confirmed dangerous permissions, consequential rule violations, security findings, and leaked credentials. Server counts and estimated context percentages never establish Critical severity.

Example:

  • [!] settings.local.json committed to git (exposes MCP tokens) Why: leaked token enables remote code execution via installed MCP servers Action: git rm --cached .claude/settings.local.json && echo '.claude/settings.local.json' >> .gitignore
[~] Structural -- fix soon

Agent instructions in the wrong layer, missing hooks, oversized descriptions, verifier gaps.

Codex/Claude/Pi instruction drift. Use AGENT CONFIG SUMMARY first. project_instructions_mode says which files Claude Code loads: on claude-md an AGENTS.md alone reaches Codex and Cursor but not Claude, and nested_agents_md counted together with a root CLAUDE.md means those nested guides reach nobody on Claude, because the root file switches the whole project off the AGENTS.md path rather than just its own folder. The exception is claude-md-and-agents-md, where both are read and the nested files still load, unless CLAUDE.md is the same physical file as AGENTS.md and the deduplicated chain is skipped. Report a Structural finding when AGENTS.md and runtime-specific files both contain substantial guidance without delegation, when Codex config.toml lacks trust for the current project, when Pi settings or package metadata point at missing skill roots, when project agent instructions are missing, or when runtime-specific instructions contradict the shared project source of truth. Also report when important rules live only in ignored or private local instruction overlays but the tracked/public docs lack them; those overlays are private context, not durable project source of truth. Do not print raw config values. Secrets, tokens, keys, and passwords must appear only as [REDACTED].

Quick check from the project root, reusing $HEALTH_SCRIPT resolved in Step 1 (standalone output has no AGENT CONFIG SUMMARY wrapper):

powershell
& "$POWERSHELL" -NoLogo -NoProfile -ExecutionPolicy Bypass -File "$HEALTH_LAUNCHER" agent-context . summary

On Linux and macOS:

bash
BASH_ENV= ENV= /bin/bash -p "${HEALTH_SCRIPT%/*}/check-agent-context.sh" . summary

AI-maintainability findings. For the maintainability lane (verification surface, conversation-derived guidance, concentrated fix chains, risk-backed hotspot ownership, non-obvious constraint reachability, verifier wrapper, broken doc and Markdown references, stale verifier cache output), load references/maintainability-findings.md and work its checks with AI MAINTAINABILITY SUMMARY / DETAIL.

[-] Incremental -- nice to have

Outdated items, global vs local placement, context hygiene, stale allowedTools entries.

If no issues: All relevant checks passed. Nothing to fix.

A report-only request never authorizes fixes; an explicit optimization or repair request continues into its authorized repair phase without another confirmation. The audit is not a heavy lint, typecheck, duplication, or architecture-rewrite substitute; /health reports maintainability guardrails and concrete next actions only.

© tw93, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 20 other files (scripts, references) in skills/health of tw93/Waza.

  • SKILL.md
  • agents/inspector-context.md
  • agents/inspector-control.md
  • agents/inspector-maintainability.md
  • references/durable-context.md
  • references/long-running-agents.md
  • references/maintainability-findings.md
  • scripts/block-pipe-to-shell.py
  • scripts/check-agent-context.sh
  • scripts/check-doc-refs.sh
  • scripts/check-maintainability.sh
  • scripts/check-verifier-output.sh
  • scripts/check_agent_context.py
  • scripts/check_doc_refs.py
  • scripts/check_maintainability.py
  • scripts/check_verifier_output.py
  • scripts/collect-data.sh
  • scripts/conversation_audit.py
  • … and 3 more

Open the folder on GitHubat commit 8b2c356

Compare with similar skills

Agent Setup Health Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent Setup Health Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent Setup Health Audit this skilltw93/Waza7.2k—~5.2kAutomated safety check: NotesMIT
Working With Claude Code Docsobra/superpowers-developing-for-claude-code142—~1.5kAutomated safety check: PassNone
Claude Code Mastery Squadohmyjahh/xquads-squads277—~1.1kAutomated safety check: PassMIT
Mistral Vibe CLI Referencemistralai/mistral-vibe5.1k—~15kAutomated safety check: NotesApache-2.0
Zcode Configuration Guidezai-org/ZCode7.7k—~2.5kAutomated safety check: PassApache-2.0
Claude Codekid-sid/claude-spellbook190—~3.9kAutomated safety check: PassMIT

Similar skills

  • Working With Claude Code Docs

    obra/superpowers-developing-for-claude-code

    Looks up official Claude Code documentation stored as reference files instead of guessing about CLI commands, configuration, or plugin APIs.

    142 GitHub stars~1.5k tokensUpdated 10 mo ago
    Agent WorkflowsAuto-check passed
  • Claude Code Mastery Squad

    ohmyjahh/xquads-squads

    Routes a request to one of eight specialist agents covering hooks, skills, subagents, MCP integration and context engineering for Claude Code.

    277 GitHub stars~1.1k tokensUpdated 11 days ago
    Agent WorkflowsAuto-check passed
  • Mistral Vibe CLI Reference

    mistralai/mistral-vibe

    Official

    Reference for Mistral Vibe, the CLI agent it runs inside: config files, env vars, agents, skills, tools, hooks and MCP servers, so the agent can explain and troubleshoot its own setup.

    5.1k GitHub stars~15k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • A skill your agent uses when configuring ZCode's extension resources (MCP servers, slash commands, skills, hooks, and plugins) or instruction files such as AGENTS.md in the ZCode client.

    7.7k GitHub stars~2.5k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Claude Code

    kid-sid/claude-spellbook

    A skill your agent uses when configuring Claude Code — installing skills or agents, writing hook configurations, setting up tool permissions, registering MCP servers, or authoring CLAUDE.md project…

    190 GitHub stars~3.9k tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from tw93/Waza

  • Fetches web pages and PDFs and returns a source-grounded summary, clean Markdown, quotes or citations, routing each kind of link to a suitable fetch method.

    7.2k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Reviews diffs and pull requests, triages issues, and checks release readiness, reporting findings with evidence and making no edits unless authorized.

    7.2k GitHub stars~6.9k tokensUpdated today
    Auto-check passed
  • Forces a one-sentence, evidence-backed root cause before any fix is applied, and gates when a diagnosis session is even allowed to touch code.

    7.2k GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Turns a rough idea into an approved, decision-complete plan or recommendation before any code is written, for architecture choices and go or no-go calls.

    7.2k GitHub stars~3k tokensUpdated today
    Auto-check: notes
  • Builds or restyles production UI with a clear point of view, checks the result against screenshots and responsive states, and hands document typography to other skills.

    7.2k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Runs a six-phase research workflow from a bundle of sources to a chosen output, whether quick notes, a canonical reference article or a publish-ready draft.

    7.2k GitHub stars~2.2k tokensUpdated today
    Auto-check passed

Questions about Agent Setup Health Audit

What does Agent Setup Health Audit do?

Audits a project's agent configuration, instruction drift, hooks, MCP and AI maintainability, then reports prioritized findings with evidence and next actions. A layered framework drives the audit, running from agent config through instruction surfaces, tools and runtime, and verifiers to maintainability. The agent looks for violations and names the misaligned layer.

When should I use Agent Setup Health Audit?

Agent Setup Health Audit fits situations like: Codex or Claude setup looks wrong or its instructions contradict each other; auditing hooks, MCP servers and permissions in a project; checking whether verifier output points at stale paths; reviewing how maintainable a repository is for AI coding agents.

How do I install Agent Setup Health Audit in Claude Code?

Run `npx skills add tw93/Waza --skill health -a claude-code`. Or copy the skill folder (skills/health in tw93/Waza) into .claude/skills/health in your project. Claude Code loads it when a task matches its description.

How do I install Agent Setup Health Audit in Codex?

Run `npx skills add tw93/Waza --skill health -a codex`. Or copy the skill folder (skills/health in tw93/Waza) into .agents/skills/health in your project. Codex loads it when a task matches its description.

Can I use Agent Setup Health Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tw93/Waza --skill health -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/health, .gemini/skills/health, .github/skills/health and .opencode/skills/health in your project.

What does Agent Setup Health Audit need to run?

Going by SKILL.md and its folder, Agent Setup Health Audit needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (git, bash and python3). Our summary lists: Python and a shell to run the bundled check scripts.

Does Agent Setup Health Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Agent Setup Health Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Agent Setup Health Audit use?

Agent Setup Health Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent Setup Health Audit use?

About 5.2k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.

What are the alternatives to Agent Setup Health Audit?

Skills that share tags, products or a category with Agent Setup Health Audit: Working With Claude Code Docs (obra/superpowers-developing-for-claude-code, 142 stars), Claude Code Mastery Squad (ohmyjahh/xquads-squads, 277 stars), Mistral Vibe CLI Reference (mistralai/mistral-vibe, 5.1k stars) and Zcode Configuration Guide (zai-org/ZCode, 7.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent Setup Health Audit?

tw93 (a GitHub user) maintains it in tw93/Waza, which has 7,239 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 11, 2026.

Source: tw93/Waza on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.