Agent skill

Audit Flow

by zebbern in zebbern/claude-code-guide

Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.

MITAuto-check passedDevelopment

Install Audit Flow

skills CLI
$ npx skills add zebbern/claude-code-guide --skill audit-flow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zebbern/claude-code-guide audit-flow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-flow .claude/skills/audit-flow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-flow
GitHub stars
4.7k
Token cost
~4.2k tokens
SKILL.md length
1,270 words
Files
6 (incl. scripts)
Skills in repo
46
Repo updated
First seen
Licence
MIT

At a glance

Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.

  • Works in 4 steps: Session Start - Ask → Granularity - Ask → During Trace → …
  • Security audits
  • SKILL.md covers ⚠️ MANDATORY ENTRY POINT —…, Organization Principles, DB-First Discipline and Interactive Workflow - ALWAYS…, plus 14 more sections
  • Runs Python and Shell scripts from its folder; calls python, git and sqlite3

What it does

Audit Flow is an agent skill from zebbern/claude-code-guide. Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems. Triggers on audit, trace flow, document flow, security review, debug flow, brainstorm, architecture review, post-mortem, incident review.

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `COMMANDS.md`, `EXAMPLES.md` and `scripts/audit.py`). Compatibility notes: Requires Python 3.8+ (stdlib only, zero dependencies). Optional pyyaml for YAML export. Git for merge/diff driver features.

It sits in Development, covering Brainstorming, Software architecture and Runbooks and postmortems. It works with SQLite and Mermaid. The repository describes itself as: Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks from beginner to power user! The licence is MIT.

When your agent uses it

  • Security audits
  • Compliance documentation
  • Feature ideation
  • Architecture reviews

Example prompts

  • “/audit-flow”

Requirements

  • Python 3
  • A Bash shell
  • Compatibility (from SKILL.md): Requires Python 3.8+ (stdlib only, zero dependencies). Optional pyyaml for YAML export. Git for merge/diff driver features.

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Session Start - Ask
  2. Granularity - Ask
  3. During Trace
  4. On Export

What it can do on your machine

Read from SKILL.md and the folder at commit e62775c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • git
    • sqlite3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Python 3.8+ (stdlib only, zero dependencies). Optional pyyaml for YAML export. Git for merge/diff driver features.

    From compatibility in the SKILL.md frontmatter.

Context cost

Audit Flow loads about 4.2k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 1,270 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from zebbern/claude-code-guide at commit e62775c, republished under its MIT licence (© zebbern). 1,270 words, ~4,182 tokens.

Download SKILL.mdSave it as .claude/skills/audit-flow/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
audit-flow
description
Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems. Triggers on audit, trace flow, document flow, security review, debug flow, brainstorm, architecture review, post-mortem, incident review.
compatibility
Requires Python 3.8+ (stdlib only, zero dependencies). Optional pyyaml for YAML export. Git for merge/diff driver features.
license
MIT
metadata.author
ArunJRK
metadata.version
1.0.0

⚠️ MANDATORY ENTRY POINT — Execute Before ANY Other Action

Step 1: Read schema.sql

bash
# ALWAYS read the schema first to understand tables, constraints, views
cat .claude/skills/audit-flow/schema.sql

Step 2: Check if DB exists — NEVER recreate

bash
# Check for existing database
ls -la .audit/audit.db 2>/dev/null && echo "DB EXISTS - DO NOT RECREATE" || echo "No DB - safe to init"

Step 3: If DB exists, show current state

bash
python .claude/skills/audit-flow/scripts/audit.py list
🚫 FORBIDDEN ACTIONS
ActionWhy Forbidden
rm .audit/audit.dbDestroys audit history
audit.py init when DB existsOverwrites existing data
DROP TABLEDestroys audit history
sqlite3 .audit/audit.db < schema.sql when DB existsOverwrites existing data

Rule: If .audit/audit.db exists, ONLY use audit.py list, show, export, or INSERT operations. NEVER recreate.


Audit Flow

Interactive tracing of system flows with SQLite persistence. Supports multiple named flows per session, non-linear flows (branching/merging), and multi-format exports.

Organization Principles

Directory structure by purpose:

  • Audits/Documentation/Compliance: docs/audits/{name}-{YYYY-MM-DD}/
  • Ideation/Brainstorming: docs/ideation/{name}-{YYYY-MM-DD}.md (single file, no subdirectory unless artifacts needed)
  • Debugging/Incident Review: docs/audits/{name}-{YYYY-MM-DD}/ (same as audits — captures evidence)
  • Architecture Review: docs/audits/{name}-{YYYY-MM-DD}/ (same as audits — captures structural analysis)

Required files:

  • INDEX.md (manifest, entry point)
  • README.md (executive summary)
  • {name}-audit.md (flow trace)

Lazy initialization: Create subdirectories only when artifacts exist

  • screenshots/ network-traces/ diagrams/ code-samples/ test-results/ evidence/

Naming: {audit-name}-{type}.md

DB-First Discipline

Invariant: SQLite = sole source of truth. Context window: volatile, compacts without notice, hallucinates state.

🚨 CRITICAL: NEVER DESTROY EXISTING DATA

  • If .audit/audit.db exists → it contains irreplaceable audit history
  • NEVER run init when DB exists — use list to see what's there
  • NEVER delete, drop, or recreate — only append

Constraints:

OperationRuleBlocked rationalization
EntryRead schema.sql FIRST, check if DB exists SECOND"I'll just start working"
InitONLY if .audit/audit.db does NOT exist"Let me reinitialize to start fresh"
SchemaRead schema.sql BEFORE any SQLite command — understand tables, constraints, views first"I know the schema from context"
WriteINSERT each tuple/edge/finding before moving to the next code location"I'll batch-insert at the end"
ReadSELECT from DB before referencing tuple IDs, counts, or flow structure"I remember the flow so far"
Exportaudit.py export only — never generate mermaid/markdown from context"Let me generate mermaid directly"
Resumeaudit.py show <session> before any operation that references prior tuples"I have the full trace in context"
ReferenceQuery tuple IDs from DB — IDs are DB-assigned, never inferred"The tuple ID should be N"
DefaultWhen uncertain of flow state → query DB before proceeding(any unlisted rationalization)

Checkpoint: Every 5 tuples → audit.py show <session> <flow>


Interactive Workflow - ALWAYS ASK USER

1. Session Start - Ask:
Name: ___
Purpose: security-audit | documentation | compliance | ideation | brainstorming | debugging | architecture-review | incident-review
Description: ___ (optional)

Initialize directory immediately. Lazily create subdirectories when artifacts are generated.

2. Granularity - Ask:
[fine]   Function-level trace (~50-200 tuples)
         Use: Security audits, debugging

[coarse] Boundary-level trace (~10-30 tuples)
         Use: Documentation, high-level flows

Choose: fine / coarse
3. During Trace:

Ask at decision points: trace deeper? mark concern? add finding (severity)? note?

4. On Export:

Ask format: json | yaml | md | mermaid | all

Post-export: Generate INDEX.md manifest. Organize artifacts by type. Prune empty directories.

Quick Reference

CommandPurpose
/audit-flow startNew session (name, purpose, granularity)
/audit-flow flow {name}Add new flow to session
/audit-flow add {layer} {desc}Add tuple to current flow
/audit-flow link {from} {to} {rel}Create edge (supports conditions for branches)
/audit-flow finding {desc}Record finding
/audit-flow showView session/flow details
/audit-flow exportExport (json/yaml/md/mermaid)
/audit-flow git-setupConfigure git merge/diff drivers (once)

Layers: CODE | API | NETWORK | AUTH | DATA

Relations: TRIGGERS | READS | WRITES | VALIDATES | TRANSFORMS | BRANCHES | MERGES

Semantic Rules for Relations

RelationMeaningUse WhenNOT For
TRIGGERSA causes B to executeFunction calls, event handlers, HTTP requestsStatic observations
READSA consumes data from BCookie reads, DB queries, config lookupsMutations
WRITESA mutates data in BCookie writes, DB inserts, state updatesRead-only access
VALIDATESA checks/verifies BAuth checks, input validation, expiry checksChaining analyst observations
TRANSFORMSA converts/maps data for BToken exchange, response formattingUnrelated processing
BRANCHESA has conditional pathsif/else, switch, error vs successMust have condition label
MERGESMultiple paths converge at BParallel paths rejoin, error recoverySingle-path flow

CRITICAL: BRANCHES Must Have Conditions. Every BRANCHES edge requires a condition describing which path. Example: BRANCHES [token expired] vs BRANCHES [token valid].

Observations vs Flow Steps

Flow steps = things the SYSTEM DOES (function calls, data reads, network requests). Verified by tracing code.

Observations = things the ANALYST NOTES (missing features, potential risks). Record as findings, not tuples.

Wrong pattern:

T50 "NO cross-tab sync"       ← observation, not a system action
T51 "React state NOT shared"  ← observation
T50 --VALIDATES--> T51         ← chaining observations as flow

Correct pattern:

sql
-- Record as finding instead:
INSERT INTO findings (flow_id, session_id, severity, category, description)
VALUES (?, ?, 'medium', 'state-management',
        'No cross-tab sync: React state not shared across tabs');

Rule: NEVER chain observations with VALIDATES. If describing what the system DOESN'T do, use a finding.

Data Model

Session (audit container)
  └── Flow (named DAG with entry point)
       └── Tuple (node: layer + action + subject)
            └── Edge (relation + optional condition)

Storage & CLI

bash
# Core
python .claude/skills/audit-flow/scripts/audit.py init              # Initialize DB
python .claude/skills/audit-flow/scripts/audit.py list              # List sessions
python .claude/skills/audit-flow/scripts/audit.py show <session>    # Show flows
python .claude/skills/audit-flow/scripts/audit.py show <session> <flow>  # Show flow details
python .claude/skills/audit-flow/scripts/audit.py export <session>  # Export all
python .claude/skills/audit-flow/scripts/audit.py export <session> -f <flow>  # Export one flow
python .claude/skills/audit-flow/scripts/audit.py validate <session>         # Validate flows

# Git integration
python .claude/skills/audit-flow/scripts/audit.py git-setup         # Configure merge/diff drivers (once)
python .claude/skills/audit-flow/scripts/audit.py db-merge %O %A %B # Git merge driver (auto-called)

# CSV backup/portability (optional)
python .claude/skills/audit-flow/scripts/audit.py csv-export               # DB → .audit/csv/*.csv
python .claude/skills/audit-flow/scripts/audit.py csv-import               # .audit/csv/*.csv → DB
python .claude/skills/audit-flow/scripts/audit.py csv-merge <theirs_dir>   # Merge two CSV sets

Non-Linear Flows

Branching: One tuple → multiple outgoing edges with conditions

sql
INSERT INTO edges (from_tuple, to_tuple, relation, condition)
VALUES (5, 6, 'BRANCHES', 'token valid'),
       (5, 7, 'BRANCHES', 'token expired');

Merging: Multiple tuples → one tuple

sql
INSERT INTO edges (from_tuple, to_tuple, relation)
VALUES (6, 8, 'TRIGGERS'),
       (9, 8, 'MERGES');  -- refresh path merges back

Files

  • scripts/audit.py - CLI for all commands (init, list, show, export, validate, db-merge, git-setup, csv-*)
  • COMMANDS.md - Detailed SQL reference
  • EXAMPLES.md - Full examples with non-linear flows
  • schema.sql - Database schema
  • .gitattributes - Git merge/diff driver config for audit.db

Git Context

Capture on session start: commit hash, branch, working tree status. Include in all exports.

Show full SKILL.md (530 more words)Show less

Mermaid Validation

Run python .claude/skills/audit-flow/scripts/audit.py validate <session> before export.

CheckSeverityDescription
BRANCHES without conditionERROREvery BRANCHES edge needs a condition label
Node count >= 60ERRORSplit into sub-flows
Node count >= 40WARNConsider splitting
Orphan nodesWARNNode with no edges (disconnected)
Duplicate labelsWARNSame action text without subject disambiguation
No entry pointWARNAll nodes have incoming edges

Post-export features (automatic):

  • Step numbers: BFS topological order from entry point (1. action, 2. action)
  • Entry point: Stadium shape with green styling
  • Edge arrows: --> solid (TRIGGERS/VALIDATES/TRANSFORMS/BRANCHES/MERGES), -.-> dotted (READS), ==> thick (WRITES)
  • Observations: Separated into dashed-border OBSERVATIONS subgraph
  • Direction: --direction LR flag for horizontal layouts

Diagram Readability Requirements

All diagrams MUST be produced by audit.py export. Never hand-craft mermaid. The exporter enforces:

  1. Entry point marker — Green stadium-shape node ([label]):::entryPoint
  2. Step numbers — BFS topological order: 1. action, 2. action, 3. action
  3. Legend block — classDef styles for entryPoint, concern, observation
  4. Observation separation — Concern-only chains go to OBSERVATIONS subgraph, not main flow
  5. Label safety — HTML entities for (), "", <>, |, [] characters (auto-sanitized)

Reading flow must be obvious. A reader opening the diagram cold must immediately see:

  • WHERE to start (green entry node)
  • WHAT ORDER to read (step numbers)
  • WHICH PATH is happy vs error (branch conditions on edges)
  • WHAT THE COLORS MEAN (legend)

Node label rules:

  • Use concrete nouns/verbs: handleCallback(), exchangeCodeForTokens()
  • NOT bare verbs: "Configure", "Select", "Enable"
  • Disambiguate duplicates: auto-suffixed with subject when action repeats

Size limits:

  • 40+ nodes → warning, consider splitting
  • 60+ nodes → error, MUST split into sub-flows
  • If flow has 5+ independent sub-flows → split by purpose

Git Workflow — Custom Merge Driver

Problem: SQLite is binary — git merge can't auto-resolve .audit/audit.db.

Solution: Custom git merge driver. audit.db stays in git (small, single file). On conflict, git calls audit.py db-merge to auto-merge using SQL.

One-Time Setup
bash
python .claude/skills/audit-flow/scripts/audit.py git-setup

This configures (in .git/config):

  • Merge driver: merge.sqlite-audit — calls audit.py db-merge %O %A %B on conflict
  • Diff driver: diff.sqlite — sqlite3 .dump for readable git diff output

Also requires .gitattributes (already in repo):

.audit/audit.db diff=sqlite merge=sqlite-audit
How It Works
  1. You commit audit.db normally — git add .audit/audit.db && git commit
  2. git diff shows SQL text (via textconv)
  3. On git merge with conflict → git calls the merge driver automatically
  4. Driver opens both DBs, merges sessions by name (later updated_at wins), remaps IDs
  5. Result written to ours — merge completes cleanly
Merge Strategy
TableMerge KeyConflict Resolution
sessionsname (unique)Keep later updated_at
flows(session_name, flow_name)Follow parent session winner
tuplesParent flowAll tuples from winning flow kept
edgesBoth endpoint tuplesKept if both endpoints survive
findings(session_name, category, description)Dedup by content

All INTEGER PKs remapped sequentially. Foreign keys updated.

CSV Backup (Optional)

CSV export/import still available for portability and backup:

bash
python .claude/skills/audit-flow/scripts/audit.py csv-export   # DB → .audit/csv/*.csv (QUOTE_ALL)
python .claude/skills/audit-flow/scripts/audit.py csv-import   # CSV → DB (recreates from scratch)

Output Quality

Principles:

  • ASCII sequence diagrams for complex flows
  • Side-by-side tables for alternatives
  • Real code from traced files with file:line references
  • What/Why/Example pattern
  • No generic templates

Completion Checklist

  • Directory exists with ISO date suffix
  • INDEX.md manifest generated
  • README.md (executive summary)
  • Naming convention: {name}-{type}.md
  • Artifacts in typed subdirectories (lazy init)
  • Git context captured
  • Git merge driver configured (audit.py git-setup)
  • No orphaned files
  • Diagrams pass audit.py validate

Anti-Patterns

Flat structure, empty directories, orphan nodes, unlabeled branches, generic identifiers, missing git context, no manifest, hand-crafted mermaid, bare-verb labels.

© zebbern, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts) in skills/audit-flow of zebbern/claude-code-guide.

  • SKILL.md
  • COMMANDS.md
  • EXAMPLES.md
  • schema.sql
  • scripts/audit.py
  • setup.sh

Open the folder on GitHubat commit e62775c

Compare with similar skills

Audit Flow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Flow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Flow this skillzebbern/claude-code-guide4.7k—~4.2kAutomated safety check: PassMIT
Code Graph Mermaid Diagramstrailofbits/skills7.4k1 repos~1.7kAutomated safety check: PassCC-BY-SA-4.0
Work Issuejoesaby/astro-mermaid123—~891Automated safety check: PassMIT
Codebase Pathfinderthedotmack/claude-mem98k1 repos~1.5kAutomated safety check: PassApache-2.0
Mind Mapmohitagw15856/pm-claude-skills1.4k—~710Automated safety check: PassMIT
Archify Diagramstt-a1i/archify79k—~2.9kAutomated safety check: PassMIT

Similar skills

  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub starsUsed in 1 repo~1.7k tokens
    DevelopmentAuto-check passed
  • Work Issue

    joesaby/astro-mermaid

    End-to-end workflow for resolving a GitHub issue in astro-mermaid — triages complexity, then runs brainstorm → TDD → implement → docs/spec → code review at the right depth.

    123 GitHub stars~891 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Codebase Pathfinder

    thedotmack/claude-mem

    Maps a codebase into feature-grouped Mermaid flowcharts, finds duplicated concerns across features and proposes a unified architecture with handoff prompts for planning.

    98k GitHub starsUsed in 1 repo~1.5k tokens
    DevelopmentAuto-check passed
  • Mind Map

    mohitagw15856/pm-claude-skills

    Turn a topic, brainstorm, or document into a structured mind map.

    1.4k GitHub stars~710 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Archify Diagrams

    tt-a1i/archify

    Creates interactive architecture, workflow, sequence, data-flow and lifecycle diagrams as standalone HTML with inline SVG, themes and image or video export.

    79k GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Archify Diagram Builder

    Unclecheng-li/AI_Animation

    Builds validated architecture, workflow, sequence, data-flow and lifecycle diagrams as standalone interactive HTML from a small JSON spec, with optional motion and image export.

    1.5k GitHub starsUsed in 2 repos~4.1k tokens
    DevelopmentAuto-check passed

More from zebbern/claude-code-guide

All 46 skills in this repo
  • Code To Diagram

    zebbern/claude-code-guide

    Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts.

    4.7k GitHub starsUsed in 1 repo~972 tokens
    Auto-check passed
  • Localization Toolkit

    zebbern/claude-code-guide

    This skill should be used when setting up, auditing, or enforcing internationalization/localization in UI codebases (React/TS, i18next or similar, JSON locales), including installing/configuring the…

    4.7k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Chart Image

    zebbern/claude-code-guide

    Generate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts.

    4.7k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.7k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Linux Shell Scripting

    zebbern/claude-code-guide

    This skill should be used when the user asks to "create bash scripts", "automate Linux tasks", "monitor system resources", "backup files", "manage users", or "write production shell scripts".

    4.7k GitHub starsUsed in 9 repos~3.1k tokens
    Auto-check: notes
  • Idor Testing

    zebbern/claude-code-guide

    This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

    4.7k GitHub starsUsed in 8 repos~3.1k tokens
    Auto-check passed

Works with

Questions about Audit Flow

What does Audit Flow do?

Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Audit Flow is an agent skill from zebbern/claude-code-guide. Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.

When should I use Audit Flow?

Audit Flow fits situations like: security audits; compliance documentation; feature ideation; architecture reviews.

How do I install Audit Flow in Claude Code?

Run `npx skills add zebbern/claude-code-guide --skill audit-flow -a claude-code`. Or copy the skill folder (skills/audit-flow in zebbern/claude-code-guide) into .claude/skills/audit-flow in your project. Claude Code loads it when a task matches its description.

How do I install Audit Flow in Codex?

Run `npx skills add zebbern/claude-code-guide --skill audit-flow -a codex`. Or copy the skill folder (skills/audit-flow in zebbern/claude-code-guide) into .agents/skills/audit-flow in your project. Codex loads it when a task matches its description.

Can I use Audit Flow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zebbern/claude-code-guide --skill audit-flow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-flow, .gemini/skills/audit-flow, .github/skills/audit-flow and .opencode/skills/audit-flow in your project.

What does Audit Flow need to run?

Going by SKILL.md and its folder, Audit Flow needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (python, git and sqlite3). Our summary lists: Python 3; A Bash shell. Compatibility (from SKILL.md): Requires Python 3.8+ (stdlib only, zero dependencies). Optional pyyaml for YAML export. Git for merge/diff driver features..

Does Audit Flow access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Flow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Audit Flow use?

Audit Flow is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Flow use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Flow?

Skills that share tags, products or a category with Audit Flow: Code Graph Mermaid Diagrams (trailofbits/skills, 7.4k stars), Work Issue (joesaby/astro-mermaid, 123 stars), Codebase Pathfinder (thedotmack/claude-mem, 98k stars) and Mind Map (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Flow?

zebbern (a GitHub user) maintains it in zebbern/claude-code-guide, which has 4,650 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 8, 2026.

Source: zebbern/claude-code-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.