Agent skill

Zhin Audit

by zhinjs in zhinjs/zhin

Audit Zhin.js changes for security, performance, lifecycle, and architecture regressions.

MITAuto-check: notesSecurity

Install Zhin Audit

skills CLI
$ npx skills add zhinjs/zhin --skill zhin-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zhinjs/zhin zhin-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zhinjs/zhin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/zhin-audit .claude/skills/zhin-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
zhin-audit
GitHub stars
136
Token cost
~596 tokens
SKILL.md length
114 words
Files
4 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Audit Zhin.js changes for security, performance, lifecycle, and architecture regressions.

  • Works in 4 steps: 固定审计基线 → 按范围检查 → Zhin 当前不变量 → …
  • Security review
  • SKILL.md covers 1. 固定审计基线, 2. 按范围检查, 3. Zhin 当前不变量 and 4. 报告格式
  • Calls pnpm

What it does

Zhin Audit is an agent skill from zhinjs/zhin. Audit Zhin.js changes for security, performance, lifecycle, and architecture regressions. Use for release review, security review, performance review, architecture review, or change-based code audit.

Its SKILL.md is about 600 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/architecture-checklist.md`, `references/performance-checklist.md` and `references/security-checklist.md`).

It sits in Security, covering Security review, Software architecture and Performance reviews. The repository describes itself as: AI-native TypeScript bot framework — one codebase for 20+ chat platforms (QQ, Discord, Telegram, Slack, WeChat…). Opt-in AI agent with MCP, tools & security policies. <10MB core. The licence is MIT.

When your agent uses it

  • Security review
  • Performance review
  • Architecture review
  • Change-based code audit

Example prompts

  • “/zhin-audit”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. 固定审计基线
  2. 按范围检查
  3. Zhin 当前不变量
  4. 报告格式

What it can do on your machine

Read from SKILL.md and the folder at commit f38698f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Zhin Audit loads about 596 tokens when it runs, and up to ~2k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 114 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~596
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:63
    范围与未验证边界。不要粘贴 token、`.env`、用户 ID 或完整敏感请求。

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zhinjs/zhin at commit f38698f, republished under its MIT licence (© zhinjs). 114 words, ~596 tokens.

Download SKILL.mdSave it as .claude/skills/zhin-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
zhin-audit
description
Audit Zhin.js changes for security, performance, lifecycle, and architecture regressions. Use for release review, security review, performance review, architecture review, or change-based code audit.
argument-hint
Describe the scope: changed files, package, security, performance, architecture, or full release.
user-invocable
true

Zhin.js 代码审计

先建立当前分支事实,再给结论。仓库的 AGENTS.md、docs/concepts/architecture.md、目标包 package.json 和现有 harness 是契约来源;不要从旧类名或旧目录推断实现。

1. 固定审计基线

  1. 读取目标 diff、相关测试和最近的包 README。
  2. 明确比较基线与未提交改动;变更审计默认看完整 diff,不只看最后一个 commit。
  3. 先跑与变更对应的最小门禁,再读失败调用链。
  4. 报告只写有证据的问题:给出触发条件、影响、文件和最小修复方向。

2. 按范围检查

  • 安全:按 安全清单 检查 Tool 策略、文件/网络/Shell 边界、Host 鉴权、凭据和输入验证。
  • 性能与生命周期:按 性能清单 检查 generation 回滚、listener、timer、socket、缓存和外部请求。
  • 架构:按 架构清单 检查依赖方向、Resource ownership、Feature 约定目录、Adapter 与消息链。

根据 diff 选择门禁,常用入口:

bash
pnpm check:architecture
pnpm check:domain-module-boundaries
pnpm check:harness-paths
pnpm check:adapter-endpoint-boundaries
pnpm check:no-removed-plugin-api
pnpm check:runtime-config-boundaries
pnpm check:agent-tool-authoring-boundaries
pnpm check:skill-authoring-boundaries
pnpm check:agent-authoring-boundaries
pnpm check:hook-authoring-boundaries
pnpm check:plugin-capability-publish

包内变更先跑 pnpm --filter <pkg> test / build。发布前再根据影响面扩大到 pnpm check:all;不要用静态搜索代替测试,也不要把环境故障写成代码缺陷。

3. Zhin 当前不变量

  • Plugin Runtime:plugin.ts default-export definePlugin();能力位于命名目录的 index.ts(x)。已移除的 usePlugin/getPlugin 不得回归。
  • Resource:setup 使用 context.resources;能力执行上下文直接 context.use(token)。 generation 状态不能退回模块级 latest-value 单例。
  • Tool:声明字段是 requiresApproval: never | on-risk | once | always;权限、审批与 Shell/文件/网络专用策略是不同层。builtin 安全检查统一进入 packages/im/agent/src/security/policy-facade.ts 的 runToolPolicies。
  • Adapter:优先 defineAdapter({ capabilities, create }) 的 { client, connect, activate?, send } 契约;WS/SSE 生命周期用 createEndpointLifecycle。
  • 出站:Message.$reply / Adapter.sendMessage 必须经过 renderSendMessage → before.sendMessage → AdapterIndex/Endpoint。
  • Console 页面:pages/<name>/index.tsx 默认导出组件并命名导出 meta = definePage(...)。

4. 报告格式

问题按 P0–P3 排序。每项包含:触发条件、实际影响、证据位置、建议修复。无问题时明确说明已覆盖 范围与未验证边界。不要粘贴 token、.env、用户 ID 或完整敏感请求。

© zhinjs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in .github/skills/zhin-audit of zhinjs/zhin.

  • SKILL.md
  • references/architecture-checklist.md
  • references/performance-checklist.md
  • references/security-checklist.md

Open the folder on GitHubat commit f38698f

Compare with similar skills

Zhin Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Zhin Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Zhin Audit this skillzhinjs/zhin136—~596Automated safety check: NotesMIT
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Audit Fullyonatangross/orchestkit292—~3.5kAutomated safety check: NotesMIT
Code Reviewerrevfactory/harness-1001.3k—~1.8kAutomated safety check: PassApache-2.0
Audit Flowzebbern/claude-code-guide4.7k—~4.2kAutomated safety check: PassMIT
Chatting With AWS Devops Agentaws/agent-toolkit-for-aws2.8k—~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Audit Full

    yonatangross/orchestkit

    Single-pass codebase analysis leveraging a 1M-token context window for comprehensive security scanning, architecture review, and dependency auditing.

    292 GitHub stars~3.5k tokensUpdated today
    SecurityAuto-check: notes
  • Code Reviewer

    revfactory/harness-100

    Full pipeline for automated code review. An agent skill from revfactory/harness-100.

    1.3k GitHub stars~1.8k tokensUpdated 6 mo ago
    DevelopmentAuto-check passed
  • Audit Flow

    zebbern/claude-code-guide

    Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.

    4.7k GitHub stars~4.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Chatting With AWS Devops Agent

    aws/agent-toolkit-for-aws

    Official

    Have a fast, conversational analysis with the AWS DevOps Agent.

    2.8k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Solutions Architect

    borghei/Claude-Skills

    Solutions architecture for technical pre-sales. An agent skill from borghei/Claude-Skills.

    891 GitHub stars~4.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed

More from zhinjs/zhin

All 11 skills in this repo
  • Refactor existing Zhin.js plugins into a cleaner standard structure.

    136 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Migrate legacy Zhin.js plugins and projects to the convention-based Plugin Runtime — from usePlugin/getPlugin/addCommand/addMiddleware/addComponent/addTool/addCron/declareConfig/useContext and…

    136 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Implement Zhin.js plugins with Plugin Runtime. An agent skill from zhinjs/zhin.

    136 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • GitHub CLI

    zhinjs/zhin

    使用 gh CLI 处理内置 GitHub Tool 未覆盖的 Issue、PR、Release、Workflow、搜索和 API 操作。

    136 GitHub stars~366 tokensUpdated today
    Auto-check passed
  • Wecom

    zhinjs/zhin

    企业微信平台管理能力。当用户在企业微信中请求用户信息查询、部门架构查询、 发送文本消息时使用。即使用户没有提到企业微信,只要上下文是企业微信/WeCom 场景且涉及用户查询、部门管理或消息发送,就应触发。

    136 GitHub stars~297 tokensUpdated today
    Auto-check passed
  • Checkin

    zhinjs/zhin

    签到积分系统查询能力。当用户想查看自己的积分、签到排行榜、连签天数、 或了解签到奖励时使用。日常签到通过聊天命令触发,此技能提供积分查询的 AI 工具。

    136 GitHub stars~167 tokensUpdated today
    Auto-check passed

Questions about Zhin Audit

What does Zhin Audit do?

Audit Zhin.js changes for security, performance, lifecycle, and architecture regressions. Zhin Audit is an agent skill from zhinjs/zhin.js changes for security, performance, lifecycle, and architecture regressions.

When should I use Zhin Audit?

Zhin Audit fits situations like: security review; performance review; architecture review; change-based code audit.

How do I install Zhin Audit in Claude Code?

Run `npx skills add zhinjs/zhin --skill zhin-audit -a claude-code`. Or copy the skill folder (.github/skills/zhin-audit in zhinjs/zhin) into .claude/skills/zhin-audit in your project. Claude Code loads it when a task matches its description.

How do I install Zhin Audit in Codex?

Run `npx skills add zhinjs/zhin --skill zhin-audit -a codex`. Or copy the skill folder (.github/skills/zhin-audit in zhinjs/zhin) into .agents/skills/zhin-audit in your project. Codex loads it when a task matches its description.

Can I use Zhin Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhinjs/zhin --skill zhin-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/zhin-audit, .gemini/skills/zhin-audit, .github/skills/zhin-audit and .opencode/skills/zhin-audit in your project.

What does Zhin Audit need to run?

Going by SKILL.md and its folder, Zhin Audit needs the command-line tools its instructions call (pnpm).

Does Zhin Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Zhin Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Zhin Audit use?

Zhin Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Zhin Audit use?

About 596 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Zhin Audit?

Skills that share tags, products or a category with Zhin Audit: Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Audit Full (yonatangross/orchestkit, 292 stars), Code Reviewer (revfactory/harness-100, 1.3k stars) and Audit Flow (zebbern/claude-code-guide, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Zhin Audit?

zhinjs (a GitHub organization) maintains it in zhinjs/zhin, which has 136 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 10, 2026.

Source: zhinjs/zhin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.