Home › Tag › Audit

Audit — Claude Code Skills

2344 Claude Code skills tagged Audit. Browse all behavioural skill type-related skills in the open ClaudSkills registry — free to install, one-click via the desktop app.

Showing top 200 of 2344 skills, ranked by quality score.

design-context-extract

Extract design DNA from existing app screenshots or live URLs using Google Stitch. Produces color palettes, typography specs, spacing tokens, and component patterns as design-token

general

gsd:eval-review

Retroactively audit an executed AI phase's evaluation coverage — scores each eval dimension as COVERED/PARTIAL/MISSING and produces an actionable EVAL-REVIEW.md with remediation pl

general

geo-lint

SEO & GEO content linter — validates Markdown/MDX files for AI search visibility using 92 deterministic rules (35 GEO, 32 SEO, 14 content quality, 8 technical, 3 i18n). Runs an aut

growth

inspect

Plan-vs-implementation deep audit using Agent Teams. Parses a plan file (or inline description), extracts requirements, and summons 4 Inspector Ashes to measure implementation comp

general

ops-infra-code

Infrastructure as Code with Terraform/OpenTofu. Trigger to create modules, configure backends, write idiomatic HCL, or audit infrastructure.

engineering

ops-orchestrate

Autonomous multi-project orchestration engine. Audits all registered projects, structures work into dependency-wired tasks, dispatches parallel agents (subagents or Agent Teams), a

general

performance-auditor

Audit de performance du code et de l'application. Analyse Lighthouse, bundle size, Core Web Vitals, et optimisations. Utiliser après l'implémentation, avant une release, ou quand l

general

qa-security

Perform a security audit based on OWASP. Use when the user wants to verify security, look for vulnerabilities, or before a production deployment.

security

seo-programmatic

Plan and audit programmatic SEO pages generated at scale from structured data. Use when designing templates, URL systems, internal linking, quality gates, and index-bloat safeguard

growth

seo-technical

Audit technical SEO across crawlability, indexability, security, URLs, mobile, Core Web Vitals, structured data, JavaScript rendering, and related platform signals like robots.txt

growth

supabase-security

Audit de sécurité complet pour les projets Supabase. Lance un pentest automatisé qui vérifie RLS, buckets, auth, keys exposées, et génère un rapport avec remediation. Utiliser quan

security

test-harness-auditor

Audit a repo's test, lint, type-check, static analysis, build, and debug infrastructure for AI coding agents. Generate scored reports and optimized configs for the lint-on-write ho

engineering

transparency-audit

Prüft die Transparenz-Compliance des Menschlichkeit Österreich Projekts — ZVR-Nummer 1182213083, Vereinsstatuten, Datenschutzerklärung und Impressum auf Vollständigkeit und Korrekt

general

work-quick

Quick workflow for trivial changes (single-file fix, rename, typo). Skip the full Explore-Plan-TDD-Audit cycle. Trigger when the user wants a quick fix, a simple change, or mention

engineering

schema-evolve

This skill should be used when the user asks about 'schema drift', 'schema evolution', 'evolve schema', 'schema sync', 'sync schemas', 'update schema fields', 'schema field frequen

general

30x-seo-content-audit

Content quality audit for both traditional SEO (E-E-A-T) and AI search (citability, structure, authority). Use when user says "content audit", "content quality", "E-E-A-T", "AI cit

growth

30x-seo-hreflang

Hreflang and international SEO audit, validation, and generation. Detects common mistakes, validates language/region codes, and generates correct hreflang implementations. Use when

growth

30x-seo-images

Image optimization analysis for SEO and performance. Checks alt text, file sizes, formats, responsive images, lazy loading, and CLS prevention. Use when user says "image optimizati

growth

30x-seo-local

Local SEO audit and optimization for Google Business Profile, Google Maps, and Gemini Ask Maps. Covers GBP completeness, NAP consistency, review strategy, local schema, competitor

growth

30x-seo-redirects

Redirect chain audit and analysis. Detects redirect loops, long chains, mixed protocols, and orphaned redirects. Use when user says "redirect audit", "301 redirect", "redirect chai

growth

30x-seo-technical

Technical SEO audit across 8 categories: crawlability, indexability, security, URL structure, mobile, Core Web Vitals, structured data, JS rendering. Schema deep validation → seo-s

growth

agentic-actions-auditor

Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attac

security

api-documentation

Use when API code changes (routes, endpoints, schemas). Enforces Swagger/OpenAPI sync. Pauses work if documentation has drifted, triggering documentation-audit skill.

engineering

audit-expert

Expert-level security auditing, compliance, code review, and vulnerability assessment

security

gsd:audit-fix

Autonomous audit-to-fix pipeline — find issues, classify, fix, test, commit

general

gsd:audit-milestone

Audit milestone completion against original intent before archiving

general

audit-plugin

Use when about to install a community tool (MCP, plugin, package) that is not from Anthropic or an explicitly trusted source. Audits against docs/SAFETY_POLICY.md and returns GO /

general

audit-sampling-calculator

Statistical and non-statistical audit sampling skill with sample size determination and evaluation

science

audit-session

Use when you want to audit a session for drift between policy.yaml declarations and the real .claude/logs/ — declares candidate signals across skills_allowed, lifecycle hooks_requi

general

authentication

Authentication and authorization including JWT, OAuth2, OIDC, sessions, RBAC, and security analysis. Activate for login, auth flows, security audits, threat modeling, access contro

security

aws-cost-operations

AWS cost optimization, monitoring, and operational excellence expert. Use when analyzing AWS bills, estimating costs, setting up CloudWatch alarms, querying logs, auditing CloudTra

engineering

brand-audit

Discover and assess existing brand assets for cohesion, gaps, and inconsistencies. Scans codebases, websites, and social presence. Triggers when someone wants to evaluate their cur

growth

burpsuite-project-parser

Searches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings,

security

cfo-reporting

Skill de reporting financier. Flash mensuel M+5, reporting trimestriel YoY, rapport annuel, board pack exécutif, lettres trimestrielles investisseurs, rapport RNS actionnaires, com

general

check-consistency

Audit ytstack internal consistency. Compares README (source of truth) against docs/concept.md, .ytstack/DECISIONS.md, and actual plugin content (skills/, hooks/, agents/, artifacts

general

chome-pattern

Use when a Bash command references ~/.claude/ and fails with "path not found" or "No such file or directory" in multi-account setups. Use when writing rm -rf for team or task direc

general

cloudflare-api

Hit the Cloudflare REST API directly for operations that wrangler and MCP can't handle well. Bulk DNS, custom hostnames, email routing, cache purge, WAF rules, redirect rules, zone

engineering

dev-auth

Modern web auth implementation (better-auth, Lucia, NextAuth/Auth.js, Clerk, Supabase Auth). Trigger when the user wants to add login, signup, sessions, OAuth, magic links, 2FA, or

engineering

devex-review

Live developer experience audit. Uses the browse tool to actually TEST the developer experience: navigates docs, tries the getting started flow, times TTHW, screenshots error messa

general

devops-dx

GitHub/Railway housekeeping for CI env/secret management and DX maintenance. Use when setting or auditing GitHub Actions variables/secrets, syncing Railway env → GitHub, or fixing

engineering

documentation-audit

Use when documentation drift is detected. Comprehensively audits codebase and creates/updates Swagger, features docs, and general documentation to achieve full sync.

engineering

energy-auditor

Process energy audit skill for consumption analysis, benchmarking, and efficiency improvement identification

general

entry-point-analyzer

Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access

security

features-documentation

Use when user-facing features change. Ensures features documentation is updated. Pauses work if documentation has drifted, triggering documentation-audit skill.

general

five-s-auditor

5S workplace organization audit skill with scoring, photo documentation, and sustainability tracking

general

fork-discipline

Audit and enforce the core/client boundary in multi-client projects. Detects where shared platform code is tangled with client-specific code, finds hardcoded client checks, config

engineering

freight-audit-validator

Automated freight bill validation skill with discrepancy detection and payment processing automation

general

gate-evaluator

Avalia quality gates entre fases do SDLC. Verifica artefatos obrigatorios, criterios de qualidade, e aprovacoes necessarias antes de permitir transicao. Use quando: transicao entre

general

gsd-ui-review

Retroactive 6-pillar visual audit of implemented frontend code

general

gsd-validate-phase

Retroactively audit and fill Nyquist validation gaps for a completed phase

general

ha-safety-audit

Audit all live Home Assistant automations against the safety policy. Catches policy drift from automations added via the HA UI that bypassed this plugin's safety gate. Runs weekly

general

hack

Containerized security auditing and ethical hacking tools. All operations run in isolated Docker containers for safety.

security

hipaa-compliance-automator

HIPAA security and privacy compliance automation for ePHI protection, safeguards assessment, and audit preparation

security

insecure-defaults

Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing confi

security

install-almanac-content

Install skills, agents, and teams from agent-almanac into any supported agentic framework using the CLI. Covers framework detection, content search, installation with dependency re

general

paper-audit

Audit paper drafts for logical consistency, compliance, and academic integrity (Triangulation Matrix).

science

pattern-audit

Use when you want to validate that existing `.claude/patterns/` entries remain consistent with the codebase and flag drift.

general

plan-design-review

Designer's eye plan review — interactive, like CEO and Eng review. Rates each design dimension 0-10, explains what would make it a 10, then fixes the plan to get there. Works in pl

general

plan-devex-review

Interactive developer experience plan review. Explores developer personas, benchmarks against competitors, designs magical moments, and traces friction points before scoring. Three

general

pr-triage

PR triage: audit open PRs, deep review selected ones, draft and post review comments. Args: "all" to review all, PR numbers to focus (e.g. "42 57"), "en"/"fr" for language, no arg

general

qa-design

UI/UX design audit and verification of web best practices. Trigger when the user wants to audit the design, verify the UI/UX, or improve the user interface.

general

quality-auditor

Internal quality audit skill with planning, execution, findings documentation, and corrective action tracking

general

roundtable-circle

Use when running /rune:appraise or /rune:audit, when spawning multiple review agents, when TOME aggregation fails or produces malformed output, or when a TeammateIdle hook fires be

general

rune-echoes

Use when agents need to read or write project memory, when persisting learnings from reviews or audits, when managing echo lifecycle (prune, reset), when a user wants to remember s

general

scv-scan

Audits Solidity codebases for smart contract vulnerabilities using a four-phase workflow (cheatsheet loading, codebase sweep, deep validation, reporting) covering 36 vulnerability

security

security-review

Auditoría de seguridad OWASP Top 10. Usar para revisar código en busca de vulnerabilidades, validar autenticación/autorización, analizar input sanitization, detectar SQL injection,

security

semgrep

Run Semgrep static analysis scan on a codebase using parallel subagents. Supports two scan modes — "run all" (full ruleset coverage) and "important only" (high-confidence security

security

seo-internal-links

Analyze internal link structure by crawling a domain. Identifies orphan pages, underlinked pages (fewer than 3 inbound links), and broken internal links. Suggests anchor text for t

growth

seo-llms-txt

Generate, validate, or audit llms.txt files for AI search visibility. Crawls site structure, generates spec-compliant Markdown index for LLMs. Use when user says "llms.txt", "llm t

growth

seo-markdown-audit

Audit markdown files for SEO before publishing. Checks heading structure, meta description, keyword density, content length, link quality, image alt text, and frontmatter completen

growth

seo-migration-check

Validate SEO preservation during site migrations. Checks redirect chains (301 vs 302, hop count), canonical consistency, title/meta preservation, HTTP status codes, content similar

growth

seo-report

Generate and save a complete SEO report to disk. Use when user says "SEO report", "generate report", "monthly report", "weekly report", "audit report", "competitor report", "save r

growth

seo-robots-ai

Audit robots.txt for AI crawler access policies. Checks GPTBot, ClaudeBot, PerplexityBot, Google-Extended, and other AI crawlers. Use when user says "robots AI", "AI crawlers", "bl

growth

seo-site-audit-pro

Flagship comprehensive SEO audit combining Ahrefs and GSC data in sequential waves with checkpoint saves. Use when user says "site audit pro", "full audit", "comprehensive audit",

growth

setup-checklist

Nutze diesen Skill wenn der Nutzer Claude Code einrichten, konfigurieren oder Best Practices umsetzen moechte. Ausloeser: "setup", "einrichten", "bootstrapping", "checkliste", "bes

tools

soc2-compliance-automator

SOC 2 Trust Services Criteria compliance automation for evidence collection, control mapping, and audit preparation

general

supply-chain-risk-auditor

Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagement

security

test-audit

Use when you want to audit test suites for potential issues (declares candidate signals: flaky, orphan, trivial assertions).

engineering

gsd:validate-phase

Retroactively audit and fill Nyquist validation gaps for a completed phase

general

wap-ingestion

Ingest data from S3 into bauplan using the Write-Audit-Publish pattern for safe data loading. Use when loading new data from S3, performing safe data ingestion, or when the user me

general

wooyun-legacy

Provides web vulnerability testing methodology distilled from 88,636 real-world cases from the WooYun vulnerability database (2010-2016). Use when performing penetration testing, s

security

zeroize-audit

Detects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis, and control-flow verificati

general

web-design-guidelines

Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practic

product

claude-md-generator

Gera CLAUDE.md inteligente para projetos consumidores. Consome output do Repo Auditor, faz entrevista guiada com o dev e produz um CLAUDE.md especifico, conciso e acionavel. Use ap

tools

accessibility-review

Run a WCAG 2.1 AA accessibility audit on a design or page. Trigger with "audit accessibility", "check a11y", "is this accessible?", or when reviewing a design for color contrast, k

product

acreadiness-assess

Run the AgentRC readiness assessment on the current repository and produce a static HTML dashboard at reports/index.html. Wraps `npx github:microsoft/agentrc readiness` and hands o

tools

ag-9-auditar

Auditoria completa de software (wrapper FORTRESS). Roda MERIDIAN + SENTINEL + ARCHITECT + CONDUCTOR + LIGHTHOUSE em sequencia. Fortress Score = laudo completo.

tools

ag-publicar-deploy

Deploy para Vercel ou plataforma detectada, com smoke tests. Use quando codigo esta auditado, testado e versionado.

general

ag-referencia-mock-first

Metodologia Mock-First para frontends de integracao. 6 fases (mock data → UI → auditoria UX → preparacao integracao → validacao → execucao). Carregado on-demand como referencia.

general

ag-verificar-seguranca

Auditoria de seguranca, qualidade e conformidade. OWASP Top 10, secrets scan, dependency audit. Use antes de deploy.

security

ai-gateway-guardrails

Enforce Input/Output Guardrails at the LLM Gateway layer — PII redaction, Prompt Injection defense, Jailbreak detection, Toxicity filter, and Tool Allow-list. Integrates Bedrock Gu

security

aif-dockerize

Analyze project and generate Docker configuration: Dockerfile (multi-stage dev/prod), compose.yml, compose.override.yml (dev), compose.production.yml (hardened), and .dockerignore.

engineering

aif-security-checklist

Security audit checklist based on OWASP Top 10 and best practices. Covers authentication, injection, XSS, CSRF, secrets management, and more. Use when reviewing security, before de

security

analyze-spec

Analyze an existing spec for inconsistencies, missing information, ambiguities, and structure issues. Use when user says "analyze spec", "review spec", "spec quality check", "valid

general

arch-check

Review code or a module implementation against PMTL_VN architecture contracts. Flags ownership violations, missing audit/rate-limit, wrong async boundaries, security gaps, and perm

security

audit

Execute project-specific verification rules. Validates business logic, architecture patterns, and naming conventions that linters cannot catch. Auto-suggests bootstrap if no rules

tools

audit-and-fix

Composite: security audit -> production upgrade -> self-evaluation. Use when user says 'audit', 'check the codebase', 'find and fix issues', or 'is this production-ready'.

security

audit-auth

Audit de sécurité complet de l'authentification d'une application (backend + frontend + infra)

general

audit-env-variables

Analyze environment variables in JavaScript/TypeScript projects. Identifies unused variables, infers permission scopes, detects specific services (Stripe, AWS, Supabase), and docum

security

audit-full

Single-pass codebase analysis leveraging Opus 4.6 1M context for comprehensive security scanning, architecture review, and dependency auditing. Loads entire codebases for cross-fil

security

audit-permissions

Audits existing table permissions on a Power Pages site by analyzing them against site code and Dataverse metadata. Generates an HTML audit report with findings grouped by severity

security

audit-skill

Comprehensive audit capabilities for security, code quality, module structure, compliance, and performance analysis. Use this skill when performing security audits, code reviews, v

security

audit-tools

Audit tools/ directory for structure compliance, test coverage, CLI quality, and documentation completeness. Use when checking tool health, validating tools, reviewing tool quality

general

audit-trail

모든 사용자 발화·agent 행동·phase 전환·gate 판정을 ISO 8601 타임스탬프와 함께 감사 로그에 기록한다. 사용자 입력은 축약·요약 없이 verbatim blockquote로 보존하며, SOC2·ISMS-P 감사 요구사항에 매핑되는 보존 정책(30·90·365일)을 프로젝트별로 선택한다. 모든 AIDLC

security

auditing-milestones

Use this skill to verify milestone achievement against its definition of done, checking requirements coverage, cross-phase integration, and end-to-end flows. Triggers include "audi

security

auditing-seo

Analyzes a single web page URL for SEO quality, identifying issues with title tags, meta descriptions, heading structure, and content. Use when the user says "audit this page", "ch

security

auditor

Use when: auditing a website URL or codebase, checking site health score, SEO audit, performance audit, security scan, accessibility audit, mobile audit, broken links, meta tags, s

security

kairos:auditoria

Consulta a trilha de auditoria de uma feature. Mostra rastreabilidade completa de decisões, modelos, assertions e commits. Use quando o usuário disser "kairos auditoria", "trilha d

general

auth-audit

Audit authentication and authorization patterns. Checks JWT, sessions, OAuth2, PKCE implementations for security best practices and common vulnerabilities.

security

aws-specialist

Deep-dive AWS architecture review, debugging, and service design. Use for structured investigations of AWS-specific issues, cost or IAM audits, and multi-service design reviews. Tr

engineering

azure-specialist

Deep-dive Azure architecture review, debugging, and service design. Use for structured investigations of Azure-specific issues, identity or cost audits, and multi-service design re

engineering

billing

Use when: billing audit, subscription lifecycle review, Stripe/Paddle integration check, webhook security, payment form CSRF, pricing centralization, webhook idempotency, billing b

security

bitcoin

Complete Bitcoin payment lifecycle. Audits current state, fixes all issues, and verifies payment flows work end-to-end. Every run does all of this.

general

brand-review

Review content against your brand voice, style guide, and messaging pillars, flagging deviations by severity with specific before/after fixes. Use when checking a draft before it s

growth

broken-link-checker

Scans a website to find broken links (404s, 500s). Crawls internal pages, identifies broken outbound links, and reports source pages for easy fixing. Use this when the user asks to

general

cf-audit

Audit content library for freshness decay, coverage gaps, and optimization opportunities.

general

check

Detect breaking changes in a Go project's public API. Use when: checking API compatibility before release, reviewing PRs for breaking changes, comparing two git refs or tags, or au

general

check-forms

Analyze and validate forms on web pages. Use when users ask to check form accessibility, verify form labels, audit input fields, check form validation, or analyze form UX. Detects

product

check-images

Analyze and validate images on web pages. Use when users ask to check image alt tags, verify image accessibility, find missing alt attributes, audit image SEO, or check image optim

product

check-meta

Analyze and validate meta tags on web pages. Use when users ask to check meta tags, verify SEO tags, audit page titles, check Open Graph tags, verify canonical URLs, or analyze soc

general

check-mr-review

ALWAYS use when reviewing GitLab MR diff and posting review findings as MR comments via glab CLI. ALWAYS use when user mentions MR 리뷰, MR review, MR 검토, MR 코드 리뷰, MR 안전성 리뷰, MR 코멘트

science

citation-audit

Zero-context verification that every bibliographic entry in the paper is real, correctly attributed, and used in a context the cited paper actually supports. Uses a fresh cross-mod

general

claude-standards

Audit Claude Code assets — skills, commands, subagents, hooks, and MCP servers — against best practices and optionally apply conservative conformance changes. Use when reviewing ov

general

claudit

Audit and optimize Claude Code configuration with dynamic best-practice research

science

code-audit

Audits the entire codebase for bugs, security vulnerabilities, CLAUDE.md violations, dead code, duplicate code, and test quality issues. Use when asked to "audit code", "find bugs"

security

competitor-intelligence

Competitor analysis, competitor SEO, who ranks for, competitive audit, compare my SEO, competitor gap. Covers content gaps, technical SEO comparison (observable signals), SERP feat

general

complete-implementation

\"Holistic completion workflow after a feature's tasks are marked COMPLETE: code review, feature verification, integration check, documentation drift audit/update, and context refi

general

compliance

Use when: compliance audit, GDPR/CCPA/SOC2/ISO27001/HIPAA/PCI-DSS review, regulatory requirements, data privacy audit, legal compliance check, India DPDP/M.A.N.A.V., EU AI Act, NIS

engineering

consulting-client-presentation

AUTO-TRIGGER: Apply this skill when the user is preparing to present findings, recommendations, or results to a consulting client. Trigger phrases include: "presenting to my client

general

conventions-improver

Audit and improve project conventions files (AGENTS.md, CLAUDE.md, GEMINI.md). Scans for all conventions files, evaluates quality against a scoring rubric, outputs a quality report

general

crossplane-specialist

Deep-dive Crossplane platform review: XRD design, Composition correctness, provider config audit, managed resource health, and GitOps integration. Use for structured investigations

engineering

cve-scan

Scan project dependencies for known CVEs using native audit tools (npm, pip, composer, cargo, go, bundler, dart)

security

daily-integration-audit

Run one integration audit per invocation, rotating through docs/features/ least-recently-audited-first. Audits the feature's code + doc accuracy/clarity/organization, then triages

general

dead-features

Feature audit: finds implemented but user-unreachable functionality in any project. Discovers tech stack and architecture automatically, then checks connectivity between layers (en

engineering

dep-audit

Audit npm dependencies across all package.json files — reports outdated, security issues, and unused packages

security

accessibility-review

Run a WCAG 2.1 AA accessibility audit on a design or page. Trigger with "audit accessibility", "check a11y", "is this accessible?", or when reviewing a design for color contrast, k

product

design-audit

Run technical quality checks across accessibility, performance, responsive design, theming, and anti-patterns. Generate a scored report with P0-P3 severity ratings. Report-only — d

product

design-system

Audit, document, or extend your design system. Use when checking for naming inconsistencies or hardcoded values across components, writing documentation for a component's variants,

product

design-polish

Final quality pass fixing alignment, spacing, consistency, interaction states, and micro-details before shipping. Executes changes (unlike design-audit and design-critique which ar

growth

design-system

Audit, document, or extend your design system. Use when checking for naming inconsistencies or hardcoded values across components, writing documentation for a component's variants,

product

do-integration-audit

Audit how well a named feature is integrated into its host project. Checks for orphan code, dead wiring, missing tests, undocumented entry points, config gaps, and partial connecti

general

do-investigation-issue

Use when posting a GitHub investigation issue for an unverified finding, potential gap, or anomaly that needs root-cause analysis before any action is taken. Also use when an audit

science

do-skills-audit

Audit all Claude Code skills for compliance with canonical template standards. Use when checking skill quality, validating skill structure, linting SKILL.md files, verifying frontm

general

evolve-loop

Use when the user invokes /evolve-loop or asks to run autonomous improvement cycles, self-evolving development, compound discovery, or multi-cycle code improvement with research, b

science

experiment-audit

Audit experiment integrity before claiming results. Uses cross-model review (GPT-5.4) to check for fake ground truth, score normalization fraud, phantom results, and insufficient s

science

extend-deck

Hunt for one previously-undocumented defect, derivation gap, doc drift, missing test or wrong concept. Also architectural ugliness, code smells and inconsistencies. Files via Skill

product

firebase-apk-scanner

Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. Use when analyzing APK fil

engineering

firebase-apk-scanner

Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. Use when analyzing APK fil

engineering

fix-review

Verifies that git commits address security audit findings without introducing bugs. This skill should be used when the user asks to "verify these commits fix the audit findings", "

security

fix-seo

Fix my SEO, fix this SEO issue, fix missing meta, fix broken links, fix page speed code-level risk, fix schema — user has a specific SEO problem to remediate. Routes to specialized

growth

forensify

Cross-agent self-inspection of your AI-agent stack. Audits skills, MCP servers, hooks, plugins, commands, credentials, and memory files across Claude Code, Codex, OpenClaw, and Nan

security

full-seo-audit

Audit my SEO, run an SEO audit, SEO score, SEO health check, full SEO analysis — comprehensive multi-category request. Performs a scoped 6-phase audit over the user's codebase plus

growth

full-suite

Run all 36 agents across 9 categories in 4 phases — complete codebase audit with orchestration, Observer Agent, and token management.

general

gate-audit

Mine Claude Code session logs for bash commands getting incorrect permission decisions. Find read-only commands that return "ask" when they should be "allow", unknown commands that

general

gcp-specialist

Deep-dive Google Cloud architecture review, debugging, and service design. Use for structured investigations of GCP-specific issues, IAM or cost audits, and multi-service design re

engineering

geo-optimizer

Generative Engine Optimization (GEO) — make content rank in AI search answers from ChatGPT, Claude, Perplexity, Gemini, and Google AI Overviews. Audits existing content, rewrites f

growth

github-ruleset-architecture

Design and audit repository and organization ruleset architecture, including layering, bypass controls, enforcement modes, and merge queue compatibility.

engineering

hipaa-validate

Validate code against HIPAA policy: PHI exposure, missing audit logging, unencrypted transmission/storage, access control gaps, temp file exposure, and missing BAA references

security

hone

Audit and improve an existing Quickstop plugin's quality against Claude Code plugin spec

general

hubspot-audit

AUTO-TRIGGER: Apply this skill when the user asks about auditing, cleaning up, reviewing, or improving their HubSpot instance. Trigger phrases include: "audit our HubSpot," "clean

sales

integration

Manage codemap integration — 'check' audits installation health (scan-query reachable, index fresh, injection present), 'init' onboards codemap by discovering skills/agents, recomm

general

journal-entry

Prepare journal entries with proper debits, credits, and supporting detail. Use when booking month-end accruals (AP, payroll, prepaid), recording depreciation or amortization, post

general

kata

Orchestrate an improvement cycle: diagnose, select methodology, execute, record, persist. The meta-pattern that connects all skills into a coherent workflow. USE WHEN: improve, aud

general

kiroku

Evidence trail management. Start sessions, record decisions during work, close sessions, index decisions, validate trail integrity. The implementation of Observable Autonomy (Princ

general

knowledge

Retrieve claudit knowledge cache domains (ecosystem, core-config, optimization). Checks freshness and auto-refreshes stale domains.

general

knowledge-gaps

This skill should be used when the user asks about 'knowledge gaps', 'package coverage', 'which packages need notes', 'undocumented dependencies', 'dependency audit', 'missing docu

tools

google-ads-landing

Score and diagnose Google Ads landing pages. Use when asked to audit a landing page, check landing page quality, diagnose high-CTR but low-conversion-rate ad groups, improve Qualit

ads

vgv-license-compliance

Audits package dependency licenses using the Very Good CLI packages_check_licenses MCP tool. Flags non-compliant or unknown licenses and produces a compliance summary.

general

lightning

Complete Lightning Network lifecycle. Audits channels, routing, invoices. Plans capacity, executes rebalancing, verifies payments. Every run does all.

general

marketing

Use when: SEO audit, reviewing landing pages, writing marketing copy, content strategy, social media content, CRO/conversion optimization, growth hacking, programmatic SEO, analyti

growth

brand-review

Review content against your brand voice, style guide, and messaging pillars, flagging deviations by severity with specific before/after fixes. Use when checking a draft before it s

growth

marketing-seo-audit

Run a comprehensive SEO audit — keyword research, on-page analysis, content gaps, technical checks, and competitor comparison

growth

martech-contract-auditor

AUTO-TRIGGER: Apply this skill when the user mentions a vendor renewal, SaaS contract, MarTech negotiation, or any conversation about renewing, renegotiating, or evaluating a marke

sales

mcp-eval

Evaluate the attached MCP set by running agent-authored scenarios and producing an adversarial friction report. Claude exercises each MCP live, logs every tool call with justificat

content

nextjs-seo

Next.js SEO optimization guide. Use when building Next.js apps, optimizing for search engines, fixing Google indexing issues, implementing metadata, sitemaps, robots.txt, JSON-LD,

engineering

ng:seo

SEO audit toolkit: full site audit, single page analysis, content quality, technical SEO, image optimization, pre-upload content audit, SEO content rewrite. Use for SEO check, audi

general

ops-process-doc

Documentar um processo de negócio — fluxogramas, RACI e SOPs. Use quando formalizar um processo que vive na cabeça de alguém, construir RACI para deixar claro quem é dono de quê, e

general

overleaf-sync

Two-way sync between a local paper directory and an Overleaf project via the Overleaf Git bridge (Premium feature). Lets you keep ARIS audit/edit workflows on the local copy while

general

paper-claim-audit

Zero-context verification that every number, comparison, and scope claim in the paper matches raw result files. Uses a fresh cross-model reviewer with NO prior context to prevent c

science

partner-marketing-infrastructure

AUTO-TRIGGER: Apply this skill when the user wants to build, audit, or improve a partner marketing program. Trigger phrases include: "partner program," "channel partners," "reselle

growth

paseo-epic

Heavy-ceremony orchestration for big work — research, planning, adversarial review, phased implementation, audit, delivery. Use when the user says "epic", "long task", "build this

growth

pipeline-review

Analyze pipeline health — prioritize deals, flag risks, get a weekly action plan. Use when running a weekly pipeline review, deciding which deals to focus on this week, spotting st

general

plugin-status

Audit the current state of a WordPress plugin against its task list. Reads the tasks file and inspects the actual codebase to report what's done, what's incomplete, and what's miss

general

process-doc

Document a business process — flowcharts, RACI, and SOPs. Use when formalizing a process that lives in someone's head, building a RACI to clarify who owns what, writing an SOP for

general

product

Use when: product strategy review, feature prioritization, product-market fit analysis, roadmap planning, product design critique, user story review, MVP scoping. Triggers: 'review

product

product-analysis

Multi-path parallel product analysis with cross-model test-time compute scaling. Spawns parallel agents (Claude Code agent teams + Codex CLI) to explore product from multiple persp

product

project-health-check

Comprehensive health check of a Next.js/Payload CMS project. Use when user asks to "check the project", "audit the codebase", "what's the state of the project", "project health", o

engineering

proof-checker

Rigorous mathematical proof verification and fixing workflow. Reads a LaTeX proof, identifies gaps via cross-model review (Codex GPT-5.4 xhigh), fixes each gap with full derivation

general

prune-memory

Audit project memory (.agents/MEMORY.md and ~/.claude/.../memory/MEMORY.md) against current code and remove stale claims to prevent bad signals in future sessions

general

pulumi-specialist

Deep-dive Pulumi stack review, component design, Automation API audit, and secrets management. Use for structured investigations of Pulumi stack drift, ComponentResource coupling,

engineering

rad-code-review

Review my code, code review, is this ready to ship, check for bugs, security audit, review this PR, pre-merge check, is this safe to deploy, check code quality. Blame-aware diff sc

engineering

Rails Upgrade Guide (Internal Reference)

Internal reference skill loaded by audit and fix skills for version-specific Rails breaking changes and fix patterns. Not a user-facing skill — do not activate this directly. Only

engineering

react-effects-audit

Audit React components for unnecessary useEffect patterns. Detects 9 anti-patterns from "You Might Not Need an Effect" and proposes fixes with severity levels.

engineering

readme-audit

Audit a README against its actual project state. Decomposes README into atomic claims, then verifies each against repo files, configs, code, git history, and live URLs. Launches 17

general

repo-forensics

Security forensics for git repos, AI skills, and MCP servers. Audits dependencies, detects prompt injection, credential theft, runtime dynamism, manifest drift, known CVEs, CISA KE

security

repo-profile-governance

Audit and harden repository profile, community health, discoverability metadata, and contribution surfaces across repos using bounded, evidence-based checks.

general

resubmit-pipeline

Workflow 5: orchestrate a text-only resubmit of a polished paper to a different venue under hard constraints (no new experiments, no bib edits, no framework changes, never overwrit

science

review-architecture

Reviews an architecture (file, repo, design doc, or pasted text) against scalability, security, reliability, compliance, and anti-pattern checklists plus fitness functions. Use whe

engineering

review-claude-md

Audit and fix CLAUDE.md files using a tiered binary checklist based on official Anthropic best practices and community guidelines. Use when the user asks to "review CLAUDE.md", "au

general

review-crate

Deep audit of a Rust crate for vulnerabilities, bugs, unfinished work, inconsistencies, duplicate code, and oversights. Works on the current crate or a specified path.

security