audit-skills

audit-skills is a skill for Claude Code from mostafa-drz/claude-skills. It costs 58 tokens per session (2,279 once invoked), scanned A, original, MIT.

A review tool for personal Claude skills that checks their structure, instructions, tool permissions, and consistency against recommended standards.

In plain words
What is it for?
It can inspect all skills or one named skill, show detailed results, and optionally fix reported issues.
Why use it?
It helps identify outdated, contradictory, or incomplete skill definitions before they cause unreliable behavior.

Skill for Claude Code

Written for Claude Code: allowed-tools in frontmatter. Also seen: reads .claude/ paths; names the AskUserQuestion tool; positional $N argument.

Good fit It can inspect all skills or one named skill, show detailed results, and optionally fix reported issues.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/mostafa-drz/claude-skills/audit-skills
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add mostafa-drz/claude-skills --skill audit-skills
Clone the repo
git clone --depth 1 https://github.com/mostafa-drz/claude-skills

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for audit-skills

README.md
[![agentmods](https://agentmods.dev/badge/skills/mostafa-drz/claude-skills/audit-skills/github.svg)](https://agentmods.dev/skills/mostafa-drz/claude-skills/audit-skills)
Your own site
<a href="https://agentmods.dev/skills/mostafa-drz/claude-skills/audit-skills"><img src="https://agentmods.dev/badge/skills/mostafa-drz/claude-skills/audit-skills/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for audit-skills

Your own site · 80×15
<a href="https://agentmods.dev/skills/mostafa-drz/claude-skills/audit-skills"><img src="https://agentmods.dev/badge/skills/mostafa-drz/claude-skills/audit-skills.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 58 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,279 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00058 $0.02279
Opus 5 $0.00029 $0.01140
Sonnet 5 $0.00012 $0.00456
Haiku 4.5 $0.00006 $0.00228

Measured today against content hash d914b20a9050, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

audit-skills scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

code/audit-skills/SKILL.md · 268 lines

How it starts

The opening of the file, as written. The whole thing — 268 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Audit Skills

Audit personal Claude skills for consistency, best practices, and up-to-date standards.

Command routing

Check $ARGUMENTS:

  • help → display help then stop
  • --fix [skill-name] → auto-fix issues (see Fix mode)
  • --verbose [skill-name] → show full details for every check (not just failures)
  • <skill-name> → audit a single skill
  • empty → audit all skills

Help

Doctor — Audit personal Claude skills for health and consistency

Usage:
  /audit-skills                      Audit all personal skills
  /audit-skills <skill-name>         Audit a single skill
  /audit-skills --fix                Auto-fix all skills
  /audit-skills --fix <skill-name>   Auto-fix a specific skill
  /audit-skills --verbose            Full detail for every check
  /audit-skills help                 This help

Checks performed:
  Manifest    Does the skill follow SKILLS_GUIDE.md conventions?
  Frontmatter Are all required/recommended fields present and correct?
  Content     Is the skill under 500 lines? Are references bundled?
  Tools       Are allowed-tools minimal? Any duplicates? Any contradictions?
  UX          Does it have help/config/reset? First-time detection? Memory?
  Docs        Is the description third-person with trigger keywords?
  Security    Does disable-model-invocation match the side-effect profile?
  Upstream    Does it follow latest official Claude skills documentation?

Output:
  [PASS] Check passed
  [WARN] Non-critical suggestion
  [FAIL] Violates manifest or best practice
  [INFO] Informational note

Example output:
  /slack-to-ticket
    [PASS] Third-person description
    [PASS] disable-model-invocation: true (has side effects)
    [WARN] SKILL.md is 120 lines — fine, but has inline examples that could be bundled
    [FAIL] Missing help subcommand
    [PASS] Preferences memory pattern present

Step 1: Load references

Local manifest

Read ~/.claude/skills/SKILLS_GUIDE.md — this is the source of truth for local conventions.

Read the full file on GitHub · 268 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today Changed · +7 lines · +58 tokens per session d914b20a9050
  2. 11d ago First seen · 261 lines · 0 tokens per session scan A 9711d7fbcef4

Subscribe to this mod's changes

audit-skills is a skill published in the GitHub repository mostafa-drz/claude-skills (4 stars, last pushed today), licensed MIT. It adds 58 tokens to every session and 2,279 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

codex-symphony

Install and operate a portable OpenAI Symphony + Linear orchestration setup in any Git repository. Use when the user wants a one-command local Symphony runner, a reusable WORKFLOW template, background launch scripts, or a Codex wrapper that restarts Symphony automatically when reopening the CLI.

citedy/skills · 61 tokens

skill-builder

Automatically detect source types and build AI skills using Skill Seekers. Use when the user wants to create skills from documentation, repos, PDFs, videos, or other knowledge sources.

yusufkaraaslan/Skill_Seekers · 38 tokens

ensemble-solving

Generate multiple diverse solutions in parallel and select the best. Use for architecture decisions, code generation with multiple valid approaches, or creative tasks where exploring alternatives improves quality.

mhattingpete/claude-skills-marketplace · 35 tokens

code-execution

Execute Python code locally with marketplace API access for 90%+ token savings on bulk operations. Activates when user requests bulk operations (10+ files), complex multi-step workflows, iterative processing, or mentions efficiency/performance.

mhattingpete/claude-skills-marketplace · 49 tokens

code-refactor

Perform bulk code refactoring operations like renaming variables/functions across files, replacing patterns, and updating API calls. Use when users request renaming identifiers, replacing deprecated code patterns, updating method calls, or making consistent changes across multiple locations.

mhattingpete/claude-skills-marketplace · 51 tokens

feature-planning

Break down feature requests into detailed, implementable plans with clear tasks. Use when user requests a new feature, enhancement, or complex change.

mhattingpete/claude-skills-marketplace · 32 tokens