magento-audit

magento-audit is a skill for Claude Code from staksoft/magento-claude-skills. It costs 167 tokens per session (1,326 once invoked), scanned A, original, MIT.

A procedure for investigating slow Magento 2, Mage-OS, and Adobe Commerce storefronts. It examines caching, server response time, page size, background jobs, and user-facing performance measures such as Core Web Vitals.

In plain words
What is it for?
Use it to audit a live store, a codebase, or both, and produce a severity-ranked report with evidence and exact fixes.
Why use it?
It helps find the specific cause of slow pages, especially when full-page caching is not working, instead of relying on general performance suggestions.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the magento-skills plugin — 3 skills shipped together

Good fit Use it to audit a live store, a codebase, or both, and produce a severity-ranked report with evidence and exact fixes.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/staksoft/magento-claude-skills/magento-audit
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add staksoft/magento-claude-skills --skill magento-audit
Clone the repo
git clone --depth 1 https://github.com/staksoft/magento-claude-skills

Made for: Claude Code.

Or install magento-skills, the plugin that ships this one along with the rest of its 3 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for magento-audit

README.md
[![agentmods](https://agentmods.dev/badge/skills/staksoft/magento-claude-skills/magento-audit/github.svg)](https://agentmods.dev/skills/staksoft/magento-claude-skills/magento-audit)
Your own site
<a href="https://agentmods.dev/skills/staksoft/magento-claude-skills/magento-audit"><img src="https://agentmods.dev/badge/skills/staksoft/magento-claude-skills/magento-audit/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for magento-audit

Your own site · 80×15
<a href="https://agentmods.dev/skills/staksoft/magento-claude-skills/magento-audit"><img src="https://agentmods.dev/badge/skills/staksoft/magento-claude-skills/magento-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 167 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,326 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00167 $0.01326
Opus 5 $0.00084 $0.00663
Sonnet 5 $0.00033 $0.00265
Haiku 4.5 $0.00017 $0.00133

Measured 12d ago against content hash da60d0a65848, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

magento-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

The scan reads SKILL.md. This mod also ships 2 executable files (scripts/check-headers.py, scripts/scan-layout.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/magento-audit/SKILL.md · 110 lines

How it starts

The opening of the file, as written. The whole thing — 110 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Magento 2 / Mage-OS Storefront Performance Audit

Audit procedure for Magento storefront performance. The output is always a severity-ranked markdown report (references/scoring.md) where every finding carries verbatim evidence and an exact fix — never a list of generic tips.

The cardinal rule: audit caching first. Until full-page cache works, every other number (TTFB, CWV, server load) is measuring the wrong thing. Most "Magento is slow" reports are FPC failures with a different hat on.

Pick the mode

You have Mode Tools
A store URL URL mode scripts/check-headers.py, browser/Lighthouse if available
The codebase (and ideally a running install) Codebase mode scripts/scan-layout.py, env.php, bin/magento CLI
Both Combined — do URL mode first, use codebase mode to explain what it found both

Ask for the missing half only if the findings demand it (e.g. URL mode shows MISSes → request codebase access to find the killer); otherwise audit what you have and record the gap in the report's "Not audited" section.

URL mode

  1. Collect 3–5 public URLs: homepage, a category page, a product page, a CMS page. Never test cart/checkout/account pages for cache hits — they are uncacheable by design.

  2. Run the header check (stdlib-only Python, two requests per URL so the second is warm):

    python scripts/check-headers.py https://store.example/ https://store.example/some-category \
        [--insecure]   # for local/dev self-signed certs
    

    It measures TTFB cold/warm, payload size, compression, and parses X-Magento-Cache-Debug / Age / Varnish headers into pre-classified findings.

  3. Interpret with references/fpc-audit.md — particularly the header table and what a warm MISS means.

  4. Frontend layer: read references/frontend-perf.md; run Lighthouse/PageSpeed if available, otherwise estimate from the fetched HTML (script/CSS counts, LCP image preload, lazy-loading mistakes, third-party tags).

Read the full file on GitHub · 110 lines

Files

What ships with it

7 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 110 lines · 167 tokens per session scan A da60d0a65848

Subscribe to this mod's changes

magento-audit is a skill published in the GitHub repository staksoft/magento-claude-skills (6 stars, last pushed 2mo ago), licensed MIT. It adds 167 tokens to every session and 1,326 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

paid-ads-amazon

Plan and review Amazon Ads with margin-aware ACoS, product, and search-term guardrails. Use for Amazon advertising, Sponsored Products, Sponsored Brands, Sponsored Display, ASIN targeting, Amazon ACoS, or Amazon Ads performance exports.

nowork-studio/notfair-plugin · 55 tokens

beat-sync-reel

Generates Instagram Reels where product image cuts are synced to audio beats. Accepts audio as a local file, URL, or search query. Uses librosa for beat detection, FFmpeg Ken Burns for scene animation, and Pillow for text overlays. No AI video generation — fully free, fast, and scalable.

gooseworks-ai/goose-skills · 68 tokens

ebay-search

Search eBay listings - find items, auctions, deals, and compare prices.

gooseworks-ai/goose-skills · 19 tokens

einbeziehung-online-clickwrap-browsewrap

Für Einbeziehung Online Clickwrap Browsewrap: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt.

Klotzkette/claude-fuer-deutsches-recht · 42 tokens

kurzfristige-preiserhoehung-lieferfrist

Für Kurzfristige Preiserhöhung 309: prüft Frist, Form, Zuständigkeit und Eilbedarf; Ergebnis: Fristen- und Risikoampel. Fachgebiet: AGB-Recht-Prüfer. Route: kurzfristige-preiserhoehung-lieferfrist.

Klotzkette/claude-fuer-deutsches-recht · 72 tokens

plattform-online-gate-rollout-rangfolge

Für Plattform und Online Checkout: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: plattform-online-gate-rollout-rangfolge.

Klotzkette/claude-fuer-deutsches-recht · 62 tokens