code audit skills

213 tagged code audit, measured the same way as everything else here.

Browse within: cwe 57python 57appsec 40ai-coding-agent 39ai-coding-agents 39code-quality 22ai-coding-assistant 20react-native 6

rn-metro-console

25

AndrewDongminYoo/rn-agents-kit

Skill Claude CodeCodex

Use when you need to read a running React Native app's console output — confirm a log fired, watch console.warn/error, or verify runtime behavior — without opening the DevTools GUI. Reads logs from Metro's CDP endpoint; bounded by default. Read-only with respect to project source. Runs the bundled rn-console.mjs…

2 12d ago A 72 tokens original Apache-2.0

rn-newarch-audit

26

AndrewDongminYoo/rn-agents-kit

Skill Claude CodeCodex

Use when planning a React Native upgrade or asking "is my app ready for the New Architecture?" — audits which dependencies and app-local native modules block enabling the New Architecture. Read-only; reports and interprets, changes nothing. Wraps the rn-newarch-ready CLI.

2 12d ago A 60 tokens original Apache-2.0

wgo

27

wgo-audit/code

Skill Claude CodeCodex

Evidence-led startup and SMB transition-control audit workflow for products, repositories, teams, vendors, continuity, value, cost, security, delivery, and architecture. Use when the active agent should onboard or resume a Whats.Going.On. audit, run one approved audit reviewer, report status, synthesize reports, draft…

2 9d ago A 80 tokens original MIT

arena

28

serdardb/multi-agent

Skill Claude CodeCodex

Multi-model review arena — several AI models audit the code, cross-critique each other until they converge, then a judge verifies against real code and a scoreboard names a winner. Runs as a Workflow (visible in /workflows).

1 1mo ago A 49 tokens original MIT

multi-agent

29

serdardb/multi-agent

Skill Claude CodeCodex

Run one of THIS project's agents on ANOTHER AI model (codex / grok) as a LIVE, STEERABLE background agent — watch it work underneath, and type to it while it runs to steer the running turn. Scope from plain words (git diff / method / path), no flags.

1 1mo ago A 64 tokens original MIT

audit-agent-code

30

William2333ZZ/trustshell

Skill Claude CodeCodex

Security-audit an AI agent's OWN framework code for classic appsec vulnerabilities the LLM can't defend — path traversal, command injection, SSRF, fail-open security controls, missing/late auth, unsafe deserialization — especially at the untrusted-input boundaries (channels, file/media handlers, config & skill…

1 1mo ago A 102 tokens original MIT

craft-fix

31

gul-labs/craftsman-marketplace

Skill Claude CodeCodex

The Craftsman standard for driving fixes against an existing craft-audit workspace — "fix the findings", "fix SEC-003", "work through the audit", "start the climb". An ACTION skill, not a domain: it picks findings off the master tracker's climb sequence, re-verifies each is still real, gets the user's approval, and…

1 3d ago A 182 tokens original MIT

craft-lint

32

gul-labs/craftsman-marketplace

Skill Claude CodeCodex

The Craftsman standard for linting and static quality gates — ESLint version policy, resolved-rule extraction, typed TypeScript linting, React/Next/a11y/security rule hardening, zero-warning CI gates, pre-commit alignment, and migration from weak default configs to an enterprise-grade lint setup. Use this WHENEVER the…

1 3d ago A 147 tokens original MIT

tax

33

gul-labs/craftsman-marketplace

Skill Claude CodeCodex

Expert US tax, accounting, entity, and state-filing guidance for individuals, partnerships, S corporations, C corporations, disregarded LLCs, and multi-entity portfolios. Use for estimates, return workpapers, basis and carryforwards, tax planning and deductions (including accountable plans, home office, QBI, QSBS…

1 3d ago A 146 tokens original MIT

audit

34

rodlunt/engineering-audit

Skill Claude CodeCodex

Use when the user asks to audit this repo, run the engineering audit, run a practice audit, or check the codebase against the engineering-audit rules pack. Drives the engineering-audit MCP server's tools through a full audit run and produces a self-contained HTML report.

1 3d ago A 57 tokens original Apache-2.0

engineering-grill

35

rodlunt/engineering-audit

Skill Claude CodeCodex

Run a project-start interview against the live engineering rules pack, decide which engineering domains apply, put the highest-consequence questions first, and record terminology, decisions, risks, and build gates. Use when a user explicitly asks for an Engineering Grill before building or substantially redesigning a…

1 3d ago A 78 tokens original Apache-2.0

priyanshuchawda/codeaudit

Skill Claude CodeCodex

Use when initializing, auditing, refactoring, securing, documenting, testing, planning, or preparing PR workflows for a software repository with CodeAudit project detection and skill routing.

1 4mo ago A 40 tokens original MIT

codeaudit

37

priyanshuchawda/codeaudit

Skill Claude CodeCodex

Use when an AI coding agent needs to inspect a repository, choose the right workflow, audit code/docs/tests/skills, improve Python or TypeScript projects, plan issues or PRs, or use the CodeAudit MCP server.

1 4mo ago A 48 tokens original MIT

priyanshuchawda/codeaudit

Skill Claude CodeCodex

Use when reviewing, creating, or improving Python services, CLIs, libraries, FastAPI, Django, Flask, pytest, uv, pyproject, typing, Pydantic, SQLAlchemy, async code, packaging, or deployment.

1 4mo ago A 52 tokens original MIT

mcporter

39

nobodyohm-web/Thot

Skill Claude CodeCodex

List, auth, and call MCP servers/tools from the terminal.

0 7d ago A 16 tokens copy · 83% MIT

accelerate

40

nobodyohm-web/Thot

Skill Claude CodeCodex

Run PyTorch training across GPUs with minimal changes.

0 7d ago A 13 tokens copy · 88% MIT

chroma

41

nobodyohm-web/Thot

Skill Claude CodeCodex

Embedding database for RAG and semantic search.

0 7d ago A 12 tokens copy · 83% MIT

crucible

42

robcsaszar/crucible

Skill Claude CodeCodex

Targeted multi-domain codebase audit. Use when auditing a user flow end to end, investigating issues that span several domains (auth, data, API, UI), or running a structured find-then-fix cycle over a named area. Produces a validated findings set and a SPEC handoff for implementation. Not for reviewing a single file…

0 2d ago A 90 tokens original MIT