audit
Project health audit and health check — architecture, performance, tests, dependencies, code quality
Install / Use
npx skills add oliver-kriska/claude-elixir-phoenix --skill auditInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of audit
audit scores 87/100 on our quality scale, 641st of 1,120 Security skills we index.
Its SKILL.md is 7.9 KB long, well organised into 17 sections with 4 code examples: a thorough specification that gives an agent plenty to work with.
It has 560 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 3 days ago, so audit is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-05. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
audit compared with similar skills
All 4 of these similar skills score higher than audit; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| audit (this skill)by oliver-kriska | 87 | 560 | 3d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 13d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 13d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 14d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 14d ago | SKILL.md |
Frequently asked questions
- How do I install audit?
- Run
npx skills add oliver-kriska/claude-elixir-phoenix --skill audit. The install tabs above show the steps for each supported agent. - Which AI agents does audit work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is audit safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is audit still maintained?
- The repository was last updated 3 days ago, so audit is actively maintained.
Skill content
View source on GitHubname: audit description: Project health audit and health check — architecture, performance, tests, dependencies, code quality. Use when assessing overall project health, before releases, or after refactors. effort: high argument-hint: "[--quick|--full|--focus=area|--since=commit]"
Project Health Audit
Comprehensive project-wide health assessment using 5 parallel specialist subagents.
Usage
/phx:audit # Full audit (default)
/phx:audit --quick # 2-3 minute pulse check
/phx:audit --focus=security # Deep dive single area
/phx:audit --focus=performance
/phx:audit --since abc123 # Incremental audit since commit
/phx:audit --since HEAD~10 # Audit last 10 commits
When to Use
- Quarterly health checks
- Before major releases
- After large refactors
- New team member onboarding (understand codebase health)
Iron Laws
- Wait for ALL agents before synthesizing — Partial results create misleading health scores because cross-category correlations get missed
- Scope agent prompts to specific directories — Vague prompts like "analyze the codebase" produce generic findings that waste tokens and miss real issues
- Never compare scores across projects — Scoring methodology depends on project size and maturity; only track trends within the same project
- Quick mode before full mode — Run
--quickfirst to catch compile/test failures before spending tokens on 5 parallel agents
Subagent Architecture
Spawn 5 specialists in parallel using Agent tool. Three route to plugin
specialists with a declared model; the two categories without a specialist use
general-purpose pinned to model: "sonnet" — unpinned, they inherit the
session model (Opus by default):
| Subagent | Focus | Output File | Routes to |
|----------|-------|-------------|-----------|
| Architecture Reviewer | Structure quality, coupling, cohesion | arch-review.md | phoenix-patterns-analyst (sonnet) |
| Performance Auditor | N+1, indexes, bottlenecks, scalability | perf-audit.md | general-purpose, model: "sonnet" (no perf specialist yet) |
| Security Auditor | OWASP scan, auth patterns, secrets | security-audit.md | security-analyzer (opus) |
| Test Health Auditor | Coverage, quality, flaky tests | test-audit.md | testing-reviewer (sonnet) |
| Dependency Auditor | Vulnerabilities, outdated, unused | deps-audit.md | general-purpose, model: "sonnet" (hex-deps-triager is per-package only) |
Workflow
Step 1: Create Task List and Spawn All 5 Auditors (Parallel)
If TaskCreate is in your tool list, create Claude Code tasks for
progress visibility (Sonnet 5+ and Opus 4.8+ omit it unless
CLAUDE_CODE_ENABLE_TODO_TOOLS=1; never ToolSearch for it — skip this block):
For each auditor:
TaskCreate({subject: "{Area} audit", activeForm: "Auditing {area}..."})
TaskUpdate({taskId, status: "in_progress"})
Then spawn all 5 agents with Agent tool (parallel). Route to declared-model
specialists where they exist, keep general-purpose only where no specialist
covers the audit category:
Agent(subagent_type: "phx:phoenix-patterns-analyst", prompt: "Architecture audit: analyze module structure, context boundaries, coupling, cohesion. Write findings to .claude/audit/reports/arch-review.md", run_in_background: true)
Agent(subagent_type: "general-purpose", model: "sonnet", prompt: "Performance audit: N+1 queries, missing indexes, bottlenecks, scalability. Write findings to .claude/audit/reports/perf-audit.md", run_in_background: true)
Agent(subagent_type: "phx:security-analyzer", prompt: "Security audit: OWASP scan, auth patterns, secret leakage. Write findings to .claude/audit/reports/security-audit.md", run_in_background: true)
Agent(subagent_type: "phx:testing-reviewer", prompt: "Test health audit: coverage, quality, flakes. Write findings to .claude/audit/reports/test-audit.md", run_in_background: true)
Agent(subagent_type: "general-purpose", model: "sonnet", prompt: "Dependency audit: vulnerabilities, outdated, unused. Write findings to .claude/audit/reports/deps-audit.md", run_in_background: true)
Why specialist routing matters: a general-purpose subagent without
model: inherits the session model — Opus on every plan since CC 2.1.280.
Plugin specialists declare their own model in frontmatter, and the two
general-purpose tracks pin model: "sonnet", so no audit track runs on Opus.
Agent prompts must be FOCUSED. Scope each prompt to the relevant directories and patterns. Do NOT give vague prompts like "analyze the codebase."
Output efficiency: Tell each agent: "Report ONLY issues found. Do NOT list clean checks, passing categories, or 'What's Good'. One summary line per clean area suffices."
Step 2: Collect Results
Wait for ALL auditors to complete — one completion notification per agent
spawned. If you created tasks, mark each completed as it finishes. NEVER
proceed while any auditor is still running.
Read reports from .claude/audit/reports/.
Rate-limit circuit breaker: if 2+ auditors return empty results or
rate-limit/API errors, STOP spawning. Synthesize from the reports that
exist, mark missing categories as "not audited (rate limit)", and tell
the user to re-run /phx:audit after the limit resets. Never leave the
user typing "continue" against dead agents.
Step 3: Compress Findings
After all 5 auditors complete, spawn context-supervisor:
Agent(subagent_type: "phx:context-supervisor", prompt: """
Compress audit findings.
Input: .claude/audit/reports/
Output: .claude/audit/summaries/
Priority: Health scores per category, critical findings
only, cross-category correlations, deduplicate findings
found by 2+ agents.
""")
Read .claude/audit/summaries/consolidated.md for synthesis.
Step 4: Calculate Health Score
Each category scores 0-100. See ${CLAUDE_SKILL_DIR}/references/scoring-methodology.md.
Step 5: Generate Report
Write to .claude/audit/summaries/project-health-{date}.md.
Output Format
Report includes: Executive summary with health score (A-F, numeric/100), per-category score table (Architecture, Performance, Security, Tests, Dependencies), critical issues, top recommendations, and action plan (Immediate/Short-term/Long-term).
Quick Mode (--quick)
Only run essential checks (~2-3 minutes):
Run mix compile --warnings-as-errors, then mix hex.audit && mix deps.audit,
then mix xref graph --format stats, then mix test --trace 2>&1 | tail -20.
Skip: Full security scan, N+1 analysis, test quality metrics, architecture deep dive.
Focus Mode (--focus=area)
Deep dive single area with full specialist resources:
| Focus | Subagent | Extra Checks |
|-------|----------|--------------|
| security | security-analyzer | Full OWASP, sobelow, manual patterns |
| performance | general-purpose | Profile-level analysis, query explain (no plugin specialist yet) |
| architecture | phoenix-patterns-analyst | Full xref, coupling matrix, cohesion |
| tests | testing-reviewer | Coverage by context, quality metrics |
| deps | general-purpose | License audit, maintenance status (per-package hex-deps-triager only) |
Incremental Mode (--since <commit>)
Analyze only changes since a specific commit. Useful for pre-merge checks:
Run git diff --name-only <commit>...HEAD to identify changed files, then run targeted audits on changed files only (skips full project scan).
Combines with other flags: /phx:audit --since HEAD~5 --focus=security
Relationship to Other Commands
| Command | Scope | Frequency |
|---------|-------|-----------|
| /phx:review | Changed files (diff) | Every PR |
| /phx:audit | Entire project | Quarterly |
| /phx:boundaries | Context structure | On-demand |
| /phx:verify | Compile/test pass | Anytime |
References
${CLAUDE_SKILL_DIR}/references/scoring-methodology.md- How scores are calculated${CLAUDE_SKILL_DIR}/references/architecture-checks.md- Detailed architecture criteria
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
