SkillAgentSearch skills...

phx-audit

Project health audit and health check — architecture, performance, tests,

Install / Use

npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-audit

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

81/100

Category

Security

Supported Platforms

Universal

Our assessment of phx-audit

phx-audit scores 81/100 on our quality scale, 1003rd of 1,120 Security skills we index.

Its SKILL.md is 4.0 KB long, well organised into 11 sections with 1 code example: a solid amount of guidance for an agent.

It has 560 GitHub stars, a meaningful sign that others use it.

Substance
26/30
Structure
17/20
Description
12/15
Adoption
12/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 3 days ago, so phx-audit is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

phx-audit compared with similar skills

All 4 of these similar skills score higher than phx-audit; compare them before choosing.

SkillScoreStarsUpdatedFormat
phx-audit (this skill)by oliver-kriska815603d agoSKILL.md
algorithmic-artby anthropics100177.9k13d agoSKILL.md
pptxby anthropics100177.9k13d agoSKILL.md
designby nextlevelbuilder100130.2k14d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100130.2k14d agoSKILL.md

Frequently asked questions

How do I install phx-audit?
Run npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-audit. The install tabs above show the steps for each supported agent.
Which AI agents does phx-audit work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is phx-audit safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is phx-audit still maintained?
The repository was last updated 3 days ago, so phx-audit is actively maintained.

name: phx-audit description: Project health audit and health check — architecture, performance, tests, dependencies, code quality. Use when assessing overall project health, before releases, or after refactors.

Project Health Audit

Comprehensive project-wide health assessment across five independent concern tracks.

Usage

phx-audit              # Full audit (default)
phx-audit --quick      # 2-3 minute pulse check
phx-audit --focus=security   # Deep dive single area
phx-audit --focus=performance
phx-audit --since abc123   # Incremental audit since commit
phx-audit --since HEAD~10  # Audit last 10 commits

When to Use

  • Quarterly health checks
  • Before major releases
  • After large refactors
  • New team member onboarding (understand codebase health)

Iron Laws

  1. Complete every selected track before synthesizing — partial results make cross-category scores misleading
  2. Scope each track to concrete directories and checks — vague project-wide analysis produces generic findings
  3. Never compare scores across projects — track trends only within the same codebase
  4. Run quick mode before full mode — catch basic failures before expensive analysis

Portable Audit Workflow

  1. Create .claude/audit/reports/ and .claude/audit/summaries/.
  2. Run the quick checks below. Stop and report a blocker when the project cannot compile or its test command cannot start.
  3. Complete five tracks: architecture, performance, security, tests, and dependencies. Native generic workers may run independent tracks in parallel when the runtime provides them; otherwise run every track sequentially in this session. Never require named custom agents.
  4. Write one evidence-focused report per track under .claude/audit/reports/. Report issues only, cite paths and lines, and use one summary line for a clean area.
  5. After all selected reports exist, deduplicate findings, identify cross-category correlations, calculate scores using references/scoring-methodology.md, and write .claude/audit/summaries/project-health-{date}.md.

If two or more optional workers fail or hit limits, finish the missing tracks sequentially. Never present an incomplete track as audited.

Output Format

Report an executive health score, per-category scores for Architecture, Performance, Security, Tests, and Dependencies, critical issues, top recommendations, and an Immediate/Short-term/Long-term action plan.

Quick Mode (--quick)

Only run essential checks (~2-3 minutes):

Run mix compile --warnings-as-errors, then mix hex.audit && mix deps.audit, then mix xref graph --format stats, then mix test --trace 2>&1 | tail -20.

Skip: Full security scan, N+1 analysis, test quality metrics, architecture deep dive.

Focus Mode (--focus=area)

Run only the selected concern track with its deeper checks:

| Focus | Extra checks | |-------|--------------| | security | Full OWASP review, Sobelow, manual authorization patterns | | performance | Query plans, N+1 inventory, profiling evidence | | architecture | Full xref graph, coupling matrix, cohesion | | tests | Coverage by context, isolation, flaky-test indicators | | deps | Vulnerabilities, licenses, maintenance status |

Incremental Mode (--since <commit>)

Analyze only changes since a specific commit. Useful for pre-merge checks:

Run git diff --name-only <commit>...HEAD to identify changed files, then run targeted audits on changed files only (skips full project scan).

Combines with other flags: phx-audit --since HEAD~5 --focus=security

Relationship to Other Commands

| Command | Scope | Frequency | |---------|-------|-----------| | phx-review | Changed files (diff) | Every PR | | phx-audit | Entire project | Quarterly | | phx-boundaries | Context structure | On-demand | | phx-verify | Compile/test pass | Anytime |

References

  • references/scoring-methodology.md - How scores are calculated
  • references/architecture-checks.md - Detailed architecture criteria

Related Skills

View on GitHub
GitHub Stars560
CategorySecurity
Updated3d ago
Forks44

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions