phx-audit
Project health audit and health check — architecture, performance, tests,
Install / Use
npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-auditInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of phx-audit
phx-audit scores 81/100 on our quality scale, 1003rd of 1,120 Security skills we index.
Its SKILL.md is 4.0 KB long, well organised into 11 sections with 1 code example: a solid amount of guidance for an agent.
It has 560 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 3 days ago, so phx-audit is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
phx-audit compared with similar skills
All 4 of these similar skills score higher than phx-audit; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| phx-audit (this skill)by oliver-kriska | 81 | 560 | 3d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 13d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 13d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 14d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 14d ago | SKILL.md |
Frequently asked questions
- How do I install phx-audit?
- Run
npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-audit. The install tabs above show the steps for each supported agent. - Which AI agents does phx-audit work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is phx-audit safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is phx-audit still maintained?
- The repository was last updated 3 days ago, so phx-audit is actively maintained.
Skill content
View source on GitHubname: phx-audit description: Project health audit and health check — architecture, performance, tests, dependencies, code quality. Use when assessing overall project health, before releases, or after refactors.
Project Health Audit
Comprehensive project-wide health assessment across five independent concern tracks.
Usage
phx-audit # Full audit (default)
phx-audit --quick # 2-3 minute pulse check
phx-audit --focus=security # Deep dive single area
phx-audit --focus=performance
phx-audit --since abc123 # Incremental audit since commit
phx-audit --since HEAD~10 # Audit last 10 commits
When to Use
- Quarterly health checks
- Before major releases
- After large refactors
- New team member onboarding (understand codebase health)
Iron Laws
- Complete every selected track before synthesizing — partial results make cross-category scores misleading
- Scope each track to concrete directories and checks — vague project-wide analysis produces generic findings
- Never compare scores across projects — track trends only within the same codebase
- Run quick mode before full mode — catch basic failures before expensive analysis
Portable Audit Workflow
- Create
.claude/audit/reports/and.claude/audit/summaries/. - Run the quick checks below. Stop and report a blocker when the project cannot compile or its test command cannot start.
- Complete five tracks: architecture, performance, security, tests, and dependencies. Native generic workers may run independent tracks in parallel when the runtime provides them; otherwise run every track sequentially in this session. Never require named custom agents.
- Write one evidence-focused report per track under
.claude/audit/reports/. Report issues only, cite paths and lines, and use one summary line for a clean area. - After all selected reports exist, deduplicate findings, identify
cross-category correlations, calculate scores using
references/scoring-methodology.md, and write.claude/audit/summaries/project-health-{date}.md.
If two or more optional workers fail or hit limits, finish the missing tracks sequentially. Never present an incomplete track as audited.
Output Format
Report an executive health score, per-category scores for Architecture, Performance, Security, Tests, and Dependencies, critical issues, top recommendations, and an Immediate/Short-term/Long-term action plan.
Quick Mode (--quick)
Only run essential checks (~2-3 minutes):
Run mix compile --warnings-as-errors, then mix hex.audit && mix deps.audit,
then mix xref graph --format stats, then mix test --trace 2>&1 | tail -20.
Skip: Full security scan, N+1 analysis, test quality metrics, architecture deep dive.
Focus Mode (--focus=area)
Run only the selected concern track with its deeper checks:
| Focus | Extra checks |
|-------|--------------|
| security | Full OWASP review, Sobelow, manual authorization patterns |
| performance | Query plans, N+1 inventory, profiling evidence |
| architecture | Full xref graph, coupling matrix, cohesion |
| tests | Coverage by context, isolation, flaky-test indicators |
| deps | Vulnerabilities, licenses, maintenance status |
Incremental Mode (--since <commit>)
Analyze only changes since a specific commit. Useful for pre-merge checks:
Run git diff --name-only <commit>...HEAD to identify changed files, then run targeted audits on changed files only (skips full project scan).
Combines with other flags: phx-audit --since HEAD~5 --focus=security
Relationship to Other Commands
| Command | Scope | Frequency |
|---------|-------|-----------|
| phx-review | Changed files (diff) | Every PR |
| phx-audit | Entire project | Quarterly |
| phx-boundaries | Context structure | On-demand |
| phx-verify | Compile/test pass | Anytime |
References
references/scoring-methodology.md- How scores are calculatedreferences/architecture-checks.md- Detailed architecture criteria
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
