SkillAgentSearch skills...

code-auditing

Use when a codebase or a subsystem needs a systematic quality, security or maintainability review, when dead code or duplicated logic must be identified across many files, when a dependency or custom implementation is suspected of being replaceable, or when a pre-release review must cover more than…

Install / Use

npx skills add ratara5/app-tickets-backend --skill code-auditing

Installs into whichever agent you are using.

About this skill
♊

Gemini Rules

Gemini CLI config

Quality Score

62/100

Category

Security

Supported Platforms

Gemini CLI

Our assessment of code-auditing

code-auditing scores 62/100 on our quality scale, 1079th of 1,116 Security skills we index.

Its Gemini Rules is 4.7 KB long, well organised into 22 sections and no code examples: a solid amount of guidance for an agent.

It has no GitHub stars yet, so there is no community track record; judge it on its content.

Substance
26/30
Structure
13/20
Description
15/15
Adoption
0/20
Freshness
5/15

Maintenance, license and trust

  • We could not determine when the repository was last updated.
  • No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
  • Its trust signals score 68/100, with 3 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

code-auditing compared with similar skills

All 4 of these similar skills score higher than code-auditing; compare them before choosing.

SkillScoreStarsUpdatedFormat
code-auditing (this skill)by ratara5620—Gemini Rules
ui-ux-pro-maxby nextlevelbuilder100130.2k14d agoSKILL.md
design-isby thedotmack10094.6k12d agoSKILL.md
atlas-ledgerby sickn3310046.9k11d agoSKILL.md
diagram-designby cathrynlavery10042.3k16d agoSKILL.md

Frequently asked questions

How do I install code-auditing?
Run npx skills add ratara5/app-tickets-backend. The install tabs above show the steps for each supported agent.
Which AI agents does code-auditing work with?
It is written for Gemini CLI, as a Gemini Rules file. Other agents that read the same format can often use it too.
Is code-auditing safe to use?
It declares no license and scores 68/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is code-auditing still maintained?
We could not determine when the repository was last updated.

name: code-auditing description: Use when a codebase or a subsystem needs a systematic quality, security or maintainability review, when dead code or duplicated logic must be identified across many files, when a dependency or custom implementation is suspected of being replaceable, or when a pre-release review must cover more than the files in the current diff. States triggering conditions; the audit phases are in the body. version: 1.0.0

GENERATED by agentic-layer v1.6.1. DO NOT EDIT. Edit the harness or the consumer overlay.

Code Auditing Skill

Comprehensive methodology for systematic code quality audits.

When to Use

  • Comprehensive code quality audits
  • Security vulnerability assessments
  • Technical debt identification
  • Pre-release code reviews
  • Best practices verification
  • Library and dependency audits

Audit Phases

Phase 0: Pre-Analysis Setup

  1. Check for project configuration files (package.json, tsconfig.json, etc.)
  2. Identify tech stack and main libraries
  3. Check for linting/formatting configs
  4. Run existing linting/testing commands as baseline
  5. Load documentation for identified core libraries

Phase 1: Discovery

  1. Find all code files by type
  2. Create tracking list for each file
  3. Group files by module/feature for contextual analysis

Phase 2: File-by-File Analysis

For each file, analyze for:

  • Dead code (unused functions, variables, imports)
  • Code smells and anti-patterns
  • Custom implementations that could use established libraries
  • Security vulnerabilities
  • Performance issues
  • Outdated patterns or deprecated APIs
  • Missing error handling
  • Overly complex functions
  • Duplicate code

Phase 3: Best Practices Verification

For every library and framework:

  1. Retrieve official documentation
  2. Compare implementation against official patterns
  3. Identify deviations from recommendations
  4. Note outdated usage patterns
  5. Flag discouraged anti-patterns

Phase 4: Pattern Detection

Look for recurring issues:

  • Common anti-patterns across files
  • Duplicated logic that could be abstracted
  • Inconsistent coding styles
  • Missing error handling patterns

Phase 5: Library Recommendations

For custom implementations:

  1. Check if current libraries provide the functionality
  2. Search for mature ecosystem packages
  3. Verify library health (commits, issues, activity)
  4. Check compatibility with project setup

Phase 6: Comprehensive Report

Generate detailed report with:

  • Executive summary
  • Critical issues requiring immediate attention
  • File-by-file findings
  • Prioritized action plan
  • Effort estimates
  • Library recommendations

Issue Priority Levels

  • Critical - Security vulnerabilities, broken functionality
  • High Priority - Performance bottlenecks, unmaintainable code
  • Medium Priority - Code quality, best practices deviations
  • Low Priority - Style, minor improvements
  • Quick Wins - Less than 30 minutes to fix

Analysis Categories

Security

  • Hardcoded secrets
  • SQL injection risks
  • XSS vulnerabilities
  • Missing input validation
  • Exposed sensitive data

Performance

  • Inefficient algorithms
  • Blocking operations
  • Memory leaks
  • Missing caching opportunities
  • N+1 query patterns

TypeScript/Type Safety

  • Missing type annotations
  • Use of any type
  • Custom types duplicating official types
  • Missing @types packages

Async/Promise Issues

  • Missing await keywords
  • Unhandled promise rejections
  • Callback hell

Dead Code

  • Unused imports and exports
  • Unused functions, classes, and methods
  • Unused variables and types
  • Unreachable code blocks
  • Unused files (not imported anywhere)
  • Unused dependencies

Tools:

  • JavaScript/TypeScript: npx knip --reporter json
  • Python: deadcode . --dry

Important: Always verify tool findings before reporting. Check for:

  • Dynamic imports (import(variable))
  • Framework patterns (React components, decorators)
  • Re-exports for public API
  • Entry points (CLI scripts, serverless handlers)

Resources

See the reference documents for complete methodologies:

  • references/audit-methodology.md - Full 6-phase audit process with detailed checklists
  • references/dead-code-methodology.md - Dead code detection tools, verification, and cleanup workflows

Quick Reference

Before Starting

  • [ ] Read project configuration files
  • [ ] Identify tech stack and libraries
  • [ ] Run existing linters as baseline
  • [ ] Create file tracking list

During Audit

  • [ ] Mark files as in-progress
  • [ ] Analyze each category systematically
  • [ ] Note specific line numbers
  • [ ] Document before/after examples
  • [ ] Mark files as completed

After Audit

  • [ ] Categorize all findings by priority
  • [ ] Generate comprehensive report
  • [ ] Save report to project root
  • [ ] Provide brief console summary

Related Skills

View on GitHub
GitHub Stars0
CategorySecurity
UpdatedNaNy ago
Forks0

Trust signals

68/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

2 medium1 low