code-auditing
Use when a codebase or a subsystem needs a systematic quality, security or maintainability review, when dead code or duplicated logic must be identified across many files, when a dependency or custom implementation is suspected of being replaceable, or when a pre-release review must cover more than…
Install / Use
npx skills add ratara5/app-tickets-backend --skill code-auditingInstalls into whichever agent you are using.
Gemini Rules
Gemini CLI config
Quality Score
Category
SecuritySupported Platforms
Our assessment of code-auditing
code-auditing scores 62/100 on our quality scale, 1079th of 1,116 Security skills we index.
Its Gemini Rules is 4.7 KB long, well organised into 22 sections and no code examples: a solid amount of guidance for an agent.
It has no GitHub stars yet, so there is no community track record; judge it on its content.
Maintenance, license and trust
- We could not determine when the repository was last updated.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 68/100, with 3 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
code-auditing compared with similar skills
All 4 of these similar skills score higher than code-auditing; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| code-auditing (this skill)by ratara5 | 62 | 0 | — | Gemini Rules |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 14d ago | SKILL.md |
| design-isby thedotmack | 100 | 94.6k | 12d ago | SKILL.md |
| atlas-ledgerby sickn33 | 100 | 46.9k | 11d ago | SKILL.md |
| diagram-designby cathrynlavery | 100 | 42.3k | 16d ago | SKILL.md |
Frequently asked questions
- How do I install code-auditing?
- Run
npx skills add ratara5/app-tickets-backend. The install tabs above show the steps for each supported agent. - Which AI agents does code-auditing work with?
- It is written for Gemini CLI, as a Gemini Rules file. Other agents that read the same format can often use it too.
- Is code-auditing safe to use?
- It declares no license and scores 68/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is code-auditing still maintained?
- We could not determine when the repository was last updated.
Skill content
View source on GitHubname: code-auditing description: Use when a codebase or a subsystem needs a systematic quality, security or maintainability review, when dead code or duplicated logic must be identified across many files, when a dependency or custom implementation is suspected of being replaceable, or when a pre-release review must cover more than the files in the current diff. States triggering conditions; the audit phases are in the body. version: 1.0.0
GENERATED by agentic-layer v1.6.1. DO NOT EDIT. Edit the harness or the consumer overlay.
Code Auditing Skill
Comprehensive methodology for systematic code quality audits.
When to Use
- Comprehensive code quality audits
- Security vulnerability assessments
- Technical debt identification
- Pre-release code reviews
- Best practices verification
- Library and dependency audits
Audit Phases
Phase 0: Pre-Analysis Setup
- Check for project configuration files (package.json, tsconfig.json, etc.)
- Identify tech stack and main libraries
- Check for linting/formatting configs
- Run existing linting/testing commands as baseline
- Load documentation for identified core libraries
Phase 1: Discovery
- Find all code files by type
- Create tracking list for each file
- Group files by module/feature for contextual analysis
Phase 2: File-by-File Analysis
For each file, analyze for:
- Dead code (unused functions, variables, imports)
- Code smells and anti-patterns
- Custom implementations that could use established libraries
- Security vulnerabilities
- Performance issues
- Outdated patterns or deprecated APIs
- Missing error handling
- Overly complex functions
- Duplicate code
Phase 3: Best Practices Verification
For every library and framework:
- Retrieve official documentation
- Compare implementation against official patterns
- Identify deviations from recommendations
- Note outdated usage patterns
- Flag discouraged anti-patterns
Phase 4: Pattern Detection
Look for recurring issues:
- Common anti-patterns across files
- Duplicated logic that could be abstracted
- Inconsistent coding styles
- Missing error handling patterns
Phase 5: Library Recommendations
For custom implementations:
- Check if current libraries provide the functionality
- Search for mature ecosystem packages
- Verify library health (commits, issues, activity)
- Check compatibility with project setup
Phase 6: Comprehensive Report
Generate detailed report with:
- Executive summary
- Critical issues requiring immediate attention
- File-by-file findings
- Prioritized action plan
- Effort estimates
- Library recommendations
Issue Priority Levels
- Critical - Security vulnerabilities, broken functionality
- High Priority - Performance bottlenecks, unmaintainable code
- Medium Priority - Code quality, best practices deviations
- Low Priority - Style, minor improvements
- Quick Wins - Less than 30 minutes to fix
Analysis Categories
Security
- Hardcoded secrets
- SQL injection risks
- XSS vulnerabilities
- Missing input validation
- Exposed sensitive data
Performance
- Inefficient algorithms
- Blocking operations
- Memory leaks
- Missing caching opportunities
- N+1 query patterns
TypeScript/Type Safety
- Missing type annotations
- Use of
anytype - Custom types duplicating official types
- Missing @types packages
Async/Promise Issues
- Missing await keywords
- Unhandled promise rejections
- Callback hell
Dead Code
- Unused imports and exports
- Unused functions, classes, and methods
- Unused variables and types
- Unreachable code blocks
- Unused files (not imported anywhere)
- Unused dependencies
Tools:
- JavaScript/TypeScript:
npx knip --reporter json - Python:
deadcode . --dry
Important: Always verify tool findings before reporting. Check for:
- Dynamic imports (
import(variable)) - Framework patterns (React components, decorators)
- Re-exports for public API
- Entry points (CLI scripts, serverless handlers)
Resources
See the reference documents for complete methodologies:
references/audit-methodology.md- Full 6-phase audit process with detailed checklistsreferences/dead-code-methodology.md- Dead code detection tools, verification, and cleanup workflows
Quick Reference
Before Starting
- [ ] Read project configuration files
- [ ] Identify tech stack and libraries
- [ ] Run existing linters as baseline
- [ ] Create file tracking list
During Audit
- [ ] Mark files as in-progress
- [ ] Analyze each category systematically
- [ ] Note specific line numbers
- [ ] Document before/after examples
- [ ] Mark files as completed
After Audit
- [ ] Categorize all findings by priority
- [ ] Generate comprehensive report
- [ ] Save report to project root
- [ ] Provide brief console summary
Related Skills
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
design-is
94.6kAudit a design against Dieter Rams' ten "Good design is..." principles, then hand off a /make-plan prompt for one of three outcomes — new design, refine design, or redesign
atlas-ledger
46.9kCompanion to atlas-contract. Auto-invoked by its Final Audit on caught drift; also use after Post Reviews or user requests to record a mistake. Distills drift into WHEN/DON'T/INSTEAD clauses, writes to Atlas.md after confirmation.
diagram-design
42.3kCreate branded architecture, IT current-state, flowchart, sequence, state machine, ER/data model, timeline, swimlane, quadrant, radar/spider, polar chart (polar/radial lollipop), loop/flywheel, nested, tree, org chart, layer stack, Venn, pyramid/funnel, treemap, heatmap, bar, waterfall, line, Gantt…
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
