File contents Code Auditor
Comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and maintainability.
When to Use
"audit the code"
"analyze code quality"
"check for issues"
"review the codebase"
"find technical debt"
"security audit"
"performance review"
What It Analyzes
1. Architecture & Design
Overall structure and organization
Design patterns in use
Module boundaries and separation of concerns
Dependency management
Architectural decisions and trade-offs
2. Code Quality
Complexity hotspots (cyclomatic complexity)
Code duplication (DRY violations)
Naming conventions and consistency
Documentation coverage
Code smells and anti-patterns
3. Security
Common vulnerabilities (OWASP Top 10)
Input validation and sanitization
Authentication and authorization
Secrets management
Dependency vulnerabilities
4. Performance
Algorithmic complexity issues
Database query optimization
Memory usage patterns
Caching opportunities
Resource leaks
5. Testing
Test coverage assessment
Test quality and effectiveness
Missing test scenarios
Testing patterns and practices
Integration vs unit test balance
6. Maintainability
Technical debt assessment
Coupling and cohesion
Ease of future changes
Onboarding friendliness
Documentation quality
Approach
Explore using Explore agent (thorough mode)
Identify patterns with Grep and Glob
Read critical files for detailed analysis
Run static analysis tools if available
Synthesize findings into actionable report
Thoroughness Levels
Quick (15-30 min): High-level, critical issues only
Standard (30-60 min): Comprehensive across all dimensions
Deep (60+ min): Exhaustive with detailed examples
Output Format
# Code Audit Report
## Executive Summary
- Overall health score
- Critical issues count
- Top 3 priorities
## Findings by Category
### Architecture & Design
#### 🔴 High Priority
- [Finding with file:line reference]
- Impact: [description]
- Recommendation: [action]
#### 🟡 Medium Priority
...
### [Other categories]
## Prioritized Action Plan
1. Quick wins (< 1 day)
2. Medium-term improvements (1-5 days)
3. Long-term initiatives (> 5 days)
## Metrics
- Files analyzed: X
- Lines of code: Y
- Test coverage: Z%
- Complexity hotspots: N
Tools Used
Task (Explore agent) : Thorough codebase exploration
Grep : Pattern matching for issues
Glob : Find files by type/pattern
Read : Detailed file analysis
Bash : Run linters, coverage tools
Success Criteria
Comprehensive coverage of all six dimensions
Specific file:line references for all findings
Severity/priority ratings (Critical/High/Medium/Low)
Actionable recommendations (not just observations)
Estimated effort for fixes
Both quick wins and long-term improvements
Integration
feature-planning : Plan technical debt reduction
test-fixing : Address test gaps identified
project-bootstrapper : Set up quality tooling
Configuration
Can focus on specific areas:
Security-only audit
Performance-only audit
Testing-only assessment
Quick architecture review
1 --- 2 name: code-auditor 3 description: Code Auditor 4 --- 5 # Code Auditor 6 7 Comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and maintainability. 8 9 ## When to Use 10 11 - "audit the code" 12 - "analyze code quality" 13 - "check for issues" 14 - "review the codebase" 15 - "find technical debt" 16 - "security audit" 17 - "performance review" 18 19 ## What It Analyzes 20 21 ### 1. Architecture & Design 22 - Overall structure and organization 23 - Design patterns in use 24 - Module boundaries and separation of concerns 25 - Dependency management 26 - Architectural decisions and trade-offs 27 28 ### 2. Code Quality 29 - Complexity hotspots (cyclomatic complexity) 30 - Code duplication (DRY violations) 31 - Naming conventions and consistency 32 - Documentation coverage 33 - Code smells and anti-patterns 34 35 ### 3. Security 36 - Common vulnerabilities (OWASP Top 10) 37 - Input validation and sanitization 38 - Authentication and authorization 39 - Secrets management 40 - Dependency vulnerabilities 41 42 ### 4. Performance 43 - Algorithmic complexity issues 44 - Database query optimization 45 - Memory usage patterns 46 - Caching opportunities 47 - Resource leaks 48 49 ### 5. Testing 50 - Test coverage assessment 51 - Test quality and effectiveness 52 - Missing test scenarios 53 - Testing patterns and practices 54 - Integration vs unit test balance 55 56 ### 6. Maintainability 57 - Technical debt assessment 58 - Coupling and cohesion 59 - Ease of future changes 60 - Onboarding friendliness 61 - Documentation quality 62 63 ## Approach 64 65 1. **Explore** using Explore agent (thorough mode) 66 2. **Identify patterns** with Grep and Glob 67 3. **Read critical files** for detailed analysis 68 4. **Run static analysis tools** if available 69 5. **Synthesize findings** into actionable report 70 71 ## Thoroughness Levels 72 73 - **Quick** (15-30 min): High-level, critical issues only 74 - **Standard** (30-60 min): Comprehensive across all dimensions 75 - **Deep** (60+ min): Exhaustive with detailed examples 76 77 ## Output Format 78 79 ```markdown 80 # Code Audit Report 81 82 ## Executive Summary 83 - Overall health score 84 - Critical issues count 85 - Top 3 priorities 86 87 ## Findings by Category 88 89 ### Architecture & Design 90 #### 🔴 High Priority 91 - [Finding with file:line reference] 92 - Impact: [description] 93 - Recommendation: [action] 94 95 #### 🟡 Medium Priority 96 ... 97 98 ### [Other categories] 99 100 ## Prioritized Action Plan 101 1. Quick wins (< 1 day) 102 2. Medium-term improvements (1-5 days) 103 3. Long-term initiatives (> 5 days) 104 105 ## Metrics 106 - Files analyzed: X 107 - Lines of code: Y 108 - Test coverage: Z% 109 - Complexity hotspots: N 110 ``` 111 112 ## Tools Used 113 114 - **Task (Explore agent)**: Thorough codebase exploration 115 - **Grep**: Pattern matching for issues 116 - **Glob**: Find files by type/pattern 117 - **Read**: Detailed file analysis 118 - **Bash**: Run linters, coverage tools 119 120 ## Success Criteria 121 122 - Comprehensive coverage of all six dimensions 123 - Specific file:line references for all findings 124 - Severity/priority ratings (Critical/High/Medium/Low) 125 - Actionable recommendations (not just observations) 126 - Estimated effort for fixes 127 - Both quick wins and long-term improvements 128 129 ## Integration 130 131 - **feature-planning**: Plan technical debt reduction 132 - **test-fixing**: Address test gaps identified 133 - **project-bootstrapper**: Set up quality tooling 134 135 ## Configuration 136 137 Can focus on specific areas: 138 - Security-only audit 139 - Performance-only audit 140 - Testing-only assessment 141 - Quick architecture review
ComeOnOliver/skillshub/tree/main/skills/mhattingpete/claude-skills-marketplace/code-auditor commit cb8fca36b1
Frequently asked questions How do I install the Code Auditor skill? Run npx skillmds@latest add comeonoliver/code-auditor in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
What does the Code Auditor skill do? Code Auditor It is listed under Coding & Dev Tools on SkillMD.
Is Code Auditor safe to use? This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
Which AI agents work with Code Auditor? This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Is Code Auditor free to use? Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
Who published Code Auditor? ComeOnOliver (@comeonoliver) published this skill. Their other Agent Skills are listed on their SkillMD profile.