audit-and-fix
A safe, multi-stage workflow to analyze code and apply validated fixes.
Install
mkdir -p .claude/skills/audit-and-fix && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/12371" && unzip -o skill.zip -d .claude/skills/audit-and-fix && rm skill.zipInstalls to .claude/skills/audit-and-fix
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Structured audit-then-remediate workflow: investigate read-only, write findings to a research file, then apply fixes via cost-routed subagents. Use when the user asks to analyse / audit / review something and (potentially) fix the issues found. Enforces human-approval gates before editing and before committing.Key capabilities
- →Frame questions for an audit based on user requests and obvious adjacent issues.
- →Conduct read-only investigations using parallel subagents.
- →Write findings to a structured research file including what, where, why it matters, and proposed fixes.
- →Summarize findings and obtain user approval for scope and actions before making changes.
- →Convert approved fixes into exact, unambiguous edit specifications.
- →Delegate execution of fixes to a general-purpose subagent.
How it works
The skill first performs a read-only investigation, documenting findings in a research file, then seeks user approval for the scope and proposed fixes before applying changes through delegated subagents.
Inputs & outputs
When to use audit-and-fix
- →Auditing configuration files
- →Fixing bugs in modules
- →Analyzing codebase for issues
About audit-and-fix
Performs read-only investigations before applying changes. It uses subagents for mechanical work and requires user approval before committing, ensuring high-quality remediation.
Structured audit-then-remediate workflow: investigate read-only, write findings to a research file, then apply fixes via cost-routed subagents. Use when the user asks to analyse / audit / review something and (potentially) fix the issues found. Enforces human-approval gates before editing and before
When not to use it
- →For a single known edit.
- →For a pure question with no remediation.
- →For work where the user has already decided exactly what to change.
Limitations
- →Investigation is strictly read-only until Gate 1 is passed.
- →The skill requires user approval at three fixed points: scope sign-off, decision sign-off, and commit sign-off.
- →The skill does not expand scope or pick between user-facing options unilaterally.
How it compares
This skill enforces a structured audit-then-remediate workflow with multiple human approval gates, separating investigation from change and routing work to cost-effective models, unlike a direct fix approach.
Compared to similar skills
audit-and-fix side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| audit-and-fix (this skill) | 0 | 3mo | No flags | Advanced |
| find-bugs | 5 | 8mo | No flags | Intermediate |
| tech-debt-analyzer | 5 | 10mo | Review | Intermediate |
| static-analysis | 5 | 8mo | No flags | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
You might also like
find-bugs
davila7
Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
tech-debt-analyzer
ailabs-393
This skill should be used when analyzing technical debt in a codebase, documenting code quality issues, creating technical debt registers, or assessing code maintainability. Use this for identifying code smells, architectural issues, dependency problems, missing documentation, security vulnerabilities, and creating comprehensive technical debt documentation.
static-analysis
gmh5225
Expertise in LLVM-based static analysis including dataflow analysis, pointer analysis, taint tracking, and program verification. Use this skill when implementing security scanners, bug finders, code quality tools, or performing program analysis research.
agent-code-analyzer
ruvnet
Agent skill for code-analyzer - invoke with $agent-code-analyzer
codex-code-review
tyrchen
Perform comprehensive code reviews using OpenAI Codex CLI. This skill should be used when users request code reviews, want to analyze diffs/PRs, need security audits, performance analysis, or want automated code quality feedback. Supports reviewing staged changes, specific files, entire directories, or git diffs.
review-code
catlog22
Multi-dimensional code review with structured reports. Analyzes correctness, readability, performance, security, testing, and architecture. Triggers on "review code", "code review", "审查代码", "代码审查".