AU

audit-and-fix

A safe, multi-stage workflow to analyze code and apply validated fixes.

Install

mkdir -p .claude/skills/audit-and-fix && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/12371" && unzip -o skill.zip -d .claude/skills/audit-and-fix && rm skill.zip

Installs to .claude/skills/audit-and-fix

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Structured audit-then-remediate workflow: investigate read-only, write findings to a research file, then apply fixes via cost-routed subagents. Use when the user asks to analyse / audit / review something and (potentially) fix the issues found. Enforces human-approval gates before editing and before committing.
312 chars✓ has a “when” triggerlonger than Claude Code's old 250-char listing cap (fine on current versions)
Advanced

Key capabilities

  • →Frame questions for an audit based on user requests and obvious adjacent issues.
  • →Conduct read-only investigations using parallel subagents.
  • →Write findings to a structured research file including what, where, why it matters, and proposed fixes.
  • →Summarize findings and obtain user approval for scope and actions before making changes.
  • →Convert approved fixes into exact, unambiguous edit specifications.
  • →Delegate execution of fixes to a general-purpose subagent.

How it works

The skill first performs a read-only investigation, documenting findings in a research file, then seeks user approval for the scope and proposed fixes before applying changes through delegated subagents.

Inputs & outputs

You give it
A request to analyze, audit, or review something with potential fixes.
You get back
A structured research file with findings and proposed fixes, followed by applied and verified changes upon user approval.

When to use audit-and-fix

  • →Auditing configuration files
  • →Fixing bugs in modules
  • →Analyzing codebase for issues

About audit-and-fix

Performs read-only investigations before applying changes. It uses subagents for mechanical work and requires user approval before committing, ensuring high-quality remediation.

Structured audit-then-remediate workflow: investigate read-only, write findings to a research file, then apply fixes via cost-routed subagents. Use when the user asks to analyse / audit / review something and (potentially) fix the issues found. Enforces human-approval gates before editing and before

When not to use it

  • →For a single known edit.
  • →For a pure question with no remediation.
  • →For work where the user has already decided exactly what to change.

Limitations

  • →Investigation is strictly read-only until Gate 1 is passed.
  • →The skill requires user approval at three fixed points: scope sign-off, decision sign-off, and commit sign-off.
  • →The skill does not expand scope or pick between user-facing options unilaterally.

How it compares

This skill enforces a structured audit-then-remediate workflow with multiple human approval gates, separating investigation from change and routing work to cost-effective models, unlike a direct fix approach.

Compared to similar skills

audit-and-fix side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
audit-and-fix (this skill)03moNo flagsAdvanced
find-bugs58moNo flagsIntermediate
tech-debt-analyzer510moReviewIntermediate
static-analysis58moNo flagsAdvanced

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

find-bugs

davila7

Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.

529

tech-debt-analyzer

ailabs-393

This skill should be used when analyzing technical debt in a codebase, documenting code quality issues, creating technical debt registers, or assessing code maintainability. Use this for identifying code smells, architectural issues, dependency problems, missing documentation, security vulnerabilities, and creating comprehensive technical debt documentation.

522

static-analysis

gmh5225

Expertise in LLVM-based static analysis including dataflow analysis, pointer analysis, taint tracking, and program verification. Use this skill when implementing security scanners, bug finders, code quality tools, or performing program analysis research.

518

agent-code-analyzer

ruvnet

Agent skill for code-analyzer - invoke with $agent-code-analyzer

317

codex-code-review

tyrchen

Perform comprehensive code reviews using OpenAI Codex CLI. This skill should be used when users request code reviews, want to analyze diffs/PRs, need security audits, performance analysis, or want automated code quality feedback. Supports reviewing staged changes, specific files, entire directories, or git diffs.

16

review-code

catlog22

Multi-dimensional code review with structured reports. Analyzes correctness, readability, performance, security, testing, and architecture. Triggers on "review code", "code review", "审查代码", "代码审查".

22

Search skills

Search the agent skills registry