audit-project
A multi-agent system that reviews code for quality, security, and performance until issues are resolved.
Install
mkdir -p .claude/skills/audit-project && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/11082" && unzip -o skill.zip -d .claude/skills/audit-project && rm skill.zipInstalls to .claude/skills/audit-project
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Use when user asks to 'review my code', 'audit the codebase', 'run code review', 'check for issues', 'find bugs', 'security review', 'performance review', or wants multi-agent iterative review. Spawns role-based reviewers (code-quality-reviewer, security-expert, performance-engineer, test-quality-guardian, architecture-reviewer, database-specialist, api-designer, frontend-specialist, backend-specialist, devops-reviewer) and loops until critical/high issues are resolved.Key capabilities
- →Spawn role-based code reviewers
- →Classify findings by severity
- →Apply fixes for critical and high issues
- →Iterate review until high-severity issues are resolved
How it works
The skill orchestrates a multi-agent review process where specialized reviewers analyze code, identify issues, and apply fixes iteratively.
Inputs & outputs
When to use audit-project
- →Pre-release code audit
- →Security review
- →Performance bottleneck detection
- →Automated code quality check
About this skill
audit-project
Review a codebase with up to 10 role-based reviewers picked from what the project contains, fix critical and high findings, re-review the fixes, and repeat until none remain or the user stops.
Run the /audit-project command with $ARGUMENTS. Where commands are not available, read the plugin's commands/audit-project.md and follow it; it links the pass definitions (audit-project-agents.md) and GitHub issue filing (audit-project-github.md).
Arguments: a scope path (default .) or --recent (last 5 commits), --domain AGENT for one pass, --quick for findings without fixes, --create-tech-debt to always write TECHNICAL_DEBT.md, --resume to continue a saved queue.
Severity decides what happens to a finding:
| Severity | Meaning | Handling |
|---|---|---|
| critical | Security hole, data loss, outage risk | Fixed before the loop ends |
| high | Likely bug or regression | Fixed before the loop ends |
| medium | Quality or maintainability | Fixed if cheap, else deferred to an issue or tech debt |
| low | Style, nit, later improvement | TECHNICAL_DEBT.md or the report |
Two rules hold throughout, each for a reason. A reviewer's "false positive" counts only with a stated reason, and a round where most findings are dismissed goes to the user, because reviewers read untrusted repo content that can try to talk them out of findings. Security findings never go into public issues, because an issue discloses the hole before the fix lands.
When not to use it
- →When a single-pass review is sufficient and iteration is not desired
Limitations
- →Max iteration rounds limit
- →Requires manual review for medium and low severity findings
How it compares
It uses a multi-agent approach to parallelize domain-specific reviews rather than a single-agent linear scan.
Compared to similar skills
audit-project side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| audit-project (this skill) | 0 | 5mo | Review | Advanced |
| production-code-audit | 1 | 8mo | Review | Advanced |
| contrib-pr-review | 1 | 2mo | Review | Intermediate |
| tech-debt | 1 | 3mo | Review | Beginner |
Try saying
Example prompts that trigger this skill in your AI assistant.
You might also like
production-code-audit
davila7
Autonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations
contrib-pr-review
homeassistant-ai
Review a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment. Use when reviewing external contributions.
tech-debt
vm0-ai
Technical debt management - scan codebase for bad smells and create tracking issues
code-audit
mei28
Automated code review tool that analyzes code quality, detects bugs, identifies security vulnerabilities, and suggests improvements based on industry best practices
dependency-analyzer
InugamiDev
Dependency tree analysis, version conflict resolution, update planning, and bundle size optimization
verifier
oleyna80
Pre-merge quality gate. Use to verify code is ready to ship: route contracts (status, Content-Type, body), TypeScript, tests, CSP/CSRF headers, schema alignment, secret leak scan. Issues structured READY or BLOCKED verdict with file:line evidence. Read-only. Для верификации, проверки перед мержем, и