s-audit
Audits World of Warcraft addons for security, technical debt, and deprecation compliance.
Install
mkdir -p .claude/skills/s-audit && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/9633" && unzip -o skill.zip -d .claude/skills/s-audit && rm skill.zipInstalls to .claude/skills/s-audit
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Comprehensive quality analysis for WoW addons. Combines security, complexity, deprecation, and dead code analysis into a single audit workflow. Triggers: audit, quality, analysis, review, check, scan.Key capabilities
- →Scan for security vulnerabilities like unsafe eval
- →Analyze code complexity and nesting levels
- →Identify deprecated WoW APIs
- →Detect dead code and orphaned files
How it works
The skill executes specific MCP tools to perform multi-layered static analysis on addon code against security and maintainability standards.
Inputs & outputs
When to use s-audit
- →Scan addon for deprecated APIs
- →Perform security audit for taint risks
- →Analyze code complexity
- →Identify and remove dead code
- →Validate addon against 12.0 standards
About this skill
Auditing WoW Addons
Guidance for running and interpreting the four analyzers. All are read-only; call them through MCP (see using-mechanic).
Related Commands
- c-audit - Full audit workflow
- c-review - Full review (lint, audit, tests, debug, clean)
- c-clean - Dead code and stale docs cleanup
- c-lint - Luacheck and StyLua only (no analyzers)
MCP Tools
| Task | MCP Tool |
|---|---|
| Security | addon.security(addon="MyAddon") |
| Complexity | addon.complexity(addon="MyAddon") |
| Deprecations | addon.deprecations(addon="MyAddon") |
| Dead code | addon.deadcode(addon="MyAddon") |
Common inputs: addon, path (override folder), categories (list; an unknown name fails with INVALID_CATEGORY), include_suspicious (deadcode/security; false keeps only higher-confidence findings), limit (default 200, max 2000).
Reading results
- Findings are capped at
limit, most severe first. Checktruncatedandtotal_issuesbefore concluding anything;summarycounts cover all issues. Raiselimitor filtercategoriesto see the rest. read_errorslists files that could not be read; a clean result with read errors is not clean.- The analyzers use a Lua tokenizer (comments and strings are not code), skip
Libs/(case-insensitive, relative to the addon root) and hidden folders. - Every finding has a confidence (
definite,likely,suspicious). Static analysis cannot see dynamic access (_G[name], event names built at runtime, XML-registered handlers), so verify before deleting or "fixing".
Categories
Security (addon.security)
| Category | Meaning |
|---|---|
combat_violation | Protected call without an InCombatLockdown() guard (low confidence by design: guards are often in callers) |
secret_leak | Values from APIs known to return secrets (12.0+) that are stored, logged or reused |
taint_risk | Globals created through _G/rawset(_G, ...) or without an addon namespace prefix |
unsafe_eval | loadstring/RunScript with variable input, addon messages executed directly |
addon_comm | Unvalidated addon-message parsing |
Complexity (addon.complexity)
| Category | Default threshold (input) |
|---|---|
deep_nesting | more than 5 nested blocks (max_nesting) |
long_function | more than 100 lines (max_function_lines) |
long_file | more than 500 lines (max_file_lines) |
magic_number | numeric literals of 10 or more outside obvious contexts |
duplicate_code | near-identical blocks of 10+ code lines |
Deprecations (addon.deprecations)
Inputs: category, min_severity (info / warning / error). The database ships as resources/deprecated_apis.json. It is currently a 3-API seed (GetAddOnInfo, IsAddOnLoaded, LoadAddOn -> C_AddOns.*) with "complete": false, and the command then returns the warning DEPRECATION_DB_LIMITED. A clean result means only "none of the known deprecated APIs", not "no deprecated APIs". For anything else, consult Blizzard's Blizzard_Deprecated source (s-research) and the addon-dev-guide. The database is regenerated with python -m mechanic.deprecations_builder <wow-ui-source path>; that step is pending a maintainer decision, so check database_version in the result (seed-1 or fallback means the limited seed).
Dead code (addon.deadcode)
unused_function, unused_local, orphaned_file (Lua file not in the TOC), dead_export (referenced only inside its own file), unused_library, stale_event, unused_locale, unreachable_code, commented_code.
Workflow
Quick: addon.security, then addon.deprecations(min_severity="error"), report. Full: security, complexity, deprecations, deadcode, then one prioritized report. Always state truncated/total_issues and the deprecation DB caveat.
Priority
- Critical: confirmed secret leaks, real combat-lockdown violations, deprecated APIs with
severity: error. - High: taint risks, orphaned files, deprecated APIs with
warning. - Medium: deep nesting, long functions/files, magic numbers.
- Low: duplicates,
suspiciousdead code, commented-out code.
Run before a release; verify each critical finding by reading the code, and by game evidence where behaviour is in question (s-debug).
When not to use it
- →When auditing non-WoW addon code
- →When environment lacks access to addon files
Limitations
- →Limited to static code analysis
How it compares
It automates the detection of WoW-specific deprecations and combat lockdown risks, which manual review might miss.
Compared to similar skills
s-audit side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| s-audit (this skill) | 0 | 9mo | No flags | Advanced |
| github-code-review | 13 | 4mo | Review | Advanced |
| reviewing-code | 21 | 10mo | No flags | Intermediate |
| reviewing-nextjs-16-patterns | 11 | 10mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by Falkicon
View all by Falkicon →You might also like
github-code-review
ruvnet
Comprehensive GitHub code review with AI-powered swarm coordination
reviewing-code
CaptainCrouton89
Systematically evaluate code changes for security, correctness, performance, and spec alignment. Use when reviewing PRs, assessing code quality, or verifying implementation against requirements.
reviewing-nextjs-16-patterns
djankies
Review code for Next.js 16 compliance - security patterns, caching, breaking changes. Use when reviewing Next.js code, preparing for migration, or auditing for violations.
cookbook-audit
anthropics
Audit an Anthropic Cookbook notebook based on a rubric. Use whenever a notebook review or audit is requested.
pr-review
pytorch
Review PyTorch pull requests for code quality, test coverage, security, and backward compatibility. Use when reviewing PRs, when asked to review code changes, or when the user mentions "review PR", "code review", or "check this PR".
find-bugs
davila7
Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.