AI Agent Hub
Back to skills
Comprehensive Codebase Auditor icon

Comprehensive Codebase Auditor

Development Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please install @user_7871dce1/code-auditor-zh into your AI assistant according to https://skillhub.cn/install/skillhub.md.

About this skill

The Problem

Codebases tend to accumulate architecture drift, duplicated code, exposed secrets, and thin test coverage as features land. Manual review often stays inside a single function, while refactoring or security work needs a shared, repeatable view of the system. This skill turns a repository check into an audit-style deliverable: a prioritized issue list with severity and recommended action.

How It Works

The audit covers six dimensions:
- Architecture: module boundaries, dependency relationships, and coupling
- Code quality: naming conventions, duplicated code, and complexity
- Security: injection risks, weak authorization controls, and sensitive-data exposure
- Performance: inefficient queries, memory leaks, and unnecessary synchronization
- Testing: unit-test coverage and coverage of critical paths
- Maintainability: documentation completeness and change impact surface

It relies on read and exec to inspect repository content and run the checks needed for the audit. The output is usually structured like an engineering backlog: critical findings such as SQL concatenation or hard-coded tokens, moderate items such as missing input validation or circular dependencies, and lower-priority items such as low test coverage or overly long functions.

Boundaries

This is best used for pre-refactoring assessment, technical-debt triage, and an initial security review. It is not a replacement for a full SAST pipeline, performance load testing, or compliance auditing. For regulated systems, pair it with dedicated security scanners, architecture review, and a maintained testing strategy.

Use Cases

  • Run a health audit of a Node.js project before refactoring and get a prioritized issue list.
  • Check the codebase for security risks, focusing on authorization, sensitive data, and injection.
  • Inventory circular dependencies, duplicated code, and test coverage to guide sprint planning.
  • Assess maintainability by reviewing documentation completeness and change impact on critical paths.

Best For

  • Backend engineers preparing to refactor legacy modules need a view of coupling, debt, and fix priority.
  • Security engineers doing pre-release reviews need checks for authorization, exposed secrets, and injection points.
  • Tech leads taking over a project need a quick read on code health, test coverage, and documentation.
  • Full-stack engineers maintaining high-load services need help spotting performance bottlenecks and critical-path risks.