Comprehensive Codebase Auditor
Paste the following prompt into your AI chat to install this skill:
Please install @user_7871dce1/code-auditor-zh into your AI assistant according to https://skillhub.cn/install/skillhub.md.
About this skill
The Problem
Codebases tend to accumulate architecture drift, duplicated code, exposed secrets, and thin test coverage as features land. Manual review often stays inside a single function, while refactoring or security work needs a shared, repeatable view of the system. This skill turns a repository check into an audit-style deliverable: a prioritized issue list with severity and recommended action.
How It Works
The audit covers six dimensions:
- Architecture: module boundaries, dependency relationships, and coupling
- Code quality: naming conventions, duplicated code, and complexity
- Security: injection risks, weak authorization controls, and sensitive-data exposure
- Performance: inefficient queries, memory leaks, and unnecessary synchronization
- Testing: unit-test coverage and coverage of critical paths
- Maintainability: documentation completeness and change impact surface
It relies on read and exec to inspect repository content and run the checks needed for the audit. The output is usually structured like an engineering backlog: critical findings such as SQL concatenation or hard-coded tokens, moderate items such as missing input validation or circular dependencies, and lower-priority items such as low test coverage or overly long functions.
Boundaries
This is best used for pre-refactoring assessment, technical-debt triage, and an initial security review. It is not a replacement for a full SAST pipeline, performance load testing, or compliance auditing. For regulated systems, pair it with dedicated security scanners, architecture review, and a maintained testing strategy.
Use Cases
- Run a health audit of a Node.js project before refactoring and get a prioritized issue list.
- Check the codebase for security risks, focusing on authorization, sensitive data, and injection.
- Inventory circular dependencies, duplicated code, and test coverage to guide sprint planning.
- Assess maintainability by reviewing documentation completeness and change impact on critical paths.
Best For
- Backend engineers preparing to refactor legacy modules need a view of coupling, debt, and fix priority.
- Security engineers doing pre-release reviews need checks for authorization, exposed secrets, and injection points.
- Tech leads taking over a project need a quick read on code health, test coverage, and documentation.
- Full-stack engineers maintaining high-load services need help spotting performance bottlenecks and critical-path risks.
Related Skills
Analyzes code to extract control and data flow, then outputs Markdown with Mermaid source and high-resolution PNG diagrams.
For development and programming scenarios around VSCode and TypeScript IDE.
A TypeScript-oriented Windmill Wrap development reference.
A Python-based Selenium wrapper for engineering browser automation workflows.