code-audit
reviewing code for quality, security, and performance issues
no-skill baseline: 46% — anything below it makes the model worse.
⚖ Measured verdict: the base model already handles this capability well — every tested candidate degraded output. Recommended: no artifact at all for this step.
1WORKS 60★852WORKS 60★03WORKS 60★04WORKS 60★25WORKS 60★56WORKS 60★1357WORKS 59★168WORKS 59★9,7269WORKS 59★38110WORKS 59★17,46411WORKS 58★012WORKS 58★013WORKS 58★29214WORKS 58★115WORKS 57★2916WORKS 57★17,46417WORKS 57★3,03518WORKS 57★019WORKS 57★020WORKS 56★3521WORKS 56★38122WORKS 56★3,03523WORKS 56★27324WORKS 55★425WORKS 55★026WORKS 55★127WORKS 55★38128WORKS 55★7229WORKS 55★230WORKS 55★031WORKS 55★032WORKS 55★033WORKS 55★034WORKS 55★035WORKS 55★7636WORKS 55★137WORKS 55★338WORKS 55★1,10439WORKS 55★3440WORKS 54★041WORKS 54★17,46442WORKS 54★38143WORKS 54★144WORKS 54★045WORKS 54★1,72146WORKS 53★8147WORKS 53★38148WORKS 53★049WORKS 53★850WORKS 53★2651WORKS 53★052WORKS 52★377,53653WORKS 52★79554WORKS 52★10055WORKS 52★056WORKS 51★17,46457WORKS 51★3,03558WORKS 51★38159WORKS 51★060WORKS 51★1061WORKS 51★162WORKS 51★263WORKS 51★3464WORKS 51★19965WORKS 50★166WORKS 50★067WORKS 49★068WORKS 49★269WORKS 49★070WORKS 49★371WORKS 49★072WORKS 48★1,03373WORKS 48★574WORKS 48★075WORKS 48★476WORKS 48★177WORKS 47★078WORKS 47★12079WORKS 45★080WORKS 45★33081WORKS 45★3,03582WORKS 45★083WORKS 45★184WORKS 44★485WORKS 44★3586WORKS 44★087WORKS 41★6488WORKS 41★189WORKS 31★41290WORKS 31★091WORKS 27★2,11992WORKS 22★0
code_auditworkflowdefault
Parallel 3-phase security/style/synthesis audit with cross-file pattern detection.
analyze-codebaseworkflow
Workflow for analyze-codebase
dependency-auditworkflow
Security and compatibility audit of dependency trees with CVE verification.
smellsworkflow
Finding code regressions and systemic patterns across large codebases in batch.
level-upworkflow
Feature promotion workflows where maturity gates and dependency checks are critical
adlc-sprintworkflow
Processing batches of items through concurrent, scoped review stages with per-item result collection.
pipeline-reviewworkflow
Processing batches of items through concurrent, scoped review stages with per-item result collection.
code-reviewerskill
When you need systematic code review for bugs, security, and quality improvements.
ecosystem-alignmentskill
Keeping a custom Claude Code setup in sync with upstream platform updates, preventing drift and discovering new capabilities to adopt.
engineering-skillsplugin
When shipping production-grade code requires discipline across architecture, testing, deployment, and security domains rather than isolated linting.
code-reviewskill
Systematic identification of bugs and refactoring opportunities in pull requests.
plan-auditskill
Catching gaps and codebase drift in a plan when stakes warrant independent verification beyond same-context red-teaming with clean-context subagent.
crcommand
Catching language-specific bugs and design issues before commit by applying both project-local and generic review profiles to changed code.
code-reviewersubagent
Structured peer review of code changes before merge, catching bugs and style violations early
nuclear-reviewworkflow
Comprehensive codebase audits where structural issues must be prioritized and mapped across modules.
plugin-auditskill
Gate skill publication by enforcing consistent structure without manual 8-phase checklists
gsd:code-reviewskill
Finishing a phase when you want machine-assisted code quality review before merging, with control over depth vs time.
audit-servicesworkflow
workflow automation in specialized problem domain; check artifact name and description.
audit-pipeline-lockstepworkflow
Best for orchestrating parallel multi-phase work.
data-provenanceskill
Publishing genomics workflows where 'we aligned with STAR' is too vague—lock down exact versions, genomes, parameters, and accessions for publication-ready methods.
quality-reviewingskill
Catching ecosystem mismatches before they reach production; complements automatic hook with external verification.
bitbucket-automationskill
Automating code review workflows and branch management in Bitbucket when you're in a git-centric org using Atlassian stack
dashclaw-preship-sweepworkflow
Running go/no-go pre-deployment checks in parallel with cost-optimized model routing (cheap + expensive gates).
dependency-auditworkflow
Monthly per repo, before major releases, or when adding a significant new dependency. Surface critical security findings
agent-architecture-auditskill
Reviewing multi-agent system design for coupling, messaging patterns, and safety boundaries.
review-changesskill
Pull-request review of Android code when Kotlin correctness, lifecycle safety, and SDK integration must be jointly assessed before merge.
sonarqube-scanskill
Automated code quality gates in CI/CD to detect security vulnerabilities, bugs, and technical debt before code reaches production.
sourcesage-cliskill
Quickly documenting codebases for AI context or team onboarding without manual summarization.
migration-auditworkflow
Discovering quality gaps across multiple architecture and compliance dimensions.
dev-workflowworkflow
Orchestrating end-to-end ticket-to-PR cycles with parallel code review and automated fix loops.
auto-elevate-discoverworkflow
Automating multi-phase task execution with agents.
cross-component-reviewworkflow
Multi-perspective code review with adversarial voting and automated fix application.
dependency-upgradeworkflow
fan-out parallel research with synthesized results
review-fix-loopworkflow
Automated code review with structured feedback loops.
codebase-auditworkflow
Comprehensive codebase health check covering structure, dependencies, and quality before release.
pm-auditworkflow
Comprehensive review of codebase/content with structured audit findings.
mishkan-codebase-auditworkflow
Periodic project-wide audits, pre-release reviews, post-incident hardening passes.
review-agentsubagent
Before merging, when you need a senior engineer review catching correctness bugs, security issues, and maintainability problems.
forgeplugin
Multi-file refactors, full-stack features, or spec-driven work where parallel validation and retry beat sequential manual oversight.
codebase-onboardingskill
Bootstrapping documentation for an unfamiliar codebase when you need structure before reading individual files.
ship-gateskill
Preventing production incidents by systematically auditing security, database, and code quality before deploy.
code-reviewskill
Post-implementation review to catch security issues, bugs, and code quality gaps before merge.
security-reviewskill
Identifying security vulnerabilities and compliance risks in code diffs before merge.
site-auditworkflow
workflow automation in specialized problem domain; check artifact name and description.
audit-projectplugin
Enforcing zero-defect standards on medium codebases where iterative polish beats single-pass review.
token-doctorskill
Identifying spend concentrations and antipatterns when your Claude bill is unexpectedly high.
react-doctorskill
Quick after-change validation in React projects when a fast score + actionable fixes matter more than deep architectural review.
java-concurrency-reviewskill
When auditing Java code for race conditions, deadlocks, and thread safety.
reviewskill
Catching real bugs in code changes before PR merge, with proof and concrete fixes
review-generatorsubagent
After code implementation to document changes, verify tasks completed, and create reviewer checklists
code-review-expertsubagent
When you need mandatory code review before commit, catching security, type hints, and architecture violations.
autoreviewskill
Code review just before commit/ship when you need advisory findings verified against real dependencies.
code-health-checkskill
Regular codebase audits to catch health degradation before it blocks features.
pr-review-analystsubagent
When evaluating automated code review comments for correctness using full codebase context.
securitysubagent
Auditing code for authorization, RLS, and authentication vulnerabilities before launch.
code-reviewerskill
reviewing pull requests, analyzing code quality, identifying issues, generating review checklists.
code-healthskill
Scanning codebases for dead code, tech debt, and vulnerabilities in a single command without manual code review
find-bugsskill
Thorough security checklist + bug audit when you need systematic attack-surface mapping before merge.
dispatch-cycleworkflow
Automating the full developer→CR→ship cycle with structured gating and audit trail.
simplifyworkflow
Detecting hidden reuse opportunities and efficiency bugs across changed code in one pass.
codebase-surveyworkflow
Onboarding or refactoring when you want a comprehensive structure survey without running code.
checkcommand
Full-pipeline code validation with automatic style and format fixes.
vibe-checkcommand
Pre-commit quality check when AI agents have contributed code
behaviortree-reviewersubagent
Auditing BehaviorTree.CPP nodes for non-blocking ticks and correct base-class choice.
code-reviewskill
When you need multi-level code review before merging high-risk changes.
sast-analysisskill
When auditing source code in CI/CD or pre-release security review.
slopeskill
When you need to prioritize refactoring and identify hot spots in a large codebase
audit-quality-gatesskill
Identify linting rule gaps and tool suppression abuse in legacy projects without modifying code.
READMEsubagent
Parallel auditing of unfamiliar legacy code when multiple specialists are needed.
quality-reviewersubagent
Universal PR quality checks when no role-specific reviewer exists.
pr-cleanup-reviewersubagent
Addressing test failures and reviewer feedback systematically with detailed GitHub updates.
codebase-auditskill
Building production codebase-audit applications with best practices.
kotlin-idiom-reviewworkflow
Automated code review with structured feedback loops.
multi-reviewworkflow
Automated code review with structured feedback loops.
ccommand
Fast codebase orientation using large-context language model analysis.
architectsubagent
Auditing code for authorization, RLS, and authentication vulnerabilities before launch.
codebase-analystsubagent
Onboarding to unfamiliar codebases or assessing code health before major refactors
code-reviewersubagent
Enforcing project-specific code standards across all PR changes.
repo-scanskill
onboarding a legacy codebase, planning a refactor, or auditing embedded dependencies across C++, Android,
doctorskill
Run automated health checks and linting rules against codebase without manual review.
gsd:review-backlogskill
Systematically triaging project tasks and surfacing critical path blockers.
audit-skillskill
reviewing pull requests for production readiness
review-stylesubagent
When evaluating code clarity and idioms before merging pull requests.
project-pull-requestskill
Creating GitHub PRs with required templates, security reviews, and conventional commit standards.
code-review-part-4-three-state-verification-phasesubagent
Providing subagent-level automation for code review part 4 three state verification phase tasks.
adr-authorsubagent
Auditing code for authorization, RLS, and authentication vulnerabilities before launch.
code-reviewskill
When reviewing prs or checking code quality.
codebase-auditworkflow
Auditing codebases when you need whole-repo cross-slice analysis (orphans, duplication, dead code, architecture drift, HARD-RULE compliance).
developer-growth-analysisskill
Developers who want structured, evidence-based feedback on their work growth without waiting for code reviews, using their actual recent project history as the signal.
codacy-mcpmcp_server
Continuous integration pipelines auditing code quality and security across teams.
sprint-statuscommand
Quick snapshot of progress across parallel Claude Code sessions before switching contexts.
bitbucket-mcp-servermcp_server
Code review and PR workflows on Bitbucket Cloud or Server.