AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Project Audit

skill-bglglzd-agent-workflows-project-audit · by bglglzd

Perform a deep, evidence-based, read-only audit of a software project. Use when Codex needs to map architecture, build and deployment paths, server posture, security risks, unfinished work, and prioritized remediation before proposing or making changes.

No reviews yet
0 installs
12 views
0.0% view→install

Install

$ agentstack add skill-bglglzd-agent-workflows-project-audit

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-bglglzd-agent-workflows-project-audit)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
26d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Project Audit? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Project Audit

Audit the project before changing it. Produce conclusions that a maintainer can verify from evidence.

Workflow

  1. Inventory tracked files and relevant untracked configuration. Identify stack, entry points, package manifests, tests, docs, scripts, CI/CD, containers, infrastructure, environment templates, and git state.
  2. Map the system: application and data flow, trust boundaries, auth and permissions, persistence, background jobs, external APIs, and user-facing surfaces.
  3. Map operations: configuration, local setup, build, test, deploy, monitoring, backup, rollback, and any server connection instructions found in the repository.
  4. Review security using the actual stack: secrets, input validation, authn/authz, dependency and supply-chain risk, file/network access, logging, errors, CI permissions, containers, and exposed configuration.
  5. Review engineering health: test coverage, reliability, performance hotspots, maintainability, documentation, TODOs, migrations, release process, and unfinished product work.
  6. Run only safe and relevant existing checks. Record each command and outcome; identify checks that could not run and why.

Safety boundary

  • Keep the audit read-only unless the user explicitly approves a fix.
  • Do not connect to servers, use credentials, call production APIs, scan networks, or run destructive commands without separate explicit authorization.
  • Do not reveal secrets or private data. Cite a redacted location instead.
  • Separate verified facts, reasonable concerns, and unknowns.

Required output

Return these sections: executive summary; scope and coverage; system map; build, test, deploy, and server posture; prioritized findings; quick wins; recommended roadmap; unknowns and excluded scope; and commands or sources inspected.

Rank findings P0–P3. Every finding needs evidence (path:line, configuration key, test result, or reproducible command), impact, smallest sensible fix, and validation method. End with the three highest-leverage actions and request approval before remediation.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.