Install
$ agentstack add skill-kriscard-skills-audit ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Dotfiles Audit
Full health check of the dotfiles setup. Run all steps in order — each takes seconds and together they give a complete picture.
Security check runs first: it's always highest priority.
Step 0: Security Scan
Scan for credentials before anything else.
# API keys, tokens, passwords in config files
grep -rE "(API_KEY|TOKEN|SECRET|PASSWORD)\s*=\s*['\"][^'\"]+['\"]" ~/.dotfiles/ 2>/dev/null
# Common token prefixes
grep -rE "(ghp_|sk-|AKIA|-----BEGIN.*PRIVATE KEY-----)" ~/.dotfiles/ 2>/dev/null
Flag any findings as CRITICAL — credentials in dotfiles can leak via git.
File permission check — these should be 600:
stat -f "%A %N" ~/.dotfiles/.gitconfig-work ~/.dotfiles/.gitconfig-personal 2>/dev/null
Git safety — verify .gitignore in the dotfiles repo includes:
.env,*_token,*_secret,99-local.zsh,**/*.local.*
Step 1: Shell Startup Time
time zsh -i -c exit
Target: 500ms means something is blocking during interactive init.
If slow, isolate which zsh.d file is the culprit:
# Add timing to each zsh.d file temporarily
for f in ~/.zsh.d/*.zsh; do
time zsh -c "source $f" 2>&1 | grep real
echo " ^ $f"
done
Step 2: Zsh Plugins Audit
Check ~/.dotfiles/zsh/.zshrc and ~/.dotfiles/zsh/zsh.d/ for plugin loading (zinit, antigen, oh-my-zsh, etc.).
Flag heavy plugins:
- Large completion frameworks loaded synchronously
nvm/rbenv/pyenvwith eager shell integration (use lazy variants)- Any plugin that makes network calls or spawns subprocesses at init
Step 3: Stow Symlink Health
# Find broken symlinks in home directory (depth 3 to avoid scanning everything)
find ~ -maxdepth 3 -type l ! -e 2>/dev/null
A broken symlink means the stow source file was deleted or moved without re-stowing. Fix: either restore the source file or stow -D to remove the dead link.
Step 4: Neovim Startup Time
nvim --headless --startuptime /tmp/nvim-startup.log +q && sort -k2 -n /tmp/nvim-startup.log | tail -20
Target: 300ms needs investigation.
Check which plugins are loading eagerly: the top entries after sorting are the slowest. Cross-reference against the plugin list to find candidates for lazy-loading.
Step 5: Tool Inventory Check
Verify tools referenced in dotfiles are actually installed:
which sesh tmux yabai starship lazygit gh bat fd rg zoxide fzf
Any not found means either:
- The tool was uninstalled but its config is still in dotfiles (orphan config)
- The tool isn't installed yet on this machine (new machine setup)
Step 6: Orphan Config Detection
Cross-reference ls ~/.dotfiles/ (stow packages) against the tools found in Step 5. A package with no corresponding installed binary is an orphan.
ls ~/.dotfiles/
Review each package: if the tool it configures isn't installed and you're not planning to use it, consider archiving the package or adding a note.
Report Format
After running all steps, produce a report:
DOTFILES AUDIT REPORT
=====================
Security
🔴 Critical: [N issues] / ✅ Clean
[List any credential finds with file:line]
[File permission issues]
[Git safety gaps]
Startup Times
Shell: Xms (target (orphan or needs install)
Recommended Cleanups (priority order)
1. [most impactful fix — security first, then startup time, then cosmetic]
2. ...
Security issues always rank first regardless of other findings.
References
| Priority | Load when | Reference | |----------|-----------|-----------| | High | Security scan finds issues or credential patterns need review | references/security-patterns.md | | High | Shell startup is slow and needs profiling strategies | references/shell-performance.md | | High | Deep component-by-component analysis needed | references/component-analysis.md | | Medium | Broad pattern reference for security, perf, and tool integration | references/analysis-patterns.md | | Low | Git config issues found (permissions, multi-identity) | references/git-config.md |
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: kriscard
- Source: kriscard/Skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.