Install
$ agentstack add skill-philoserf-claude-code-config-code-audit ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Review this codebase for bugs, design issues, and code cleanliness problems. Be specific and cite file paths and line numbers.
Scope the review to $ARGUMENTS if provided, otherwise review the entire project. Examples: src/auth/, lib/api.ts, security, tests/.
What to look for
Prioritize by severity:
| Severity | Category | | ------------ | --------------------------------------------------------- | | Critical | Security vulnerabilities, data loss, crashes | | High | Correctness bugs, missing error handling, race conditions | | Medium | Design issues, code smells, missing validation | | Low | Style inconsistencies, naming, minor cleanup |
Process
For each issue found:
- Check for duplicates in both GitHub issues (
gh issue list) and the local.issues/directory - Skip if a matching issue already exists
- Otherwise, create a markdown file in
.issues/with a descriptive kebab-case filename
Each issue file should follow this format:
# Title
**Severity:** critical | high | medium | low
**Location:** `file:line`
## Description
What's wrong and why it matters.
## Suggested fix
Concrete recommendation.
Summary
After creating all issue files, output a summary:
| # | Severity | File:Line | Issue |
|---|----------|-----------|-------|
| 1 | high | src/a.ts:42 | Missing null check |
| 2 | medium | lib/b.py:17 | Bare except clause |
Total: {N} issues ({critical} critical, {high} high, {medium} medium, {low} low)
Files created in .issues/
Do not use when
- Reviewing harness customizations (skills, hooks, agents) — use
cc-review - Reviewing a specific staged or branch diff — use
diff-review - Building a prioritized backlog across the whole project — use
tech-debt
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: philoserf
- Source: philoserf/claude-code-config
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.