Install
$ agentstack add skill-withkynam-vibecode-pro-max-kit-vc-audit-context ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Audit Context
> Output style: Follow process/development-protocols/communication-standards.md — answer-first, plain language, no unexplained jargon, TL;DR on long responses.
Use this skill to verify that the project's durable context layer is discoverable and organized.
Optional input: a context group, agent, skill, or folder scope to prioritize during the audit.
Workflow
- Run
find process/context/ -type f | sortto get the full file listing before routing.
This ensures no context file is silently skipped when the router is incomplete or drifted.
- Read
process/context/all-context.mdfor the context routing protocol. - Read
references/audit-context.mdfor the full audit process. - Run the context discovery validator:
``bash node .claude/skills/vc-audit-context/scripts/validate-context-discovery.mjs ` 3a. Run the protocol discovery frontmatter validator (enforces discovery frontmatter on every process/development-protocols/**/*.md, recursive incl. vc-system-behavior/; note.md is the only intentional exclusion): `bash node .claude/skills/vc-audit-context/scripts/validate-protocol-discovery.mjs ``
- Run the shared skill routing coverage validator:
``bash node .claude/skills/vc-audit-context/scripts/validate-skill-routing.mjs ``
- Run the skill cross-reference validator:
``bash node .claude/skills/vc-audit-context/scripts/validate-skill-cross-refs.mjs ``
- Run the skill dependency/confusable analysis:
``bash node .claude/skills/vc-audit-context/scripts/validate-skill-dependencies.mjs node .claude/skills/vc-audit-context/scripts/validate-confusable-skills.mjs ``
- Regenerate or check the machine-readable skill catalog:
``bash node .claude/skills/vc-audit-context/scripts/generate-skills-catalog.mjs --write node .claude/skills/vc-audit-context/scripts/generate-skills-catalog.mjs --check ``
- Validate that every SKILL.md carries
trigger_keywords+ a validlayer
(contract|helper) and that the catalog is in sync: ``bash node .claude/skills/vc-audit-context/scripts/validate-skill-keywords.mjs ``
- If any script reports failures, inspect the referenced files and patch the smallest
relevant surface.
- Re-run the failed validators until they pass.
For agent/skill harness validation (agent parity, skill frontmatter, README.md sync, protocol wiring), use the audit-vc skill.
Context Bootstrap (when process/context/ doesn't exist or needs full init)
Use when initializing a new project's context layer from scratch:
- Run
vc-scoutin parallel across major source directories (skip.git,node_modules,.claude, caches) to gather codebase summaries. - Create
process/context/all-context.md(routing table, architecture, conventions) and groupall-{group}.mdentrypoints for any durable domains identified. - Parallel reader strategy for existing context files — before updating, spawn subagents proportional to file count: 1-3 files read directly; 4-6 files use 2-3 reader agents; 7+ files use 4-5 reader agents (max 5), distributing by LOC.
- After generating or updating context files, run
find process/context -name '*.md' -print0 | xargs -0 wc -l | sort -rn— files over 800 LOC should be split into a context group or the user asked. - Finish by running the discovery validator (step 3 above) before declaring done.
Rules
- Treat
.claude/skills/as canonical;.agents/skills/is the Codex discovery symlink. - Treat
.claude/skills/vc-audit-context/references/skill-routing-policy.jsonas the explicit allowlist for intentionally non-routed shared skills. - Do not move large context files without updating
process/context/all-context.md. - Do not delete compatibility wrappers unless no current reference points to them.
- Keep context groups durable-domain based, not one group per temporary feature.
- When updating agents, mirror Claude markdown and Codex TOML surfaces together.
- Treat validator warnings as audit findings unless the user asks for a strict cleanup.
- Prefer validator-backed routing truth over adding more soft prose.
- Treat process/context/generated-skills-catalog.json as the machine-readable catalog owned by
audit-context.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: withkynam
- Source: withkynam/vibecode-pro-max-kit
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.