Zorille — Security skill for Claude Code
Four Claude Code skills for codebase hygiene: codebase-audit (find issues) + plan-fixes (turn issues into PR-sized plans, supports SARIF) + deps (dependency audit and risk-tiered updates across Go/Pyt.
How to install Zorille
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open boinger/zorille and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Zorille does
Four Claude Code skills for codebase hygiene: codebase-audit (find issues) + plan-fixes (turn issues into PR-sized plans, supports SARIF) + deps (dependency audit and risk-tiered updates across Go/Python/Node/etc.) + issue-forensics (rigorous upstream issue/PR drafts)
Alternatives in Security
- Migration Agent — Plans a token migration (format, tool, naming or tier): chains token-audit and naming-audit, builds the transf 194 ★
- Kali Pentest — Kali Linux penetration testing skill for AI agents (Claude Code, OpenClaw, Hermes Agent) 100 ★
- API Contract Review — API platform contract review 83 ★
README
zorille
Four Claude Code skills for finding what's wrong in a codebase you don't know and doing something useful about it: bugs, fix plans, dependency hygiene, and upstream-contribution forensics.
Four skills, one repo
/codebase-auditfinds problems. Cold-start audit of any codebase: bugs, security issues, architectural problems, tech debt, test gaps. Writes a structured report and abaseline.jsonfor regression tracking. Read-only by default; opt in to mechanical fixes with--quick-fix./plan-fixesturns problems into fix plans. Reads the baseline/codebase-auditwrites — or any SARIF 2.1.0 source (CodeQL, ESLint, Semgrep, Sonar, GitHub Code Scanning). Groups findings into PR-sized plans with depth-aware investigation: callers, tests, and adjacent context./depshandles dependency hygiene. Audit, update, and CVE remediation across Go, Python, Swift, Dart/Flutter, C#/.NET, and Node.js. Risk-tiered updates (critical → security → patch → minor) with test verification; never auto-bumps majors without approval. Standalone — doesn't require the audit/plan-fixes flow, but complements/codebase-audit's quick CVE scan with deeper investigation and remediation./issue-forensicsapplies investigative rigor to a non-trivial finding before you file an upstream issue or PR. Four-question entry gate routes routine fixes to a quick-report template; substantive findings get a five-pillar playbook: SHA-pinned permalinks, structural twins, history with stated-intent-vs-side-effect discipline, disproof of current design, exhaustive caller trace. Produces a structured draft modelled on a gold-standard exemplar. Companion to give-back for anti-squatting hold-and-release timing.
The slash commands are `/codebase-audit`, `/plan-fixes`, `/deps`, and `/issue-forensics` regardless of where you cloned the repo. (For the story behind the repo name, see the bottom of this file.)
What this solves
You inherited a codebase you don't know. You n
Related Skills
Massu Deps
Dependency audit covering security vulnerabilities, updates, and compatibility analysis
/deps
check all project dependencies for updates and security issues. one command, clean output
Cleanup Repo
Read-only repo audit for stale/orphaned files, tracked cruft, accidentally-committed secrets, empty files, and
Cca Audit
Parallel multi-agent code audit + fix pipeline for Claude Code. One tiered /audit-fix command auto-selects FAS
Audit End Sprint
End-of-sprint code audit — run 9-dimension sweep (security, quality, tests, dead code, TODO/FIXME, perf, docs,
Aeo Fixes
Turn the latest AEO audit into a prioritized, ordered fix list with the reason each item matters.
Related Agents
Impl Deps
Reviews implementation plans from a dependency management perspective. Use when evaluating crate selection, de
Deps
Manages dependency hygiene and automation via Renovate, plus audits and deduplication.
Automation Designer
Turn repeated tasks into the right artifact — script, skill, command, recipe, or API integration. Follows Thre