Audit — Security skill for Claude Code
Run a read-only system audit and report findings by severity.
How to install Audit
Installs to ~/.claude/skills/rohirik-claude-code-config-audit/SKILL.md
mkdir -p ~/.claude/skills/rohirik-claude-code-config-audit && curl -fsSL https://raw.githubusercontent.com/RohiRIK/claude-code-config/HEAD/commands/audit.md -o ~/.claude/skills/rohirik-claude-code-config-audit/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
What Audit does
description: "Run a read-only system audit and report findings by severity." disable-model-invocation: true
/audit — Read-Only System Auditor
Runs two isolated Gemini CLI instances (Flash + Pro) and produces a ranked findings report.
**IMPORTANT**: Strictly read-only. Only writes to `~/.claude/auditor/reports/`.
Modes
| Command | What it audits | Time |
|---|---|---|
/audit |
Core — rules, hooks, agents, settings.json, CLAUDE.md | ~2 min |
| `/audit |
Alternatives in Security
- Security Scan Report — Generated: 2026-04-10 20:48 UTC Skills scanned: 134 Total findings: 836 Critical: 32 High: 50 Safe skills: 100 18.1k ★
- Portaljs Check Data Quality — Audit a local or remote tabular file (CSV/TSV) for common data quality issues 2.3k ★
- /chain — Build an A→B→C exploit chain for higher severity and payout 927 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Repo Audit
Read-only four-phase repository audit covering discovery and mapping, evidence-based severity-rated findings,
Audit Report
Aggregate audit checkpoints into the final report — executive summary, Scope Coverage, findings by severity, m
Vf Review
Parallel Salesforce code review of the diff against a base ref - dispatch the quality gate and security review
Ext Report
Launch the ext-reporter agent to turn the external-pentest engagement artifacts (scope, inventory, attack plan
UX A11y
WCAG 2.1 AA accessibility audit plus common-courtesy checks beyond the spec. Produces findings grouped by WCAG
Chain Findings
Escalate low-severity findings into reportable vulnerabilities by building exploit chains (A→B→C)
Related Agents
Audit Reporter
Deterministic report assembly — aggregates verdicts and findings, builds the Scope Coverage table, severity ro
Perf Report Writer
Invoke last in a performance audit, after both perf-pattern-scanner and perf-complexity-analyzer have complete
Project Structure Reviewer
Read-only audit of the current repo against spec/project/project-structure/, producing a severity-sorted findi