Audit

Audit skills and workflows surfaced by the site skill importer.

77 skills
A
workspace-surface-audit

by affaan-m

workspace-surface-audit is a read-only audit skill for checking what a workspace and machine can do right now. It inspects the repo, MCP servers, plugins, connectors, env surfaces, and harness setup, then recommends the best ECC-native skills, hooks, agents, and workflows for Workflow Automation.

Workflow Automation
Favorites 0GitHub 156.3k
A
security-bounty-hunter

by affaan-m

security-bounty-hunter helps you find bounty-worthy vulnerabilities in repositories, with a focus on remotely reachable, user-controlled issues that are likely to survive triage. Use it for Security Audit work when you want practical reportable findings instead of noisy local-only concerns.

Security Audit
Favorites 0GitHub 156.3k
A
repo-scan

by affaan-m

repo-scan is a cross-stack source audit skill that classifies files, detects embedded third-party libraries, and helps you judge what is core, duplicated, or dead weight. It is useful for repo-scan for Code Review, legacy migrations, and refactor planning. See repo-scan install and repo-scan usage guidance in the skill.

Code Review
Favorites 0GitHub 156.2k
A
quality-nonconformance

by affaan-m

quality-nonconformance is a regulated-manufacturing skill for NCR intake, root cause analysis, CAPA, SPC interpretation, and final disposition. Use it for Compliance Review, supplier quality issues, and evidence-based decisions where traceability, risk, and audit-ready judgment matter.

Compliance Review
Favorites 0GitHub 156.2k
A
product-lens

by affaan-m

product-lens is a decision-support skill for validating the why before building, pressure-testing product direction, and turning vague requests into sharper briefs. Use product-lens when you need a quick product diagnosis, not a full spec, and want a clearer go/no-go answer before engineering planning.

Decision Support
Favorites 0GitHub 156.2k
A
healthcare-phi-compliance

by affaan-m

healthcare-phi-compliance helps review healthcare apps for PHI/PII risk across data models, APIs, logs, and access paths. Use it to check data classification, access control, encryption, audit trails, and common leak vectors for HIPAA, DISHA, GDPR, and related security audit needs.

Security Audit
Favorites 0GitHub 156.2k
A
ecc-tools-cost-audit

by affaan-m

ecc-tools-cost-audit is an evidence-first audit skill for ECC Tools cost spikes, runaway PR creation, quota bypass, premium-model leakage, and duplicate jobs. Use it for Backend Development investigations that trace a request from webhook to worker to billing decision and prove where spend is being created.

Backend Development
Favorites 0GitHub 156.1k
A
click-path-audit

by affaan-m

The click-path-audit skill helps trace UI handlers through every state change to catch sequence bugs, shared-state collisions, and final-state mismatches after refactors or during code review.

Code Review
Favorites 0GitHub 156.1k
A
automation-audit-ops

by affaan-m

automation-audit-ops is an evidence-first automation inventory and overlap audit skill for Workflow Automation. Use it to identify which jobs, hooks, connectors, MCP servers, or wrappers are live, broken, redundant, or missing before fixing anything.

Workflow Automation
Favorites 0GitHub 156.1k
G
design-review

by garrytan

design-review is a UX-minded design QA skill for auditing live interfaces, spotting spacing, hierarchy, visual consistency, and interaction issues, then fixing them iteratively with verification. It supports plan-mode review before implementation and is useful when you want a design-review guide for concrete source changes instead of vague advice.

UX Audit
Favorites 1GitHub 91.8k
G
cso

by garrytan

cso is a Chief Security Officer–style security audit skill for agents. It helps review codebases and workflows for secrets exposure, dependency and supply-chain risk, CI/CD security, and LLM/AI security using OWASP Top 10 and STRIDE. Use cso for structured Security Audit reviews with confidence gates, active verification, and trend tracking.

Security Audit
Favorites 0GitHub 91.8k
W
accessibility-compliance

by wshobson

The accessibility-compliance skill helps teams audit and improve web or mobile UI with practical WCAG 2.2, ARIA, keyboard access, screen reader, and mobile accessibility guidance. Best for UX audits, component fixes, and implementation-ready recommendations.

UX Audit
Favorites 0GitHub 32.6k
W
security-requirement-extraction

by wshobson

security-requirement-extraction turns threat models and business context into testable security requirements, user stories, acceptance criteria, and backlog-ready outputs for Requirements Planning.

Requirements Planning
Favorites 0GitHub 32.6k
W
stride-analysis-patterns

by wshobson

stride-analysis-patterns helps agents run a structured STRIDE threat-modeling pass for architectures, APIs, and data flows. Install from the wshobson/agents repo, read the SKILL.md file, and use it to turn system descriptions into categorized threats and control-focused review output.

Threat Modeling
Favorites 0GitHub 32.6k
W
threat-mitigation-mapping

by wshobson

The threat-mitigation-mapping skill helps map identified threats to preventive, detective, and corrective controls across layers, supporting defense-in-depth, remediation planning, and control coverage review.

Threat Modeling
Favorites 0GitHub 32.6k
W
pci-compliance

by wshobson

Use the pci-compliance skill to guide PCI DSS architecture reviews, scope reduction, gap analysis, and payment data handling decisions. Best for teams designing payment flows, preparing for assessments, or reviewing controls before a compliance review.

Compliance Review
Favorites 0GitHub 32.6k
W
gdpr-data-handling

by wshobson

The gdpr-data-handling skill helps teams turn GDPR requirements into practical review guidance for consent, lawful basis, data subject rights, retention, and privacy-by-design decisions.

Compliance Review
Favorites 0GitHub 32.5k
W
wcag-audit-patterns

by wshobson

wcag-audit-patterns is a structured WCAG 2.2 audit skill for accessibility reviews. Use it to combine automated findings with manual checks, prioritize issues by severity and conformance level, and generate actionable remediation guidance for pages, flows, and components.

UX Audit
Favorites 0GitHub 32.5k
G
ai-prompt-engineering-safety-review

by github

ai-prompt-engineering-safety-review is a prompt audit skill for reviewing LLM prompts for safety, bias, security weaknesses, and output quality before production, evaluation, or customer-facing use.

Model Evaluation
Favorites 0GitHub 27.8k
G
agent-governance

by github

agent-governance is a documentation-first skill for designing AI agent guardrails, policy checks, trust rules, tool restrictions, and audit logging for tool-using and multi-agent systems.

Agent Standards
Favorites 0GitHub 27.8k
A
qms-audit-expert

by alirezarezvani

qms-audit-expert is an ISO 13485 internal audit skill for medical device QMS teams. It supports risk-based audit planning, clause checklists, nonconformity classification, CAPA verification, external audit prep, and schedule optimization using included references and a Python tool.

Quality Management
Favorites 0GitHub 22.2k
A
gdpr-dsgvo-expert

by alirezarezvani

gdpr-dsgvo-expert helps agents run GDPR/DSGVO Compliance Review with code scans, DPIA drafting, audit guidance, BDSG references, and DSAR deadline tracking. Use it to surface privacy risks and prepare evidence for DPO or legal review.

Compliance Review
Favorites 0GitHub 22.2k
A
review

by alirezarezvani

review audits Claude Code auto-memory in MEMORY.md to find promotion candidates, stale references, duplicates, consolidation opportunities, and health checks for Context Engineering workflows.

Context Engineering
Favorites 0GitHub 22.1k
A
iso27001-audit-prep

by alirezarezvani

iso27001-audit-prep is a focused ISO 27001 ISMS audit readiness skill. It uses six forcing questions to pressure-test scope, risk register freshness, Annex A linkage, management review, corrective actions, and sample-ready evidence before internal, certification, or surveillance audits.

Compliance Review
Favorites 0GitHub 22.1k