Audit

Audit skills and workflows surfaced by the site skill importer.

66 skills
A
workspace-surface-audit

by affaan-m

workspace-surface-audit is a read-only audit skill for checking what a workspace and machine can do right now. It inspects the repo, MCP servers, plugins, connectors, env surfaces, and harness setup, then recommends the best ECC-native skills, hooks, agents, and workflows for Workflow Automation.

Workflow Automation
Favorites 0GitHub 156.3k
A
security-bounty-hunter

by affaan-m

security-bounty-hunter helps you find bounty-worthy vulnerabilities in repositories, with a focus on remotely reachable, user-controlled issues that are likely to survive triage. Use it for Security Audit work when you want practical reportable findings instead of noisy local-only concerns.

Security Audit
Favorites 0GitHub 156.3k
A
repo-scan

by affaan-m

repo-scan is a cross-stack source audit skill that classifies files, detects embedded third-party libraries, and helps you judge what is core, duplicated, or dead weight. It is useful for repo-scan for Code Review, legacy migrations, and refactor planning. See repo-scan install and repo-scan usage guidance in the skill.

Code Review
Favorites 0GitHub 156.2k
A
quality-nonconformance

by affaan-m

quality-nonconformance is a regulated-manufacturing skill for NCR intake, root cause analysis, CAPA, SPC interpretation, and final disposition. Use it for Compliance Review, supplier quality issues, and evidence-based decisions where traceability, risk, and audit-ready judgment matter.

Compliance Review
Favorites 0GitHub 156.2k
A
product-lens

by affaan-m

product-lens is a decision-support skill for validating the why before building, pressure-testing product direction, and turning vague requests into sharper briefs. Use product-lens when you need a quick product diagnosis, not a full spec, and want a clearer go/no-go answer before engineering planning.

Decision Support
Favorites 0GitHub 156.2k
A
healthcare-phi-compliance

by affaan-m

healthcare-phi-compliance helps review healthcare apps for PHI/PII risk across data models, APIs, logs, and access paths. Use it to check data classification, access control, encryption, audit trails, and common leak vectors for HIPAA, DISHA, GDPR, and related security audit needs.

Security Audit
Favorites 0GitHub 156.2k
A
ecc-tools-cost-audit

by affaan-m

ecc-tools-cost-audit is an evidence-first audit skill for ECC Tools cost spikes, runaway PR creation, quota bypass, premium-model leakage, and duplicate jobs. Use it for Backend Development investigations that trace a request from webhook to worker to billing decision and prove where spend is being created.

Backend Development
Favorites 0GitHub 156.1k
A
click-path-audit

by affaan-m

The click-path-audit skill helps trace UI handlers through every state change to catch sequence bugs, shared-state collisions, and final-state mismatches after refactors or during code review.

Code Review
Favorites 0GitHub 156.1k
A
automation-audit-ops

by affaan-m

automation-audit-ops is an evidence-first automation inventory and overlap audit skill for Workflow Automation. Use it to identify which jobs, hooks, connectors, MCP servers, or wrappers are live, broken, redundant, or missing before fixing anything.

Workflow Automation
Favorites 0GitHub 156.1k
G
cso

by garrytan

cso is a Chief Security Officer–style security audit skill for agents. It helps review codebases and workflows for secrets exposure, dependency and supply-chain risk, CI/CD security, and LLM/AI security using OWASP Top 10 and STRIDE. Use cso for structured Security Audit reviews with confidence gates, active verification, and trend tracking.

Security Audit
Favorites 0GitHub 91.8k
G
design-review

by garrytan

design-review is a UX-minded design QA skill for auditing live interfaces, spotting spacing, hierarchy, visual consistency, and interaction issues, then fixing them iteratively with verification. It supports plan-mode review before implementation and is useful when you want a design-review guide for concrete source changes instead of vague advice.

UX Audit
Favorites 0GitHub 91.8k
W
accessibility-compliance

by wshobson

The accessibility-compliance skill helps teams audit and improve web or mobile UI with practical WCAG 2.2, ARIA, keyboard access, screen reader, and mobile accessibility guidance. Best for UX audits, component fixes, and implementation-ready recommendations.

UX Audit
Favorites 0GitHub 32.6k
W
security-requirement-extraction

by wshobson

security-requirement-extraction turns threat models and business context into testable security requirements, user stories, acceptance criteria, and backlog-ready outputs for Requirements Planning.

Requirements Planning
Favorites 0GitHub 32.6k
W
stride-analysis-patterns

by wshobson

stride-analysis-patterns helps agents run a structured STRIDE threat-modeling pass for architectures, APIs, and data flows. Install from the wshobson/agents repo, read the SKILL.md file, and use it to turn system descriptions into categorized threats and control-focused review output.

Threat Modeling
Favorites 0GitHub 32.6k
W
threat-mitigation-mapping

by wshobson

The threat-mitigation-mapping skill helps map identified threats to preventive, detective, and corrective controls across layers, supporting defense-in-depth, remediation planning, and control coverage review.

Threat Modeling
Favorites 0GitHub 32.6k
W
pci-compliance

by wshobson

Use the pci-compliance skill to guide PCI DSS architecture reviews, scope reduction, gap analysis, and payment data handling decisions. Best for teams designing payment flows, preparing for assessments, or reviewing controls before a compliance review.

Compliance Review
Favorites 0GitHub 32.6k
W
gdpr-data-handling

by wshobson

The gdpr-data-handling skill helps teams turn GDPR requirements into practical review guidance for consent, lawful basis, data subject rights, retention, and privacy-by-design decisions.

Compliance Review
Favorites 0GitHub 32.5k
W
wcag-audit-patterns

by wshobson

wcag-audit-patterns is a structured WCAG 2.2 audit skill for accessibility reviews. Use it to combine automated findings with manual checks, prioritize issues by severity and conformance level, and generate actionable remediation guidance for pages, flows, and components.

UX Audit
Favorites 0GitHub 32.5k
G
ai-prompt-engineering-safety-review

by github

ai-prompt-engineering-safety-review is a prompt audit skill for reviewing LLM prompts for safety, bias, security weaknesses, and output quality before production, evaluation, or customer-facing use.

Model Evaluation
Favorites 0GitHub 27.8k
G
agent-governance

by github

agent-governance is a documentation-first skill for designing AI agent guardrails, policy checks, trust rules, tool restrictions, and audit logging for tool-using and multi-agent systems.

Agent Standards
Favorites 0GitHub 27.8k
C
seo-audit

by coreyhaines31

seo-audit is a structured SEO review skill for diagnosing crawlability, indexation, technical, on-page, and content issues. It helps agents ask for site context, follow a clear audit order, avoid unsupported schema claims, and turn findings into a prioritized action plan.

SEO Content
Favorites 0GitHub 17.3k
C
page-cro

by coreyhaines31

page-cro is a CRO skill for reviewing marketing pages and finding practical ways to improve conversions. Use it to analyze landing, pricing, homepage, feature, and blog pages with clear input on goal, traffic source, audience, and blockers. Includes install guidance, workflow tips, prompt examples, and experiment-focused usage.

Conversion
Favorites 0GitHub 17.3k
C
free-tool-strategy

by coreyhaines31

free-tool-strategy helps Product Marketing and growth teams evaluate whether to build a free marketing tool, compare calculators, graders, analyzers, or generators, and define MVP scope, gating, and implementation tradeoffs. Includes repo-based install context, key files, and practical usage guidance.

Product Marketing
Favorites 0GitHub 17.3k
C
form-cro

by coreyhaines31

form-cro is a skill for auditing and improving non-signup forms like lead, contact, demo request, application, survey, quote, and checkout-style forms. It helps teams reduce field friction, diagnose abandonment, and restructure forms using repo-backed guidance, eval examples, and a clear install and usage path.

Conversion
Favorites 0GitHub 17.3k