audit
Installation
SKILL.md
audit
Inspect and report first. Fix only after the user says yes.
Process
- Pin the target and scope.
ui/ux/code/safety, plus what to audit. If not given, default to the current diff or most recent work and state the assumption. - Inspect the real thing. For
uiandux, run the app and look at it — screenshots, clicked-through flows — not just source. Forcodeandsafety, read the actual call paths, not just the files that changed. - Sweep with the matching checklist below, then go past it: cross-cutting patterns, inconsistencies between areas, things the checklist wouldn't catch.
- Report (format below) and offer the fixes: "Want me to apply these?" The user can take all of them or pick by number.
Applying fixes (on approval)
- Smallest diff per finding; behavior stays the same — this raises quality, not functionality.
- Verify after: render the UI, walk the flow, run the code and tests.
- Safety findings too risky to patch inline (auth-model changes, migration rewrites) stay report-only — say so explicitly.
- Report what changed; anything approved but not fixed gets listed with the reason.