workflow-codebase-audit
Installation
SKILL.md
Workflow: Codebase Audit (cold-start multi-domain sweep)
Announce at start: "Activating workflow-codebase-audit to run the cold-start audit sweep."
When to invoke
- Take-home or technical assessment requiring a broad codebase review.
- Post-acquisition or due-diligence review of an unfamiliar repo.
- Inherited-service onboarding: "I just took ownership of this, what's the state of it?"
- Pre-refactor tech-debt sweep across a monorepo or service.
When NOT to invoke
- Single-domain security audit → use
security-auditordirectly (depth-first, OWASP-focused). - Known bug with a repro → use
/swe-workbench:debug(root-cause + fix lifecycle). - PR diff review → use
/swe-workbench:revieworworkflow-pr-review. - Code already familiar; you know what to look for → run targeted tools directly.