Skip to content
Back to skills

Audit Skills

ASecurity

Audit installed skills for observed usage, explicit-only invocation controls, duplicate discovery, and global-versus-project scope. Use only when the user explicitly invokes `$audit-skills`.

  • 3 stars
  • 0 votes
  • 0 copies
  • 4 views
  • Added August 31, 2026
ai-agentsbashgitsecurity

Works with

  • claude code
  • cursor

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add twikus/claude-configuration --skill audit-skills --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Audit Skills?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Audit Skills
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/twikus-audit-skills/badge)](https://www.skillsdirectory.com/skills/twikus-audit-skills)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: audit-skills
description: Audit installed skills for observed usage, explicit-only invocation controls, duplicate discovery, and global-versus-project scope. Use only when the user explicitly invokes `$audit-skills`.
argument-hint: "[audit|fix] [project-root]"
disable-model-invocation: true
---

Proceed only on an explicit `$audit-skills` invocation. Default `audit`; `fix` applies only high-confidence corrections after the ledger exists. Resolve `project-root` from the argument or current repo. Preserve unrelated dirty changes.

```bash
bun ~/.agents/skills/audit-skills/scripts/audit-skills.mjs --project "$PWD" --format markdown
```

Report every inventoried skill with scan coverage and one evidence class: `OBSERVED_USER`, `OBSERVED_MODEL`, `UNOBSERVED`, `EXPLICIT_ONLY`, `INVOCATION_MISMATCH`, `ORCHESTRATED_STAGE`, `ORCHESTRATION_BLOCKED`, `LOCALITY_CANDIDATE`, `NAME_COLLISION`. Cursor ACP stores are opaque. Do not label `UNOBSERVED` as never used without naming the scanned range.

Safe automatic fixes: drop `disable-model-invocation` from an `ORCHESTRATION_BLOCKED` stage; mirror an existing explicit-only decision across Claude/Codex, but never onto a stage another skill calls; add missing explicit-only controls when the skill text already requires direct invocation; repair stale move/rename metadata. Move a skill between scopes only with explicit user direction or a project-specific runtime dependency. Copy the full directory, rewrite self-paths, validate, `trash` the source, then confirm the name is discovered once.

A stage another skill calls stays model-invocable. Claude Code's `disable-model-invocation` forbids every model call, unlike Codex's `allow_implicit_invocation: false`, which still honours an explicit `$skill`. Treat the two as different controls, never as a mismatch to mirror.

Recommend rather than mutate unobserved skills. Protect incident, security, recovery, and migration skills from usage-only pruning.

Done when every skill has a row, every recommendation cites evidence, and — on `fix` — touched skills validate and Git status distinguishes this run.

Files in this skill

  • SKILL.md4.1 KB
  • agents/openai.yaml233 B
  • scripts/audit-skills.mjs13.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…