Skip to content
Back to skills

Project Audit

ASecurity

Security scan, dead code detection, and code quality audit for any project

  • 530 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added May 29, 2026
ai-agentsgobashsqlnoderefactoringgitsecurity

Works with

  • terminal

Security analysis

A100/100

Scanned May 29, 2026

npx -y skills add vibeeval/vibecosystem --skill project-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Project Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Project Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/vibeeval-project-audit/badge)](https://www.skillsdirectory.com/skills/vibeeval-project-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: project-audit
description: "Security scan, dead code detection, and code quality audit for any project"
version: 1.0.0
category: quality
tags: [security, dead-code, audit, sast, quality]
---

# Project Audit

Automated security + quality scan for any codebase. Generates a report, then optionally auto-fixes safe issues.

## Usage

```bash
# Scan current directory
vibeco audit

# Scan specific path
vibeco audit /path/to/project

# Auto-fix safe issues (console.log removal)
vibeco audit --fix

# JSON output for CI integration
vibeco audit --json
```

## What It Scans

### Security (SAST)
- **CRITICAL**: eval(), exec(), execSync(), os.system(), subprocess, SQL injection patterns
- **HIGH**: innerHTML, dangerouslySetInnerHTML, document.write(), pickle.load(), hardcoded secrets
- **MEDIUM**: Sensitive data in console.log, MD5/SHA1 weak crypto

### Code Quality
- Large files (>500 lines)
- TODO/FIXME/HACK/XXX count
- Excessive console.log (>3 per file)

### Test Coverage
- Source file to test file ratio
- Test file detection (.test.ts, .spec.js, etc.)

### Dependencies
- Lock file presence check
- Node engine version check

## Output

### Terminal Report
Color-coded report with grade (A+ to F):
- A+: Zero issues
- A-: Only MEDIUM issues
- B: Some MEDIUM issues
- C: HIGH issues present
- D: Many HIGH issues
- F: CRITICAL issues present

### JSON Report
Saved to `.vibeco-audit.json` in project root. Contains all findings for programmatic processing.

## Auto-Fix (--fix)

Currently auto-fixes:
- Removes console.log statements from files with >3 occurrences

Does NOT auto-fix (manual review required):
- Security issues (too risky for automation)
- Large file refactoring
- TODO/FIXME resolution

## Workflow

```
1. vibeco audit          -> Scan, generate report
2. Review report         -> Understand issues
3. vibeco audit --fix    -> Auto-fix safe issues
4. Manual fixes          -> Address security findings
5. vibeco audit          -> Re-scan to verify
```

## Ignored Directories

node_modules, dist, .git, vendor, __pycache__, .next, build, coverage

## Ignored in Security Scan

Test files (*.test.ts, *.spec.js, __tests__/, __mocks__/) are excluded from security scanning to avoid false positives.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…