Phx audit
Skill oliver-kriska/claude-elixir-phoenix/targets/pi/skills/phx-audit
Claude Code plugin for Elixir/Phoenix/LiveView — 20 specialist agents, Iron Laws enforcement, and Tidewave MCP integration. Plan features with parallel research agents, execute with automatic verification, review with 4-agent parallel audits, and capture learnings as reusable knowledge.
npx -y skills add oliver-kriska/claude-elixir-phoenix --skill phx-auditAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
What its author says it does
Copied from the file, not written here
Project health audit and health check — architecture, performance, tests, dependencies, code quality. Use when assessing overall project health, before releases, or after refactors.
SKILL.md
4.1 KB, as published. Nobody here has run it
Project Health Audit
Comprehensive project-wide health assessment across five independent concern tracks.
Usage
/skill:phx-audit # Full audit (default)
/skill:phx-audit --quick # 2-3 minute pulse check
/skill:phx-audit --focus=security # Deep dive single area
/skill:phx-audit --focus=performance
/skill:phx-audit --since abc123 # Incremental audit since commit
/skill:phx-audit --since HEAD~10 # Audit last 10 commits
When to Use
- Quarterly health checks
- Before major releases
- After large refactors
- New team member onboarding (understand codebase health)
Iron Laws
- Complete every selected track before synthesizing — partial results make cross-category scores misleading
- Scope each track to concrete directories and checks — vague project-wide analysis produces generic findings
- Never compare scores across projects — track trends only within the same codebase
- Run quick mode before full mode — catch basic failures before expensive analysis
Portable Audit Workflow
- Create
.claude/audit/reports/and.claude/audit/summaries/. - Run the quick checks below. Stop and report a blocker when the project cannot compile or its test command cannot start.
- Complete five tracks: architecture, performance, security, tests, and dependencies. Native generic workers may run independent tracks in parallel when the runtime provides them; otherwise run every track sequentially in this session. Never require named custom agents.
- Write one evidence-focused report per track under
.claude/audit/reports/. Report issues only, cite paths and lines, and use one summary line for a clean area. - After all selected reports exist, deduplicate findings, identify
cross-category correlations, calculate scores using
references/scoring-methodology.md, and write.claude/audit/summaries/project-health-{date}.md.
If two or more optional workers fail or hit limits, finish the missing tracks sequentially. Never present an incomplete track as audited.
Output Format
Report an executive health score, per-category scores for Architecture, Performance, Security, Tests, and Dependencies, critical issues, top recommendations, and an Immediate/Short-term/Long-term action plan.
Quick Mode (--quick)
Only run essential checks (~2-3 minutes):
Run mix compile --warnings-as-errors, then mix hex.audit && mix deps.audit,
then mix xref graph --format stats, then mix test --trace 2>&1 | tail -20.
Skip: Full security scan, N+1 analysis, test quality metrics, architecture deep dive.
Focus Mode (--focus=area)
Run only the selected concern track with its deeper checks:
| Focus | Extra checks |
|---|---|
security | Full OWASP review, Sobelow, manual authorization patterns |
performance | Query plans, N+1 inventory, profiling evidence |
architecture | Full xref graph, coupling matrix, cohesion |
tests | Coverage by context, isolation, flaky-test indicators |
deps | Vulnerabilities, licenses, maintenance status |
Incremental Mode (--since <commit>)
Analyze only changes since a specific commit. Useful for pre-merge checks:
Run git diff --name-only <commit>...HEAD to identify changed files, then run targeted audits on changed files only (skips full project scan).
Combines with other flags: /skill:phx-audit --since HEAD~5 --focus=security
Relationship to Other Commands
| Command | Scope | Frequency |
|---|---|---|
/skill:phx-review | Changed files (diff) | Every PR |
/skill:phx-audit | Entire project | Quarterly |
/skill:phx-boundaries | Context structure | On-demand |
/skill:phx-verify | Compile/test pass | Anytime |
References
references/scoring-methodology.md- How scores are calculatedreferences/architecture-checks.md- Detailed architecture criteria
Gives 0 of the 12 instructions most audit compliance skills give
Counted across 936 of the 1,487 authors here whose files we hold, read 2026-08-06
- group findings by severityin 44 of 936
- Fetch latest guidelines before each reviewin 43 of 936, across 3 files
- Check files against all fetched rulesin 42 of 936, across 2 files
- Output findings in terse file:line formatin 41 of 936, across 3 files
- Ask user which files to review if none specifiedin 41 of 936, across 3 files
- Read specified files or prompt user for filesin 39 of 936, across 1 file
- generate the audit reportin 39 of 936, across 36 files
- assign a severity to every findingin 25 of 936
- run automated accessibility scansin 23 of 936, across 13 files
- map findings to WCAG criteriain 20 of 936, across 10 files
- confirm audit scopein 19 of 936, across 9 files
- check title tags and meta descriptions for uniquenessin 19 of 936, across 5 files
Said here and by no other author read
- run quick mode before full mode
- stop and report blockers if compilation or tests fail
- scope each track to concrete directories
- complete every selected track before synthesizing
- run independent tracks in parallel when possible
- write one evidence-focused report per track
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once.