agentsclimarketplace

Project audit

Skill vibeeval/vibecosystem/skills/project-audit

AI software team for Claude Code - 138 agents, 295 skills, 73 hooks. Self-learning, multi-agent swarm, autonomous skill evolution.

Install
npx -y skills add vibeeval/vibecosystem --skill project-audit

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Security scan, dead code detection, and code quality audit for any project

SKILL.md

2.2 KB, as published. Nobody here has run it

Project Audit

Automated security + quality scan for any codebase. Generates a report, then optionally auto-fixes safe issues.

Usage

# Scan current directory
vibeco audit

# Scan specific path
vibeco audit /path/to/project

# Auto-fix safe issues (console.log removal)
vibeco audit --fix

# JSON output for CI integration
vibeco audit --json

What It Scans

Security (SAST)

  • CRITICAL: eval(), exec(), execSync(), os.system(), subprocess, SQL injection patterns
  • HIGH: innerHTML, dangerouslySetInnerHTML, document.write(), pickle.load(), hardcoded secrets
  • MEDIUM: Sensitive data in console.log, MD5/SHA1 weak crypto

Code Quality

  • Large files (>500 lines)
  • TODO/FIXME/HACK/XXX count
  • Excessive console.log (>3 per file)

Test Coverage

  • Source file to test file ratio
  • Test file detection (.test.ts, .spec.js, etc.)

Dependencies

  • Lock file presence check
  • Node engine version check

Output

Terminal Report

Color-coded report with grade (A+ to F):

  • A+: Zero issues
  • A-: Only MEDIUM issues
  • B: Some MEDIUM issues
  • C: HIGH issues present
  • D: Many HIGH issues
  • F: CRITICAL issues present

JSON Report

Saved to .vibeco-audit.json in project root. Contains all findings for programmatic processing.

Auto-Fix (--fix)

Currently auto-fixes:

  • Removes console.log statements from files with >3 occurrences

Does NOT auto-fix (manual review required):

  • Security issues (too risky for automation)
  • Large file refactoring
  • TODO/FIXME resolution

Workflow

1. vibeco audit          -> Scan, generate report
2. Review report         -> Understand issues
3. vibeco audit --fix    -> Auto-fix safe issues
4. Manual fixes          -> Address security findings
5. vibeco audit          -> Re-scan to verify

Ignored Directories

node_modules, dist, .git, vendor, pycache, .next, build, coverage

Ignored in Security Scan

Test files (*.test.ts, *.spec.js, tests/, mocks/) are excluded from security scanning to avoid false positives.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.