Crewai audit
Audit a CrewAI project against official best practices (architecture, tasks, agents, flows, LLM config, tools, security) and generate/update the project's AGENTS.md context file. Use when the user asks to review, audit, or improve existing CrewAI code, or to refresh the project's AGENTS.md.From its SKILL.md
npx -y skills add victorgrein/victorgrein-skills --skill crewai-auditAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
5.2 KB, ~1.2k tokens by cl100k_base, as published. Nobody here has run it
Audit a CrewAI project
Audit the project at $target_path (default: current directory). Two deliverables, in order: (1) a findings report, (2) a created/updated AGENTS.md.
Step 1 — Inventory
bash ${CLAUDE_SKILL_DIR}/scripts/inventory.sh $target_path
This prints every CrewAI artifact: JSONC/YAML configs, Flow subclasses, @CrewBase classes, load_crew call sites, custom tools, .env handling, plus a leaked-secrets check. Read each listed file. If the inventory finds no CrewAI artifacts, say so and stop.
Step 2 — Audit checklist
Check every artifact against this list. For deeper API context while judging, load the crewai-expert skill references (references/crews.md, references/flows.md, etc.). Severity: critical (breaks or leaks), high (wrong results or waste), medium (fragility), low (style).
Architecture
- Production logic not wrapped in a Flow (bare crew as the whole app) → recommend Flow-first.
- Agent/Crew used for deterministic work (parsing, I/O, computable branching) → plain Python step.
- LLM-based router where the decision is computable from state → plain
@routerreturning a label. hierarchicalprocess withoutmanager_llm(breaks) or without a coordination need (waste).
Tasks
- God tasks (multiple outcomes in one description) → split.
- Vague
expected_output(no format/length/sections) → tighten. - Output consumed downstream without
output_pydantic/output_json→ structure it. - Missing
contextlinks between dependent tasks. - No guardrail on tasks feeding later steps; guardrail functions not returning
(bool, Any).
Agents
- Generic role/goal/backstory ("Assistant", "Helper") → specialize.
allow_delegation=Truewithout demonstrated need.- No
max_rpmon crews hitting rate-limited providers. - One giant do-everything agent → split into specialists.
Flows
- Unstructured
self.state["..."]dict state in production →Flow[PydanticState]. - Long-running flow without
@persist. - Listeners/routers with side effects in router methods.
LLM config
- Anthropic model without
max_tokens(breaks at call time) — critical. - Model id without provider prefix; deprecated LiteLLM prefixes (
ollama/,groq/,mistral/, ...). - Hardcoded API keys anywhere,
.envnot gitignored, secrets in configs — critical. - Same expensive model on trivial formatting steps → tier models (haiku for simple steps).
- Memory/knowledge in use with no embedder key available (default embedder is OpenAI even in all-Claude projects).
Tools
args_schemafields withoutField(description=...).- Tools raising exceptions on expected failures instead of returning actionable messages.
- Custom tool re-implementing an existing crewai-tools tool.
- Large
knowledge_sourcesre-embedded every kickoff (use theknowledgeparameter instead).
Report format: group findings by severity; each finding = file:line — issue — concrete fix (with the reference file that justifies it). If everything passes, say so explicitly.
Step 3 — Generate/update AGENTS.md
CrewAI's convention (https://docs.crewai.com/en/guides/coding-tools/agents-md) is a repo-root AGENTS.md giving any coding agent the project's conventions, commands, architecture, and guardrails.
bash ${CLAUDE_SKILL_DIR}/scripts/project-context.sh $target_path
This dumps the full project context: tree, dependencies, config contents, flow/crew/agent/task/tool map, entry points, env var names (values redacted). Then:
- If
AGENTS.mddoes not exist: create it from${CLAUDE_SKILL_DIR}/templates/AGENTS.md.template, filling every section from the context dump and audit findings. - If it exists: update it in place — refresh the sections that came from the template, preserve any user-written sections verbatim, and never delete content you can't map to a template section.
- Ensure
CLAUDE.mdexists at the project root, symlinked toAGENTS.md— the same context must serve both AGENTS.md-reading agents (Codex, Cursor, Gemini) and CLAUDE.md-reading agents:CLAUDE.mdmissing →ln -s AGENTS.md CLAUDE.mdCLAUDE.mdis already a symlink to AGENTS.md → doneCLAUDE.mdexists as a regular file with its own content → do NOT delete it; merge its unique content intoAGENTS.md(preserving it verbatim under an appropriate section), then replace the file with the symlink. If the content can't be merged cleanly, keep the file and add a@AGENTS.mdline instead — and tell the user why.
- Never write secret values into AGENTS.md — env var names only.
Step 4 — Report
End with: findings summary (counts by severity), the top 3 fixes worth doing first, and what changed in AGENTS.md/CLAUDE.md. Do NOT apply fixes unless the user asks — this skill reports.
What ships with it: 3 files
8.2 KB alongside SKILL.md, 2 of them executable
scripts/
- inventory.shruns3.1 KB
- project-context.shruns2.8 KB
templates/
- AGENTS.md.template2.4 KB