production-code-audit
Audit Production Codebases
Production readiness work often leaves security, performance, testing, and architecture gaps hidden across many files. This skill guides a structured audit and controlled remediation plan for Claude, Codex, and Claude Code.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "production-code-audit" from https://skillstore.io/skills/sickn33-production-code-audit.md and its manifest at https://skillstore.io/api/skills/sickn33-production-code-audit/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "production-code-audit". Audit this web API before release.
Expected outcome:
- Executive summary with the main release risks.
- Prioritized findings for authentication, validation, logging, testing, and deployment.
- A remediation plan with verification steps and owners.
Using "production-code-audit". Make this service production-ready, but do not edit files yet.
Expected outcome:
- Read-only audit findings grouped by severity.
- A proposed first change set limited to the highest-risk issues.
- Test commands and manual checks to run after approval.
Using "production-code-audit". Review performance and production readiness for this repository.
Expected outcome:
- Bottleneck summary for queries, bundle size, caching, and async work.
- Production checklist covering health checks, monitoring, logging, and documentation.
- Before-and-after metrics to collect during remediation.
Security Audit
Medium RiskThe static findings are false positives caused by Markdown fences, inline tool names, illustrative vulnerable code, and reference links. No evidence of malware, credential exfiltration, prompt injection, or live network behavior was found. The remaining risk is overbroad autonomous repository reading and editing without explicit user confirmation.
Confirmed security concerns (1)
Risk Factors
โ๏ธ External commands (26)
๐ Network access (4)
๐ Env variables (5)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/sickn33-production-code-audit/audits/6?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/sickn33-production-code-audit?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/sickn33-production-code-audit?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-production-code-audit/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/sickn33-production-code-audit.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
sickn33. (2026). production-code-audit security audit report (audit version 6) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sickn33-production-code-audit/audits/6BibTeX citation
@techreport{sickn33-sickn33-production-code-audit-2026,
author = {sickn33},
title = {production-code-audit security audit report (audit version 6)},
institution = {Skillstore},
year = {2026},
number = {6},
url = {https://skillstore.io/skills/sickn33-production-code-audit/audits/6},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "production-code-audit security audit report (audit version 6)"
version: "unspecified"
type: report
authors:
- name: "sickn33"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/sickn33-production-code-audit/audits/6"
identifiers:
- type: other
value: "skillstore:sickn33-production-code-audit:audit:6"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Prepare a release for production
Review security, performance, tests, observability, and deployment gaps before a launch.
Triage application security gaps
Identify insecure patterns such as weak hashing, hardcoded secrets, missing validation, and missing authorization.
Reduce technical debt before handoff
Create a prioritized backlog for refactoring, test coverage, documentation, and production support work.
Try These Prompts
Use production-code-audit to review this repository. Identify the highest-risk security, testing, performance, and deployment gaps before making changes.
Audit the codebase and group findings by critical, high, medium, and low priority. Propose a minimal first pull request before editing files.
Use production-code-audit on the authentication and API layers. Present the plan first, then update only approved files and verify with tests.
Perform a full production readiness audit for this service. Map architecture, data flow, security controls, observability, tests, and release risks, then produce an executive summary and remediation backlog.
Best Practices
- Start with a read-only audit and approve the edit plan before changes.
- Prioritize exploitable security issues, failing tests, and deployment blockers first.
- Run the repository tests and record any verification that could not run.
Avoid
- Letting the agent rewrite the entire repository without scoped approval.
- Treating illustrative examples as proof that the current codebase is secure.
- Skipping tests after automated refactoring or dependency changes.
Frequently Asked Questions
Does this skill run a real vulnerability scanner?
Can this skill change files?
Which AI tools can use it?
What repositories fit this skill best?
Does it replace a human security review?
What should I provide before using it?
Developer Details
Author
sickn33License
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Repository
https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/production-code-auditRef
3e4b6c31a74a3bd1a291c98cf585d720cb9fbc88
Maintenance freshness
7/18/2026
Usage
5 downloads ยท 125 views
File structure
๐ SKILL.md