plugins/codebase-audit-suite/skills/ln-620-codebase-auditor/SKILL.md
Use when auditing the codebase through the evaluation platform with mandatory research, coordinated domain audit workers, and structured summaries.
npx skillsauth add levnikolaevich/claude-code-skills ln-620-codebase-auditorInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Paths: File paths (
references/,../ln-*) are relative to this skill directory.
Type: L2 Coordinator Category: 6XX Audit
MANDATORY READ: Load references/evaluation_coordinator_runtime_contract.md, references/evaluation_summary_contract.md, references/evaluation_research_contract.md
MANDATORY READ: Load references/audit_final_report_contract.md
MANDATORY READ: Load references/codebase_audit_worker_boundaries.md
MANDATORY READ: Load references/research_tool_fallback.md
Conditional read: load references/epistemic_protocol.md only when source confidence or claim uncertainty affects issue validation.
ln-621 through ln-629Runtime family:
evaluation-runtimeIdentifier:
codebase-auditPhase order:
PHASE_0_CONFIGPHASE_1_DISCOVERYPHASE_2_RESEARCHPHASE_3_DELEGATEPHASE_4_AGGREGATEPHASE_5_REPORTPHASE_6_SELF_CHECKln-621-security-boundary-auditorln-622-build-delivery-gate-auditorln-623-duplication-overabstraction-auditorln-624-code-maintainability-hotspot-auditorln-625-dependency-reuse-auditorln-626-dead-code-pruning-auditorln-627-diagnosability-auditorln-628-concurrency-correctness-auditorln-629-runtime-lifecycle-config-auditorHost Skill Invocation: Skill(skill: "...", args: "...") is mandatory delegation.
SKILL.md, treat args as $ARGUMENTS, execute that skill workflow, then return here with its result/artifact.Use the Skill tool for delegated workers. Do not inline worker logic inside the coordinator.
TodoWrite format (mandatory):
Resolve audit scope and build manifestLoad codebase structure and stackRun best-practice researchDelegate to domain audit workersAggregate worker findingsGenerate final audit report and remediation planVerify cleanup and self-checkRepresentative invocations:
Skill(skill: "ln-621-security-boundary-auditor", args: "{scope}")
Skill(skill: "ln-622-build-delivery-gate-auditor", args: "{scope}")
Skill(skill: "ln-623-duplication-overabstraction-auditor", args: "{scope}")
Skill(skill: "ln-624-code-maintainability-hotspot-auditor", args: "{scope}")
Skill(skill: "ln-625-dependency-reuse-auditor", args: "{scope}")
Skill(skill: "ln-626-dead-code-pruning-auditor", args: "{scope}")
Skill(skill: "ln-627-diagnosability-auditor", args: "{scope}")
Skill(skill: "ln-628-concurrency-correctness-auditor", args: "{scope}")
Skill(skill: "ln-629-runtime-lifecycle-config-auditor", args: "{scope}")
Start evaluation-runtime with required_research=true.
Detect project type, stack, and applicability of audit workers.
Mandatory research sources:
Delegate applicable audit workers. Child workers must use evaluation-worker-runtime and emit evaluation-compatible summaries.
Merge runtime/codebase risk findings using references/codebase_audit_worker_boundaries.md. Read every worker report_path, normalize actions, deduplicate repeated issues, resolve worker conflicts, and validate each actionable problem against the research source order in references/evaluation_research_contract.md.
Write .hex-skills/runtime-artifacts/runs/{run_id}/audit-report/ln-620--final-report.md per references/audit_final_report_contract.md. Include the remediation plan, source-backed validation for each confirmed issue, and cleanup note. Remove temporary worker markdown reports after consolidation. The evaluation-coordinator summary report_path must point to the final report only.
Required checks:
codebase_audit_worker_boundaries.mdWrite summary_kind=evaluation-coordinator.
ln-621 through ln-629codebase_audit_worker_boundaries.mdevaluation-coordinator summary writtenOptional reference: load references/meta_analysis_protocol.md only when the user asks for post-run meta-analysis or protocol-formatted run reflection.
When requested after the coordinator run, analyze the session per protocol section 7 and include the protocol-formatted output with the final codebase audit result.
../ln-621-security-boundary-auditor/SKILL.md, ../ln-622-build-delivery-gate-auditor/SKILL.md, ../ln-623-duplication-overabstraction-auditor/SKILL.md, ../ln-624-code-maintainability-hotspot-auditor/SKILL.md, ../ln-625-dependency-reuse-auditor/SKILL.md, ../ln-626-dead-code-pruning-auditor/SKILL.md, ../ln-627-diagnosability-auditor/SKILL.md, ../ln-628-concurrency-correctness-auditor/SKILL.md, ../ln-629-runtime-lifecycle-config-auditor/SKILL.mdVersion: 5.0.0 Last Updated: 2025-12-23
testing
Checks runtime lifecycle and config validation: bootstrap, shutdown, probes, cleanup, env sync, and fail-fast startup. Use for runtime readiness.
testing
Checks races, deadlocks, async hazards, TOCTOU, blocking I/O, and shared resource contention. Use when auditing concurrency correctness.
testing
Checks diagnosability through structured logs, metrics, traces, correlation IDs, and useful log levels. Use when auditing incident visibility.
development
Finds code that can be safely deleted: unreachable, unused, obsolete compatibility, and commented-out code. Use when pruning dead code.