Loading...
Loading...
Execute a complete, deterministic, read-only repository audit and produce a single `improvements.md` action plan with traceable findings (file + lines), severity, category, impact, and high-level fixes. Use when users ask for full code audits, security/performance/architecture reviews, file-by-file analysis, or technical debt mapping without modifying project files.
npx skill4agent add jpkovas/code-audit-readonly code-audit-readonlyimprovements.mdimprovements.mdimprovements.mdpendingFile fully reviewed: <path/to/file>improvements.md./pendingin_progressreviewedFile fully reviewed: <path/to/file>File fully reviewedreviewed# improvements.md
## 1. System summary
- Inferred architecture and main modules.
- Main risk surfaces.
## 2. Conventions
- Categories and severity scale used in the audit.
- Finding ID convention (`A001`, `A002`, ...).
## 3. Progress Tracking
- [ ] path/to/file-a.ext
- [ ] path/to/file-b.ext
- [ ] path/to/file-c.ext
## 4. Complete finding inventory
### A001
Category: ...
Severity: ...
Location: ...
Problem: ...
Impact: ...
Suggestion: ...
Correlation notes: ...
Security (if applicable): ...
### A002
...
## 5. Prioritized backlog (all findings)
- Priority 1: A00X, A00Y...
- Priority 2: A00Z...
## 6. Detailed phased remediation plan
### Phase 1
- Objective
- Findings included
- Dependencies
- Validation gates
- Exit criteria
### Phase 2
...
### Phase 3
...BugPerformanceSecurityDuplicationCode QualityArchitectureMaintainabilityObservabilityTestsDependenciesCriticalHighMediumLowA001A002A0XX
Category: <...>
Severity: <Critical|High|Medium|Low>
Location: <file>:<start line>-<end line>
Problem: <objective description>
Impact: <real or potential impact>
Suggestion: <high-level fix, without editing code>
Correlation notes: <related files/flows>
Security (if applicable): <plausible abuse scenario + mitigation>improvements.mdA001...A0XXSMLCorrectnessSecurityPerformanceReliabilityMaintainabilityCriticalHighFile fully reviewed: ...improvements.mdimprovements.md