‹ The Index

Code Audit

skill

Multi-agent code review that catches what humans skip. Use this skill when the user asks to review code, audit a PR, check for security issues, review changes, or wants a second opinion on their implementation. Triggers on: 'review this', 'review my code', 'review the PR', 'audit this', 'check for security issues', 'is this safe', 'code review', 'look over my changes', 'anything wrong with this', PR numbers or URLs. Also triggers automatically as part of the codesmith workflow's review phase. Do NOT trigger for explaining code or answering questions about how code works.

Works with: Claude Code (native)  ·  Cursor, Codex CLI (manual)
native: this artifact type is that client's own format

Category: Security — see all ranked ›

Install (Claude Code):

cp -r code-audit ~/.claude/skills/

Security audit

Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.

Its own instructions

Its SKILL.md says when to use it.

Read from the capability’s own SKILL.md. This is not a grade and does not compare to the instruction-depth verdict on an MCP server — a skill has no tools to document, so that rubric does not apply to it.

You searched for one. Check the rest of your stack:

npx tashan-cli doctor

Reads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.

tashan Pro$6/mo

Code Audit scores 37 today. Pro keeps the series, so you can see whether that is a project getting better or one on its way down.

Start a 7-day trial › Everything measured on this page stays free.

Show your score

Measured this well? Put the live badge in your README — it updates as the score does.

tashan badge for Code Audit
[![tashan](https://tashan.sh/badge/skill-nexteralabs-code-audit.svg)](https://tashan.sh/capability/skill-nexteralabs-code-audit.html)

source ↗  ·  skill:nexteralabs/code-audit

Everything on this page is public evidence and free. What it cannot know is whether you run this — check your whole config, free, in the browser. tashan Pro adds the series behind each row and names a replacement for anything dying.

Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.

Measured 2026-08-20  ·  scorer s5  ·  how  ·  something wrong here?