No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by 1838904818 · Codex Skill · ★ 157
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is audit-repo safe to install? View the security audit →
audit-repo An evidence-backed, read-only repository health audit Skill for Codex, with standalone Python tools for reproducible inventory and snapshot comparison. 中文简介:这是一个实用的 Codex Skill,用于只读审查代码仓库的测试、CI、依赖、文档、安全信号与技术债,并将结果整理为有证据和优先级的行动清单。参见中文快速开始。 Features Collect repository signals as Markdown or JSON without installing project dependencies. Detect Git state, manifests, lockfiles, tests, CI, automation, ownership, containers, work markers, large files, and sensitive-looking filenames. Compare two audit snapshots and surface meaningful changes over time. Flag high-confidence attention items such as newly detected sensitive filenames, lost CI or tests, and new large files. Keep secret values private: filename checks never read or print sensitive file contents. Support custom directory exclusions, file limits, and large-file thresholds. The collector produces inventory signals, not automatic findings. The Skill tells Codex to verify context and evidence before assigning impact or priority. Install as a Codex Skill Clone the repository into the Codex skills directory. macOS
| Stars | 157 |
| Forks | 8 |
| Language | Python |
| Category | Codex Skill |
| License | MIT |
| Quality Score | 72.1853023620341/100 |
| Last Updated | 2026-08-31 |
| Created | 2026-08-11 |
| Platforms | codex, python |
| Est. Tokens | ~14k |
These tools work well together with audit-repo for enhanced workflows:
Looking for a audit-repo alternative? If you're comparing audit-repo with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 287 comman
An AI-powered GitHub code review tool that uses LLMs to detect high-confidence, high-impact issues—such as sec
Offline security scanner for AI-agent repos, skills, plugins, and MCP servers.
AI-powered code quality analysis using MCP to help AI assistants review code more effectively. Analyze git cha
🚀 AI-powered code review tool for GitHub, GitLab, Bitbucket Cloud, Bitbucket Server, Azure DevOps and Gitea —
Static analysis tool that catches 1000+ bug patterns across all popular programming languages, with auto-wirin
Explore other popular codex skill tools:
audit-repo is A practical Codex skill for evidence-backed repository health audits. It is categorized as a Codex Skill with 157 GitHub stars.
audit-repo is primarily written in Python. It covers topics such as code-quality, codex, codex-skill.
You can find installation instructions and usage details in the audit-repo GitHub repository at github.com/1838904818/audit-repo. The project has 157 stars and 8 forks, indicating an active community.
audit-repo is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to audit-repo on Agent Skills Hub include roam-code, Gito, repo-forensics. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: