code-cleanup-audit
Audit a repository for architectural decay, AI-generated code smells, stale compatibility paths, dead abstractions, boundary violations, and cleanup candidates without modifying files. Use when the user asks to review code quality, find bad code, inspect AI-generated code, identi
供給アセットの概要
コーディングと開発 Agent
コードレビュー、リポジトリ分析、テスト、CI、GitHub、DevOps、開発ワークフロー向けのスキルです。
シナリオ
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent 適合
Claude Code + Browser agents + CLI
Codex、Claude Code、Cursor、CLI、またはカスタム Agent に対応します。
インストール
準備完了
npx skills add pqpo/pragma --skill code-cleanup-audit
メンテナンス
新しい
最終プッシュから 2 日
リスク
要レビュー
Dependency or permission surface needs review
GitHub 品質
100
67/100 品質 · 68/100 信頼
対象タグ
レビュー注記
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent 導入スコアカード
信頼、監査、インストール準備状況を一目で確認
公開リポジトリのメタデータ、OpenAgentSkill のレビューシグナル、保守の鮮度、インストール準備状況を組み合わせたスコアです。候補選定の目安であり、人によるレビューの代替ではありません。
品質
有望有用な候補ですが、採用前に代替と比較してください。
信頼
サンドボックス限定信頼シグナルが不足または混在する有用な候補です。結果ループがタスク適合を示すまで、隔離されたワークスペースで使用してください。
監査
要レビューインストール準備、安全メタデータ、保守、採用リスクの機械可読なレビュー。
OpenAgentSkill Trust Score v5
インストール前に人のレビュー
実作業で使う前に、サンドボックスでのみ実行し、近い代替と比較してください。
スター
GitHub スター 100
リポジトリ活動
スター 100、フォーク 8
メンテナンス
最終プッシュから 2 日
ライセンス
NOASSERTION
インストール
npx skills add pqpo/pragma --skill code-cleanup-audit
インストール安全性
標準パッケージまたはランタイムのインストールパス
権限範囲
secrets or environment access, shell or command execution
Agent の成果
Agent の成果データはまだありません
ドキュメント
README/SKILL.md の文脈が十分です
リスク概要
本番前にレビュー
- The repository license is detected as NOASSERTION, which may be ambiguous for redistribution, but this does not affect the skill's functionality or safety.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Stars/forks activity: 100 stars, 8 forks; issue activity unavailable in current metadata
インストール準備状況
インストールパスを利用可能
- インストールパスを利用できます
- リポジトリの根拠を利用できます
- ライセンスが明示されています
- Agent-Proven の成果エビデンスはまだありません
Agent 可読メタデータ
このスキルの機械可読な判断データ。
このブロックまたは埋め込み JSON を使い、Agent がこのスキルをインストールすべきか、代替を選ぶべきか、先に人のレビューを求めるべきかを判断できます。
適したタスク
- GitHub automation ワークフロー
- Claude Code チーム
- builders willing to evaluate younger projects
- Inspect repository metadata
適した Agent
インストール判断
- コマンド
- npx skills add pqpo/pragma --skill code-cleanup-audit
- ポリシー
- ブロック
- 人によるレビュー
- はい
信頼とリスク
- 信頼
- 60/100
- 監査
- 75/100
- リスクレベル
- 要レビュー
成果ループ
- エンドポイント
- /api/agent/outcome
- イベント ID
- resolve
- 成果
- 5
使わない場合
- ベンダー提供の SLA が必要なチーム
- production agents without a repository review
- The repository license is detected as NOASSERTION, which may be ambiguous for redistribution, but this does not affect the skill's functionality or safety.
- 高リスク権限のヒント: Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
Agent セーフティ v2
27/100 · 自動インストールを避ける
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
高
Shell またはコマンド実行
Skill メタデータに端末、CLI、Shell、サブプロセス、またはコマンド実行のワークフローが含まれます。
中
Browser automation
Skill may drive a browser or interact with web pages.
中
ネットワークアクセス
Skill はリモートページ、API、リポジトリ、外部サービスにアクセスする可能性があります。
中
ファイルシステムアクセス
Skill はプロジェクトファイル、ドキュメント、生成物、ローカルワークスペース状態を読み書きする可能性があります。
- 高リスク権限のヒント: Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
インストール先
Agent ワークフローにこのスキルをインストール
公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install pqpo-code-cleanup-auditAgent 解決プラン
インストール前に Agent に適合性を検証させます。
Resolve API は第一候補、代替、安全ポリシー、監査メモ、インストール先、Agent がそのまま使えるプロンプトを返します。
JSON を開く
/api/agent/resolve?task=Use%20code-cleanup-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve テキスト
/api/agent/resolve?task=Use%20code-cleanup-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
インストール引き継ぎ
/api/skills/pqpo-code-cleanup-audit/install
Agent が確認すべきこと
- Resolve API でタスク適合と代替を確認。
- 監査・信頼スコアと安全ポリシーの警告を確認。
- Codex、Claude Code、Cursor、CLI のインストール先互換性を確認。
プロンプトをコピー
Task: Use code-cleanup-audit in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20code-cleanup-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/pqpo-code-cleanup-audit/install
Install command: npx skills add pqpo/pragma --skill code-cleanup-audit
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 引き継ぎ
別のディレクトリではなく、インストール経路を Agent に渡します。
公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。
インストール引き継ぎ
/api/skills/pqpo-code-cleanup-audit/install
LLM テキスト形式
/api/skills/pqpo-code-cleanup-audit/install?format=text
代替を探す
/api/skills/search?q=code-cleanup-audit&limit=3
Agent プロンプト
Use code-cleanup-audit for this task. Review https://www.openagentskill.com/api/skills/pqpo-code-cleanup-audit/install, then install with: npx skills add pqpo/pragma --skill code-cleanup-auditRegistry メタデータ
自動スキル選択用の Agent 可読プロファイル。
Registry API 経由で判断、信頼、監査、ユースケース、インストールのシグナルを提供し、UI をスクレイピングせずに Agent が順位付けできます。
Manifest
/api/registry/manifest/pqpo-code-cleanup-audit
LLM テキスト
/api/registry/manifest/pqpo-code-cleanup-audit?format=text
インストール別名
/api/registry/install/pqpo-code-cleanup-audit
推奨
/api/registry/recommend?task=Use%20code-cleanup-audit%20in%20an%20agent%20workflow&limit=3
Agent 適合
GitHub automation
プラットフォーム
Claude Code, Browser agents
Agent 判断パネル
Fallback candidate for GitHub automation
まずこのスキルでプロトタイプを作り、代替候補を用意してください。
スタック内の役割
代替候補
主な適合
GitHub automation
信頼ラベル
まずプロトタイプ
インストールパス
コマンド準備済み
使う場面
- GitHub automation ワークフロー
- Claude Code チーム
- builders willing to evaluate younger projects
根拠
- 最近のリポジトリ活動
- インストールコマンドまたは GitHub リポジトリが利用可能
- 品質プロファイル 67/100
- OpenAgentSkill エンゲージメント 4 件
先にレビュー
- The repository license is detected as NOASSERTION, which may be ambiguous for redistribution, but this does not affect the skill's functionality or safety.
実装パス
- 1サンドボックスの Agent にインストールし、GitHub automation タスクを一度最初から最後まで実行します。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信頼プロファイル
サンドボックス限定
信頼シグナルが不足または混在する有用な候補です。結果ループがタスク適合を示すまで、隔離されたワークスペースで使用してください。
GitHub 採用度
情報GitHub スター 100
スター/フォーク活動
確認スター 100、フォーク 8; 現在のメタデータでは Issue 活動を利用できません
最近のメンテナンス
合格最終プッシュから 2 日
ライセンスの明確さ
合格NOASSERTION
良いシグナル
- AI レビュー承認済み
- インストールパスを利用できます
- リポジトリの根拠を利用できます
- 最近保守されたリポジトリ
- インストールコマンドに明確な高リスクパターンはありません
- 成果ループは準備済みですが、最初の実行が必要です
インストール前にレビュー
- The repository license is detected as NOASSERTION, which may be ambiguous for redistribution, but this does not affect the skill's functionality or safety.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Stars/forks activity: 100 stars, 8 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
- 実際の Agent 成果レポートはまだありません
- 無人インストールの前に人によるレビューが必要です
推奨アクション
実作業で使う前に、サンドボックスでのみ実行し、近い代替と比較してください。
品質プロファイル
有望 Agent ワークフロー向けの候補
有用な候補ですが、採用前に代替と比較してください。
ワークフロー適合
このスキルを使うシナリオ
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Build and ship code
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Operate web apps
Browser automation
I need my agent to control a browser, fill forms, and verify web app workflows.
ワークフロー適合
完全なワークフローに追加
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Ingest, retrieve, and cite
RAG knowledge base
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
代替候補
インストール前に比較
このタスクに適する可能性のある類似スキル。
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
概要
--- name: code-cleanup-audit description: Audit a repository for architectural decay, AI-generated code smells, stale compatibility paths, dead abstractions, boundary violations, and cleanup candidates without modifying files. Use when the user asks to review code quality, find bad code, inspect AI-generated code, identify refactoring or cleanup opportunities, detect legacy leftovers, or produce a cleanup backlog that requires human confirmation before implementation. ---
# Code Cleanup Audit
## Overview
Use this skill to produce an evidence-backed cleanup audit only. The output is a backlog of suspected or confirmed problems for human review, not an implementation plan that silently edits code.
## Non-Negotiable Guardrails
- Do not modify files. - Do not call `apply_patch`, formatters with write mode, generators, codemods, install commands, migration commands, or any command whose purpose is to change the workspace. - Do not create branches, commits, pull requests, or issue tickets unless the user explicitly asks after reviewing the audit. - If the user asks for fixes before seeing the audit, first produce findings and ask which items to implement. - If a command unexpectedly changes files, stop, report the changed paths, and ask how to proceed. - Preserve unrelated dirty worktree changes; treat them as user-owned.
## Audit Workflow
1. Establish repository context: - Read `AGENTS.md` first. - Read architecture and convention docs that directly govern the touched codebase, especially dependency boundaries, ADRs, and package conventions. - Run `git status --short` and note existing dirty files. - Inventory apps/packages with read-only commands such as `find`, `rg --files`, `pnpm -r list --depth -1`, and package manifest reads.
2. Build a map before judging: - Identify package boundaries, public exports, app entry points, runtime adapters, shared schemas, tests, and docs. - Trace imports through package names, not only filenames. - Compare implementation structure against documented allowed dependencies. - Prefer `rg` over slower search tools.
3. Inspect for cleanup categories: - Architecture violations: forbidden imports, cross-package relative imports, app-layer logic in shared packages, runtime-specific code in core/shared, browser-unsafe code in web/client/shared. - Stale compatibility: deprecated fields, fallback branches, migration shims, legacy aliases, duplicate old/new APIs, TODOs that preserve obsolete behavior, no-op adapters, unused feature flags. - AI-generated code smells: over-broad abstractions, fake extensibility, duplicated helpers, inconsistent naming, hand-rolled utilities where a project utility exists, speculative layers, uncalled code, verbose comments explaining obvious code, guessed data shapes. - Type and schema weakness: `any`, unsafe casts, unchecked `unknown`, interfaces where runtime validation is required, schema/type drift, missing boundary parsing. - Error and runtime behavior smells: swallowed errors, broad `catch`, impossible states represented as optional fields, missing cancellation/timeout handling, fragile env assumptions. - Test and validation gaps: core behavior without tests, snapshots masking behavior, tests that only assert mocks, missing negative cases for boundary rules. - Documentation drift: docs or AGENTS rules contradicted by code, public API exports not reflected in docs, stale startup/quality commands.
4. Validate suspected issues: - Read surrounding code and tests before reporting. - Run read-only validation where useful: `pnpm lint`, `pnpm typecheck`, `pnpm test`, focused Vitest commands, `pnpm build` only when build behavior is relevant. - Use existing ESLint boundary rules as evidence when available. - Distinguish confirmed problems from cleanup candidates that need product or architectural judgment.
5. Report without fixing: - Lead with findings ordered by severity. - Include file path and line or precise code location for each finding. - State the violated rule or smell, why it matters, evidence, confidence, and suggested cleanup direction. - Mark every item as one of: `confirmed`, `likely`, or `needs human decision`. - Include "Do not modify until confirmed" language when handing off.
## Severity Standard
- `Critical`: Can break runtime behavior, violate security/privacy boundaries, corrupt data, or cause CI/build failure. - `High`: Violates documented architecture, creates wrong package dependency direction, or preserves misleading/dead public API that future agents will copy. - `Medium`: Increases maintenance cost through duplication, stale compatibility, weak validation, or untested shared behavior. - `Low`: Local readability or consistency issue with limited blast radius.
Do not report pure preference, cosmetic style, or speculative rewrites unless tied to a concrete maintenance, correctness, boundary, or future-agent-copying risk.
## Recommended Commands
Use commands like these as applicable. Keep them read-only.
```bash git status --short find apps packages docs -maxdepth 3 -type f | sort rg --line-number "TODO|FIXME|deprecated|legacy|compat|shim|fallback|no-op|noop|any\\b|as unknown|as any" apps packages docs rg --line-number "from ['\"]\\.\\./\\.\\./|from ['\"]\\.\\./\\.\\./\\.\\./|@pragma/(client|server|core|runtime)" apps packages pnpm -r list --depth -1 pnpm lint pnpm typecheck pnpm test ```
Before running expensive repository-wide commands, prefer focused reads and explain why the command is useful.
## Output Format
Return:
1. Findings - Severity - Status: `confirmed`, `likely`, or `needs human decision` - Location - Problem - Evidence - Cleanup direction, without editing code
2. Cleanup backlog - Group related findings into reviewable batches. - Call out which batches are safe mechanical cleanup versus architecture decisions.
3. Non-findings and constraints - Mention important suspected issues that were checked and rejected. - Mention commands run and commands intentionally skipped.
4. Human confirmation needed - List the exact decisions needed before any code changes.
技術詳細
- バージョン
- 1.0.0
- ライセンス
- NOASSERTION
- 最終更新
- 2026年8月20日
- 公開日
- 2026年8月20日
判断の要約
代替候補
最近のリポジトリ活動
Agent 実証エビデンス
Agent 実証エビデンス
Resolve、レビュー、インストール、限定実行後の成果レポート。
- 成功率
- —
- 直近の失敗
- —
- 成果
- 0
- 出力品質
- —
- 失敗
- 0
- 非該当
- 0
- インストール数
- 0
- リスクによりブロック
- 0
- 設定が必要
- 0
- 本番
- 0
Agent の実行結果はまだありません。最初の実行では /api/agent/outcome を通じて成功、設定要件、リスクによるブロック、失敗、非該当を報告できます。
成長ループ
共有キット
code-cleanup-audit 用のシナリオベース草案です。X へ手動投稿できます。
A practical pick for source-backed research: code-cleanup-audit: Audit a repository for architectural decay, AI-generated code smells, stale compatibility paths, dead abstractions, boundar... 100 stars https://www.openagentskill.com/skills/pqpo-code-cleanup-audit?ref=x
任意:インストールコマンド付きの返信
Listing + install path for code-cleanup-audit: https://www.openagentskill.com/skills/pqpo-code-cleanup-audit?ref=x Install: npx skills add pqpo/pragma --skill code-cleanup-audit
掲載元
Registry により登録
この掲載は公開ソースから登録されており、メンテナー申請が承認されるまで公式として表示されません。
- 作成者
- pqpo
- ソース
- pqpo/pragma
- インデックス作成者
- OpenAgentSkill コミュニティインデックス
帰属は公開リポジトリまたは作成者プロフィールにリンクされています。作成者は掲載を申請して所有権シグナルを更新できます。
このスキルを申請所有者の申請
このスキル掲載を申請
この Registry により登録 掲載は pqpo に帰属していますが、まだ公式として表示されていません。申請すると、確認済み所有者シグナルが追加され、今後の公開、インストール、監査更新の信頼性が高まります。
クリエイター被リンクキット
README にエビデンスバッジを追加
開発者がリポジトリを評価する場所で、正規掲載、現在の信頼・監査シグナル、実際の Agent-Proven エビデンスを表示します。
[](https://www.openagentskill.com/skills/pqpo-code-cleanup-audit)
[](https://www.openagentskill.com/skills/pqpo-code-cleanup-audit)
[](https://www.openagentskill.com/skills/pqpo-code-cleanup-audit/audit)
[](https://www.openagentskill.com/skills/pqpo-code-cleanup-audit)作者
pqpo
@pqpo
プラットフォーム適合
健全性シグナル
- GitHub スター
- 100
- 品質スコア
- 37/100
- 最終 GitHub プッシュ
- 2026年8月20日
- フレームワークのヒント
- 不明
- OpenAgentSkill 閲覧数
- 4
- インストールコピー数
- 0
- 外部クリック
- 0
コミュニティシグナル
このスキルが Agent ワークフローに役立つかを共有してください。集約されたフィードバックがランキングを改善します。
信頼と安全性
サンドボックス限定
- GitHub 採用度GitHub スター 100情報
- スター/フォーク活動スター 100、フォーク 8; 現在のメタデータでは Issue 活動を利用できません確認
- 最近のメンテナンス最終プッシュから 2 日合格
- ライセンスの明確さNOASSERTION合格
- README/SKILL.md の完全性メタデータには十分な利用・ワークフロー文脈があります合格
- 依存関係/ランタイムのリスクcommand execution surface, credential or environment access修正
関連スキル
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K スターMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K スターNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K スターInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K スター