Skillshare Codebase AuditSAFE
📚 Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.
Overview
📚 Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.
0d9340b2ca90OBSERVED · 2026-10-08What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: skillshare-codebase-audit
description: >-
Cross-validate CLI flags, docs, tests, and targets for consistency across the
codebase. Use this skill whenever the user asks to: audit the codebase, check
for consistency issues, find undocumented flags, verify test coverage, validate
targets.yaml, check handler split conventions, or verify oplog instrumentation.
This is a read-only audit — it reports issues but never modifies files. Use
after large refactors, before releases, or whenever you suspect docs/code/tests
have drifted out of sync.
metadata:
targets: [claude, universal]
---
Read-only consistency audit across the skillshare codebase. $ARGUMENTS specifies focus area (e.g., "flags", "tests", "targets") or omit for full audit.
**Scope**: This skill only READS and REPORTS. It does not modify any files. Use `implement-feature` to fix issues or `update-docs` to fix documentation gaps.
Before acting, run `python3 scripts/ai-context.py audit`. That topic is the source of truth for audit dimensions, evidence requirements and status meanings; this skill retains the search and report workflow.
## Audit Dimensions
Run every dimension below in parallel where possible. For each, produce a summary table.
### 1. CLI Flag Audit
Compare every flag defined in `cmd/skillshare/*.go` against `website/docs/reference/commands/*.md`.
```bash
# Find all flags in Go source
grep -rn 'flag\.\(String\|Bool\|Int\)' cmd/skillshare/
grep -rn 'Args\|Usage' cmd/skillshare/
```
Report:
- **UNDOCUMENTED**: Flag exists in code but not in docs
- **STALE**: Flag documented but not found in code
- **OK**: Flag matches between code and docs
### 2. Test Coverage
For each command handler in `cmd/skillshare/<cmd>.go`:
- Check if `tests/integration/<cmd>_test.go` exists
- Check if key behaviors have test cases
```bash
# List all command handlers
ls cmd/skillshare/*.go | grep -v '_test.go\|main.go\|helpers.go\|mode.go'
# List all integration tests
ls tests/integration/*_test.go
```
Report:
- **COVERED**: Command has integration test file with test cases
- **PARTIAL**: Test file exists but missing key scenarios
- **MISSING**: No integration test for this command
### 3. Target Audit
Verify `internal/config/targets.yaml` entries:
- Each target has `skills.global` and `skills.project`
- Aliases are consistent
- No duplicate entries
Report:
- **OK**: Target entry complete and valid
- **INCOMPLETE**: Missing required fields
- **DUPLICATE**: Name or alias collision
### 4. Handler Split Audit
For commands with >300 lines in `cmd/skillshare/<cmd>.go`, verify the handler split convention is followed:
```bash
# Find large command files
wc -l cmd/skillshare/*.go | sort -rn | head -20
```
Check that large commands are properly split:
| Suffix | Expected for large commands |
|--------|---------------------------|
| `_handlers.go` | Core logic extracted |
| `_render.go` | Output rendering separated |
| `_tui.go` | TUI components isolated |
Report:
- **SPLIT**: Large command properly follows handler split convention
- **MONOLITH**: >300 lines without split (should be refactored)
- **N/A**: Small command, no split needed
### 5. Oplog Coverage
Verify all mutating commands have oplog instrumentation:
```bash
# Find commands that modify state
grep -rn 'func handle\|func cmd' cmd/skillshare/*.go
# Check for oplog.Write calls
grep -rn 'oplog.Write' cmd/skillshare/
```
Mutating commands (install, uninstall, sync, update, init, collect, backup, restore, trash) should all write to oplog. Read-only commands (list, status, check, search, audit, log, version) should not.
Report:
- **INSTRUMENTED**: Mutating command has oplog.Write
- **MISSING**: Mutating command lacks oplog instrumentation
- **N/A**: Read-only command (no oplog expected)
### 6. Web API Consistency
Verify `internal/server/handler_*.go` routes match CLI commands:
```bash
# List all handler files
ls internal/server/handler_*.go | grep -v _test.go
# Check route registration in server.go
grep -n 'HandleFunc\|Handle(' internal/server/server.go
```
Report:
- **SYNCED**: CLI command has corresponding API handler
- **CLI-ONLY**: Command exists in CLI but not in Web API (may be intentional)
- **API-ONLY**: API handler without CLI counterpart (unusual)
## Output Format
```
== Skillshare Codebase Audit ==
### CLI Flags (N issues)
| Command | Flag | Status |
|-----------|-------------|--------------|
| install | --force | OK |
| install | --into | UNDOCUMENTED |
### Test Coverage (N issues)
| Command | Status | Notes |
|-----------|---------|--------------------|
| sync | COVERED | |
| audit | PARTIAL | missing edge cases |
| target | MISSING | |
### Targets (N issues)
| Target | Status | Notes |
|-----------|------------|---------------|
| claude | OK | |
| newagent | INCOMPLETE | no skills.project |
### Handler Split (N issues)
| Command | Lines | Status | Notes |
|-----------|-------|-----------|--------------------|
| install | 450 | SPLIT | 6 sub-files |
| audit | 320 | MONOLITH | should split render |
| status | 80 | N/A | |
### Oplog (N issues)
| Command | Mutating? | Status |
|-----------|-----------|---------------|
| install | Yes | INSTRUMENTED |
| trash | Yes | MISSING |
| list | No | N/A |
### Web API (N issues)
| Command | CLI | API | Status |
|-----------|-----|-----|----------|
| install | Yes | Yes | SYNCED |
| diff | Yes | No | CLI-ONLY |
== Summary: X OK / Y issues found ==
```
## Rules
Apply the `audit` topic and keep this workflow read-only.Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
.devcontainer/bin/dev-servers
Gates applied: no_behavioural_pass.
0d9340b2ca90full audit observations/trust-audit/skill/runkids__skillshare-codebase-audit.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 0d9340b2ca90 | SAFE | B | 89 | first audit |
Questions
What does the Skillshare Codebase Audit skill do?
📚 Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.
Is Skillshare Codebase Audit safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Skillshare Codebase Audit access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (0d9340b2ca90), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.