Atlas / Skills / runkids / Skillshare Codebase Audit

Skillshare Codebase AuditSAFE

skills/runkids/skillshare-codebase-audit

📚 Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
MIT
Stars
2,749
01

Overview

📚 Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.

Read from source at commit 0d9340b2ca90OBSERVED · 2026-10-08
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: skillshare-codebase-audit
description: >-
  Cross-validate CLI flags, docs, tests, and targets for consistency across the
  codebase. Use this skill whenever the user asks to: audit the codebase, check
  for consistency issues, find undocumented flags, verify test coverage, validate
  targets.yaml, check handler split conventions, or verify oplog instrumentation.
  This is a read-only audit — it reports issues but never modifies files. Use
  after large refactors, before releases, or whenever you suspect docs/code/tests
  have drifted out of sync.
metadata: 
  targets: [claude, universal]
---

Read-only consistency audit across the skillshare codebase. $ARGUMENTS specifies focus area (e.g., "flags", "tests", "targets") or omit for full audit.

**Scope**: This skill only READS and REPORTS. It does not modify any files. Use `implement-feature` to fix issues or `update-docs` to fix documentation gaps.

Before acting, run `python3 scripts/ai-context.py audit`. That topic is the source of truth for audit dimensions, evidence requirements and status meanings; this skill retains the search and report workflow.

## Audit Dimensions

Run every dimension below in parallel where possible. For each, produce a summary table.

### 1. CLI Flag Audit

Compare every flag defined in `cmd/skillshare/*.go` against `website/docs/reference/commands/*.md`.

```bash
# Find all flags in Go source
grep -rn 'flag\.\(String\|Bool\|Int\)' cmd/skillshare/
grep -rn 'Args\|Usage' cmd/skillshare/
```

Report:
- **UNDOCUMENTED**: Flag exists in code but not in docs
- **STALE**: Flag documented but not found in code
- **OK**: Flag matches between code and docs

### 2. Test Coverage

For each command handler in `cmd/skillshare/<cmd>.go`:
- Check if `tests/integration/<cmd>_test.go` exists
- Check if key behaviors have test cases

```bash
# List all command handlers
ls cmd/skillshare/*.go | grep -v '_test.go\|main.go\|helpers.go\|mode.go'

# List all integration tests
ls tests/integration/*_test.go
```

Report:
- **COVERED**: Command has integration test file with test cases
- **PARTIAL**: Test file exists but missing key scenarios
- **MISSING**: No integration test for this command

### 3. Target Audit

Verify `internal/config/targets.yaml` entries:
- Each target has `skills.global` and `skills.project`
- Aliases are consistent
- No duplicate entries

Report:
- **OK**: Target entry complete and valid
- **INCOMPLETE**: Missing required fields
- **DUPLICATE**: Name or alias collision

### 4. Handler Split Audit

For commands with >300 lines in `cmd/skillshare/<cmd>.go`, verify the handler split convention is followed:

```bash
# Find large command files
wc -l cmd/skillshare/*.go | sort -rn | head -20
```

Check that large commands are properly split:

| Suffix | Expected for large commands |
|--------|---------------------------|
| `_handlers.go` | Core logic extracted |
| `_render.go` | Output rendering separated |
| `_tui.go` | TUI components isolated |

Report:
- **SPLIT**: Large command properly follows handler split convention
- **MONOLITH**: >300 lines without split (should be refactored)
- **N/A**: Small command, no split needed

### 5. Oplog Coverage

Verify all mutating commands have oplog instrumentation:

```bash
# Find commands that modify state
grep -rn 'func handle\|func cmd' cmd/skillshare/*.go

# Check for oplog.Write calls
grep -rn 'oplog.Write' cmd/skillshare/
```

Mutating commands (install, uninstall, sync, update, init, collect, backup, restore, trash) should all write to oplog. Read-only commands (list, status, check, search, audit, log, version) should not.

Report:
- **INSTRUMENTED**: Mutating command has oplog.Write
- **MISSING**: Mutating command lacks oplog instrumentation
- **N/A**: Read-only command (no oplog expected)

### 6. Web API Consistency

Verify `internal/server/handler_*.go` routes match CLI commands:

```bash
# List all handler files
ls internal/server/handler_*.go | grep -v _test.go

# Check route registration in server.go
grep -n 'HandleFunc\|Handle(' internal/server/server.go
```

Report:
- **SYNCED**: CLI command has corresponding API handler
- **CLI-ONLY**: Command exists in CLI but not in Web API (may be intentional)
- **API-ONLY**: API handler without CLI counterpart (unusual)

## Output Format

```
== Skillshare Codebase Audit ==

### CLI Flags (N issues)
| Command   | Flag        | Status       |
|-----------|-------------|--------------|
| install   | --force     | OK           |
| install   | --into      | UNDOCUMENTED |

### Test Coverage (N issues)
| Command   | Status  | Notes              |
|-----------|---------|--------------------|
| sync      | COVERED |                    |
| audit     | PARTIAL | missing edge cases |
| target    | MISSING |                    |

### Targets (N issues)
| Target    | Status     | Notes         |
|-----------|------------|---------------|
| claude    | OK         |               |
| newagent  | INCOMPLETE | no skills.project |

### Handler Split (N issues)
| Command   | Lines | Status    | Notes              |
|-----------|-------|-----------|--------------------|
| install   | 450   | SPLIT     | 6 sub-files        |
| audit     | 320   | MONOLITH  | should split render |
| status    | 80    | N/A       |                    |

### Oplog (N issues)
| Command   | Mutating? | Status        |
|-----------|-----------|---------------|
| install   | Yes       | INSTRUMENTED  |
| trash     | Yes       | MISSING       |
| list      | No        | N/A           |

### Web API (N issues)
| Command   | CLI | API | Status   |
|-----------|-----|-----|----------|
| install   | Yes | Yes | SYNCED   |
| diff      | Yes | No  | CLI-ONLY |

== Summary: X OK / Y issues found ==
```

## Rules

Apply the `audit` topic and keep this workflow read-only.
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.devcontainer/bin/dev-servers
.devcontainer/bin/dev-servers
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 0d9340b2ca90full audit observations/trust-audit/skill/runkids__skillshare-codebase-audit.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-080d9340b2ca90SAFEB89first audit
05

Questions

What does the Skillshare Codebase Audit skill do?

📚 Sync skills, agents, MCP, plugins to all AI CLI tools with one command and simplify team sharing.

Is Skillshare Codebase Audit safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Skillshare Codebase Audit access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (0d9340b2ca90), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement