Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Design Audit

ASecurity

Static UI convention check - off-palette colors and wrong product-name casing, dishonest data labels (AI-generated or mock data shown as real), AI-slop (lorem remnants, hedge copy, emoji headings, uniform gradient grids), and client-facing language leaks. Reports file:line findings with fixes; conventions come from config layered over pack defaults. Use when the user asks to design-audit or check UI conventions, polish, or copy.

2 stars
0 votes
0 copies
0 views
Added 9/28/2026
ai-agentsrustgoshellbashgit

Works with

cli

Security Analysis

A100/100

Scanned 9/28/2026

Install to Claude Code

$npx -y skills add AaravChadha/acstack --skill design-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Design Audit?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Design Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aaravchadha-design-audit/badge)](https://www.skillsdirectory.com/skills/aaravchadha-design-audit)

More formats (shields.io, HTML) on the badges page.

Files
SKILL.md
---
name: design-audit
description: Static UI convention check - off-palette colors and wrong product-name casing, dishonest data labels (AI-generated or mock data shown as real), AI-slop (lorem remnants, hedge copy, emoji headings, uniform gradient grids), and client-facing language leaks. Reports file:line findings with fixes; conventions come from config layered over pack defaults. Use when the user asks to design-audit or check UI conventions, polish, or copy.
argument-hint: "[path | notes]"
allowed-tools: Read, Grep, Glob, Bash(grep:*), Bash(ls:*)
---

# /design-audit — conventions, honesty, and slop

A static pass over the UI's code and copy for the things reviewers skim
past: colors off the palette, mock data wearing a real-data face, the
tells of machine-generated filler, and internal language leaking to the
user. Nothing is rendered — a rendered mode arrives with the browser
probe (same deferral as /qa, decision 2026-07-27).

`Adjacent skills:` /design (the generative half — it produces UI, this
inspects it; /design-audit stays purely detective and never generates) ·
/qa (behavior; /design-audit is look and language) · /audit code
(correctness; /design-audit is convention) · /secure (exploitability;
/design-audit flags leaked internals as language, not as a
vulnerability).

<!-- acstack:runtime -->
Run before the skill's steps — per invocation, not per session (4.36); failures degrade to markdown:
```bash
link="$(readlink "$HOME/.claude/skills/health" 2>/dev/null || true)"   # empty = not symlinked
pack="$(dirname "$(dirname "$link")")"   # NEVER trust this unless $link was non-empty
if [ "${link#/}" != "$link" ] && [ -x "$pack/bin/acstack-config" ] && ! "$pack/bin/acstack-config" runtime | grep -q '=off'; then
  "$pack/bin/acstack-config" || true          # resolved keys, with sources
  "$pack/bin/acstack-update-check" || true    # ≤1 fetch/day; silent ONLY if already checked today
  "$pack/bin/acstack-recall" || true          # LEARNINGS.md + bug-class names, capped 3KB
else
  echo "runtime off — proceeding without recall/update-check"
fi
```
<!-- /acstack:runtime -->

<!-- acstack:principles -->
## Operating principles

- Be direct. Push back in writing when the plan or the user is wrong. No sycophancy.
- Never delete a decision. Supersede it: `~~old~~ → **Verdict (YYYY-MM-DD):** new call — reason.`
- Never fix, tune, or delete a test or eval case to raise a score. Log the miss honestly and leave the case unchanged.
- Name exact things: regex patterns, function signatures, model names, before → after numbers. Never "fixed bugs".
- Attribution: follow the project's `attribution` setting (default `none`) — no AI-tool mentions in generated docs, no attribution trailers in commits or PRs. Commit with explicit `-m`/`-F` messages only.
- Config: read `.claude/acstack.md` at the project root (fall back to `~/.claude/acstack.md`) before acting. `## Settings` keys override pack defaults; a `## <skill-name>` section overrides both. Unknown keys and sections are ignored.
- Docs: BRIEF.md (frozen seed) / PLAN.md (living plan) / JOURNAL.md (rolling journal). If the repo uses legacy names (PLANNING_PROMPT.md / PLANNING.md / STATUS.md), use those instead — never create both.
- Recall: if `LEARNINGS.md` exists at the project root, read it before starting.
- Conduct: follow the `acstack-conduct` block in this repo's AGENTS.md — the word is the mode; the user sets the pace.
- Hackathon lane: if the project's AGENTS.md carries the `acstack:hackathon-lane` block, only `/do` changes the repository during the event. Any other skill that would write a tracked file, commit or push says what it would have done and stops; a change that is not a task goes through the lane's operator route.
<!-- /acstack:principles -->

## Conventions come from config

Read a `## design-audit` section from `.claude/acstack.md`:

- `palette:` — the allowed hex values; colors outside it are findings.
- `banned-palette:` — hex values that are findings wherever they appear,
  even if someone adds them to `palette`. Defaults to the violet-gradient
  family that generated UI reaches for (`references/ai-tells.md`).
- `product-names:` — exact casings; other casings are findings.

Config always wins over the brand-neutral defaults in
`references/design-conventions.md`. No config → use the defaults and say
so in scope, naming what the reader is and is NOT getting: "no palette
configured; flagged raw-hex sprawl and the dated default-look clusters
(`references/ai-tells.md` Config), **not** brand conformance — nothing here
knows what your brand is." Without a `palette:` there is no allowed set, so
conformance is unanswerable rather than merely unchecked; saying only
"flagged obvious sprawl" undersold both halves.

With `palette:` configured, the cluster check is suppressed: a look a
project chose and declared is a decision, not a defect.

## The four checks

Grep families and the default convention set live in
`references/design-conventions.md`. Apply them with the Grep tool — this
skill grants no shell `git grep`. No Grep tool? Use `grep -rnE`, never
`git grep`.

1. **Palette + branding.** Hardcoded colors outside the configured
   palette; product names in the wrong casing; spacing/font literals
   diverging from the project's own design tokens where tokens exist
   (a raw `#3b82f6` beside a `--color-primary` token is the finding).
2. **Honest data labels.** AI-generated, illustrative, sample, or mock
   data shown without saying so; a chart of fabricated numbers presented
   as real. The honest-measurement principle applied to pixels — the
   same stance /audit eval takes toward scores.
3. **Slop detection.** Placeholder/lorem remnants, emoji-decorated
   headings in product UI, uniform gradient-card grids, hedge copy
   ("simply", "just", "seamlessly", "powerful", "effortlessly"),
   user-visible debug strings (`console.log`, `TODO`, `FIXME` in
   rendered text).
4. **Client-facing language.** Internal jargon or codenames in UI
   strings; error messages exposing internals (stack traces, table
   names, file paths) — cross-referenced to /secure when they leak
   system detail; inconsistent terminology for the same object across
   screens ("order" here, "purchase" there).
5. **AI tells.** The signature of generated UI — violet gradients,
   eyebrows, fabricated statistics, motion and materials violations,
   interaction-feel misses. Rules and greps in `references/ai-tells.md`.

**Severity order is fixed: accessibility, then honesty, then everything
else** — regardless of how many hits each class produced. Unreadable text
and a fabricated statistic are harm; a gradient is embarrassment. One tell
is a choice; the full set is a signature, so say which it was.

**No UI files in the path → say so and stop.** If the target contains no
markup, styles, or component files, there is nothing to audit; report the
path, what was looked for, and stop. A "CLEAN" verdict over a directory
with no UI in it is a true statement that reads as a false reassurance.

## Stance and report shape

Read-only: findings and suggested fixes, never applied edits. First
line is the verdict: `CLEAN` or `<N> findings`. Then:

- **Findings**, grouped by the four checks: `file:line` · the
  convention violated · the suggested fix.
- **`Safety checks:`** the exact greps run.
- **Scope:** paths covered; static-only stated; whether a palette was
  configured or defaults were used.

Attribution

AaravChadhaAaravChadha
View sourceMore from AaravChadha →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

695601 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →