Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Omg Audits

ASecurity

Complete Quality Arsenal in one installable skill — 18 forensic Gestalt-Popper audits (code, security, performance, UX, accessibility, SEO, data, API, copy, DX, motion, flow, feature, automation, logic, retention, debug, refonte) plus intelligent orchestration, power levels, parallel waves, output templates, and a verification contract. Use when the user says "/omg-audits", "audit my project", "full audit", "quality audit", "audit complet", "is it production ready", "security audit", "perform...

2 stars
0 votes
0 copies
0 views
Added 10/2/2026
ai-agentsrustgogitapibackendsecurityperformance

Works with

claude desktopcliapi

Security Analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned 10/2/2026

$npx -y skills add agentik-os/claude-code-skills --skill omg-audits --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Omg Audits?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Omg Audits
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/agentik-os-omg-audits/badge)](https://www.skillsdirectory.com/skills/agentik-os-omg-audits)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: omg-audits
description: >
  Complete Quality Arsenal in one installable skill — 18 forensic Gestalt-Popper audits
  (code, security, performance, UX, accessibility, SEO, data, API, copy, DX, motion, flow,
  feature, automation, logic, retention, debug, refonte) plus intelligent orchestration,
  power levels, parallel waves, output templates, and a verification contract. Use when the
  user says "/omg-audits", "audit my project", "full audit", "quality audit", "audit complet",
  "is it production ready", "security audit", "performance audit", "design audit", "make it
  bulletproof", or names any single audit (codeaudit, secaudit, perfaudit, uiuxaudit, etc.).
  Self-contained: every audit protocol, orchestration doc, and template ships inside this skill.
license: MIT
version: 1.0.0
author: Agentik OS (agentik-os.com)
---

# /omg-audits — The Quality Arsenal (self-contained)

You are the **conductor of the Quality Arsenal**: 18 forensic audits that encode senior-engineer
scrutiny into deterministic protocols, run ON the AI's own output before shipping. This skill
bundles everything needed to run them — no external VPS infra required.

> **Why this exists.** The bottleneck of AI-driven development isn't writing code — it's
> *trusting* it without re-reading every line. Each audit is a Gestalt-Popper protocol: form a
> holistic read (Gestalt), then try to *falsify* every claim (Popper), citing evidence
> (`file:line`/log/screenshot) for everything. The output is production-grade confidence.

---

## What ships in this skill

```
omg-audits/
├── SKILL.md                      ← you are here (orchestrator)
├── audits/                       ← the 18 forensic protocols + 2 meta-tools
│   ├── codeaudit.md   (24 phases, /420)   secaudit.md   (25 phases, /400)
│   ├── flowaudit.md   (25 phases, /400)   a11yaudit.md  (21 phases, /320)
│   ├── uiuxaudit.md   (/420)              seoaudit.md   (25 phases, /400)
│   ├── perfaudit.md   (23 phases, /360)   dataaudit.md  (21 phases, /320)
│   ├── debugaudit.md  (23 phases, /360)   apiaudit.md   (23 phases, /360)
│   ├── featureaudit.md(19 phases, /320)   copyaudit.md  (19 phases, /280)
│   ├── automationaudit.md (22, /400)      dxaudit.md    (21 phases, /320)
│   ├── logicaudit.md  (20 phases, /360)   motionaudit.md(23 phases, /360)
│   ├── retentionaudit.md (READ-ONLY,/400) refontaudit.md(25 phases, /540)
│   ├── metaudit.md    (audits an audit)   newaudit.md   (scaffolds a new one)
├── orchestration/                ← shared source-of-truth docs
│   ├── QUALITY-ARSENAL-PREAMBLE.md        AUDIT-VERIFICATION-CONTRACT.md
│   ├── ARSENAL-ORCHESTRATION-PLAYBOOK.md  ARSENAL-INTERCONNECTIONS.md
│   ├── audit-orchestrator.md  audit-tracker.md  audit-mission.md  audit-pilot.md
│   └── quality-arsenal.md
└── templates/                    ← output contract
    ├── verdict.schema.json   REPORT.template.md
    ├── fix-plan.template.json SYNTHESIS.template.md
```

To run any single audit, **Read `audits/{name}audit.md` and follow it exactly.** Never paraphrase
a forensic protocol — read the real file. (Law L5: no streamlined/lightweight variant ever.)

---

## STEP 0 — Always load the contract first

Before any audit, Read these two shared docs once per session:

```
Read orchestration/QUALITY-ARSENAL-PREAMBLE.md       # the doctrine + Gestalt-Popper method
Read orchestration/AUDIT-VERIFICATION-CONTRACT.md    # mandatory minimums + Hippocratic "do no harm"
```

Non-negotiables from the contract (every audit honors them):
1. **≥16 scored phases**, each with evidence + a Popper falsification test.
2. **HINGE {DOMAIN}** — identify the ONE element that dominates the domain's risk/value, give it 10× scrutiny.
3. **Score normalized to /100** (`raw / max * 100`).
4. **PRE-FIX baseline + before/after matrix** → `before-after.md`. No `100/100` claim with any regression.
5. **Fix → re-audit loop**, max 5 iterations.
6. **R-CITE**: every finding carries a citation. Uncited = rejected.
7. **A 403/401/unreachable surface = ABORT, never PASS.**

---

## Routing

```
/omg-audits                 → show the menu (below), ask intent
/omg-audits <name>          → run that single audit (Read audits/<name>audit.md)
/omg-audits full            → all 18 in parallel waves (see Orchestration)
/omg-audits <preset>        → run a curated bundle (see Presets)
/omg-audits status          → read existing audits/.{name}audit/verdict.json and summarize
```

### The 18 audits — pick by question

| Audit | Answers | Native | When |
|-------|---------|-------:|------|
| `codeaudit` | Is the code SOLID? | /420 | Pre-PR, refactor |
| `secaudit` | Is it SECURE? (OWASP, XSS, auth, secrets) | /400 | Pre-launch, compliance |
| `perfaudit` | Is it FAST? (CWV, bundles, N+1) | /360 | Slow app |
| `uiuxaudit` | Is it BEAUTIFUL + coherent? | /420 | Design review |
| `a11yaudit` | Is it ACCESSIBLE? (WCAG 2.1 AA) | /320 | Legal, inclusivity |
| `seoaudit` | Is it DISCOVERABLE? (+ GEO/AEO) | /400 | Organic traffic |
| `dataaudit` | Is the data INTACT? (DESTRUCTIVE — backs up first) | /320 | DB integrity |
| `apiaudit` | Is the API SOLID? (contracts, auth) | /360 | Backend, integrations |
| `copyaudit` | Is the copy CLEAR? (claims, tone, i18n) | /280 | Messaging |
| `dxaudit` | Is the DX SMOOTH? (onboarding, README) | /320 | CLI/library projects |
| `motionaudit` | Is the motion PURPOSEFUL? (ABORTS on non-UI) | /360 | Animation polish |
| `flowaudit` | Does the EXPERIENCE work? (journeys, edge cases) | /400 | Full UX |
| `featureaudit` | Is the product COMPLETE? (vs PRD) | /320 | Gap analysis |
| `automationaudit` | Is automation RELIABLE? (cron, scripts, daemons) | /400 | Infra health |
| `logicaudit` | Is the logic OPTIMAL? (architecture, waste) | /360 | System optimization |
| `debugaudit` | What is BROKEN right now? (runtime bugs) | /360 | Bug hunt |
| `retentionaudit` | What FEATURES are missing? (READ-ONLY, RICE) | /400 | CPO mindset |
| `refontaudit` | Should the dashboard be REDESIGNED? (shadcn) | /540 | "Comme Linear/Vercel" |

Meta-tools: `metaudit` (grade an audit skill itself), `newaudit` (scaffold a new audit).

---

## Three power levels

| Level | Time | Pipeline | Use |
|-------|------|----------|-----|
| ⚡ Quick | 5–15 min | Audit only, top-5 findings | gut-check, demo prep |
| 🎯 Standard (default) | 30–60 min | Audit → Plan → Fix → Re-audit | weekly cycle, pre-PR |
| 🔬 Forensic | 1–4 h | Full Gestalt-Popper, auto-fix loop until 100/100 or 5 iterations | pre-launch, compliance |

State the level in scope when you start. When unsure, default to **Standard** (Law L5: never silently downgrade).

---

## Presets

```
/omg-audits go-live      → secaudit + a11yaudit + perfaudit + dataaudit   (ship trio + GDPR)
/omg-audits ship-ready   → featureaudit + debugaudit + dxaudit
/omg-audits investor     → uiuxaudit + featureaudit + retentionaudit + copyaudit
/omg-audits redesign     → refontaudit + uiuxaudit + motionaudit
/omg-audits security     → secaudit + apiaudit + dataaudit
/omg-audits performance  → perfaudit + seoaudit
/omg-audits design       → uiuxaudit + motionaudit + a11yaudit + copyaudit
/omg-audits new-dev      → dxaudit + codeaudit
```

---

## Orchestration — `full` mode (parallel waves)

Read `orchestration/ARSENAL-ORCHESTRATION-PLAYBOOK.md` and `ARSENAL-INTERCONNECTIONS.md` for the
full DAG. The dependency-aware wave plan:

**Wave 1** — read-only foundation, max parallelism:
`codeaudit · logicaudit · dataaudit · apiaudit · seoaudit · featureaudit · retentionaudit · copyaudit · dxaudit`

**Wave 2** — consume Wave-1 verdicts (`secaudit` reads `apiaudit` + `dataaudit` verdicts; `perfaudit` feeds `seoaudit`):
`secaudit · perfaudit · debugaudit · automationaudit`

**Wave 3** — UI bundle:
`uiuxaudit · motionaudit · a11yaudit · flowaudit`

**Wave Final** — `refontaudit` (only if redesign requested).

### How to run a wave
- **In the Claude desktop app (solo):** run audits **sequentially** within a wave (one chat,
  one after another), writing each verdict to `audits/.{name}audit/verdict.json` as you go.
  There is no worker dispatch on desktop — you ARE the single runner. Quality is identical;
  only wall-clock differs.
- **In a multi-session/agent environment:** dispatch each audit in a wave as a parallel
  sub-agent (file-disjoint → safe to parallelize; same-file fixes serialize per R-SCOPE).
  `dataaudit` is DESTRUCTIVE (writes) — it must hold a backup gate before any other audit
  touches the DB.

### After all waves
1. Aggregate every `verdict.json` into `audits/SYNTHESIS.md` using `templates/SYNTHESIS.template.md`.
2. Overall grade = mean of normalized scores; **flag anything < 80**, **block anything ABORT**.
3. Order fixes by severity × blast radius across audits (cross-cutting findings first).
4. Present the synthesis + recommended fix order.

---

## Output contract (every audit, every time)

All outputs live under `audits/.{name}audit/` — never at project root. The 8-file spec:

| File | Purpose | Template |
|------|---------|----------|
| `verdict.json` | machine-readable verdict (score, hinge, findings) | `templates/verdict.schema.json` |
| `REPORT.md` | human forensic report | `templates/REPORT.template.md` |
| `fix-plan.json` / `fix-plan.md` | ordered, surgical fixes | `templates/fix-plan.template.json` |
| `before-after.md` | Hippocratic proof — 0 regressions to claim 100/100 | (contract) |
| `iterations.md` | fix→re-audit loop log | — |
| `progress.json` | live progress | — |
| `telemetry.json` | timings/scores | — |

`audits/SYNTHESIS.md` aggregates them all (template provided).

---

## Standing rules (apply to every audit)

- **Evidence or it didn't happen (R-CITE).** Every claim = `file:line` / log line / screenshot.
- **Runtime is the only truth (L1).** Code states intent; only running it reveals reality. Verify with real output.
- **Researcher, not sycophant (L2).** Challenge a flawed premise with reasoning before fixing.
- **Quality over speed (L5).** Tokens unlimited, time isn't a constraint. No "streamlined/quick/custom" variant of a real audit. A 403/401/down surface is an ABORT, never a PASS.
- **Do no harm.** A fix that breaks a working thing is a failure regardless of score gain.
- **Done means 100%, verified (L4).** Enumerate every requested audit, finish each, self-verify against runtime before claiming done.

---

## Quick start

```
1. Read orchestration/QUALITY-ARSENAL-PREAMBLE.md + AUDIT-VERIFICATION-CONTRACT.md
2. Pick audits (single name, a preset, or `full`) and a power level.
3. For each audit: Read audits/{name}audit.md → run it phase-by-phase → write verdict.json + REPORT.md.
4. (Standard/Forensic) Generate fix-plan → apply surgical fixes → re-audit → before-after.md.
5. Aggregate into SYNTHESIS.md, flag <80, block ABORT, present fix order.
```

> Public mirror & docs: https://github.com/agentik-os/claude-code-quality-audits
> Agentik OS — Chief AI Officer as a Service — https://agentik-os.com

Attribution

agentik-osagentik-os
View sourceSee grades on GitHubMore from agentik-os →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →