Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Dim Audit

ASecurity

Audit an existing codebase across independent quality areas, one reader each, and report findings the owner turns into orders. Use for a read-only sweep of code already on the default branch.

5 stars
0 votes
0 copies
0 views
Added 10/5/2026
researchsecurity

Security Analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned 10/5/2026

$npx -y skills add cniska/dim-factory --skill dim-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dim Audit?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Dim Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cniska-dim-audit/badge)](https://www.skillsdirectory.com/skills/cniska-dim-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: dim-audit
description: Audit an existing codebase across independent quality areas, one reader each, and report findings the owner turns into orders. Use for a read-only sweep of code already on the default branch.
argument-hint: "<project or path>"
---

# Audit

`dim-review` judges a change; an audit examines the project, or the scope named, as it stands. It changes nothing: not the project, not the record, not an order.

## Scope

Name the project, revision and scope. Read its rules and the docs that state the scope's behavior and boundaries, then list the source and tests it owns. Name a missing authority instead of assuming one. Leave out generated files and dependencies, and name any part that cannot be inspected. Size the scope so each reader inspects its paths in full; divide a larger audit into coherent scopes and report each separately.

## The passes

One read-only agent per area in [quality areas](references/quality-areas.md), plus one for every entry in [agent anti-patterns](references/agent-anti-patterns.md), each given the same scope and revision, the project's rules and only its own brief. A reader may search to find candidates, but judges each only after reading the surrounding implementation, callers, tests and contracts. The anti-pattern examples are from dim-factory; apply a project rule only where the audited project has adopted it, and translate each fix to that project's own files and commands. A test that must change for a behavior-preserving refactor is suspect, while a guard for a wire value, a model-facing instruction, security or storage stays.

Each reader returns source-backed findings, the paths it checked and the paths it could not judge. For a proposed test deletion, it names the failure the test can detect, the production owner, overlapping tests and the stronger proof that would remain. Responsibility for the result stays in this session.

## Report

State the revision and scope. One row per area with `findings`, `clear`, `not_applicable` or `incomplete`, and a reason for either of the last two; the anti-pattern row accounts for every entry. A `clear` mark means the relevant paths were read, not that a search matched nothing. For each confirmed finding, give the area, file and line, the consequence, the source evidence and the fix. Say what would settle each unresolved case.

The result is for the operator to decide what work to request. A clean audit means every applicable area was read in the stated scope and no finding survived verification.

Attribution

cniskacniska
View sourceSee grades on GitHubMore from cniska →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Competitor Analysis

This skill provides comprehensive analysis of competitor SEO and GEO strategies, revealing what's working in your market and identifying opportunities to outperform the competition.

1823 votes

Deep Research

Universal deep research agent team. 13-agent pipeline for rigorous academic research on any topic. 8 modes: full research, quick brief, paper review, lit-review, fact-check, three-way literature scan, Socratic guided research dialogue, and systematic review with optional meta-analysis. Covers research question formulation, Socratic mentoring, methodology design, systematic literature search, source verification, cross-source synthesis, risk of bias assessment, meta-analysis, APA 7.0 report co...

502942 votes

Paperclip Distill

Use when an operation issue is a Paperclip cursor-window, distill, or backfill — `operationType: "distill"` or `"backfill"` and the body references a Paperclip source bundle for a project or root issue. Turn raw Paperclip activity into a wiki-insightful project page, decisions log, and history note. This skill exists specifically to replace the stiff, datestamp-heavy templated output that the deterministic distiller produces.

953191 votes

Academic Pipeline

Orchestrator for the full academic research pipeline: research -> write -> integrity check -> review -> revise -> re-review -> re-revise -> final integrity check -> finalize. Coordinates deep-research, academic-paper, and academic-paper-reviewer into a seamless 10-stage workflow with mandatory, coverage-bounded integrity checks, two-stage peer review, and auditable quality-assurance artifacts. Triggers on: academic pipeline, research to paper, full paper workflow, paper pipeline, end-to-end p...

502941 votes

Literature Review

Assistance with writing literature reviews by searching for academic sources via Semantic Scholar, OpenAlex, Crossref and PubMed APIs. Use when the user needs to find papers on a topic, get details for specific DOIs, or draft sections of a literature review with proper citations.

6511 votes
View all in research →