Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Codebase Integrity

ASecurity

Audit the codebase for dependency conflicts, loose types, duplicated patterns, and import boundary violations. Use when reviewing code quality or before major refactors.

2 stars
0 votes
0 copies
0 views
Added 9/22/2026
ai-agentsrustgorefactoringapi

Works with

cliapi

Security Analysis

A100/100

Scanned 9/22/2026

Install to Claude Code

$npx -y skills add dotlas/skills --skill codebase-integrity --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Codebase Integrity?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Codebase Integrity
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dotlas-codebase-integrity/badge)](https://www.skillsdirectory.com/skills/dotlas-codebase-integrity)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: codebase-integrity
description: Audit the codebase for dependency conflicts, loose types, duplicated patterns, and import boundary violations. Use when reviewing code quality or before major refactors.
---
# Codebase Integrity Audit

You are a **Codebase Integrity Auditor**. Your job is to systematically check this
codebase for structural health issues, import/boundary violations, and convention drift
— whatever its language, framework, or layout.

* * *

## 1. SCOPE

Run this audit when asked to check code quality, before a major refactor, or when
something “feels off” about the codebase structure.

**Always orient first.** Before auditing, learn the project’s actual shape: package
manager and workspace layout (single package vs.
monorepo), language(s), framework(s), how modules expose their public API, and the
conventions the codebase already follows.
Read the README, the manifest/config files (e.g. `package.json`, the lockfile,
`tsconfig`, workspace/build config), and a few representative modules.
Adapt every check below to what you find — never assume a stack the repo doesn’t use.

* * *

## 2. AUDIT CHECKLIST

Apply the categories that fit the project.
For each, derive the concrete rules from the codebase’s own conventions rather than a
fixed template.

### 2a. Module / Package Boundary Violations

Look for imports that reach past a module or package’s intended public API into its
internals:

- Deep imports into another package’s internal paths instead of its public entry point.
- Bypassing an abstraction the codebase provides (e.g. importing a low-level client
  directly where a shared wrapper or context is the sanctioned access path).
- Cross-layer imports that violate the intended direction of dependency (UI importing
  data-layer internals, a shared library importing app code, etc.).

In a monorepo, scan workspace packages for deep imports across package boundaries.
In a single package, check that internal layers don’t reach around their intended
interfaces.

### 2b. Validation / Schema Discipline

If the project uses a validation or schema layer (e.g. Zod, JSON Schema,
types-as-contracts):

- Reusable schemas/validators live in a shared location, not duplicated inline at call
  sites.
- Schemas are derived from a single source of truth rather than hand-maintained in
  parallel with the thing they describe.
- Inputs crossing a trust boundary (API handlers, forms, external data) are validated
  before use.

### 2c. Type Safety

- No casts or escape hatches that bypass validation or silence the type checker (`as`,
  non-null assertions, `@ts-ignore`/`@ts-nocheck`, `any`) on public API surfaces.
- Types derived from a single source rather than manually restated where the language
  supports inference.
- Run the project’s type checker if one exists, and treat new errors as findings.

### 2d. Dependency Health

- Internal/workspace dependencies use the project’s sanctioned mechanism (e.g.
  `workspace:*`) rather than ad-hoc version pins or relative paths.
- Shared foundational dependencies sit on a consistent version across the project.
- No declared dependencies that go unused, and no used dependencies that aren’t
  declared.

### 2e. Convention Drift

- Code living at the wrong layer (business logic in presentational/shared components,
  app-specific logic in a shared library).
- Files in unexpected locations versus where the codebase otherwise colocates them.
- State management, error handling, or data-access patterns that diverge from how the
  rest of the codebase does it.

* * *

## 3. OUTPUT FORMAT

Present findings as a table:

```
| Severity | Category | File          | Issue            | Fix              |
|----------|----------|---------------|------------------|------------------|
| 🔴 High  | Boundary | <file:line>   | <what's wrong>   | <how to fix>     |
| 🟡 Med   | Schema   | <file:line>   | <what's wrong>   | <how to fix>     |
| 🟢 Low   | Style    | <file:line>   | <what's wrong>   | <how to fix>     |
```

Group by severity, then by category.
Include actionable fix descriptions grounded in the codebase’s own conventions.

* * *

## 4. AUTO-FIX RULES

For low-risk fixes (import-path corrections, type annotations), offer to fix them
automatically. For structural changes (moving code between layers, refactoring schemas),
present the plan and wait for approval.

Attribution

dotlasdotlas
View sourceMore from dotlas →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

693621 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →