Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Refactor

ASecurity

Audit an existing project against its standards and apply selected improvements while preserving behavior.

12 stars
0 votes
0 copies
0 views
Added 9/22/2026
developmentgodatabasesecuritydocumentation

Security Analysis

A100/100

Scanned 9/22/2026

Install to Claude Code

$npx -y skills add reidemeister94/development-skills --skill refactor --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Refactor?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Refactor
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/reidemeister94-refactor/badge)](https://www.skillsdirectory.com/skills/reidemeister94-refactor)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: refactor
description: "Audit an existing project against its standards and apply selected improvements while preserving behavior."
argument-hint: "[focus]"
user-invocable: true
disable-model-invocation: true
effort: xhigh
disallowed-tools: Write Edit NotebookEdit
---

# Refactor

Bring an existing project closer to its standards without changing user-visible behavior.
This is the repository-convergence exception in the [development loop](../../shared/development-loop.md).
It can inspect the whole target but can change only an approved tranche.

`$ARGUMENTS` is a free-text focus, such as `database queries`, `src/orders`, or a planned feature.
With a focus, audit that area and its required dependencies. Without one, audit the whole project.
The audit is always read-only. The user chooses what to change afterwards.

The audit changes nothing in the target.
The frontmatter withholds write tools during the audit, but the rule holds even when the harness exposes them.

## 1. Audit

Apply the loop's Standards gate and the [engineering contract](../../shared/engineering.md).
Record the source paths you selected.

Use focused owners where their signal exists:

- `align-docs` in inspection-only mode for repository context and documentation;
- `staff-review` for code quality inside the scope.

Then inspect what these owners do not cover.
Check the data model, query access paths, batching, indexes, repeated work, held resources, retries, recomputation, and behavior with multiple owners.

Exclude generated code and dependencies.
Record inspected surfaces and gaps.
Confirm disputed library behavior in official documentation for the installed version.

Every finding includes evidence, location, [severity](../../shared/review-categories.md), expected result, impact, effort, change risk, dependencies, confidence, and required proof.

## 2. Rank

Do not invent a score.
Put security and data-loss risks before normal impact-to-effort ordering.
Severity measures defect risk. Impact over effort orders the roadmap.

Use repository history to weight code that changes often.
Group findings with one root cause into one item.
Label each item `strong`, `worth exploring`, or `speculative`. Mark estimated values as estimates.
Diagnose only. Do not design the fix yet.

## 3. Choose

Present the roadmap, then ask the user to select tranches.
Selecting none ends the work with the audit.
A tranche covers one area, has compatible dependencies, and shares one verification and rollback strategy.

A pure audit writes nothing.
Save the roadmap under `docs/plans/` only after the user selects work or explicitly asks to save it.

## 4. Converge

Run a full cycle for each tranche:

1. Use `brainstorming` and `create-test` to settle invariants, thresholds, failure cases, and rollback.
2. Capture a characterization proof that passes on unchanged code and after the refactor.
3. Write the plan and chronicle, then present the plan for approval before code changes.
4. Implement in small slices and run the nearest check after each slice.

Finish with cumulative verification, independent review, and a recalculated roadmap.
If a tranche fails proof or review, stop and report it.

Keep business changes as separate tasks.
Do not widen a tranche during implementation. Record a new finding in the roadmap.
Never commit.

## 5. Resume

The saved roadmap and any incomplete tranche plan are the persistent state.
A later run resumes them instead of repeating the audit.

Attribution

reidemeister94reidemeister94
View sourceMore from reidemeister94 →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

284072 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2192 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

9881 votes

Pentest

PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.

5491 votes
View all in development →