production-audit

Installation
SKILL.md

Production Audit

Overview

A skill that runs an external audit on a shipped repo's deployed state — live URL, GitHub signals, secrets exposure, RLS gaps, webhook idempotency, indexes, observability, prompt injection, and ten other failure modes that AI-assisted projects routinely miss.

This is complementary to in-session security skills (security-review, OWASP-style, VibeSec, Trail of Bits). Those scan the editor buffer at write-time. This scans the deployed product after you commit. Different timing, different inputs, different findings. Run both for serious launches.

The skill wraps the commit.show audit engine via the public CLI (npx commitshow@0.3.23 audit . --json). Stable JSON envelope (schema_version: "1", additive-only). Writes a .commitshow/audit.{md,json} sidecar so future agent sessions can read prior state without re-running the engine.

When to Use This Skill

  • Use when the user asks "is this production-ready", "what would break in prod", "score my project", "what did I miss", "audit my repo", "ready to ship".
  • Use right after merging a feature branch to main (helpful as a pre-deploy gate).
  • Use before a public launch / Show HN post / investor demo.
  • Use when git log shows >20 commits since the last .commitshow/audit.md was written.

Skip when

Related skills
Installs
4
GitHub Stars
37.3K
First Seen
7 days ago