Skip to content
Documentation
Command

/audit

Run a comprehensive audit of: $ARGUMENTS

From plugin
claude-best-practice
48 skills3 agents8 commands
Install
$ npx -y skills add vignesh2027/claude-best-practice --agent claude-code

How it fires

How this command gets triggered: by you, by Claude, or both.

  • Fires itselfClaude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/audit

Context preview

What this command does when you run it.

Run a comprehensive audit of: $ARGUMENTS

Command definition

audit.md

/audit — Security & Quality Audit

Run a comprehensive audit of: $ARGUMENTS

If no argument, audit all files changed since last commit.

Security Audit

Secrets & Credentials

Search for hardcoded:

  • API keys, tokens, passwords
  • Database connection strings
  • Private keys or certificates
  • Internal URLs or IP addresses
grep -rn "password\|secret\|token\|api_key\|apikey\|private_key" --include="*.ts" --include="*.js" --include="*.py" .

Injection Vulnerabilities

  • SQL queries built with string concatenation
  • Shell commands built from user input
  • Template injection risks

Authentication & Authorization

  • Are all sensitive routes protected?
  • Is authorization checked (not just authentication)?
  • Are JWT secrets properly managed?
  • Are session tokens properly invalidated?

Dependencies

npm audit

Report any HIGH or CRITICAL vulnerabilities.

OWASP Top 10 Checklist

  • [ ] A01: Broken Access Control
  • [ ] A02: Cryptographic Failures
  • [ ] A03: Injection
  • [ ] A04: Insecure Design
  • [ ] A05: Security Misconfiguration
  • [ ] A06: Vulnerable Components
  • [ ] A07: Auth Failures
  • [ ] A08: Software Integrity Failures
  • [ ] A09: Logging Failures
  • [ ] A10: SSRF

Quality Audit

Code Complexity

Find functions with high cyclomatic complexity (many branches).

Dead Code

Find exports/functions that are defined but never imported/called.

Test Coverage Gaps

Find files with no corresponding test files.

Output

Report all findings grouped by severity: Critical → High → Medium → Low → Info

Read more
Ships withclaude-best-practice

The most comprehensive, production-ready guide to mastering Claude Code From vibe coding → agentic engineering → autonomous AI development teams Built for engineers who treat Claude Code as infrastructure, not a toy.

Get the whole plugin
Stats
4
Stars
1
Forks
Active
Maintenance
Shell
Language
17d ago
Last commit
4mo ago
Created

Repo: vignesh2027/claude-best-practice

Other commands on claude-best-practice.