audit

Audit code, infrastructure, and sprint artifacts for security and quality risks.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/project-purupuru/world-purupuru --skill audit-project-purupuru
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit
Source: https://github.com/project-purupuru/world-purupuru/tree/main/.claude/skills/auditing-security
Command: npx skills add https://github.com/project-purupuru/world-purupuru --skill audit-project-purupuru

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill identifies security and quality risks across codebases, configurations, deployments, and sprint outcomes, enabling teams to act quickly on the most critical findings.

Core Features & Use Cases

  • Comprehensive coverage across Security, Architecture, Code Quality, DevOps, and Blockchain (where applicable) to surface cross-cutting risks.
  • Actionable reporting that prioritizes issues with remediation steps and references to standards (CWE/OWASP) for fast remediation.
  • Sprint-aware audits that tie findings to sprint artifacts (review notes, deployment plans, and code changes) to accelerate remediation before release.

Quick Start

Analyze the latest sprint and codebase to produce a comprehensive security audit report.

Frequently Asked Questions about audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security audit on my codebase before a release?

To run a security audit on your codebase, apply this Skill to code changes, deployment configurations, and infrastructure-as-code. It identifies security and quality risks, then generates structured findings with severity levels and references to standards like CWE and OWASP.

Can I audit infrastructure-as-code and deployment configurations for compliance risks?

Yes, you can audit infrastructure-as-code and deployment configurations for compliance risks. The Skill surfaces cross-cutting security and architecture issues across these artifacts, enforcing mandatory frontmatter to ensure structured, actionable reporting.

What is the best way to tie security findings to sprint deliverables?

The best way to tie security findings to sprint deliverables is to apply sprint-aware audits. This connects findings directly to sprint artifacts like review notes and deployment plans, accelerating remediation before release.

Does the audit report include remediation steps and references to security standards?

Yes, the audit report includes remediation steps and references to security standards. It prioritizes identified issues with actionable guidance mapped to CWE and OWASP, outputting comprehensive reports in Markdown or JSONL formats.

How do I generate structured security findings in Markdown and JSONL formats?

You generate structured security findings in Markdown and JSONL formats by applying the Skill to your codebase and sprint artifacts. It automatically produces audit reports detailing severity levels and references for fast remediation.

What coverage areas does a codebase security audit include?

A codebase security audit includes comprehensive coverage across Security, Architecture, Code Quality, DevOps, and Blockchain where applicable. This surfaces cross-cutting risks throughout your development and review processes.