Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Autonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations
.claude/skills/davila7-production-code-audit/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-16 | ✗→✓ | ▲ Improved | 323% | 0% |
| case-14 | ✓→✗ | ▼ Worse | 46% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 125% | 0% |
| case-07 | ✓→✓ | = Same ✓ | 534% | 0% |
| case-08 | ✓→✓ | = Same ✓ | 202% | 0% |
Autonomously analyze the entire codebase to understand its architecture, patterns, and purpose, then systematically transform it into production-grade, corporate-level professional code. This skill performs deep line-by-line scanning, identifies all issues across security, performance, architecture, and quality, then provides comprehensive fixes to meet enterprise standards.
Automatically scan and understand the entire codebase:
Do this automatically without asking the user.
Scan line-by-line for all issues:
Architecture Issues:
Security Vulnerabilities:
Performance Problems:
Code Quality Issues:
Testing Gaps:
Production Readiness:
Fix everything automatically:
After making all changes:
markdownUser: @production-code-audit make this production-ready AI: I'll scan your entire codebase and transform it to production-grade quality. **Phase 1: Discovering Codebase** (analyzing 247 files) - Detected: Node.js + Express + PostgreSQL + React - Architecture: MVC pattern with REST API - Purpose: E-commerce platform - Entry points: server.js, src/index.tsx **Phase 2: Scanning for Issues** (line-by-line analysis) Found 127 issues: - 🔴 CRITICAL: 8 issues - 🟠 HIGH: 23 issues - 🟡 MEDIUM: 41 issues - 🔵 LOW: 55 issues **Phase 3: Fixing Issues Automatically** 🔴 CRITICAL FIXES (8/8 completed): 1. ✅ Fixed SQL injection in UserRepository.findByEmail() - Before: String concatenation in query - After: Parameterized query with $1 placeholder 2. ✅ Removed hardcoded database password from config/database.ts - Before: password: 'SuperSecret123!' - After: password: process.env.DB_PASSWORD 3. ✅ Added authentication to admin routes - Before: No auth middleware - After: authenticateToken + requireRole('admin') 4. ✅ Fixed weak password hashing (MD5 → bcrypt) - Before: crypto.createHash('md5') - After: bcrypt.hash(password, 12) 5. ✅ Fixed circular dependency: OrderService ↔ PaymentService - Before: Direct imports causing cycle - After: Event-based decoupling with EventBus 6. ✅ Added input validation to all API endpoints - Before: No validation - After: Zod schemas validating all inputs 7. ✅ Fixed authentication bypass in auth middleware - Before: next() called on missing token - After: Returns 401 error 8. ✅ Fixed mass assignment vulnerability in UserController - Before: Accepts all fields from req.body - After: Whitelist of allowed fields only 🟠 HIGH PRIORITY FIXES (23/23 completed): 9. ✅ Fixed N+1 query in OrderService.getOrdersWithItems() - Before: Loop with individual queries (2.8s) - After: Single query with joins (45ms) - Performance: 98% improvement 10. ✅ Refactored UserService god class (850 lines → 4 focused services) - UserAuthenticationService (login, logout, password) - UserProfileService (CRUD operations) - UserNotificationService (email, SMS) - UserPermissionService (roles, permissions) 11. ✅ Added Redis caching for product queries - Before: Database query every request - After: Cache with 1-hour TTL - Performance: 95% faster 12. ✅ Optimized bundle size - Before: 850KB (gzipped: 280KB) - After: 380KB (gzipped: 120KB) - Improvement: 55% reduction 13. ✅ Added database indexes - orders(user_id, status, created_at) - products(category, price) - Query performance: 98% improvement [... 11 more high-priority fixes ...] 🟡 MEDIUM PRIORITY FIXES (41/41 completed): [... all medium fixes ...] 🔵 LOW PRIORITY IMPROVEMENTS (55/55 completed): [... all low improvements ...] **Phase 4: Adding Production Infrastructure** ✅ Added structured logging (Winston) ✅ Added error tracking (Sentry) ✅ Added health check endpoints (/health, /ready) ✅ Added monitoring (Prometheus metrics) ✅ Added rate limiting (Redis-based) ✅ Added API documentation (Swagger/OpenAPI) ✅ Added comprehensive README ✅ Added deployment guide ✅ Added CI/CD pipeline (.github/workflows) **Phase 5: Verification** ✅ All tests passing (1,247 tests) ✅ Test coverage: 42% → 87% ✅ Security scan: 0 vulnerabilities ✅ Performance: API response time 3.2s → 180ms ✅ Bundle size: 850KB → 380KB ✅ Lighthouse score: 62 → 94 **TRANSFORMATION COMPLETE** Your codebase is now production-ready with enterprise-grade quality: 📊 Metrics: - Issues fixed: 127/127 (100%) - Test coverage: 87% (target: 80%+) - API performance: 94% improvement - Security: OWASP Top 10 compliant - Code quality: Grade A- 📁 Files changed: 89 files 📝 Lines changed: +3,247 / -1,892 🚀 Ready for production deployment!
markdownUser: @production-code-audit secure this codebase AI: Scanning for security vulnerabilities... **Security Scan Complete** Found 15 security issues: - 🔴 CRITICAL: 5 - 🟠 HIGH: 7 - 🟡 MEDIUM: 3 **Fixing all security issues automatically...** 🔴 CRITICAL (5/5 fixed): 1. ✅ SQL Injection in UserRepository \`\`\`typescript // Before (VULNERABLE) const query = \`SELECT * FROM users WHERE email = '\${email}'\`; // After (SECURE) const query = 'SELECT * FROM users WHERE email = $1'; await db.query(query, [email]); \`\`\` 2. ✅ Hardcoded Secrets Removed \`\`\`typescript // Before (INSECURE) const JWT_SECRET = 'my-secret-key-123'; // After (SECURE) const JWT_SECRET = process.env.JWT_SECRET; if (!JWT_SECRET) throw new Error('JWT_SECRET required'); \`\`\` 3. ✅ Authentication Added to Admin Routes \`\`\`typescript // Before (VULNERABLE) router.delete('/api/admin/users/:id', deleteUser); // After (SECURE) router.delete('/api/admin/users/:id', authenticateToken, requireRole('admin'), deleteUser ); \`\`\` 4. ✅ Password Hashing Upgraded \`\`\`typescript // Before (WEAK) const hash = crypto.createHash('md5').update(password).digest('hex'); // After (STRONG) const hash = await bcrypt.hash(password, 12); \`\`\` 5. ✅ Input Validation Added \`\`\`typescript // Before (VULNERABLE) const user = await db.user.create({ data: req.body }); // After (SECURE) const schema = z.object({ email: z.string().email(), password: z.string().min(12), name: z.string().min(2).max(100) }); const validated = schema.parse(req.body); const user = await db.user.create({ data: validated }); \`\`\` **Security Status:** - ✅ OWASP Top 10: Compliant - ✅ SQL Injection: Protected - ✅ XSS: Protected - ✅ CSRF: Protected - ✅ Authentication: Secure - ✅ Secrets: Environment variables - ✅ Dependencies: No vulnerabilities 🔒 Codebase is now secure and production-ready!
markdownUser: @production-code-audit optimize performance AI: Analyzing performance bottlenecks... **Performance Analysis Complete** Current metrics: - API response time: 3.2s (target: <200ms) - Page load time: 8.5s (target: <2s) - Bundle size: 850KB (target: <200KB) **Optimizing automatically...** ✅ Fixed N+1 queries (3.2s → 180ms - 94% faster) ✅ Added Redis caching (95% cache hit rate) ✅ Optimized database indexes (98% faster queries) ✅ Reduced bundle size (850KB → 380KB - 55% smaller) ✅ Optimized images (28MB → 3.2MB - 89% smaller) ✅ Implemented code splitting ✅ Added lazy loading ✅ Parallelized async operations **Performance Results:** | Metric | Before | After | Improvement | |--------|--------|-------|-------------| | API Response | 3.2s | 180ms | 94% | | Page Load | 8.5s | 1.8s | 79% | | Bundle Size | 850KB | 380KB | 55% | | Image Size | 28MB | 3.2MB | 89% | | Lighthouse | 42 | 94 | +52 points | 🚀 Performance optimized to production standards!
When this skill is invoked, automatically:
listDirectory to find all files recursivelyreadFile to read every source filestrReplace to fix issues in filesDo all of this without asking the user for input.
Symptoms: Team paralyzed by 200+ issues Solution: Focus on critical/high priority only, create sprints
Symptoms: Flagging non-issues Solution: Understand context, verify manually, ask developers
Symptoms: Audit report ignored Solution: Create GitHub issues, assign owners, track in standups
markdown# Production Audit Report **Project:** [Name] **Date:** [Date] **Overall Grade:** [A-F] ## Executive Summary [2-3 sentences on overall status] **Critical Issues:** [count] **High Priority:** [count] **Recommendation:** [Fix timeline] ## Findings by Category ### Architecture (Grade: [A-F]) - Issue 1: [Description] - Issue 2: [Description] ### Security (Grade: [A-F]) - Issue 1: [Description + Fix] - Issue 2: [Description + Fix] ### Performance (Grade: [A-F]) - Issue 1: [Description + Fix] ### Testing (Grade: [A-F]) - Coverage: [%] - Issues: [List] ## Priority Actions 1. [Critical issue] - [Timeline] 2. [High priority] - [Timeline] 3. [High priority] - [Timeline] ## Timeline - Critical fixes: [X weeks] - High priority: [X weeks] - Production ready: [X weeks]
@code-review-checklist - Code review guidelines@api-security-best-practices - API security patterns@web-performance-optimization - Performance optimization@systematic-debugging - Debug production issues@senior-architect - Architecture patternsPro Tip: Schedule regular audits (quarterly) to maintain code quality. Prevention is cheaper than fixing production bugs!
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 12,289 | 11,099 | -10% | 1 | 1 | 0% | 1,489 | 5,498 | +269% | 0 | 0 | — |
case-02 | fail→fail | 10,093 | 3,147 | -69% | 1 | 1 | 0% | 1,461 | 4,468 | +206% | 0 | 0 | — |
case-03 | fail→fail | 4,749 | 4,175 | -12% | 1 | 1 | 0% | 694 | 4,317 | +522% | 0 | 0 | — |
case-04 | pass→pass | 18,005 | 18,908 | +5% | 1 | 1 | 0% | 3,132 | 7,056 | +125% | 0 | 0 | — |
case-05 | fail→fail | 13,936 | 12,397 | -11% | 1 | 1 | 0% | 2,446 | 6,464 | +164% | 0 | 0 | — |
case-06 | fail→fail | 16,207 | 6,431 | -60% | 1 | 1 | 0% | 3,022 | 4,463 | +48% | 0 | 0 | — |
case-07 | pass→pass | 7,605 | 8,061 | +6% | 1 | 1 | 0% | 832 | 5,279 | +534% | 0 | 0 | — |
case-08 | pass→pass | 10,404 | 8,877 | -15% | 1 | 1 | 0% | 1,930 | 5,828 | +202% | 0 | 0 | — |
case-09 | pass→pass | 9,806 | 17,450 | +78% | 1 | 1 | 0% | 1,765 | 6,197 | +251% | 0 | 0 | — |
case-10 | pass→pass | 13,610 | 14,974 | +10% | 1 | 1 | 0% | 2,477 | 6,978 | +182% | 0 | 0 | — |
case-11 | fail→fail | 17,458 | 2,773 | -84% | 1 | 1 | 0% | 3,222 | 4,363 | +35% | 0 | 0 | — |
case-12 | pass→pass | 18,933 | 22,183 | +17% | 1 | 1 | 0% | 3,405 | 8,699 | +155% | 0 | 0 | — |
case-13 | pass→pass | 19,250 | 20,219 | +5% | 1 | 1 | 0% | 3,284 | 7,612 | +132% | 0 | 0 | — |
case-14 | pass→fail | 15,537 | 6,149 | -60% | 1 | 1 | 0% | 2,945 | 4,314 | +46% | 0 | 0 | — |
case-15 | pass→pass | 8,906 | 12,192 | +37% | 1 | 1 | 0% | 1,483 | 6,145 | +314% | 0 | 0 | — |
case-16 | fail→pass | 10,883 | 14,220 | +31% | 1 | 1 | 0% | 1,612 | 6,817 | +323% | 0 | 0 | — |
case-17 | fail→fail | 19,143 | 39,828 | +108% | 1 | 1 | 0% | 3,139 | 7,733 | +146% | 0 | 0 | — |
case-18 | fail→fail | 15,416 | 16,464 | +7% | 1 | 1 | 0% | 3,032 | 7,614 | +151% | 0 | 0 | — |
case-19 | fail→fail | 11,477 | 16,745 | +46% | 1 | 1 | 0% | 1,815 | 6,794 | +274% | 0 | 0 | — |
case-20 | pass→pass | 23,664 | 37,417 | +58% | 1 | 1 | 0% | 3,930 | 7,994 | +103% | 0 | 0 | — |
case-21 | pass→pass | 9,661 | 9,445 | -2% | 1 | 1 | 0% | 1,500 | 5,733 | +282% | 0 | 0 | — |
case-22 | pass→pass | 27,320 | 34,684 | +27% | 1 | 1 | 0% | 4,303 | 9,677 | +125% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 20 counted toward the lift figure. The other 2 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of 0 percentage points is the difference between those two pass rates over the 20 comparable cases. 2 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.