hyperflow-audit
Hyperflow code review. Use when the user wants the current diff, a commit, branch, or PR reviewed — verbs like audit, review, "check for issues", "security check", "code review". Multi-level review (L1 quick → L5 exhaustive), writes findings to .hyperflow/audits/, then a fix-gate.
git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace /tmp/hyperflow-audit && cp -r /tmp/hyperflow-audit/plugins/ai-agency/hyperflow/templates/antigravity/skills/hyperflow-audit ~/.claude/skills/hyperflow-auditSKILL.md
# hyperflow-audit — review phase (Antigravity single-agent) Multi-level review over a target (default: `git diff HEAD` + staged). Follow the `hyperflow` doctrine. Security scan is mandatory at L3+. ## Levels | L | Checks | |---|--------| | 1 | syntax, obvious bugs, formatting | | 2 | L1 + spec compliance, naming, edge cases | | 3 | L2 + cross-file consistency, integration risks, security (secrets, injection, path traversal, XSS, missing validation) | | 4 | L3 + architecture, scalability, accessibility | | 5 | L4 + adversarial probing, perf profiling, alternatives | Default to L2; elevate to L3 when the diff touches auth, data, money, or external input. ## Steps 1. **Resolve scope** (target arg or current diff). Read the changed files + their immediate dependencies. 2. **Review** at the chosen level. Grade each finding `[Critical] / [Important] / [Suggestion] / [Praise]` with `file:line` + a concrete fix. 3. **Write** the full report to `.hyperflow/audits/<YYYY-MM-DD-HHmm>-<scope>.md` (status table → TL;DR → findings → security-scan table). Print a one-line summary pointing at the file. 4. **Fix gate** via AskUserQuestion (only when Critical/Important exist): `Fix all (Recommended) / Critical+Important / Critical only / No`. On a fix choice, route the findings into `hyperflow-plan` → `hyperflow-dispatch`. On `SECURITY_VIOLATION`, skip the gate and surface immediately. ## Rules - Findings live in the file, not chat — chat shows only the summary box. - A clean run (no Critical/Important) prints `Audit clean` and still writes the file for history.
Guard the beads execution record: enforce the write-flush-verify discipline that defeats the bd rapid-write race, audit epic dependency graphs for cycles and orphans, catch closures whose title overstates what shipped, flag open beads carrying no disposition or a disproven premise, and reconcile bd against its GitHub and Plane projections. Owns RECORD INTEGRITY; delegates graph analysis to bead-dependency-mapper and epic-closure drift to bead-epic-auditor rather than duplicating them. Use before closing an epic, after any batch of bd writes, when a bead premise looks stale, or when auditing whether the record matches reality. Trigger with "audit beads", "check the bead DAG", "did that close actually land", "bead hygiene".
Verify every factual assertion in a diff, PR body, commit message, bead note, or governing doc against the actual repository, and fail anything that cannot be substantiated by a command. Use before merging any PR that makes claims about counts, coverage, consumers, enforcement, provenance, or certification, and when auditing standing docs for rot. Trigger with "verify claims", "check this PR body", "is this claim true", "claim audit".
Design and build Omarchy (Quickshell/QML) bar-widget, panel, and service plugins that actually work on a stock install. Knows the hard runtime constraint (no node on the graphical session PATH), the first-party contracts (BarWidget, Panel, KeyboardPanel, PanelKeyCatcher, Service), the curl-from-QML data pattern, FileView persistence, and the marketplace submission bar. Use when starting a new Omarchy plugin, porting a plugin off an external runtime, wiring a service to a bar widget, or deciding how a widget should fetch and persist. Trigger with "build an omarchy plugin", "omarchy widget", "quickshell plugin", "port this plugin to QML".
Audit an Omarchy plugin before it reaches the marketplace: prove it installs and runs on a stock box (no node/python on the session PATH), run the omarchy-submit gate lane, validate on the rig with omarchy-plugin-validate and qmllint, and check the QML security invariants and first-party idiom contracts. Read-only: it reports and blocks, it does not rewrite the plugin. Use before submitting an entry, after any data-layer change, or when a plugin works on the dev box and you need to know whether it works for a real user. Trigger with "audit this omarchy plugin", "is this plugin submission ready", "will this plugin work when installed".
Audit and fix Claude Code SKILL.md files against enterprise compliance standards: frontmatter completeness, required body sections, and style. Use when validating or repairing skills in a plugin directory. Trigger with "audit skill", "fix skill compliance".
Learn how SKILL.md files work in Claude Code plugins, then build a production-quality agent skill from scratch. Covers frontmatter schema, body structure, testing, and iteration.
Step-by-step guide to writing a SKILL.md file for Claude Code. Learn how to plan, structure, and test auto-activating skills with proper frontmatter, allowed-tools, dynamic context injection, and supporting files.
|