⏳ This skill is pending AI review.

Scores will appear once the review pipeline completes.

version unknown

audit

@grinchenkoedu⭐ 2 stars

Audit a whole repository — not a diff — against the rules the other skills already apply to a change: the security checklist, code provenance and licensing, the family's code-quality rules, and whether the repository is ready for agent-driven development (CLAUDE.md, AGENTS.md, an ignored profile, a detectable test command). Asks you in the chat, in one batched round, the decisions that block a fix — which licence, whether a copyleft dependency may stay, where a copied block came from — and writes your answers in as steps. Writes a task file in the /gku:plan shape, findings grouped into branch-sized rounds, that /gku:implement builds in one run or one step at a time. Read-only; writes no production code.

Choose how to use this skill

You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.

1. Native installer

This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.

Do not guess an installer command or replace an existing version without reviewing the diff.

2. Complete package recommended

Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.

No complete ProSkills package is published for this listing yet.

3. Prompt-only

Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.

Need only the instruction file?

Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.

No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.

—/10

// RATINGS

⭐GitHub Stars
⭐ 2 on GitHubGitHub ↗

New / niche

🟢ProSkills Score
—
📍

Not yet listed on ClawHub or SkillsMP

// README

claude-skills

🇬🇧 English · 🇺🇦 Українська

Skills for Claude Code that cover an ordinary development day: work out what to build, build it, check your own work, review a colleague's pull request, deal with the comments on yours, and prove the result actually works.

They work in any repository — nothing here is tied to a particular project, language or framework. They are also written to be economical, so they are usable on a modest Claude plan: no background agent swarms, no parallel sub-agents by default, and answers in the chat instead of a pile of generated report files.

They do not have to write your code. /gku:plan --manual produces a plan you build by hand — the shape of each change, the reason it is shaped that way, and the command that proves it — and the rest of the toolkit follows: /gku:implement asks before it would build such a plan, /gku:review and /gku:verify read what you typed exactly as they read anything else, and none of them ever commits for you. Use the agent as an adviser and reviewer, where that is what helps, and keep the keyboard: in a repository that does not accept generated code, on a change too delicate to hand over, or while you are learning a codebase and writing it yourself is the whole point.

MIT licensed.


Contents


What is this, exactly?

A skill is a set of instructions you can call by name in Claude Code. Instead of explaining what a good code review looks like every time, you type /gku:review and Claude follows a procedure that was written once and refined.

You call them with a slash, like /gku:review, in the Claude Code chat.

They are not magic and they are not automatic. Every one of them does something you could do yourself; they just do it consistently and without forgetting the boring parts — which is exactly where mistakes come from.

Six of them (/gku:research, /gku:plan, /gku:audit, /gku:review, /gku:pr-review, /gku:verify) never change your code at all. Three do (/gku:implement, /gku:fix, /gku:pr-resolve), and each tells you what it is about to do. /gku:pr changes nothing locally; it pushes commits you already made and opens the pull request.

None of them takes instructions from what it reads. A comment on a pull request, a brief, a findings file, a test's output — these are evidence about the code, and a skill checks them against it; they cannot make a skill push, skip a hook, run a command or change its own rules. Only you can, in the chat. plugins/gku/reference/untrusted-input.md says where that line is drawn, and why holding it costs almost nothing per run.

They do not read the internet either, except /gku:research, whose job it is, and /gku:audit --provenance when you ask for it. Both send only public names and stripped error text, never your code, and both say how much they sent.

The code they write is their own, a dependency installed through Composer, npm or pip, or code under your project's own licence with its header kept. Code under a different licence — closed, or open source under MIT or any other — is never pasted in without your approval in the chat, and renaming a pasted block does not count as writing it. The review skills look for the signs of a copy. plugins/gku/reference/code-provenance.md draws that line.

Before you start

You need:

  1. Claude Code installed and working — installation guide.

  2. git — you have this already if you are cloning repositories. On Windows, install Git for Windows, which includes Git Bash. Claude Code uses it to run commands, and these skills assume it is there.

  3. The GitHub CLI (gh), for the three pull-request skills:

    winget install --id GitHub.cli     # Windows
    brew install gh                    # macOS
    sudo apt install gh                # Ubuntu/Debian
    

    Then sign in once, and check it worked:

    gh auth login
    gh auth status
    

    /gku:plan, /gku:audit, /gku:research, /gku:implement, /gku:review, /gku:fix and /gku:verify work without gh. /gku:pr, /gku:pr-review and /gku:pr-resolve need it, because they talk to GitHub — and so does /gku:audit --provenance, which searches GitHub for where copied code came from. /gku:research uses it for upstream issues and releases when it is signed in, and searches the web without it.

  4. Docker — Docker Desktop on Windows and macOS, Docker Engine on Linux. Strongly recommended on every platform, not just Windows.

    The skills run a project's own commands inside its container by default. That is not about convenience — it is about being right. These projects target specific runtime versions: a plugin written for PHP 7.4 checked by a host PHP 8.4 will accept syntax that breaks in production, and a test suite that passes against the wrong version has not proven anything. The container has the version the project actually uses, along with its dependencies and its database.

    It also means you do not need PHP, Composer, Python or Node installed locally at all — several of these projects assume you do not have them — and the same commands work identically on Windows, macOS, Linux and WSL.

    Without Docker the skills still work, falling back to whatever is on your machine, and they will tell you they did. If the versions differ from the project's, treat a green run with suspicion.

Windows works. Use Git Bash, as in step 2. The skills detect your platform on first use and store commands that work there. WSL also works and behaves like Linux.

Installation

In Claude Code, run these two commands:

/plugin marketplace add grinchenkoedu/claude-skills
/plugin install gku@grinchenkoedu

That is all. Type / and you will see /gku:init, /gku:audit, /gku:research, /gku:plan, /gku:implement, /gku:review, /gku:fix, /gku:pr, /gku:pr-review, /gku:pr-resolve and /gku:verify in the list.

Updating

The skills are improved regularly. To pull the latest:

/plugin marketplace update grinchenkoedu
/reload-plugins

The first refreshes the marketplace from GitHub; the second reloads skills in the current session so you do not have to restart.

If you would rather not think about it, /plugin opens the manager where you can check what is installed and update from there.

Why you always get updates: this plugin deliberately omits the version field in its manifest. Claude Code then treats **every commit a

// HOW IT'S BUILT

KEY FILES

plugins/gku/skills/audit/SKILL.mdREADME.md

// REPO STATS

2 stars