repo-audit is agent-read markdown (skill) from iuliandita/skills: Audit repositories or PRs for bugs, security, code quality, and docs: quick review or exhaustive domain coverage..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Repo Audit
Choose the audit depth explicitly. **Quick** is a bounded pre-merge sweep. **Exhaustive** is a wave-based repository health audit. Never turn a quick request into exhaustive coverage without saying so.
## When to use
- Review a repository or PR across bugs, security, code quality, and documentation.
- Run a predictable quick merge check.
- Run a deliberate exhaustive audit that detects and covers applicable technical domains.
## When NOT to use
- Review one concern only: invoke its owning skill.
- Review a product, business, or implementation decision: use **plan-review**.
- Audit the skill collection itself: use **skill-creator**.
- Diagnose a live incident or administer a live system: use the matching operational skill.
## Workflow
1. **Preflight:** require a git repository; collect commit, branch, integration base, scope, changed files, languages, manifests, file count, instructions, and whether `docs/local/` is ignored before artifacts are written.
…
Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
A 17 of 17 checks passed. Deterministic, no model, same answer every run.
pass: Frontmatter block present
pass: Frontmatter declares a name
pass: Frontmatter declares a description
pass: Size between 200 bytes and 200 KB (5539 bytes)
pass: No zero-width or bidi control characters
pass: No instruction hidden inside an HTML comment
pass: No link to an exfiltration or paste host
pass: No credential-shaped string
pass: No instruction to send local credentials anywhere
pass: No text hidden with inline styles
pass: No prompt-injection phrasing
pass: No curl or wget piped into a shell
pass: No recursive delete of root, home or parent
pass: No instruction to read or print local credentials
pass: No base64 blob over 200 characters
pass: No link to a raw IP address
pass: No script tag
Source
GitHub
iuliandita/skills · 7 stars · license MIT · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_ktjs5e6trvlikgpp
GET https://markdownregistry.com/api/v1/resolve?ref=iuliandita/skills/repo-audit
GET https://markdownregistry.com/api/v1/blob/88132fccea1c847f989f7657e0bc4edb40e21f7d03e46326ba14ea0fb7ce68fb
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
iuliandita/skills · skills/anti-slop/SKILL.md · Deprecated name. Use code-simplification; load this notice only when anti-slop is explicitly requested.
iuliandita/skills · skills/cluster-health/SKILL.md · Deprecated name. Use kubernetes-health; load this notice only when cluster-health is explicitly requested.
kanevry/session-orchestrator · skills/repo-audit/SKILL.md · Use this skill when the user wants to audit a repository for baseline compliance, check code quality, security posture…
kanevry/session-orchestrator · .agents/skills/repo-audit/SKILL.md · Use this skill when the user wants to audit a repository for baseline compliance, check code quality, security posture…
kanevry/session-orchestrator · .codex-plugin/skills/repo-audit/SKILL.md · Use this skill when the user wants to audit a repository for baseline compliance, check code quality, security posture…
kanevry/session-orchestrator · .cursor/skills/repo-audit/SKILL.md · Use this skill when the user wants to audit a repository for baseline compliance, check code quality, security posture…
lstr-1/skills · orchestrator/skills/repo-audit/SKILL.md · Use this skill when the user wants to audit a repository for baseline compliance, check code quality, security posture…