CtrlK
BlogDocsLog inGet started
Tessl Logo

code-audit

Find recurring Epicenter code smells and scope the cleanup they require. Use for periodic audits, cleanup PRs, post-refactor reviews, or reviews of a primitive’s consumers.

64

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An unusually concrete audit skill: each smell category pairs an executable detection command with a validated real example, a triage rule, and false-positive guidance, and the rejected-categories section prevents wasted hunts. The main weaknesses are minor: BRE-fragile grep patterns, a missing post-fix verification step, and some logger detail that could be split into a reference file.

Suggestions

Fix the grep patterns so they run as written: add -E (or -P) to the category 1, 2, and 7 greps that rely on \s and parenthesized alternation, which otherwise match literally and silently return nothing.

Add a final verification step to the Workflow (e.g., 're-run the greps on the changed files and confirm zero untriaged hits before opening the PR').

Move the logger injection patterns and the two consoleSink/new Error evasion greps into a references/ file (e.g., references/logging.md) to slim category 3, and deduplicate the single-method Pick grep shared by categories 5 and 6.

DimensionReasoningScore

Conciseness

The body is dense and assumes competence (no explanation of what TypeScript or grep are), and every category carries a pattern, triage rule, and real example. A few sections could be trimmed — the apps/whispering narrative in category 3 is long, and the single-method `Pick` grep is repeated verbatim in categories 5 and 6 — so it is not the fully lean fit of 5.

4 / 5

Actionability

Every category ships a concrete grep/rg command plus a real file-path example and a step-by-step triage recipe. Not 5 because several grep patterns use BRE metacharacters (\s, bare parens, backreference-style alternation) that fail without -E/-P as written, so they are not reliably copy-paste ready.

4 / 5

Workflow Clarity

The Workflow section gives a clear four-step sequence (run greps → triage each hit as justified/refactor/false-positive → group by category → single PR with audit log), and the triage step acts as a checkpoint. Not 5 because there is no explicit verification loop, e.g., re-running the greps after fixes to confirm the hits are gone.

4 / 5

Progressive Disclosure

No bundle files exist, and the single file is well organized with numbered categories, a rejected-patterns section, and clearly signaled cross-references to other skills (define-errors, logging, refactoring) and one spec file. Not 5 because some detail that belongs in reference files is inlined — the logger injection patterns and consoleSink evasion prose in category 3 could live in a references/ file.

4 / 5

Total

16

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit 'what' plus four concrete 'Use for' triggers in third-person voice. Its main limitation is that the 'what' half covers only two actions, which is terse rather than comprehensive.

DimensionReasoningScore

Specificity

Names the domain ('recurring Epicenter code smells') and exactly two concrete actions — 'Find ... code smells' and 'scope the cleanup they require'. This matches the anchor for naming the domain with 1-2 concrete actions; it does not list several specific actions, so 4 is too high.

3 / 5

Completeness

Explicitly answers both: what ('Find recurring Epicenter code smells and scope the cleanup they require') and when ('Use for periodic audits, cleanup PRs, post-refactor reviews, or reviews of a primitive's consumers') with four concrete trigger phrases. Not 4 because the 'when' is already explicit and specific, not merely present.

5 / 5

Trigger Term Quality

'periodic audits', 'cleanup PRs', 'post-refactor reviews' are phrases a user of this codebase would naturally say when they need the skill. A few natural terms are missing (e.g., 'code review pass', 'tech debt', 'lint'), which keeps it at 4 rather than the comprehensive synonym coverage of 5.

4 / 5

Distinctiveness Conflict Risk

The audit/cleanup-PR/post-refactor-review niche is distinct from general review skills, and 'Epicenter' plus 'primitive's consumers' pin it to this codebase. Minor overlap risk remains with generic code-review or refactoring skills a user might reach for instead, so it does not fully match the minimal-conflict anchor at 5.

4 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
EpicenterHQ/epicenter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.