Pro

Agent Repo Auditor

Find what trips up Claude Code and Codex in your repo, with evidence and fixes

$59.90

Agent Repo Auditor checks whether a code repository is ready for AI coding agents and writes a prioritized AUDIT.md you can act on the same day. It is for developers and teams who use Claude Code, Codex, Cursor or similar agents and keep seeing them run the wrong command, fail to find a working test, or touch things they should not.

What it does

  • Runs a bundled, read-only Python scanner (standard library only) that gathers deterministic facts as JSON: languages, manifests and lockfiles, every script with a safety class, agent instruction files and their stale commands or paths, CI risks, large binaries, undocumented env vars, TODO clusters and git history signals.
  • Detects secret-like patterns in files and recent history and reports them with redacted previews. Secret values are never printed.
  • Verifies documented build, test and lint commands by running only safe check commands, asking before anything that installs, writes, deploys or uses the network.
  • Rates findings Critical/High/Medium/Low with file:line evidence, a concrete fix and a way to verify it.
  • Optionally proposes a lean AGENTS.md built only from commands it confirmed.

What you get

SKILL.md workflow, the scanner script, a check catalog, command-safety rules, a secrets triage guide, notes on how each agent loads its instruction files, and a report template with a filled example.

Works with Claude Code, Codex, Cursor and other SKILL.md-compatible agents; not affiliated with any of them. The audit reports evidence it found; it cannot prove the absence of every problem.

Highlights

  • Read-only Python scanner with 50+ deterministic checks, JSON output
  • Catches stale AGENTS.md/CLAUDE.md commands and package-manager drift
  • Verifies build, test and lint commands by running only safe ones
  • Finds secret-like strings in files and history without printing them
  • Prioritized AUDIT.md with file:line evidence and an AGENTS.md patch

Example

Full readiness audit
You

Audit this repo before we let Codex and Claude Code work in it. Write AUDIT.md.

Agent + skill
# Agent readiness audit - ledgerline-api
Grade: D - one live-looking credential in tracked config; the documented test command does not exist.

Top actions
1. Revoke the AWS access key referenced at config/prod.yaml:1, then load it from the environment (C1).
2. Replace npm's placeholder test script with `vitest run`; point AGENTS.md at it (H1, H2).
3. Make AGENTS.md canonical, reduce CLAUDE.md to `@AGENTS.md`, use pnpm everywhere (H1, M1).
4. Add a Boundaries section forbidding `pnpm deploy`; fix `make clean`, which runs rm -rf ~/ (H3).
5. Switch the PR workflow from pull_request_target to pull_request (H4).

[C1] AWS access key in tracked production config
Evidence: config/prod.yaml:1 - rule aws-access-key-id, preview AKIA[REDACTED 20 chars], tracked, also in history (b0dacab)
Fix: owner revokes the key, then read it from AWS_ACCESS_KEY_ID; add the name to .env.example; add a pre-commit secret scan.

Command verification
| npm run test:unit | AGENTS.md:3 | check | ran | fail (exit 1): Missing script |
| pnpm vitest run   | manual      | check | ran | pass, 38 tests, 12 s |
| pnpm deploy       | package.json| deploy| not run (never in an audit) |
Stale instruction files
You

Our CLAUDE.md and AGENTS.md feel out of date. Check them against the real scripts and fix the mess.

Agent + skill
Scanner flags for instruction files (repo_scan.py, values verified by hand):

[H1] AGENTS.md:14 says `make check`, but the Makefile defines only lint, test, build (AGT-STALE-CMD).
[H2] AGENTS.md:9 uses `npm install`; packageManager is pnpm@9 and only pnpm-lock.yaml is committed (AGT-PM-MISMATCH).
[M1] CLAUDE.md (212 lines) and AGENTS.md (88 lines) share 61 lines and disagree on the test command. CLAUDE.md has no @AGENTS.md import, so Claude Code reads CLAUDE.md while Codex and Cursor read AGENTS.md (AGT-SPLIT, AGT-DUP).
[L1] CLAUDE.md:40-52 is generic advice ("follow best practices", "write clean code") - delete (AGT-VAGUE).

Proposed fix: keep AGENTS.md as the single source of truth (78 lines, every command verified passing), replace CLAUDE.md with:

@AGENTS.md

plus the two Claude-specific notes. Full diff in AUDIT.md, section "Proposed AGENTS.md".
Secrets in history
You

Did anyone ever commit keys to this repo? Check history too, but don't show me the keys.

Agent + skill
Secrets (values never shown)

Working tree
- src/deploy.py:2  github-token  ghp_[REDACTED 40 chars]  tracked  -> Critical, likely real
- tests/fixtures/stripe.json:4  stripe-key  sk_test_[REDACTED 32 chars]  -> Low: documented fixture, test-mode prefix

History (last 300 commits)
- 604a10c src/config.js  slack-token  xoxb-[REDACTED 42 chars]  removed from HEAD, still in history -> High
- .env was committed in 7d21f3e and deleted later (SEC-HISTORY-FILE) -> High

Remediation order: revoke/rotate first (removal does not un-leak a pushed secret), then move values to env vars, ignore .env*, add a pre-commit secret scanner. Rewrite history only after rotation, and only if you accept a coordinated force push.

What's inside

agent-repo-auditor/
├── agents/
│   └── openai.yaml
├── references/
│   ├── agent-instruction-files.md
│   ├── audit-template.md
│   ├── checks.md
│   ├── command-safety.md
│   ├── scanner-output.md
│   └── secrets-triage.md
├── scripts/
│   └── repo_scan.py
├── LICENSE.txt
├── README.md
└── SKILL.md

Install by unzipping into your agent's skills folder. Install guide →