Audit Codebase
PM-focused codebase exploration and capability mapping
- Type
- Slash Command
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
What Audit Codebase is
Audit Codebase is a slash command published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A slash command is a reusable prompt saved as a markdown file and run by typing its name after a slash. In Claude Code, custom commands have been merged into skills: a file in .claude/commands/ and a skill folder in .claude/skills/ both create the same kind of command, and existing command files keep working.
Audit Codebase gives you a repeatable way to run the same instructions without retyping them, optionally with arguments.
How to install Audit Codebase
Claude Code
- Download audit-codebase.md from the repository.
- Save it to ~/.claude/commands/ (all projects) or .claude/commands/ (one project). As a skill, you can instead save it as ~/.claude/skills/<name>/SKILL.md.
- Run it by typing / followed by its name.
Claude Cowork
- Turn the command into a skill: create a folder with the file saved as SKILL.md and zip it.
- In Customize → Skills, click +, then upload the ZIP.
- Run it from any task with / and the skill name.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/productivity/pm-ai-partner/commands/pm/audit-codebase.md, shared under the repository's MIT license. Read the full file on GitHub.
Help me understand the codebase for: $ARGUMENTS
Instructions
Conduct a PM-focused codebase exploration. The goal is not to understand every line of code, but to map what the system can do and what that means for the product.
Process
- Auto-detect structure — Identify language, framework, repo layout, entry points
- Explore architecture — Map services, components, data flows, and external dependencies
- Map capabilities — What product capabilities does this code enable?
- Find the gaps — What's claimed in docs but missing in code? What exists but isn't documented?
- Connect to product decisions — What does this mean for what we can build, change, or promise?
Tools to Use
- Search the codebase for key patterns, APIs, and data models
- Read configuration files, READMEs, and service definitions
- Trace user-facing flows from entry point to data store
- Compare implementation reality to documentation claims
- GitHub MCP (if available): Pull open issues, recent PRs, contributor activity for context on what's changing
- Sentry MCP (if available): Check for recurring errors or performance issues in this service
Auto-Detection
Start by detecting the repo's characteristics:
## Repo Profile
- **Language(s):** [auto-detect from file extensions and config]
- **Framework:** [detect from package.json, pom.xml, build.gradle, etc.]
- **Architecture:** [monolith / microservice / monorepo / library]
- **Entry points:** [main files, server startup, route definitions]
- **Data stores:** [databases, caches, queues detected from config/code]
- **External deps:** [APIs, services this code calls]Output Format
# Codebase Audit: [System/Service Name]
## One-Sentence Summary
What this system does in plain language.
## Repo Profile
| Attribute | Value |
|-----------|-------|
| Language | [detected] |
| Framework | [detected] |
| Architecture | [type] |
| Size | [files/lines estimate] |
## Architecture Overview
[Mermaid diagram showing key components, data flow, and external dependencies]
## Capability Map
…Principles
- Evidence over assumption — Cite file paths and code patterns
- Product language — Translate technical findings into PM-relevant insights
- Honest about limits — Flag what you can't determine from code alone
- Mermaid for diagrams — Use Mermaid format for architecture diagrams, not ASCII art
- Auto-detect first — Don't ask the user for repo details you can discover by reading the code
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Audit Codebase?
Audit Codebase is a slash command for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. PM-focused codebase exploration and capability mapping
How do I install Audit Codebase in Claude Code?
Download audit-codebase.md from the repository. Save it to ~/.claude/commands/ (all projects) or .claude/commands/ (one project). As a skill, you can instead save it as ~/.claude/skills/<name>/SKILL.md. Run it by typing / followed by its name.
Can I use Audit Codebase in Claude Cowork?
Turn the command into a skill: create a folder with the file saved as SKILL.md and zip it. In Customize → Skills, click +, then upload the ZIP. Run it from any task with / and the skill name.
Is Audit Codebase safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Optimize Cache Optimize caching strategies and implementation Slash Command · jeremylongshore/tons-of-skills-marketplace
- Optimize Get performance optimization recommendations Slash Command · jeremylongshore/tons-of-skills-marketplace
- Optimize Staking Analyze and optimize staking rewards across protocols Slash Command · jeremylongshore/tons-of-skills-marketplace
- Optimize Gas Optimize gas fees with timing and routing strategies Slash Command · jeremylongshore/tons-of-skills-marketplace
- Audit Report Generate comprehensive security audit report Slash Command · jeremylongshore/tons-of-skills-marketplace
- Archival Archive old database records with automated retention policies and cold Slash Command · jeremylongshore/tons-of-skills-marketplace
- Auth Setup Generate authentication boilerplate with JWT, OAuth, and session support Slash Command · jeremylongshore/tons-of-skills-marketplace
- Api Security Audit Comprehensive security audit for REST and GraphQL APIs Slash Command · jeremylongshore/tons-of-skills-marketplace