Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问许可证需确认审计通过

implementation-status-auditor实施状况审核员

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

339

周安装

14

GitHub Stars

11

下载量

111
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:implementation-status-auditor(实施状况审核员)
来源仓库:https://github.com/peterbamuhigire/skills-web-dev
仓库路径:skills/implementation-status-auditor
安装命令:
npx skills add https://github.com/peterbamuhigire/skills-web-dev --skill implementation-status-auditor
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/peterbamuhigire/skills-web-dev --skill implementation-status-auditor

简介

implementation-status-auditor 用于辅助安全审计、权限检查和认证流程分析,帮助梳理敏感配置与依赖风险。

  • 适用于安全复核、鉴权逻辑检查及常见漏洞排查等安全相关任务。
  • 可生成安全复核清单,但不能将工具输出直接作为最终结论。
  • 安装命令为 npx skills add https://github.com/peterbamuhigire/skills-web-dev --skill implementation-status-auditor。
  • 涉及密钥、令牌或生产系统时,应先确认最小权限与脱敏方式。

SKILL.md

Platform Notes

  • Optional helper plugins may help in some environments, but they must not be treated as required for this skill.

Implementation Status Auditor

Use When

  • Conduct a comprehensive implementation status audit of any software project. Produces structured documentation in docs/implementation/review-{date}/ with gap analysis, schema audit, integration status, completion blueprint, and prioritized action...
  • The task needs reusable judgment, domain constraints, or a proven workflow rather than ad hoc advice.

Do Not Use When

  • The task is unrelated to implementation-status-auditor or would be better handled by a more specific companion skill.
  • The request only needs a trivial answer and none of this skill's constraints or references materially help.

Required Inputs

  • Gather relevant project context, constraints, and the concrete problem to solve; load references only as needed.
  • Confirm the desired deliverable: design, code, review, migration plan, audit, or documentation.

Workflow

  • Read this SKILL.md first, then load only the referenced deep-dive files that are necessary for the task.
  • Apply the ordered guidance, checklists, and decision rules in this skill instead of cherry-picking isolated snippets.
  • Produce the deliverable with assumptions, risks, and follow-up work made explicit when they matter.

Quality Standards

  • Keep outputs execution-oriented, concise, and aligned with the repository's baseline engineering standards.
  • Preserve compatibility with existing project conventions unless the skill explicitly requires a stronger standard.
  • Prefer deterministic, reviewable steps over vague advice or tool-specific magic.

Anti-Patterns

  • Treating examples as copy-paste truth without checking fit, constraints, or failure modes.
  • Loading every reference file by default instead of using progressive disclosure.

Outputs

  • A concrete result that fits the task: implementation guidance, review findings, architecture decisions, templates, or generated artifacts.
  • Clear assumptions, tradeoffs, or unresolved gaps when the task cannot be completed from available context alone.
  • References used, companion skills, or follow-up actions when they materially improve execution.

Evidence Produced

CategoryArtifactFormatExample
Release evidenceImplementation status audit reportMarkdown doc in docs/implementation/ covering feature-by-feature status, evidence, and gapsdocs/implementation/status-audit-2026-04-16.md

References

  • Use the references/ directory for deep detail after reading the core workflow below.

Overview

This skill transforms Claude into an elite Enterprise Software Architect and Technical Auditor. It conducts a brutal, no-stones-unturned analysis of a project's implementation status, producing actionable documentation that serves as both a status report and a completion blueprint.

When to use: User asks to audit a project, check implementation status, identify gaps, or generate a completion roadmap.

Core Workflow

Step 0: Prepare Output Directory

Create the review directory with today's date:

docs/implementation/review-{DD-MMM-YYYY}/

Example: docs/implementation/review-21-Feb-2026/

If the directory exists (re-run), append a sequence: review-21-Feb-2026-v2/.

Step 1: Discovery Phase (Gather Inputs)

Before any analysis, systematically collect all project materials. Use the Explore agent and direct file reads.

Required discovery targets:

SourceWhat to FindHow
Database schemasTables, migrations, ERDsGlob **/*.sql, **/migrations/**, schema dumps
Project documentationPRDs, SRS, architecture docsGlob docs/**/*.md, **/AGENTS.md, **/CLAUDE.md
Project plansMilestones, task lists, roadmapsGlob **/plans/**, **/NEXT_FEATURES.md, **/requirements.md
API contractsEndpoints, payloads, authGlob **/routes/**, **/api/**, Swagger/OpenAPI files
Source code structureControllers, models, servicesDirectory tree of src/, app/, project root
Related projectsSister apps, shared librariesCheck for monorepo siblings, API consumers
Test coverageExisting tests, test plansGlob **/tests/**, **/test/**, **/*Test.*
Config & infraCI/CD, deployment, envGlob **/docker*, **/.github/**, **/deploy/**

Discovery SOP:

  1. Read CLAUDE.md, AGENTS.md, README.md at project root
  2. Read docs/ directory tree for all planning/architecture docs
  3. Scan database directory for schema files and migrations
  4. Map the source code directory structure (top 2 levels)
  5. Identify all API route/controller files
  6. Check for sister/related project references
  7. Locate test files and coverage reports

Step 2: Analysis Phase (Five Audit Pillars)

Analyze gathered materials against five pillars:

Pillar 1: Schema & Data Model Reality Check

Cross-reference database schemas against project documentation.

Checklist:

  • All planned entities have corresponding tables
  • Foreign keys enforce documented relationships
  • Multi-tenancy isolation is schema-enforced (tenant_id scoping)
  • Indexes support documented query patterns
  • Normalization level is appropriate (3NF minimum for transactional)
  • Audit columns exist (created_at, updated_at, created_by)
  • Soft-delete support where documented
  • Character set/collation consistency (utf8mb4_unicode_ci)

Cross-reference with: mysql-best-practices skill for schema standards.

Pillar 2: Implementation vs. Plan Gap Analysis

Compare current codebase against project plans and requirements.

Classification system:

StatusDefinitionEvidence Required
CompleteFeature fully functionalRoutes + Controllers + Models + UI + Tests
PartialSome layers existSchema exists but no endpoints, or UI stub only
PhantomIn plan, zero footprintNo schema, no code, no routes — only in docs
UndocumentedExists in code, not in plansCode present but no matching requirement

Cross-reference with: feature-planning skill for spec-to-implementation mapping.

Pillar 3: Cross-Platform & Integration Integrity

Evaluate API contracts and data flow between systems.

Checklist:

  • All documented API endpoints exist in code
  • Authentication/authorization covers all endpoints
  • Response payloads match expected client schemas
  • Pagination implemented where needed
  • Error responses follow consistent format
  • Webhook/callback endpoints documented and implemented
  • Data sync mechanisms between platforms verified

Cross-reference with: api-pagination, api-error-handling, dual-auth-rbac skills.

Pillar 4: Technical Risk & Debt Assessment

Identify blockers, debt, and architectural concerns.

Risk categories:

  • Critical Blocker — Prevents next milestone, must fix immediately
  • High Debt — Works now but will break at scale
  • Medium Debt — Suboptimal but functional
  • Low Debt — Cosmetic or minor improvement

Pillar 5: Completion Blueprint

Transform gaps into an actionable completion plan.

Blueprint structure:

  • Group remaining work by module/feature
  • Prioritize by dependency order (foundations first)
  • Estimate complexity (S/M/L/XL)
  • Map each item to the skills needed for implementation
  • Define acceptance criteria for each item

Step 3: Documentation Output Phase

Generate the following files in the review directory:

docs/implementation/review-{date}/
├── 00-executive-summary.md          # Project health overview
├── 01-schema-audit.md               # Database & data model analysis
├── 02-implementation-progress.md    # Module-by-module status
├── 03-integration-status.md         # Cross-platform & API analysis
├── 04-technical-risks.md            # Risks, debt, and blockers
├── 05-completion-blueprint.md       # Actionable roadmap to finish
├── 06-module-details/               # Per-module deep dives
│   ├── {module-name}-status.md      # One file per major module
│   └── ...
└── 07-appendices/                   # Supporting data
    ├── schema-entity-map.md         # Table-to-feature mapping
    ├── api-endpoint-inventory.md    # Full endpoint listing
    └── test-coverage-map.md         # Test status per module

Report Templates

00-executive-summary.md

# Implementation Status Audit — Executive Summary
**Project:** {name}
**Date:** {date}
**Auditor:** Claude (Implementation Status Auditor Skill)

## Project Health Score: {X}/10

## Completion Overview
| Category | Complete | Partial | Missing | Total |
|----------|----------|---------|---------|-------|
| Database Schema | X | X | X | X |
| Backend API | X | X | X | X |
| Frontend UI | X | X | X | X |
| Authentication | X | X | X | X |
| Testing | X | X | X | X |
| **Overall** | **X%** | **X%** | **X%** | — |

## Top 3 Critical Findings
1. {finding}
2. {finding}
3. {finding}

## Recommended Immediate Actions
1. {action} — Skill: `{skill-name}`
2. {action} — Skill: `{skill-name}`
3. {action} — Skill: `{skill-name}`

02-implementation-progress.md

# Implementation Progress by Module

## Module: {name}
**Status:** Complete | Partial | Missing
**Completion:** {X}%

### What Exists
- {component}: {status with evidence}

### What's Missing
- {component}: {what needs to be built}
- **Skill to use:** `{skill-name}`
- **Complexity:** S | M | L | XL
- **Blocked by:** {dependency or "None"}

05-completion-blueprint.md

# Completion Blueprint

## Phase 1: Foundation (Must Complete First)
| # | Task | Module | Complexity | Skill | Blocked By |
|---|------|--------|-----------|-------|------------|
| 1 | {task} | {module} | S/M/L/XL | `{skill}` | None |

## Phase 2: Core Features
...

## Phase 3: Integration & Polish
...

## Phase 4: Testing & Hardening
...

Cross-Skill Integration Map

This auditor leverages other skills for both analysis and recommended actions:

Audit AreaAnalysis SkillAction Skill
Database schema gapsmysql-best-practicesmysql-best-practices
Missing featuresfeature-planningfeature-planning
API gapsapi-error-handlingapi-pagination, dual-auth-rbac
Multi-tenant issuesmulti-tenant-saas-architecturemulti-tenant-saas-architecture
Documentation gapsdoc-architectupdate-claude-documentation
Testing gapssdlc-testingsdlc-testing
Planning gapssdlc-planningsdlc-planning
UI issueswebapp-gui-designjetpack-compose-ui
Mobile integrationandroid-developmentandroid-saas-planning
Security concernsvibe-security-skillweb-app-security-audit
Code quality toolingphp-modern-standardsphp-modern-standards
User docs missingmanual-guidesdlc-user-deploy
Module architecturemodular-saas-architecturemodular-saas-architecture

Iterative Drilling

After the initial audit, the user can request deep dives:

  • "Drill into {module}" — Generate detailed 06-module-details/{module}-status.md
  • "Show me the API payloads for {feature}" — Extract expected JSON from schema
  • "What tests are missing for {module}" — Cross-reference with sdlc-testing
  • "Generate the completion plan for {phase}" — Expand blueprint phase into tasks

Anti-Patterns

Don'tDo Instead
Guess about features without reading codeRead actual route files and controllers
Mark features "complete" based on schema aloneVerify full stack: schema + API + UI + tests
Skip sister project analysisAlways check for API consumers/mobile apps
Write one massive fileBreak into the defined file structure
Ignore test coverageAlways report testing status per module
Make vague recommendationsMap every action to a specific skill

Output Standards

  • All generated files follow doc-standards.md (500-line max per file)
  • Use tables for status mappings (scannable, not prose)
  • Every gap must have: description, severity, recommended skill, complexity
  • Blueprint must be dependency-ordered (no orphan tasks)
  • Executive summary must fit on one screen (< 40 lines of content)

See Also

  • references/audit-checklist.md — Complete pre-flight checklist
  • references/gap-analysis-patterns.md — Classification methodology
  • references/drill-down-templates.md — Templates for iterative deep dives

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

31.54%
按下载量换算35

Claude

31.38%
按下载量换算35

Cursor

18.72%
按下载量换算21

Gemini CLI

8.75%
按下载量换算10

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills