Merge feature/audit-tokens into develop

This commit is contained in:
Bastien Chanot
2026-07-02 14:32:59 +02:00
13 changed files with 75 additions and 97 deletions
+3 -2
View File
@@ -34,8 +34,9 @@ guard
learn
retro
# Plugin: PR review toolkit (pre-merge audit)
pr-review-toolkit plugin@claude-code-plugins
# pr-review-toolkit removed (audit 2026-07-02 #12 — ~2.2k tokens, PR-only):
# enable per PR session via `bash lib/profile.sh apply audit` or
# claude plugin enable pr-review-toolkit@claude-code-plugins
# CLIs (advisory)
ctx7 cli
+6 -1
View File
@@ -79,7 +79,12 @@ emil-design-eng external
frontend-design external
design-motion-principles external
ui-ux-pro-max plugin@ui-ux-pro-max-skill
pr-review-toolkit plugin@claude-code-plugins
# pr-review-toolkit REMOVED from full (audit 2026-07-02 #12): heaviest
# single plugin cost (~2.2k tokens of agent descriptions/session), useful
# only when reviewing PRs. Reactivate per PR session:
# claude plugin enable pr-review-toolkit@claude-code-plugins
# or profile-based: bash lib/profile.sh apply audit (audit.profile keeps it;
# a later `set full` re-disables it — MANAGED_PLUGINS lifecycle).
magic mcp
# === CLIs (advisory) =================================================
+1 -1
View File
@@ -230,7 +230,7 @@
"ui-ux-pro-max@ui-ux-pro-max-skill": true,
"security-guidance@claude-code-plugins": true,
"superpowers@superpowers-marketplace": true,
"pr-review-toolkit@claude-code-plugins": true
"pr-review-toolkit@claude-code-plugins": false
},
"extraKnownMarketplaces": {
"claude-code-plugins": {
+7 -10
View File
@@ -1,16 +1,13 @@
---
name: audit-delta
description: |
Use when the user wants a recurring code audit scoped to everything that
changed since the previous audit run (full codebase on first run), on one
or more selectable axes: CLAUDE.md norm conformity, bugs/improvements,
dead code, security. NOT for one obvious bug (/hotfix, /bugfix), one-shot
full cleanup (/code-clean), full security posture (/cso), quality
dashboard (/health), or branch/PR diff review (/review, /code-review).
Triggers: "audit-delta", "audit since last run", "incremental audit",
"audit incrémental", "audit les changements", "audit ce qui a changé
depuis la dernière fois", "periodic audit", "audit périodique",
"re-run the audit", "relance l'audit", "audit conformité + sécurité".
Use when the user wants a recurring code audit scoped to changes since
the previous run (full codebase on first run), on selectable axes:
CLAUDE.md conformity, bugs, dead code, security. NOT one obvious bug
(/hotfix, /bugfix), one-shot cleanup (/code-clean), security posture
(/cso), dashboard (/health), branch diff (/review).
Triggers: "audit-delta", "incremental audit", "audit incrémental",
"audit ce qui a changé", "periodic audit", "relance l'audit".
argument-hint: "[axes among: conformity errors deadcode security — blank = asked]"
allowed-tools:
- Read
+8 -12
View File
@@ -1,18 +1,14 @@
---
name: capitalize
description: |
Use when about to /clear or /compact, or when closing a session, and the
conversation holds decisions, learnings, blockers, eval results, or
finished/new TODO items not yet written to `.claude/memory/` or
`.claude/tasks/TODO.md`. Plain invocation = pre-wipe flush; `--ritual` (or the
word "close"/"ritual" in the request) = end-of-session reflection mode. NOT
registry curation (that is /prune-memory).
Triggers: "capitalize", "capitalise", "before clear", "before compact",
"save before clear", "flush memory", "don't lose this", "what's not logged
yet", "avant de clear", "avant compact", "sauvegarde avant clear",
"capitalise ce qui manque", "close", "end session", "session close",
"ferme la session", "checkpoint memory", "what did we learn", "retro rapide",
"fin de journée".
Use when about to /clear or /compact, or closing a session, with
decisions, learnings, blockers, evals, or TODO changes not yet written
to .claude/memory/ or .claude/tasks/TODO.md. Plain = pre-wipe flush;
--ritual (or "close") = end-of-session reflection. NOT registry
curation (that is /prune-memory).
Triggers: "capitalize", "before clear/compact", "flush memory", "don't
lose this", "avant de clear/compact", "capitalise ce qui manque",
"close", "fin de journée", "checkpoint memory".
argument-hint: "[--ritual] (scans conversation + git + TODO against .claude/memory/; --ritual adds the 3-question reflection)"
allowed-tools:
- Read
+6 -8
View File
@@ -1,14 +1,12 @@
---
name: client-handover
description: |
Use when finalizing a project for non-technical client delivery — needs
final audits, deploy validation against live site, and a branded
deliverable (Markdown + HTML + PDF). Multi-agent orchestrator: dispatches
client-handover-writer which spawns parallel /seo + /harden subagents,
then /web-validate, then writes the deliverable.
Triggers: "client handover", "compte rendu client", "livraison client",
"rapport client", "deliverable", "summary for client", "handover doc",
"livrable", "ship and handover", "finaliser et livrer".
Use when finalizing a project for non-technical client delivery —
final audits, live-site validation, branded deliverable (MD + HTML +
PDF). Orchestrator: client-handover-writer spawns /seo + /harden in
parallel, then /web-validate, then writes the deliverable.
Triggers: "client handover", "livraison client", "rapport client",
"deliverable", "livrable", "finaliser et livrer".
argument-hint: [optional: language fr|en, --include-deploy, --skip-deploy, --skip-seo, --skip-audits, --skip-fix-loop, --max-iterations N, --audit-max-age <duration>, --output <path>]
allowed-tools:
- Read
+7 -7
View File
@@ -1,13 +1,13 @@
---
name: code-clean
description: |
Full codebase cleanup: dead code removal, style/norm enforcement, structural
issues. Two-phase workflow: audit first (read-only report), then execute
approved fixes only. Delegates refactoring to the refactorer agent.
Trigger: "code-clean", "clean up the code", "remove dead code",
"enforce code style", "cleanup", "nettoyage du code", "code hygiene".
For targeted refactoring without audit → use /refactor instead.
For bug fixes discovered during cleanup → logged to .claude/audits/BUGS-FOUND.md, not fixed here.
Full codebase cleanup: dead code, style/norm enforcement, structural
issues. Two-phase: read-only audit, then approved fixes only
(refactorer agent).
Triggers: "code-clean", "remove dead code", "cleanup", "nettoyage du
code", "code hygiene".
Targeted refactor without audit → /refactor. Bugs found → logged to
.claude/audits/BUGS-FOUND.md, not fixed here.
argument-hint: <file, directory, or blank for entire project>
allowed-tools:
- Read
+6 -7
View File
@@ -2,13 +2,12 @@
name: commit-change
version: 1.0.0
description: |
Analyze all changes since the last commit (staged, unstaged, untracked files)
and create well-structured commits grouped by logical unit. Use this skill
whenever the user says "commit my changes", "smart commit", "auto commit",
"commit everything", "analyse et commit", or any variation of wanting to
commit their pending work intelligently. Also trigger when the user has
been working on multiple things and wants to create clean, atomic commits
from their messy working directory. Works in any git repository.
Analyze all pending changes (staged, unstaged, untracked) and create
atomic commits grouped by logical unit, retracing the work. Any git
repository.
Triggers: "commit my changes", "smart commit", "auto commit", "commit
everything", "analyse et commit", or any variation of committing messy
pending work intelligently.
allowed-tools:
- Bash
- Read
+6 -8
View File
@@ -1,14 +1,12 @@
---
name: doc
description: |
Use when documentation may be out of sync with code — added features
missing from docs, removed features still documented, or README / INSTALL
/ DEPLOY / CHANGELOG drift detected. Stack-aware audit, cross-references
git history, patches approved items.
Triggers: "doc", "sync docs", "audit docs", "update readme", "check
documentation", "are docs up to date", "documentation drift", "stale docs",
"new feature not documented", "removed feature still in docs",
"create README", "should I have a DEPLOY doc".
Use when documentation may be out of sync with code — features
added/removed vs README / INSTALL / DEPLOY / CHANGELOG. Stack-aware
audit, cross-references git history, patches approved items.
Triggers: "doc", "sync docs", "update readme", "documentation drift",
"stale docs", "docs à jour ?", "create README", "should I have a
DEPLOY doc".
argument-hint: [leave empty for full audit, or list specific files/docs to check]
allowed-tools:
- Read
+5 -8
View File
@@ -2,14 +2,11 @@
name: geo
description: |
Use when a web project needs AI-search visibility audit — ChatGPT,
Perplexity, Claude, Gemini, AI Overviews, Copilot, Brave AI, DuckAssist,
You.com, Apple Intelligence. Standalone GEO; dispatches the geo-analyzer
agent.
Triggers: "geo", "AI search", "ChatGPT visibility", "Perplexity
optimisation", "llms.txt", "AI crawlers", "Google AI Overview",
"entity SEO", "Wikidata", "generative engine optimization",
"référencement IA", "optimisation IA".
For combined SEO+GEO → /seo.
Perplexity, Gemini, AI Overviews, Copilot… Standalone GEO; dispatches
the geo-analyzer agent.
Triggers: "geo", "AI search", "llms.txt", "AI crawlers", "entity SEO",
"Wikidata", "generative engine optimization", "référencement IA".
Combined SEO+GEO → /seo.
argument-hint: optional keywords/scope, e.g. "SaaS B2B content GEO" or "audit llms.txt et entity SEO"
allowed-tools:
- Read
+7 -15
View File
@@ -1,21 +1,13 @@
---
name: harden
description: |
Web hardening audit — transport (HTTPS/TLS, HTTP→HTTPS redirect, HSTS),
security headers (CSP, X-Frame-Options, X-Content-Type-Options,
Referrer-Policy, Permissions-Policy), cookie flags (Secure, HttpOnly,
SameSite), canonical URLs, custom 404, and server config hardening
(.htaccess, nginx.conf, netlify.toml, vercel.json, _headers, _redirects,
wrangler.toml). Dispatches the seo-analyzer agent with a STRICT scope
filter — no meta/OG/JSON-LD/sitemap/CWV/headings/alt/i18n noise.
Produces .claude/audits/HARDEN.md.
Trigger: "harden", "web hardening", "ssl audit", "https audit",
"hsts", "csp", "security headers", "http to https", "redirect audit",
"htaccess audit", "404 page", "canonical audit", "transport security",
"durcissement web", "audit sécurité web", "entêtes sécurité".
For full SEO audit (meta/OG/JSON-LD/sitemap/CWV) → use /seo.
For AI search / llms.txt / AI crawlers → use /geo.
For secrets / dependency CVEs / OWASP code-level → use /cso.
Web hardening audit — HTTPS/TLS, HSTS, security headers (CSP,
X-Frame-Options…), cookie flags, canonical, custom 404, server config
(.htaccess, nginx, netlify, vercel…). Strict scope: no
meta/OG/JSON-LD/sitemap noise. Report: .claude/audits/HARDEN.md.
Triggers: "harden", "security headers", "csp", "hsts", "https/ssl
audit", "redirect audit", "durcissement web", "entêtes sécurité".
Meta/sitemap/CWV → /seo. llms.txt/AI → /geo. Secrets/CVE/OWASP → /cso.
argument-hint: [URL] [--fix] [--local|--full] [--no-external]
allowed-tools:
- Read
+7 -10
View File
@@ -1,16 +1,13 @@
---
name: seo
description: |
Use when a web project needs SEO + GEO audit or optimization — classical
search (Google, Bing, DuckDuckGo) AND AI search (ChatGPT, Perplexity,
Claude, Gemini, AI Overviews, Copilot). Parallel multi-agent orchestrator:
dispatches seo-analyzer + geo-analyzer concurrently, merges envelopes into
.claude/audits/SEO.md.
Triggers: "seo", "referencement", "audit SEO", "meta tags",
"structured data", "JSON-LD", "sitemap", "robots.txt", "Google ranking",
"local SEO", "AI search", "GEO", "llms.txt", "ChatGPT visibility",
"Perplexity", "Google AI Overview".
For GEO only → /geo. For W3C/a11y → /web-validate. For bugs → /bugfix.
Use when a web project needs SEO + GEO audit or optimization —
classical search (Google, Bing) AND AI search (ChatGPT, Perplexity, AI
Overviews). Parallel orchestrator: dispatches seo-analyzer +
geo-analyzer concurrently, merges into .claude/audits/SEO.md.
Triggers: "seo", "referencement", "meta tags", "JSON-LD", "sitemap",
"robots.txt", "local SEO", "llms.txt", "ChatGPT visibility".
GEO only → /geo. W3C/a11y → /web-validate. Bugs → /bugfix.
argument-hint: optional keywords/scope, e.g. "local SEO plombier 91 94 77" or "SaaS B2B content strategy"
allowed-tools:
- Read
+6 -8
View File
@@ -1,14 +1,12 @@
---
name: web-validate
description: |
Use when a web project needs W3C HTML/CSS validity check or WCAG 2.1
accessibility audit. Dispatches the validator-analyzer agent with a
STRICT scope filter (no meta/OG/JSON-LD/CWV/security-header noise).
Triggers: "validate", "validation", "w3c", "html validity",
"css validity", "wcag", "accessibility", "a11y audit", "axe", "pa11y",
"wave", "validator.w3.org", "nu validator", "accessibilité",
"audit a11y", "audit wcag", "normes w3c", "conformité web".
For CSP/HSTS/404 → /harden. For meta/sitemap → /seo. For AI engines → /geo.
Use when a web project needs W3C HTML/CSS validity or WCAG 2.1
accessibility audit. Dispatches the validator-analyzer agent, strict
scope (no meta/security-header noise).
Triggers: "validate", "w3c", "wcag", "a11y", "accessibility", "axe",
"pa11y", "accessibilité", "conformité web".
CSP/HSTS/404 → /harden. Meta/sitemap → /seo. AI engines → /geo.
argument-hint: [URL] [--fix] [--local|--full] [--no-external]
allowed-tools:
- Read