Merge feature/audit-tokens into develop

This commit is contained in:
Bastien Chanot
2026-07-02 14:32:59 +02:00
13 changed files with 75 additions and 97 deletions
+3 -2
View File
@@ -34,8 +34,9 @@ guard
learn learn
retro retro
# Plugin: PR review toolkit (pre-merge audit) # pr-review-toolkit removed (audit 2026-07-02 #12 — ~2.2k tokens, PR-only):
pr-review-toolkit plugin@claude-code-plugins # enable per PR session via `bash lib/profile.sh apply audit` or
# claude plugin enable pr-review-toolkit@claude-code-plugins
# CLIs (advisory) # CLIs (advisory)
ctx7 cli ctx7 cli
+6 -1
View File
@@ -79,7 +79,12 @@ emil-design-eng external
frontend-design external frontend-design external
design-motion-principles external design-motion-principles external
ui-ux-pro-max plugin@ui-ux-pro-max-skill ui-ux-pro-max plugin@ui-ux-pro-max-skill
pr-review-toolkit plugin@claude-code-plugins # pr-review-toolkit REMOVED from full (audit 2026-07-02 #12): heaviest
# single plugin cost (~2.2k tokens of agent descriptions/session), useful
# only when reviewing PRs. Reactivate per PR session:
# claude plugin enable pr-review-toolkit@claude-code-plugins
# or profile-based: bash lib/profile.sh apply audit (audit.profile keeps it;
# a later `set full` re-disables it — MANAGED_PLUGINS lifecycle).
magic mcp magic mcp
# === CLIs (advisory) ================================================= # === CLIs (advisory) =================================================
+1 -1
View File
@@ -230,7 +230,7 @@
"ui-ux-pro-max@ui-ux-pro-max-skill": true, "ui-ux-pro-max@ui-ux-pro-max-skill": true,
"security-guidance@claude-code-plugins": true, "security-guidance@claude-code-plugins": true,
"superpowers@superpowers-marketplace": true, "superpowers@superpowers-marketplace": true,
"pr-review-toolkit@claude-code-plugins": true "pr-review-toolkit@claude-code-plugins": false
}, },
"extraKnownMarketplaces": { "extraKnownMarketplaces": {
"claude-code-plugins": { "claude-code-plugins": {
+7 -10
View File
@@ -1,16 +1,13 @@
--- ---
name: audit-delta name: audit-delta
description: | description: |
Use when the user wants a recurring code audit scoped to everything that Use when the user wants a recurring code audit scoped to changes since
changed since the previous audit run (full codebase on first run), on one the previous run (full codebase on first run), on selectable axes:
or more selectable axes: CLAUDE.md norm conformity, bugs/improvements, CLAUDE.md conformity, bugs, dead code, security. NOT one obvious bug
dead code, security. NOT for one obvious bug (/hotfix, /bugfix), one-shot (/hotfix, /bugfix), one-shot cleanup (/code-clean), security posture
full cleanup (/code-clean), full security posture (/cso), quality (/cso), dashboard (/health), branch diff (/review).
dashboard (/health), or branch/PR diff review (/review, /code-review). Triggers: "audit-delta", "incremental audit", "audit incrémental",
Triggers: "audit-delta", "audit since last run", "incremental audit", "audit ce qui a changé", "periodic audit", "relance l'audit".
"audit incrémental", "audit les changements", "audit ce qui a changé
depuis la dernière fois", "periodic audit", "audit périodique",
"re-run the audit", "relance l'audit", "audit conformité + sécurité".
argument-hint: "[axes among: conformity errors deadcode security — blank = asked]" argument-hint: "[axes among: conformity errors deadcode security — blank = asked]"
allowed-tools: allowed-tools:
- Read - Read
+8 -12
View File
@@ -1,18 +1,14 @@
--- ---
name: capitalize name: capitalize
description: | description: |
Use when about to /clear or /compact, or when closing a session, and the Use when about to /clear or /compact, or closing a session, with
conversation holds decisions, learnings, blockers, eval results, or decisions, learnings, blockers, evals, or TODO changes not yet written
finished/new TODO items not yet written to `.claude/memory/` or to .claude/memory/ or .claude/tasks/TODO.md. Plain = pre-wipe flush;
`.claude/tasks/TODO.md`. Plain invocation = pre-wipe flush; `--ritual` (or the --ritual (or "close") = end-of-session reflection. NOT registry
word "close"/"ritual" in the request) = end-of-session reflection mode. NOT curation (that is /prune-memory).
registry curation (that is /prune-memory). Triggers: "capitalize", "before clear/compact", "flush memory", "don't
Triggers: "capitalize", "capitalise", "before clear", "before compact", lose this", "avant de clear/compact", "capitalise ce qui manque",
"save before clear", "flush memory", "don't lose this", "what's not logged "close", "fin de journée", "checkpoint memory".
yet", "avant de clear", "avant compact", "sauvegarde avant clear",
"capitalise ce qui manque", "close", "end session", "session close",
"ferme la session", "checkpoint memory", "what did we learn", "retro rapide",
"fin de journée".
argument-hint: "[--ritual] (scans conversation + git + TODO against .claude/memory/; --ritual adds the 3-question reflection)" argument-hint: "[--ritual] (scans conversation + git + TODO against .claude/memory/; --ritual adds the 3-question reflection)"
allowed-tools: allowed-tools:
- Read - Read
+6 -8
View File
@@ -1,14 +1,12 @@
--- ---
name: client-handover name: client-handover
description: | description: |
Use when finalizing a project for non-technical client delivery — needs Use when finalizing a project for non-technical client delivery —
final audits, deploy validation against live site, and a branded final audits, live-site validation, branded deliverable (MD + HTML +
deliverable (Markdown + HTML + PDF). Multi-agent orchestrator: dispatches PDF). Orchestrator: client-handover-writer spawns /seo + /harden in
client-handover-writer which spawns parallel /seo + /harden subagents, parallel, then /web-validate, then writes the deliverable.
then /web-validate, then writes the deliverable. Triggers: "client handover", "livraison client", "rapport client",
Triggers: "client handover", "compte rendu client", "livraison client", "deliverable", "livrable", "finaliser et livrer".
"rapport client", "deliverable", "summary for client", "handover doc",
"livrable", "ship and handover", "finaliser et livrer".
argument-hint: [optional: language fr|en, --include-deploy, --skip-deploy, --skip-seo, --skip-audits, --skip-fix-loop, --max-iterations N, --audit-max-age <duration>, --output <path>] argument-hint: [optional: language fr|en, --include-deploy, --skip-deploy, --skip-seo, --skip-audits, --skip-fix-loop, --max-iterations N, --audit-max-age <duration>, --output <path>]
allowed-tools: allowed-tools:
- Read - Read
+7 -7
View File
@@ -1,13 +1,13 @@
--- ---
name: code-clean name: code-clean
description: | description: |
Full codebase cleanup: dead code removal, style/norm enforcement, structural Full codebase cleanup: dead code, style/norm enforcement, structural
issues. Two-phase workflow: audit first (read-only report), then execute issues. Two-phase: read-only audit, then approved fixes only
approved fixes only. Delegates refactoring to the refactorer agent. (refactorer agent).
Trigger: "code-clean", "clean up the code", "remove dead code", Triggers: "code-clean", "remove dead code", "cleanup", "nettoyage du
"enforce code style", "cleanup", "nettoyage du code", "code hygiene". code", "code hygiene".
For targeted refactoring without audit → use /refactor instead. Targeted refactor without audit → /refactor. Bugs found → logged to
For bug fixes discovered during cleanup → logged to .claude/audits/BUGS-FOUND.md, not fixed here. .claude/audits/BUGS-FOUND.md, not fixed here.
argument-hint: <file, directory, or blank for entire project> argument-hint: <file, directory, or blank for entire project>
allowed-tools: allowed-tools:
- Read - Read
+6 -7
View File
@@ -2,13 +2,12 @@
name: commit-change name: commit-change
version: 1.0.0 version: 1.0.0
description: | description: |
Analyze all changes since the last commit (staged, unstaged, untracked files) Analyze all pending changes (staged, unstaged, untracked) and create
and create well-structured commits grouped by logical unit. Use this skill atomic commits grouped by logical unit, retracing the work. Any git
whenever the user says "commit my changes", "smart commit", "auto commit", repository.
"commit everything", "analyse et commit", or any variation of wanting to Triggers: "commit my changes", "smart commit", "auto commit", "commit
commit their pending work intelligently. Also trigger when the user has everything", "analyse et commit", or any variation of committing messy
been working on multiple things and wants to create clean, atomic commits pending work intelligently.
from their messy working directory. Works in any git repository.
allowed-tools: allowed-tools:
- Bash - Bash
- Read - Read
+6 -8
View File
@@ -1,14 +1,12 @@
--- ---
name: doc name: doc
description: | description: |
Use when documentation may be out of sync with code — added features Use when documentation may be out of sync with code — features
missing from docs, removed features still documented, or README / INSTALL added/removed vs README / INSTALL / DEPLOY / CHANGELOG. Stack-aware
/ DEPLOY / CHANGELOG drift detected. Stack-aware audit, cross-references audit, cross-references git history, patches approved items.
git history, patches approved items. Triggers: "doc", "sync docs", "update readme", "documentation drift",
Triggers: "doc", "sync docs", "audit docs", "update readme", "check "stale docs", "docs à jour ?", "create README", "should I have a
documentation", "are docs up to date", "documentation drift", "stale docs", DEPLOY doc".
"new feature not documented", "removed feature still in docs",
"create README", "should I have a DEPLOY doc".
argument-hint: [leave empty for full audit, or list specific files/docs to check] argument-hint: [leave empty for full audit, or list specific files/docs to check]
allowed-tools: allowed-tools:
- Read - Read
+5 -8
View File
@@ -2,14 +2,11 @@
name: geo name: geo
description: | description: |
Use when a web project needs AI-search visibility audit — ChatGPT, Use when a web project needs AI-search visibility audit — ChatGPT,
Perplexity, Claude, Gemini, AI Overviews, Copilot, Brave AI, DuckAssist, Perplexity, Gemini, AI Overviews, Copilot… Standalone GEO; dispatches
You.com, Apple Intelligence. Standalone GEO; dispatches the geo-analyzer the geo-analyzer agent.
agent. Triggers: "geo", "AI search", "llms.txt", "AI crawlers", "entity SEO",
Triggers: "geo", "AI search", "ChatGPT visibility", "Perplexity "Wikidata", "generative engine optimization", "référencement IA".
optimisation", "llms.txt", "AI crawlers", "Google AI Overview", Combined SEO+GEO → /seo.
"entity SEO", "Wikidata", "generative engine optimization",
"référencement IA", "optimisation IA".
For combined SEO+GEO → /seo.
argument-hint: optional keywords/scope, e.g. "SaaS B2B content GEO" or "audit llms.txt et entity SEO" argument-hint: optional keywords/scope, e.g. "SaaS B2B content GEO" or "audit llms.txt et entity SEO"
allowed-tools: allowed-tools:
- Read - Read
+7 -15
View File
@@ -1,21 +1,13 @@
--- ---
name: harden name: harden
description: | description: |
Web hardening audit — transport (HTTPS/TLS, HTTP→HTTPS redirect, HSTS), Web hardening audit — HTTPS/TLS, HSTS, security headers (CSP,
security headers (CSP, X-Frame-Options, X-Content-Type-Options, X-Frame-Options…), cookie flags, canonical, custom 404, server config
Referrer-Policy, Permissions-Policy), cookie flags (Secure, HttpOnly, (.htaccess, nginx, netlify, vercel…). Strict scope: no
SameSite), canonical URLs, custom 404, and server config hardening meta/OG/JSON-LD/sitemap noise. Report: .claude/audits/HARDEN.md.
(.htaccess, nginx.conf, netlify.toml, vercel.json, _headers, _redirects, Triggers: "harden", "security headers", "csp", "hsts", "https/ssl
wrangler.toml). Dispatches the seo-analyzer agent with a STRICT scope audit", "redirect audit", "durcissement web", "entêtes sécurité".
filter — no meta/OG/JSON-LD/sitemap/CWV/headings/alt/i18n noise. Meta/sitemap/CWV → /seo. llms.txt/AI → /geo. Secrets/CVE/OWASP → /cso.
Produces .claude/audits/HARDEN.md.
Trigger: "harden", "web hardening", "ssl audit", "https audit",
"hsts", "csp", "security headers", "http to https", "redirect audit",
"htaccess audit", "404 page", "canonical audit", "transport security",
"durcissement web", "audit sécurité web", "entêtes sécurité".
For full SEO audit (meta/OG/JSON-LD/sitemap/CWV) → use /seo.
For AI search / llms.txt / AI crawlers → use /geo.
For secrets / dependency CVEs / OWASP code-level → use /cso.
argument-hint: [URL] [--fix] [--local|--full] [--no-external] argument-hint: [URL] [--fix] [--local|--full] [--no-external]
allowed-tools: allowed-tools:
- Read - Read
+7 -10
View File
@@ -1,16 +1,13 @@
--- ---
name: seo name: seo
description: | description: |
Use when a web project needs SEO + GEO audit or optimization — classical Use when a web project needs SEO + GEO audit or optimization —
search (Google, Bing, DuckDuckGo) AND AI search (ChatGPT, Perplexity, classical search (Google, Bing) AND AI search (ChatGPT, Perplexity, AI
Claude, Gemini, AI Overviews, Copilot). Parallel multi-agent orchestrator: Overviews). Parallel orchestrator: dispatches seo-analyzer +
dispatches seo-analyzer + geo-analyzer concurrently, merges envelopes into geo-analyzer concurrently, merges into .claude/audits/SEO.md.
.claude/audits/SEO.md. Triggers: "seo", "referencement", "meta tags", "JSON-LD", "sitemap",
Triggers: "seo", "referencement", "audit SEO", "meta tags", "robots.txt", "local SEO", "llms.txt", "ChatGPT visibility".
"structured data", "JSON-LD", "sitemap", "robots.txt", "Google ranking", GEO only → /geo. W3C/a11y → /web-validate. Bugs → /bugfix.
"local SEO", "AI search", "GEO", "llms.txt", "ChatGPT visibility",
"Perplexity", "Google AI Overview".
For GEO only → /geo. For W3C/a11y → /web-validate. For bugs → /bugfix.
argument-hint: optional keywords/scope, e.g. "local SEO plombier 91 94 77" or "SaaS B2B content strategy" argument-hint: optional keywords/scope, e.g. "local SEO plombier 91 94 77" or "SaaS B2B content strategy"
allowed-tools: allowed-tools:
- Read - Read
+6 -8
View File
@@ -1,14 +1,12 @@
--- ---
name: web-validate name: web-validate
description: | description: |
Use when a web project needs W3C HTML/CSS validity check or WCAG 2.1 Use when a web project needs W3C HTML/CSS validity or WCAG 2.1
accessibility audit. Dispatches the validator-analyzer agent with a accessibility audit. Dispatches the validator-analyzer agent, strict
STRICT scope filter (no meta/OG/JSON-LD/CWV/security-header noise). scope (no meta/security-header noise).
Triggers: "validate", "validation", "w3c", "html validity", Triggers: "validate", "w3c", "wcag", "a11y", "accessibility", "axe",
"css validity", "wcag", "accessibility", "a11y audit", "axe", "pa11y", "pa11y", "accessibilité", "conformité web".
"wave", "validator.w3.org", "nu validator", "accessibilité", CSP/HSTS/404 → /harden. Meta/sitemap → /seo. AI engines → /geo.
"audit a11y", "audit wcag", "normes w3c", "conformité web".
For CSP/HSTS/404 → /harden. For meta/sitemap → /seo. For AI engines → /geo.
argument-hint: [URL] [--fix] [--local|--full] [--no-external] argument-hint: [URL] [--fix] [--local|--full] [--no-external]
allowed-tools: allowed-tools:
- Read - Read