production-code-audit
sickn33/agentic-awesome-skills
Autonomously scan and transform entire codebases to production-grade quality with security hardening and performance optimization.
What is production-code-audit?
This skill performs deep line-by-line analysis of entire codebases to identify and fix issues across security, performance, architecture, and code quality. Use it when preparing code for production deployment, meeting corporate standards, or systematically improving codebase quality at enterprise level.
- Discovers and catalogs codebase architecture, patterns, and entry points
- Identifies and categorizes issues by severity (critical, high, medium, low)
- Automatically fixes security vulnerabilities including SQL injection, weak hashing, and authentication bypasses
- Optimizes performance through N+1 query fixes, caching, indexing, and bundle size reduction
- Refactors god classes and circular dependencies into focused, maintainable services
- Adds production infrastructure including logging, error tracking, monitoring, and health checks
How to install production-code-audit
npx skills add https://github.com/sickn33/agentic-awesome-skills --skill production-code-audit- Complete codebase access (all source files)
- Understanding of your application's architecture and tech stack
- Read the detailed guide (references/detailed-guide.md) before execution
How to use production-code-audit
- 1.Invoke the skill with a request like 'make this production-ready' or 'audit my codebase'
- 2.Allow Phase 1 to complete: the skill discovers your codebase structure, architecture, and entry points
- 3.Review the issues identified in Phase 2, organized by severity level
- 4.Allow Phase 3 to execute: automatic fixes for all identified issues
- 5.Verify Phase 4 additions: production infrastructure (logging, monitoring, health checks)
- 6.Review Phase 5 verification results and metrics before deploying
Use cases
- Transforming a legacy codebase to meet enterprise security and performance standards before production deployment
- Conducting comprehensive security hardening across an entire application to address OWASP Top 10 vulnerabilities
- Optimizing API response times and reducing bundle sizes for slow or bloated applications
- Refactoring monolithic services into properly separated concerns with clear responsibilities
- Preparing a startup MVP for corporate acquisition or institutional use
- Backend and full-stack engineers preparing code for production
- DevOps and platform engineers standardizing code quality across teams
- Technical leads auditing inherited or legacy codebases
- Development teams meeting corporate or compliance standards
production-code-audit FAQ
It identifies security vulnerabilities (SQL injection, weak hashing, authentication bypasses), performance bottlenecks (N+1 queries, missing indexes, large bundles), architectural problems (circular dependencies, god classes), and code quality issues across all severity levels.
Yes, but read the detailed guide first. It performs automated fixes, so review changes carefully. The skill includes verification phases to validate all tests pass and security scans show zero vulnerabilities before completion.
The skill transforms your code in-place, fixing issues across 89+ files typically. It provides detailed before/after comparisons for each fix and tracks all changes (+3,247 / -1,892 lines in the example).
Time varies by codebase size. The example with 247 files completed all 5 phases with 127 fixes. Expect proportional scaling based on your file count and issue density.
You can invoke the skill with specific requests like 'secure this codebase' to focus on security hardening, or 'optimize performance' for performance work only, rather than a full production-ready transformation.
Full instructions (SKILL.md)
Source of truth, from sickn33/agentic-awesome-skills.
name: production-code-audit description: "Autonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations" risk: critical source: community date_added: "2026-02-27"
Production Code Audit
Detailed Guide
Read the detailed guide before executing this skill. It retains the complete procedure and reference material. Treat its safety, prerequisites, and validation requirements as mandatory. For focused work, load the relevant sections; for end-to-end work, read the guide completely.
When to Use This Skill
- Use when user says "make this production-ready"
- Use when user says "audit my codebase"
- Use when user says "make this professional/corporate-level"
- Use when user says "optimize everything"
- Use when user wants enterprise-grade quality
- Use when preparing for production deployment
- Use when code needs to meet corporate standards
Examples
Example 1: Autonomous Codebase Transformation
User: @production-code-audit make this production-ready
AI: I'll scan your entire codebase and transform it to production-grade quality.
**Phase 1: Discovering Codebase** (analyzing 247 files)
- Detected: Node.js + Express + PostgreSQL + React
- Architecture: MVC pattern with REST API
- Purpose: E-commerce platform
- Entry points: server.js, src/index.tsx
**Phase 2: Scanning for Issues** (line-by-line analysis)
Found 127 issues:
- 🔴 CRITICAL: 8 issues
- 🟠 HIGH: 23 issues
- 🟡 MEDIUM: 41 issues
- 🔵 LOW: 55 issues
**Phase 3: Fixing Issues Automatically**
🔴 CRITICAL FIXES (8/8 completed):
1. ✅ Fixed SQL injection in UserRepository.findByEmail()
- Before: String concatenation in query
- After: Parameterized query with $1 placeholder
2. ✅ Removed hardcoded database password from config/database.ts
- Before: password: 'SuperSecret123!'
- After: password: process.env.DB_PASSWORD
3. ✅ Added authentication to admin routes
- Before: No auth middleware
- After: authenticateToken + requireRole('admin')
4. ✅ Fixed weak password hashing (MD5 → bcrypt)
- Before: crypto.createHash('md5')
- After: bcrypt.hash(password, 12)
5. ✅ Fixed circular dependency: OrderService ↔ PaymentService
- Before: Direct imports causing cycle
- After: Event-based decoupling with EventBus
6. ✅ Added input validation to all API endpoints
- Before: No validation
- After: Zod schemas validating all inputs
7. ✅ Fixed authentication bypass in auth middleware
- Before: next() called on missing token
- After: Returns 401 error
8. ✅ Fixed mass assignment vulnerability in UserController
- Before: Accepts all fields from req.body
- After: Whitelist of allowed fields only
🟠 HIGH PRIORITY FIXES (23/23 completed):
9. ✅ Fixed N+1 query in OrderService.getOrdersWithItems()
- Before: Loop with individual queries (2.8s)
- After: Single query with joins (45ms)
- Performance: 98% improvement
10. ✅ Refactored UserService god class (850 lines → 4 focused services)
- UserAuthenticationService (login, logout, password)
- UserProfileService (CRUD operations)
- UserNotificationService (email, SMS)
- UserPermissionService (roles, permissions)
11. ✅ Added Redis caching for product queries
- Before: Database query every request
- After: Cache with 1-hour TTL
- Performance: 95% faster
12. ✅ Optimized bundle size
- Before: 850KB (gzipped: 280KB)
- After: 380KB (gzipped: 120KB)
- Improvement: 55% reduction
13. ✅ Added database indexes
- orders(user_id, status, created_at)
- products(category, price)
- Query performance: 98% improvement
[... 11 more high-priority fixes ...]
🟡 MEDIUM PRIORITY FIXES (41/41 completed):
[... all medium fixes ...]
🔵 LOW PRIORITY IMPROVEMENTS (55/55 completed):
[... all low improvements ...]
**Phase 4: Adding Production Infrastructure**
✅ Added structured logging (Winston)
✅ Added error tracking (Sentry)
✅ Added health check endpoints (/health, /ready)
✅ Added monitoring (Prometheus metrics)
✅ Added rate limiting (Redis-based)
✅ Added API documentation (Swagger/OpenAPI)
✅ Added comprehensive README
✅ Added deployment guide
✅ Added CI/CD pipeline (.github/workflows)
**Phase 5: Verification**
✅ All tests passing (1,247 tests)
✅ Test coverage: 42% → 87%
✅ Security scan: 0 vulnerabilities
✅ Performance: API response time 3.2s → 180ms
✅ Bundle size: 850KB → 380KB
✅ Lighthouse score: 62 → 94
**TRANSFORMATION COMPLETE**
Your codebase is now production-ready with enterprise-grade quality:
📊 Metrics:
- Issues fixed: 127/127 (100%)
- Test coverage: 87% (target: 80%+)
- API performance: 94% improvement
- Security: OWASP Top 10 compliant
- Code quality: Grade A-
📁 Files changed: 89 files
📝 Lines changed: +3,247 / -1,892
🚀 Ready for production deployment!
Example 2: Automatic Security Hardening
User: @production-code-audit secure this codebase
AI: Scanning for security vulnerabilities...
**Security Scan Complete**
Found 15 security issues:
- 🔴 CRITICAL: 5
- 🟠 HIGH: 7
- 🟡 MEDIUM: 3
**Fixing all security issues automatically...**
🔴 CRITICAL (5/5 fixed):
1. ✅ SQL Injection in UserRepository
\`\`\`typescript
// Before (VULNERABLE)
const query = \`SELECT * FROM users WHERE email = '\${email}'\`;
// After (SECURE)
const query = 'SELECT * FROM users WHERE email = $1';
await db.query(query, [email]);
\`\`\`
2. ✅ Hardcoded Secrets Removed
\`\`\`typescript
// Before (INSECURE)
const tokenSigningKey = '[redacted weak value]';
// After (SECURE)
const JWT_SECRET = process.env.JWT_SECRET;
if (!JWT_SECRET) throw new Error('JWT_SECRET required');
\`\`\`
3. ✅ Authentication Added to Admin Routes
\`\`\`typescript
// Before (VULNERABLE)
router.delete('/api/admin/users/:id', deleteUser);
// After (SECURE)
router.delete('/api/admin/users/:id',
authenticateToken,
requireRole('admin'),
deleteUser
);
\`\`\`
4. ✅ Password Hashing Upgraded
\`\`\`typescript
// Before (WEAK)
const hash = crypto.createHash('md5').update(password).digest('hex');
// After (STRONG)
const hash = await bcrypt.hash(password, 12);
\`\`\`
5. ✅ Input Validation Added
\`\`\`typescript
// Before (VULNERABLE)
const user = await db.user.create({ data: req.body });
// After (SECURE)
const schema = z.object({
email: z.string().email(),
password: z.string().min(12),
name: z.string().min(2).max(100)
});
const validated = schema.parse(req.body);
const user = await db.user.create({ data: validated });
\`\`\`
**Security Status:**
- ✅ OWASP Top 10: Compliant
- ✅ SQL Injection: Protected
- ✅ XSS: Protected
- ✅ CSRF: Protected
- ✅ Authentication: Secure
- ✅ Secrets: Environment variables
- ✅ Dependencies: No vulnerabilities
🔒 Codebase is now secure and production-ready!
Example 3: Performance Optimization
User: @production-code-audit optimize performance
AI: Analyzing performance bottlenecks...
**Performance Analysis Complete**
Current metrics:
- API response time: 3.2s (target: <200ms)
- Page load time: 8.5s (target: <2s)
- Bundle size: 850KB (target: <200KB)
**Optimizing automatically...**
✅ Fixed N+1 queries (3.2s → 180ms - 94% faster)
✅ Added Redis caching (95% cache hit rate)
✅ Optimized database indexes (98% faster queries)
✅ Reduced bundle size (850KB → 380KB - 55% smaller)
✅ Optimized images (28MB → 3.2MB - 89% smaller)
✅ Implemented code splitting
✅ Added lazy loading
✅ Parallelized async operations
**Performance Results:**
| Metric | Before | After | Improvement |
|--------|--------|-------|-------------|
| API Response | 3.2s | 180ms | 94% |
| Page Load | 8.5s | 1.8s | 79% |
| Bundle Size | 850KB | 380KB | 55% |
| Image Size | 28MB | 3.2MB | 89% |
| Lighthouse | 42 | 94 | +52 points |
🚀 Performance optimized to production standards!
Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.
Related skills
More from sickn33/agentic-awesome-skills and the wider catalog.

prompt-engineer
Transforms raw prompts into optimized ones using proven frameworks like Chain of Thought, RISEN, and RODES.

prompt-engineering
Master prompt engineering patterns and techniques to optimize LLM performance and reliability.

python-patterns
Python development principles and decision-making for architecture, frameworks, async patterns, and project structure.

radix-ui-design-system
Build accessible, unstyled design systems with Radix UI primitives and full customization control.

react-nextjs-development
React and Next.js 14+ development with App Router, Server Components, TypeScript, and Tailwind CSS.

react-ui-patterns
Modern React UI patterns for loading states, error handling, and data fetching.