From Code Quality Atlas
Audits configuration and build/CI health: validates config schemas, checks for secrets in config files, ensures environment parity, reproducible hermetic builds, pinned toolchains, cache correctness, and pipeline reliability. Use for repo-wide or scheduled reviews of CI pipelines, Dockerfiles, build scripts, env vars, or config files.
How this skill is triggered — by the user, by Claude, or both
Slash command
/code-quality-atlas:auditing-config-and-build-hygieneThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
*Are config and CI trustworthy? Secrets, env parity, reproducible pinned builds, cache correctness.*
Are config and CI trustworthy? Secrets, env parity, reproducible pinned builds, cache correctness.
Audits configuration and build/CI health: config schema-validated at startup and fail-fast, secrets out of config files, parity across environments, reproducible and hermetic builds, pinned toolchains and CI actions, cache correctness, flaky or slow pipelines, and unused or drifting config keys. A repo-wide / scheduled audit. Use when auditing CI pipelines, Dockerfiles, build scripts, env vars, or config files.
Shape: repo. Run against the whole repository (scheduled or on demand), not a single diff.
Report only real problems. If the code correctly handles the case, reply "No findings" and stop — do not invent issues. This guards against false positives on correct code; still report every genuine issue you do find, with its full detail.
Defects are the default; improvements are opt-in. By default this lens is defect-only: do not suggest changes to code that is already correct. When the team has opted up into improvement suggestions, a finding on already-correct code is admissible only as nit-severity, route: implementer (the author applies, defers, or ignores), and must clear the non-configurable anti-churn floor: it must genuinely improve — never offer a merely equivalent alternative — and must converge (once a dimension is as good as you can confidently make it, stop; never oscillate A→B then B→A, never re-order to an equivalent state). Defects keep the strict bar above regardless of this setting.
The head of the full checklist — enough for a first pass without opening any reference file:
route: implementer), not a floor-tier block: surface "no coverage gate / no perf benchmark / no complexity budget" as a gap worth wiring up, and let a repo that deliberately skips it suppress the note (cross #17, #21).Where a finding here is one a tool can catch deterministically, surface that as an advisory route: implementer note next to the finding: the hand review caught it this time, and wiring the matching tool from reference/tool-rules.md into CI gates it going forward. This is a suggestion to mechanize, not a defect — it never blocks a verdict, and it falls away on a repo that already runs the tool.
npx claudepluginhub brandondees/code-quality-atlas --plugin code-quality-atlasProvides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.