Skills Development Autonomous Production Code Audit

Autonomous Production Code Audit

v20260928
production-code-audit
This skill autonomously deep-scans entire codebases line-by-line to identify security vulnerabilities, performance bottlenecks, and architectural flaws. It systematically refactors code to meet enterprise-grade production standards, including adding logging, monitoring, CI/CD pipelines, and security hardening. Ideal for preparing software for deployment.
Get Skill
374 downloads
Overview

Production Code Audit

Detailed Guide

Read the detailed guide before executing this skill. It retains the complete procedure and reference material. Treat its safety, prerequisites, and validation requirements as mandatory. For focused work, load the relevant sections; for end-to-end work, read the guide completely.

When to Use This Skill

  • Use when user says "make this production-ready"
  • Use when user says "audit my codebase"
  • Use when user says "make this professional/corporate-level"
  • Use when user says "optimize everything"
  • Use when user wants enterprise-grade quality
  • Use when preparing for production deployment
  • Use when code needs to meet corporate standards

Examples

Example 1: Autonomous Codebase Transformation

User: @production-code-audit make this production-ready

AI: I'll scan your entire codebase and transform it to production-grade quality.

**Phase 1: Discovering Codebase** (analyzing 247 files)
- Detected: Node.js + Express + PostgreSQL + React
- Architecture: MVC pattern with REST API
- Purpose: E-commerce platform
- Entry points: server.js, src/index.tsx

**Phase 2: Scanning for Issues** (line-by-line analysis)

Found 127 issues:
- ๐Ÿ”ด CRITICAL: 8 issues
- ๐ŸŸ  HIGH: 23 issues  
- ๐ŸŸก MEDIUM: 41 issues
- ๐Ÿ”ต LOW: 55 issues

**Phase 3: Fixing Issues Automatically**

๐Ÿ”ด CRITICAL FIXES (8/8 completed):

1. โœ… Fixed SQL injection in UserRepository.findByEmail()
   - Before: String concatenation in query
   - After: Parameterized query with $1 placeholder

2. โœ… Removed hardcoded database password from config/database.ts
   - Before: password: 'SuperSecret123!'
   - After: password: process.env.DB_PASSWORD

3. โœ… Added authentication to admin routes
   - Before: No auth middleware
   - After: authenticateToken + requireRole('admin')

4. โœ… Fixed weak password hashing (MD5 โ†’ bcrypt)
   - Before: crypto.createHash('md5')
   - After: bcrypt.hash(password, 12)

5. โœ… Fixed circular dependency: OrderService โ†” PaymentService
   - Before: Direct imports causing cycle
   - After: Event-based decoupling with EventBus

6. โœ… Added input validation to all API endpoints
   - Before: No validation
   - After: Zod schemas validating all inputs

7. โœ… Fixed authentication bypass in auth middleware
   - Before: next() called on missing token
   - After: Returns 401 error

8. โœ… Fixed mass assignment vulnerability in UserController
   - Before: Accepts all fields from req.body
   - After: Whitelist of allowed fields only

๐ŸŸ  HIGH PRIORITY FIXES (23/23 completed):

9. โœ… Fixed N+1 query in OrderService.getOrdersWithItems()
   - Before: Loop with individual queries (2.8s)
   - After: Single query with joins (45ms)
   - Performance: 98% improvement

10. โœ… Refactored UserService god class (850 lines โ†’ 4 focused services)
    - UserAuthenticationService (login, logout, password)
    - UserProfileService (CRUD operations)
    - UserNotificationService (email, SMS)
    - UserPermissionService (roles, permissions)

11. โœ… Added Redis caching for product queries
    - Before: Database query every request
    - After: Cache with 1-hour TTL
    - Performance: 95% faster

12. โœ… Optimized bundle size
    - Before: 850KB (gzipped: 280KB)
    - After: 380KB (gzipped: 120KB)
    - Improvement: 55% reduction

13. โœ… Added database indexes
    - orders(user_id, status, created_at)
    - products(category, price)
    - Query performance: 98% improvement

[... 11 more high-priority fixes ...]

๐ŸŸก MEDIUM PRIORITY FIXES (41/41 completed):
[... all medium fixes ...]

๐Ÿ”ต LOW PRIORITY IMPROVEMENTS (55/55 completed):
[... all low improvements ...]

**Phase 4: Adding Production Infrastructure**

โœ… Added structured logging (Winston)
โœ… Added error tracking (Sentry)
โœ… Added health check endpoints (/health, /ready)
โœ… Added monitoring (Prometheus metrics)
โœ… Added rate limiting (Redis-based)
โœ… Added API documentation (Swagger/OpenAPI)
โœ… Added comprehensive README
โœ… Added deployment guide
โœ… Added CI/CD pipeline (.github/workflows)

**Phase 5: Verification**

โœ… All tests passing (1,247 tests)
โœ… Test coverage: 42% โ†’ 87%
โœ… Security scan: 0 vulnerabilities
โœ… Performance: API response time 3.2s โ†’ 180ms
โœ… Bundle size: 850KB โ†’ 380KB
โœ… Lighthouse score: 62 โ†’ 94

**TRANSFORMATION COMPLETE**

Your codebase is now production-ready with enterprise-grade quality:

๐Ÿ“Š Metrics:
- Issues fixed: 127/127 (100%)
- Test coverage: 87% (target: 80%+)
- API performance: 94% improvement
- Security: OWASP Top 10 compliant
- Code quality: Grade A-

๐Ÿ“ Files changed: 89 files
๐Ÿ“ Lines changed: +3,247 / -1,892

๐Ÿš€ Ready for production deployment!

Example 2: Automatic Security Hardening

User: @production-code-audit secure this codebase

AI: Scanning for security vulnerabilities...

**Security Scan Complete**

Found 15 security issues:
- ๐Ÿ”ด CRITICAL: 5
- ๐ŸŸ  HIGH: 7
- ๐ŸŸก MEDIUM: 3

**Fixing all security issues automatically...**

๐Ÿ”ด CRITICAL (5/5 fixed):

1. โœ… SQL Injection in UserRepository
\`\`\`typescript
// Before (VULNERABLE)
const query = \`SELECT * FROM users WHERE email = '\${email}'\`;

// After (SECURE)
const query = 'SELECT * FROM users WHERE email = $1';
await db.query(query, [email]);
\`\`\`

2. โœ… Hardcoded Secrets Removed
\`\`\`typescript
// Before (INSECURE)
const tokenSigningKey = '[redacted weak value]';

// After (SECURE)
const JWT_SECRET = process.env.JWT_SECRET;
if (!JWT_SECRET) throw new Error('JWT_SECRET required');
\`\`\`

3. โœ… Authentication Added to Admin Routes
\`\`\`typescript
// Before (VULNERABLE)
router.delete('/api/admin/users/:id', deleteUser);

// After (SECURE)
router.delete('/api/admin/users/:id',
  authenticateToken,
  requireRole('admin'),
  deleteUser
);
\`\`\`

4. โœ… Password Hashing Upgraded
\`\`\`typescript
// Before (WEAK)
const hash = crypto.createHash('md5').update(password).digest('hex');

// After (STRONG)
const hash = await bcrypt.hash(password, 12);
\`\`\`

5. โœ… Input Validation Added
\`\`\`typescript
// Before (VULNERABLE)
const user = await db.user.create({ data: req.body });

// After (SECURE)
const schema = z.object({
  email: z.string().email(),
  password: z.string().min(12),
  name: z.string().min(2).max(100)
});
const validated = schema.parse(req.body);
const user = await db.user.create({ data: validated });
\`\`\`

**Security Status:**
- โœ… OWASP Top 10: Compliant
- โœ… SQL Injection: Protected
- โœ… XSS: Protected
- โœ… CSRF: Protected
- โœ… Authentication: Secure
- โœ… Secrets: Environment variables
- โœ… Dependencies: No vulnerabilities

๐Ÿ”’ Codebase is now secure and production-ready!

Example 3: Performance Optimization

User: @production-code-audit optimize performance

AI: Analyzing performance bottlenecks...

**Performance Analysis Complete**

Current metrics:
- API response time: 3.2s (target: <200ms)
- Page load time: 8.5s (target: <2s)
- Bundle size: 850KB (target: <200KB)

**Optimizing automatically...**

โœ… Fixed N+1 queries (3.2s โ†’ 180ms - 94% faster)
โœ… Added Redis caching (95% cache hit rate)
โœ… Optimized database indexes (98% faster queries)
โœ… Reduced bundle size (850KB โ†’ 380KB - 55% smaller)
โœ… Optimized images (28MB โ†’ 3.2MB - 89% smaller)
โœ… Implemented code splitting
โœ… Added lazy loading
โœ… Parallelized async operations

**Performance Results:**

| Metric | Before | After | Improvement |
|--------|--------|-------|-------------|
| API Response | 3.2s | 180ms | 94% |
| Page Load | 8.5s | 1.8s | 79% |
| Bundle Size | 850KB | 380KB | 55% |
| Image Size | 28MB | 3.2MB | 89% |
| Lighthouse | 42 | 94 | +52 points |

๐Ÿš€ Performance optimized to production standards!

Limitations

  • Use this skill only when the task clearly matches the scope described above.
  • Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
  • Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.
Info
Category Development
Name production-code-audit
Version v20260928
Size 7.23KB
Updated At 2026-09-28
Language