
from audit-flow11
Interactive system flow tracing with SQLite persistence and Mermaid export for security audits, debugging, architecture reviews and post-mortems.
Interactive tracing of system flows across CODE, API, AUTH, DATA and NETWORK layers. Stores flows in a SQLite DB, supports non-linear branching/merging, and exports diagrams (Mermaid) and structured exports for documentation, compliance, and incident post-mortems. Includes CLI scripts for listing, showing, exporting and validating flows, plus a git merge driver to safely merge the audit DB.
Use this skill when performing security audits, architecture reviews, debugging complex multi-layer interactions, preparing compliance documentation, running incident post-mortems, or brainstorming feature flows that need persistent, auditable tracing. Trigger on actions like 'audit', 'trace flow', 'document flow', 'security review', 'post-mortem'.
Designed for Claude Code / Claude Code-like agent integrations that can invoke local Python scripts and follow structured CLI workflows.
Audit-flow is an interactive system flow tracing skill that uses SQLite persistence and Mermaid export for security audits, debugging, architecture reviews, and post-mortems. The single bundled script (audit.py, ~60KB) is a well-structured argparse CLI with comprehensive commands (init, list, show, export, validate, csv-*, db-merge, git-setup). It failed to run only because it requires a subcommand argument — the CLI itself works correctly and shows proper usage. No security concerns: subprocess calls are git-only with explicit arg lists (no shell=True), no network calls, no hardcoded credentials, no destructive operations without guards. Architecture follows the skill spec well with progressive disclosure, clear output contracts, and good separation between SKILL.md documentation and scripts/.
Very thorough SKILL.md with detailed semantic rules, anti-patterns, and validation checks. The DB-first approach with forbidden actions table is a thoughtful guardrail. Mermaid validation with step numbers, entry points, and edge styling is well-designed. Git merge driver for SQLite binary is a clever solution. Script quality is high — proper error handling, CSV import/export for portability, and idempotent init with --force guard.