Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
laurigates avatar

Health Audit

  • 53 installs
  • 49 repo stars
  • Updated August 4, 2026
  • laurigates/claude-plugins

Helps with security tasks.

About

health-audit is a Claude Code skill for security. It helps solo builders move faster with AI-assisted development.

  • health-audit
  • Security
  • AI-coding skill

Health Audit by the numbers

  • 53 all-time installs (skills.sh)
  • Ranked #1,292 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/laurigates/claude-plugins --skill health-audit

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs53
repo stars49
Last updatedAugust 4, 2026
Repositorylaurigates/claude-plugins

What it does

Helps with security tasks.

Files

SKILL.mdMarkdownGitHub ↗

/health:audit

Audit the project's enabled plugins against the actual technology stack. Identifies plugins that don't apply to this project and suggests relevant plugins that aren't enabled.

When to Use This Skill

Use this skill when...Use another approach when...
Reviewing plugin relevance for current projectGeneral health diagnostics (use /health:check)
Cleaning up unused pluginsPlugin registry corruption (use /health:plugins --fix)
Discovering relevant plugins for tech stackAgentic optimization audit (use /health:agentic-audit)
Optimizing project-specific plugin configurationInstalling specific plugin (install directly)
Onboarding to existing projectNeed comprehensive settings validation

Context

  • Current project: !pwd
  • Project settings exists: !find .claude -maxdepth 1 -name 'settings.json'
  • Package.json exists: !find . -maxdepth 1 -name 'package.json'
  • Cargo.toml exists: !find . -maxdepth 1 -name 'Cargo.toml'
  • pyproject.toml exists: !find . -maxdepth 1 -name 'pyproject.toml'
  • requirements.txt exists: !find . -maxdepth 1 -name 'requirements.txt'
  • go.mod exists: !find . -maxdepth 1 -name 'go.mod'
  • Dockerfile exists: !find . -maxdepth 1 -name 'Dockerfile'
  • docker-compose exists: !find . -maxdepth 1 \( -name 'docker-compose.yml' -o -name 'docker-compose.yaml' -o -name 'compose.yml' -o -name 'compose.yaml' \)
  • GitHub workflows: !find .github/workflows -maxdepth 1 -name '*.yml' -quit -print
  • Terraform files: !find . -maxdepth 2 -name '*.tf' -quit -print
  • Kubernetes manifests: !find . -maxdepth 3 \( -path '*/k8s/*' -o -path '*/kubernetes/*' \) -name '*.yaml' -quit -print

Parameters

ParameterDescription
--fixApply recommended changes to .claude/settings.json
--dry-runShow what would be changed without modifying files
--verboseShow detailed analysis of each plugin decision

Execution

Execute this plugin relevance audit:

Step 1: Detect the project technology stack

Analyze project files from the context above to determine the technology stack. Match indicators against the tech stack mapping in REFERENCE.md.

Step 2: Retrieve available plugins

Run claude plugin list --json to get all available plugins from configured marketplaces. Parse the output for plugin name, description, keywords, and category.

Step 3: Read currently enabled plugins

Read .claude/settings.json and extract the enabledPlugins array. If the file does not exist or enabledPlugins is not set, treat as empty list.

Step 4: Analyze plugin relevance

Compare each enabled plugin against the detected tech stack. Use the plugin relevance mapping in REFERENCE.md to determine which plugins are relevant, irrelevant, or missing.

Categorize each plugin as:

  • RELEVANT -- matches detected tech stack
  • NOT RELEVANT -- no matching indicators found
  • MISSING -- relevant plugin not currently enabled

Step 5: Generate the audit report

Print a structured report covering: 1. Detected technology stack with evidence 2. Currently enabled plugins with relevance status 3. Suggested plugins to add (with reasons) 4. Suggested plugins to remove (with reasons) 5. Summary counts

Step 6: Apply changes (if --fix)

When --fix is passed:

1. Back up current settings: cp .claude/settings.json .claude/settings.json.backup 2. Ask for confirmation before each category of changes (removals, additions) 3. Update .claude/settings.json -- remove confirmed irrelevant plugins, add confirmed relevant plugins, preserve other settings 4. Verify changes by re-reading the file, confirming valid JSON, and showing the diff

User-Level vs Project-Level

Note: This command only manages project-level plugin settings in .claude/settings.json.

User-level plugins (in ~/.claude/settings.json) are managed separately and don't need duplication at project level.

When analyzing, check if a plugin is already enabled at user level:

jq -r '.enabledPlugins[]? // empty' ~/.claude/settings.json 2>/dev/null

If a plugin is enabled at user level, it doesn't need to be in project settings unless you want project-specific behavior.

Edge Cases

ScenarioBehavior
No .claude/settings.jsonCreate it with recommended plugins
Empty enabledPluginsSuggest adding relevant plugins
Monorepo with multiple languagesSuggest all matching plugins
Plugin not in marketplaceFlag as "unknown" but don't remove
User declined changesRespect decision, show manual instructions

Agentic Optimizations

ContextCommand
Plugin relevance audit/health:audit
Audit with auto-fix/health:audit --fix
Dry-run mode/health:audit --dry-run
List enabled pluginsjq -r '.enabledPlugins[]? // empty' .claude/settings.json 2>/dev/null
Detect project languagesfind . -maxdepth 1 \( -name 'package.json' -o -name 'Cargo.toml' -o -name 'pyproject.toml' \) -exec basename {} \;

Flags

FlagDescription
--fixApply recommended changes (with confirmation)
--dry-runShow what would be changed without modifying
--verboseShow detailed reasoning for each decision

See Also

  • /health:plugins - Fix plugin registry issues
  • /health:check - Full diagnostic scan
  • /configure:claude-plugins - Initial plugin setup

Related skills

Securityappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.