
Health Audit
- 53 installs
- 49 repo stars
- Updated August 4, 2026
- laurigates/claude-plugins
Helps with security tasks.
About
health-audit is a Claude Code skill for security. It helps solo builders move faster with AI-assisted development.
- health-audit
- Security
- AI-coding skill
Health Audit by the numbers
- 53 all-time installs (skills.sh)
- Ranked #1,292 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/laurigates/claude-plugins --skill health-auditAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 53 |
|---|---|
| repo stars | ★ 49 |
| Last updated | August 4, 2026 |
| Repository | laurigates/claude-plugins ↗ |
What it does
Helps with security tasks.
Files
/health:audit
Audit the project's enabled plugins against the actual technology stack. Identifies plugins that don't apply to this project and suggests relevant plugins that aren't enabled.
When to Use This Skill
| Use this skill when... | Use another approach when... |
|---|---|
| Reviewing plugin relevance for current project | General health diagnostics (use /health:check) |
| Cleaning up unused plugins | Plugin registry corruption (use /health:plugins --fix) |
| Discovering relevant plugins for tech stack | Agentic optimization audit (use /health:agentic-audit) |
| Optimizing project-specific plugin configuration | Installing specific plugin (install directly) |
| Onboarding to existing project | Need comprehensive settings validation |
Context
- Current project: !
pwd - Project settings exists: !
find .claude -maxdepth 1 -name 'settings.json' - Package.json exists: !
find . -maxdepth 1 -name 'package.json' - Cargo.toml exists: !
find . -maxdepth 1 -name 'Cargo.toml' - pyproject.toml exists: !
find . -maxdepth 1 -name 'pyproject.toml' - requirements.txt exists: !
find . -maxdepth 1 -name 'requirements.txt' - go.mod exists: !
find . -maxdepth 1 -name 'go.mod' - Dockerfile exists: !
find . -maxdepth 1 -name 'Dockerfile' - docker-compose exists: !
find . -maxdepth 1 \( -name 'docker-compose.yml' -o -name 'docker-compose.yaml' -o -name 'compose.yml' -o -name 'compose.yaml' \) - GitHub workflows: !
find .github/workflows -maxdepth 1 -name '*.yml' -quit -print - Terraform files: !
find . -maxdepth 2 -name '*.tf' -quit -print - Kubernetes manifests: !
find . -maxdepth 3 \( -path '*/k8s/*' -o -path '*/kubernetes/*' \) -name '*.yaml' -quit -print
Parameters
| Parameter | Description |
|---|---|
--fix | Apply recommended changes to .claude/settings.json |
--dry-run | Show what would be changed without modifying files |
--verbose | Show detailed analysis of each plugin decision |
Execution
Execute this plugin relevance audit:
Step 1: Detect the project technology stack
Analyze project files from the context above to determine the technology stack. Match indicators against the tech stack mapping in REFERENCE.md.
Step 2: Retrieve available plugins
Run claude plugin list --json to get all available plugins from configured marketplaces. Parse the output for plugin name, description, keywords, and category.
Step 3: Read currently enabled plugins
Read .claude/settings.json and extract the enabledPlugins array. If the file does not exist or enabledPlugins is not set, treat as empty list.
Step 4: Analyze plugin relevance
Compare each enabled plugin against the detected tech stack. Use the plugin relevance mapping in REFERENCE.md to determine which plugins are relevant, irrelevant, or missing.
Categorize each plugin as:
- RELEVANT -- matches detected tech stack
- NOT RELEVANT -- no matching indicators found
- MISSING -- relevant plugin not currently enabled
Step 5: Generate the audit report
Print a structured report covering: 1. Detected technology stack with evidence 2. Currently enabled plugins with relevance status 3. Suggested plugins to add (with reasons) 4. Suggested plugins to remove (with reasons) 5. Summary counts
Step 6: Apply changes (if --fix)
When --fix is passed:
1. Back up current settings: cp .claude/settings.json .claude/settings.json.backup 2. Ask for confirmation before each category of changes (removals, additions) 3. Update .claude/settings.json -- remove confirmed irrelevant plugins, add confirmed relevant plugins, preserve other settings 4. Verify changes by re-reading the file, confirming valid JSON, and showing the diff
User-Level vs Project-Level
Note: This command only manages project-level plugin settings in .claude/settings.json.
User-level plugins (in ~/.claude/settings.json) are managed separately and don't need duplication at project level.
When analyzing, check if a plugin is already enabled at user level:
jq -r '.enabledPlugins[]? // empty' ~/.claude/settings.json 2>/dev/nullIf a plugin is enabled at user level, it doesn't need to be in project settings unless you want project-specific behavior.
Edge Cases
| Scenario | Behavior |
|---|---|
No .claude/settings.json | Create it with recommended plugins |
Empty enabledPlugins | Suggest adding relevant plugins |
| Monorepo with multiple languages | Suggest all matching plugins |
| Plugin not in marketplace | Flag as "unknown" but don't remove |
| User declined changes | Respect decision, show manual instructions |
Agentic Optimizations
| Context | Command |
|---|---|
| Plugin relevance audit | /health:audit |
| Audit with auto-fix | /health:audit --fix |
| Dry-run mode | /health:audit --dry-run |
| List enabled plugins | jq -r '.enabledPlugins[]? // empty' .claude/settings.json 2>/dev/null |
| Detect project languages | find . -maxdepth 1 \( -name 'package.json' -o -name 'Cargo.toml' -o -name 'pyproject.toml' \) -exec basename {} \; |
Flags
| Flag | Description |
|---|---|
--fix | Apply recommended changes (with confirmation) |
--dry-run | Show what would be changed without modifying |
--verbose | Show detailed reasoning for each decision |
See Also
/health:plugins- Fix plugin registry issues/health:check- Full diagnostic scan/configure:claude-plugins- Initial plugin setup
Health Audit Reference
Tech Stack Detection Mapping
| Indicator | Technology | Related Plugins |
|---|---|---|
package.json + tsconfig.json | TypeScript | typescript-plugin |
package.json (no tsconfig) | JavaScript | typescript-plugin (JS support) |
bun.lockb or bun in package.json | Bun runtime | typescript-plugin |
Cargo.toml | Rust | rust-plugin |
pyproject.toml, requirements.txt, setup.py | Python | python-plugin |
go.mod | Go | (no plugin yet) |
Dockerfile, docker-compose.yml | Docker/Containers | container-plugin |
.github/workflows/*.yml | GitHub Actions | github-actions-plugin |
*.tf files | Terraform | terraform-plugin |
k8s/, kubernetes/ with manifests | Kubernetes | kubernetes-plugin |
bevy in Cargo.toml | Bevy game engine | bevy-plugin |
.claude-plugin/ directory | Claude plugin development | (this repo) |
docs/ with markdown | Documentation | documentation-plugin |
langchain in dependencies | LangChain | langchain-plugin |
| OpenAPI/Swagger specs | API development | api-plugin |
biome.json, .eslintrc* | Code quality | code-quality-plugin |
vitest.config.*, jest.config.* | Testing | testing-plugin |
| Home Assistant configs | Home Assistant | home-assistant-plugin |
Plugin Relevance Mapping
| Plugin | Relevant When |
|---|---|
| typescript-plugin | package.json exists |
| python-plugin | Python project indicators exist |
| rust-plugin | Cargo.toml exists |
| container-plugin | Dockerfile or compose file exists |
| kubernetes-plugin | K8s manifests exist |
| github-actions-plugin | .github/workflows/ exists |
| terraform-plugin | *.tf files exist |
| git-plugin | Always relevant (all repos use git) |
| tools-plugin | Always relevant (common CLI tools) |
| configure-plugin | Always relevant (setup automation) |
| testing-plugin | Test files/configs exist |
| code-quality-plugin | Linter configs exist |
| bevy-plugin | Bevy in Cargo.toml dependencies |
| langchain-plugin | LangChain in dependencies |
| api-plugin | OpenAPI specs exist |
| documentation-plugin | docs/ directory with markdown |
| blueprint-plugin | docs/blueprint/ or planning documents |
| agents-plugin | Agent development context |
| project-plugin | Project management needs |
Report Template
Plugin Audit Report
===================
Project: <current-directory>
Date: <timestamp>
Detected Technology Stack
-------------------------
- TypeScript/JavaScript (package.json, tsconfig.json)
- Docker (Dockerfile, docker-compose.yml)
- GitHub Actions (.github/workflows/)
Currently Enabled Plugins (N)
-----------------------------
+ typescript-plugin - RELEVANT (TypeScript project)
+ git-plugin - RELEVANT (all repos)
x kubernetes-plugin - NOT RELEVANT (no K8s manifests found)
x terraform-plugin - NOT RELEVANT (no .tf files found)
x python-plugin - NOT RELEVANT (no Python indicators)
Suggested Plugins to Add (N)
----------------------------
+ container-plugin - Docker files detected
+ github-actions-plugin - Workflow files detected
+ testing-plugin - Test configuration detected
Suggested Plugins to Remove (N)
-------------------------------
- kubernetes-plugin - No K8s usage detected
- terraform-plugin - No Terraform usage detected
- python-plugin - No Python usage detected
Summary
-------
Enabled: N plugins
Relevant: N plugins
Irrelevant: N plugins (consider removing)
Missing: N plugins (consider adding)
Run `/health:audit --fix` to apply these recommendations.