web-quality-audit

Kiểm tra chất lượng web toàn diện bao gồm hiệu suất, khả năng tiếp cận, SEO và các phương pháp tốt nhất. Sử dụng khi được yêu cầu "kiểm tra trang web của tôi", "đánh giá chất lượng web", "chạy kiểm tra lighthouse", "kiểm tra chất lượng trang" hoặc "tối ưu hóa trang web của tôi".

npx skills add https://github.com/addyosmani/web-quality-skills --skill web-quality-audit

Web quality audit

Comprehensive quality review based on Google Lighthouse audits. Covers Performance, Accessibility, SEO, and Best Practices across 150+ checks.

Lighthouse v13 note (Oct 2025+). Lighthouse has migrated the Performance category from per-opportunity audits to Performance Insight Audits (announcement). Several individual audit names this skill historically referenced — First Meaningful Paint, No Document Write, Uses Passive Event Listeners, Uses Rel Preload — have been removed or merged. The underlying advice is unchanged and still applies; only the report format moved. The CLS-related audits ("layout shifts", "non-composited animations", "unsized images") are now consolidated into a single cls-culprits-insight, and image audits are merged into image-delivery-insight. Treat older Lighthouse JSON output as a superset, not a contradiction.

How it works

  1. Analyze the provided code/project for quality issues
  2. Categorize findings by severity (Critical, High, Medium, Low)
  3. Provide specific, actionable recommendations
  4. Include code examples for fixes

Audit categories

Performance (40% of typical issues)

Core Web Vitals — Must pass for good page experience:

  • LCP (Largest Contentful Paint) < 2.5s. The largest visible element must render quickly. Optimize images, fonts, and server response time.
  • INP (Interaction to Next Paint) < 200ms. User interactions must feel instant. Reduce JavaScript execution time and break up long tasks.
  • CLS (Cumulative Layout Shift) < 0.1. Content must not jump around. Set explicit dimensions on images, embeds, and ads.

Resource Optimization:

  • Compress images. Use WebP/AVIF with fallbacks. Serve correctly sized images via srcset.
  • Minimize JavaScript. Remove unused code. Use code splitting. Defer non-critical scripts.
  • Optimize CSS. Extract critical CSS. Remove unused styles. Avoid @import.
  • Efficient fonts. Use font-display: swap. Preload critical fonts. Subset to needed characters.

Loading Strategy:

  • Preconnect to origins. Add <link rel="preconnect"> for third-party domains.
  • Preload critical assets. LCP images, fonts, and above-fold CSS.
  • Lazy load below-fold content. Images, iframes, and heavy components.
  • Cache effectively. Long cache TTLs for static assets. Immutable caching for hashed files.

Accessibility (30% of typical issues)

Perceivable:

  • Text alternatives. Every <img> has meaningful alt text. Decorative images use alt="".
  • Color contrast. Minimum 4.5:1 for normal text, 3:1 for large text (WCAG AA).
  • Don't rely on color alone. Use icons, patterns, or text alongside color indicators.
  • Captions and transcripts. Video has captions. Audio has transcripts.

Operable:

  • Keyboard accessible. All functionality available via keyboard. No keyboard traps.
  • Focus visible. Clear focus indicators on all interactive elements.
  • Skip links. Provide "Skip to main content" for keyboard users.
  • Sufficient time. Users can extend time limits. No auto-advancing content without controls.

Understandable:

  • Page language. Set lang attribute on <html>.
  • Consistent navigation. Same navigation structure across pages.
  • Error identification. Form errors clearly described and associated with fields.
  • Labels and instructions. All form inputs have associated labels.

Robust:

  • Valid HTML. No duplicate IDs. Properly nested elements.
  • ARIA used correctly. Prefer native elements. ARIA roles match behavior.
  • Name, role, value. Interactive elements have accessible names and correct roles.

SEO (15% of typical issues)

Crawlability:

  • Valid robots.txt. Doesn't block important resources.
  • XML sitemap. Lists all important pages. Submitted to Search Console.
  • Canonical URLs. Prevent duplicate content issues.
  • No noindex on important pages. Check meta robots and headers.

On-Page SEO:

  • Unique title tags. 50-60 characters. Primary keyword included.
  • Meta descriptions. 150-160 characters. Compelling and unique.
  • Heading hierarchy. Single <h1>. Logical heading structure.
  • Descriptive link text. Not "click here" or "read more".

Technical SEO:

  • Mobile-friendly. Responsive design. Tap targets ≥ 48px.
  • HTTPS. Secure connection required.
  • Fast loading. Performance directly impacts ranking.
  • Structured data. JSON-LD for rich snippets (Article, Product, FAQ, etc.).

Best practices (15% of typical issues)

Security:

  • HTTPS everywhere. No mixed content. HSTS enabled.
  • No vulnerable libraries. Keep dependencies updated.
  • CSP headers. Content Security Policy to prevent XSS.
  • No exposed source maps. In production builds.

Modern Standards:

  • No deprecated APIs. Replace document.write, synchronous XHR, etc.
  • Valid doctype. Use <!DOCTYPE html>.
  • Charset declared. <meta charset="UTF-8"> as first element in <head>.
  • No browser errors. Clean console. No CORS issues.

UX Patterns:

  • No intrusive interstitials. Especially on mobile.
  • Clear permission requests. Only ask when needed, with context.
  • No misleading buttons. Buttons do what they say.

Severity levels

LevelDescriptionAction
CriticalSecurity vulnerabilities, complete failuresFix immediately
HighCore Web Vitals failures, major a11y barriersFix before launch
MediumPerformance opportunities, SEO improvementsFix within sprint
LowMinor optimizations, code qualityFix when convenient

Audit output format

When performing an audit, structure findings as:

## Audit results

### Critical issues (X found)
- **[Category]** Issue description. File: `path/to/file.js:123`
  - **Impact:** Why this matters
  - **Fix:** Specific code change or recommendation

### High priority (X found)
...

### Summary
- Performance: X issues (Y critical)
- Accessibility: X issues (Y critical)
- SEO: X issues
- Best Practices: X issues

### Recommended priority
1. First fix this because...
2. Then address...
3. Finally optimize...

Quick checklist

Before every deploy

  • Core Web Vitals passing
  • No accessibility errors (axe/Lighthouse)
  • No console errors
  • HTTPS working
  • Meta tags present

Weekly review

  • Check Search Console for issues
  • Review Core Web Vitals trends
  • Update dependencies
  • Test with screen reader

Monthly deep dive

  • Full Lighthouse audit
  • Performance profiling
  • Accessibility audit with real users
  • SEO keyword review

References

For detailed guidelines on specific areas:

Thêm skills từ addyosmani

accessibility
addyosmani
Kiểm tra và cải thiện khả năng truy cập web theo hướng dẫn WCAG 2.2. Sử dụng khi được yêu cầu "cải thiện khả năng truy cập", "kiểm tra a11y", "tuân thủ WCAG", "hỗ trợ trình đọc màn hình", "điều hướng bàn phím" hoặc "làm cho có thể truy cập".
developmenttestingcode-review
seo
addyosmani
Tối ưu hóa khả năng hiển thị và thứ hạng trên công cụ tìm kiếm. Sử dụng khi được yêu cầu "cải thiện SEO", "tối ưu hóa cho tìm kiếm", "sửa thẻ meta", "thêm dữ liệu có cấu trúc", "tối ưu hóa sơ đồ trang web" hoặc "tối ưu hóa công cụ tìm kiếm".
marketingresearchdevelopment
performance
addyosmani
Tối ưu hiệu suất web để tải nhanh hơn và cải thiện trải nghiệm người dùng. Sử dụng khi được yêu cầu "tăng tốc trang web của tôi", "tối ưu hiệu suất", "giảm thời gian tải", "sửa tải chậm", "cải thiện tốc độ trang" hoặc "kiểm tra hiệu suất".
developmenttesting
code-review-and-quality
addyosmani
Thực hiện đánh giá mã nguồn đa chiều. Sử dụng trước khi hợp nhất bất kỳ thay đổi nào. Sử dụng khi xem xét mã do chính bạn, một tác nhân khác hoặc con người viết. Sử dụng khi bạn cần đánh giá chất lượng mã trên nhiều khía cạnh trước khi nó được đưa vào nhánh chính.
developmentcode-review
frontend-ui-engineering
addyosmani
Xây dựng giao diện người dùng chất lượng sản xuất, có khả năng truy cập và phản hồi. Sử dụng khi xây dựng hoặc sửa đổi giao diện và trang, tạo thành phần, triển khai bố cục, đáp ứng yêu cầu truy cập WCAG, quản lý trạng thái, hoặc khi đầu ra cần trông và cảm nhận chất lượng sản xuất thay vì do AI tạo ra.
developmentdesign
security-and-hardening
addyosmani
Tăng cường bảo mật mã nguồn chống lại các lỗ hổng. Sử dụng khi xử lý đầu vào người dùng, xác thực, lưu trữ dữ liệu hoặc tích hợp bên ngoài. Sử dụng khi xây dựng bất kỳ tính năng nào chấp nhận dữ liệu không đáng tin cậy, quản lý phiên người dùng hoặc tương tác với dịch vụ bên thứ ba.
spec-driven-development
addyosmani
Tạo đặc tả trước khi viết mã. Sử dụng khi bắt đầu một dự án mới, tính năng mới hoặc thay đổi quan trọng và chưa có đặc tả nào tồn tại. Sử dụng khi yêu cầu chưa rõ ràng, mơ hồ hoặc chỉ tồn tại dưới dạng ý tưởng mơ hồ.
developmentdocumentproject-management
performance-optimization
addyosmani
Tối ưu hóa hiệu suất ứng dụng trên frontend, backend, truy vấn và cơ sở dữ liệu. Sử dụng khi có yêu cầu về hiệu suất, khi nghi ngờ có suy giảm hiệu suất, khi cần cải thiện Core Web Vitals hoặc thời gian tải, khi cần sửa các mẫu truy vấn N+1, hoặc khi hồ sơ hiệu suất phát hiện điểm nghẽn.
developmentdatabasedata-analysis