Ca audit
Skill arbiterForge/codeArbiter/plugins/ca-codex/skills/ca-audit
When you can't trust yourself with your code base, trust Arbiter.
npx -y skills add arbiterForge/codeArbiter --skill ca-auditAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
What its author says it does
Copied from the file, not written here
Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only.
SKILL.md
2.7 KB, 632 tokens by cl100k_base, as published. Nobody here has run it
$ca-audit — promotion packet
Everything codeArbiter logs, it logs append-only and scattered: overrides.log, triage.log,
decisions/, sprint-log.md, checkpoints/. This command assembles them into the one document a
team lead, compliance reviewer, or auditor actually asks for: what happened in this window, who
authorized it, and what is still open. Read-only over every source; its only write is the packet.
Window
<from-ref> <to-ref>— two tags/SHAs (e.g.v1.2.0 v1.3.0).--since-checkpoint— from thelast-checkpointrecord to HEAD.--since <date>— ISO date to HEAD.- No argument → from the most recent tag to HEAD (no tags → last checkpoint; neither → BLOCK and ask for an explicit window).
Flow
- Resolve the window to a commit range and a time range; both appear in the packet header.
- Gather, citing each source file:
- Commits —
git logover the range, grouped by Conventional-Commit type; merge commits listed with their PR reference. - Overrides — every
overrides.logline in the time range, verbatim (includingSECURITY-OVERRIDEandDEV:entries), each with itsBY:identity. - Triage — every small-lane classification in
triage.login range. - Decisions — ADRs created or superseded in range (from
decisions/file dates and the supersede chains), each with its Decided-by attribution. - Sprint auto-decisions — entries from
sprint-log.mdin range; list everylow-confidence entry verbatim, count thehighones. - Open questions — all currently-unresolved
[CONFIRM-NN]items. - Checkpoint findings — from the most recent
checkpoints/*.md: findings still open.
- Commits —
- Write the packet to
<project-root>/.codearbiter/audits/<YYYY-MM-DD>.md(second run the same day appends-2,-3, … — an existing packet is never overwritten). Surface the path and a three-line summary: commits, overrides, open items.
Hard gate
Read-only over every source — MUST NOT modify any log, decision, or checkpoint while assembling. MUST NOT overwrite an existing packet. MUST quote override and low-confidence sprint entries verbatim — never paraphrase an audit line. An empty section is stated as empty, never omitted — "no overrides in window" is itself the finding.
When NOT to use
- Live project state right now →
$ca-status. - Triggering reviews →
$ca-checkpoint(this command only reports what reviews already found).
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.