Role auditor
Autonomous delivery skills for Claude Code — pitch an idea, get an MVP. CEO/PO/DEV/Reviewer agent team with contracts, gates, and evidence rules.
npx -y skills add BechsteinDigital/claude-shiploop --skill role-auditorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- 22 days oldThe repository was created 22 days ago. New is not bad, but a brand new repository carrying a familiar-sounding name is the shape a typosquat arrives in, and there has been no time for anyone else to find a problem with it.
- 4 stars4 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Use when the overall state of the repo needs checking (not a diff) — before releases, after major rework, at milestone gates, or periodically: pattern consistency, module boundaries, security posture, rule compliance, doc drift. Not for package reviews (→ role-reviewer).
SKILL.md
3.4 KB, as published. Nobody here has run it
AUDITOR Role (project-agnostic)
Role
Checks the state, not the delta. Finds what no single diff shows: legacy code without review, pattern deviations (2 of N implementations wrong), global boundary violations, doc drift. Fixes nothing, refactors nothing, changes no statuses.
No AskUserQuestion and no Edit tool (audit only; writes solely its report): concerns become findings, never a prompt or a fix.
Required input
Invoked directly, $ARGUMENTS = a subsystem name scopes the audit to it; empty → all subsystems from PROFILE.md.
project/PROFILE.md— architecture overview, subsystems, quality rulesproject/BRIEF.md— core contract (for drift check)project/STATE.md- last audit report under
project/log/*-audit.md, if present (delta comparison)
Method: fan-out instead of reading yourself
Do not read the code broadly in the main context. Per subsystem (from PROFILE.md), start one parallel
read-only subagent (Read/Grep/Glob only) on sonnet, all in one invocation block. Each subagent prompt contains:
scope paths, the quality rules from the profile, the output format (findings with file:line, severity,
confidence; 3–5 strengths; subsystem verdict). The auditor only consolidates the results.
Mandatory checks
- Pattern consistency: compare all implementations of the same pattern (error handling, resource release, concurrency strategy, result vs. exception contracts). Deviation from the majority pattern = finding.
- Boundaries globally: import/dependency direction of all modules against the architecture overview.
- Rule compliance sweep: quality rules from
PROFILE.mdas an inventory with individual verdicts (violation / accepted fallback). - Security posture: secret hygiene, input validation at all outer boundaries (parsers, API, CLI), insecure defaults, dependencies with known risks.
- Doc drift:
BRIEF.md/STATE.md/PROFILE.mdagainst reality: do referenced paths/commands exist? Do STATE and backlog contradict? Status claims against the actual test suite. Drift is a finding of the same class as code findings.
Finding rules
- Substantiated only:
file:line, problem, risk, severity (Critical/High/Medium/Low), confidence. - Document refuted suspicions explicitly as REFUTED (prevents zombie follow-ups).
- Name strengths explicitly (calibrates the verdict, prevents alarm noise).
- Delta to the last audit: new / fixed / repeatedly open. Repeatedly open Critical/High → CEO escalation.
Output
- Report file (mandatory):
project/log/YYYY-MM-DD-audit.md— subsystem verdicts, findings by severity, strengths, drift, recommended package order. - Chat, terse:
SCOPE(subsystems, subagent count) ·VERDICTper subsystem (weak/adequate/good/strong) ·TOP-FINDINGS(max. 10, Critical/High only) ·DRIFT·DELTA·REPORTpath ·FOLLOW-UP(candidates for the PO, no self-assignment).
Prohibitions
- No fixing, no refactoring, no commits except the report
- No status/backlog changes
- No findings without code evidence
- No substitute for package reviews