Pipeline auditor protocol
Skill gustavo-meilus/superpipelines/plugins/superpipelines/skills/pipeline-auditor-protocol
Loaded by the pipeline-auditor agent to audit Superpipelines pipeline bundles against compliance, CAD, topology, and bundle hygiene rules.From its SKILL.md
npx -y skills add gustavo-meilus/superpipelines --skill pipeline-auditor-protocolAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 5 stars5 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
6.6 KB, ~1.6k tokens by cl100k_base, as published. Nobody here has run it
Pipeline Auditor — Operational Protocol
<glossary> <term name="Compliance Matrix">The full checklist in `compliance-matrix.md` covering layout, frontmatter, topology, runtime safety (criteria 1–25), and resolver consolidation (PR-01..PR-05, PR-07..PR-10).</term> <term name="Severity Bands">Classification levels from SEV-0 (Critical/Blocking) to SEV-3 (Informational/Style).</term> <term name="Audit Report">A generated Markdown document summarizing findings with quoted evidence and remediation paths.</term> </glossary> <invariant> The Auditor is strictly read-only; it cannot modify files. Remediation must be routed to the `pipeline-architect`. </invariant>Operating Modes
<operating_modes>
| Mode | Trigger | Scope |
|---|---|---|
| FULL | Direct invocation or first audit. | Entire pipeline bundle: all agents, skills, and topology. |
| DELTA | Triggered by mutation commands. | Changed files plus immediate neighbors and the entry skill. |
| SCOPE-WIDE | audit-steps --all command. | FULL audit across all registered pipelines in all scope roots. |
| </operating_modes> |
Workflow
<protocol> ### 1. LOCATE - Resolve paths via `sk-pipeline-paths`. - **FULL**: Glob all agents and skills; read `topology.json` and the registry. - **DELTA**: Target only changed files and their graph neighbors. - **SCOPE-WIDE**: Iterate through all scope roots and registered pipelines.2. AUDIT
- Detect layout FIRST: determine whether the bundle is data-only (CAD agents +
entry.mdunder.superpipelines/pipelines/{P}/) or legacy old-root (zero-body agents +run-{P}skill under tool dirs), perreferences/compliance-matrix.md§ "Pipeline layout & criterion applicability". Apply criteria by layout: legacy layout/frontmatter/Lean-Agent criteria (1, 4, 5, 8, 9, 10, 10a, 19) are N/A on data-only — CAD-01..CAD-10 govern there instead. Never FAIL a conformant CAD against a legacy-only criterion. - Compliance Matrix: Execute the full compliance check in
references/compliance-matrix.md(criteria 1-25 including 10a, resolver consolidation criteria PR-01..PR-05 and PR-07..PR-10, canonical agent-def criteria CAD-01..CAD-10, and bundle-maintenance criteria BUNDLE-01..BUNDLE-07 when auditing the Superpipelines bundle), honoring the layout applicability table. - Topology Rules: Verify graph validity, agent coverage, and edge consistency via
references/topology-rules.md. - Assign severity per
references/severity-classification.mdand select fixes fromreferences/fix-templates.md.
3. REPORT
- The auditor is read-only (
disallowedTools: Write, Edit, Bash) and NEVER writes the report file or mutatesregistry.json. Persistence is the orchestrator's responsibility (seecommands/audit-steps.mdREPORTING). - Render the full report per
references/audit-report-template.mdas inline output in the agent's response, together with the executive summary. - Hand the orchestrator an explicit registry-update instruction: the target
audit/latest.mdpath and thelast_audittimestamp value to record. - Record every audit, even those with zero findings.
4. FIX ROUTING
- Auditor remains read-only.
- SEV-0/1: Route to
pipeline-architectwith the remediation plan. - SEV-2/3: Surface to the user for manual decision.
Model-Tier Resolution Criteria (v2.0)
| ID | Criterion | SEV | Detection |
|---|---|---|---|
| MT-01 | Hardcoded model ID in skill body | SEV-2 | grep -E "claude-(sonnet|opus|haiku)-[0-9]|gpt-5\.[0-9]|gemini-3\." skills/**/SKILL.md skills/**/references/*.md returns matches outside skills/sk-platform-dispatch/profiles/ |
| MT-02 | Agent missing both model_tier: and model: | SEV-1 | Agent frontmatter has neither field. Runtime resolver tolerates (defaults to fast) but scaffold-time auditor blocks: explicit declaration required for v2.0+ agents. |
| MT-03 | Agent has explicit model: without comment justification | SEV-3 | Escape hatch in use. Surface to reviewer; do not block. Distinguish by plugin_version: if absent or < 2.0.0 → v1 legacy (Phase 0.45 migrates automatically); if >= 2.0.0 → intentional v2 escape hatch (advisory only). |
| MT-04 | Profile JSON missing model_tiers_version field | SEV-2 | Required for drift detection. |
| MT-05 | Preference file references a model not in any profile's catalog | SEV-2 | Compare every prefs.platforms[*].tiers[*] value against the union of all profiles' model_tiers[*].model. Mismatch likely typo or stale ID. |
| MT-06 | Agent has effort_tier: set on a platform with effort_field_name == null | SEV-3 | Effort will be silently ignored on this platform — inform user. Detection requires knowing the source/runtime tier. |
Resolution
- MT-01: Move the hardcoded ID to a profile JSON; reference via
platform_profile.model_tiers[tier]. - MT-02: Add
model_tier:to the agent (architect should have done this in Phase 4). - MT-03: Add a comment line above
model:documenting WHY the escape hatch is needed. - MT-04: Add
"model_tiers_version": "YYYY-MM-DD"to the profile. - MT-05: Run
/superpipelines:change-modelsMode F (catalog refresh) to reconcile. - MT-06: Either drop
effort_tier:or accept that it's a no-op on this platform. </protocol>
Reference Files
${CLAUDE_PLUGIN_ROOT}/skills/pipeline-auditor-references/references/compliance-matrix.md${CLAUDE_PLUGIN_ROOT}/skills/pipeline-auditor-references/references/canonical-agent-def.md${CLAUDE_PLUGIN_ROOT}/skills/pipeline-auditor-references/references/topology-rules.md${CLAUDE_PLUGIN_ROOT}/skills/pipeline-auditor-references/references/severity-classification.md${CLAUDE_PLUGIN_ROOT}/skills/pipeline-auditor-references/references/audit-report-template.md${CLAUDE_PLUGIN_ROOT}/skills/pipeline-auditor-references/references/fix-templates.md
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.
Gives 1 of the 12 instructions most audit compliance skills give in ~1.6k tokens
Counted across 937 of the 1,487 authors here whose files we hold, read 2026-08-07
- Fetch latest guidelines before each reviewin 43 of 937, across 3 files
- Group findings by severityin 43 of 937
- Check files against all fetched rulesin 42 of 937, across 2 files
- Output findings in terse file:line formatin 41 of 937, across 3 files
- Ask user which files to review if none specifiedin 41 of 937, across 3 files
- Read specified files or prompt user for filesin 39 of 937, across 1 file
- Generate the audit reportin 33 of 937, across 30 files
- Assign a severity to every findinghere, and in 25 of 937
- Run automated accessibility scansin 23 of 937, across 13 files
- Output a markdown audit reportin 22 of 937
- Map findings to WCAG criteriain 20 of 937, across 10 files
- Confirm audit scopein 19 of 937, across 9 files
Said here and by no other author read
- resolve file paths via the pipeline paths command
- detect data-only versus legacy-old-root layout first
- execute the full compliance matrix checks
- verify graph validity, agent coverage, and edge consistency
- render the full audit report as inline output
- record every audit even with zero findings
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.