Self audit
Skill richfrem/agent-plugins-skills/plugins/agent-scaffolders/skills/self-audit
Trigger with "run self-audit", "test the analyzer", "regression test the plugin analyzer", "audit the agent-scaffolders", or "verify the analyzer works correctly". Runs the analyze-plugin skill against the agent-scaffolders itself and its test fixtures as a regression smoke test. Use this after making changes to the analyzer to verify nothing broke.From its SKILL.md
npx -y skills add richfrem/agent-plugins-skills --skill self-auditAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 4 stars4 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
3.2 KB, 661 tokens by cl100k_base, as published. Nobody here has run it
Dependencies
This skill requires Python 3.8+ and standard library only. No external packages needed.
To install this skill's dependencies:
pip-compile ./requirements.in
pip install -r ./requirements.txt
See ./requirements.txt for the dependency lockfile (currently empty — standard library only).
Self-Audit: Analyze the Analyzer
Run the analyze-plugin skill against the agent-scaffolders itself and the test fixtures. This is a regression smoke test that verifies the analyzer produces consistent, expected results.
Execution Steps
-
Run inventory on self (security scanning is on by default):
python ./scripts/inventory_plugin.py --path . --format json -
Run scanner against test fixtures:
python ./scripts/inventory_plugin.py --path ./tests/gold-standard-plugin --format json python ./scripts/inventory_plugin.py --path ./tests/flawed-plugin --format json -
Validate deterministic scanner results:
Self-analysis scanner must confirm:
security_flags= [] (zero security findings in the analyzer itself)issues= [] (zero structural violations)
Gold-standard fixture scanner must confirm:
security_flags= [] (zero security findings)issues= [] (zero structural violations)warnings= [] (zero missing components)
Flawed fixture scanner must confirm:
security_flagscount ≥ 4 (network calls + env access; obfuscated credential is LLM-only)issuescount ≥ 1 (bash script violation)warningscount ≥ 2 (missing acceptance criteria + references)- See
./README.mdfor the full expected findings manifest
To run assertions programmatically:
python ./scripts/assert_audit.py --fixture flawed --json-output <path-to-scan-output.json> -
Run the full 6-phase analysis on each fixture:
tests/gold-standard-plugin/— should score maturity ≥ L2, zero Critical, at least 2 patterns identifiedtests/flawed-plugin/— LLM must additionally detect: missing README file tree, missing plugin manifest
-
Validate self-analysis (full 6-phase on the analyzer itself):
- Maturity Level ≥ L3
- Security score ≥ 4/5
- Structure score ≥ 4/5
- Pattern catalog governance model present with lifecycle states
-
Report deviations:
⚠️ SELF-AUDIT REGRESSION: [dimension] expected [X] got [Y] ✅ SELF-AUDIT PASSED: [N] scanner checks passed, [M] fixtures validated, [K] 6-phase checks passed
When to Run
- After any modification to the analyzer's own files
- Before creating a bundle for external review
- Before pattern catalog updates (to verify governance compliance)
What ships with it: 7 files
1.8 KB alongside SKILL.md, 2 of them executable
evals/
- evals.json1.1 KB
- .lock.hashes395 B
- results.tsv191 B
scripts/
- assert_audit.pyruns32 B
- inventory_plugin.pyruns36 B
- README.md35 B
- requirements.txt22 B