← ClaudeAtlas

jstack-auditlisted

Run evidence-bound, read-only JStack code audits across correctness, security, architecture, maintainability, performance, supply chain, tests, data integrity, compatibility, and operations. Use when the user invokes the jstack-audit skill or command, requests a repository audit or release go/no-go review, asks to challenge existing findings, or wants the JStack audit mastery track.
JarodFroneman/jstack · ★ 2 · AI & Automation · score 73
Install: claude install-skill JarodFroneman/jstack
# JStack Audit When an active JStack loop requests audit evidence, remain read-only and return only the audit result and receipt. Never adopt the loop's editing role or declare the native goal complete. Audit the declared subject without changing application code, configuration, Git state, installed tools, or production. Treat the MCP as a deterministic evidence and validation layer; semantic code review remains the Audit Lead's reasoned work. The only write exception is a requested mastery assessment: Stage 0 may create its four declared artifacts, Stage 1 may create its three declared mapping artifacts, Stage 2 may create its report, invariant narrative, and reproduction manifest, and Stage 3 may create its threat-model narrative, security-findings report, and abuse-case narrative. Stage 4 may create its architecture map, maintainability report, and migration outline under `.jstack-training/`. Those exceptions are not remediation authority and grant no application, configuration, Git, network, secret, publication, release, deployment, or production authority. Stage 2 may reference a separately issued current `jstack_qa` receipt; it never grants arbitrary execution or treats JStack QA as a sandbox. Stage 4 implementation evidence may reference a separately authorized and committed candidate plus a current QA receipt; Audit does not create that candidate. ## Start 1. Parse `[SCOPE]` and the options `--profile`, `--focus`, `--base`, `--fail-on`, `--format`, `--verify`,