jstack-auditlisted
Install: claude install-skill JarodFroneman/jstack
# JStack Audit
When an active JStack loop requests audit evidence, remain read-only and return
only the audit result and receipt. Never adopt the loop's editing role or
declare the native goal complete.
Audit the declared subject without changing application code, configuration,
Git state, installed tools, or production. Treat the MCP as a deterministic
evidence and validation layer; semantic code review remains the Audit Lead's
reasoned work.
The only write exception is a requested mastery assessment: Stage 0 may create
its four declared artifacts, Stage 1 may create its three declared mapping
artifacts, Stage 2 may create its report, invariant narrative, and
reproduction manifest, and Stage 3 may create its threat-model narrative,
security-findings report, and abuse-case narrative. Stage 4 may create its
architecture map, maintainability report, and migration outline under
`.jstack-training/`. Those exceptions are not
remediation authority and grant no application, configuration, Git, network,
secret, publication, release, deployment, or production authority. Stage 2
may reference a separately issued current `jstack_qa` receipt; it never grants
arbitrary execution or treats JStack QA as a sandbox. Stage 4 implementation
evidence may reference a separately authorized and committed candidate plus a
current QA receipt; Audit does not create that candidate.
## Start
1. Parse `[SCOPE]` and the options `--profile`, `--focus`, `--base`,
`--fail-on`, `--format`, `--verify`,