← ClaudeAtlas

godauditslisted

Audit a codebase end to end and emit validated JSON plus remediation MDX, or review one diff for non-obvious blast radius with explicit safety facts and a compiled merge proof gate. godaudits fingerprints the repository, detects six project forms, validates Pillars 1.1 and arc-ready artifacts, evaluates 437 checks across 18 domains with pass/fail/unknown/not-applicable outcomes, records hashed secret-safe evidence, covers OWASP Web Top 10:2025, adversarially refutes findings, computes scores with coverage and risk caps, and renders optional SARIF. Includes focused, full, re-audit, plan-aware, and change-safety modes. Static mode never runs the app, tests, live systems, network, or models. Use for audits, health checks, due diligence, production readiness, remediation, blast-radius reviews, and pre-merge safety. Refuses stale evidence, invented citations, secrets, unsupported regulatory claims, double-billing, unproven merge safety, and Critical or High findings without executable tasks.
hannsxpeter/godaudits · ★ 4 · Code & Development · score 78
Install: claude install-skill hannsxpeter/godaudits
> Invocation: `/godaudits` in Claude Code, Cursor, VS Code, Zed, and Factory; `$godaudits` in Codex; `@godaudits` in Windsurf; auto-triggered elsewhere. Treat text after the command as a path, focus, or constraint. The runtime lives beside this file at `runtime/godaudits.js`; use the installed `godaudits` command when available, otherwise run that file with Node 22 or newer. # godaudits Audit everything after anything. godaudits 2.18 is an evidence-first audit system, not only an audit prompt. The domain modules carry judgment. The bundled zero-dependency runtime carries inventory, form and overlay detection, Pillars 1.1 routing, arc-ready artifact validation, check-catalog compilation, state initialization, freshness validation, score computation, rendering, SARIF export, re-audit diffs, remediation wayfinding, and evaluation metrics. The machine source of truth is `.godaudits/AUDIT.json`. It records every applicable check, including clean and unknown checks. `.godaudits/AUDIT.mdx` is a generated standalone report and remediation handoff. `.godaudits/AUDIT.sarif` is optional integration output. Never hand-edit derived scores or counts. godaudits remains the mirror of godplans. Audit check `A-SEC-3` verifies plan requirement `R-SEC-3`. In plan-aware mode, findings carry both ids and plan drift is audited in the owning domain. ## Ground rules (non-negotiable) 1. **Static is the safe default.** Static mode reads source and git metadata, writes only under `.godaudits/`, an