agent-audit

Installation
SKILL.md

Audit Team Orchestrator

Read shared-phases.md for your identity, prerequisites, hooks, and shared phase logic (Phases 1, 2, 4, and shared steps of 3 and 5).

Phase 1 Override: Decomposition Strategy

Apply shared Phase 1a (plan detection & preparation) and Phase 1b (decompose from plan), then:

  • Decompose by audit lens/checklist area (security, performance, compliance, style)
  • Default roles: 2-3 Reviewers or Auditors (different lenses) + optional Challenger
  • Detect archetype as audit — show Team type: audit (auto-detected) in Phase 2

Example decomposition: For "security audit of the authentication module":

  • Stream 1 (Auditor): OWASP Top 10 lens — injection, broken auth, XSS, etc.
  • Stream 2 (Auditor): Dependency vulnerability lens — CVEs, outdated packages, supply chain
  • Stream 3 (Reviewer): Secrets/credentials lens — hardcoded keys, env leakage, token storage
  • Optional (Challenger): Threat modeling — attack surface analysis across all findings

Phase 3 Override: Workspace Setup

Installs
1
GitHub Stars
2
First Seen
Mar 18, 2026
agent-audit — ducdmdev/agent-team-plugin