--- name: agentsmd-audit description: > Use when the user wants a repo's AGENTS.md audited for secrets, structure and drift — "is this AGENTS.md safe to commit" — or after a hand-edit outside `agentsmd-author`. Not converting a provider file -> `provider-adapter-author`. Not writing AGENTS.md -> `agentsmd-author`. allowed-tools: Bash Read metadata: category: docs source_keys: - agents-md-official - context7-websites-agents-md - context7-agentsmd-agents-md - governance-secrets-hard-prohibition version: "0.1.4" --- ## Gotchas - Always run all three checks — this skill does a single combined pass, not staged/gated passes. Don't skip structure or drift checks just because a secrets FAIL was found. - Never inspect or mention provider-specific adapter files (`CLAUDE.md`, `.cursor/rules/*.mdc`, `copilot-instructions.md`, etc.) — that's out of scope. - Gather findings internally; don't narrate PASS/FAIL per check as you go — surface them only in the final report. ## Step 1 — Run the validators ```bash bash scripts/validate-secrets.sh bash scripts/validate-structure.sh bash scripts/validate-drift.sh ``` Each script walks the repo for every `AGENTS.md` file (root and nested, excluding `.git`, `node_modules`, `vendor`, and similar) and prints `FAIL` lines, plus `INFO`/`SUGGESTION` where applicable, with `Why`/`Fix` (or `Note`) per finding. A nonzero exit means at least one FAIL was found in that dimension. If a script cannot execute (`python3` unavailable, Bash denied), fall back to manual review: scan for real-looking credentials, check common sections are present, and spot-check a few referenced commands/paths by hand. Grade a manual finding the way the scripts grade theirs: a missing common section (e.g. no "Security" heading) is informational, not a failure — not every repo needs every section from the checklist. Only flag a FAIL when the file is empty, entirely unfilled placeholder text, or contains a real embedded secret/stale reference. ## Step 2 — Report Open with a coverage line: ```text Checked: secrets · structure · drift ``` Then output only findings that were found, in this order within a repo: `### Secrets`, `### Structure`, `### Drift`. Omit a dimension heading entirely if it produced nothing — its absence confirms it passed. Report each finding verbatim as emitted by the scripts (they already carry file:line, Why/Fix or Note). Close with a `## Result` block holding one line: `PASS`, `PASS (N suggestions)`, or `FAIL (N fails · M suggestions)`, each optionally followed by ` · P info`. Omit the suggestion count when there are none, and omit `· P info` when there are none. INFO and SUGGESTION findings are observational — they never flip PASS to FAIL. Do not fix anything — this skill reports and proposes only. Point the user to `agentsmd-author` to apply fixes.