Files
holocron/plugins/core/skills/agentsmd-audit/SKILL.md
Defame1297 6c8ea8e8f0 feat(core): add agentsmd-audit skill files
The previous commit only landed the research-folder rename — a multi-path
git add silently failed and left CONTEXT.md, ADR-0012, and the actual skill
files unstaged. This lands them: the agentsmd-audit skill itself (three
deterministic validators for secrets, structure, and drift against a target
repo's AGENTS.md), its bats test suite, provenance record, and the
CONTEXT.md/ADR entries documenting why this lives in core rather than
kyberforge.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 17:08:19 +00:00

3.5 KiB

name, description, allowed-tools, metadata
name description allowed-tools metadata
agentsmd-audit Use when the user wants to review a repo's AGENTS.md file, says "audit this AGENTS.md", "check my AGENTS.md", "is this AGENTS.md any good", or wants to know if AGENTS.md is safe to commit — even if they don't use the word "audit". Also invoke proactively after agentsmd-author creates or updates AGENTS.md, or after a hand-edit made outside agentsmd-author. Audits a target repo's AGENTS.md file(s) — root and any nested monorepo files — for embedded secrets/credentials, structural completeness against the agents.md common-sections checklist, and drift (referenced commands or paths that no longer resolve against the repo). Produces a compact findings report (findings only, no PASS noise) with Why and Fix per finding. Do not use to audit CLAUDE.md, .cursor/rules, or other provider-specific adapter files — that's provider-adapter-author's self-contained concern. Do not use to fix or write AGENTS.md content — use agentsmd-author instead. Bash Read
category source_keys version
docs
agents-md-official
context7-websites-agents-md
context7-agentsmd-agents-md
governance-secrets-hard-prohibition
0.1.0

Gotchas

  • Always run all three checks — this skill does a single combined pass, not staged/gated passes. Don't skip structure or drift checks just because a secrets FAIL was found.
  • Never inspect or mention provider-specific adapter files (CLAUDE.md, .cursor/rules/*.mdc, copilot-instructions.md, etc.) — that's out of scope. If one exists and duplicates AGENTS.md content, that's provider-adapter-author's concern, not this skill's.
  • A missing common section (e.g. no "Security" heading) is informational, not a failure — not every repo needs every section from the checklist. Only flag a FAIL when the file is empty, entirely unfilled placeholder text, or contains a real embedded secret/stale reference.
  • Gather findings internally; don't narrate PASS/FAIL per check as you go — surface them only in the final report.

Step 1 — Run the validators

bash scripts/validate-secrets.sh <repo-root>
bash scripts/validate-structure.sh <repo-root>
bash scripts/validate-drift.sh <repo-root>

Each script walks the repo for every AGENTS.md file (root and nested, excluding .git, node_modules, vendor, and similar) and prints FAIL/INFO/SUGGESTION lines with Why/Fix (or Note) per finding. A nonzero exit means at least one FAIL was found in that dimension. If a script cannot execute (python3 unavailable, Bash denied), fall back to manual review: scan for real-looking credentials, check common sections are present, and spot-check a few referenced commands/paths by hand.

Step 2 — Report

Open with a coverage line:

Checked: secrets · structure · drift

Then output only findings that were found, in this order within a repo: ### Secrets, ### Structure, ### Drift. Omit a dimension heading entirely if it produced nothing — its absence confirms it passed. Report each finding verbatim as emitted by the scripts (they already carry file:line, Why/Fix or Note).

Close with a result block:

## Result

PASS
PASS · P info
PASS (N suggestions) · P info
FAIL (N fails)
FAIL (N fails) · P info

INFO and SUGGESTION findings are observational — they never flip PASS to FAIL. Do not fix anything — this skill reports and proposes only. Point the user to agentsmd-author to apply fixes.