Files
holocron/plugins/core/.apm/skills/agentsmd-audit/SKILL.md
Defame1297 f0526b310d refactor(core): retrofit agentsmd-audit to the ADR-0020 context contract
Description 944 -> 322 chars, Gotchas 36% -> 22%. The composition note
moves to README.md.

Restores the hand-edit trigger, which a clean-context audit found had no
other caller: agentsmd-author owns the post-authoring invocation, but a
hand-edit has no author skill in the loop, so nothing invoked the audit
at all. It survived only in README.md, which neither the router nor the
invoked agent loads. That is the path on which a human pastes a
credential into AGENTS.md.

The first pass dropped it against a measured budget of '~9 spare chars'.
The real cost was ~49, and 250 is the SUGGESTION tier, not a ceiling --
the gate fails at 400. Ships at 322 with one advisory line.

Names the three audit dimensions in the capability clause, recovering
routing for 'does my AGENTS.md leak credentials', and qualifies the
'is this AGENTS.md safe to commit' phrasing, whose pronoun had no
antecedent inside the quoted string.

Refs #99
2026-08-30 15:06:49 +00:00

2.8 KiB

name, description, allowed-tools, metadata
name description allowed-tools metadata
agentsmd-audit Use when the user wants a repo's AGENTS.md audited — "audit this AGENTS.md", "is this AGENTS.md safe to commit" — or after a hand-edit outside `agentsmd-author`. Reports secrets, structure and drift; never edits. Not for CLAUDE.md or provider files -> `provider-adapter-author`. Not writing AGENTS.md -> `agentsmd-author`. Bash Read
category source_keys version
docs
agents-md-official
context7-websites-agents-md
context7-agentsmd-agents-md
governance-secrets-hard-prohibition
0.1.2

Gotchas

  • Always run all three checks — this skill does a single combined pass, not staged/gated passes. Don't skip structure or drift checks just because a secrets FAIL was found.
  • Never inspect or mention provider-specific adapter files (CLAUDE.md, .cursor/rules/*.mdc, copilot-instructions.md, etc.) — that's out of scope.
  • Gather findings internally; don't narrate PASS/FAIL per check as you go — surface them only in the final report.

Step 1 — Run the validators

bash scripts/validate-secrets.sh <repo-root>
bash scripts/validate-structure.sh <repo-root>
bash scripts/validate-drift.sh <repo-root>

Each script walks the repo for every AGENTS.md file (root and nested, excluding .git, node_modules, vendor, and similar) and prints FAIL/INFO/SUGGESTION lines with Why/Fix (or Note) per finding. A nonzero exit means at least one FAIL was found in that dimension. If a script cannot execute (python3 unavailable, Bash denied), fall back to manual review: scan for real-looking credentials, check common sections are present, and spot-check a few referenced commands/paths by hand. Grade a manual finding the way the scripts grade theirs: a missing common section (e.g. no "Security" heading) is informational, not a failure — not every repo needs every section from the checklist. Only flag a FAIL when the file is empty, entirely unfilled placeholder text, or contains a real embedded secret/stale reference.

Step 2 — Report

Open with a coverage line:

Checked: secrets · structure · drift

Then output only findings that were found, in this order within a repo: ### Secrets, ### Structure, ### Drift. Omit a dimension heading entirely if it produced nothing — its absence confirms it passed. Report each finding verbatim as emitted by the scripts (they already carry file:line, Why/Fix or Note).

Close with a result block:

## Result

PASS
PASS · P info
PASS (N suggestions) · P info
FAIL (N fails)
FAIL (N fails) · P info

INFO and SUGGESTION findings are observational — they never flip PASS to FAIL. Do not fix anything — this skill reports and proposes only. Point the user to agentsmd-author to apply fixes.