Agent skill

Universal Audit

by aiskillstore in aiskillstore/marketplace

Audit software releases with unforgiving standards. An agent skill from aiskillstore/marketplace.

MITAuto-check passed

Install Universal Audit

skills CLI
$ npx skills add aiskillstore/marketplace --skill universal-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace universal-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/glenskii/universal-audit .claude/skills/universal-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
universal-audit
GitHub stars
430
Token cost
~1.9k tokens
SKILL.md length
930 words
Files
21 (incl. scripts, references, assets)
Skills in repo
1,108
Repo updated
First seen
Licence
MIT

At a glance

Audit software releases with unforgiving standards. An agent skill from aiskillstore/marketplace.

  • Works in 7 steps: Engagement Setup (blocking) → Control Selection → Evidence Collection → …
  • Incomplete scope could create deployment risk
  • SKILL.md covers Phase 0 - Engagement Setup…, Phase 1 - Control Selection, Phase 2 - Evidence Collection and Phase 3 - Findings and Status, plus 5 more sections
  • Calls python

What it does

Universal Audit is an agent skill from aiskillstore/marketplace. Audit software releases with unforgiving standards. Use when soft approvals or incomplete scope could create deployment risk. Execute a full-lifecycle audit across fifteen core domains, including security, architecture, UX, and privacy. Apply deterministic scoring, evaluate hard evidence, and enforce release gates with hard-stop rules regardless of the overall score.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 26 other files, including scripts, reference files and assets (for example `agents/openai.yaml`, `assets/audit-manifest-template.json` and `docs/evidence-ledger-guide.md`).

The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified. The licence is MIT.

When your agent uses it

  • Incomplete scope could create deployment risk

Example prompts

  • “/universal-audit”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Engagement Setup (blocking)
  2. Control Selection
  3. Evidence Collection
  4. Findings and Status
  5. Scoring and Verdict
  6. Independent Challenge
  7. Report and Release

What it can do on your machine

Read from SKILL.md and the folder at commit ad8daf7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Universal Audit loads about 1.9k tokens when it runs, and up to ~9.2k if it reads all its reference files. Until then it costs about 96 tokens; SKILL.md has 930 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from aiskillstore/marketplace at commit ad8daf7, republished under its MIT licence (© aiskillstore). 930 words, ~1,928 tokens.

Download SKILL.mdSave it as .claude/skills/universal-audit/SKILL.md (or your agent's skills folder). This skill also uses 20 other files; get the full folder from GitHub.
name
universal-audit
description
Audit software releases with unforgiving standards. Use when soft approvals or incomplete scope could create deployment risk. Execute a full-lifecycle audit across fifteen core domains, including security, architecture, UX, and privacy. Apply deterministic scoring, evaluate hard evidence, and enforce release gates with hard-stop rules regardless of the overall score.
license
MIT
metadata.version
1.0.3

Universal Audit - Formal Production Assurance

This skill executes the Universal Software Engineering Audit Specification v2.2 (bundled at spec/Universal_Software_Engineering_Audit_Specification.md). The spec is normative. This file is the execution procedure. When they conflict, the spec wins.

Core discipline, non-negotiable:

  • Every conclusion traces to evidence. PASS requires affirmative evidence, never scanner silence.
  • Insufficient evidence is UNVERIFIED, stated plainly, with what would verify it.
  • Never invent defects, never soften verified risk, never pad findings to look thorough.
  • The numeric score never overrides release gates.

Phase 0 - Engagement Setup (blocking)

  1. Confirm the target: repo path, running URL, or both. Read package.json / requirements.txt / wrangler.toml / equivalent before anything else.
  2. Fill the intake from references/templates/intake-template.md. Ask the operator only for items you cannot establish yourself. Missing inputs go to Audit Limitations, never silently assumed.
  3. Declare: audit type, depth tier (rapid / standard / deep), environment, access level, assurance objective, and risk profile (P1–P6, see references/depth-and-profiles.md). If the operator did not specify depth, propose one with rationale and wait.
  4. Assign the audit ID: AUD-[PRODUCT]-[YYYYMMDD]-[SEQ].
  5. Rules of Engagement: this skill defaults to passive, read-only inspection. No load tests, no destructive actions, no auth bypass attempts, no tests against systems the operator does not own. Active testing requires the RoE template completed and explicit operator authorization recorded in the manifest.
  6. Gate controls: evaluate GOV-SCOPE-001 and GOV-ROE-001 first. If either cannot PASS, the engagement is advisory only - say so now, not in the report.
  7. Create the artifact directory: audits/<audit-id>/ in the project root (or an operator-specified location). Run scripts/init_audit_artifacts.py --audit-id <audit-id> --output audits/<audit-id> to create the initial manifest from assets/audit-manifest-template.json. It refuses to overwrite an existing directory.

Phase 1 - Control Selection

  1. Load the catalog: spec Appendix A. Select every control at or below the declared tier (Rapid = R; Standard = R+S; Deep = R+S+D). Profile-critical controls are mandatory regardless of tier.
  2. Mark NOT APPLICABLE controls with recorded justification. NA without justification is invalid.
  3. Assign each selected control its scoring category from spec A.0. A control without a category is a validation failure.
  4. Write selected-controls.json (schema in references/schemas/). This freezes the coverage denominator before any evidence is gathered - selection cannot be trimmed later to inflate coverage.

Phase 2 - Evidence Collection

Work the spec Section 12 order. For each selected control, gather the minimum PASS evidence listed in the catalog or stronger. Practical guidance per family is in references/control-procedures.md. Read references/release-evidence-catalog.md when choosing evidence for a release gate. Read docs/evidence-ledger-guide.md before recording evidence for the first time.

  • Record every material observation in evidence-ledger.json: ID, class, timestamp, location (file:line, endpoint, config key), method, sanitized excerpt, limitations.
  • Repository unavailable: source-dependent claims are UNVERIFIED - Runtime inference only.
  • Tool output (linters, SCA, scanners) is evidence to assess, not a verdict. Validate before accepting severity.
  • Sanitize as you go: no secrets, tokens, personal data, or working exploit payloads in the ledger.
  • For large targets, fan evidence collection out to subagents by control family, one ledger merged afterward. Deduplicate observations across families before Phase 3.

Phase 3 - Findings and Status

  1. Assign each selected control exactly one status: PASS / FAIL / WARN / NOTE / UNVERIFIED / NOT APPLICABLE.
  2. Every FAIL and WARN becomes a finding using the twenty-field standard (spec Section 9), written to findings.json. Severity is impact, likelihood is separate, confidence is separate. Low-confidence concerns normally stay UNVERIFIED.
  3. Consolidate duplicates around root causes. Apply the systemic-risk rule (spec 13.5) only when all four conditions hold.
  4. WARN may not carry Critical severity. A WARN - High on a C3 control must survive the Phase 5 challenge or be reclassified FAIL - High.
Show full SKILL.md (352 more words)Show less

Phase 4 - Scoring and Verdict

  1. Run scripts/score.py:

    python scripts/score.py audits/<audit-id>/selected-controls.json \
        --profile P4 --tier standard --out audits/<audit-id>/score-sheet.json

It computes per-category provisional scores, applies the mandatory caps, computes tier-relative coverage (and the Standard-denominator figure for Rapid audits), validates category mapping, and evaluates the release gates. Do not hand-calculate scores; the script is the single source of arithmetic. 2. Select exactly one verdict - APPROVED / APPROVED WITH CONDITIONS / REQUIRES REWORK / DO NOT SHIP - from the script's gate evaluation plus the qualitative gates the script cannot check (critical-workflow verification, interim-control ownership). Justify the verdict against the gates line by line.

Phase 5 - Independent Challenge

Standard tier: run a separate contradiction pass - a fresh subagent that did not author the findings attempts to refute every Critical/High finding, every release-significant Medium/WARN, and every C3 PASS supporting approval, and recalculates the score sheet. Deep tier: the challenge must be a genuinely independent agent or human review.

Record each challenge outcome: UPHELD / MODIFIED / REJECTED / NEEDS MORE EVIDENCE, with rationale, in verification-log.json. Resolve differences transparently.

Phase 6 - Report and Release

  1. Render report.md from references/templates/report-template.md. Executive summary is seven sentences maximum.
  2. Confirm the twelve-point quality gate (spec 19.2). Any failure means the report is not ready - fix it, do not ship it annotated.
  3. Final artifact set in audits/<audit-id>/: audit-manifest.json, selected-controls.json, evidence-ledger.json, findings.json, score-sheet.json, risk-register.json, verification-log.json, report.md.
  4. Deliver the verdict, the top risks, and the coverage figures in the final message. Plain language, no alarmism, no softening.

Re-Audit Mode

If the operator supplies a prior audit ID or report, run spec Section 16 instead of a fresh Phase 1–3: verify each prior FAIL/WARN against its original reproduction, classify (OPEN / PARTIALLY REMEDIATED / REMEDIATED / ACCEPTED / REGRESSED / NOT REPRODUCIBLE), re-run all applicable C3 controls, recalculate from current evidence, and produce the delta table. Never carry a PASS forward without confirming its evidence still holds.

Scope Control

  • A time box changes coverage, not truth standards. Out of time: remaining controls are UNVERIFIED and reported as such.
  • Never present a limited audit as full production assurance.
  • Stop immediately if authorization is exceeded, a test risks material harm, or the audited version cannot be established.

© aiskillstore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 20 other files (scripts, references, assets) in skills/glenskii/universal-audit of aiskillstore/marketplace.

  • SKILL.md
  • LICENSE
  • agents/openai.yaml
  • assets/audit-manifest-template.json
  • docs/evidence-ledger-guide.md
  • references/control-procedures.md
  • references/depth-and-profiles.md
  • references/release-evidence-catalog.md
  • references/schemas/audit-manifest.schema.json
  • references/schemas/evidence.schema.json
  • references/schemas/finding.schema.json
  • references/schemas/selected-controls.schema.json
  • references/templates/intake-template.md
  • references/templates/report-template.md
  • references/templates/roe-template.md
  • … and 6 more

Open the folder on GitHubat commit ad8daf7

Compare with similar skills

Universal Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Universal Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Universal Audit this skillaiskillstore/marketplace430—~1.9kAutomated safety check: PassMIT
Releasepaperclipai/paperclip99k—~2.4kAutomated safety check: PassMIT
Universal Project Release WorkflowJimLiu/baoyu-skills26k—~4.9kAutomated safety check: PassMIT
Openclaw Release Validationopenclaw/openclaw392k—~987Automated safety check: PassMIT
Release Generate Release Notesmountain-loop/yaak19k—~548Automated safety check: PassMIT
Verify Releaseopenclaw/openclaw392k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Release

    paperclipai/paperclip

    Coordinate a full Paperclip release across engineering verification, npm, GitHub, smoke testing, and announcement follow-up.

    99k GitHub stars~2.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Detects a project's version file and changelog format, then runs a release: bumping the version, writing release notes and creating GitHub releases, including backfill.

    26k GitHub stars~4.9k tokensUpdated 28 days ago
    DevelopmentAuto-check passed
  • Guide human release testing on an isolated OCM copy or approved in-place gateway, collect feedback, or refresh the release campaign.

    392k GitHub stars~987 tokensUpdated today
    Auto-check passed
  • Generate Yaak release notes from git history and PR metadata, including feedback links and full changelog compare links.

    19k GitHub stars~548 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Verify Release

    openclaw/openclaw

    Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release…

    392k GitHub stars~2.4k tokensUpdated today
    Testing & QAAuto-check passed
  • Release

    codewhale-hq/Codewhale

    Prepare a named version: preflight, version consistency, build/package, smoke test, checksums/notes, and release readiness.

    41k GitHub stars~189 tokensUpdated yesterday
    Testing & QAAuto-check passed

More from aiskillstore/marketplace

All 1,108 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    430 GitHub starsUsed in 2 repos~697 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    430 GitHub starsUsed in 2 repos~598 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    430 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    430 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Investigating Codebases

    aiskillstore/marketplace

    Automatically activated when user asks how something works, wants to understand unfamiliar code, needs to explore a new codebase, or asks questions like "where is X implemented?", "how does Y…

    430 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check: notes

Questions about Universal Audit

What does Universal Audit do?

Audit software releases with unforgiving standards. An agent skill from aiskillstore/marketplace. Universal Audit is an agent skill from aiskillstore/marketplace. Audit software releases with unforgiving standards.

When should I use Universal Audit?

Universal Audit fits situations like: incomplete scope could create deployment risk.

How do I install Universal Audit in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill universal-audit -a claude-code`. Or copy the skill folder (skills/glenskii/universal-audit in aiskillstore/marketplace) into .claude/skills/universal-audit in your project. Claude Code loads it when a task matches its description.

How do I install Universal Audit in Codex?

Run `npx skills add aiskillstore/marketplace --skill universal-audit -a codex`. Or copy the skill folder (skills/glenskii/universal-audit in aiskillstore/marketplace) into .agents/skills/universal-audit in your project. Codex loads it when a task matches its description.

Can I use Universal Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill universal-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/universal-audit, .gemini/skills/universal-audit, .github/skills/universal-audit and .opencode/skills/universal-audit in your project.

What does Universal Audit need to run?

Going by SKILL.md and its folder, Universal Audit needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Universal Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Universal Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Universal Audit use?

Universal Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Universal Audit use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.3k tokens, read only when the agent opens those files.

What are the alternatives to Universal Audit?

Skills that share tags, products or a category with Universal Audit: Release (paperclipai/paperclip, 99k stars), Universal Project Release Workflow (JimLiu/baoyu-skills, 26k stars), Openclaw Release Validation (openclaw/openclaw, 392k stars) and Release Generate Release Notes (mountain-loop/yaak, 19k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Universal Audit?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 430 GitHub stars. The repository holds 1,108 skills in this directory. The repository was last updated on October 7, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.