Interlinked Spec Audit
QuentinCody/interlinked-cli
Keep prose specs and design docs honest against the code using Interlinked's spec-audit system.
Exhaustive, denominator-driven audit of an entire area (codebase, docs, memory, skills, DB, config).
$ npx skills add AlexZio00/sovereign-skills --skill full-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install AlexZio00/sovereign-skills full-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/full-audit .claude/skills/full-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "full-audit" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/full-audit into .claude/skills/full-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "full-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/AlexZio00/sovereign-skills/tree/master/full-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add AlexZio00/sovereign-skills --skill full-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install AlexZio00/sovereign-skills full-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/full-audit .agents/skills/full-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "full-audit" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/full-audit into .agents/skills/full-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "full-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AlexZio00/sovereign-skills --skill full-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install AlexZio00/sovereign-skills full-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/full-audit .cursor/skills/full-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "full-audit" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/full-audit into .cursor/skills/full-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "full-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/AlexZio00/sovereign-skills.git --path full-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add AlexZio00/sovereign-skills --skill full-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install AlexZio00/sovereign-skills full-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/full-audit .gemini/skills/full-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "full-audit" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/full-audit into .gemini/skills/full-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "full-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install AlexZio00/sovereign-skills full-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add AlexZio00/sovereign-skills --skill full-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/full-audit .github/skills/full-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "full-audit" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/full-audit into .github/skills/full-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "full-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AlexZio00/sovereign-skills --skill full-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install AlexZio00/sovereign-skills full-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/full-audit .opencode/skills/full-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "full-audit" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/full-audit into .opencode/skills/full-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "full-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
full-auditExhaustive, denominator-driven audit of an entire area (codebase, docs, memory, skills, DB, config).
Full Audit is an agent skill from AlexZio00/sovereign-skills. Exhaustive, denominator-driven audit of an entire area (codebase, docs, memory, skills, DB, config). Runs a 6-phase pipeline: scope agreement + prior-map diff - deterministic sweep (counts/versions/paths/parsing plus cross-index reconciliation) - parallel read-only content review (citations forced, rule dry-run) - judgment (false-positive/UNCERTAIN triage) - fix-vs-addition split, gated by execution mode (AUDITONLY default = read-only, PROPOSE = list only, APPLYAPPROVED = apply approved items only) - coverage-map…
Its SKILL.md is about 6.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including scripts (for example `.claude-plugin/plugin.json`, `agents/openai.yaml` and `scripts/canaries/README.md`).
It sits in Business, Finance & HR, covering Accounting and bookkeeping, Code review and Citation management. The repository describes itself as: 20 production-grade skills for AI coding agents — setup, scope, discipline, code review, security, session management, governance, ops, and quality audits (eval-leakage… The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c062683. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 11 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythongitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Full Audit loads about 6.4k tokens when it runs. Until then it costs about 224 tokens; SKILL.md has 3,298 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from AlexZio00/sovereign-skills at commit c062683, republished under its MIT licence (© AlexZio00). 3,298 words, ~6,351 tokens.
.claude/skills/full-audit/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.Accuracy of the coverage claim — the word "exhaustive" ships with a method label or it doesn't ship at all. The moment an unreviewed area gets reported as reviewed, this skill has failed its own purpose.
/full-audit [area] · "audit everything" · "exhaustive audit" · "full audit" · "double-check everything"AUDIT_ONLY. These are analysis requests, not execution requests — see Execution Modes below. Advancing to PROPOSE or APPLY_APPROVED in the same invocation requires the user to say so explicitly (e.g. "audit everything and apply the fixes", "전수감사하고 바로 고쳐줘").This skill keeps analysis and execution in separate, explicitly-named modes. A trigger phrase like "audit everything" or "분석해줘" selects a mode — it does not, by itself, authorize any file write.
| Mode | When active | What runs | Writable scope |
|---|---|---|---|
AUDIT_ONLY (default) | Any bare audit/analysis trigger, with no separate execution request | Phase 0-3 (scope, deterministic sweep, content review, judgment) + Phase 5 (coverage map) | None — audited files are read-only. No Edit/Write to any target file, protected or not. Only audit artifacts may be written (scratch scripts, canary staging, coverage map, recall ledger). |
PROPOSE | User asks for fix proposals (after an AUDIT_ONLY pass, or up front) | AUDIT_ONLY output + a listed fix/addition bucket (Phase 4 framing, nothing applied) | None — still read-only, output is a proposal list |
APPLY_APPROVED | User explicitly approves specific items or the fix bucket as a whole ("apply these items", "apply the fix bucket") | Applies only the items the user named as approved | Limited to the approved items. A deny-listed path (rules/CLAUDE.md/settings — see Safety Layers) is reachable only here, only for that one named item, and only by drafting the edit plus an apply script for the user to run themselves — the model has no path to lift the deny (the deny rule lives in the same settings file it protects). |
One-way per pass: AUDIT_ONLY never auto-advances into PROPOSE or APPLY_APPROVED within the same invocation. Advancing needs a new, explicit user statement. This closes the gap where "audit everything" silently walked all the way to Phase 4 fix-bucket execution — including a Protect-Hooks-guarded file changing — without the user ever approving execution, not just analysis.
AUDIT_ONLY unless the request explicitly names PROPOSE/APPLY_APPROVED or explicitly approves specific items up front.git ls-files and git ls-files --others --exclude-standard - a tracked-only list drops uncommitted files, which are the ones most in need of review.Whatever a machine can count, a script counts — never eyeball it:
Cross-index contract sweep (mandatory sub-step — this is the layer most exhaustive audits skip): The layer most easily missed in "exhaustive" audits is "does the index/routing doc match the real files?" — careful reading of individual files alone will never catch this. Sweep deterministically:
Coverage caps intervention value (borrowed from arXiv 2608.04618): before starting Phase 2 content review, count how many items this audit could actually affect (e.g., "N files this rule change would apply to"). That count caps the maximum value of the intervention before you've even seen the results — if only 3 items are in scope, no amount of review sophistication can produce more improvement than those 3 items allow. Computing this cap up front prevents over-investing deep-review time in low-cap areas, and gives a concrete basis for shifting review effort toward higher-cap areas instead.
Canary mixing (a control group for telling "clean" apart from "the reviewer missed it"): when reviewing a code area, stage one known-clean file and one file with a planted defect from this skill's bundled example pool (scripts/canaries/{clean,seeded}/) using python scripts/canary_mix.py select --pool both --n-clean 1 --n-seeded 1 --stage-dir <scratch>/<run>/bundle --out <scratch>/<run>/canary-manifest.json, then mix the staged files into one or two real review bundles. Don't tell the reviewer dispatch that a control exists or which file it is, and don't count canaries in the Phase 1 denominator. The bundled pool ships with only 2 clean / 2 seeded example files — extend or replace it with pairs representative of the actual codebase before treating a recall number as meaningful. Docs/rules areas have no canary pool by default; skip this step there and note "canary not applied (no pool for this area)" on the map.
Structural checks (Phase 1) alone do NOT justify calling something "exhaustive" — exhaustive = structure + content + rule dry-run, three layers. Rules and guards can't be confirmed as actually working just by reading their documentation — only running them against mock input fills in the third layer. The three layers are non-substitutable: structural checks can come back clean while the content is wrong, and the content can be correct while a rule still fails to fire at runtime.
CONFIRMED / FALSE-POSITIVE (reviewed and dismissed, with a refuting citation) / UNCERTAIN (needs inference — keep it, don't discard, to avoid false negatives) / NIT, each with a reasoning note. CONFIRMED at Critical/High needs 2+ of {condition, impact, reproduction} or it gets downgraded to Medium. FALSE-POSITIVE needs the discarded hypothesis + a refuting citation (command output or a line quote) — "no issue" in one line is not acceptable. An empty false-positive list is not a penalty (state "none dismissed" explicitly — this prevents over-suppression).(refutation check: output refutes the finding / output is unrelated and insufficient). If refuted, it moves to the false-positive bucket. "It's missing" claims must be backed by an exhaustive grep across the whole denominator (explicit regex and scope, grep -rn <pattern> <root> — substring matching alone doesn't count). Passing a mock test alone does not count as a refutation (remove the code and re-test instead). The conclusion needs one objective anchor: a rule/linter, an actual execution result, a direct two-point comparison within the reviewed content, or a grep-derived denominator — "it looks like" with no anchor is invalid (inference-requiring cases aren't invalid, they go to UNCERTAIN instead). Anchor-inject the countables: for anything a machine can count, hand reviewers Phase 1's deterministic values as a given anchor up front rather than asking them to re-derive it — this keeps reviewers out of the business of re-counting what a script already settled.file:line) that justifies it. Report any check with no mapped clause as a false-positive source candidate - checks left without a basis are what block legitimate work.Personally re-verify every reviewer report before classifying. Common false-positive patterns to check for:
agents/code-reviewer.md). A flagged area is not promoted to CONFIRMED, but must be listed at least once in the Phase 4 addition bucket so the user sees it. [The 3/5 thresholds are initial estimates, subject to recalibration once operational data accumulates.][{"file": <path>, "verdict": <final bucket>, "summary": <one line>}] JSON and run python scripts/canary_score.py --manifest <canary-manifest.json> --findings <that JSON>. If a clean control file comes back CONFIRMED, mark every CONFIRMED finding from this run as "needs re-verification" on the coverage map — this does not auto-downgrade them. Drop any finding on a canary file from the fix/addition buckets.PROPOSE or APPLY_APPROVED. In AUDIT_ONLY (the default for a bare audit/analysis request), stop after Phase 3 — the coverage map may still list what would land in each bucket, but nothing here executes.PROPOSE; applied only under APPLY_APPROVED, and only for items the user approved (a blanket "apply the fix bucket" covers non-protected paths — a deny-listed path always needs its own explicit approval, see Safety Layers)PROPOSE; executed under APPLY_APPROVED only per-item after explicit approval — never covered by a blanket approvalCreate or update a coverage-map file (same-day re-run = append a pass section):
Area | Method label | Findings/actions — three method labels required: [deterministic] / [LLM judgment] / [close read]Assumption/Parameter | Status | Evidence needed | Materiality (would it flip the verdict?) | Owner. Five status values: externally-anchored (verified by a third party) / author-calibrated-prior (an adjusted assumption) / assertion-only (unsupported claim) / open-proposal (a TODO) / open-question. If one or more rows are assertion-only, open-proposal, or open-question AND materiality is High (flipping it changes the verdict), downgrade the final label to PARTIAL and name the owner who must resolve it (user / follow-up investigation / tooling). If the CONFIRMED conclusion does not depend on any unverified assumption, the Assumption Ledger may be omitted — if omitted, state "Assumption ledger: N/A (reason)" as one line.python scripts/canary_score.py --summary --skill full-audit (recall: k/n (seeded), RECALL_UNMEASURED while n<5) to the map verbatim.| Does | Does NOT |
|---|---|
| [BASH] Deterministic sweep (counts/versions/paths/parsing) | Compute a harness maturity score (a different tool's job) |
| [AGENT] Dispatch parallel content review (read-only) | Grant reviewers edit access |
[EDIT] Apply fix-bucket edits (stale/dead-refs/violations) — only in APPLY_APPROVED mode | Apply any edit while in AUDIT_ONLY or PROPOSE mode; execute addition-bucket changes without per-item approval (propose-only) |
| [WRITE] Record the coverage map | Declare "100% done" while hiding remaining gaps |
| [READ] Read the prior coverage map and diff | Silently include areas the user excluded |
| Risky Action | Reversibility | Applied Layers |
|---|---|---|
| Fix-bucket edit (existing file) | high (git) | L1+L3 (the mode-gate itself is the L3 confirmation — switching to APPLY_APPROVED is the approval) |
| Delete/move a file (addition bucket) | medium | L1+L3 (explicit per-item user approval required) + mode-gate (APPLY_APPROVED only) |
| Editing a protected config/rules path (deny-listed) | medium | L2 (deny — the model cannot edit it directly) + L3 (the user runs the apply script themselves) + mode-gate: reachable only in APPLY_APPROVED, and only for the specific item the user named, by drafting an edit plus an apply script. There is no path for the model to lift the deny. |
Guard-degradation observability: if a Phase 1 checker can't run, don't silently skip it — record ⚠️ check unavailable: [reason] on the coverage map.
AUDIT_ONLY and never auto-advances into Phase 4 execution, and a deny-listed path is never touched outside APPLY_APPROVED with that specific item named. Violation → a request to "look at X" silently becomes a request that changed X, including a Protect-Hooks-guarded file.| Failure | Detection | Recovery |
|---|---|---|
| Checker script execution failure | Script errors out | Rewrite and retry once → on repeat failure, record "⚠️ check unavailable" on the map, never treat it as passed |
| Ambiguous scope ("everything" — but everything up to where?) | Scope unclear at Phase 0 | Make the area table explicit and confirm with the user |
| Reviewers disagree with each other, or disagree with the deterministic sweep | Contradictory reports | Deterministic wins → adversarial re-check → escalate to the user if still unresolved |
WORKING / PARTIAL / BROKEN / BLOCKED (stalled on an external unresolved dependency or pending approval) + a bullet list of remaining gaps or blockers.| Rationalization | Counter |
|---|---|
| "The grep came back clean, so this area is done" | A clean grep means "pattern not found," not "content is sound." Label it [deterministic] only until content review happens (Invariant 1) |
| "Three reviewers found the same thing, so it must be true" | Agreement from reviewers sharing the same blind spot is a false-consensus trap, not confirmation. Verify with citations before accepting |
| "I checked this area last week, skip it this time" | Diff-based scope reduction is fine; silently skipping with no label is coverage inflation |
| "It's a small addition, let's just fix it along the way" | Violates fix/addition separation (Invariant 3). Batch additions and propose them together |
| "I'll do the map later if there's time" | An audit with no map resets to zero for the next session (Invariant 4) |
| "A few UNCERTAINs here and there do not matter" | Individual passes do not hide accumulated risk — 3+ in the same area triggers the composite-accumulation-gate flag (Phase 3) |
| "The user said 'audit', so finding an issue and just fixing it right there is helpful" | An audit/analysis trigger defaults to AUDIT_ONLY — fixing without an explicit mode-advance conflates analysis with execution (Invariant 5). Report it in the coverage map instead and wait for PROPOSE/APPLY_APPROVED |
AUDIT_ONLY/PROPOSE/APPLY_APPROVED) / list of applied fixes with line anchors (APPLY_APPROVED only) / list of proposed fixes and additions (PROPOSE/APPLY_APPROVED) / verification results (✅⚠️❌) / final status label / remaining gaps / Assumption ledger (if applicable)Changelog: v1.0 (initial release) → v1.1 (added the coverage-caps-intervention-value step to Phase 1) → v1.2 (added the AUDIT_ONLY/PROPOSE/APPLY_APPROVED execution-mode gate — a bare audit/analysis trigger now defaults to read-only and never auto-advances to Phase 4 fix-bucket execution or a Protect-Hooks deny-lift; those now require an explicit mode-advance from the user) → v1.3 (added the single-reviewer batch-size cap to Phase 2 — batch size is a separate axis from parallel-agent count) → v1.4 (added an opt-in canary-mixing step to Phase 1/2/3/5 — a known-clean and a known-defective file from a bundled example pool are mixed unlabeled into a review bundle, then scored after the fact, as a control for whether "zero findings" means clean or means the reviewer missed it; corrected the deny-lift claim — the model drafts an edit plus an apply script for the user to run, it never lifts a deny itself; added
BLOCKEDto the Truthful Reporting status enum)
© AlexZio00, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 13 other files (scripts) in full-audit of AlexZio00/sovereign-skills.
Open the folder on GitHubat commit c062683
Full Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Full Audit this skillAlexZio00/sovereign-skills | 140 | — | ~6.4k | Automated safety check: Pass | MIT | |
| Interlinked Spec AuditQuentinCody/interlinked-cli | 178 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Sandbox Lifecycle Debugvercel-labs/vercel-openclaw-archived | 117 | — | ~809 | Automated safety check: Pass | MIT | |
| Agentic System Designooiyeefei/ccc | 495 | — | ~7.3k | Automated safety check: Pass | MIT | |
| Merge ReviewSethGammon/Citadel | 924 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Canva Core Workflow Bjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~950 | Automated safety check: Pass | MIT |
QuentinCody/interlinked-cli
Keep prose specs and design docs honest against the code using Interlinked's spec-audit system.
vercel-labs/vercel-openclaw-archived
Sandbox lifecycle debugging for vercel-openclaw: create, resume, stop, snapshotting, reset, stale-running reconciliation, persistent Sandbox v2 behavior, hot spares, and lifecycle locks.
ooiyeefei/ccc
Prescriptive Q&A workflow for designing agentic pipelines, multi-model councils, sub-agent hierarchies, and tool-loop hardening for any domain.
SethGammon/Citadel
Reviews pending fleet worktree merges before they're accepted.
jeremylongshore/tons-of-skills-marketplace
Operate Canva assets, brand-template autofill, and folders with explicit rights and asynchronous reconciliation.
jeremylongshore/tons-of-skills-marketplace
Design a Mistral integration from policy gateway through adapter, queues, state reconciliation, and audited output.
AlexZio00/sovereign-skills
A skill your agent uses when the user wants a deterministic cross-project status map generated from registered projects' session handoffs.
AlexZio00/sovereign-skills
Scope definition before implementation — two modes. An agent skill from AlexZio00/sovereign-skills.
AlexZio00/sovereign-skills
Interview-based project setup — generates CLAUDE.md, ROADMAP, .gitignore, .env.example from scratch.
AlexZio00/sovereign-skills
This skill should be used when the user types /collab-audit or requests AI collaboration diagnosis.
AlexZio00/sovereign-skills
A skill your agent uses when the user wants to audit the memory and documents Claude Code loads into context — CLAUDE.md (user global + project + nested), MEMORY.md, @imports, .claude/skills…
AlexZio00/sovereign-skills
A skill your agent uses when saving session state before context compaction, switching tasks, or ending a session.
Categories
Exhaustive, denominator-driven audit of an entire area (codebase, docs, memory, skills, DB, config). Full Audit is an agent skill from AlexZio00/sovereign-skills. Exhaustive, denominator-driven audit of an entire area (codebase, docs, memory, skills, DB, config).
Full Audit fits situations like: tasks that involve Accounting and bookkeeping; tasks that involve Code review; tasks that involve Citation management.
Run `npx skills add AlexZio00/sovereign-skills --skill full-audit -a claude-code`. Or copy the skill folder (full-audit in AlexZio00/sovereign-skills) into .claude/skills/full-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add AlexZio00/sovereign-skills --skill full-audit -a codex`. Or copy the skill folder (full-audit in AlexZio00/sovereign-skills) into .agents/skills/full-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AlexZio00/sovereign-skills --skill full-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/full-audit, .gemini/skills/full-audit, .github/skills/full-audit and .opencode/skills/full-audit in your project.
Going by SKILL.md and its folder, Full Audit needs Python for the scripts in its folder and the command-line tools its instructions call (python and git). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Full Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.4k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Full Audit: Interlinked Spec Audit (QuentinCody/interlinked-cli, 178 stars), Sandbox Lifecycle Debug (vercel-labs/vercel-openclaw-archived, 117 stars), Agentic System Design (ooiyeefei/ccc, 495 stars) and Merge Review (SethGammon/Citadel, 924 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
AlexZio00 (a GitHub user) maintains it in AlexZio00/sovereign-skills, which has 140 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 9, 2026.
Source: AlexZio00/sovereign-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.