Agent skill

Audit Session

by devcodex-labs in devcodex-labs/devcodex

审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复

AGPL-3.0Auto-check passed

Install Audit Session

skills CLI
$ npx skills add devcodex-labs/devcodex --skill audit-session -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install devcodex-labs/devcodex audit-session --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/audit-session .claude/skills/audit-session && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-session
GitHub stars
439
Token cost
~1.8k tokens
SKILL.md length
396 words
Files
2
Skills in repo
70
Repo updated
First seen
Licence
AGPL-3.0

At a glance

审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复

  • Works in 6 steps: 用户说"继续审计" / "继续上次的审查" → 读取 /.audit-state/ 下有界 .json 清单,先按上述兼容规则分类 → 只在 current session 与可导航的 legacy audit 中按… → …
  • SKILL.md covers 适用范围, 状态文件路径, 状态机 and 状态文件 schema, plus 4 more sections
  • Calls git

What it does

Audit Session is an agent skill from devcodex-labs/devcodex. 审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `intent.json`).

The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.

Example prompts

  • “/audit-session”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. 用户说"继续审计" / "继续上次的审查"
  2. 读取 /.audit-state/ 下有界 .json 清单,先按上述兼容规则分类
  3. 只在 current session 与可导航的 legacy audit 中按 lastUpdatedAt 倒序,找出 state ∈ {paused, active, resumed} 的最新一份;其他 schema 不参与排序
  4. 输出:"发现未完成审计会话 :目标 ,已完成 R{round},发现 {open} 项 open。是否继续?"
  5. 用户确认 → state=resumed → 立即 → active,从 round+1 开始
  6. 用户拒绝 → 询问是否 closed 该会话

What it can do on your machine

Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Session loads about 1.8k tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 396 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 396 words, ~1,761 tokens.

Download SKILL.mdSave it as .claude/skills/audit-session/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
audit-session
description
审计工作流的跨会话状态机 — 在 <audit-root>/.audit-state/<session-id>.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复

Audit Session Skill

适用范围

  • 触发:意图为 audit 且预期轮次 ≥3(即所有非 chat 审计场景)
  • 不适用:analyze(仅 ≥3 轮收敛但无 audit finding 交接状态机)、chat(无审计语义)

状态文件路径

text
<audit-root>/.audit-state/<session-id>.json

<audit-root> 取值:

  • 旧布局:<项目根>/.devcodex

  • 集中布局单项目:<工作区根>/.devcodex/<project>

  • 集中布局全工作区:<工作区根>/.devcodex/workspace

  • <session-id> 取首次启动审计的时间戳:YYYYMMDD-HHmmss

  • <audit-root>/.audit-state/ 目录由本 Skill 首次写入时创建(不随 init 分发)

  • .gitignore 须覆盖 <audit-root>/.audit-state/ 对应路径(如 .devcodex/.audit-state/、.devcodex/*/.audit-state/,同记忆策略)

状态机

text
active ──┬─> paused (Token 防护触发 / 用户中断)
         ├─> resumed (跨会话 resume 重新进入)
         ├─> converged (CRS + PCV 通过 + 连续3轮零发现)
         └─> closed (用户确认审计闭环)

paused ──> resumed ──> active
converged ──> closed
状态进入条件退出条件
active首次 audit 意图识别成功任一退出条件触发
pausedC08 Token 防护(>15 轮)或 用户中断resume 意图 + 当前 session 命中
resumedresume 意图 + 读取本文件立即转 active 继续审计
convergedzeroFindingStreak ≥ 3 且 crsPassed 且 pcvPassed用户确认 → closed
closed用户确认审计完成或放弃终态(不再写入)

状态文件 schema

json
{
  "schemaVersion": "AuditSessionStateV2",
  "sessionId": "20260520-143055",
  "startedAt": "2026-05-20T14:30:55+08:00",
  "lastUpdatedAt": "2026-05-20T16:12:33+08:00",
  "target": {
    "type": "spec | tech-design | requirements | project | report | document",
    "scope": "<被审查文件 glob 或目录>"
  },
  "dimensions": ["D1", "D2", "..."],
  "round": 3,
  "state": "active | paused | resumed | converged | closed",
  "findings": [
    {
      "id": "F-001",
      "round": 1,
      "dim": "D5",
      "file": "instructions/12-audit.instructions.md",
      "severity": "🔴 | 🟡 | 💡",
      "summary": "<一句话>",
      "status": "open | pending | in-progress | fixed | wontfix | accepted | recorded | transferred | superseded",
      "category": "spec-defect | release-pending | v{X.Y.Z}-candidate",
      "fixPlan": "<修复方案概述>",
      "fixCommit": "<git commit hash, 修复后写入>",
      "linkedPF": "PF-NNN | null"
    }
  ],
  "regressionProbes": [
    {
      "findingId": "F-007",
      "scanCmd": "grep -c 'PC5' CLAUDE.md",
      "expectedMatches": 3,
      "lastVerifiedRound": 4,
      "lastVerifiedAt": "2026-05-21T03:30:00+08:00"
    }
  ],
  "r2Probes": [{"name": "<probe>", "status": "✅|⚠️|❌"}],
  "r3Probes": [{"name": "<probe>", "status": "✅|⚠️|❌"}],
  "r4Probes": [{"name": "<probe>", "status": "✅|⚠️|❌"}],
  "zeroFindingStreak": 0,
  "crsPassed": false,
  "pcvPassed": false,
  "remoteReleased": {
    "gitPush": false,
    "npmPublish": false,
    "recordedAt": "ISO8601",
    "source": "user-confirmed-manual | ci-automation"
  },
  "lastCheckpoint": {
    "round": 3,
    "writtenAt": "2026-05-20T16:12:33+08:00",
    "reason": "round-end | token-protect | user-interrupt | switching-to-release-vX.Y.Z | release-pending-vX.Y.Z"
  },
  "linkedMemory": "tasks/20260520.md",
  "linkedReport": "<active-root>/<task-kind>/<task>/reports/<agent>/20260520/01--<name>.md",
  "linkedRelease": "<active-root>/requirements/<task>/reports/<agent>/YYYYMMDD/01--vX.Y.Z-release.md"
}
.audit-state 兼容读取边界

.audit-state 是多类运行态证据的共享目录名,不代表目录内每个 JSON 都属于当前审计会话。读取者必须先分类,再决定校验方式:

分类识别处理
current sessionexact AuditSessionStateV1 / AuditSessionStateV2按本 Skill 的状态、finding 与 regression probe 合同严格校验
legacy auditAuditStateV1 或可识别的历史无 schema 审计形状只读导航与取证,不要求满足当前枚举或新探针,不改写历史字节
non-auditSkillRoute、batch plan、validation 等其他 schema跳过审计会话校验,由各自 owner 负责
unsupported current未支持的 AuditSessionStateV*明确报告不支持,禁止猜测或降成 legacy
invalidJSON 损坏或顶层不是 object报告结构错误,不静默忽略

兼容分类只解决 reader 误判,不授予旧状态新的写权限,也不得伪造 superseded、重算旧 finding 或迁移历史文件。

v1.9.4+ schema 字段说明
字段引入用途
findings[].categoryv1.9.4分类标识:spec-defect(规范缺陷)/ release-pending(仅发版动作未启动导致)/ v{X.Y.Z}-candidate(推迟到下版本同源合并)
findings[].fixPlanv1.9.4修复方案概述,留作 release/dev 工作流参考
findings[].fixCommitv1.9.4独立 fix/self-fix 工作流产生的修复 commit hash;audit 只读取并验证,不自行提交
regressionProbes[]v1.9.5+已修复 finding 的回归扫描定义;audit-common §收敛门禁第 7 步触发;任一回归 → status 切回 open,streak 归零
r{N}Probes[]v1.9.4第 N 轮的探针清单与状态,便于跨会话 resume 时审计深度可追溯
remoteReleasedv1.9.4远端发版动作状态(git push + npm publish),消除 release-pending findings 的依据
lastCheckpoint.reasonv1.9.4扩充值:switching-to-release-vX.Y.Z(切 release 流程缓冲)/ release-pending-vX.Y.Z(等下版本合并)
linkedReleasev1.9.4关联 release 报告路径,建立 audit → release 双向链
findings[].status 枚举
状态含义是否未解决
open当前审计仍需处理是
pending已确认但等待后续批次处理是
in-progress正在修复或验证中是
fixed已修复并通过回归验证否
wontfix已确认不修复,需保留理由否
accepted已接受为项目例外或可接受风险,需保留理由否
recorded已记录到外部台账、问题池或报告,当前审计不再直接处理否
transferred已转入其他报告、需求或问题池继续跟进否
superseded已被后续报告或新版结论取代否

终态 converged / closed 不得保留 open、pending、in-progress findings;允许 fixed、wontfix、accepted、recorded、transferred、superseded 作为已处置状态。

Show full SKILL.md (161 more words)Show less

写入时机

AuditMutationBoundaryGate:audit session 只记录 finding/交接/外部修复证据;sourceMutationAuthorized 在 audit 中恒为 false,用户修复授权由独立 fix/self-fix 的 CP/ExecutionContract 持有。

时机动作字段更新
首轮启动创建文件,state=activesessionId / startedAt / target / dimensions
每轮结束追加 findings + 更新 roundround / findings / zeroFindingStreak
CRS 完成标记通过状态crsPassed
PCV 完成标记通过状态pcvPassed
Token 防护(C08 >15轮)state=pausedstate / lastCheckpoint.reason=token-protect
收敛state=convergedstate
用户确认state=closedstate

与其他 Skill / Instruction 的协同

关联点说明
instructions/12-audit.instructions.md审计工作流入口须读取/创建本文件;收敛门禁须校验 crsPassed && pcvPassed && zeroFindingStreak>=3
instructions/15-memory.instructions.mdtasks/YYYYMMDD.md 段落须追加 🔗 审计会话:<session-id> 字段,建立双向链
intent/SKILL.mdresume 意图识别后须在三层记忆读取之前优先扫描 <audit-root>/.audit-state/*.json 查找未 closed 的会话
skills/audit-execution-guide/SKILL.mdfinding 先记录/交接;用户显式授权的独立 fix/self-fix 完成后,audit 读取新证据并重启新轮,旧轮不得在 audit 内伪造 fixed

跨会话 resume 流程

  1. 用户说"继续审计" / "继续上次的审查"
  2. 读取 <audit-root>/.audit-state/ 下有界 .json 清单,先按上述兼容规则分类
  3. 只在 current session 与可导航的 legacy audit 中按 lastUpdatedAt 倒序,找出 state ∈ {paused, active, resumed} 的最新一份;其他 schema 不参与排序
  4. 输出:"发现未完成审计会话 <sessionId>:目标 <target.scope>,已完成 R{round},发现 {open} 项 open。是否继续?"
  5. 用户确认 → state=resumed → 立即 → active,从 round+1 开始
  6. 用户拒绝 → 询问是否 closed 该会话

⛔ 禁止

  • ⛔ 状态文件不得提交到 git(同 .devcodex/.memory/)
  • ⛔ 同一 sessionId 不得并行写入;这是 C07 ConcurrencyPolicy 中不可变 audit-session 单写者锁,不受项目 concurrency 配置放开
  • ⛔ converged 状态不得自动转 closed —— 须用户明确确认(避免静默关闭)
  • ⛔ audit 不得因 finding 严重度或对象是 plugin 文件而自动获得 fix/self-fix、git add、commit 或 source mutation 权限

© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in content/skills/audit-session of devcodex-labs/devcodex.

  • SKILL.md
  • intent.json

Open the folder on GitHubat commit 1dd4525

Compare with similar skills

Audit Session next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Session compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Session this skilldevcodex-labs/devcodex439—~1.8kAutomated safety check: PassAGPL-3.0
Rootly AutomationComposioHQ/awesome-claude-skills77k3 repos~727Automated safety check: PassNone
Monte Carlo Analyze Root Causesickn33/agentic-awesome-skills47k1 repos~4kAutomated safety check: PassApache-2.0
Issue Root ResolutionGentleman-Programming/gentle-ai7.6k—~1.4kAutomated safety check: PassApache-2.0
Root Cause Paretodavila7/claude-code-templates32k—~791Automated safety check: PassMIT
Root Cause Debugginggarrytan/gstack136k—~1.4kAutomated safety check: PassMIT

Similar skills

  • Rootly Automation

    ComposioHQ/awesome-claude-skills

    Automate Rootly tasks via Rube MCP (Composio). An agent skill from ComposioHQ/awesome-claude-skills.

    77k GitHub starsUsed in 3 repos~727 tokens
    Productivity & AutomationAuto-check passed
  • Monte Carlo Analyze Root Cause

    sickn33/agentic-awesome-skills

    Curated upstream guidance for Monte Carlo Analyze Root Cause; use when the workflow matches the user goal.

    47k GitHub starsUsed in 1 repo~4k tokens
    DevelopmentAuto-check passed
  • Issue Root Resolution

    Gentleman-Programming/gentle-ai

    Trigger: root audit, atacar la raíz, issue roots, backlog roots, mechanism map, deletion-driven fix, resolver issues de raíz, close outdated issues.

    7.6k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Root Cause Pareto

    davila7/claude-code-templates

    Build a decision-grade Pareto for downtime, defects, complaints or delays - with unit-of-measure discipline, category hygiene, exposure normalization and a follow-up metric.

    32k GitHub stars~791 tokensUpdated today
    DevelopmentAuto-check passed
  • Root Cause Debugging

    garrytan/gstack

    Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.

    136k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Debugs in four phases (investigate, analyze, hypothesize, implement) under one rule: no fix is made until the root cause is found.

    136k GitHub stars~12k tokensUpdated today
    DevelopmentAuto-check: notes

More from devcodex-labs/devcodex

All 70 skills in this repo
  • Accessibility I18n

    devcodex-labs/devcodex

    无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。

    439 GitHub stars~718 tokensUpdated 20 days ago
    Auto-check passed
  • AI Agent System Architecture

    devcodex-labs/devcodex

    AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。

    439 GitHub stars~2.4k tokensUpdated 20 days ago
    Auto-check passed
  • API Contract Architecture

    devcodex-labs/devcodex

    API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。

    439 GitHub stars~865 tokensUpdated 20 days ago
    Auto-check passed
  • Architecture Design

    devcodex-labs/devcodex

    架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。

    439 GitHub stars~1.1k tokensUpdated 20 days ago
    Auto-check passed
  • Audit Common

    devcodex-labs/devcodex

    审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层

    439 GitHub stars~4.1k tokensUpdated 20 days ago
    Auto-check passed
  • Backend Domain Architecture

    devcodex-labs/devcodex

    后端领域架构专家 Owner — 当任务涉及领域模型、业务流程、权限、API、事务、一致性、幂等、兼容、数据边界、服务职责或用户要求从后端/领域专家角度审查时使用;要求用领域语言和业务不变量约束实现。

    439 GitHub stars~575 tokensUpdated 20 days ago
    Auto-check passed

Questions about Audit Session

What does Audit Session do?

审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复. Audit Session is an agent skill from devcodex-labs/devcodex.

How do I install Audit Session in Claude Code?

Run `npx skills add devcodex-labs/devcodex --skill audit-session -a claude-code`. Or copy the skill folder (content/skills/audit-session in devcodex-labs/devcodex) into .claude/skills/audit-session in your project. Claude Code loads it when a task matches its description.

How do I install Audit Session in Codex?

Run `npx skills add devcodex-labs/devcodex --skill audit-session -a codex`. Or copy the skill folder (content/skills/audit-session in devcodex-labs/devcodex) into .agents/skills/audit-session in your project. Codex loads it when a task matches its description.

Can I use Audit Session in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill audit-session -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-session, .gemini/skills/audit-session, .github/skills/audit-session and .opencode/skills/audit-session in your project.

What does Audit Session need to run?

Going by SKILL.md and its folder, Audit Session needs the command-line tools its instructions call (git).

Does Audit Session access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Session safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Session use?

Audit Session is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Session use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Session?

Skills that share tags, products or a category with Audit Session: Rootly Automation (ComposioHQ/awesome-claude-skills, 77k stars), Monte Carlo Analyze Root Cause (sickn33/agentic-awesome-skills, 47k stars), Issue Root Resolution (Gentleman-Programming/gentle-ai, 7.6k stars) and Root Cause Pareto (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Session?

devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.

Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.