Agent skill

Context Tree Audit

by first-tree-ai in first-tree-ai/first-tree

Audit stored normal content on the bound Context Tree's actual binding branch when a human explicitly asks to audit the whole tree, a domain, or specific normal paths for drift, contradictions…

Apache-2.0Auto-check passedProductivity & Automation

Install Context Tree Audit

skills CLI
$ npx skills add first-tree-ai/first-tree --skill context-tree-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install first-tree-ai/first-tree context-tree-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/first-tree-ai/first-tree.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/context-tree-audit .claude/skills/context-tree-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
context-tree-audit
GitHub stars
154
Token cost
~1.9k tokens
SKILL.md length
1,041 words
Files
3
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit stored normal content on the bound Context Tree's actual binding branch when a human explicitly asks to audit the whole tree, a domain, or specific normal paths for drift, contradictions…

  • Works in 9 steps: Read .first-tree/workspace.json and the… → From the bound checkout, inspect… → Fetch the bound upstream branch and… → …
  • Ordinary task reads
  • SKILL.md covers Purpose, Trigger Boundary, Stable Snapshot and Audit Workflow, plus 3 more sections
  • Calls git

What it does

Context Tree Audit is an agent skill from first-tree-ai/first-tree. Audit stored normal content on the bound Context Tree's actual binding branch when a human explicitly asks to audit the whole tree, a domain, or specific normal paths for drift, contradictions, duplication, density, metadata, placement, or relationship problems. Do not use for ordinary task reads, source-backed writes, Context Tree PR/MR reviews, or empty-tree setup.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `agents/openai.yaml`).

It sits in Productivity & Automation. The repository describes itself as: First-tree routes work to the right agent, gives it the same context your team has, and loops humans in only when the rules say so. Lives in your GitHub. Open source. The licence is Apache-2.0.

When your agent uses it

  • Ordinary task reads
  • Source-backed writes
  • Context Tree PR/MR reviews
  • Empty-tree setup

Example prompts

  • “/context-tree-audit”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Read .first-tree/workspace.json and the generated Tree Location section.
  2. From the bound checkout, inspect first-tree tree tree --help before using
  3. Fetch the bound upstream branch and resolve its exact remote HEAD SHA. If
  4. Create a uniquely named, agent-owned detached worktree at that exact SHA.
  5. Report the repository, branch, exact SHA, requested scope, and execution
  6. In the registered, clean detached worktree, run the selected
  7. In the detached worktree, run first-tree tree verify --json before any
  8. If validation passes, read only the scoped
  9. Remove the detached worktree through git worktree remove when finished.

What it can do on your machine

Read from SKILL.md and the folder at commit 13f2a38. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Context Tree Audit loads about 1.9k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 1,041 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from first-tree-ai/first-tree at commit 13f2a38, republished under its Apache-2.0 licence (© first-tree-ai). 1,041 words, ~1,923 tokens.

Download SKILL.mdSave it as .claude/skills/context-tree-audit/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
context-tree-audit
description
Audit stored normal content on the bound Context Tree's actual binding branch when a human explicitly asks to audit the whole tree, a domain, or specific normal paths for drift, contradictions, duplication, density, metadata, placement, or relationship problems. Do not use for ordinary task reads, source-backed writes, Context Tree PR/MR reviews, or empty-tree setup.

Context Tree Audit

Purpose

Audit a stable snapshot of stored normal content on the bound Context Tree's actual binding branch and route each evidence-backed finding to the smallest safe follow-up.

The workspace-generated AGENTS.md / CLAUDE.md Context Tree Policy is the only content-policy and authority baseline. Apply it directly; do not recreate its definitions or rules in this skill. If the policy or binding is missing, stop and report the environment gap.

Trigger Boundary

Use this skill only when a human explicitly asks for a broad stored-tree audit or names a domain or set of normal paths to audit. This trigger is exclusive: do not run first-tree-read first and expand a task-scoped read into an audit.

Do not use this workflow for a concrete source artifact that should be written to the tree, a Context Tree pull request or merge request review, ordinary task context, or an empty-tree setup. Those remain owned by their dedicated skills.

Choose the execution mode from the request:

  • Report-only (default): a request to audit, inspect, or report grants read-only authority. Perform no commit, push, pull request, merge request, issue, tracked ask, or other external mutation; report findings and recommended routes in the completion response.
  • Maintenance: select this only when the human explicitly asks to maintain, fix, or create follow-up artifacts. Mutation authority extends only to the requested artifact kinds. High-confidence local findings may produce one focused artifact per coherent finding group. Nothing is merged automatically.

Stable Snapshot

  1. Read .first-tree/workspace.json and the generated Tree Location section. Resolve the bound tree checkout, upstream, and actual binding branch. Use the branch declared in Tree Location; never assume main or substitute the checkout's current branch. Fail closed on a missing binding, repository mismatch, or ambiguous branch.
  2. From the bound checkout, inspect first-tree tree tree --help before using its current selectors.
  3. Fetch the bound upstream branch and resolve its exact remote HEAD SHA. If freshness cannot be confirmed because of network, permission, or remote identity failure, do not claim a current audit and do not create a semantic fix.
  4. Create a uniquely named, agent-owned detached worktree at that exact SHA. Never switch or edit the main tree checkout and never reuse an unowned path.
  5. Report the repository, branch, exact SHA, requested scope, and execution mode. Keep all discovery reads fixed to this snapshot.
  6. In the registered, clean detached worktree, run the selected first-tree tree tree --no-pull ... command and confirm its HEAD is still the exact audited SHA. Never resolve the audit scope from the mutable main checkout after the snapshot exists.
  7. In the detached worktree, run first-tree tree verify --json before any semantic node read. Record validator failures as mechanical findings and do not hide them inside semantic conclusions.
  8. If validation passes, read only the scoped normal nodes plus the minimum parent, sibling, relationship, and source evidence needed to judge them under the generated policy.
  9. Remove the detached worktree through git worktree remove when finished. Never use --force; a dirty snapshot is an integrity failure.

Audit Workflow

Check the requested scope for stale or contradictory claims, duplicated canonical truth, misplaced decisions, misleading metadata or relationships, excessive density, and source-boundary violations. Do not treat model suspicion as evidence.

Each finding must contain:

  • path: the exact normal node or relationship;
  • policy: the generated-policy rule that applies;
  • claim: the current claim and concrete problem;
  • evidence: verifiable current source, configuration, validator output, human decision, or related canonical normal content;
  • confidence: mechanical, strong, uncertain, or human-authority;
  • action: report, focused tree PR/MR, issue or draft proposal, tracked human ask, or source-code escalation.

Tree history and forge discussion may help locate evidence, but delivery history does not become normal-node prose. Apply the generated policy's code-versus-tree drift authority exactly; never turn an authority conflict into an automatic normal-content rewrite.

Show full SKILL.md (413 more words)Show less

Finding Routing

  • In Report-only mode, record every finding and its recommended route in the response, including authority conflicts. Do not create an issue, proposal, tracked ask, branch, commit, pull request, or merge request.
  • A local mechanical or strong semantic finding may become one small tree PR/MR in Maintenance mode only after it becomes a concrete audit source artifact. Include the audited SHA and scope, exact finding group, current evidence, canonical-placement judgment, and risk. Then load first-tree-write; that skill rechecks freshness and owns target selection, drafting, verification, worktree, and PR/MR discipline. Every Audit-originated tree PR/MR is created as a draft and remains draft when Audit and Writer finish. Audit never edits the tree directly.
  • Weak, broad, or cross-domain evidence does not change normal truth. Report it or, when Maintenance explicitly authorizes it, create a focused issue or draft proposal that names the missing evidence.
  • In Maintenance mode, ownership, human-authority, or locked-decision conflicts use a tracked human ask only when the next step genuinely depends on that decision and the request authorizes follow-up actions. Otherwise report the blocker without mutation. Source implementation that conflicts with a locked decision is escalated to the source side, not repaired by changing the tree.
  • No findings means report the exact audited SHA, scope, validator result, and evidence coverage. Do not claim correctness outside the inspected scope.

One pull request or merge request carries one coherent finding group. Do not turn a broad audit into a tree-wide rewrite or a bundle of unrelated domain changes.

Mutation Boundary

Audit owns discovery, evidence classification, and action selection. It does not own a second authoring policy or PR/MR verdict workflow.

Never edit owners without explicit human authority, approve a pull request or merge request created from this audit, merge, change repository governance, create a new CLI surface, or claim scheduled execution. A GitHub tree PR continues through context-tree-review. A GitLab tree MR also continues through context-tree-review, but Audit leaves it draft so that run remains read-only. Create every review request with the matching forge. After creating or reusing a GitLab draft MR, run first-tree gitlab follow <mr-url>. Audit never creates a Reviewer Chat, marks either artifact ready, publishes a verdict, approves it, repairs it, or merges it.

Completion Report

Report the repository, binding branch, exact audited SHA, scope, validator result, findings grouped by confidence and action, artifacts actually created, snapshot cleanup result, and any decision that blocks the next step. State explicitly when the run was report-only or freshness could not be confirmed.

© first-tree-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in skills/context-tree-audit of first-tree-ai/first-tree.

  • SKILL.md
  • VERSION
  • agents/openai.yaml

Open the folder on GitHubat commit 13f2a38

Compare with similar skills

Context Tree Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Context Tree Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Context Tree Audit this skillfirst-tree-ai/first-tree154—~1.9kAutomated safety check: PassApache-2.0
Agent Browserquran/quran.com-frontend-next1.9k42 repos~3.3kAutomated safety check: PassNone
Process Inboxtelegramdesktop/tdesktop33k2 repos~4.5kAutomated safety check: PassGPL-3.0
Perform Tasktelegramdesktop/tdesktop33k2 repos~3kAutomated safety check: PassGPL-3.0
Brave Searchbadlogic/pi-skills2.6k6 repos~592Automated safety check: PassMIT
Continuetelegramdesktop/tdesktop33k2 repos~9.4kAutomated safety check: PassGPL-3.0

Similar skills

  • Agent Browser

    quran/quran.com-frontend-next

    Automates browser interactions for web testing, form filling, screenshots, and data extraction.

    1.9k GitHub starsUsed in 42 repos~3.3k tokens
    Productivity & AutomationAuto-check passed
  • Process Inbox

    telegramdesktop/tdesktop

    Process the local ignored ai-tdesktop inbox into durable, independently testable Telegram Desktop task records while task execution worktrees remain active.

    33k GitHub starsUsed in 2 repos~4.5k tokens
    Productivity & AutomationAuto-check passed
  • Perform Task

    telegramdesktop/tdesktop

    Resolve, start or resume, implement, review, test, and publish exactly one existing ai-tdesktop task by short slug or full dated id, including rare blocked retries and split-required results.

    33k GitHub starsUsed in 2 repos~3k tokens
    Productivity & AutomationAuto-check passed
  • Brave Search

    badlogic/pi-skills

    Web search and content extraction via Brave Search API. An agent skill from badlogic/pi-skills.

    2.6k GitHub starsUsed in 6 repos~592 tokens
    Productivity & AutomationAuto-check passed
  • Continue

    telegramdesktop/tdesktop

    Continue autonomous Telegram Desktop development from the shared ai-tdesktop repository.

    33k GitHub starsUsed in 2 repos~9.4k tokens
    Productivity & AutomationAuto-check passed
  • Feishu Doc

    openclaw/openclaw

    Feishu document read/write workflows. An agent skill from openclaw/openclaw.

    392k GitHub stars~516 tokensUpdated today
    Productivity & AutomationAuto-check passed

More from first-tree-ai/first-tree

All 9 skills in this repo
  • First Tree File Bug

    first-tree-ai/first-tree

    File a GitHub issue about a defect in First Tree itself — the CLI, agent runtime, chat, web app, GitHub integration, GitLab integration, or Context Tree tooling — onto First Tree's own GitHub-hosted…

    154 GitHub stars~2.8k tokensUpdated 7 days ago
    Auto-check passed
  • Context Tree Review

    first-tree-ai/first-tree

    Review a GitHub pull request or GitLab merge request against the workspace-bound Context Tree when a trusted server-authored Context Reviewer run supplies provider-scoped authority.

    154 GitHub stars~8k tokensUpdated 7 days ago
    Auto-check passed
  • First Tree Welcome

    first-tree-ai/first-tree

    A skill your agent uses for a First Tree onboarding first chat, especially natural opening messages like "welcome aboard", "Please help me get started with First Tree", or "Please help me get…

    154 GitHub stars~11k tokensUpdated 7 days ago
    Auto-check passed
  • First Tree Read

    first-tree-ai/first-tree

    Read the applicable Context Tree before acting. An agent skill from first-tree-ai/first-tree.

    154 GitHub stars~6.1k tokensUpdated 7 days ago
    Auto-check: warnings
  • First Tree QA

    first-tree-ai/first-tree

    Act as an independent QA engineer for a software repository.

    154 GitHub stars~2.1k tokensUpdated 7 days ago
    Auto-check passed
  • First Tree Seed

    first-tree-ai/first-tree

    Bootstrap a team's Context Tree from readable source repos — for an onboarding "build / set up the Context Tree" task on a tree that has no domain structure yet: either no tree exists (creates and…

    154 GitHub stars~17k tokensUpdated 7 days ago
    Auto-check passed

Questions about Context Tree Audit

What does Context Tree Audit do?

Audit stored normal content on the bound Context Tree's actual binding branch when a human explicitly asks to audit the whole tree, a domain, or specific normal paths for drift, contradictions…. Context Tree Audit is an agent skill from first-tree-ai/first-tree. Audit stored normal content on the bound Context Tree's actual binding branch when a human explicitly asks to audit the whole tree, a domain, or specific normal paths for drift, contradictions, duplication, density, metadata, placement, or relationship problems.

When should I use Context Tree Audit?

Context Tree Audit fits situations like: ordinary task reads; source-backed writes; context Tree PR/MR reviews; empty-tree setup.

How do I install Context Tree Audit in Claude Code?

Run `npx skills add first-tree-ai/first-tree --skill context-tree-audit -a claude-code`. Or copy the skill folder (skills/context-tree-audit in first-tree-ai/first-tree) into .claude/skills/context-tree-audit in your project. Claude Code loads it when a task matches its description.

How do I install Context Tree Audit in Codex?

Run `npx skills add first-tree-ai/first-tree --skill context-tree-audit -a codex`. Or copy the skill folder (skills/context-tree-audit in first-tree-ai/first-tree) into .agents/skills/context-tree-audit in your project. Codex loads it when a task matches its description.

Can I use Context Tree Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add first-tree-ai/first-tree --skill context-tree-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/context-tree-audit, .gemini/skills/context-tree-audit, .github/skills/context-tree-audit and .opencode/skills/context-tree-audit in your project.

What does Context Tree Audit need to run?

Going by SKILL.md and its folder, Context Tree Audit needs the command-line tools its instructions call (git).

Does Context Tree Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Context Tree Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Context Tree Audit use?

Context Tree Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Context Tree Audit use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Context Tree Audit?

Skills that share tags, products or a category with Context Tree Audit: Agent Browser (quran/quran.com-frontend-next, 1.9k stars), Process Inbox (telegramdesktop/tdesktop, 33k stars), Perform Task (telegramdesktop/tdesktop, 33k stars) and Brave Search (badlogic/pi-skills, 2.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Context Tree Audit?

first-tree-ai (a GitHub organization) maintains it in first-tree-ai/first-tree, which has 154 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on September 30, 2026.

Source: first-tree-ai/first-tree on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.