Agent skill

Goat Audit

by katopz in katopz/katgpt-rs

Audit cross-repo GOAT/gain primitive cherry-pick status across the multi-repo stack (katgpt-rs upstream, riir- consumers).

MITAuto-check passed

Install Goat Audit

skills CLI
$ npx skills add katopz/katgpt-rs --skill goat-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install katopz/katgpt-rs goat-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/katopz/katgpt-rs.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/goat-audit .claude/skills/goat-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
goat-audit
GitHub stars
138
Token cost
~7.9k tokens
SKILL.md length
3,368 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Audit cross-repo GOAT/gain primitive cherry-pick status across the multi-repo stack (katgpt-rs upstream, riir- consumers).

  • Works in 7 steps: Pre-flight (MANDATORY before any verdict) → Build the default-on primitive inventory → For each primitive, check riir-*… → …
  • Auditing primitive cherry-pick coverage
  • SKILL.md covers When to use, DO NOT use for, Repos in scope (the product… and Workflow, plus 3 more sections
  • Calls git

What it does

Goat Audit is an agent skill from katopz/katgpt-rs. Audit cross-repo GOAT/gain primitive cherry-pick status across the multi-repo stack (katgpt-rs upstream, riir- consumers). Detects stalls (default-on in katgpt-rs for ≥7 days with zero runtime wiring in riir-), DRY violations (duplicated substrate in riir- that should consume katgpt-core), and SOLID violations. Use when auditing primitive cherry-pick coverage, before opening a plan that consumes a katgpt-rs primitive, or quarterly as a hygiene gate.

Its SKILL.md is about 7.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: A neuro-symbolic micro-Transformer with speculative decoding, constraint pruning, recurrent attention, and adaptive test-time scaling — built in Rust. The licence is MIT.

When your agent uses it

  • Auditing primitive cherry-pick coverage
  • Before opening a plan that consumes a katgpt-rs primitive
  • Quarterly as a hygiene gate

Example prompts

  • “/goat-audit”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Pre-flight (MANDATORY before any verdict)
  2. Build the default-on primitive inventory
  3. For each primitive, check riir-* consumption (THREE-LAYER check)
  4. Classify each primitive
  5. DRY / SOLID check
  6. Output
  7. Commit + report

What it can do on your machine

Read from SKILL.md and the folder at commit 94a4da5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Goat Audit loads about 7.9k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 3,368 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~7.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from katopz/katgpt-rs at commit 94a4da5, republished under its MIT licence (© katopz). 3,368 words, ~7,889 tokens.

Download SKILL.mdSave it as .claude/skills/goat-audit/SKILL.md (or your agent's skills folder).
name
goat-audit
description
Audit cross-repo GOAT/gain primitive cherry-pick status across the multi-repo stack (katgpt-rs upstream, riir-* consumers). Detects stalls (default-on in katgpt-rs for ≥7 days with zero runtime wiring in riir-*), DRY violations (duplicated substrate in riir-* that should consume katgpt-core), and SOLID violations. Use when auditing primitive cherry-pick coverage, before opening a plan that consumes a katgpt-rs primitive, or quarterly as a hygiene gate.

goat-audit — Cross-Repo GOAT/Gain Cherry-Pick Audit

Use this skill when auditing whether the riir-* private repos have consumed the GOAT-validated primitives shipped in katgpt-rs. It detects four failure classes:

  1. Stalls — primitive default-on in katgpt-rs for ≥7 days, zero runtime wiring in riir-*.
  2. DRY violations — riir-* ships a local copy of substrate that should consume katgpt-core / katgpt-transformer / katgpt-pruners.
  3. SOLID violations — primitive consumed in the wrong layer (e.g. a sync-boundary primitive wired into a latent-only runtime, or vice versa).
  4. Fork drift (the Issue 019 class) — riir-* is a fork of katgpt-rs (e.g. riir-engine/src/lib.rs says "Extracted from katgpt-rs (MIT, frozen at v0.1.0)") and a Layer 2 struct-name grep hits a file that defines its own pub struct SameName with zero use katgpt_*:: imports. The audit must distinguish consumer (true positive, primitive wired) from duplicate (false positive, primitive re-implemented locally — the canonical has bit-rotted since v0.1.0).

When to use

  • Quarterly hygiene gate — re-audit after every major katgpt-rs release.
  • Before opening a plan that consumes a katgpt-rs primitive — confirm it isn't already wired (avoid duplicate work).
  • When a user asks "did riir-* get every good thing from katgpt-rs yet?" (the canonical trigger).
  • After a promotion in katgpt-rs — track that the riir-* runtime wiring plan is filed within 7 days.

DO NOT use for

  • Paper distillation (use the research skill).
  • Single-repo refactors with no cross-repo angle.
  • Bug fixes with no architectural impact.

Repos in scope (the product set of 7 — audit focuses on the 4 cherry-pick targets)

Canonical list: katgpt-rs/AGENTS.md §"Repo count". riir-dapps (dApp layer, added 2026-08-20) is OUT OF SCOPE here for the same reason as riir-game-sdk: it composes outcomes, it hosts no feature-gated katgpt primitive to audit. (This header said "8" from 2026-09-01 — correct for one day, stale from riir-armageddon's retirement 2026-09-02 until 2026-09-11.)

katgpt-rs          ← public engine (substrate: katgpt-core + 16 leaf crates + root)
riir-ai            ← private runtime/game (cognitive, ARG, CLR, HLA, karc, cwm, etc.)
riir-chain         ← private chain (LatCal, quorum, asset lifecycle)
riir-neuron-db     ← private neuron-shard leaf (Pod, freeze, consolidation, AnyRAG)
riir-train         ← private training vault (OUT OF SCOPE — training-only methods)
riir-game-sdk      ← private game-vocabulary facade + dev-tool workspace (OUT OF SCOPE —
                      consumes vocabulary from riir-games-shared in riir-ai, not katgpt-rs
                      engine primitives directly; transitively reaches katgpt-core only via
                      the always-on path dep, no feature-flag-gated primitives to audit)
riir-dapps         ← private dApp layer (OUT OF SCOPE — settlement composition over
                      riir-chain programs; hosts no feature-gated katgpt-rs primitive)

Why the SDK is out of scope: this audit tracks katgpt-rs default-on primitives (feature-flag-gated, GOAT-validated) consumed in riir-* runtimes. The SDK is a facade over riir-games-shared (in riir-ai workspace) — its primitives are vocabulary types, not katgpt-rs engine features, so it ships no feature-flag-gated katgpt-rs primitive that needs cherry-pick tracking. (riir-armageddon was listed here on the same reasoning — product-domain types — until it was retired 2026-09-02, owner act.)

Newer workspace repos outside the product set consume katgpt-core directly — riir-refine (ConstraintPruner + ternary matvec + pick_domain), riir-dao (rating Elo + beta_lcb_order_into — its ONE path dep), riir-auth (sigmoid + dot-product primitives), riir-esp32 (katgpt-device-verify), riir-kat (katgpt-* via the [patch] unified pin only, no direct imports). They host no feature-gated katgpt-rs ENGINE primitive, so they are not cherry-pick targets — but they ARE duplication candidates: never scope a Check A/B sweep to the product set alone. Derive the repo set (substrate-first Step 2), don't type it.

Workflow

Step 0 — Pre-flight (MANDATORY before any verdict)

Run all of these in parallel; do NOT skip:

  1. read_file katgpt-rs/Cargo.toml — extract the default = [...] feature list. These are the GOAT-validated primitives.
  2. read_file katgpt-rs/crates/katgpt-core/Cargo.toml — extract substrate features.
  3. read_file riir-ai/crates/riir-engine/Cargo.toml — extract riir-engine features + the katgpt features each one forwards to.
  4. read_file riir-neuron-db/Cargo.toml — extract neuron-db features.
  5. read_file riir-chain/Cargo.toml + riir-chain/crates/riir-chaind/Cargo.toml — extract chain features.
  6. list_directory katgpt-rs/.benchmarks — these track the GOAT gate evidence per primitive.
  7. list_directory riir-ai/.issues + riir-ai/.plans — existing wiring plans/issues to avoid duplication.
Step 1 — Build the default-on primitive inventory

From katgpt-rs/Cargo.toml's default = [...], build a table:

PrimitiveDefault-on sincekatgpt-rs planSubstrate location

Source the "default-on since" from the inline comment in the Cargo.toml (e.g. # zone_density_routing DEFAULT-ON (Plan 351 Phase 3): ...). If no date, mark "unknown" and treat as fresh.

Step 2 — For each primitive, check riir-* consumption (THREE-LAYER check)

Critical lesson (Issue 003): feature-name grep returns false negatives. The salience_tri_gate feature is consumed via SalienceTriGate::decide_with_delegate_nudge in karc_bridge/anticipation.rs — a feature-name grep missed this; struct/function-name grep caught it.

Critical lesson (Issue 019, 2026-07-04): struct-name grep returns false POSITIVES in fork-derived repos. riir-engine/src/transformer/mod.rs defined its own KVCache/KVSnapshot/PAGE_SIZE with zero use katgpt_transformer:: imports even though katgpt-transformer was declared as a mandatory dep in Cargo.toml and paid for in compile time — the prior audit marked KVCache as WIRED when it was actually a local duplicate shadowing the canonical type. Plan 406 Phase 1/2 de-forked these. Layer 3 (consumer-vs-duplicate discrimination) is mandatory before any WIRED verdict.

Skill correction (2026-07-09, Issue 420): the prior version of this paragraph cited riir-engine/src/kvarn_quality.rs defining KvCacheQualityReport as a duplicate of katgpt-kv::kvarn::KvCacheQualityReport. That example was factually wrong — katgpt-kv does NOT ship KvCacheQualityReport (verified: 0 matches across katgpt-rs/**/*.rs). The riir-engine type is a legitimately local ThinkingController abstraction (Plan 199 T1), NOT fork drift. The crate::transformer shadow case above replaces it as the canonical example.

For each primitive, run ALL THREE greps in parallel across the three consumer repos named by §"Repos in scope" above.

This narrow set is deliberate, not drift — it is the reasoned in-scope list (product set of 7 minus the three documented OUT OF SCOPE entries), which is why the block carries the marker below and scripts/skill_repo_set_gate.py does not flag it. Widen it only by editing §"Repos in scope" first; the scope section is the decision, this grep is only its implementation.

Caveat worth knowing when you read a "0 consumers" result: it is a claim about these three repos, not about the workspace's 18. A DUPLICATE of a primitive can live in an out-of-scope repo (the standing example was riir-armageddon consuming GenericSpatialBelief in 3 files — that repo is retired as of 2026-09-02, but the hazard it illustrates is not) — the anti-duplication sweep that covers all of them is substrate-first Audit Step 2, not this one.

<!-- repo-set-ok: the reasoned in-scope consumer set per §"Repos in scope" -->
bash
cd /Users/katopz/git

# Layer 1 — feature-name grep (catches Cargo.toml forwards + cfg gates)
# -r + --include, NOT `riir-ai/**/*.toml`: bash without `shopt -s globstar`
# expands `**` as a single `*`, so the old form silently checked ONE level.
grep -rn "<feature_name>" --include='*.toml' --exclude-dir=target \
  riir-ai/ riir-chain/ riir-neuron-db/

# Layer 2 — struct/function-name grep (catches actual code consumption)
grep -rnE "<CamelCaseStruct>|<snake_case_fn>" --include='*.rs' \
  --exclude-dir=target riir-ai/ riir-chain/ riir-neuron-db/

# Layer 3 — consumer-vs-duplicate check (MANDATORY for every Layer 2 hit)
# For each file returned by Layer 2, grep the FILE for katgpt imports.
# If the file has zero `use katgpt_*::` lines, the hit is a DUPLICATE, not a consumer.
grep "^use katgpt" <each-file-from-layer-2-results>

Layer 3 classification rules:

  • File has use katgpt_*::SomeType AND uses SomeType in code → CONSUMER (true wired)
  • File has zero use katgpt lines but defines pub struct SameName → DUPLICATE (fork drift) — file the file as a de-fork candidate per Issue 019; do NOT count the primitive as wired
  • File has use katgpt_*::SomeType but the Layer 2 hit name is locally defined → MERGE candidate — the file consumes some katgpt types but re-defines the queried primitive locally; needs human review

Vocabulary translation before grepping: list the primitive's 3–5 exported type/function names from the source file (e.g. katgpt-rs/crates/katgpt-pruners/src/soft_reject.rs exports SoftRejectVerdict, SoftRejectConfig, soft_reject_decide, soft_reject_with_relax, RelaxationStrategy, NoRelaxation). Grep for ALL of them, not just the feature name.

Derived-primitive grep (the T2 smooth_min_similarity lesson, Issue 532, 2026-07-18): when a primitive is consumed as SUBSTRATE by a later promoted primitive (e.g. recos in katgpt-core is implemented on top of smooth_min_similarity — #[cfg(feature = "recos")] lives inside the similarity module and implies smooth_min_similarity), grepping for the substrate's own names misses consumers of the derivative. The riir-* consumer of recos calls recos_sim_ranking, not smooth_min_similarity — a Layer 2 grep for smooth_min returns 20+ katgpt-rs hits and the riir-neuron-db consumer hides on a later page. Mitigation: before auditing a substrate primitive, list the katgpt-core features that imply it (read each feature definition in crates/katgpt-core/Cargo.toml for feature_x = ["feature_y"] edges — recos = ["smooth_min_similarity"] is the canonical case), then grep for the derivative primitive's exported names too. This was the second occurrence of the paginated-grep-hides-consumer failure mode (the first was T9 local_branch_routing, where the consumer used branch_routing::{DotProductRouter, PostCandidateRouter} aliases while the grep was for branching).

Step 3 — Classify each primitive
ClassCriteriaAction
Wired (DEFAULT-ON)Layer 3 CONSUMER in riir-* runtime AND promoted to default-on in riir-engine/riir-gamesNo action
Wired (opt-in)Layer 3 CONSUMER in riir-* runtime, opt-in feature in riir-*Check the opt-in reason; if "until GOAT gate passes" and the gate is overdue, flag
StallDefault-on in katgpt-rs ≥7 days, zero Layer 3 CONSUMER (Layers 1+2 miss OR Layer 2 hits are all DUPLICATES)File .issues/ in the appropriate riir- repo*
Fork drift (Issue 019 class)Layer 2 hit but Layer 3 says DUPLICATE — riir-* file defines its own pub struct SameName with no use katgpt_*::File de-fork task in .issues/ — see Issue 019 for the canonical riir-engine substrate de-fork plan
PartialLayer 3 CONSUMER in one riir-* repo but the natural second consumer is missingNote in issue; defer if natural consumer doesn't exist yet
DeliberateHas a documented reason for not being wired (e.g. claim_rubric is CI-only by design)No action
Too freshDefault-on <7 daysDefer; re-audit next quarter
Step 4 — DRY / SOLID check

Two complementary checks: the crate::* scan (catches imports) and the zero-import scan (catches fork drift).

Check A — crate::* substrate refs (the Plan 008 lesson)

For each katgpt-core/katgpt-transformer/katgpt-pruners substrate module, check riir-engine src for crate::* imports of substrate that should be katgpt_*:::

# If riir-engine has its own hla/transformer/types.rs/tokenizer.rs/dd_tree.rs that
# duplicates katgpt-core, that's a DRY violation (Plan 008 class).
grep "crate::hla|crate::transformer|crate::types|crate::tokenizer|crate::dd_tree|crate::spec_types|crate::mcts|crate::sampling|crate::delta_mem|crate::simd" riir-ai/crates/riir-engine/src/**/*.rs

All should be katgpt_core::* / katgpt_transformer::* / katgpt_speculative::* (Plan 008 Phase 2 closure). Any remaining crate::* is a DRY violation.

Check B — Zero-import substrate files (the Issue 019 lesson)

Fork drift can hide in files that have NO crate::* substrate refs and NO use katgpt_*:: lines — pure standalone local impls. Check B finds them:

# List all .rs files in riir-engine/src that have zero katgpt imports.
# Every substrate-side file in this list is a fork-drift candidate.
for f in $(find riir-ai/crates/riir-engine/src -name '*.rs'); do
  if ! grep -q '^use katgpt' "$f"; then
    echo "ZERO-IMPORT: $f"
  fi
done

For each ZERO-IMPORT file, manually classify:

  • Substrate duplicate (matches a katgpt-* leaf module) → de-fork candidate per Issue 019
  • riir-only runtime (cognitive stack like clr/karc/cgsp with no katgpt equivalent) → KEEP, not a violation
  • Test/example file → exempt

The cognitive stack (arg_runtime, bom_arena, cce_runtime, etc.) intentionally has riir-local files; the LLM-substrate layer (transformer, quant, sampling, kv, lora-adapters, mcts, delta_mem) is where drift hides.

For SOLID: check that primitives are consumed in the right layer:

  • Sync-boundary primitives (chain commitment, Merkle root) → riir-chain or riir-neuron-db, NOT riir-ai runtime.
  • Latent-only primitives (emotion projection, set attention) → riir-ai runtime, NOT riir-chain.
  • Substrate (SIMD, transformer, types) → katgpt-core, NOT riir-engine local.
Step 5 — Output

Write the audit to a new .issues/NNN_cross_repo_goat_cherry_pick_audit.md file in the riir-* repo that owns the largest gap (usually riir-ai). Use this format:

markdown
# Issue NNN: Cross-Repo GOAT/Gain Cherry-Pick Audit

## TL;DR
<one paragraph: how many stalls, which is strongest, what's the fix>

## Gap inventory (default-on in katgpt-rs, NOT cherry-picked)
| # | Primitive | Default-on since | riir-* status | Class |
|---|---|---|---|---|
| T1 | ... | ... | ... | TRUE GAP — fix |
| T2 | ... | ... | ... | Stall — defer |

## What IS wired (the strong half)
<list of consumed primitives, no action>

## Tasks
### Phase 1 — T1 <strongest stall>
- [ ] T1.1 ...
Step 6 — Commit + report

Per global AGENTS.md rule, commit on develop (no feature branches):

bash
git add .issues/NNN_cross_repo_goat_cherry_pick_audit.md
git commit -m "docs: file issue NNN — cross-repo GOAT cherry-pick audit (T1: <strongest stall>)"

Report to the user:

  • Total primitives audited (count of katgpt-rs default-on).
  • Stalls found (with days-since-promotion).
  • DRY violations (count of remaining crate::* substrate refs).
  • Top 3 priorities (strongest stalls with clear design intent).

Common false-positive patterns (DO NOT report as gaps)

  1. Feature-name-only grep miss — the primitive IS wired under a different name (struct/function). Always run the struct/function grep (Layer 2).
  2. Bench-only consumer is sufficient — some primitives (e.g. future_probe) ship as benches that validate the primitive; runtime wiring waits for the gate to pass. Mark "Too fresh" not "Stall".
  3. Meta-discipline validators — claim_rubric is CI-time only by design. Its claim_rubric_bridge.rs doc-comment says so explicitly. Don't flag.
  4. Opt-in by design — closed_unit_compaction is opt-in because compaction is a sleep-cycle op, not hot path. Don't flag unless the opt-in reason is stale.
  5. Cross-repo transitively — subspace_phase_gate is consumed via riir-neuron-db's freeze gate even though riir-ai runtime doesn't call the diagnostic directly. Mark "Partial" not "Stall".
  6. Fork-drift false WIRED (Issue 019 class) — Layer 2 struct-name grep hits a file, but Layer 3 reveals the file has zero use katgpt_*:: imports and defines its own pub struct SameName. The primitive is NOT wired — it's locally re-implemented. Report as Fork drift (file de-fork task), NOT as WIRED. Without Layer 3, the audit systematically under-counts substrate-side drift in fork-derived repos. Canonical case: riir-engine/src/transformer/mod.rs defined local KVCache/KVSnapshot/PAGE_SIZE while katgpt_transformer::{KVCache, KVSnapshot, PAGE_SIZE} shipped upstream (the dep was even declared in Cargo.toml but unused — grep "^use katgpt_transformer" returned 0 matches). Plan 406 Phase 1/2 de-forked these bit-identical and superset types. NOTE (Issue 420, 2026-07-09): a prior version of this example cited riir-engine/src/kvarn_quality.rs duplicating katgpt-kv::kvarn::KvCacheQualityReport — that was factually wrong (katgpt-kv ships no such type); the riir-engine KvCacheQualityReport is a legitimately local ThinkingController abstraction, not fork drift.
  7. Substrate-via-derivative consumer (Issue 532 T2 class, 2026-07-18) — a substrate primitive IS wired in riir-, but only transitively via a derivative primitive. smooth_min_similarity is substrate for recos (recos implies smooth_min_similarity); riir-neuron-db's recos_rerank calls recos_sim_ranking, which compiles + uses smooth_min_similarity transitively. A Layer 2 grep for smooth_min returns 20+ katgpt-rs-side hits and the riir-neuron-db consumer (using the recos_sim_ranking alias) hides on a later page. The audit verdicted "0 consumers in riir-" — wrong. Mitigation: when a substrate primitive has derivative primitives that depend on it (read the feature implications in crates/katgpt-core/Cargo.toml), grep for the derivatives' exported names too, not just the substrate's own names. Same failure class as #1 (feature-name-only grep miss) but harder to spot because the alias lives in katgpt-rs, not riir-*.
  8. Data-contract consumption (Issue 532 method note, 2026-07-17) — a primitive is consumed via a sync-boundary data contract, NOT via a use katgpt_*:: import. The primitive's output shape (e.g. η ∈ R^P weights) crosses the sync boundary (chain quorum commit) as a sidecar receipt; the consumer (e.g. riir-chain) reads the committed bytes, not the Rust type. A Layer 2 grep for use katgpt_*:: returns 0 matches → false STALL verdict. Mitigation: when a primitive produces raw synced values, check whether the consumer reads the committed sidecar bytes (Issue 003 T3-T7 pattern) rather than importing the type. The primitive's output shape IS the load-bearing contract — consumption is via byte-level agreement, not Rust-level import.
Show full SKILL.md (1,292 more words)Show less

The 7-day rule (when a stall becomes actionable)

  • < 7 days default-on: Too fresh. Note in audit but don't file an issue.
  • 7–14 days default-on: Stall. File issue with wiring plan.
  • > 14 days default-on: Critical stall. File issue + flag for the next standup.

The 7-day window gives the open primitive time to land its bench evidence before the runtime wiring is expected. It mirrors the "promote-or-demote within one cycle" discipline.

Cross-references

  • katgpt-rs/AGENTS.md — Feature Flag Discipline (the GOAT gate contract).
  • katgpt-rs/.agents/skills/research/SKILL.md — research workflow (paper → 7-repo routing).
  • riir-ai/.issues/003_cross_repo_goat_cherry_pick_audit.md — the canonical audit (2026-07-03). Compromised by the Layer 3 gap — substrate-side primitives marked WIRED in this audit need re-verification per Issue 019.
  • riir-ai/.issues/019_riir_engine_substrate_de_fork.md — the LLM-substrate de-fork plan (2026-07-04). Documents the fork-drift failure class and the Layer 3 fix.
  • katgpt-rs/.plans/008_katgpt_core_substrate_extraction.md — the cross-repo DRY closure record (cognitive substrate: hla/types/tokenizer/dd_tree).
  • riir-ai/.issues/532_cross_repo_goat_cherry_pick_audit.md — the 2026-07-17 audit (Phase 1 HLA de-fork + Phase 2 watch list T2-T9 all resolved). File removed per noise-reduction rule; the method-note lessons (paginated grep, data-contract consumption) are preserved as false-positive patterns #7 + #8 above.
  • 2026-10-07 delta pass (8th run) — EMPTY, no issue filed (noise-reduction rule). Scope: default-list delta since the 09-24 pass — exactly one promotion: fitted_v_reconstruct (2026-10-05 34145bfd5, the pre-registered window-edge rule re-fired, riir-infer Bench 017), Layer 3 CONSUMER verified in riir-infer src/transformer/gemma2_vrecon.rs (katgpt_core::position_group_action::PositionGroupAction + the VReadPath/reconstruct_v_from_rope_k selector over the gemma-2 f16 decode path) — consumer-bearing at promotion, third consecutive wired-at-promotion landing; 2 days old = Too fresh, no stall clock; the product-set grep (ai/chain/ndb) correctly returns zero — decode-lane KV primitives route through riir-infer, not the three runtime repos (the skill's standing caveat about out-of-scope consumers). The overdue 09-24 re-check window (slt/slt_sweep ≥7-day consumer-regression, due 10-01) DISCHARGED: all four standing consumers re-verified intact — slt via riir-games swarm/mb_personality.rs (bayes_gap + sigmoid_wbic_weight), slt_sweep via riir-neuron-db consolidation/free_energy_ledger.rs (use katgpt_core::slt::sweep:: + from_rank_verified), hmm_homeostasis via riir-engine mop_runtime/homeostat.rs, slice_tca/bmr via latent_functor/reestimation/ + cgsp_runtime/evpi_gate.rs. Zero regressions, zero new opt-ins needing clocks (entropy_bounded_commit 917, lattice_memory Plan 619, bias_delta 920, gmm_support Plan 618 — all opt-in, no promotion). Next actionable window: the next promotion, or fitted_v_reconstruct ≥7-day re-check (10-12).
  • 2026-09-24 delta pass (7th run) — 1 stall found, filed + RESOLVED same-day (riir-neuron-db Issue 624, landed 381f061 there; noise-reduction-removed, record in its HISTORY.md). Scope: default-list delta since the 09-14 pass — exactly two promotions: slt + slt_sweep (2026-09-15, Issues 781/782, Benches 764/765; core default 200 → 202), and the matured re-checks. Verdict: 4 of 5 wired — slt via riir-ai mb_personality.rs (bayes_gap + sigmoid_wbic_weight, Issue 956) AND riir-neuron-db free_energy_ledger.rs (rlct_reduced_rank + free_energy, Issue 620); hmm_homeostasis (14d) + slice_tca/bmr (12d) consumers re-verified standing; distance_abstain (09-21) opt-in + wired at landing (riir-reflex engine.rs CorpusDistanceGate) — no clock. 1 stall: slt_sweep (9d, zero consumers) — filed with a wiring plan in riir-neuron-db (the natural freeze/consolidation-seam owner) and landed same day as FreeEnergyLedger::from_rank_verified (planted-rank witness sweep, ledger λ stays closed-form) + from_measured. Measured en route: the estimator's λ ≳ 3 sample-starvation bound (Bench 765) reproduced as a MONOTONE deepening in this repo's own consumer gate — (3,3,1) −5.2% → (3,3,2) −30.2% → (8,8,4) −67.9% at λ=24; full-matrix (λ=d/2) callers must stay on the closed form. Next actionable window: the next promotion, or slt/slt_sweep ≥7-day consumer-regression re-check (10-01).
  • 2026-09-14 delta pass (6th run) — EMPTY, no issue filed (noise-reduction rule). Scope: default-list delta since the 09-11 pass — exactly one promotion: slice_tca + bmr (Phase 31, 2026-09-12 54bf63bf; Benches 714+715, both pure modelless math, core default 198 → 200), and BOTH carry Layer 3 CONSUMERS already: bmr via riir-poc/src/rule_discovery_poc.rs + crates/riir-poc/tests/scientist_npc_bmr_poc.rs (use katgpt_core::bmr::{occam_log_bayes_factor, Counts, EfeScratch, ModelSpace}) + riir-engine cgsp_runtime/evpi_gate.rs (the EFE-over-models third tier); slice_tca via riir-engine/latent_functor/reestimation/tests_covariability_drift.rs (use katgpt_core::slice_tca::{ROUTE_ALPHA, ROUTE_THETA}) + the reestimation/mod.rs routing-constants consume — consumer-bearing at promotion, the second consecutive wired-at-promotion landing. 1.7 days old = Too fresh, no stall clock. Issue 771's radix_prefix_cache landed deliberately OPT-IN (no production consumer — single-stream lanes; consumer note lives in riir-gpu qwen38_prefix_cache) — starts no clock. Next actionable window: hmm_homeostasis ≥7-day re-check (09-17), slice_tca/bmr ≥7-day re-check (09-19), or the next promotion.
  • 2026-09-11 delta pass (5th run) — EMPTY, no issue filed (noise-reduction rule). Scope: default-list delta since the 09-10 pass — exactly one promotion: hmm_homeostasis (Phase 30, 2026-09-10, owner call; Bench 704 + riir-ai 904/905/907), and Layer 3 CONSUMER verified in riir-engine/src/mop_runtime/homeostat.rs (use katgpt_core::hmm_control::{HmmControlSolver, HmmSolution} + structural solver: field + per-drive setpoint slots) — wired-at-promotion, the first promotion since the Issue 867 demotion to land with its runtime consumer in the same window; 1 day old = Too fresh regardless, no stall clock. New opt-ins (gw_alignment / karc_hebbian_readout / nonergodic_belief / saddle_escape / pca_dec) start no clocks; the karc_hebbian arc's ai-side consumer verified same-day by the substrate-first wave. Next actionable window: hmm_homeostasis ≥7-day re-check (09-17) or the next promotion.
  • 2026-09-10 delta pass (4th run) — EMPTY, no issue filed (noise-reduction rule). Scope: katgpt-core default-list delta since the 09-04 audit — zero new default-on promotions; the only new features are both opt-in (regime_probe Issue 740, leakage_probe Issue 736) and regime_probe already carries its first consumer (riir-clippy score_bench OOD axis, 0a9994fd) — no stall clocks started, nothing to audit beyond the 09-04 inventory, which cleared 10/10 + demoted similarity_inference. Method: default-list tail read (still ends at kinematic_rollout, the 09-04 state) + Phase-comment tail (newest = Phase 29, the 09-04 demotion itself). Next actionable window: a regime_probe/leakage_probe promotion, or the next quarterly gate.
  • 2026-09-04 audit (3rd run) — 1 critical stall filed (riir-ai Issue 867); RESOLVED same day. Scope: the 3 katgpt-core default-on promotions since the 08-15 pass (contrastive_scope 08-19, rating 08-25, kinematic_rollout 08-26) + the 5 too-fresh deferrals now matured. Verdict: 2 wired (rating via riir-games ruliology ParadigmRanking — production update_scored; drift_segment via riir-engine npc_episodic → civ salience gate, opt-in both sides), 1 critical stall (similarity_inference: 24 days default-on, ZERO consumers workspace-wide — coordinator-verified; wire-or-demote in Issue 867 T1) → T1 RESOLVED 2026-09-04: DEMOTED to opt-in (katgpt-rs e5fdbd35, Issue 867 T1.3) — all three wire candidates were gameplay-emergence owner calls; the compose-partner question answered (latent_cce_moderator enables katgpt-rs/cce_moderator, never similarity_inference); default lib surface 2004 → 1981 (−23). T2.1 also done same day: the 5th Elo copy (go_trust_region.rs) delegated to rating::update_scored, bit-identical (riir-ai 567ff35c3). T2.2 premise drift: kg_pkm_attention is now Issue 765's GOAT-benched opt-in-pending-consumer fix (sanctioned posture); latent_functor/pkm_bridge stays the one genuine zero-caller deletion candidate (owner call). 2026-09-11 deletion re-verdict: REVISE as scoped — zero external callers CONFIRMED workspace-wide (grep pkm_bridge over .rs/.toml/*.md = 8 files: self-refs, riir-ai .docs/02_crates/latent_functor.md, riir-ai HISTORY.md, this skill, the obsolete ai-perfwt copy), but the module lives in riir-ai crates/riir-engine/src/latent_functor/pkm_bridge.rs (+ mod.rs pub mod pkm_bridge;), NOT katgpt-rs — route the deletion to a riir-ai-scope session. 4 notes (contrastive_scope's consumer is riir-clippy only; kinematic_rollout's two designated PoCs both REFUTED their gameplay claims — non-adoption is defend-wrong-correct; self-spec acceptance is a config default exercised only via the FlashAR bench; the PkmEpisodicStore TF-IDF bridge idea for ndb's Bm25Index). Two run-premise corrections: FlashAR Eq 21 + PkmEpisodicStore TF-IDF are opt-in upstream (no stall clock). Upstream record drift found + fixed same day: the contrastive_scope lib.rs comment still said "Opt-in POC" post-promotion. Method note: the root-vs-core default-list diff must extract only up to the FIRST ] — a greedy sed that captures into the trailing Phase-comment text (which contains ] and commas) inflated the core default count 73→308 and hid the kinematic_rollout/contrastive_scope promotions from the first diff pass.
  • 2026-08-15 clean-pass audit (no issue filed — zero actionable findings, per the noise-reduction rule). Scope: all 10 katgpt-core primitives promoted default-on after the 2026-07-17 audit and ≥7 days old — poincare_navigator (07-18), chunked_content_store (07-18), causal_identification (07-18), conformal_predictive_intervals (07-20), karc_forecaster (07-21), hope_capacity (07-24), hebbian_kernel_memory (07-25), ane_fused_chain (07-14, borderline re-check), clr_weighted_set_attention (08-06), phase_separation (08-07). Method: Layers 1+2+3 via two parallel subagent greps across riir-ai/riir-chain/riir-neuron-db. Verdict: 10/10 WIRED, zero stalls, zero unintentional duplicates. Two default-on-strong (karc_forecaster via engine karc_runtime+npc_sleep_time; ane_fused_chain via npc_brain_router); eight opt-in consumers, all with Layer-3-verified use katgpt_core:: imports (chain neuron_vessel_cold_tier, neuron-db hope_bridge/hebbian_fact_store, games swarm tick_swarm_emotions_collective, engine causal_id/poincare_bridge/karc_bridge::conformal_sidecar/phase_separation_bridge). Partial-surface notes (no action — natural consumers don't exist yet): the conformal metrics suite (winkler_score/empirical_coverage/mean_crps/ResidualRingBuffer) and the content-store CDC/fetcher half (FastCdcChunker/TieredChunkFetcher/NetChunkFetcher/build_binary_merkle_*) are unconsumed; riir-gpu does not consume ane_roofline (its "roofline" hits are local GB/s bench helpers — an open opportunity, not drift). Deferred as too fresh for the next audit: similarity_inference (Bench 579, 08-11), katgpt-forward self-spec acceptance (Issue 587/Bench 634, 08-14), mop (opt-in — promotion is a product decision), drift_segment (katgpt-kv, 08-15), FlashAR Eq 21 (08-15), PkmEpisodicStore TF-IDF gate (08-15).

© katopz, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/goat-audit of katopz/katgpt-rs.

Open the folder on GitHubat commit 94a4da5

Compare with similar skills

Goat Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Goat Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Goat Audit this skillkatopz/katgpt-rs138—~7.9kAutomated safety check: PassMIT
Flutter Cherry Pickflutter/flutter179k—~1.8kAutomated safety check: PassBSD-3-Clause
Chatbox Pro Cherry-Pick Syncchatboxai/chatbox42k—~1.2kAutomated safety check: PassGPL-3.0
Cherry Studio Agent BrowserCherryHQ/cherry-studio53k—~1.2kAutomated safety check: PassAGPL-3.0
Cherry Pick PRkubernetes-sigs/cloud-provider-azure294—~636Automated safety check: PassApache-2.0
Cherry Skill MarketplaceCherryHQ/cherry-studio53k—~534Automated safety check: PassAGPL-3.0

Similar skills

  • Flutter Cherry Pick

    flutter/flutter

    How to land a formal cherry-pick of a merged PR for the flutter/flutter repo stable or beta channel.

    179k GitHub stars~1.8k tokensUpdated today
    MobileAuto-check passed
  • Cherry-picks commits from the chatbox-pro repo into the open chatbox repo, skipping mobile-only files and keeping the open package name.

    42k GitHub stars~1.2k tokensUpdated 16 days ago
    DevelopmentAuto-check passed
  • Cherry Studio Agent Browser

    CherryHQ/cherry-studio

    Operates the visible browser pane of a Cherry Studio Agent session through live browser tools: navigation, snapshots, screenshots, forms and clicks, verifying outcomes.

    53k GitHub stars~1.2k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Cherry Pick PR

    kubernetes-sigs/cloud-provider-azure

    Official

    Cherry-pick a merged pull request onto a release branch with Prow-style branch naming, manual conflict resolution, targeted validation, and GitHub PR creation.

    294 GitHub stars~636 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Cherry Skill Marketplace

    CherryHQ/cherry-studio

    Searches for, installs and helps create agent skills in Cherry Studio when you ask or when a built-in skill falls short, then returns to the original task.

    53k GitHub stars~534 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Cherry Studio Product Guide

    CherryHQ/cherry-studio

    Answers questions about Cherry Studio's features, routes, shortcuts and providers from the installed build's manifest, and diagnoses runtime problems.

    53k GitHub stars~494 tokensUpdated today
    Sales & SupportAuto-check passed

More from katopz/katgpt-rs

All 8 skills in this repo
  • Proposal

    katopz/katgpt-rs

    Write a reasoned architectural proposal (.proposals/NNN.md) grounded in focused codebase grep + prior-art paper search.

    138 GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Boundary Guard

    katopz/katgpt-rs

    Audit + enforce game-stack boundary rules across the multi-repo workspace.

    138 GitHub stars~11k tokensUpdated today
    Auto-check passed
  • Feature Gate Audit

    katopz/katgpt-rs

    Audit feature-gate status claims across the multi-repo stack.

    138 GitHub stars~6.2k tokensUpdated today
    Auto-check passed
  • Research

    katopz/katgpt-rs

    Research workflow for distilling ML/AI papers into modelless inference primitives, freeze/thaw runtime patterns, latent-space operations, AND model-based training plans across the multi-repo stack.

    138 GitHub stars~20k tokensUpdated today
    Auto-check passed
  • Rust Optimize

    katopz/katgpt-rs

    Optimize Rust code until nothing left to improve. An agent skill from katopz/katgpt-rs.

    138 GitHub stars~7k tokensUpdated today
    Auto-check passed
  • Substrate First

    katopz/katgpt-rs

    Pre-implementation DRY gate + existing-code drift audit for the multi-repo workspace.

    138 GitHub stars~18k tokensUpdated today
    Auto-check passed

Questions about Goat Audit

What does Goat Audit do?

Audit cross-repo GOAT/gain primitive cherry-pick status across the multi-repo stack (katgpt-rs upstream, riir- consumers). Goat Audit is an agent skill from katopz/katgpt-rs. Audit cross-repo GOAT/gain primitive cherry-pick status across the multi-repo stack (katgpt-rs upstream, riir- consumers).

When should I use Goat Audit?

Goat Audit fits situations like: auditing primitive cherry-pick coverage; before opening a plan that consumes a katgpt-rs primitive; quarterly as a hygiene gate.

How do I install Goat Audit in Claude Code?

Run `npx skills add katopz/katgpt-rs --skill goat-audit -a claude-code`. Or copy the skill folder (.agents/skills/goat-audit in katopz/katgpt-rs) into .claude/skills/goat-audit in your project. Claude Code loads it when a task matches its description.

How do I install Goat Audit in Codex?

Run `npx skills add katopz/katgpt-rs --skill goat-audit -a codex`. Or copy the skill folder (.agents/skills/goat-audit in katopz/katgpt-rs) into .agents/skills/goat-audit in your project. Codex loads it when a task matches its description.

Can I use Goat Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add katopz/katgpt-rs --skill goat-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/goat-audit, .gemini/skills/goat-audit, .github/skills/goat-audit and .opencode/skills/goat-audit in your project.

What does Goat Audit need to run?

Going by SKILL.md and its folder, Goat Audit needs the command-line tools its instructions call (git).

Does Goat Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Goat Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Goat Audit use?

Goat Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Goat Audit use?

About 7.9k tokens (SKILL.md is roughly 32k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Goat Audit?

Skills that share tags, products or a category with Goat Audit: Flutter Cherry Pick (flutter/flutter, 179k stars), Chatbox Pro Cherry-Pick Sync (chatboxai/chatbox, 42k stars), Cherry Studio Agent Browser (CherryHQ/cherry-studio, 53k stars) and Cherry Pick PR (kubernetes-sigs/cloud-provider-azure, 294 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Goat Audit?

katopz (a GitHub user) maintains it in katopz/katgpt-rs, which has 138 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 10, 2026.

Source: katopz/katgpt-rs on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.