Agent skill

Audit Thread

by nubjs in nubjs/nub

A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…

MITAuto-check passedDevelopment

Install Audit Thread

skills CLI
$ npx skills add nubjs/nub --skill audit-thread -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nubjs/nub audit-thread --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-thread .claude/skills/audit-thread && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-thread
GitHub stars
4.4k
Token cost
~1.8k tokens
SKILL.md length
587 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…

  • Works in 5 steps: Pin the reference target surgically.… → Empirical over source. A candidate is… → Cross-check the decision record.… → …
  • Running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar
  • SKILL.md covers The 5 gates, Orchestration shape and Dispatch template (every audit…
  • Calls git

What it does

Audit Thread is an agent skill from nubjs/nub. Use when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a flag surface). Encodes the hard gates that stop an audit from surfacing false positives. Auto-triggers on "audit", "compat audit", "parity audit", "find all the gaps", "what are we missing vs <tool".

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management. It works with pnpm and Git. The repository describes itself as: The fast all-in-one Node.js toolkit. The licence is MIT.

When your agent uses it

  • Running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar
  • A lockfile format
  • A Node behavior
  • A flag surface)

Example prompts

  • “compat audit”
  • “parity audit”
  • “find all the gaps”
  • “/audit-thread”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Pin the reference target surgically. State the EXACT major (e.g. pnpm 10) and VERIFY every reference checkout's version before reading it…
  2. Empirical over source. A candidate is not a finding until a differential fixture reproduces it by RUNNING the real pinned tool + nub on…
  3. Cross-check the decision record. Deprecated/removed flags, npm-isms nub rejects, the deliberate pnpm-compat divergences, and…
  4. Mandatory adversarial self-refutation. Fresh-context reviewer(s) try to REFUTE each surfaced finding by re-pinning, re-reproducing, and…
  5. Tier + deliverable. Opus at high+ effort for judgment AND refutation (a cheap tier may harvest breadth, but every item is Opus-verified)…

What it can do on your machine

Read from SKILL.md and the folder at commit 568e73a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Thread loads about 1.8k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 587 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nubjs/nub at commit 568e73a, republished under its MIT licence (© nubjs). 587 words, ~1,809 tokens.

Download SKILL.mdSave it as .claude/skills/audit-thread/SKILL.md (or your agent's skills folder).
name
audit-thread
description
Use when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a flag surface). Encodes the hard gates that stop an audit from surfacing false positives. Auto-triggers on "audit", "compat audit", "parity audit", "find all the gaps", "what are we missing vs <tool>".
metadata.internal
true

Audit threads

An audit's deliverable is a CLEAN, COMPLETE, VERIFIED list of real gaps between nub and a reference it claims parity with. A single false positive destroys trust in the whole audit; the bar is zero garbage.

Canonical methodology: AGENTS.md → "Audit threads." Read it first. This skill is the operational surface: the gate checklist, the verbatim dispatch template, and the orchestration shape.

The 5 gates

  1. Pin the reference target surgically. State the EXACT major (e.g. pnpm 10) and VERIFY every reference checkout's version before reading it (git -C .repos/<tool> describe --tags, its package.json version, the installed tool's --version). Wrong-major reference is the #1 garbage source. When the audit target is a branch/SHA of THIS repo, git fetch origin FIRST and pin origin/<branch>@<sha> — never a local worktree/branch checkout, which routinely lags origin. Verify reachability (git merge-base --is-ancestor <sha> origin/<branch>) before reading a byte.
  2. Empirical over source. A candidate is not a finding until a differential fixture reproduces it by RUNNING the real pinned tool + nub on identical input and diffing. Source and --help reading yield leads only.
  3. Cross-check the decision record. Deprecated/removed flags, npm-isms nub rejects, the deliberate pnpm-compat divergences, and already-decided/already-built work are NOT findings. Filter against AGENTS.md "Core design positions", wiki/ decision docs, and prior thread notes.
  4. Mandatory adversarial self-refutation. Fresh-context reviewer(s) try to REFUTE each surfaced finding by re-pinning, re-reproducing, and re-checking the decision record. They must also challenge any claim that a gap is irreducible by exhausting the mechanism's documented alternatives and testing plausible closures. Default to refuted when uncertain. Surface only survivors, each with reproduction evidence; never forward the raw breadth-pass output.
  5. Tier + deliverable. Opus at high+ effort for judgment AND refutation (a cheap tier may harvest breadth, but every item is Opus-verified). Thoroughness is two-dimensional: COVERAGE (enumerate the FULL surface from the pinned reference's own authoritative source) AND PRECISION (every item verified). Catalog → wiki/research/<topic>.md with all buckets explicit (real gaps / confirmed-OK / intentional-divergence); each finding records reproduction + decision-record cross-check + severity + confidence.
Show full SKILL.md (256 more words)Show less

Orchestration shape

Enumerate the full surface (coverage) → harvest candidate gaps → cross-check the decision record → reproduce each against the pinned real tool → adversarially refute in fresh context → surface ONLY survivors, with evidence.

Run it with individually-dispatched agents — not a blind parallel Workflow fan-out that buries the gates.

Only a top-level session dispatches those agents. If you are yourself a dispatched sub-agent, the repo-wide depth cap in AGENTS.local.md applies: run the gates INLINE and return. Gate 4's "fresh context" is then a fresh PASS, not a fresh agent — re-pin, re-run the fixture, and re-check the decision record yourself, defaulting to refuted when uncertain. An audit prong that cannot be refuted inline returns saying so rather than spawning a refuter.

When a finding is ACTIONED. An audit is investigation-scope: it surfaces gaps, it does not land fixes. The moment a finding becomes a code change, verify it the standard way — an ad-hoc fixture sweep against a built binary, re-running the audit's own differential against the pinned reference, then an in-thread read of the diff. A parity fix touching a shared verb/flag dispatch path routinely ripples to sibling commands, which is one of the cases that earns escalating to a fresh-context impact-analysis pass — but that never substitutes for running the sibling commands and diffing them against the reference. Gate 4 asks whether a FINDING is real; impact analysis asks whether a FIX is safe.

Dispatch template (every audit sub-agent prompt must be self-contained)

You are running a <SCOPE> audit: find where nub diverges from <REFERENCE> <EXACT MAJOR> on <SURFACE>.
This is an AUDIT — the deliverable is a CLEAN, VERIFIED list of REAL gaps. A single false positive is
unacceptable. Follow all 5 gates; do not skip any.

GATE 1 — PIN: The target is <REFERENCE> <EXACT MAJOR>. BEFORE reading anything, verify the version of
  every reference you use: `git -C .repos/<tool> describe --tags` and its package.json version, and
  `<tool> --version` for any installed binary. If a checkout is the wrong major, check out the right
  tag / install the right version FIRST. State the verified versions at the top of your output.
  If the AUDIT TARGET is a branch/SHA of THIS repo (not a reference tool): `git fetch origin` FIRST,
  pin `origin/<branch>@<sha>` (NEVER a local worktree/branch — it routinely lags origin), and verify
  `git merge-base --is-ancestor <sha> origin/<branch>` before reading. State the pinned SHA at the top.
GATE 2 — EMPIRICAL: A gap is NOT a finding until you reproduce it by RUNNING <REFERENCE> <MAJOR> AND nub
  on identical input and diffing the actual output. Source-reading and --help parsing are LEADS only.
  Build a minimal differential fixture per candidate; capture both commands + both outputs.
GATE 3 — DECISION RECORD: Drop any candidate that is a deprecated/removed flag in <REFERENCE> <MAJOR>,
  an npm-ism nub deliberately rejects, one of nub's intentional pnpm-compat divergences, or already
  decided/built. Cross-check AGENTS.md "Core design positions", wiki/ decision docs, and prior thread notes.
  Deeply evaluate what has ALREADY been discussed — surfacing a settled call is as bad as a false positive.
GATE 4 — REFUTE: After harvesting, re-verify every surviving candidate adversarially (try to REFUTE it:
  re-pin, re-reproduce, re-check the record). Treat "irreducible" or "cannot close" as claims that also
  require evidence: exhaust the documented mechanism surface and test plausible closures. Keep only
  what survives, with its reproduction evidence.
GATE 5 — COVERAGE + PRECISION: Enumerate the FULL surface from <REFERENCE> <MAJOR>'s own authoritative
  source (its --help / source), so nothing is missed; AND verify every surfaced item. Output ALL buckets:
  real gaps / confirmed-OK / intentional-divergence. Each real finding: reproduction command + both
  outputs + decision-record cross-check + severity + confidence.

Deliverable: a catalog at wiki/research/<topic>.md (all buckets) + a tight triaged list of REAL gaps for
the maintainer. Investigation-scope — do NOT land fixes; surface findings recommend-only.

When an audit reveals a NEW pitfall not covered above, fold it into the gate it strengthens.

© nubjs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/audit-thread of nubjs/nub.

Open the folder on GitHubat commit 568e73a

Compare with similar skills

Audit Thread next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Thread compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Thread this skillnubjs/nub4.4k—~1.8kAutomated safety check: PassMIT
Fix Vulnslinuxfoundation/insights280—~3.8kAutomated safety check: NotesMIT
React Router Release Notes Prepremix-run/react-router57k—~1.1kAutomated safety check: PassMIT
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Pnpm Engineteambit/bit18k—~1.9kAutomated safety check: PassCustom licence
Ghostty Submodule and GhosttyKit Workflowmanaflow-ai/cmux28k1 repos~580Automated safety check: PassCustom licence

Similar skills

  • Fix Vulns

    linuxfoundation/insights

    Automated triage and fixing of Dependabot security vulnerabilities (IN-1189).

    280 GitHub stars~3.8k tokensUpdated 6 days ago
    SecurityAuto-check: notes
  • React Router Release Notes Prep

    remix-run/react-router

    Polishes pending React Router change files before the versioning scripts run, and decides whether a long-form What's Changed section is warranted.

    57k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Workflow rules for the Ghostty submodule in cmux: rebuilding GhosttyKit.xcframework, pushing fork changes and updating the parent submodule pointer safely.

    28k GitHub starsUsed in 1 repo~580 tokens
    DevelopmentAuto-check passed
  • GitVersion .NET Development

    GitTools/GitVersion

    Gives repository-specific .NET guidance for GitVersion: build and test commands, central package management, project layout and coding conventions.

    3.1k GitHub stars~1.7k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from nubjs/nub

All 31 skills in this repo
  • Cpu Reduction

    nubjs/nub

    Diagnose and clear CPU, memory, and disk contention on the maintainer's dev host.

    4.4k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Reclaim disk on the maintainer's Mac when the volume is full or filling — ENOSPC, "no space left on device", a failed build or agent harness, or a routine sweep of Rust build residue.

    4.4k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Nub Charts

    nubjs/nub

    Build a performance chart for nubjs.com — the SVG bar figures in blog posts, docs pages and social posts (a runtime augmentation against plain node, an install or dispatch comparison, a cross-tool…

    4.4k GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Linux Vm Test

    nubjs/nub

    Run ad-hoc Nub tests and debugging probes on real local Linux guests.

    4.4k GitHub stars~986 tokensUpdated today
    Auto-check passed
  • Performance-trace Nub package-manager installs using the existing phase timings, structured diagnostics, and sampling-profiler workflow.

    4.4k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Rust Build

    nubjs/nub

    A skill your agent uses when building or testing the nub Rust workspace inside a git worktree — cargo build/test/clippy for nub-cli/nub-core/aube in a worktree off origin/main.

    4.4k GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Audit Thread

What does Audit Thread do?

A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…. Audit Thread is an agent skill from nubjs/nub. Use when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a flag surface).

When should I use Audit Thread?

Audit Thread fits situations like: running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar; A lockfile format; A Node behavior; A flag surface).

How do I install Audit Thread in Claude Code?

Run `npx skills add nubjs/nub --skill audit-thread -a claude-code`. Or copy the skill folder (.claude/skills/audit-thread in nubjs/nub) into .claude/skills/audit-thread in your project. Claude Code loads it when a task matches its description.

How do I install Audit Thread in Codex?

Run `npx skills add nubjs/nub --skill audit-thread -a codex`. Or copy the skill folder (.claude/skills/audit-thread in nubjs/nub) into .agents/skills/audit-thread in your project. Codex loads it when a task matches its description.

Can I use Audit Thread in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nubjs/nub --skill audit-thread -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-thread, .gemini/skills/audit-thread, .github/skills/audit-thread and .opencode/skills/audit-thread in your project.

What does Audit Thread need to run?

Going by SKILL.md and its folder, Audit Thread needs the command-line tools its instructions call (git).

Does Audit Thread access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Thread safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Thread use?

Audit Thread is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Thread use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Thread?

Skills that share tags, products or a category with Audit Thread: Fix Vulns (linuxfoundation/insights, 280 stars), React Router Release Notes Prep (remix-run/react-router, 57k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars) and Pnpm Engine (teambit/bit, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Thread?

nubjs (a GitHub organization) maintains it in nubjs/nub, which has 4,370 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 7, 2026.

Source: nubjs/nub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.