Agent skill

Audit Infrastructure

by pikax in pikax/verter

Verter audit infrastructure — RequestAuditRecord, RequestKind variants, producer entry-points, AuditRequestRegistration lifecycle, HostAuditRuntime, NAPI/WASM bindings, BatchAuditAggregator

MITAuto-check passed

Install Audit Infrastructure

skills CLI
$ npx skills add pikax/verter --skill audit-infrastructure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pikax/verter audit-infrastructure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pikax/verter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-infrastructure .claude/skills/audit-infrastructure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-infrastructure
GitHub stars
113
Token cost
~8.4k tokens
SKILL.md length
3,010 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Verter audit infrastructure — RequestAuditRecord, RequestKind variants, producer entry-points, AuditRequestRegistration lifecycle, HostAuditRuntime, NAPI/WASM bindings, BatchAuditAggregator

  • Works in 4 steps: An LspAuditSession keyed by LspMethodTag… → The same explicit request_deadlines… → finalize_ok(payload) on success or RPC… → …
  • SKILL.md covers Architecture Overview —…, RequestAuditRecord Envelope, AuditedResult Carrier and Producer Entry-Points, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Infrastructure is an agent skill from pikax/verter. Verter audit infrastructure — RequestAuditRecord, RequestKind variants, producer entry-points, AuditRequestRegistration lifecycle, HostAuditRuntime, NAPI/WASM bindings, BatchAuditAggregator

Its SKILL.md is about 8.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with WebAssembly. The repository describes itself as: Fast Rust-powered compiler, semantic extraction, and LSP for component frameworks. The licence is MIT.

Example prompts

  • “/audit-infrastructure”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. An LspAuditSession keyed by LspMethodTag and RequestTargetIdentity (constructed via VerterHost::lsp_audit_begin). Registered URIs use the…
  2. The same explicit request_deadlines policy used when audit is disabled. Production defaults every request deadline to zero (unbounded)…
  3. finalize_ok(payload) on success or RPC error. audit_supersede is an observational latency SLO only: exceeding it emits telemetry but does…
  4. Optional drain to VERTER_LSP_AUDIT_TRACE_OUT (JSON-lines append, configurable via env var).

What it can do on your machine

Read from SKILL.md and the folder at commit 858624d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Infrastructure loads about 8.4k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 3,010 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~8.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pikax/verter at commit 858624d, republished under its MIT licence (© pikax). 3,010 words, ~8,416 tokens.

Download SKILL.mdSave it as .claude/skills/audit-infrastructure/SKILL.md (or your agent's skills folder).
name
audit-infrastructure
description
Verter audit infrastructure — RequestAuditRecord, RequestKind variants, producer entry-points, AuditRequestRegistration lifecycle, HostAuditRuntime, NAPI/WASM bindings, BatchAuditAggregator

Audit Infrastructure

Per-request observability for every public host entry-point: component-meta resolution, compile, semantic analysis, type resolution, workspace ops, LSP handlers, MCP tool invocations, and bundler-batch summaries. Each audited request produces one RequestAuditRecord envelope carrying timing, memory, store counters, scheduler attribution, per-file reads, optional semantic footprint, and a strongly-typed kind-specific payload.

For end-user API reference and debug workflows see docs/audit-footprint/.

Architecture Overview — Substrate Vs Session

Optional capture policy and availability

The binding REQUIRED / REQUIRED-budget / REQUIRED-lifetime / OPTIONAL policy, per-owner inventory format, default-off semantic-observe feature and generator constraints live in docs/arch/semantic-observe.md. Inventory files are crates/*/observe-inventory/*.md; extend the owning file, not a shared table. Required validity, budgets, diagnostic data and current occupancy/ownership charges remain independent of capture.

verter_audit::observe::CaptureAvailability::compiled() reports Unavailable when semantic-observe is off and Available when on. observe::capture returns None without calling its collector when off; it returns the collected payload when on, never fabricated zero metrics. ObserveMode supplies the uncaptured/captured vocabulary; root selection and existing audit-endpoint migration remain with the execution/consolidation owner. The feature currently implies legacy measurement gates without removing them. Integration tests in crates/verter_audit/tests/cases/observe_feature_closure.rs check resolver-2 production and dev-unified closures on host/WASM; run the audit tests both with and without --features semantic-observe.

Audit state is split between a leaf substrate crate (verter_audit) and the session crate (verter_session). verter_audit may depend only on verter_span plus ecosystem crates — never on verter_session or any other verter_* crate.

LayerCrateOwns
Substrate (DTOs + observer trait)verter_auditRequestAuditRecord, RequestTargetIdentity, RequestKind, RequestKindPayload, per-kind payload structs, AuditedResult<T, E> (audit-bearing execution carrier), AuditObserver trait, current_observer() TLS accessor, NoOpObserver, AuditConfig + AuditConsumerFilter, the StructuredAuditEvent enum + variant payloads (in verter_audit::origin_graph), AuditEvent counter hook, BatchAuditAggregator + AuditRecordSource, IncidentalFields masking trait, WALKER_DEPTH_CAP
Session (lifecycle + runtime)verter_sessionHostAuditRuntime, AuditRequestRegistration::{Active, Noop}, AuditRecordsStore, RequestContext (implements AuditObserver), RequestContextGuard, peak-RSS sampler thread, the per-request accumulator + footprint miner (audit endpoints why_loaded / why_instantiated read from the accumulator), LspAuditSession, audited entry-points (compile_with_audit, analyze_with_audit, resolve_type_with_audit, audit_workspace_op, audit_mcp_tool_call, get_component_meta_with_resolution)

Isolation enforced by: verter_audit_no_upward_deps guard (rejects any verter_* dep in verter_audit/Cargo.toml other than verter_span) and audit_substrate_isolation guard (rejects any use verter_* under crates/verter_audit/src/ other than verter_span).

RequestAuditRecord Envelope

Top-level record (crates/verter_audit/src/record.rs):

FieldTypeDescription
request_idu64 (decimal-string transport)Monotonic id stamped at the public entry-point. Unique per audited request
canonical_idStringLegacy compatibility projection: exact registered canonical, otherwise empty
target_identityOption<RequestTargetIdentity>Additive tagged identity: RegisteredCanonical(String), UnregisteredUri(String), or NotApplicable. New producers always emit Some; None is reserved for older serialized records
kindRequestKindDiscriminant naming the producer surface
parent_request_idOption<String>Correlation id for nested audited requests (sniffed from scheduler-side TLS slot at construction)
from_cachebooltrue when satisfied from warm result cache
timingsRequestTimingAuditPer-phase wall-clock timings (ms)
memoryRequestMemoryAuditRSS snapshots (before/after/delta + peak from sampler)
storeRequestStoreAuditGeneric store/view counters
footprintOption<RequestFootprintAudit>Semantic footprint (component-meta only, gated by HostConfig::footprint_capture)
schedulerOption<SchedulerAudit>Scheduler-side attribution at first dispatch (native only)
filesVec<FileAudit>Per-file attribution deduplicated by canonical id
waitsOption<WaitAudit>Lock + queue contention (gated by audit_timing_capture)
kind_payloadRequestKindPayloadStrongly-typed payload paired with kind
RequestKind Variants
VariantPayloadProducer
ComponentMetaComponentMetaPayloadVerterHost::get_component_meta_with_resolution
TypeResolutionTypeResolutionPayloadVerterHost::resolve_type_with_audit
SemanticAnalysisSemanticAnalysisPayloadVerterHost::analyze_with_audit
Compile { target: CompileTargetTag }CompilePayloadVerterHost::compile_with_audit / compile_with_audit_options
Workspace { op: WorkspaceOp }WorkspacePayloadVerterHost::audit_workspace_op
Lsp { method: LspMethodTag }LspRequestPayloadverter_lsp::audit_harness::run_with_audit (per LSP handler)
Mcp { tool: String }McpToolPayloadVerterHost::audit_mcp_tool_call
BundlerBatch { kind: BundlerKindTag }BundlerBatchPayloadBatchAuditAggregator::summarize
Custom { name: String }RequestKindPayload::NoneOpen-ended escape hatch
TypeInfoGraphTypeInfoGraphPayloadVerterHost::resolve_framework_surface_with_audit (the typeinfo graph wire envelope)
FlowReturnInferenceFlowReturnInferencePayloadVerterHost::get_flow_return_type_with_audit
Typed Payload Accessors

RequestAuditRecord typed accessors (each returns None when kind_payload is not the matching variant):

  • component_meta_payload() -> Option<&ComponentMetaPayload>
  • type_resolution_payload() -> Option<&TypeResolutionPayload>
  • compile_payload() -> Option<&CompilePayload>
  • semantic_analysis_payload() -> Option<&SemanticAnalysisPayload>
  • workspace_payload() -> Option<&WorkspacePayload>
  • lsp_payload() -> Option<&LspRequestPayload>
  • mcp_payload() -> Option<&McpToolPayload>
  • bundler_batch_payload() -> Option<&BundlerBatchPayload>
  • typeinfo_graph_payload() -> Option<&TypeInfoGraphPayload>
  • flow_return_inference_payload() -> Option<&FlowReturnInferencePayload>
FlowReturnInference (U6 flow-return substrate)

RequestKind::FlowReturnInference audits the demand-sliced flow-return entry VerterHost::get_flow_return_type_with_audit(function, demand) (crates/verter_session/src/host_flow_return_audit.rs), which resolves ONE SemanticQueryKey::FlowReturn through the shared dispatch and returns AuditedResult<Arc<FlowReturnResult>, FlowReturnError> — the carrier's audit field is populated on BOTH arms. FlowReturnInferencePayload (crates/verter_audit/src/payloads/flow_return.rs) carries function_symbol, three per-request counters mirroring the cold-path structured events one to one, and the typed partiality reason:

CounterPaired structured eventBumped when
cold_computesFlowReturnStarteda cold whole-function flow evaluation runs (root + nested inline frames)
budget_exceeded_eventsFlowSliceBudgetExceeded { axis: FlowSliceBudgetAxisTag }a flow-slice budget refusal routes through ReturnOnly
cycle_reentry_holdsFlowCycleSentinelHita coinductive re-entry hold is recorded on the shared obligation runtime

The counters report THAT a request did cold work, hit a budget, or held on a cycle. partiality: Option<FlowPartialityTag> reports WHY it came back incomplete, and is None for the complete, warm-admissible outcome (and on the default-filled filtered / audit-disabled record, where no payload was collected at all):

ArmCarriesPopulated from
FlowPartialityTag::Degraded(FlowDegradationTag)the degraded-but-usable Ok outcome's reasonFlowReturnResult::degradation()
FlowPartialityTag::NoValue(FlowFailureTag)the Err outcome's no-value reasonthe typed FlowReturnError

partiality reports exactly ONE reason, never a set: the producer's typed outcome already reduced every observed gap to the FIRST in source order, so a function carrying several distinct gaps still names only the earliest. Read it as "the reason this request was partial", never as "the complete inventory of what is missing".

FlowDegradationTag and FlowFailureTag are CLOSED MIRRORS of the session's FlowReturnDegradation / FlowGap and FlowReturnFailure vocabularies, so the leaf audit substrate keeps no back-edge to verter_session. Both flatten their domain's nested closed enums — FlowReturnDegradation::FlowGap(_) reduces through the gap variant (GapGuardNarrowing, GapNominalRelation, GapClosureCapture, GapAbruptCompletion, GapUnmodeledExpression), and FlowReturnFailure's Unsupported / CallResolution / Budget arms reduce through their inner reason (UnsupportedLoop, CallUndecidable, BudgetWorkExceeded, …) — so every distinct reason keeps its own wire spelling instead of collapsing into a catch-all bucket. FlowFailureTag additionally carries UnstableState for the host's own FlowReturnError::UnstableState refusal, so the Err arm never reports an unexplained no-value.

The projection lives at the ONE producer, observed_partiality in crates/verter_session/src/host_flow_return_audit.rs, and maps through exhaustive matches (a new domain variant is a compile error, never a silently collapsed reason). It is READ-ONLY telemetry: it runs after the outcome is bound, and no admission decision, warm/cold classification, or cache identity reads it back.

Cold-vs-warm contract: a warm family hit emits NO FlowReturnStarted and bumps NO counter (cold_computes == 0 is the counter-side witness), and allocates no audit payload without an active accumulator. A degraded success never warms at all, so it reports its partiality on every call. Guards: crates/verter_session/tests/cases/g_type/flow_return_audit_contract.rs (cold/warm event + payload contract, the partial-vs-complete partiality contract, and the filter-driven projected-vs-unprojected equivalence — denying KindBit::FlowReturnInference takes the Noop arm and removes the projection outright, and the served value, degradation verdict and warm/cold sequence are unchanged) and crates/verter_session/tests/cases/g_misc0/flow_return_audit_tls_propagation.rs (TLS observer propagation across the dispatch's worker hops); the wire surface is pinned by crates/verter_audit/tests/cases/ts_bindings.rs.

AuditedResult<T, E> Carrier

AuditedResult<T, E> (crates/verter_audit/src/audited_result.rs) pairs the outcome — success T or typed error E — with the RequestAuditRecord captured while producing it. #[serde(tag = "kind")] discriminated enum (Ok { value, audit } / Err { error, audit }); both arms carry the record so the envelope survives regardless of outcome.

Lives in verter_audit, not verter_protocol: it is generic over T/E (protobuf cannot express) and embeds RequestAuditRecord — putting it in the protobuf-authoritative verter_protocol would invert the dependency or force a hand-written TS mirror. Rides the ts-rs path, exporting as export type AuditedResult<T, E> into packages/types/audit.generated.ts; packages/typeinfo imports the generated type. The typeinfo native session's _with_audit methods return AuditedResult<Arc<...>, TypeInfoRequestError>.

Surface: ok(value, audit) / err(error, audit) constructors; audit(), as_result(), into_parts(), into_result(), map(), map_err(). Home + export rule pinned by audited_result_lives_in_audit_and_exports_through_generated_ts (crates/verter_session/tests/cases/g_block/typeinfo_audit_contract_guards.rs).

Producer Entry-Points

Every public audited entry-point follows the same lifecycle: stamp a request id, build a RequestContext keyed by the matching RequestKind, construct an AuditRequestRegistration BEFORE installing the TLS guard, run the producer body under either RequestContextGuard (active) or install_noop_observer() (filtered), assemble the typed payload from per-request counters, and finalise through the registration. Filtered kinds short-circuit to None; the producer body always runs regardless of audit state.

Component-Meta

VerterHost::get_component_meta_with_resolution(canonical_id, mode) returns (Option<ComponentMetaAnalysis>, Option<ResolvedComponentMetaState>). The audit record is published into the host's bounded AuditRecordsStore and drained via HostAuditRuntime::take_record(request_id).

AuditedRequest builder (crates/verter_session/src/audited_request.rs) wraps one call in a request-scoped audit harness, resets per-thread counters, validates exactly one request was created, and returns (ComponentMetaAnalysis, ResolvedComponentMetaState, RequestAuditRecord) as a triple. AuditedRequestBuilder::resolve_component_meta is the test-facing convenience; AuditedRequestBuilder::run_custom lets a closure issue arbitrary single-request audited work.

Compile

VerterHost::compile_with_audit(canonical_id, target) -> (VerterCompileResult, Option<RequestAuditRecord>) and compile_with_audit_options(canonical_id, target, verter_options) for explicit force_vapor / force_js control. The target bitset maps to CompileTargetTag (Vdom, Ide, Vapor) on kind. Producer-side instrumentation in verter_compiler emits record_phase_timing at parse/transform/codegen/css_analysis/sourcemap boundaries and record_event(CompileCodeTransformOp) at every CodeTransform operation — the session-side RequestContext accumulates these into per-request atomics that assemble_compile_payload reads at finalize time.

Semantic Analysis

VerterHost::analyze_with_audit(canonical_id) -> (Option<AnalysisReady>, Option<RequestAuditRecord>). Probes FileArtifactStore cache before constructing the registration so from_cache is unaffected by audit work. Audit-disabled fast path runs materialize_analysis_ready with no RequestContextGuard.

Type Resolution

VerterHost::resolve_type_with_audit(query: SemanticQueryKey, canonical_hint: &str) -> (Option<TypeResolutionResult>, Option<RequestAuditRecord>). Drives one ProjectSemanticDispatch::execute(query) inside the audit window. TypeResolutionPayload reports the caller's projection mode (derived from the query variant) plus per-mode counters mined off the active RequestContext.

Workspace

VerterHost::audit_workspace_op(op: WorkspaceOp) -> RequestAuditRecord. Drives WorkspaceAccess::audit_op(op) under audit. Constructs the AuditRequestRegistration first so the registry slot precedes the workspace traversal. Returns the record unconditionally; Noop arm only suppresses the records-store side effect.

LSP

verter_lsp::audit_harness::run_with_audit(host, method, target_identity, position, body, populate) wraps each LSP handler future in:

  1. An LspAuditSession keyed by LspMethodTag and RequestTargetIdentity (constructed via VerterHost::lsp_audit_begin). Registered URIs use the registry's exact stored identity; request-before-registration uses the raw URI; NotApplicable is reserved for operations with no single document target.
  2. The same explicit request_deadlines policy used when audit is disabled. Production defaults every request deadline to zero (unbounded); audit never adds a feature/provider timeout.
  3. finalize_ok(payload) on success or RPC error. audit_supersede is an observational latency SLO only: exceeding it emits telemetry but does not cancel or alter the response. Explicit client cancellation may still finalize a session with finalize_cancelled() through the cancellation lifecycle.
  4. Optional drain to VERTER_LSP_AUDIT_TRACE_OUT (JSON-lines append, configurable via env var).

Audit-disabled fast path runs the body under the identical explicit request-deadline policy without registration cost. The audit-on and audit-off paths are therefore semantically equivalent.

Position-bound LSP payloads carry the same additive tagged identity in PositionInfo::target_identity. PositionInfo::canonical_id remains the legacy projection; an unregistered URI never becomes NotApplicable.

MCP

VerterHost::audit_mcp_tool_call(tool_name, canonical_id, args_size_bytes, f) -> (T, Option<RequestAuditRecord>) wraps a closure FnOnce(&Arc<Self>) -> McpToolOutcome<T> under audit. McpToolOutcome { value, result_size_bytes, error } carries the two facts the wrapper cannot infer (response size and optional error message). A non-empty canonical_id is tagged RegisteredCanonical; an empty value represents a tool with no single file target and is tagged NotApplicable while the retained legacy field stays empty. Sub-requests inherit the MCP request's id as parent_request_id via the scheduler-side TLS slot.

AuditRequestRegistration Lifecycle

Every audited entry-point allocates exactly one AuditRequestRegistration (crates/verter_session/src/host_audit_runtime.rs):

text
AuditRequestRegistration ::= Active(ActiveRegistration) | Noop
  • Active — captures a Weak<RequestContext> slot in HostAuditRuntime::active_requests. finalize(record) atomically removes the slot and publishes the record into AuditRecordsStore (idempotent — first call wins). Drop defensively sweeps the slot when finalize did not run (panic/cancellation paths).
  • Noop — returned when AuditConfig::consumer_filter rejects the request's RequestKind. Holds no state; finalize returns false and emits no record.

The three lifecycle methods on HostAuditRuntime (register_active_request, finalize_active_request, drop_active_request) are crate-private and have exactly ONE in-tree call site each, all in host_audit_runtime.rs. The audit_request_registration_lifecycle architecture guard mechanically enforces this.

Show full SKILL.md (1,252 more words)Show less

Substrate TLS — current_observer()

Lower crates emit audit signals through verter_audit::current_observer() -> Option<Arc<dyn AuditObserver>> (crates/verter_audit/src/observer.rs). Reads a thread-local slot installed by either RequestContextGuard::install (active) or install_noop_observer() (filtered).

AuditObserver trait carries default no-op implementations; producers override only what they care about:

  • record_event(event: AuditEvent) — counter-style attribution (InflightAbortedRetry, ColdAbortSwept, CompileCodeTransformOp).
  • record_cache_event(layer: &'static str, hit: bool) — per-layer hit/miss.
  • record_file(canonical_id, layer: VfsLayer, bytes_read, cache_hit) — workspace file read.
  • record_lock_acquisition(lock_name: &'static str, wait_ns: u64) — single lock acquisition wait.
  • record_phase_timing(phase: &'static str, elapsed_ms: f64) — phase-boundary timing.
  • record_scheduler_dispatch(audit: SchedulerAudit) — first-dispatch attribution (subsequent calls bump dispatch counter).

Session-side RequestContext provides full implementations; NoOpObserver leaves them defaulted. The audit_observer_single_accessor architecture guard enforces that the five lower crates (verter_compiler, verter_semantic, verter_workspace, verter_lsp, verter_mcp_server) reach audit state ONLY through verter_audit::current_observer() — the session-internal current_request_context() typed accessor is forbidden in those crates.

Consumer Filter (Install-Time)

AuditConfig::consumer_filter (crates/verter_audit/src/config.rs) is a u32 bitset deciding which RequestKind variants emit records. Bits are positionally stable via KindBit enum (ComponentMeta = 0, TypeResolution = 1, SemanticAnalysis = 2, Compile = 3, Workspace = 4, Lsp = 5, Mcp = 6, BundlerBatch = 7, Custom = 8, TypeInfoGraph = 9, FlowReturnInference = 10).

ConstructorBehaviour
AuditConsumerFilter::default() / allow_all()Allow every kind
deny_all()Reject every kind
allow_only([KindBit::…, …])Allow only the listed kinds
.allow(KindBit::…) / .deny(KindBit::…)Toggle a single bit (chainable)

Filter is read ONCE at registration time inside AuditRequestRegistration::new and CANNOT change for that request's lifetime. The current AuditConfig snapshot is mirrored from HostConfig flags in host_construction.rs (today only audit_timing_capture is wired; consumer filter defaults to allow-all). Tests that need a non-default filter swap the runtime's AuditConfig via a test-only helper without bypassing active_requests privacy.

HostAuditRuntime & Sampler Thread

HostAuditRuntime (crates/verter_session/src/host_audit_runtime.rs) mints and solely owns the host's AuditRecordsStore, and holds the AuditConfig snapshot and the active-request registry. Each VerterHost owns one independent runtime; multiple hosts in one process do NOT share audit state. The host keeps no second store handle and has no audit-record methods of its own: records publish through an AuditRequestRegistration or, for a read outside an audited entry-point, the crate-private publish_record; consumers drain with host_audit_runtime().take_record(id). Every record is keyed by an id from the host's one request-id counter (VerterHost::next_request_id) — there is no process-wide id counter, so an unregistered record can never land on, and replace, an audited record's id (audit_request_ids_share_one_host_key_space).

Public surface
  • audit_config() -> Arc<AuditConfig> — borrow the config snapshot.
  • audit_records_store() -> &Arc<AuditRecordsStore> — borrow the records store.
  • snapshot() -> AuditRuntimeSnapshot — read-only view of (active_request_count, active_request_ids, records_store_size, records_store_capacity).
  • take_record(request_id) -> Option<RequestAuditRecord> — drain a specific record.

audit_records_store is bounded — AUDIT_RECORDS_STORE_CAPACITY = 256. Insertion at capacity evicts the oldest entry by insertion order.

Peak-RSS sampler thread (native only)
  • Spawns lazily on the first AuditRequestRegistration::new call when AuditConfig::audit_timing_capture is on (single-shot start latch via compare_exchange).
  • Holds Arc<SamplerState> only — never Arc<HostAuditRuntime>. Runtime drop cannot land on the sampler thread.
  • Ticks every 50 ms; writes fetch_max(current_process_rss()) into each in-flight request's process_rss_peak_bytes slot.
  • Owner drop sends stop, unparks, and joins the sampler on the owner thread. Per-host observer state, not process-static join counters, discriminates spawn vs join.

WASM targets gated off via #[cfg(not(target_arch = "wasm32"))] — no sampler thread, process_rss_peak_bytes stays at 0 regardless of audit_timing_capture.

Architecture Guards

All live in crates/verter_session/tests/cases/architecture_guards.rs unless noted:

GuardRole
verter_audit_no_upward_depsverter_audit/Cargo.toml may declare only verter_span from the verter_* namespace
audit_substrate_isolationSource files under crates/verter_audit/src/ may use only verter_span, std, and external crates
audit_request_registration_lifecycleThe three lifecycle methods (register_active_request, finalize_active_request, drop_active_request) on HostAuditRuntime have exactly ONE in-tree caller each, all inside host_audit_runtime.rs
audit_observer_single_accessorThe five lower crates (verter_compiler, verter_semantic, verter_workspace, verter_lsp, verter_mcp_server) reach the substrate ONLY via verter_audit::current_observer() — current_request_context is forbidden
audit_no_hot_loop_instrumentationPhase-boundary instrumentation only; the canonical (crate, function_path) denylist forbids current_observer() calls inside hot-loop bodies
audit_counter_single_helperThe two record_inflight_aborted_retry / record_cold_abort_swept increments live in helper bodies only — no inline fetch_add callers anywhere else
wave_3_entry_points_propagate_tlsEach audited *_with_audit entry-point has at least one paired test that drives it AND calls assert_observer_reaches(...) so TLS propagation is mechanically verified
every_consumer_has_production_call_siteEvery RequestKind variant has at least one production producer under crates/*/src/ that constructs the variant in expression context (not match-arm pattern). Custom and BundlerBatch are documented exemptions in KIND_EXEMPTIONS
audit_ts_bindings_are_in_sync (in tests/cases/g_misc1/ts_bindings.rs)packages/types/audit.generated.ts matches what ts-rs would regenerate from current Rust DTOs

The general external_corpus_paths_not_present_outside_gated_tests guard applies across the workspace, including audit code, as does the review-enforced no-roadmap-archaeology rule.

TLS Propagation Coverage

wave_3_entry_points_propagate_tls pins one TLS-propagation driver per Wave-3 audited entry-point. Each driver invokes the production entry-point through assert_observer_reaches(...) and asserts the substrate observer is reachable inside the audited window AND that the calling thread's harness-installed guard remains visible after the nested entry-point guard drops:

Entry-pointPaired TLS driver
resolve_type_with_auditcrates/verter_session/tests/cases/g_type/type_resolution_audit_tls_propagation.rs
compile_with_auditcrates/verter_session/tests/cases/g_misc0/tls_harness_cross_crate.rs
analyze_with_auditcrates/verter_session/tests/cases/g_misc0/semantic_analysis_audit_tls_propagation.rs
audit_op (WorkspaceAccess trait method, driven via the host wrapper audit_workspace_op)crates/verter_session/tests/cases/g_misc0/workspace_audit_tls_propagation.rs
verter_lsp::audit_harness::run_with_auditcrates/verter_lsp/tests/cases/lsp_audit_tls_propagation.rs
audit_mcp_tool_callcrates/verter_session/tests/cases/g_misc0/mcp_audit_tls_propagation.rs

The guard's MISSING_TLS_TEST allow-list is empty: every Wave-3 entry-point is paired. Adding a new audited entry-point requires landing a paired TLS driver in the same change and pinning the pair into WAVE_3_ENTRY_POINTS; the stale-allow-list check rejects an unpaired entry that has a TLS driver already.

NAPI / WASM Bindings

JS exportRust bindingReturns
getComponentMetaWithAuditMetaSession::get_component_meta_with_auditBuffer (JSON { payload, audit })
compileWithAuditVerterHost::compile_with_auditBuffer (JSON record)
analyzeWithAuditVerterHost::analyze_with_auditBuffer (JSON record)
resolveTypeWithAuditVerterHost::resolve_type_with_auditBuffer (JSON record)
auditWorkspaceOpVerterHost::audit_workspace_opBuffer (JSON record)
getLastAuditRecorddrains the most recent record from AuditRecordsStoreBuffer (JSON record or empty)
getAuditRecords({ kind?, sinceRequestId?, limit? })non-destructive filtered queryBuffer (JSON array)
getBundlerBatchSummary({ kind?, sinceRequestId? })invokes BatchAuditAggregator over the storeBuffer (JSON BundlerBatchPayload)

NAPI bindings: crates/verter_napi/src/audit.rs (helper types + decoders) and inline #[napi] impl NapiVerterHost in crates/verter_napi/src/lib.rs. WASM bindings: crates/verter_wasm/src/audit.rs + crates/verter_wasm/src/lib.rs. All exports return Buffer (JSON UTF-8 payload) for parity with the original getComponentMetaWithAudit contract; consumers decode against @verter/types/audit.generated.ts.

BatchAuditAggregator

BatchAuditAggregator (crates/verter_audit/src/batch.rs) folds an AuditRecordSource into a BundlerBatchPayload. The substrate stays leaf — the aggregator depends only on the trait callback contract:

text
trait AuditRecordSource {
    fn for_each_record(&self, f: &mut dyn FnMut(Instant, &RequestAuditRecord));
}

AuditRecordsStore implements AuditRecordSource; non-destructive iteration exposes each record with its insertion Instant. BatchAuditAggregator::summarize(since) partitions by RequestKind, accumulates total duration, total bytes parsed, from_cache_count, and cache_hit_rate, and tracks the top-SLOWEST_RECORD_LIMIT (= 5) slowest records as SlowRecordSummary entries. Each slow summary carries the additive target_identity alongside the retained legacy canonical_id; CLI rendering reads the tag and falls back to the legacy field only when the source record predates the tag. Empty sources yield a zeroed payload with no division-by-zero on cache_hit_rate.

since filters records inserted strictly after the supplied Instant. Bundler integrations call summarize(Some(last_summary_instant)) on every flush so each batch reports only work since the last call.

Tests & TLS-Propagation Harness

verter_session::tests::audit_tls_harness::assert_observer_reaches(install_audit, f) is the primary verification primitive for TLS propagation. Runs the closure under either a RequestContextGuard (install_audit = true) or no guard (install_audit = false, the control case), records whether verter_audit::current_observer().is_some() was visible on the calling thread, and exposes a WorkerSinkHandle so workers spawned inside the closure can report their own observation via report_worker_observer_presence.

Worker threads spawned bare via std::thread::spawn get a fresh TLS slot by construction. Closures needing observer propagation into a worker pool must either install the guard again on the worker or rely on a runtime that plumbs RequestContextGuard through to its workers (the production scheduler does this for its rayon pool).

The wave_3_entry_points_propagate_tls guard pins the (entry_point_symbol, paired_test_files) invariant — every *_with_audit entry-point has at least one test that both invokes the symbol AND calls assert_observer_reaches(...). Tests living in crates/verter_session/tests/cases/g_misc0/tls_harness_in_crate.rs, tls_harness_cross_crate.rs, and semantic_analysis_audit_tls_propagation.rs exercise the harness across in-crate, cross-crate, and analysis-specific propagation.

Key Files

FileRole
crates/verter_audit/src/lib.rsSubstrate root + re-exports
crates/verter_audit/src/record.rsRequestAuditRecord, RequestTargetIdentity, RequestKind, RequestKindPayload, IncidentalFields
crates/verter_audit/src/observer.rsAuditObserver trait, current_observer(), install_observer guard
crates/verter_audit/src/noop.rsNoOpObserver, install_noop_observer()
crates/verter_audit/src/config.rsAuditConfig, AuditConsumerFilter, KindBit
crates/verter_audit/src/payloads/Per-RequestKind payload data structs
crates/verter_audit/src/batch.rsBatchAuditAggregator, AuditRecordSource, SLOWEST_RECORD_LIMIT
crates/verter_session/src/host_audit_runtime.rsHostAuditRuntime, AuditRequestRegistration, sampler thread
crates/verter_session/src/component_meta_audit/audit_records_store.rsAuditRecordsStore, capacity = 256
crates/verter_session/src/audited_request.rsAuditedRequest builder + run-custom harness
crates/verter_session/src/host_compile_audit.rsVerterHost::compile_with_audit
crates/verter_session/src/host_analyze_audit.rsVerterHost::analyze_with_audit
crates/verter_session/src/host_resolve_type_audit.rsVerterHost::resolve_type_with_audit
crates/verter_session/src/host_workspace_audit.rsVerterHost::audit_workspace_op
crates/verter_session/src/host_mcp_audit.rsVerterHost::audit_mcp_tool_call, McpToolOutcome
crates/verter_session/src/host_lsp_audit.rsLspAuditSession, lsp_audit_begin
crates/verter_lsp/src/audit_harness.rsrun_with_audit, payload_with_position, drain_to_trace_out
crates/verter_session/src/tests/audit_tls_harness.rsassert_observer_reaches, WorkerSinkHandle, report_worker_observer_presence
crates/verter_napi/src/audit.rs + crates/verter_napi/src/lib.rsNAPI typed entry-points
crates/verter_wasm/src/audit.rs + crates/verter_wasm/src/lib.rsWASM typed entry-points
packages/types/audit.generated.tsTS bindings (regenerated via ts-rs)

© pikax, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/audit-infrastructure of pikax/verter.

Open the folder on GitHubat commit 858624d

Compare with similar skills

Audit Infrastructure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Infrastructure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Infrastructure this skillpikax/verter113—~8.4kAutomated safety check: PassMIT
RuView CLI, API and WASMruvnet/RuView97k—~1.2kAutomated safety check: NotesMIT
Nginx To Higress Migrationhigress-group/higress9.5k—~3.9kAutomated safety check: PassApache-2.0
Update V86felixrieseberg/windows9524k—~1.7kAutomated safety check: PassCustom licence
Dotlottie WebLottieFiles/dotlottie-web892—~3.5kAutomated safety check: PassMIT
Adding Internal API RouteTriliumNext/Trilium38k—~3.3kAutomated safety check: PassAGPL-3.0

Similar skills

  • Covers the RuView `wifi-densepose` command line binary, its Axum REST API and the WebAssembly builds for browsers and ESP32, for embedding or scripting RuView.

    97k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Nginx To Higress Migration

    higress-group/higress

    Migrate from ingress-nginx to Higress in Kubernetes environments.

    9.5k GitHub stars~3.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Update V86

    felixrieseberg/windows95

    Build and install v86 (wasm + libv86.js + BIOS) into windows95.

    24k GitHub stars~1.7k tokensUpdated 28 days ago
    Testing & QAAuto-check passed
  • Dotlottie Web

    LottieFiles/dotlottie-web

    Implement Lottie animations using dotLottie runtimes (@lottiefiles/dotlottie-web and @lottiefiles/dotlottie-react).

    892 GitHub stars~3.5k tokensUpdated 2 days ago
    Media & CreativeAuto-check passed
  • Adding Internal API Route

    TriliumNext/Trilium

    A skill your agent uses when adding, moving, or wiring an internal REST endpoint in Trilium (a new /api/ route) — choosing between a core-shared handler (packages/trilium-core/src/routes/index.ts…

    38k GitHub stars~3.3k tokensUpdated today
    Testing & QAAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated today
    SecurityAuto-check passed

More from pikax/verter

All 14 skills in this repo
  • Debug Tooling

    pikax/verter

    In-process backtrace watchdog + LLDB attach wrapper + release-dbg profile for diagnosing hangs and slow paths in Verter benches and binaries on Windows / macOS / Linux.

    113 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Agent Prompts

    pikax/verter

    Generate copy-pasteable prompts for driving separate Claude Code sessions through refactor, review, or migration work.

    113 GitHub stars~5k tokensUpdated today
    Auto-check: warnings
  • Build dependency chains, rebuild sequences, profiling with MCP, and Analysis MCP server setup for Verter

    113 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Compiler Codegen

    pikax/verter

    Rust compiler pipeline, template codegen (VDOM/IDE), CodeTransform, cached directives, strict slots, IDE error recovery, style preprocessing, CompileTarget, compiler authority/policy/demand/admission

    113 GitHub stars~23k tokensUpdated today
    Auto-check passed
  • CTO/manager-of-managers methodology for autonomous multi-train plans where the user says "you are the MoM/CTO", "orchestrate the whole plan", "drive the migration end-to-end", "manager-of-managers"…

    113 GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Rust Performance

    pikax/verter

    Rust performance optimization patterns: batch operations, allocation hierarchy, object pooling, CodeTransform API for vertercompiler

    113 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Works with

Questions about Audit Infrastructure

What does Audit Infrastructure do?

Verter audit infrastructure — RequestAuditRecord, RequestKind variants, producer entry-points, AuditRequestRegistration lifecycle, HostAuditRuntime, NAPI/WASM bindings, BatchAuditAggregator. Audit Infrastructure is an agent skill from pikax/verter.

How do I install Audit Infrastructure in Claude Code?

Run `npx skills add pikax/verter --skill audit-infrastructure -a claude-code`. Or copy the skill folder (.claude/skills/audit-infrastructure in pikax/verter) into .claude/skills/audit-infrastructure in your project. Claude Code loads it when a task matches its description.

How do I install Audit Infrastructure in Codex?

Run `npx skills add pikax/verter --skill audit-infrastructure -a codex`. Or copy the skill folder (.claude/skills/audit-infrastructure in pikax/verter) into .agents/skills/audit-infrastructure in your project. Codex loads it when a task matches its description.

Can I use Audit Infrastructure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pikax/verter --skill audit-infrastructure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-infrastructure, .gemini/skills/audit-infrastructure, .github/skills/audit-infrastructure and .opencode/skills/audit-infrastructure in your project.

What does Audit Infrastructure need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Infrastructure is instructions for the agent only.

Does Audit Infrastructure access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Infrastructure safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Infrastructure use?

Audit Infrastructure is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Infrastructure use?

About 8.4k tokens (SKILL.md is roughly 34k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Infrastructure?

Skills that share tags, products or a category with Audit Infrastructure: RuView CLI, API and WASM (ruvnet/RuView, 97k stars), Nginx To Higress Migration (higress-group/higress, 9.5k stars), Update V86 (felixrieseberg/windows95, 24k stars) and Dotlottie Web (LottieFiles/dotlottie-web, 892 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Infrastructure?

pikax (a GitHub user) maintains it in pikax/verter, which has 113 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 9, 2026.

Source: pikax/verter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.