RuView CLI, API and WASM
ruvnet/RuView
Covers the RuView `wifi-densepose` command line binary, its Axum REST API and the WebAssembly builds for browsers and ESP32, for embedding or scripting RuView.
Verter audit infrastructure — RequestAuditRecord, RequestKind variants, producer entry-points, AuditRequestRegistration lifecycle, HostAuditRuntime, NAPI/WASM bindings, BatchAuditAggregator
$ npx skills add pikax/verter --skill audit-infrastructure -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install pikax/verter audit-infrastructure --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/pikax/verter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-infrastructure .claude/skills/audit-infrastructure && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-infrastructure" agent skill from https://github.com/pikax/verter/tree/main/.claude/skills/audit-infrastructure into .claude/skills/audit-infrastructure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-infrastructure", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/pikax/verter/tree/main/.claude/skills/audit-infrastructureType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add pikax/verter --skill audit-infrastructure -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install pikax/verter audit-infrastructure --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pikax/verter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/audit-infrastructure .agents/skills/audit-infrastructure && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-infrastructure" agent skill from https://github.com/pikax/verter/tree/main/.claude/skills/audit-infrastructure into .agents/skills/audit-infrastructure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-infrastructure", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pikax/verter --skill audit-infrastructure -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install pikax/verter audit-infrastructure --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pikax/verter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/audit-infrastructure .cursor/skills/audit-infrastructure && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-infrastructure" agent skill from https://github.com/pikax/verter/tree/main/.claude/skills/audit-infrastructure into .cursor/skills/audit-infrastructure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-infrastructure", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/pikax/verter.git --path .claude/skills/audit-infrastructure--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add pikax/verter --skill audit-infrastructure -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install pikax/verter audit-infrastructure --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pikax/verter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/audit-infrastructure .gemini/skills/audit-infrastructure && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-infrastructure" agent skill from https://github.com/pikax/verter/tree/main/.claude/skills/audit-infrastructure into .gemini/skills/audit-infrastructure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-infrastructure", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install pikax/verter audit-infrastructureInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add pikax/verter --skill audit-infrastructure -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/pikax/verter.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/audit-infrastructure .github/skills/audit-infrastructure && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-infrastructure" agent skill from https://github.com/pikax/verter/tree/main/.claude/skills/audit-infrastructure into .github/skills/audit-infrastructure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-infrastructure", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pikax/verter --skill audit-infrastructure -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install pikax/verter audit-infrastructure --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pikax/verter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/audit-infrastructure .opencode/skills/audit-infrastructure && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-infrastructure" agent skill from https://github.com/pikax/verter/tree/main/.claude/skills/audit-infrastructure into .opencode/skills/audit-infrastructure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-infrastructure", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-infrastructureVerter audit infrastructure — RequestAuditRecord, RequestKind variants, producer entry-points, AuditRequestRegistration lifecycle, HostAuditRuntime, NAPI/WASM bindings, BatchAuditAggregator
Audit Infrastructure is an agent skill from pikax/verter. Verter audit infrastructure — RequestAuditRecord, RequestKind variants, producer entry-points, AuditRequestRegistration lifecycle, HostAuditRuntime, NAPI/WASM bindings, BatchAuditAggregator
Its SKILL.md is about 8.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with WebAssembly. The repository describes itself as: Fast Rust-powered compiler, semantic extraction, and LSP for component frameworks. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 858624d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Audit Infrastructure loads about 8.4k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 3,010 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from pikax/verter at commit 858624d, republished under its MIT licence (© pikax). 3,010 words, ~8,416 tokens.
.claude/skills/audit-infrastructure/SKILL.md (or your agent's skills folder).Per-request observability for every public host entry-point: component-meta resolution, compile, semantic analysis, type resolution, workspace ops, LSP handlers, MCP tool invocations, and bundler-batch summaries. Each audited request produces one RequestAuditRecord envelope carrying timing, memory, store counters, scheduler attribution, per-file reads, optional semantic footprint, and a strongly-typed kind-specific payload.
For end-user API reference and debug workflows see docs/audit-footprint/.
The binding REQUIRED / REQUIRED-budget / REQUIRED-lifetime / OPTIONAL policy,
per-owner inventory format, default-off semantic-observe feature and generator
constraints live in docs/arch/semantic-observe.md.
Inventory files are crates/*/observe-inventory/*.md; extend the owning file,
not a shared table. Required validity, budgets, diagnostic data and current
occupancy/ownership charges remain independent of capture.
verter_audit::observe::CaptureAvailability::compiled() reports Unavailable
when semantic-observe is off and Available when on. observe::capture
returns None without calling its collector when off; it returns the collected
payload when on, never fabricated zero metrics. ObserveMode supplies the
uncaptured/captured vocabulary; root selection and existing audit-endpoint
migration remain with the execution/consolidation owner. The feature currently
implies legacy measurement gates without removing them. Integration tests in
crates/verter_audit/tests/cases/observe_feature_closure.rs check resolver-2
production and dev-unified closures on host/WASM; run the audit tests both with
and without --features semantic-observe.
Audit state is split between a leaf substrate crate (verter_audit) and the session crate (verter_session). verter_audit may depend only on verter_span plus ecosystem crates — never on verter_session or any other verter_* crate.
| Layer | Crate | Owns |
|---|---|---|
| Substrate (DTOs + observer trait) | verter_audit | RequestAuditRecord, RequestTargetIdentity, RequestKind, RequestKindPayload, per-kind payload structs, AuditedResult<T, E> (audit-bearing execution carrier), AuditObserver trait, current_observer() TLS accessor, NoOpObserver, AuditConfig + AuditConsumerFilter, the StructuredAuditEvent enum + variant payloads (in verter_audit::origin_graph), AuditEvent counter hook, BatchAuditAggregator + AuditRecordSource, IncidentalFields masking trait, WALKER_DEPTH_CAP |
| Session (lifecycle + runtime) | verter_session | HostAuditRuntime, AuditRequestRegistration::{Active, Noop}, AuditRecordsStore, RequestContext (implements AuditObserver), RequestContextGuard, peak-RSS sampler thread, the per-request accumulator + footprint miner (audit endpoints why_loaded / why_instantiated read from the accumulator), LspAuditSession, audited entry-points (compile_with_audit, analyze_with_audit, resolve_type_with_audit, audit_workspace_op, audit_mcp_tool_call, get_component_meta_with_resolution) |
Isolation enforced by: verter_audit_no_upward_deps guard (rejects any verter_* dep in verter_audit/Cargo.toml other than verter_span) and audit_substrate_isolation guard (rejects any use verter_* under crates/verter_audit/src/ other than verter_span).
RequestAuditRecord EnvelopeTop-level record (crates/verter_audit/src/record.rs):
| Field | Type | Description |
|---|---|---|
request_id | u64 (decimal-string transport) | Monotonic id stamped at the public entry-point. Unique per audited request |
canonical_id | String | Legacy compatibility projection: exact registered canonical, otherwise empty |
target_identity | Option<RequestTargetIdentity> | Additive tagged identity: RegisteredCanonical(String), UnregisteredUri(String), or NotApplicable. New producers always emit Some; None is reserved for older serialized records |
kind | RequestKind | Discriminant naming the producer surface |
parent_request_id | Option<String> | Correlation id for nested audited requests (sniffed from scheduler-side TLS slot at construction) |
from_cache | bool | true when satisfied from warm result cache |
timings | RequestTimingAudit | Per-phase wall-clock timings (ms) |
memory | RequestMemoryAudit | RSS snapshots (before/after/delta + peak from sampler) |
store | RequestStoreAudit | Generic store/view counters |
footprint | Option<RequestFootprintAudit> | Semantic footprint (component-meta only, gated by HostConfig::footprint_capture) |
scheduler | Option<SchedulerAudit> | Scheduler-side attribution at first dispatch (native only) |
files | Vec<FileAudit> | Per-file attribution deduplicated by canonical id |
waits | Option<WaitAudit> | Lock + queue contention (gated by audit_timing_capture) |
kind_payload | RequestKindPayload | Strongly-typed payload paired with kind |
RequestKind Variants| Variant | Payload | Producer |
|---|---|---|
ComponentMeta | ComponentMetaPayload | VerterHost::get_component_meta_with_resolution |
TypeResolution | TypeResolutionPayload | VerterHost::resolve_type_with_audit |
SemanticAnalysis | SemanticAnalysisPayload | VerterHost::analyze_with_audit |
Compile { target: CompileTargetTag } | CompilePayload | VerterHost::compile_with_audit / compile_with_audit_options |
Workspace { op: WorkspaceOp } | WorkspacePayload | VerterHost::audit_workspace_op |
Lsp { method: LspMethodTag } | LspRequestPayload | verter_lsp::audit_harness::run_with_audit (per LSP handler) |
Mcp { tool: String } | McpToolPayload | VerterHost::audit_mcp_tool_call |
BundlerBatch { kind: BundlerKindTag } | BundlerBatchPayload | BatchAuditAggregator::summarize |
Custom { name: String } | RequestKindPayload::None | Open-ended escape hatch |
TypeInfoGraph | TypeInfoGraphPayload | VerterHost::resolve_framework_surface_with_audit (the typeinfo graph wire envelope) |
FlowReturnInference | FlowReturnInferencePayload | VerterHost::get_flow_return_type_with_audit |
RequestAuditRecord typed accessors (each returns None when kind_payload is not the matching variant):
component_meta_payload() -> Option<&ComponentMetaPayload>type_resolution_payload() -> Option<&TypeResolutionPayload>compile_payload() -> Option<&CompilePayload>semantic_analysis_payload() -> Option<&SemanticAnalysisPayload>workspace_payload() -> Option<&WorkspacePayload>lsp_payload() -> Option<&LspRequestPayload>mcp_payload() -> Option<&McpToolPayload>bundler_batch_payload() -> Option<&BundlerBatchPayload>typeinfo_graph_payload() -> Option<&TypeInfoGraphPayload>flow_return_inference_payload() -> Option<&FlowReturnInferencePayload>FlowReturnInference (U6 flow-return substrate)RequestKind::FlowReturnInference audits the demand-sliced flow-return
entry VerterHost::get_flow_return_type_with_audit(function, demand)
(crates/verter_session/src/host_flow_return_audit.rs), which resolves ONE
SemanticQueryKey::FlowReturn through the shared dispatch and returns
AuditedResult<Arc<FlowReturnResult>, FlowReturnError> — the carrier's
audit field is populated on BOTH arms. FlowReturnInferencePayload
(crates/verter_audit/src/payloads/flow_return.rs) carries
function_symbol, three per-request counters mirroring the cold-path
structured events one to one, and the typed partiality reason:
| Counter | Paired structured event | Bumped when |
|---|---|---|
cold_computes | FlowReturnStarted | a cold whole-function flow evaluation runs (root + nested inline frames) |
budget_exceeded_events | FlowSliceBudgetExceeded { axis: FlowSliceBudgetAxisTag } | a flow-slice budget refusal routes through ReturnOnly |
cycle_reentry_holds | FlowCycleSentinelHit | a coinductive re-entry hold is recorded on the shared obligation runtime |
The counters report THAT a request did cold work, hit a budget, or held
on a cycle. partiality: Option<FlowPartialityTag> reports WHY it came
back incomplete, and is None for the complete, warm-admissible outcome
(and on the default-filled filtered / audit-disabled record, where no
payload was collected at all):
| Arm | Carries | Populated from |
|---|---|---|
FlowPartialityTag::Degraded(FlowDegradationTag) | the degraded-but-usable Ok outcome's reason | FlowReturnResult::degradation() |
FlowPartialityTag::NoValue(FlowFailureTag) | the Err outcome's no-value reason | the typed FlowReturnError |
partiality reports exactly ONE reason, never a set: the producer's
typed outcome already reduced every observed gap to the FIRST in source
order, so a function carrying several distinct gaps still names only the
earliest. Read it as "the reason this request was partial", never as
"the complete inventory of what is missing".
FlowDegradationTag and FlowFailureTag are CLOSED MIRRORS of the
session's FlowReturnDegradation / FlowGap and FlowReturnFailure
vocabularies, so the leaf audit substrate keeps no back-edge to
verter_session. Both flatten their domain's nested closed enums —
FlowReturnDegradation::FlowGap(_) reduces through the gap variant
(GapGuardNarrowing, GapNominalRelation, GapClosureCapture,
GapAbruptCompletion, GapUnmodeledExpression), and
FlowReturnFailure's Unsupported / CallResolution / Budget arms
reduce through their inner reason (UnsupportedLoop, CallUndecidable,
BudgetWorkExceeded, …) — so every distinct reason keeps its own wire
spelling instead of collapsing into a catch-all bucket. FlowFailureTag
additionally carries UnstableState for the host's own
FlowReturnError::UnstableState refusal, so the Err arm never reports
an unexplained no-value.
The projection lives at the ONE producer,
observed_partiality in crates/verter_session/src/host_flow_return_audit.rs,
and maps through exhaustive matches (a new domain variant is a compile
error, never a silently collapsed reason). It is READ-ONLY telemetry: it
runs after the outcome is bound, and no admission decision, warm/cold
classification, or cache identity reads it back.
Cold-vs-warm contract: a warm family hit emits NO FlowReturnStarted and
bumps NO counter (cold_computes == 0 is the counter-side witness), and
allocates no audit payload without an active accumulator. A degraded
success never warms at all, so it reports its partiality on every call.
Guards:
crates/verter_session/tests/cases/g_type/flow_return_audit_contract.rs
(cold/warm event + payload contract, the partial-vs-complete partiality
contract, and the filter-driven projected-vs-unprojected equivalence —
denying KindBit::FlowReturnInference takes the Noop arm and removes
the projection outright, and the served value, degradation verdict and
warm/cold sequence are unchanged) and
crates/verter_session/tests/cases/g_misc0/flow_return_audit_tls_propagation.rs
(TLS observer propagation across the dispatch's worker hops); the wire
surface is pinned by crates/verter_audit/tests/cases/ts_bindings.rs.
AuditedResult<T, E> CarrierAuditedResult<T, E> (crates/verter_audit/src/audited_result.rs) pairs the outcome — success T or typed error E — with the RequestAuditRecord captured while producing it. #[serde(tag = "kind")] discriminated enum (Ok { value, audit } / Err { error, audit }); both arms carry the record so the envelope survives regardless of outcome.
Lives in verter_audit, not verter_protocol: it is generic over T/E (protobuf cannot express) and embeds RequestAuditRecord — putting it in the protobuf-authoritative verter_protocol would invert the dependency or force a hand-written TS mirror. Rides the ts-rs path, exporting as export type AuditedResult<T, E> into packages/types/audit.generated.ts; packages/typeinfo imports the generated type. The typeinfo native session's _with_audit methods return AuditedResult<Arc<...>, TypeInfoRequestError>.
Surface: ok(value, audit) / err(error, audit) constructors; audit(), as_result(), into_parts(), into_result(), map(), map_err(). Home + export rule pinned by audited_result_lives_in_audit_and_exports_through_generated_ts (crates/verter_session/tests/cases/g_block/typeinfo_audit_contract_guards.rs).
Every public audited entry-point follows the same lifecycle: stamp a request id, build a RequestContext keyed by the matching RequestKind, construct an AuditRequestRegistration BEFORE installing the TLS guard, run the producer body under either RequestContextGuard (active) or install_noop_observer() (filtered), assemble the typed payload from per-request counters, and finalise through the registration. Filtered kinds short-circuit to None; the producer body always runs regardless of audit state.
VerterHost::get_component_meta_with_resolution(canonical_id, mode) returns (Option<ComponentMetaAnalysis>, Option<ResolvedComponentMetaState>). The audit record is published into the host's bounded AuditRecordsStore and drained via HostAuditRuntime::take_record(request_id).
AuditedRequest builder (crates/verter_session/src/audited_request.rs) wraps one call in a request-scoped audit harness, resets per-thread counters, validates exactly one request was created, and returns (ComponentMetaAnalysis, ResolvedComponentMetaState, RequestAuditRecord) as a triple. AuditedRequestBuilder::resolve_component_meta is the test-facing convenience; AuditedRequestBuilder::run_custom lets a closure issue arbitrary single-request audited work.
VerterHost::compile_with_audit(canonical_id, target) -> (VerterCompileResult, Option<RequestAuditRecord>) and compile_with_audit_options(canonical_id, target, verter_options) for explicit force_vapor / force_js control. The target bitset maps to CompileTargetTag (Vdom, Ide, Vapor) on kind. Producer-side instrumentation in verter_compiler emits record_phase_timing at parse/transform/codegen/css_analysis/sourcemap boundaries and record_event(CompileCodeTransformOp) at every CodeTransform operation — the session-side RequestContext accumulates these into per-request atomics that assemble_compile_payload reads at finalize time.
VerterHost::analyze_with_audit(canonical_id) -> (Option<AnalysisReady>, Option<RequestAuditRecord>). Probes FileArtifactStore cache before constructing the registration so from_cache is unaffected by audit work. Audit-disabled fast path runs materialize_analysis_ready with no RequestContextGuard.
VerterHost::resolve_type_with_audit(query: SemanticQueryKey, canonical_hint: &str) -> (Option<TypeResolutionResult>, Option<RequestAuditRecord>). Drives one ProjectSemanticDispatch::execute(query) inside the audit window. TypeResolutionPayload reports the caller's projection mode (derived from the query variant) plus per-mode counters mined off the active RequestContext.
VerterHost::audit_workspace_op(op: WorkspaceOp) -> RequestAuditRecord. Drives WorkspaceAccess::audit_op(op) under audit. Constructs the AuditRequestRegistration first so the registry slot precedes the workspace traversal. Returns the record unconditionally; Noop arm only suppresses the records-store side effect.
verter_lsp::audit_harness::run_with_audit(host, method, target_identity, position, body, populate) wraps each LSP handler future in:
LspAuditSession keyed by LspMethodTag and RequestTargetIdentity (constructed via VerterHost::lsp_audit_begin). Registered URIs use the registry's exact stored identity; request-before-registration uses the raw URI; NotApplicable is reserved for operations with no single document target.request_deadlines policy used when audit is disabled. Production defaults every request deadline to zero (unbounded); audit never adds a feature/provider timeout.finalize_ok(payload) on success or RPC error. audit_supersede is an observational latency SLO only: exceeding it emits telemetry but does not cancel or alter the response. Explicit client cancellation may still finalize a session with finalize_cancelled() through the cancellation lifecycle.VERTER_LSP_AUDIT_TRACE_OUT (JSON-lines append, configurable via env var).Audit-disabled fast path runs the body under the identical explicit request-deadline policy without registration cost. The audit-on and audit-off paths are therefore semantically equivalent.
Position-bound LSP payloads carry the same additive tagged identity in PositionInfo::target_identity. PositionInfo::canonical_id remains the legacy projection; an unregistered URI never becomes NotApplicable.
VerterHost::audit_mcp_tool_call(tool_name, canonical_id, args_size_bytes, f) -> (T, Option<RequestAuditRecord>) wraps a closure FnOnce(&Arc<Self>) -> McpToolOutcome<T> under audit. McpToolOutcome { value, result_size_bytes, error } carries the two facts the wrapper cannot infer (response size and optional error message). A non-empty canonical_id is tagged RegisteredCanonical; an empty value represents a tool with no single file target and is tagged NotApplicable while the retained legacy field stays empty. Sub-requests inherit the MCP request's id as parent_request_id via the scheduler-side TLS slot.
AuditRequestRegistration LifecycleEvery audited entry-point allocates exactly one AuditRequestRegistration (crates/verter_session/src/host_audit_runtime.rs):
AuditRequestRegistration ::= Active(ActiveRegistration) | NoopActive — captures a Weak<RequestContext> slot in HostAuditRuntime::active_requests. finalize(record) atomically removes the slot and publishes the record into AuditRecordsStore (idempotent — first call wins). Drop defensively sweeps the slot when finalize did not run (panic/cancellation paths).Noop — returned when AuditConfig::consumer_filter rejects the request's RequestKind. Holds no state; finalize returns false and emits no record.The three lifecycle methods on HostAuditRuntime (register_active_request, finalize_active_request, drop_active_request) are crate-private and have exactly ONE in-tree call site each, all in host_audit_runtime.rs. The audit_request_registration_lifecycle architecture guard mechanically enforces this.
current_observer()Lower crates emit audit signals through verter_audit::current_observer() -> Option<Arc<dyn AuditObserver>> (crates/verter_audit/src/observer.rs). Reads a thread-local slot installed by either RequestContextGuard::install (active) or install_noop_observer() (filtered).
AuditObserver trait carries default no-op implementations; producers override only what they care about:
record_event(event: AuditEvent) — counter-style attribution (InflightAbortedRetry, ColdAbortSwept, CompileCodeTransformOp).record_cache_event(layer: &'static str, hit: bool) — per-layer hit/miss.record_file(canonical_id, layer: VfsLayer, bytes_read, cache_hit) — workspace file read.record_lock_acquisition(lock_name: &'static str, wait_ns: u64) — single lock acquisition wait.record_phase_timing(phase: &'static str, elapsed_ms: f64) — phase-boundary timing.record_scheduler_dispatch(audit: SchedulerAudit) — first-dispatch attribution (subsequent calls bump dispatch counter).Session-side RequestContext provides full implementations; NoOpObserver leaves them defaulted. The audit_observer_single_accessor architecture guard enforces that the five lower crates (verter_compiler, verter_semantic, verter_workspace, verter_lsp, verter_mcp_server) reach audit state ONLY through verter_audit::current_observer() — the session-internal current_request_context() typed accessor is forbidden in those crates.
AuditConfig::consumer_filter (crates/verter_audit/src/config.rs) is a u32 bitset deciding which RequestKind variants emit records. Bits are positionally stable via KindBit enum (ComponentMeta = 0, TypeResolution = 1, SemanticAnalysis = 2, Compile = 3, Workspace = 4, Lsp = 5, Mcp = 6, BundlerBatch = 7, Custom = 8, TypeInfoGraph = 9, FlowReturnInference = 10).
| Constructor | Behaviour |
|---|---|
AuditConsumerFilter::default() / allow_all() | Allow every kind |
deny_all() | Reject every kind |
allow_only([KindBit::…, …]) | Allow only the listed kinds |
.allow(KindBit::…) / .deny(KindBit::…) | Toggle a single bit (chainable) |
Filter is read ONCE at registration time inside AuditRequestRegistration::new and CANNOT change for that request's lifetime. The current AuditConfig snapshot is mirrored from HostConfig flags in host_construction.rs (today only audit_timing_capture is wired; consumer filter defaults to allow-all). Tests that need a non-default filter swap the runtime's AuditConfig via a test-only helper without bypassing active_requests privacy.
HostAuditRuntime & Sampler ThreadHostAuditRuntime (crates/verter_session/src/host_audit_runtime.rs) mints and solely owns the host's AuditRecordsStore, and holds the AuditConfig snapshot and the active-request registry. Each VerterHost owns one independent runtime; multiple hosts in one process do NOT share audit state. The host keeps no second store handle and has no audit-record methods of its own: records publish through an AuditRequestRegistration or, for a read outside an audited entry-point, the crate-private publish_record; consumers drain with host_audit_runtime().take_record(id). Every record is keyed by an id from the host's one request-id counter (VerterHost::next_request_id) — there is no process-wide id counter, so an unregistered record can never land on, and replace, an audited record's id (audit_request_ids_share_one_host_key_space).
audit_config() -> Arc<AuditConfig> — borrow the config snapshot.audit_records_store() -> &Arc<AuditRecordsStore> — borrow the records store.snapshot() -> AuditRuntimeSnapshot — read-only view of (active_request_count, active_request_ids, records_store_size, records_store_capacity).take_record(request_id) -> Option<RequestAuditRecord> — drain a specific record.audit_records_store is bounded — AUDIT_RECORDS_STORE_CAPACITY = 256. Insertion at capacity evicts the oldest entry by insertion order.
AuditRequestRegistration::new call when AuditConfig::audit_timing_capture is on (single-shot start latch via compare_exchange).Arc<SamplerState> only — never Arc<HostAuditRuntime>. Runtime drop cannot land on the sampler thread.fetch_max(current_process_rss()) into each in-flight request's process_rss_peak_bytes slot.WASM targets gated off via #[cfg(not(target_arch = "wasm32"))] — no sampler thread, process_rss_peak_bytes stays at 0 regardless of audit_timing_capture.
All live in crates/verter_session/tests/cases/architecture_guards.rs unless noted:
| Guard | Role |
|---|---|
verter_audit_no_upward_deps | verter_audit/Cargo.toml may declare only verter_span from the verter_* namespace |
audit_substrate_isolation | Source files under crates/verter_audit/src/ may use only verter_span, std, and external crates |
audit_request_registration_lifecycle | The three lifecycle methods (register_active_request, finalize_active_request, drop_active_request) on HostAuditRuntime have exactly ONE in-tree caller each, all inside host_audit_runtime.rs |
audit_observer_single_accessor | The five lower crates (verter_compiler, verter_semantic, verter_workspace, verter_lsp, verter_mcp_server) reach the substrate ONLY via verter_audit::current_observer() — current_request_context is forbidden |
audit_no_hot_loop_instrumentation | Phase-boundary instrumentation only; the canonical (crate, function_path) denylist forbids current_observer() calls inside hot-loop bodies |
audit_counter_single_helper | The two record_inflight_aborted_retry / record_cold_abort_swept increments live in helper bodies only — no inline fetch_add callers anywhere else |
wave_3_entry_points_propagate_tls | Each audited *_with_audit entry-point has at least one paired test that drives it AND calls assert_observer_reaches(...) so TLS propagation is mechanically verified |
every_consumer_has_production_call_site | Every RequestKind variant has at least one production producer under crates/*/src/ that constructs the variant in expression context (not match-arm pattern). Custom and BundlerBatch are documented exemptions in KIND_EXEMPTIONS |
audit_ts_bindings_are_in_sync (in tests/cases/g_misc1/ts_bindings.rs) | packages/types/audit.generated.ts matches what ts-rs would regenerate from current Rust DTOs |
The general external_corpus_paths_not_present_outside_gated_tests guard applies across the workspace, including audit code, as does the review-enforced no-roadmap-archaeology rule.
wave_3_entry_points_propagate_tls pins one TLS-propagation driver per Wave-3 audited entry-point. Each driver invokes the production entry-point through assert_observer_reaches(...) and asserts the substrate observer is reachable inside the audited window AND that the calling thread's harness-installed guard remains visible after the nested entry-point guard drops:
| Entry-point | Paired TLS driver |
|---|---|
resolve_type_with_audit | crates/verter_session/tests/cases/g_type/type_resolution_audit_tls_propagation.rs |
compile_with_audit | crates/verter_session/tests/cases/g_misc0/tls_harness_cross_crate.rs |
analyze_with_audit | crates/verter_session/tests/cases/g_misc0/semantic_analysis_audit_tls_propagation.rs |
audit_op (WorkspaceAccess trait method, driven via the host wrapper audit_workspace_op) | crates/verter_session/tests/cases/g_misc0/workspace_audit_tls_propagation.rs |
verter_lsp::audit_harness::run_with_audit | crates/verter_lsp/tests/cases/lsp_audit_tls_propagation.rs |
audit_mcp_tool_call | crates/verter_session/tests/cases/g_misc0/mcp_audit_tls_propagation.rs |
The guard's MISSING_TLS_TEST allow-list is empty: every Wave-3 entry-point is paired. Adding a new audited entry-point requires landing a paired TLS driver in the same change and pinning the pair into WAVE_3_ENTRY_POINTS; the stale-allow-list check rejects an unpaired entry that has a TLS driver already.
| JS export | Rust binding | Returns |
|---|---|---|
getComponentMetaWithAudit | MetaSession::get_component_meta_with_audit | Buffer (JSON { payload, audit }) |
compileWithAudit | VerterHost::compile_with_audit | Buffer (JSON record) |
analyzeWithAudit | VerterHost::analyze_with_audit | Buffer (JSON record) |
resolveTypeWithAudit | VerterHost::resolve_type_with_audit | Buffer (JSON record) |
auditWorkspaceOp | VerterHost::audit_workspace_op | Buffer (JSON record) |
getLastAuditRecord | drains the most recent record from AuditRecordsStore | Buffer (JSON record or empty) |
getAuditRecords({ kind?, sinceRequestId?, limit? }) | non-destructive filtered query | Buffer (JSON array) |
getBundlerBatchSummary({ kind?, sinceRequestId? }) | invokes BatchAuditAggregator over the store | Buffer (JSON BundlerBatchPayload) |
NAPI bindings: crates/verter_napi/src/audit.rs (helper types + decoders) and inline #[napi] impl NapiVerterHost in crates/verter_napi/src/lib.rs. WASM bindings: crates/verter_wasm/src/audit.rs + crates/verter_wasm/src/lib.rs. All exports return Buffer (JSON UTF-8 payload) for parity with the original getComponentMetaWithAudit contract; consumers decode against @verter/types/audit.generated.ts.
BatchAuditAggregatorBatchAuditAggregator (crates/verter_audit/src/batch.rs) folds an AuditRecordSource into a BundlerBatchPayload. The substrate stays leaf — the aggregator depends only on the trait callback contract:
trait AuditRecordSource {
fn for_each_record(&self, f: &mut dyn FnMut(Instant, &RequestAuditRecord));
}AuditRecordsStore implements AuditRecordSource; non-destructive iteration exposes each record with its insertion Instant. BatchAuditAggregator::summarize(since) partitions by RequestKind, accumulates total duration, total bytes parsed, from_cache_count, and cache_hit_rate, and tracks the top-SLOWEST_RECORD_LIMIT (= 5) slowest records as SlowRecordSummary entries. Each slow summary carries the additive target_identity alongside the retained legacy canonical_id; CLI rendering reads the tag and falls back to the legacy field only when the source record predates the tag. Empty sources yield a zeroed payload with no division-by-zero on cache_hit_rate.
since filters records inserted strictly after the supplied Instant. Bundler integrations call summarize(Some(last_summary_instant)) on every flush so each batch reports only work since the last call.
verter_session::tests::audit_tls_harness::assert_observer_reaches(install_audit, f) is the primary verification primitive for TLS propagation. Runs the closure under either a RequestContextGuard (install_audit = true) or no guard (install_audit = false, the control case), records whether verter_audit::current_observer().is_some() was visible on the calling thread, and exposes a WorkerSinkHandle so workers spawned inside the closure can report their own observation via report_worker_observer_presence.
Worker threads spawned bare via std::thread::spawn get a fresh TLS slot by construction. Closures needing observer propagation into a worker pool must either install the guard again on the worker or rely on a runtime that plumbs RequestContextGuard through to its workers (the production scheduler does this for its rayon pool).
The wave_3_entry_points_propagate_tls guard pins the (entry_point_symbol, paired_test_files) invariant — every *_with_audit entry-point has at least one test that both invokes the symbol AND calls assert_observer_reaches(...). Tests living in crates/verter_session/tests/cases/g_misc0/tls_harness_in_crate.rs, tls_harness_cross_crate.rs, and semantic_analysis_audit_tls_propagation.rs exercise the harness across in-crate, cross-crate, and analysis-specific propagation.
| File | Role |
|---|---|
crates/verter_audit/src/lib.rs | Substrate root + re-exports |
crates/verter_audit/src/record.rs | RequestAuditRecord, RequestTargetIdentity, RequestKind, RequestKindPayload, IncidentalFields |
crates/verter_audit/src/observer.rs | AuditObserver trait, current_observer(), install_observer guard |
crates/verter_audit/src/noop.rs | NoOpObserver, install_noop_observer() |
crates/verter_audit/src/config.rs | AuditConfig, AuditConsumerFilter, KindBit |
crates/verter_audit/src/payloads/ | Per-RequestKind payload data structs |
crates/verter_audit/src/batch.rs | BatchAuditAggregator, AuditRecordSource, SLOWEST_RECORD_LIMIT |
crates/verter_session/src/host_audit_runtime.rs | HostAuditRuntime, AuditRequestRegistration, sampler thread |
crates/verter_session/src/component_meta_audit/audit_records_store.rs | AuditRecordsStore, capacity = 256 |
crates/verter_session/src/audited_request.rs | AuditedRequest builder + run-custom harness |
crates/verter_session/src/host_compile_audit.rs | VerterHost::compile_with_audit |
crates/verter_session/src/host_analyze_audit.rs | VerterHost::analyze_with_audit |
crates/verter_session/src/host_resolve_type_audit.rs | VerterHost::resolve_type_with_audit |
crates/verter_session/src/host_workspace_audit.rs | VerterHost::audit_workspace_op |
crates/verter_session/src/host_mcp_audit.rs | VerterHost::audit_mcp_tool_call, McpToolOutcome |
crates/verter_session/src/host_lsp_audit.rs | LspAuditSession, lsp_audit_begin |
crates/verter_lsp/src/audit_harness.rs | run_with_audit, payload_with_position, drain_to_trace_out |
crates/verter_session/src/tests/audit_tls_harness.rs | assert_observer_reaches, WorkerSinkHandle, report_worker_observer_presence |
crates/verter_napi/src/audit.rs + crates/verter_napi/src/lib.rs | NAPI typed entry-points |
crates/verter_wasm/src/audit.rs + crates/verter_wasm/src/lib.rs | WASM typed entry-points |
packages/types/audit.generated.ts | TS bindings (regenerated via ts-rs) |
© pikax, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/audit-infrastructure of pikax/verter.
Open the folder on GitHubat commit 858624d
Audit Infrastructure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Audit Infrastructure this skillpikax/verter | 113 | — | ~8.4k | Automated safety check: Pass | MIT | |
| RuView CLI, API and WASMruvnet/RuView | 97k | — | ~1.2k | Automated safety check: Notes | MIT | |
| Nginx To Higress Migrationhigress-group/higress | 9.5k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Update V86felixrieseberg/windows95 | 24k | — | ~1.7k | Automated safety check: Pass | Custom licence | |
| Dotlottie WebLottieFiles/dotlottie-web | 892 | — | ~3.5k | Automated safety check: Pass | MIT | |
| Adding Internal API RouteTriliumNext/Trilium | 38k | — | ~3.3k | Automated safety check: Pass | AGPL-3.0 |
ruvnet/RuView
Covers the RuView `wifi-densepose` command line binary, its Axum REST API and the WebAssembly builds for browsers and ESP32, for embedding or scripting RuView.
higress-group/higress
Migrate from ingress-nginx to Higress in Kubernetes environments.
felixrieseberg/windows95
Build and install v86 (wasm + libv86.js + BIOS) into windows95.
LottieFiles/dotlottie-web
Implement Lottie animations using dotLottie runtimes (@lottiefiles/dotlottie-web and @lottiefiles/dotlottie-react).
TriliumNext/Trilium
A skill your agent uses when adding, moving, or wiring an internal REST endpoint in Trilium (a new /api/ route) — choosing between a core-shared handler (packages/trilium-core/src/routes/index.ts…
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
pikax/verter
In-process backtrace watchdog + LLDB attach wrapper + release-dbg profile for diagnosing hangs and slow paths in Verter benches and binaries on Windows / macOS / Linux.
pikax/verter
Generate copy-pasteable prompts for driving separate Claude Code sessions through refactor, review, or migration work.
pikax/verter
Build dependency chains, rebuild sequences, profiling with MCP, and Analysis MCP server setup for Verter
pikax/verter
Rust compiler pipeline, template codegen (VDOM/IDE), CodeTransform, cached directives, strict slots, IDE error recovery, style preprocessing, CompileTarget, compiler authority/policy/demand/admission
pikax/verter
CTO/manager-of-managers methodology for autonomous multi-train plans where the user says "you are the MoM/CTO", "orchestrate the whole plan", "drive the migration end-to-end", "manager-of-managers"…
pikax/verter
Rust performance optimization patterns: batch operations, allocation hierarchy, object pooling, CodeTransform API for vertercompiler
Works with
Verter audit infrastructure — RequestAuditRecord, RequestKind variants, producer entry-points, AuditRequestRegistration lifecycle, HostAuditRuntime, NAPI/WASM bindings, BatchAuditAggregator. Audit Infrastructure is an agent skill from pikax/verter.
Run `npx skills add pikax/verter --skill audit-infrastructure -a claude-code`. Or copy the skill folder (.claude/skills/audit-infrastructure in pikax/verter) into .claude/skills/audit-infrastructure in your project. Claude Code loads it when a task matches its description.
Run `npx skills add pikax/verter --skill audit-infrastructure -a codex`. Or copy the skill folder (.claude/skills/audit-infrastructure in pikax/verter) into .agents/skills/audit-infrastructure in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pikax/verter --skill audit-infrastructure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-infrastructure, .gemini/skills/audit-infrastructure, .github/skills/audit-infrastructure and .opencode/skills/audit-infrastructure in your project.
SKILL.md names no scripts, command-line tools or credentials: Audit Infrastructure is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Audit Infrastructure is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 8.4k tokens (SKILL.md is roughly 34k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Audit Infrastructure: RuView CLI, API and WASM (ruvnet/RuView, 97k stars), Nginx To Higress Migration (higress-group/higress, 9.5k stars), Update V86 (felixrieseberg/windows95, 24k stars) and Dotlottie Web (LottieFiles/dotlottie-web, 892 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
pikax (a GitHub user) maintains it in pikax/verter, which has 113 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 9, 2026.
Source: pikax/verter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.