Agent skill

Auditor

by RaoFoundation in RaoFoundation/subtensor

Run the domain-focused Auditor persona on the local working tree's diff against a base branch.

Apache-2.0Auto-check passedDevelopment

Install Auditor

skills CLI
$ npx skills add RaoFoundation/subtensor --skill auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install RaoFoundation/subtensor auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/RaoFoundation/subtensor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/auditor .claude/skills/auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auditor
GitHub stars
389
Token cost
~813 tokens
SKILL.md length
333 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run the domain-focused Auditor persona on the local working tree's diff against a base branch.

  • Works in 3 steps: Determine the diff → Run the persona → Output
  • Trusts their own code and wants the domain review
  • SKILL.md covers Step 1 — Determine the diff, Step 2 — Run the persona and Step 3 — Output
  • Calls git, gh and cargo

What it does

Auditor is an agent skill from RaoFoundation/subtensor. Run the domain-focused Auditor persona on the local working tree's diff against a base branch. May build/test if needed for confirmation. Outputs a verdict, optional suggested-changes patch, and (if relevant) a proposed PR description. Use after the Skeptic has cleared the branch, or directly when the user trusts their own code and wants the domain review.

Its SKILL.md is about 810 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests. It works with Rust and GitHub. The licence is Apache-2.0.

When your agent uses it

  • Trusts their own code and wants the domain review
  • Tasks that involve Pull requests

Example prompts

  • “/auditor”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Determine the diff
  2. Run the persona
  3. Output

What it can do on your machine

Read from SKILL.md and the folder at commit 5c6e83e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auditor loads about 813 tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 333 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~813

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from RaoFoundation/subtensor at commit 5c6e83e, republished under its Apache-2.0 licence (© RaoFoundation). 333 words, ~813 tokens.

Download SKILL.mdSave it as .claude/skills/auditor/SKILL.md (or your agent's skills folder).
name
auditor
description
Run the domain-focused Auditor persona on the local working tree's diff against a base branch. May build/test if needed for confirmation. Outputs a verdict, optional suggested-changes patch, and (if relevant) a proposed PR description. Use after the Skeptic has cleared the branch, or directly when the user trusts their own code and wants the domain review.

Auditor — local mode

You are running the Auditor persona locally against the user's working tree. The Skeptic has either already passed (or the user is running you directly because they wrote the code themselves and trust intent). Your output goes to the terminal, not GitHub.

Step 1 — Determine the diff

Same detection as the Skeptic skill:

  1. PR base via gh pr view --json baseRefName if a PR exists.
  2. Default to devnet.
  3. Override via skill argument: /auditor main.

Compute the diff:

bash
git fetch origin "$BASE" --quiet
git diff --merge-base "origin/$BASE"...HEAD

If the diff is empty, report "No changes vs $BASE" and exit.

Step 2 — Run the persona

Load and follow:

  • .github/ai-review/common.md
  • .github/ai-review/auditor.md

Local-mode adaptations:

  • PR description handling: if a PR exists, follow the persona's auto-fill / discrepancy-comment logic but do NOT actually call gh pr edit. Instead, write the proposed description to .auditor-pr-description.md and tell the user. If no PR exists, generate a draft description and write it to the same file — the user will use it when they open the PR.
  • Auto-fix CI failures: you MAY run ./scripts/fix_rust.sh against the working tree if lints / formatting are off, but DO NOT commit. Leave changes in the working tree for the user to review.
  • Spec version bump: if the diff touches runtime/ or pallets/ and spec_version in runtime/src/lib.rs was not bumped, do NOT modify the file. Instead, surface this as a finding the user must address.
  • Build/test escalation: same rules as the workflow — only build/test when a finding requires runtime confirmation. Use cargo test -p <pallet> <test> for targeted tests rather than the full workspace.
  • Duplicate-work check: if a PR exists, run the same gh pr list check the persona file describes. If no PR exists, skip this step (no duplicates to check yet).

Step 3 — Output

============================================================
  AUDITOR VERDICT: 👍 | 👎
============================================================

Gittensor: KNOWN | LIKELY | UNKNOWN
Spec version: <bumped | NOT BUMPED — required>
Auto-fix: <ran fix_rust.sh, modified N files | not needed>

Description: <see .auditor-pr-description.md | already adequate>
Duplicates: <none | PR #N is the better candidate>

Findings:
  [SEVERITY] Title
    file:line — description

Suggested new files:
  path/to/new_test.rs (see .auditor-suggestions.patch)

Conclusion: <one or two sentences>

Write any suggested code changes to .auditor-suggestions.patch (apply with git apply). Write any proposed new files into the patch as well, as added-file diffs. Write the proposed PR description (if generated) to .auditor-pr-description.md.

Do NOT post anything to GitHub. Do NOT commit. Do NOT push.

© RaoFoundation, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/auditor of RaoFoundation/subtensor.

Open the folder on GitHubat commit 5c6e83e

Compare with similar skills

Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auditor this skillRaoFoundation/subtensor389—~813Automated safety check: PassApache-2.0
PR Cyclejaemk/cached2.1k—~4.8kAutomated safety check: NotesMIT
PR Reviewjaemk/self_update961—~1.5kAutomated safety check: NotesMIT
PR Reviewjaemk/cached2.1k—~2.5kAutomated safety check: NotesMIT
Resolve PR Reviewshencangsheng/easydb_app590—~2.4kAutomated safety check: PassMIT
Firewood Reviewava-labs/firewood153—~2.1kAutomated safety check: NotesCustom licence

Similar skills

  • PR Cycle

    jaemk/cached

    PR review-and-update cycle — the orchestrator that takes a PR from review to resolved.

    2.1k GitHub stars~4.8k tokensUpdated 8 days ago
    DevelopmentAuto-check: notes
  • PR Review

    jaemk/self_update

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.

    961 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • PR Review

    jaemk/cached

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/cached.

    2.1k GitHub stars~2.5k tokensUpdated 8 days ago
    DevelopmentAuto-check: notes
  • Resolve PR Review

    shencangsheng/easydb_app

    Resolve pull request code review comments end-to-end. An agent skill from shencangsheng/easydb_app.

    590 GitHub stars~2.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Firewood Review

    ava-labs/firewood

    A skill your agent uses when reviewing ava-labs/firewood code changes — pull request or local workspace.

    153 GitHub stars~2.1k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Beava PR Review

    beava-dev/beava

    Reviews a beava PR diff for real bugs, beava-specific architectural invariants, and AI-generated "slop" patterns (hollow code, phantom imports, inflated comments, disconnected pipelines).

    138 GitHub stars~2.1k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed

More from RaoFoundation/subtensor

  • Skeptic

    RaoFoundation/subtensor

    Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

    389 GitHub stars~660 tokensUpdated yesterday
    Auto-check passed
  • Evm Maintainer

    RaoFoundation/subtensor

    Maintain backwards-compatible, versioned EVM precompiles that expose runtime extrinsics, state, constants, and APIs to Solidity.

    389 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Auditor

What does Auditor do?

Run the domain-focused Auditor persona on the local working tree's diff against a base branch. Auditor is an agent skill from RaoFoundation/subtensor. Run the domain-focused Auditor persona on the local working tree's diff against a base branch.

When should I use Auditor?

Auditor fits situations like: trusts their own code and wants the domain review; tasks that involve Pull requests.

How do I install Auditor in Claude Code?

Run `npx skills add RaoFoundation/subtensor --skill auditor -a claude-code`. Or copy the skill folder (.agents/skills/auditor in RaoFoundation/subtensor) into .claude/skills/auditor in your project. Claude Code loads it when a task matches its description.

How do I install Auditor in Codex?

Run `npx skills add RaoFoundation/subtensor --skill auditor -a codex`. Or copy the skill folder (.agents/skills/auditor in RaoFoundation/subtensor) into .agents/skills/auditor in your project. Codex loads it when a task matches its description.

Can I use Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add RaoFoundation/subtensor --skill auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditor, .gemini/skills/auditor, .github/skills/auditor and .opencode/skills/auditor in your project.

What does Auditor need to run?

Going by SKILL.md and its folder, Auditor needs the command-line tools its instructions call (git, gh and cargo).

Does Auditor access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auditor use?

Auditor is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auditor use?

About 813 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auditor?

Skills that share tags, products or a category with Auditor: PR Cycle (jaemk/cached, 2.1k stars), PR Review (jaemk/self_update, 961 stars), PR Review (jaemk/cached, 2.1k stars) and Resolve PR Review (shencangsheng/easydb_app, 590 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auditor?

RaoFoundation (a GitHub organization) maintains it in RaoFoundation/subtensor, which has 389 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 8, 2026.

Source: RaoFoundation/subtensor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.