Agent skill

Adversarial Docs Audit

by shift-editor in shift-editor/shift

Fact-checks DOCS.md files against the source code, testing each concrete claim and sorting it as true, false, stale or unverifiable.

Apache-2.0Auto-check passedDevelopment

Install Adversarial Docs Audit

skills CLI
$ npx skills add shift-editor/shift --skill docs-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install shift-editor/shift docs-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/shift-editor/shift.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/docs-audit .claude/skills/docs-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
docs-audit
GitHub stars
343
Token cost
~818 tokens
SKILL.md length
389 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
Apache-2.0

At a glance

Fact-checks DOCS.md files against the source code, testing each concrete claim and sorting it as true, false, stale or unverifiable.

  • Works in 5 steps: Run the mechanical checkers first —… → Extract the doc's concrete checkable… → Verify each claim by reading the actual… → …
  • Checking whether a module's DOCS.md still matches what the code does
  • SKILL.md covers Scope, Procedure per doc and Reporting and fixing
  • Calls python3, git and node

What it does

This skill is the semantic layer on top of the repository's mechanical checkers. A script such as `context-drift-check.py` can show that links, symbols and paths exist, but only reading the code shows whether the prose is true. With no arguments it audits the docs whose `reviewed:` date is oldest, a path limits it to one module, and a full audit runs one parallel subagent per document. On scheduled runs it first checks `git log` for meaningful changes over the last 8 days and stops if there are none.

For each document it runs the mechanical checkers first, extracts the roughly 12 most load-bearing claims (invariants, key types, codemap lines, how-it-works statements, gotchas, recipe steps), and verifies each by reading the actual source, tracing code paths and running referenced tests where cheap. Findings are labeled TRUE, FALSE, MISLEADING or STALE, or UNVERIFIABLE, with the doc line and contradicting source location for anything that is not true. The report is a per-doc tally. The excerpt ends in the reporting section.

When your agent uses it

  • Checking whether a module's DOCS.md still matches what the code does
  • Running a scheduled documentation review after recent source changes
  • Finding documentation that describes superseded behavior or the wrong symbol

Example prompts

  • “Audit the docs for the rendering module and cite the source line for anything false.”
  • “Run the docs audit on whichever DOCS.md files are overdue for review.”
  • “Verify the Key Types section in the shaping docs against the actual code.”

Requirements

  • Python 3 and Node.js for the repository's mechanical checker scripts
  • Git history of the repository

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Run the mechanical checkers first — don't spend audit effort on what they already catch
  2. Extract the doc's concrete checkable claims: architecture invariants, Key Types descriptions, Codemap one-liners, How-it-works statements…
  3. Verify each claim by reading the actual source — never by plausibility. For behavioral claims (ordering, caching, skipping, round-trips)…
  4. Classify: TRUE (verified), FALSE (contradicted — cite doc line and source file:line), MISLEADING/STALE (real symbols, wrong or superseded…
  5. Watch for the known rot patterns: superseded API narratives (per-method flows replaced by batch entry points), mechanisms attributed to…

What it can do on your machine

Read from SKILL.md and the folder at commit e7dacfa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • git
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Adversarial Docs Audit loads about 818 tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 389 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~818

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from shift-editor/shift at commit e7dacfa, republished under its Apache-2.0 licence (© shift-editor). 389 words, ~818 tokens.

Download SKILL.mdSave it as .claude/skills/docs-audit/SKILL.md (or your agent's skills folder).
name
docs-audit
description
Adversarially fact-check DOCS.md files against the actual source code, verifying every concrete claim rather than trusting structure checks. Use when the user asks to audit docs, verify documentation accuracy, check whether docs are still true, or on a scheduled documentation review. This is the semantic layer the mechanical checkers cannot cover.

/docs-audit — Adversarial Documentation Audit

scripts/context-drift-check.py proves referential integrity (links, symbols, commands, codemap paths, structure). It cannot prove that prose is TRUE. This skill is the semantic layer: read the doc, read the module, and try to refute every checkable claim.

Scope

Given no arguments, audit the DOCS.md files whose reviewed: date is oldest or overdue (the checker's stale warnings list them). Given a module or doc path, audit that doc. A full-repo audit fans out one subagent per doc (they are independent — run them in parallel).

On a scheduled run, guard first — before installing dependencies or reading any docs:

bash
git log --oneline --since='8 days ago' -- crates packages apps '**/docs/DOCS.md' docs/architecture

No output (or only commits whose changes are all outside those paths — CI config, lockfiles, release chores) means nothing meaningful changed: report "no source or docs commits since <date>; audit skipped" and stop. When there are meaningful commits, prioritize the docs whose modules those commits touched.

Procedure per doc

  1. Run the mechanical checkers first — don't spend audit effort on what they already catch: python3 scripts/context-drift-check.py, node scripts/check-docs-fences.mjs, python3 scripts/check-invariants.py.
  2. Extract the doc's concrete checkable claims: architecture invariants, Key Types descriptions, Codemap one-liners, How-it-works statements, Gotchas, Workflow recipe steps. Prioritize the ~12 most load-bearing claims; cover long-standing content, not just recent edits.
  3. Verify each claim by reading the actual source — never by plausibility. For behavioral claims (ordering, caching, skipping, round-trips), trace the code path; where cheap, verify numerically or by running the referenced test.
  4. Classify: TRUE (verified), FALSE (contradicted — cite doc line and source file:line), MISLEADING/STALE (real symbols, wrong or superseded behavior), UNVERIFIABLE (pure rationale — fine, leave it).
  5. Watch for the known rot patterns: superseded API narratives (per-method flows replaced by batch entry points), mechanisms attributed to the wrong symbol, behavior claims inverted by edge cases (wrapping, malformed input), and codemap entries for moved responsibilities.
Show full SKILL.md (91 more words)Show less

Reporting and fixing

  • Report a per-doc tally (e.g. 11 TRUE / 1 FALSE / 2 MISLEADING) with details only for non-TRUE findings, each carrying doc line + contradicting source location.
  • If asked to fix (or running as a scheduled audit): apply corrections per the docs skill, re-run the checkers, bump the doc's reviewed: date (the audit IS the attestation), and commit as docs: ... per the commit skill. Never invent content to fill a finding you did not verify.
  • An audit that finds nothing wrong still bumps reviewed: — that is the point of the attestation.

© shift-editor, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/docs-audit of shift-editor/shift.

Open the folder on GitHubat commit e7dacfa

Compare with similar skills

Adversarial Docs Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Adversarial Docs Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Adversarial Docs Audit this skillshift-editor/shift343—~818Automated safety check: PassApache-2.0
Fact Checkerdaymade/claude-code-skills1.4k2 repos~2.1kAutomated safety check: PassMIT
Review DocsKaggle/kaggle-environments454—~2.7kAutomated safety check: PassApache-2.0
Diagram Designcathrynlavery/diagram-design44k1 repos~7.5kAutomated safety check: PassMIT
Simple Englishmoeru-ai/airi50k2 repos~4.6kAutomated safety check: PassMIT
Get API Docs with chubandrewyng/context-hub14k2 repos~775Automated safety check: PassMIT

Similar skills

  • Fact Checker

    daymade/claude-code-skills

    Verifies factual claims in documents using web search and official sources, then proposes corrections with user confirmation.

    1.4k GitHub starsUsed in 2 repos~2.1k tokens
    DevelopmentAuto-check passed
  • Review Docs

    Kaggle/kaggle-environments

    Audit a game environment's README.md and AGENTS.md against its engine implementation.

    454 GitHub stars~2.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Diagram Design

    cathrynlavery/diagram-design

    Creates branded diagrams, from architecture, flowchart and sequence to charts and maps, as self-contained HTML with inline SVG, with import from draw.io, Mermaid and Excalidraw.

    44k GitHub starsUsed in 1 repo~7.5k tokens
    DevelopmentAuto-check passed
  • Simple English

    moeru-ai/airi

    Write or rewrite technical text with the rules of ASD-STE100 Simplified Technical English so it is clear, unambiguous, and free of AI slop.

    50k GitHub starsUsed in 2 repos~4.6k tokens
    DevelopmentAuto-check passed
  • Get API Docs with chub

    andrewyng/context-hub

    Fetches current documentation for third-party APIs and SDKs with the chub CLI before the agent writes code against them, instead of relying on remembered API shapes.

    14k GitHub starsUsed in 2 repos~775 tokens
    DevelopmentAuto-check passed
  • Doc Sync

    JetBrains/ideavim

    Official

    Keeps IdeaVim documentation in sync with code changes. An agent skill from JetBrains/ideavim.

    10k GitHub starsUsed in 2 repos~2.6k tokens
    DevelopmentAuto-check passed

More from shift-editor/shift

All 14 skills in this repo
  • Shift Commit Rules

    shift-editor/shift

    Rules for writing git commits in the Shift font editor repo: Conventional Commits subjects, user-facing changelog wording, concise subjects and logical commit boundaries.

    343 GitHub stars~1.4k tokensUpdated today
    Auto-check: notes
  • Dead Code Removal with Knip

    shift-editor/shift

    Finds unused files, exports and class members with Knip, then verifies each candidate through reference tracing before removing anything, never using knip --fix.

    343 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Shift Subsystem Docs

    shift-editor/shift

    Updates or creates DOCS.md files for Shift subsystems, recording the architecture invariants and constraints that cannot be learned from reading the source.

    343 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Shift Issue Writer

    shift-editor/shift

    Sets the rules for finding, writing and updating Shift GitHub issues: search for duplicates first, use outcome-focused titles and testable acceptance criteria.

    343 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Shift JSDoc Contracts

    shift-editor/shift

    Guides writing JSDoc for Shift exported APIs as a stable caller contract, covering ownership, lifetime, side effects and nullability that TypeScript types cannot express.

    343 GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Shift Pull Request Rules

    shift-editor/shift

    Rules for preparing, opening and updating pull requests in the Shift repository: Conventional Commit titles, Release Please effects, evidence-based bodies and UI screenshots.

    343 GitHub stars~2.1k tokensUpdated today
    Auto-check: notes

Categories

Questions about Adversarial Docs Audit

What does Adversarial Docs Audit do?

Fact-checks DOCS.md files against the source code, testing each concrete claim and sorting it as true, false, stale or unverifiable. This skill is the semantic layer on top of the repository's mechanical checkers.py` can show that links, symbols and paths exist, but only reading the code shows whether the prose is true.

When should I use Adversarial Docs Audit?

Adversarial Docs Audit fits situations like: checking whether a module's DOCS.md still matches what the code does; running a scheduled documentation review after recent source changes; finding documentation that describes superseded behavior or the wrong symbol.

How do I install Adversarial Docs Audit in Claude Code?

Run `npx skills add shift-editor/shift --skill docs-audit -a claude-code`. Or copy the skill folder (.claude/skills/docs-audit in shift-editor/shift) into .claude/skills/docs-audit in your project. Claude Code loads it when a task matches its description.

How do I install Adversarial Docs Audit in Codex?

Run `npx skills add shift-editor/shift --skill docs-audit -a codex`. Or copy the skill folder (.claude/skills/docs-audit in shift-editor/shift) into .agents/skills/docs-audit in your project. Codex loads it when a task matches its description.

Can I use Adversarial Docs Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shift-editor/shift --skill docs-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docs-audit, .gemini/skills/docs-audit, .github/skills/docs-audit and .opencode/skills/docs-audit in your project.

What does Adversarial Docs Audit need to run?

Going by SKILL.md and its folder, Adversarial Docs Audit needs the command-line tools its instructions call (python3, git and node). Our summary lists: Python 3 and Node.js for the repository's mechanical checker scripts; Git history of the repository.

Does Adversarial Docs Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Adversarial Docs Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Adversarial Docs Audit use?

Adversarial Docs Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Adversarial Docs Audit use?

About 818 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Adversarial Docs Audit?

Skills that share tags, products or a category with Adversarial Docs Audit: Fact Checker (daymade/claude-code-skills, 1.4k stars), Review Docs (Kaggle/kaggle-environments, 454 stars), Diagram Design (cathrynlavery/diagram-design, 44k stars) and Simple English (moeru-ai/airi, 50k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Adversarial Docs Audit?

shift-editor (a GitHub organization) maintains it in shift-editor/shift, which has 343 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 6, 2026.

Source: shift-editor/shift on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.