skill-candidates/skill-auditor/SKILL.md
Audit skill candidates and classify each changed skill as unique or upgrade with severity findings. Use when creating/updating skills, preparing admission evidence, or producing audit JSON for skill-game scoring.
npx skillsauth add grtninja/skill-arbiter skill-auditorInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill to classify and gate new or updated skills.
--include-skill) or scan the full candidate set.unique or upgrade.name, description),agents/openai.yaml presence,Documents\GitHub roots or :1234 treated as an authority surface.high, medium, low) and fix failures.high_count=0 for admission-ready output.Audit selected skills:
python3 scripts/skill_audit.py \
--skills-root skill-candidates \
--include-skill <skill-name> \
--json-out /tmp/skill-audit.json
Audit with arbiter evidence required:
python3 scripts/skill_audit.py \
--skills-root skill-candidates \
--include-skill <skill-name> \
--arbiter-report /tmp/skill-arbiter-evidence.json \
--require-arbiter-evidence \
--json-out /tmp/skill-audit.json
unique: no strong near-peer overlap detected in current skill set.upgrade: near-peer overlap indicates refinement/extension of an existing lane.high findings block completion.medium findings should be addressed before admission when possible.G:\GitHub root contract, authoritative :9000/:2337 model lanes, and PC Control-first evidence rules where applicable.Use this skill only for skill-audit classification and findings generation.
Do not use this skill for runtime skill arbitration; use $skill-arbiter-lockdown-admission.
references/audit-rubric.mdscripts/skill_audit.pyIf findings remain unresolved:
$skill-hub for chain recalculation.tools
Run a defender-first security sweep on code, configs, prompts, model/tooling surfaces, or third-party contribution lanes. Use when a request involves safe bug, leak, zero-day-class, exploit, or hack hunting for protection, when contributing to outside repositories and you want a focused security pass, or when touching auth, secrets, permissions, network exposure, prompt/tool boundaries, data flow, or update/build surfaces. This skill is defensive only and must never be used for weaponization or unauthorized access.
development
Validate and repair VRM Sandbox startup acceptance with shim-first local model authority, frontend/backend bring-up, and avatar-runtime launch proof. Use when launch behavior, chat handoff, voice fallback, or runtime bridge acceptance must be verified end to end.
documentation
Align documented voice-command catalogs, endpoint action allowances, and live runtime handlers so operator-visible voice surfaces match what the stack can actually execute. Use when voice command docs, parser matrices, endpoint permissions, or runtime action routing drift apart.
development
Track SkillHub trend and topic drift, maintain a bounded rewrite watchlist, and surface emerging gaps worth turning into repo-owned skills. Use when the marketplace query set shows new families or when the current shortlist has gone stale.