plugins/agent-scaffolders/skills/self-audit/SKILL.md
Trigger with "run self-audit", "test the analyzer", "regression test the plugin analyzer", "audit the agent-scaffolders", or "verify the analyzer works correctly". Runs the analyze-plugin skill against the agent-scaffolders itself and its test fixtures as a regression smoke test. Use this after making changes to the analyzer to verify nothing broke.
npx skillsauth add richfrem/agent-plugins-skills self-auditInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
This skill requires Python 3.8+ and standard library only. No external packages needed.
To install this skill's dependencies:
pip-compile ./requirements.in
pip install -r ./requirements.txt
See ./requirements.txt for the dependency lockfile (currently empty — standard library only).
Run the analyze-plugin skill against the agent-scaffolders itself and the test fixtures. This is a regression smoke test that verifies the analyzer produces consistent, expected results.
Run inventory on self (security scanning is on by default):
python ./scripts/inventory_plugin.py --path . --format json
Run scanner against test fixtures:
python ./scripts/inventory_plugin.py --path ./tests/gold-standard-plugin --format json
python ./scripts/inventory_plugin.py --path ./tests/flawed-plugin --format json
Validate deterministic scanner results:
Self-analysis scanner must confirm:
security_flags = [] (zero security findings in the analyzer itself)issues = [] (zero structural violations)Gold-standard fixture scanner must confirm:
security_flags = [] (zero security findings)issues = [] (zero structural violations)warnings = [] (zero missing components)Flawed fixture scanner must confirm:
security_flags count ≥ 4 (network calls + env access; obfuscated credential is LLM-only)issues count ≥ 1 (bash script violation)warnings count ≥ 2 (missing acceptance criteria + references)./README.md for the full expected findings manifestTo run assertions programmatically:
python ./scripts/assert_audit.py --fixture flawed --json-output <path-to-scan-output.json>
Run the full 6-phase analysis on each fixture:
tests/gold-standard-plugin/ — should score maturity ≥ L2, zero Critical, at least 2 patterns identifiedtests/flawed-plugin/ — LLM must additionally detect: missing README file tree, missing plugin manifestValidate self-analysis (full 6-phase on the analyzer itself):
Report deviations:
⚠️ SELF-AUDIT REGRESSION: [dimension] expected [X] got [Y]
✅ SELF-AUDIT PASSED: [N] scanner checks passed, [M] fixtures validated, [K] 6-phase checks passed
testing
Skill for creating and managing isolated git worktrees (`.worktrees/issue-NNN`) for issue execution branches. USE ONLY when setting up or cleaning up isolated git worktrees for specific issue execution. DO NOT USE for managing local task files (use `task-agent`) or escalating tasks to issues (use `github-issue-backlog-agent`).
data-ai
Skill for orchestrating the end-to-end GitHub issue lifecycle flow: Issue -> Worktree -> Implementation -> PR Creation -> Resolution Closure. USE ONLY when running or dry-running full lifecycle orchestration for resolving an issue with a PR. DO NOT USE for isolated worktree management only (use `issue-worktree-agent`) or logging issues (use `github-issue-agent`).
tools
Automatically ranks GitHub issues (P0-P3) based on friction tier, frequency, and blockages, synchronizing priority labels and GitHub Projects v2 custom fields.
testing
Bridge skill for escalating ephemeral local task scratchpad items (`tasks/*.md`) into durable, taxonomy-validated, evidence-rich GitHub Issues. USE ONLY when promoting a single-session local task into durable repository backlog. DO NOT USE for managing local kanban boards (use `task-agent` instead) or directly querying/commenting on issues (use `github-issue-agent` instead).