add-dep
Vet a new or changed third-party dependency for license, provenance, and supply-chain risk before any install runs.
Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only.
> /plugin marketplace add arbiterForge/codeArbiterHow it fires
How this command gets triggered: by you, by Claude, or both.
/auditContext preview
What this command does when you run it.
Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only.
description: Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only. argument-hint: "[<from-ref> <to-ref> | --since-checkpoint | --since <date>]"
Everything codeArbiter logs, it logs append-only and scattered: `overrides.log`, `triage.log`, `decisions/`, `sprint-log.md`, `checkpoints/`. This command assembles them into the one document a team lead, compliance reviewer, or auditor actually asks for: *what happened in this window, who authorized it, and what is still open.* Read-only over every source; its only write is the packet.
ask for an explicit window).
1. Resolve the window to a commit range and a time range; both appear in the packet header. 2. Gather, citing each source file:
listed with their PR reference.
`SECURITY-OVERRIDE` and `DEV:` entries), each with its `BY:` identity.
supersede chains), each with its Decided-by attribution.
entry verbatim, count the `high` ones.
3. Write the packet to `{{PROJECT_DIR}}/.codearbiter/audits/<YYYY-MM-DD>.md` (second run the same day appends `-2`, `-3`, … — an existing packet is never overwritten). Surface the path and a three-line summary: commits, overrides, open items.
Read-only over every source — MUST NOT modify any log, decision, or checkpoint while assembling. MUST NOT overwrite an existing packet. MUST quote override and low-confidence sprint entries verbatim — never paraphrase an audit line. An empty section is stated as empty, never omitted — "no overrides in window" is itself the finding.
When you can't trust yourself with your code base, trust Arbiter.
Repo: arbiterForge/codeArbiter
Vet a new or changed third-party dependency for license, provenance, and supply-chain risk before any install runs.
Report the health of Architecture Decision Records — aged, unchallenged, supersession candidates, unresolved CONFIRM-NN. Read-only.
Author a numbered, dated, user-attributed Architecture Decision Record under .codearbiter/decisions/.
Lightweight Q&A about the project — answer from context and return, no routing, no state change.
Periodic multi-reviewer sweep of the whole codebase — surfaces a triaged checkpoint report.
Sanctioned lane for non-behavioral work — docs-only edits, dependency bumps, reverts. Type-scaled gates; no TDD demanded of prose.