add-dep
Vet a new or changed third-party dependency for license, provenance, and supply-chain risk before any install runs.
Deep, rarely-convened whole-codebase audit — eleven specialist lenses, a resumable on-disk audit log, findings filed as GitHub issues on approval. Expensive; estimates cost and STOPs before running. Never a required gate.
> /plugin marketplace add arbiterForge/codeArbiterHow it fires
How this command gets triggered: by you, by Claude, or both.
/tribunalContext preview
What this command does when you run it.
Deep, rarely-convened whole-codebase audit — eleven specialist lenses, a resumable on-disk audit log, findings filed as GitHub issues on approval. Expensive; estimates cost and STOPs before running. Never a required gate.
description: Deep, rarely-convened whole-codebase audit — eleven specialist lenses, a resumable on-disk audit log, findings filed as GitHub issues on approval. Expensive; estimates cost and STOPs before running. Never a required gate. argument-hint: "[scope-path] [--tag <label>]"
The deepest, most expensive review codeArbiter offers, convened rarely and on demand. Routes to the tribunal skill. Eleven lenses judge the codebase; every finding persists to its own file (plus append-only triage/run logs) under `.codearbiter/reports/<run-id>/`, so an interrupted run resumes from disk. Never a required gate — critical/high are blocking-severity findings, not a pipeline halt.
Cost first — this lane routinely costs millions of tokens on a large repo. Phase 0 sizes the codebase, prints a token-cost band, recommends the highest-reasoning model, and STOPs for your acknowledgement before dispatching anything. Nothing runs unacknowledged.
Load and follow the tribunal skill (`{{PLUGIN_ROOT}}/skills/tribunal/SKILL.md`). In brief:
Phase 0 (STOP) — cost estimate, model recommendation, resume check. Phase 1 (BLOCK) — map the codebase; risk-rank and mark trust boundaries; record AI-authorship markers and iteration depth. Phase 2 (BLOCK) — dispatch `tribunal-lens-reviewer` once per active lens in priority waves (≤5 in flight); each dispatch writes one file per finding under its own `findings/<lens>/` dir. Phase 3 (BLOCK) — triage per wave from disk: dedup, independent calibration, decision vocabulary. Phase 4 (BLOCK) — project the human-readable report from the logs. Phase 5 (BLOCK) — on explicit selection, file findings as GitHub issues; idempotent against the tracker. Phase 6 (STOP) — optional, opt-in KPI telemetry to the public codeArbiter repo.
`"scope-path"` — focus the audit on a subtree (default: repository root). The full lens roster still runs; only the scope narrows.
`--tag <label>` — freeform run label recorded in telemetry (see `references/telemetry.md`).
`{{PLUGIN_ROOT}}/skills/tribunal/SKILL.md` — dispatches `tribunal-lens-reviewer` once per active lens (and, on a large repo, the optional map-structure / map-deps mappers).
MUST NOT dispatch any lens before you acknowledge the Phase 0 cost estimate. MUST NOT act as a required gate or block a merge/commit. MUST NOT file an issue or send telemetry without explicit authorization. Read-only on project code until the filing gate; findings file as GitHub issues, never the task board.
When you can't trust yourself with your code base, trust Arbiter.
Repo: arbiterForge/codeArbiter
Vet a new or changed third-party dependency for license, provenance, and supply-chain risk before any install runs.
Report the health of Architecture Decision Records — aged, unchallenged, supersession candidates, unresolved CONFIRM-NN. Read-only.
Author a numbered, dated, user-attributed Architecture Decision Record under .codearbiter/decisions/.
Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit…
Lightweight Q&A about the project — answer from context and return, no routing, no state change.
Periodic multi-reviewer sweep of the whole codebase — surfaces a triaged checkpoint report.