/ca-audit
Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only.
$ npx -y skills add arbiterForge/codeArbiter --skill ca-audit --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/ca-audit
Context preview
The summary Claude sees to decide when to auto-load this skill.
Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only.
SKILL.md
ca-audit.SKILL.mdname: ca-audit
description: Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only.
argument-hint: "[<from-ref> <to-ref> | --since-checkpoint | --since <date>]"
$ca-audit — promotion packet
Everything codeArbiter logs, it logs append-only and scattered: `overrides.log`, `triage.log`, `decisions/`, `sprint-log.md`, `checkpoints/`. This command assembles them into the one document a team lead, compliance reviewer, or auditor actually asks for: *what happened in this window, who authorized it, and what is still open.* Read-only over every source; its only write is the packet.
Window
- `<from-ref> <to-ref>` — two tags/SHAs (e.g. `v1.2.0 v1.3.0`).
- `--since-checkpoint` — from the `last-checkpoint` record to HEAD.
- `--since <date>` — ISO date to HEAD.
- No argument → from the most recent tag to HEAD (no tags → last checkpoint; neither → BLOCK and
ask for an explicit window).
Flow
1. Resolve the window to a commit range and a time range; both appear in the packet header. 2. Gather, citing each source file:
- **Commits** — `git log` over the range, grouped by Conventional-Commit type; merge commits
listed with their PR reference.
- **Overrides** — every `overrides.log` line in the time range, verbatim (including
`SECURITY-OVERRIDE` and `DEV:` entries), each with its `BY:` identity.
- **Triage** — every small-lane classification in `triage.log` in range.
- **Decisions** — ADRs created or superseded in range (from `decisions/` file dates and the
supersede chains), each with its Decided-by attribution.
- **Sprint auto-decisions** — entries from `sprint-log.md` in range; list every `low`-confidence
entry verbatim, count the `high` ones.
- **Open questions** — all currently-unresolved `[CONFIRM-NN]` items.
- **Checkpoint findings** — from the most recent `checkpoints/*.md`: findings still open.
3. Write the packet to `<project-root>/.codearbiter/audits/<YYYY-MM-DD>.md` (second run the same day appends `-2`, `-3`, … — an existing packet is never overwritten). Surface the path and a three-line summary: commits, overrides, open items.
Hard gate
Read-only over every source — MUST NOT modify any log, decision, or checkpoint while assembling. MUST NOT overwrite an existing packet. MUST quote override and low-confidence sprint entries verbatim — never paraphrase an audit line. An empty section is stated as empty, never omitted — "no overrides in window" is itself the finding.
When NOT to use
- Live project state right now → `$ca-status`.
- Triggering reviews → `$ca-checkpoint` (this command only reports what reviews already found).
Read more
name: ca-audit description: Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only. argument-hint: "[<from-ref> <to-ref> | --since-checkpoint | --since <date>]"
$ca-audit — promotion packet
Everything codeArbiter logs, it logs append-only and scattered: `overrides.log`, `triage.log`, `decisions/`, `sprint-log.md`, `checkpoints/`. This command assembles them into the one document a team lead, compliance reviewer, or auditor actually asks for: *what happened in this window, who authorized it, and what is still open.* Read-only over every source; its only write is the packet.
Window
- `<from-ref> <to-ref>` — two tags/SHAs (e.g. `v1.2.0 v1.3.0`).
- `--since-checkpoint` — from the `last-checkpoint` record to HEAD.
- `--since <date>` — ISO date to HEAD.
- No argument → from the most recent tag to HEAD (no tags → last checkpoint; neither → BLOCK and
ask for an explicit window).
Flow
1. Resolve the window to a commit range and a time range; both appear in the packet header. 2. Gather, citing each source file:
- **Commits** — `git log` over the range, grouped by Conventional-Commit type; merge commits
listed with their PR reference.
- **Overrides** — every `overrides.log` line in the time range, verbatim (including
`SECURITY-OVERRIDE` and `DEV:` entries), each with its `BY:` identity.
- **Triage** — every small-lane classification in `triage.log` in range.
- **Decisions** — ADRs created or superseded in range (from `decisions/` file dates and the
supersede chains), each with its Decided-by attribution.
- **Sprint auto-decisions** — entries from `sprint-log.md` in range; list every `low`-confidence
entry verbatim, count the `high` ones.
- **Open questions** — all currently-unresolved `[CONFIRM-NN]` items.
- **Checkpoint findings** — from the most recent `checkpoints/*.md`: findings still open.
3. Write the packet to `<project-root>/.codearbiter/audits/<YYYY-MM-DD>.md` (second run the same day appends `-2`, `-3`, … — an existing packet is never overwritten). Surface the path and a three-line summary: commits, overrides, open items.
Hard gate
Read-only over every source — MUST NOT modify any log, decision, or checkpoint while assembling. MUST NOT overwrite an existing packet. MUST quote override and low-confidence sprint entries verbatim — never paraphrase an audit line. An empty section is stated as empty, never omitted — "no overrides in window" is itself the finding.
When NOT to use
- Live project state right now → `$ca-status`.
- Triggering reviews → `$ca-checkpoint` (this command only reports what reviews already found).
When you can't trust yourself with your code base, trust Arbiter.
Repo: arbiterForge/codeArbiter
Other skills on codearbiter.
- /brainstorming
The Socratic spec-refinement front of /feature, and the planning front of /sprint. Routed to BEFORE any code — it takes a one-line idea and drives it to an approved, concrete spec with testable acceptance criteria. Four gated phases — frame, refine, write, approve. No
Open skill - /commit-gate
The only path to a commit. Routed to when the user invokes /commit or otherwise instructs codeArbiter to persist staged changes. Nine gated phases — permission, branch, classification, verification (test/lint/secrets), behavioral proof, diff review, selective stage, message,
Open skill - /context-check
Optional manual drift audit — report stale provenance-tracked docs (via _provenancelib drift detection across .codearbiter/.provenance/), then per stale doc offer re-scout / re-baseline / defer. Not the daily loop; commit-gate auto-heal owns routine maintenance.
Open skill - /context-creation
The brownfield back-fill. Routed to by /create-context, and by startup when .codearbiter/CONTEXT.md lacks the <!--INITIALIZED--> body marker but source code exists. Six gated phases — pre-flight, scout dispatch, synthesis, gap interview, write, lock. Reads the existing codebase
Open skill - /crypto-compliance
The banned-primitive gate. Routed to when changed code hashes, signs, encrypts, derives keys, generates security-relevant randomness, configures TLS, or imports a crypto library. Rejects broken primitives, disabled TLS verification, and home-rolled crypto; the approved-primitive
Open skill - /debug
Investigate-then-decide root-cause analysis for a defect whose cause is unknown (distinct from /fix, which assumes a known bug). Five gated phases: capture, hypothesize, gather, decide, hand off. Investigation only, no code changes; exits to /fix, /adr, or a no-action close.
Open skill

