/ca-tribunal
Deep, rarely-convened whole-codebase audit — eleven specialist lenses, a resumable on-disk audit log, findings filed as GitHub issues on approval. Expensive; estimates cost and STOPs before running. Never a required gate.
$ npx -y skills add arbiterForge/codeArbiter --skill ca-tribunal --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/ca-tribunal
Context preview
The summary Claude sees to decide when to auto-load this skill.
Deep, rarely-convened whole-codebase audit — eleven specialist lenses, a resumable on-disk audit log, findings filed as GitHub issues on approval. Expensive; estimates cost and STOPs before running. Never a required gate.
SKILL.md
ca-tribunal.SKILL.mdname: ca-tribunal
description: Deep, rarely-convened whole-codebase audit — eleven specialist lenses, a resumable on-disk audit log, findings filed as GitHub issues on approval. Expensive; estimates cost and STOPs before running. Never a required gate.
argument-hint: "[scope-path] [--tag <label>]"
$ca-tribunal — deep codebase audit
The deepest, most expensive review codeArbiter offers, convened rarely and on demand. Routes to the tribunal skill. Eleven lenses judge the codebase; every finding persists to its own file (plus append-only triage/run logs) under `.codearbiter/reports/<run-id>/`, so an interrupted run resumes from disk. Never a required gate — critical/high are blocking-severity findings, not a pipeline halt.
Cost first — this lane routinely costs millions of tokens on a large repo. Phase 0 sizes the codebase, prints a token-cost band, recommends the highest-reasoning model, and STOPs for your acknowledgement before dispatching anything. Nothing runs unacknowledged.
Flow
Load and follow the tribunal skill (`${CLAUDE_PLUGIN_ROOT}/routines/tribunal/SKILL.md`). In brief:
Phase 0 (STOP) — cost estimate, model recommendation, resume check. Phase 1 (BLOCK) — map the codebase; risk-rank and mark trust boundaries; record AI-authorship markers and iteration depth. Phase 2 (BLOCK) — dispatch the eleven tribunal-* lenses in priority waves (≤5 in flight); each writes one file per finding under its own `findings/<lens>/` dir. Phase 3 (BLOCK) — triage per wave from disk: dedup, independent calibration, decision vocabulary. Phase 4 (BLOCK) — project the human-readable report from the logs. Phase 5 (BLOCK) — on explicit selection, file findings as GitHub issues; idempotent against the tracker. Phase 6 (STOP) — optional, opt-in KPI telemetry to the public codeArbiter repo.
Arguments
`"scope-path"` — focus the audit on a subtree (default: repository root). The full lens roster still runs; only the scope narrows.
`--tag <label>` — freeform run label recorded in telemetry (see `references/telemetry.md`).
Routes to
`${CLAUDE_PLUGIN_ROOT}/routines/tribunal/SKILL.md` — dispatches the eleven tribunal-* reviewers (and, on a large repo, the optional map-structure / map-deps mappers).
When NOT to use
- A review of the current diff → `$ca-review` (gate-blocking, fast).
- A lean periodic sweep → `$ca-checkpoint` (cheap, frequent; tribunal is its rare, deep counterpart).
- An adversarial STRIDE pass on one sensitive feature → `$ca-threat-model`.
- A governance packet for a window → `$ca-audit`.
- Anything on a schedule or in a hot loop — tribunal is a rare, deliberate, expensive convening, not a routine gate.
Hard gate
MUST NOT dispatch any lens before you acknowledge the Phase 0 cost estimate. MUST NOT act as a required gate or block a merge/commit. MUST NOT file an issue or send telemetry without explicit authorization. Read-only on project code until the filing gate; findings file as GitHub issues, never the task board.
Read more
name: ca-tribunal description: Deep, rarely-convened whole-codebase audit — eleven specialist lenses, a resumable on-disk audit log, findings filed as GitHub issues on approval. Expensive; estimates cost and STOPs before running. Never a required gate. argument-hint: "[scope-path] [--tag <label>]"
$ca-tribunal — deep codebase audit
The deepest, most expensive review codeArbiter offers, convened rarely and on demand. Routes to the tribunal skill. Eleven lenses judge the codebase; every finding persists to its own file (plus append-only triage/run logs) under `.codearbiter/reports/<run-id>/`, so an interrupted run resumes from disk. Never a required gate — critical/high are blocking-severity findings, not a pipeline halt.
Cost first — this lane routinely costs millions of tokens on a large repo. Phase 0 sizes the codebase, prints a token-cost band, recommends the highest-reasoning model, and STOPs for your acknowledgement before dispatching anything. Nothing runs unacknowledged.
Flow
Load and follow the tribunal skill (`${CLAUDE_PLUGIN_ROOT}/routines/tribunal/SKILL.md`). In brief:
Phase 0 (STOP) — cost estimate, model recommendation, resume check. Phase 1 (BLOCK) — map the codebase; risk-rank and mark trust boundaries; record AI-authorship markers and iteration depth. Phase 2 (BLOCK) — dispatch the eleven tribunal-* lenses in priority waves (≤5 in flight); each writes one file per finding under its own `findings/<lens>/` dir. Phase 3 (BLOCK) — triage per wave from disk: dedup, independent calibration, decision vocabulary. Phase 4 (BLOCK) — project the human-readable report from the logs. Phase 5 (BLOCK) — on explicit selection, file findings as GitHub issues; idempotent against the tracker. Phase 6 (STOP) — optional, opt-in KPI telemetry to the public codeArbiter repo.
Arguments
`"scope-path"` — focus the audit on a subtree (default: repository root). The full lens roster still runs; only the scope narrows.
`--tag <label>` — freeform run label recorded in telemetry (see `references/telemetry.md`).
Routes to
`${CLAUDE_PLUGIN_ROOT}/routines/tribunal/SKILL.md` — dispatches the eleven tribunal-* reviewers (and, on a large repo, the optional map-structure / map-deps mappers).
When NOT to use
- A review of the current diff → `$ca-review` (gate-blocking, fast).
- A lean periodic sweep → `$ca-checkpoint` (cheap, frequent; tribunal is its rare, deep counterpart).
- An adversarial STRIDE pass on one sensitive feature → `$ca-threat-model`.
- A governance packet for a window → `$ca-audit`.
- Anything on a schedule or in a hot loop — tribunal is a rare, deliberate, expensive convening, not a routine gate.
Hard gate
MUST NOT dispatch any lens before you acknowledge the Phase 0 cost estimate. MUST NOT act as a required gate or block a merge/commit. MUST NOT file an issue or send telemetry without explicit authorization. Read-only on project code until the filing gate; findings file as GitHub issues, never the task board.
When you can't trust yourself with your code base, trust Arbiter.
Repo: arbiterForge/codeArbiter
Other skills on codearbiter.
- /brainstorming
The Socratic spec-refinement front of /feature, and the planning front of /sprint. Routed to BEFORE any code — it takes a one-line idea and drives it to an approved, concrete spec with testable acceptance criteria. Four gated phases — frame, refine, write, approve. No
Open skill - /commit-gate
The only path to a commit. Routed to when the user invokes /commit or otherwise instructs codeArbiter to persist staged changes. Nine gated phases — permission, branch, classification, verification (test/lint/secrets), behavioral proof, diff review, selective stage, message,
Open skill - /context-check
Optional manual drift audit — report stale provenance-tracked docs (via _provenancelib drift detection across .codearbiter/.provenance/), then per stale doc offer re-scout / re-baseline / defer. Not the daily loop; commit-gate auto-heal owns routine maintenance.
Open skill - /context-creation
The brownfield back-fill. Routed to by /create-context, and by startup when .codearbiter/CONTEXT.md lacks the <!--INITIALIZED--> body marker but source code exists. Six gated phases — pre-flight, scout dispatch, synthesis, gap interview, write, lock. Reads the existing codebase
Open skill - /crypto-compliance
The banned-primitive gate. Routed to when changed code hashes, signs, encrypts, derives keys, generates security-relevant randomness, configures TLS, or imports a crypto library. Rejects broken primitives, disabled TLS verification, and home-rolled crypto; the approved-primitive
Open skill - /debug
Investigate-then-decide root-cause analysis for a defect whose cause is unknown (distinct from /fix, which assumes a known bug). Five gated phases: capture, hypothesize, gather, decide, hand off. Investigation only, no code changes; exits to /fix, /adr, or a no-action close.
Open skill

