/audit-evidence
Cross-phase audit of all outstanding Evidence Review and findings validation items
$ npx -y skills add backbay-labs/thrunt-god --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/audit-evidence
Context preview
What this command does when you run it.
Cross-phase audit of all outstanding Evidence Review and findings validation items
Command definition
audit-evidence.mdname: thrunt:audit-evidence description: Cross-phase audit of all outstanding Evidence Review and findings validation items allowed-tools: - Read - Glob - Grep - Bash
<objective> Scan all phases for pending, skipped, blocked, and human_needed Evidence Review items. Cross-reference against codebase to detect stale documentation. Produce prioritized human test plan. </objective>
<execution_context> @~/.claude/thrunt-god/workflows/audit-evidence.md </execution_context>
<context> Core planning files are loaded in-workflow via CLI.
**Scope:** Glob: .planning/phases/*/*-EVIDENCE_REVIEW.md Glob: .planning/phases/*/*-FINDINGS.md </context>
Threat hunting command system for agentic IDEs
Repo: backbay-labs/thrunt-god
Other commands on thrunt-god.
- /help
Show available THRUNT threat hunting commands and artifact layout
Open command - /map-environment
Map available telemetry, query surfaces, tenants, retention windows, and investigation blind spots
Open command - /new-case
Initialize a threat hunting case from a signal, detection, intel lead, or analyst suspicion
Open command - /new-program
Initialize a threat hunting program with an environment map, tool inventory, huntmap, and empty execution directories
Open command - /plan
Create phase plans for a threat hunt with exact telemetry tasks, receipts, and query outputs
Open command - /publish
Publish a hunt as a case report, escalation, detection promotion, or leadership summary
Open command

