/cross-audit
Second-model review. Picks an auditor (codex/gemini/opencode/aider/copilot), excludes the caller, writes a prompt to paste, reads the response back. Usage: /cross-audit [--with <id> | list | compare] <target>
$ npx -y skills add FerroxLabs/ijfw --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/cross-audit
Context preview
What this command does when you run it.
Second-model review. Picks an auditor (codex/gemini/opencode/aider/copilot), excludes the caller, writes a prompt to paste, reads the response back. Usage: /cross-audit [--with <id> | list | compare] <target>
Command definition
cross-audit.mddescription: "Second-model review. Picks an auditor (codex/gemini/opencode/aider/copilot), excludes the caller, writes a prompt to paste, reads the response back. Usage: /cross-audit [--with <id> | list | compare] <target>"
allowed-tools: ["Read", "Write", "Bash", "Grep"]
Structured peer review from a different agent. Solves "don't trust a single model." Works by preparing a prompt for you to paste into another CLI tab, then comparing their response against our own findings.
Subcommands
| Form | Behavior | |------|----------| | `/cross-audit` | **Zero-arg auto-pick.** Detect target from git state (staged → unstaged → last commit). Pick default auditor (first non-self). Generate request. | | `/cross-audit <target>` | Pick default auditor (first non-self). Generate request for the named target. | | `/cross-audit --with <id> [target]` | Force a specific auditor: `codex`, `gemini`, `opencode`, `aider`, `copilot`, `claude`. Target optional (auto-detect if omitted). | | `/cross-audit list` | Show the roster with self marker. No request generated. | | `/cross-audit compare` | Read `.ijfw/cross-audit/response.md`, render agreement/new/disputed table, archive. |
Smart target auto-detection (bare `/cross-audit`)
When invoked without a target, run this detection cascade and use the first non-empty result as the target:
1. **Staged changes** -- `git diff --cached --name-only` (the user is mid-commit) 2. **Unstaged changes** -- `git diff --name-only` 3. **Last commit** -- `git diff HEAD~1 --name-only` 4. If all empty: print the roster and ask "what would you like audited?" -- don't guess at random files.
Tell the user which step succeeded:
Cross-audit target auto-detected: 3 staged file(s)
installer/src/install.js
installer/src/marketplace.js
installer/test.js
(Override with /cross-audit <path> or /cross-audit --with <id> <path>.)
If >5 files match, group them in the request body but list all paths so the auditor can scope themselves. If a single huge file (>2000 lines), include only the diff hunks not the full file, to stay under typical context windows.
The natural-language phrase **"cross audit this"** / **"second opinion"** fires the intent router (see `mcp-server/src/intent-router.js`) which nudges Claude to invoke `/cross-audit` automatically -- same auto-detect flow runs.
Default flow -- Donahoe Trident (don't make me think)
Caller is one perspective. **Default ask is for two more.** Per the Donahoe Loop: never trust a single AI; run through three. Two diverse auditors triangulating the caller's findings catches gaps that any single second-opinion would miss.
When invoked, do this in order:
1. **Probe roster.** Call `pickAuditors({ count: 2, env: process.env })` from `audit-roster.js`. Returns `{ picks, missing, note }` -- picks are installed AND non-self. 2. **Show a TODO surface** in chat:
Cross-audit plan
[ ] Wave A Step 1: Generate request (target: <auto-detected>)
[ ] Wave A Step 2: Run auditor 1: <picks[0].name>
[ ] Wave A Step 2: Run auditor 2: <picks[1].name> (or note if only 1 installed)
[ ] Wave B Step 1: Compare findings3. **Ask the user once** which combo to actually run:
Auditors detected and ready: codex, gemini.
Run cross-audit against:
[A] codex only (~$0.20-0.50 estimated)
[B] gemini only (free if Google AI Studio key, else ~$0.05)
[C] Both -- recommended (Donahoe Trident)
[D] Cancel / pick customDefault suggestion: **C (Both)** when >=2 installed.
4. **If only one installed**, surface the principle:
> "Only `<id>` is installed locally. Per the Donahoe Loop and IJFW principles, you're best to have two top-tier AIs review to help avoid gaps and issues that one alone may miss. Install one of the missing auditors (`opencode`, `aider`, etc.) for the full Trident."
Then offer to run the single auditor anyway.
5. **Run** via Bash (`<picks[i].invoke> < .ijfw/cross-audit/request.md > .ijfw/cross-audit/response-<id>.md`). Update TODO to `in_progress` then `completed` per auditor.
5a. **Fire Claude specialist swarm in parallel** (caller leg of the Trident). The caller's contribution is NOT a solo in-session opinion -- it's a parallel dispatch of specialist subagents via the `Agent` tool. Fire these in the same message as the external bg-bash calls so they run concurrently:
| Specialist | Dispatched via | Angle | |------------|---------------|-------| | Code reviewer specialist | `Agent` tool | convention/correctness | | Silent-failure hunter specialist | `Agent` tool | error-swallowing, fallbacks | | Test-coverage analyst specialist | `Agent` tool | coverage gaps | | Type-design analyst specialist | `Agent` tool (typed codebases only) | invariants |
Pick the subset relevant to the target. Merge their findings into ONE composite JSON array matching the audit schema, write to `.ijfw/cross-audit/response-self.md`. This joins the external responses in step 6.
6. **Compare** all returned responses together -- external auditors AND the caller's specialist-swarm composite (`response-self.md`):
- Findings agreed by >=2 sources → **high confidence**
- Findings unique to one source → **investigate**
- Render single merged table with a "consensus" column and a source tag
per finding (codex | gemini | self:code-reviewer | self:silent-failure | …).
7. **Archive** all request + response files to `.ijfw/cross-audit/archive/<ts>-<ids>/`.
Auditor picking
Invoke `node -e "import('./mcp-server/src/audit-roster.js').then(m => console.log(m.formatRoster()))"` (or just read `mcp-server/src/audit-roster.js`) to see:
- Who we detect as the current caller (via env fingerprint)
- Who's available as auditors
- Invocation command for each
Default pick order (first non-self): `codex -> gemini -> opencode -> aider -> copilot -> claude`.
| Aud
Read more
description: "Second-model review. Picks an auditor (codex/gemini/opencode/aider/copilot), excludes the caller, writes a prompt to paste, reads the response back. Usage: /cross-audit [--with <id> | list | compare] <target>" allowed-tools: ["Read", "Write", "Bash", "Grep"]
Structured peer review from a different agent. Solves "don't trust a single model." Works by preparing a prompt for you to paste into another CLI tab, then comparing their response against our own findings.
Subcommands
| Form | Behavior | |------|----------| | `/cross-audit` | **Zero-arg auto-pick.** Detect target from git state (staged → unstaged → last commit). Pick default auditor (first non-self). Generate request. | | `/cross-audit <target>` | Pick default auditor (first non-self). Generate request for the named target. | | `/cross-audit --with <id> [target]` | Force a specific auditor: `codex`, `gemini`, `opencode`, `aider`, `copilot`, `claude`. Target optional (auto-detect if omitted). | | `/cross-audit list` | Show the roster with self marker. No request generated. | | `/cross-audit compare` | Read `.ijfw/cross-audit/response.md`, render agreement/new/disputed table, archive. |
Smart target auto-detection (bare `/cross-audit`)
When invoked without a target, run this detection cascade and use the first non-empty result as the target:
1. **Staged changes** -- `git diff --cached --name-only` (the user is mid-commit) 2. **Unstaged changes** -- `git diff --name-only` 3. **Last commit** -- `git diff HEAD~1 --name-only` 4. If all empty: print the roster and ask "what would you like audited?" -- don't guess at random files.
Tell the user which step succeeded:
Cross-audit target auto-detected: 3 staged file(s) installer/src/install.js installer/src/marketplace.js installer/test.js (Override with /cross-audit <path> or /cross-audit --with <id> <path>.)
If >5 files match, group them in the request body but list all paths so the auditor can scope themselves. If a single huge file (>2000 lines), include only the diff hunks not the full file, to stay under typical context windows.
The natural-language phrase **"cross audit this"** / **"second opinion"** fires the intent router (see `mcp-server/src/intent-router.js`) which nudges Claude to invoke `/cross-audit` automatically -- same auto-detect flow runs.
Default flow -- Donahoe Trident (don't make me think)
Caller is one perspective. **Default ask is for two more.** Per the Donahoe Loop: never trust a single AI; run through three. Two diverse auditors triangulating the caller's findings catches gaps that any single second-opinion would miss.
When invoked, do this in order:
1. **Probe roster.** Call `pickAuditors({ count: 2, env: process.env })` from `audit-roster.js`. Returns `{ picks, missing, note }` -- picks are installed AND non-self. 2. **Show a TODO surface** in chat:
Cross-audit plan
[ ] Wave A Step 1: Generate request (target: <auto-detected>)
[ ] Wave A Step 2: Run auditor 1: <picks[0].name>
[ ] Wave A Step 2: Run auditor 2: <picks[1].name> (or note if only 1 installed)
[ ] Wave B Step 1: Compare findings3. **Ask the user once** which combo to actually run:
Auditors detected and ready: codex, gemini.
Run cross-audit against:
[A] codex only (~$0.20-0.50 estimated)
[B] gemini only (free if Google AI Studio key, else ~$0.05)
[C] Both -- recommended (Donahoe Trident)
[D] Cancel / pick customDefault suggestion: **C (Both)** when >=2 installed.
4. **If only one installed**, surface the principle:
> "Only `<id>` is installed locally. Per the Donahoe Loop and IJFW principles, you're best to have two top-tier AIs review to help avoid gaps and issues that one alone may miss. Install one of the missing auditors (`opencode`, `aider`, etc.) for the full Trident."
Then offer to run the single auditor anyway.
5. **Run** via Bash (`<picks[i].invoke> < .ijfw/cross-audit/request.md > .ijfw/cross-audit/response-<id>.md`). Update TODO to `in_progress` then `completed` per auditor.
5a. **Fire Claude specialist swarm in parallel** (caller leg of the Trident). The caller's contribution is NOT a solo in-session opinion -- it's a parallel dispatch of specialist subagents via the `Agent` tool. Fire these in the same message as the external bg-bash calls so they run concurrently:
| Specialist | Dispatched via | Angle | |------------|---------------|-------| | Code reviewer specialist | `Agent` tool | convention/correctness | | Silent-failure hunter specialist | `Agent` tool | error-swallowing, fallbacks | | Test-coverage analyst specialist | `Agent` tool | coverage gaps | | Type-design analyst specialist | `Agent` tool (typed codebases only) | invariants |
Pick the subset relevant to the target. Merge their findings into ONE composite JSON array matching the audit schema, write to `.ijfw/cross-audit/response-self.md`. This joins the external responses in step 6.
6. **Compare** all returned responses together -- external auditors AND the caller's specialist-swarm composite (`response-self.md`):
- Findings agreed by >=2 sources → **high confidence**
- Findings unique to one source → **investigate**
- Render single merged table with a "consensus" column and a source tag
per finding (codex | gemini | self:code-reviewer | self:silent-failure | …).
7. **Archive** all request + response files to `.ijfw/cross-audit/archive/<ts>-<ids>/`.
Auditor picking
Invoke `node -e "import('./mcp-server/src/audit-roster.js').then(m => console.log(m.formatRoster()))"` (or just read `mcp-server/src/audit-roster.js`) to see:
- Who we detect as the current caller (via env fingerprint)
- Who's available as auditors
- Invocation command for each
Default pick order (first non-self): `codex -> gemini -> opencode -> aider -> copilot -> claude`.
| Aud
IJFW — It Just F*cking Works. Ferrox Labs' local-first infrastructure for AI coding agents: shared memory, smart routing, multi-AI cross-audits, disciplined workflow.
Repo: FerroxLabs/ijfw
Other commands on ijfw.
- /compress
Compress a memory/context file into terse form. Saves ~40-50% tokens per session. Usage: /compress <filepath>
Open command - /consolidate
Dream cycle -- promote patterns, prune stale, reconcile contradictions, optionally promote to global.
Open command - /cross-critique
Adversarial multi-angle critique. All three auditors fire in parallel (codex=technical, gemini=strategic, claude=ux). Counter-args ranked by rebuttal survival score, not raw severity. Usage: /cross-critique [--with <id> | list | compare] <target>
Open command - /cross-research
Two-phase multi-model research. Phase A fans codex+gemini in parallel (benchmarks + citations angles); Phase B synthesises via fresh Claude session. Usage: /cross-research [--with <id> | list | compare] <target>
Open command - /doctor
Run IJFW health check (files, MCP server, hooks, memory, caps, framing)
Open command - /handoff
Generate or load a session handoff. Usage: /handoff [create|resume]
Open command

