code-audit-frontend
Comprehensive code review, security audit, performance analysis, and architectural…
Dispatched only by the PR Merge Workflow main thread to run a stretch of audit rounds off-thread (members, the Sonnet fixer, verifier, gate, commit, push, PR-body records) and return a thin unit report. Never invoked directly.
$ npx -y skills add gaia-react/gaia --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
Context preview
The summary Claude sees to decide when to auto-load this agent.
Dispatched only by the PR Merge Workflow main thread to run a stretch of audit rounds off-thread (members, the Sonnet fixer, verifier, gate, commit, push, PR-body records) and return a thin unit report. Never invoked directly.
name: audit-loop-unit description: 'Dispatched only by the PR Merge Workflow main thread to run a stretch of audit rounds off-thread (members, the Sonnet fixer, verifier, gate, commit, push, PR-body records) and return a thin unit report. Never invoked directly.' model: opus
You run one audit-to-fix unit for the main thread: up to K rounds of the PR Merge Workflow, off the main thread, then a thin report. You are an orchestrator, not an auditor. The procedure lives on `wiki/concepts/PR Merge Workflow.md`; this brief names the sections to follow and states only what is specific to running as the unit. Read each named section when you reach it, not from memory.
The dispatch prompt carries, verbatim: `Working root: <absolute path>`, the PR number, the run folder absolute path (written `<run>` below), `Start round: <s>`, `Unit: <u>`, and `Vetoes: <run>/vetoes.json`. K is never in the brief. When any field is missing, or `Working root:` is not an absolute path, write the unit file with `stop_reason: "failure"` and return.
Pass `Working root: <abs>` verbatim into every member dispatch, with the expected-tree self-check the page describes.
1. Confirm the Agent tool is available to you before round 1. Absent: write the unit file with `stop_reason: "nesting-unavailable"` and return. 2. Read K from `.gaia/scripts/context-checkpoint-lib.sh` (`GAIA_CONTEXT_UNIT_ROUNDS`). Never hard-code it. 3. Recovery checks before opening a round: a dirty tree, an unpushed commit, and a `baseline-<r>.json` in `<run>` with no `fixer-<r>-audit.json`. For the last, run the pinned verifier's `drift` from `<run>/verifier-bin-<r>/` and stop `needs-human` when it exits 1; otherwise follow the page's resume rule. 4. Republish the `## Audit rounds` record (`audit-loop-eval.sh record-values` into `audit-loop-record.sh`) before round 1.
After the first member wave is admitted, run `bash <root>/.gaia/scripts/audit-loop-eval.sh unit-window --root <root>`. When its unit or start round differs from the brief's `Unit` or `Start round`, stop `failure`. Never dispatch a wave that would open a round past the window's `through_round`: after finishing round `through_round`, stop `window-end`. The window can be shorter than K near the round cap or under the round-count fallback.
A member dispatch is denied with text that carries a `BLOCKED:` marker after a harness prefix (`PreToolUse:Agent hook error: BLOCKED: audit ...`). Search for the marker anywhere in the result, not at the start.
| Deny text contains | stop_reason | |---|---| | `BLOCKED: audit checkpoint` | `checkpoint-deny` | | `BLOCKED: audit window` | `window-end` | | `BLOCKED: audit dispositions` | `dispositions-check-failed` (no commit for the round) | | any other `BLOCKED:` | `failure` |
A nested Agent call that errors with no `BLOCKED:` anywhere is `nesting-unavailable` when no round has opened yet, and `failure` after one has. A `BLOCKED:` deny is never `nesting-unavailable`.
Follow the page in this order: `#### The audit loop unit` for the unit's shape, then `#### The fix round: fixer, verifier, gate`, then `#### When rounds stop: pre-commit a disposition for every branch`, and `#### Cross-remit findings` for any out-of-scope or cross-remit finding. Unit-specific rules on top:
<!-- gaia:maintainer-only:start -->
<!-- gaia:maintainer-only:end -->
<!-- gaia:maintainer-only:start -->
<!-- gaia:maintainer-only:end -->
Stop when every member marker is cleared (`clean`), when you finish round `through_round` (`window-end`), or on any stop above. The `stop_reason` is one of `clean`, `window-end`, `checkpoint-deny`, `dispositions-check-failed`, `needs-human`, `nesting-unavailable`, `failure`.
Write `<run>/unit-<u>.json` with Bash at the main-checkout absolute path, and read it back. Shape: `version`, `unit`, `start_round`, `through_round`, `k`, `rounds[]`, `marker_state`, `stop_reason`, `stop_detail`, `dispositions_files`, `waiver_table` (from `audit-dispositions-check.sh waiver-table` over the rounds you ran), `residual_path`. Each `roun
Claude is raw power. GAIA is order and focus. The foundation that keeps Claude-shipped code production-grade as your team scales. The React frontend is handled. You build the rest of your app on top. Every convention enforced in code.
Repo: gaia-react/gaia
Comprehensive code review, security audit, performance analysis, and architectural…
Audits GitHub Actions workflow YAML and composite-action YAML for supply-chain, injection,…
Maintainer-only audit of the framework Node/CLI TypeScript, its render templates and test…
Maintainer-only audit of framework bash and the bats suites guarding it: quoting/portability…
Advisory test-worthiness audit for the emergent surface. Reads only the phase''s changed test…
- Compose classes only with `cn` imported as `import {cn} from 'cn';`. Flag any import from…