Skip to content
Back to skills

Critical Auditor

ASecurity

Conducts a full-system adversarial audit of agent plugins, skills, specifications, and orchestration against enforced runtime contracts using deep reasoning.

  • 7 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 20, 2026
ai-agentspythonshellbashgitsecurity

Security analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned October 3, 2026

npx -y skills add richfrem/agent-plugins-skills --skill critical-auditor --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Critical Auditor?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Critical Auditor
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/richfrem-critical-auditor/badge)](https://www.skillsdirectory.com/skills/richfrem-critical-auditor)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: critical-auditor
description: Conducts a full-system adversarial audit of agent plugins, skills, specifications, and orchestration against enforced runtime contracts using deep reasoning.
allowed-tools: Read, Write, Edit, Bash, Glob, Grep
---

# Critical Auditor (`critical-auditor`)

Conducts failure-seeking adversarial system audits designed to uncover boundary violations, unverified assumptions, and enforcement loopholes.

## Contents

- [Critical Constraints](#critical-constraints)
- [Quick start](#quick-start)
- [Workflow](#workflow)
- [Output Requirements](#output-requirements)
- [Verification](#verification)
- [References](#references)

## Critical Constraints

1. **Unforgiving Mandate**: Treat guarantees as unenforced unless mathematically or programmatically verified by code and tests.
2. **Exploit Reproduction**: Every finding must include a concrete exploit reproduction scenario.
3. **No Muted Severity**: Never downgrade security or boundary findings without empirical proof of remediation.

## Quick start

Audit a target skill for boundary violations and contract enforcement:

```bash
python3 scripts/audit_skill.py <path/to/skill> --strict
```

## Workflow

1. **Map Target Surface**: Identify boundaries, evaluation suites, and state mutators in target skill or plugin.
2. **Adversarial Pass**: Probe execution enforcement, mutation integrity, eval coverage, and sandbox isolation.
3. **Draft Exploitation Scenarios**: Construct minimal repro steps illustrating how checks can be bypassed.
4. **Document Findings**: Assign severity (P0-P2), explain root failure cause, and propose remediation.

## Output Requirements

For each finding, specify:
- **Severity**: P0 (Critical), P1 (Major), P2 (Minor).
- **Reproduction**: Concrete exploit path with shell/code snippet.
- **Root Failure**: Exact reason why existing checks failed to catch it.
- **Remediation**: Structural patch or invariant enforcement.

## Verification

Confirm audit findings are documented and reproducible:

```bash
git status --short
```

## References

- [acceptance-criteria.md](references/acceptance-criteria.md) — Acceptance criteria for adversarial audits.
- [fallback-tree.md](references/fallback-tree.md) — Failure resolution and audit escalation paths.

Files in this skill

  • SKILL.md2.1 KB
  • evals/evals.json1.1 KB
  • references/acceptance-criteria.md59 B
  • references/fallback-tree.md53 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…