Install
openclaw skills install agent-skills-auditRun a two-pass, multidisciplinary code audit led by a tie-breaker lead, combining security, performance, UX, DX, and edge-case analysis into one prioritized report with concrete fixes. Use when the user asks to audit code, perform a deep review, stress-test a codebase, or produce a risk-ranked remediation plan across backend, frontend, APIs, infra scripts, and product flows.
openclaw skills install agent-skills-auditRun an expert-panel audit with strict sequencing and one unified output document. Produce findings first, sorted by severity, with file references, exploit/perf/flow impact, and actionable fixes.
Load references/audit-framework.md before starting the analysis.
Collect or infer the following:
If product context is missing, state assumptions explicitly and continue.
Use exactly these roles:
The tie-breaker lead resolves conflicts, prioritizes issues, and produces the final single report.
Follow this sequence every time:
Build Context Read code + product flows. Identify assets, entry points, high-risk operations, privileged actions, external dependencies, and "failure hurts" journeys.
Build Invariant Coverage Matrix Before specialist pass 1, map critical invariants to every mutating path (HTTP routes, webhooks, async jobs, scripts):
references/audit-framework.md.Enforce these requirements:
Apply these guardrails while auditing:
Follow this response structure:
Findings
List only validated issues. Use the finding schema in references/audit-framework.md.
Open Questions / Assumptions State missing context that could change priority or validity.
Change Summary Summarize high-impact remediation themes in a few lines.
Suggested Verification List focused tests/checks to confirm each major fix.
When the target stack is Bun + SQLite, apply the runtime-specific checklist in references/audit-framework.md (Runtime-Specific Heuristics (Bun + SQLite)) before finalizing findings.