Skills universal-audit
๐Ÿ“ฆ

universal-audit

v1.0.3 Content revision r2 Safe ๐ŸŒ Network access๐Ÿ“ Filesystem accessโš™๏ธ External commands

Audit Software Releases with Evidence

Release decisions often rely on incomplete evidence and inconsistent standards. This skill applies structured controls, deterministic scoring, and mandatory gates to assess readiness.

Supports: Claude Codex Code(CC)
๐Ÿ’Ž 92 Featured

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "universal-audit" from https://skillstore.io/skills/glenskii-universal-audit.md and its manifest at https://skillstore.io/api/skills/glenskii-universal-audit/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "universal-audit". Audit this release at standard depth for a public web application.

Expected outcome:

  • Verdict: Requires rework because two release gates remain unresolved.
  • Coverage: 87 percent overall, with security and reliability above required thresholds.
  • Top actions: close the authorization gap, verify recovery, and resolve the high-severity access-control finding.

Using "universal-audit". Compare this build with the previous audit.

Expected outcome:

  • Four findings are remediated, one is partially remediated, and one has regressed.
  • The current build improves quality coverage but still lacks verified rollback evidence.
  • The release remains conditionally eligible after independent challenge.

Security Audit

Safe
v2 โ€ข 8/9/2026 Open versioned report

All 56 static findings are false positives caused by Markdown formatting, JSON Schema identifiers, audit terminology, or expected local artifact output. The reviewed procedures require authorization for active testing, default to passive inspection, and prohibit unsafe or unauthorized actions.

18
Files scanned
2,534
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were detected by the latest completed static and semantic audit. This does not prove the skill has no side effects.
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/glenskii-universal-audit/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/glenskii-universal-audit/security.svg)](https://skillstore.io/skills/glenskii-universal-audit?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/glenskii-universal-audit?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/glenskii-universal-audit/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/glenskii-universal-audit.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

glenskii. (2026). universal-audit security audit report (audit version 2) [Author version 1.0.3]. Skillstore. https://skillstore.io/skills/glenskii-universal-audit/audits/2

BibTeX citation

@techreport{glenskii-glenskii-universal-audit-2026, author = {glenskii}, title = {universal-audit security audit report (audit version 2)}, institution = {Skillstore}, year = {2026}, number = {2}, url = {https://skillstore.io/skills/glenskii-universal-audit/audits/2}, note = {Author version 1.0.3} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "universal-audit security audit report (audit version 2)" version: "1.0.3" type: report authors: - name: "glenskii" date-released: "2026-08-09" url: "https://skillstore.io/skills/glenskii-universal-audit/audits/2" identifiers: - type: other value: "skillstore:glenskii-universal-audit:audit:2" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
100
Architecture
100
Maintainability
87
Content
65
Community
91
Spec Compliance

What You Can Build

Prepare a release decision

Assess a candidate release against evidence coverage, quality controls, and mandatory gates before deployment.

Run a structured security review

Evaluate security and privacy controls while recording authorization, evidence, limitations, and remediation priorities.

Measure production readiness

Compare engineering quality across architecture, reliability, operations, accessibility, performance, and delivery practices.

Try These Prompts

Start a rapid audit
Run a rapid audit of this repository. Begin with scope, authorization, product profile, and missing intake information.
Assess release readiness
Perform a standard production-readiness audit for this release. Record evidence, limitations, control statuses, scores, coverage, findings, and release gates.
Review a sensitive system
Plan a deep audit for this data-sensitive system. Define required access, evidence, controls, authorization boundaries, and independent verification.
Re-audit remediation
Re-audit the supplied prior findings against the current build. Verify remediation, regressions, remaining risks, current evidence, and changed scores.

Best Practices

  • Define scope, authorization, environment, depth, and product profile before selecting controls.
  • Use affirmative, sanitized evidence and mark unsupported claims as unverified.
  • Keep scores separate from mandatory gates and independent review outcomes.

Avoid

  • Do not treat scanner silence or missing evidence as a passed control.
  • Do not run active tests outside explicit rules of engagement.
  • Do not remove applicable controls to improve coverage or scores.

Frequently Asked Questions

What audit depths are supported?
Rapid supports early screening, standard supports normal release decisions, and deep supports high-consequence or high-assurance reviews.
Does the skill perform penetration testing?
It defaults to passive inspection. Active testing requires explicit authorization and may still require a qualified specialist.
How are release scores calculated?
A bundled Python script applies category weights, control criticality, coverage rules, score caps, and mechanical release gates.
Can a high score override a serious finding?
No. Mandatory gates and unresolved critical or high findings constrain the verdict regardless of the numeric score.
What happens when evidence is unavailable?
The affected control remains unverified, and the missing evidence appears in audit limitations and coverage calculations.
What artifacts does the skill produce?
It produces a manifest, selected controls, evidence ledger, findings, scores, risk register, verification log, and final report.

Developer Details

Author

glenskii

License

MIT

Author version

v1.0.3

Skillstore revision

r2

Ref

f4838806900353c20a6899b1cbb5f5bc3a23357a

Maintenance freshness

8/9/2026

Usage

5 downloads ยท 3 views

File structure

More from glenskii

View all
View all