← ClaudeAtlas

jstack-auditlisted

Run evidence-bound, read-only JStack code audits across correctness, security, architecture, maintainability, performance, supply chain, tests, data integrity, compatibility, and operations. Use when the user invokes the jstack-audit skill or command, requests a repository audit or release go/no-go review, asks to challenge existing findings, or wants the JStack audit mastery track.
JarodFroneman/jstack · ★ 0 · AI & Automation · score 72
Install: claude install-skill JarodFroneman/jstack
# JStack Audit When an active JStack loop requests audit evidence, remain read-only and return only the audit result and receipt. Never adopt the loop's editing role or declare the native goal complete. Audit the declared subject without changing application code, configuration, Git state, installed tools, or production. Treat the MCP as a deterministic evidence and validation layer; semantic code review remains the Audit Lead's reasoned work. ## Start 1. Parse `[SCOPE]` and the options `--profile`, `--focus`, `--base`, `--fail-on`, `--format`, `--verify`, `--learning-mode`, and `--team-mode`. 2. Return usage only for `help`, `--help`, or `?`; do not inspect a repository. 3. Read project instructions and relevant durable context. 4. Call `jstack_runtime_status`, then `jstack_detect_project`. 5. Call `jstack_audit` to bind the subject, controls, profile, scope manifest, adapter inventory, review evidence, existing secret-scan evidence, and the focus-routed `specialistCapabilityPlan`. Its capability audit domains may strengthen required coverage but may never remove profile or policy domains. 6. Generate candidate findings from cited source evidence, then run a separate challenge pass that looks for guards, callers, tests, reachability limits, and mitigating controls. 7. Call `jstack_audit_finalize` with the coverage manifest, surviving findings, accepted-risk records, and requested formats. 8. Report the result, coverage, findings, blockers, residual r