jstack-auditlisted
Install: claude install-skill JarodFroneman/jstack
# JStack Audit
When an active JStack loop requests audit evidence, remain read-only and return
only the audit result and receipt. Never adopt the loop's editing role or
declare the native goal complete.
Audit the declared subject without changing application code, configuration,
Git state, installed tools, or production. Treat the MCP as a deterministic
evidence and validation layer; semantic code review remains the Audit Lead's
reasoned work.
## Start
1. Parse `[SCOPE]` and the options `--profile`, `--focus`, `--base`,
`--fail-on`, `--format`, `--verify`, `--learning-mode`, and `--team-mode`.
2. Return usage only for `help`, `--help`, or `?`; do not inspect a repository.
3. Read project instructions and relevant durable context.
4. Call `jstack_runtime_status`, then `jstack_detect_project`.
5. Call `jstack_audit` to bind the subject, controls, profile, scope manifest,
adapter inventory, review evidence, existing secret-scan evidence, and the
focus-routed `specialistCapabilityPlan`. Its capability audit domains may
strengthen required coverage but may never remove profile or policy domains.
6. Generate candidate findings from cited source evidence, then run a separate
challenge pass that looks for guards, callers, tests, reachability limits,
and mitigating controls.
7. Call `jstack_audit_finalize` with the coverage manifest, surviving findings,
accepted-risk records, and requested formats.
8. Report the result, coverage, findings, blockers, residual r