auditlisted
Install: claude install-skill sjh9714/red-handed
# Audit this session
Run the audit and report what it found. Nothing here needs to be installed first;
`npx` fetches the CLI on demand.
## Running it
Default — the most recent session for this directory:
```bash
npx --yes @jinhyuk9714/red-handed@latest
```
Useful variations:
- `--all` — every session recorded for this project, not just the latest
- `--lang ko` — report in Korean (it follows the system locale by default)
- `--git-only` — when there is no transcript, audit the working tree diff instead
- `--json` — when you need to read the findings programmatically rather than quote them
The command exits 1 when something reached the CAUGHT tier and 0 otherwise. A
non-zero exit here is the tool working, not an error to retry.
## Reporting what it found
Show the tool's own output. It is written to be read by a person: each finding
already carries a plain-language description, the evidence with timestamps, and
one thing to go check.
Then, briefly:
- If nothing was found, say so plainly. That is the common case and it is not a
disappointment. Do not pad it.
- If something was found, state it without softening and without arguing. When
the finding is about this session, it is about **your own** work — resist the
pull to explain it away. The user asked what the record says; the record is
what it says.
- `CAUGHT` means the session shows it happening and the change is still in the
working tree. `SUSPICIOUS` means the pattern is there but the motive is not
estab