Audit Finding Verifier — Security agent for Claude Code
Verifies a single reported audit finding against the actual codebase.
How to install Audit Finding Verifier
Installs to ~/.claude/agents/guidodinello-claude-dotfiles-audit-finding-verifier.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/guidodinello/claude-dotfiles/HEAD/.claude/agents/audit-finding-verifier.md -o ~/.claude/agents/guidodinello-claude-dotfiles-audit-finding-verifier.md Restart Claude Code, or start a new session, for it to be picked up.
What Audit Finding Verifier does
name: audit-finding-verifier description: Verifies a single reported audit finding against the actual codebase. Determines whether it is confirmed, a false positive, or partially accurate. Use when fact-checking audit reports before client delivery. tools: Read, Bash model: sonnet
You are fact-checking a single reported audit finding against a codebase. Your job is to determine if the finding accurately describes reality. Do not fix anything.
The caller will provide: codebase root, fin
Alternatives in Security
- JS Analyzer — JavaScript static analysis agent for client-side security review 812 ★
- Audit Verifier — Adversarially verifies one candidate finding from /bug-audit — tries to REFUTE it by reading the code and, whe 335 ★
- After Confirming A Vulnerability — findings.sh update vuln --status confirmed --confirmed-by "poc-validator" \ --poc-output " " findings.sh updat 213 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Security Triage
Independently evaluate a single security finding to decide whether it is a real, exploitable vulnerability or
Knowledge Verifier
Skeptical fact-checker for proposed changes to the ASEN Engineering system. Verifies every claim against allow
Review Boss
Use PROACTIVELY as the final QA gate before any Forge task is reported done — reviews the finished work agains
Threat Detection Engineer
Principal Threat Detection Engineer with VETO authority over detection-as-code coverage, false-positive-rate d
Audit Sweep
A read-only audit or survey sweep — reviewing a corpus against a stated rule and reporting what violates it, w
Code Reviewer Quality
Use this agent as the second stage of a code review, after spec compliance is confirmed — evaluating code qual
Related Skills
False Positive Triage
Use when investigating a suspected false positive in drift detection, reducing false positive rates, or adding
Skill Audit MCP
Static security scanner for MCP servers, agent skills & plugins: 17 attack patterns / 60 regex signatures, cal
Axguard Adversary
False Positive Adversary diagnostic (not a vuln report). Usage: /axguard-adversary [path]