Claude Code Audit Gate — Security skill for Claude Code
Independent audit agent for Claude Code: audits an app built by another agent (OWASP ASVS/Top 10 security, every feature, UI via Playwright, single source of truth, repo hygiene, git practice, token e.
How to install Claude Code Audit Gate
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open fotografvecerek-ai/claude-code-audit-gate and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Claude Code Audit Gate does
Independent audit agent for Claude Code: audits an app built by another agent (OWASP ASVS/Top 10 security, every feature, UI via Playwright, single source of truth, repo hygiene, git practice, token efficiency), never writes code, hands findings with fixes to the project agent, verifies fixes via six gates, blocks release via hooks/pre-commit/CI.
Alternatives in Security
- Competitive Audit — Capture a competitor website with Playwright and extract its color system, typography, layout patterns, and 's 309 ★
- Gdpr Review — Audit the codebase (or a given path/feature) for GDPR compliance and produce a prioritized findings report 172 ★
- Security Audit Stride — Chạy checklist bảo mật OWASP Top 10 + STRIDE trước bước review cuối của Tech Lead trong WF-REVIEW-CRIT (luôn c 90 ★
README
Auditor — independent audit agent for Claude Code
**EN:** An independent *audit agent* for [Claude Code](https://code.claude.com). It audits an application built by another agent (the project agent, here called **Kapitán**): security (OWASP ASVS / Top 10), every feature, the UI via Playwright (every screen, every interactive element), single source of truth, repo hygiene, git practice, agent efficiency (tokens, model routing), sustainability of the stack for the stated intent, backups. It **never writes code, never changes the repo, never deploys**. It hands a package of findings with proposed fixes to the project agent, enforces *stop-the-line*, independently re-verifies every fix through six gates, and gates the release with **technical barriers** (Claude Code hooks, git pre-commit, GitHub Actions) — not just words in a prompt.
The tool, its prompts and documentation are in **Czech** today. An English layer is the most wanted contribution — see [CONTRIBUTING.md](CONTRIBUTING.md). Windows (`START.cmd`) and macOS/Linux (`start.sh`) are supported.
**Read first / Čtěte nejdřív:** [docs/WHAT-IT-DOES.md](docs/WHAT-IT-DOES.md) (EN) · [docs/CO-TO-UMI.md](docs/CO-TO-UMI.md) (CZ) — why this is not a one-shot audit tool but a permanent, independent role in the project, what exactly it audits, how the release gate works, and what you get.
CZ — co to je
Samostatný agent pro Claude Code, který **audituje** aplikaci vyvíjenou jiným agentem (**Kapitánem**): bezpečnost, funkčnost každé funkce, UI přes Playwright (každá obrazovka, každý prvek), jediný zdroj pravdy, pořádek v repu, git praxi, efektivitu agentů (tokeny, modely), vhodnost technologie pro záměr, zálohy. Sám **nic nekóduje, nemění a nevydává**. Nálezy s návrhem řešení předá Kapitánovi, vynutí STOP-THE-LINE, každou opravu nezávisle ověří (šest bran) a vydání povolí až zeleným verdiktem — brány jsou technické (hooky, git hook, CI).
Vznikl z reálné potřeby: agenti píšou kód rychle, ale „hotovo"
Related Skills
Audit With Verification
Run a parallel-review-then-adversarial-verify audit on a URL, feature spec, or code path. Dispatches N reviewe
Owasp Security
OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026) with code review checklists, secure patterns, and
Architecture Pro
Pro-level system architecture design and audit with typed evidence, independent verification, explicit consent
Persuasion Audit
Claude Skill: audits a website or app for Robert Cialdini's 7 principles of persuasion — screenshot-backed fin
Orchestrate Consult
Run an independent external audit of a completed ZOdyssey run. Hands the plan + full git diff to the external
Audit End Sprint
End-of-sprint code audit — run 9-dimension sweep (security, quality, tests, dead code, TODO/FIXME, perf, docs,
Related Agents
Appsec Engineer
Application Security Engineer (Tier 3): reviews and tests code against OWASP Top 10:2025 / ASVS — authenticati
Security Audit Agent
자바 코드 보안 취약점 검증 전문. Refactor 작업 직후 또는 git commit 직전 호출. OWASP Top 10 + Secret Scan (trufflehog/ggshield) + Pro
Tc Creator
Creates one test case in Zephyr or another test-management system from an approved structured spec. Use for bu