Sota Deep Audit — Security skill for Claude Code
The heavy audit — a hostile review of a whole repository by someone who will inherit it: the threat model reconstructed from the code and a control-presence matrix built against it, then code, history.
How to install Sota Deep Audit
Installs to ~/.claude/skills/martinholovsky-sota-skills-sota-deep-audit/SKILL.md
mkdir -p ~/.claude/skills/martinholovsky-sota-skills-sota-deep-audit && curl -fsSL https://raw.githubusercontent.com/martinholovsky/SOTA-skills/HEAD/commands/sota-deep-audit.md -o ~/.claude/skills/martinholovsky-sota-skills-sota-deep-audit/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
What Sota Deep Audit does
description: The heavy audit — a hostile review of a whole repository by someone who will inherit it: the threat model reconstructed from the code and a control-presence matrix built against it, then code, history, decisions, results and forward plan, fanned out across independent agents, load-bearing claims re-measured this session or labelled unverified, every serious finding handed to a refuter that is not you. Expensive; run it at a milestone, an inheritance or a go/no-go, not routinely.
Alternatives in Security
- Security Threat Model — Generate repo-specific threat models identifying trust boundaries 14.6k ★
- Install — Install the Damage Control security hooks system 456 ★
- Engage.Threatmodel — Materialize, lint, and drift-check the engagement threat model 348 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Threat Model Skill
Claude Code skill: write the project's security constitution (assets, roles, trust boundaries, invariants, ent
HarnessDesk
Open-source control plane for coding agents you own — run Codex, Claude Code, Gemini, Cursor and ACP agents si
Security Audit Extended
Read-only security audit skill for coding agents. Cloudflare's audit workflow (coverage ledger, verdict contra
Audit Cc Tail
Detects distinct Claude model variants per family from behavioral fingerprints in Claude Code JSONL history
Skill Threat Modeling
Code-First Deep Risk Analysis Skill for Claude Code - 8-Phase Workflow with Security design review, STRIDE Thr
Agentic Developer Platform
ADP is the foundation for building and running AI agents across an enterprise. Not one product — a base on whi
Related Agents
Video Continuity
Use to audit a multi-clip AI video script for continuity across clip pairs and across the whole story - space,
Gtfs Adversary
Use when you want a hostile GTFS fixture built to break an ingest function or a validator that already exists
Lead Consistency
Cross-unit consistency pass and deduction-matrix arbitration for an audit-style evaluation run. Runs ONCE per