MUST-panxiao

Codebase Tribunal — Security skill for Claude Code

Security community

⚖️ Your codebase is on trial: 5-8 AI expert personas (PM/architect/backend/security/QA/DevOps) audit any project → quantified verdict with score caps + evidence-backed findings + an executable fix pla.

How to install Codebase Tribunal

This entry records only its repository, not the path inside it, so there is no exact command to give. Open MUST-panxiao/codebase-tribunal and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Codebase Tribunal does

⚖️ Your codebase is on trial: 5-8 AI expert personas (PM/architect/backend/security/QA/DevOps) audit any project → quantified verdict with score caps + evidence-backed findings + an executable fix plan. Distilled from 8 real project reviews. 把代码库送上审判庭

Alternatives in Security

  • CodexQB — CodexQB is a Codex plugin for evidence-backed repo comprehension, planning, QA audit, and gated implementation 186 ★
  • UX A11y — WCAG 2.1 AA accessibility audit plus common-courtesy checks beyond the spec 66 ★
  • POC — Generate an executable proof-of-concept exploit for a confirmed High/Critical finding — detect the toolchain 50 ★

README

⚖️ Codebase Tribunal

**Your codebase is on trial. Eight AI experts are the judges.**

[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE) ![Agent Skill](https://img.shields.io/badge/type-Agent%20Skill%20·%20SKILL.md-8b5cf6.svg) ![Field-tested](https://img.shields.io/badge/field--tested-8%20real%20projects-green.svg) ![Precedents](https://img.shields.io/badge/finding%20patterns-44-f97316.svg)

In this court, your project is **guilty until proven shippable**.

One command convenes a full review tribunal — Project Manager, Product Manager, Architect, Backend Engineer, Frontend/UI Engineer, Security Engineer, QA Engineer, DevOps Engineer. Each judge inspects your project through their own professional lens, **independently, without seeing each other's notes**. Then the court hands down:

  • ⚖️ A quantified verdict — per-role scores, plus an overall score under sentencing guidelines: any Critical finding caps the project at 7/10; three Criticals cap it at 5. A beautiful average can't save you.
  • 📋 A rap sheet with evidence — every finding cites path:line, severity (🔴 Critical / 🟡 Warning / 🟢 Suggestion), and why it matters. Dynamic findings are verified by actually running your app locally (实测 = tested, not guessed). No "the code could be better" hand-waving.
  • 🔧 A court-ordered fix plan (MASTER_FIX_PLAN.md) — every task carries the exact file, line number, current code snippet, expected change, and a copy-pasteable verification command. Hand it to Claude Code / Cursor / your coding agent and walk away.

**Field-tested, not vibes.** On a real flu-prediction platform, a manual 5-role sequential pass found 16 issues. The same project before this tribunal: **31 issues** — including unauthenticated delete endpoints, path traversal, and a CVE in the auth library that nobody had noticed. Parallel judges with independent context windows surface what a single-pass review misses. All 44 finding patterns in this repo's pre