Codebase Tribunal — Security skill for Claude Code
⚖️ Your codebase is on trial: 5-8 AI expert personas (PM/architect/backend/security/QA/DevOps) audit any project → quantified verdict with score caps + evidence-backed findings + an executable fix pla.
How to install Codebase Tribunal
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open MUST-panxiao/codebase-tribunal and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Codebase Tribunal does
⚖️ Your codebase is on trial: 5-8 AI expert personas (PM/architect/backend/security/QA/DevOps) audit any project → quantified verdict with score caps + evidence-backed findings + an executable fix plan. Distilled from 8 real project reviews. 把代码库送上审判庭
Alternatives in Security
- CodexQB — CodexQB is a Codex plugin for evidence-backed repo comprehension, planning, QA audit, and gated implementation 186 ★
- UX A11y — WCAG 2.1 AA accessibility audit plus common-courtesy checks beyond the spec 66 ★
- POC — Generate an executable proof-of-concept exploit for a confirmed High/Critical finding — detect the toolchain 50 ★
README
⚖️ Codebase Tribunal
**Your codebase is on trial. Eight AI experts are the judges.**
[](LICENSE)   
In this court, your project is **guilty until proven shippable**.
One command convenes a full review tribunal — Project Manager, Product Manager, Architect, Backend Engineer, Frontend/UI Engineer, Security Engineer, QA Engineer, DevOps Engineer. Each judge inspects your project through their own professional lens, **independently, without seeing each other's notes**. Then the court hands down:
- ⚖️ A quantified verdict — per-role scores, plus an overall score under sentencing guidelines: any Critical finding caps the project at 7/10; three Criticals cap it at 5. A beautiful average can't save you.
- 📋 A rap sheet with evidence — every finding cites
path:line, severity (🔴 Critical / 🟡 Warning / 🟢 Suggestion), and why it matters. Dynamic findings are verified by actually running your app locally (实测= tested, not guessed). No "the code could be better" hand-waving. - 🔧 A court-ordered fix plan (
MASTER_FIX_PLAN.md) — every task carries the exact file, line number, current code snippet, expected change, and a copy-pasteable verification command. Hand it to Claude Code / Cursor / your coding agent and walk away.
**Field-tested, not vibes.** On a real flu-prediction platform, a manual 5-role sequential pass found 16 issues. The same project before this tribunal: **31 issues** — including unauthenticated delete endpoints, path traversal, and a CVE in the auth library that nobody had noticed. Parallel judges with independent context windows surface what a single-pass review misses. All 44 finding patterns in this repo's pre
Related Skills
Understudy
One AI, Every Role — A system that configures teams of specialized AI agents (Architect, Backend, Frontend, De
Openclaw Godmode Skill
🚀 GodMode Skill for OpenClaw - Autonomous Claude Code multi-agent coding orchestration. 8 specialized agents
Full Feature
End-to-end feature pipeline from ADR to deploy-ready PR. Chains architect-planner → implementation agents → te
Claude Code Dev Agents
A comprehensive collection of specialized Claude Code subagents for software development lifecycle. Domain-agn
Millieskills
Research-driven universal AI Agent Skills for UI/UX, code repair, security, testing, architecture, backend/API
Hermes Claude Code Bridge
Run Claude Code or OpenCode as an OpenAI-compatible backend — a security-first, read-only Lead DevOps/SRE agen
Related Agents
Deployment Risk Scorer
Risk-score a change set before deploy. SfSkills devops workflow agent, /score-deployment: reads its AGENT.md p
Jackson
Independent red-team agent for plans, architecture, strategy, and consequential recommendations. Checks decisi
Convergence Monitor
Cross-iteration convergence tracker — runs 6 detection algorithms (score-based, semantic, diminishing returns,