Azienda Audit — Security skill for Claude Code
Audit of the Leader's compliance with the project's policies (policy-drift, on-demand).
How to install Azienda Audit
Installs to ~/.claude/skills/tcsenpai-azienda-azienda-audit/SKILL.md
mkdir -p ~/.claude/skills/tcsenpai-azienda-azienda-audit && curl -fsSL https://raw.githubusercontent.com/tcsenpai/azienda/HEAD/commands/azienda-audit.md -o ~/.claude/skills/tcsenpai-azienda-azienda-audit/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
What Azienda Audit does
description: Audit of the Leader's compliance with the project's policies (policy-drift, on-demand) argument-hint: (none) allowed-tools: Bash(bash ${CLAUDE_PLUGIN_ROOT}/scripts/audit.sh *)
Facts for the audit
!`bash ${CLAUDE_PLUGIN_ROOT}/scripts/audit.sh report`
What to do now
Above are the facts and instructions for the compliance audit. It's not automatic: it's YOU (the Leader) who judges your own work against the stated policies. Proceed as follows:
- Read `./.claude/azien
Alternatives in Security
- OpenTag — Open-source, channel-native agent gateway for Slack 499 ★
- Design Compliance — Audit or generate regulation-specific UI patterns for HIPAA, PCI DSS, or ADA compliance 309 ★
- Gdpr Review — Audit the codebase (or a given path/feature) for GDPR compliance and produce a prioritized findings report 172 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Review Iac Consistency
Audit infrastructure-as-code for per-environment drift, over-permissive IAM policies, unencrypted resources, a
Ops Engineering Skills
Open-source, cross-agent Agent Skills for DevOps, DevSecOps, Cloud, Kubernetes/platform engineering, CI/CD too
Review Code Maintainability
Structural maintainability audit: god objects, hidden coupling, dead code, comment-standard compliance, and dr
Kit Audit
Measure the factory-kit's token footprint — baseline vs on-demand, heaviest assets, trim candidates
Msf Quickwin
Metasploit exploit-on-demand for an identified CVE / fingerprinted service / scanner-detected vuln — use audit
Securevector AI Threat Monitor
Security & Observability for AI Agents — audit every tool call, enforce allow/block policies, catch prompt inj
Related Agents
Luogotenente
CONFINED operational executor for azienda mode. The Leader/CTO persona (main session) delegates HERE the heavy
Governance Reviewer
Reviews a change for governance compliance using PromptWise — security scan, policy check, quality gate, and a
Audit Policy Compliance
Platform policy specialist. Returns schema-valid findings covering platform eligibility, regulated categories,