---
title: "audits"
description: "Scheduled findings that open PRs/issues, deliberately capped and conservative: audit-architecture (tech-debt sweep), audit-tests (test-suite health), audit-security (vulnerable deps, committed secrets incl. git history, "
canonical: https://agentpluginsdirectory.com/plugins/audits
last-updated: 2026-10-08
---

# audits
Scheduled findings that open PRs/issues, deliberately capped and conservative: audit-architecture (tech-debt sweep), audit-tests (test-suite health), audit-security (vulnerable deps, committed secrets incl. git history, permissive defaults: code patterns are left to Claude Code's built-in /security-review), audit-deps (dependency health: outdated, deprecated, unused, lockfile drift, licenses), audit-design-docs (validate design docs against code), and audit-product-docs (validate user-facing docs against code). Detection rules and invariants come from the repo's.claude/maintainerd.json and guidelines files.
- Slug: audits
- Publisher: Allen Hutchison
- Repository: https://github.com/Vycari/maintainerd
- Manifest: plugins/audits/plugin.json
- Version: 0.3.10
- License: MIT
- Category (editorial): code-review
- Skills: 6 (audit-architecture, audit-deps, audit-design-docs, audit-product-docs, audit-security, audit-tests)
- MCP servers: 0
- Stars: 3
- Repository created: 2026-06-28
- Repository last pushed: 2026-10-08
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/audits
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What audits does, in the publisher's words

Six scheduled sweeps that find work and file it as discrete units, one PR or one issue per finding, never bundled. Built to run unattended several times a day, which is why they are deliberately capped, strict about dedup, and silent on clean: a run that finds nothing produces no PR, no issue, and no report. Absence is the signal.

Honest about coverage. A category whose scanner isn't installed is reported "not scanned", never "clean". A green audit has to mean "we looked", not "we couldn't look".

Pattern promotion. When the same specific problem gets fixed repeatedly, the guideline-checking audits stop re-fixing it and file one human-gated issue proposing it become a rule in config.guidelines: or, if the rule already exists and keeps being violated, a mechanical guard. The mechanism is in references/pattern-promotion.md.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/Vycari/maintainerd/HEAD/plugins/audits/README.md

## Skills

- audit-architecture: Walk the repo's source in the configured language looking for technical debt, oversized files, DRY violations, dead code, missing tests, sloppy typing, weak abstractions, and drift against the repo's documented invariants. Categorize each finding into a discrete unit of work; open a focused PR for…
- audit-deps: Scheduled dependency-health sweep: outdated packages (behind on patch/minor/major), deprecated or end-of-life packages, unused declared dependencies, phantom (used-but-undeclared) dependencies, lockfile drift, and license issues. Routes one focused PR for mechanically-safe fixes (a batched routine…
- audit-design-docs: Review design/architecture/planning docs, validate each claim against the code, fix drift, and add docs for uncovered load-bearing subsystems. Use when the user asks to "review planning docs", "audit the design docs", "validate docs against the code", "sync docs with the codebase", "find doc gaps",…
- audit-product-docs: Validate the repo's user-facing / product / contributor docs against the code (settings/config names + defaults, command/action IDs, file paths, schedule/cron formats, tool/function names), patch drift in place, and add new docs only for user-visible features that aren't covered. Use when the user…
- audit-security: Scheduled security sweep of the whole repo, known-vulnerable dependencies (CVEs), secrets/credentials committed to the tree or git history, and hardcoded config / permissive defaults. Severity-ranked; opens a focused PR for mechanically-safe fixes and files an issue for anything needing judgment, …
- audit-tests: The repo's test-suite health expert. Reviews the test suite the way a senior staff engineer who cares about test quality would, coverage gaps on critical paths, inappropriate or excessive mocking (mocking what you own, mocks that never assert, asserting on mock internals over behavior), weak or ab…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
