$ca-audit — promotion packet
SkillDev toolsAssemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the $ca-audit — promotion packet skill
What this skill tells your AI
The instructions your AI receives, as published by arbiterforge/codearbiter in plugins/ca-pi/skills/ca-audit/SKILL.md and read by ahel’s review.
Everything codeArbiter logs, it logs append-only and scattered: overrides.log, triage.log,
decisions/, sprint-log.md, checkpoints/. This command assembles them into the one document a
team lead, compliance reviewer, or auditor actually asks for: what happened in this window, who
authorized it, and what is still open. Read-only over every source; its only write is the packet.
Window
<from-ref> <to-ref>— two tags/SHAs (e.g.v1.2.0 v1.3.0).--since-checkpoint— from thelast-checkpointrecord to HEAD.--since <date>— ISO date to HEAD.- No argument → from the most recent tag to HEAD (no tags → last checkpoint; neither → BLOCK and ask for an explicit window).
Flow
- Resolve the window to a commit range and a time range; both appear in the packet header.
- Gather, citing each source file:
- Commits —
git logover the range, grouped by Conventional-Commit type; merge commits listed with their PR reference. - Overrides — every
overrides.logline in the time range, verbatim (includingSECURITY-OVERRIDEandDEV:entries), each with itsBY:identity. - Triage — every small-lane classification in
triage.login range. - Decisions — ADRs created or superseded in range (from
decisions/file dates and the supersede chains), each with its Decided-by attribution. - Sprint auto-decisions — entries from
sprint-log.mdin range; list everylow-confidence entry verbatim, count thehighones. - Open questions — all currently-unresolved
[CONFIRM-NN]items. - Checkpoint findings — from the most recent
checkpoints/*.md: findings still open.
- Commits —
- Write the packet to
<project-root>/.codearbiter/audits/<YYYY-MM-DD>.md(second run the same day appends-2,-3, … — an existing packet is never overwritten). Surface the path and a three-line summary: commits, overrides, open items.
Hard gate
Read-only over every source — MUST NOT modify any log, decision, or checkpoint while assembling. MUST NOT overwrite an existing packet. MUST quote override and low-confidence sprint entries verbatim — never paraphrase an audit line. An empty section is stated as empty, never omitted — "no overrides in window" is itself the finding.
When NOT to use
- Live project state right now →
$ca-status. - Triggering reviews →
$ca-checkpoint(this command only reports what reviews already found).
Signals
- GitHub stars
- 144
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
ca-audit- Source
- github.com/arbiterforge/codearbiter