arbiterforge/ca-audit
Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only.
npx skills add https://github.com/arbiterForge/codeArbiter --skill ca-audit
Everything codeArbiter logs, it logs append-only and scattered: overrides.log, triage.log,
decisions/, sprint-log.md, checkpoints/. This command assembles them into the one document a
team lead, compliance reviewer, or auditor actually asks for: *what happened in this window, who
authorized it, and what is still open.* Read-only over every source; its only write is the packet.
<from-ref> <to-ref> — two tags/SHAs (e.g. v1.2.0 v1.3.0).--since-checkpoint — from the last-checkpoint record to HEAD.--since <date> — ISO date to HEAD.ask for an explicit window).
git log over the range, grouped by Conventional-Commit type; merge commitslisted with their PR reference.
overrides.log line in the time range, verbatim (includingSECURITY-OVERRIDE and DEV: entries), each with its BY: identity.
triage.log in range.decisions/ file dates and thesupersede chains), each with its Decided-by attribution.
sprint-log.md in range; list every low-confidenceentry verbatim, count the high ones.
[CONFIRM-NN] items.checkpoints/*.md: findings still open.<project-root>/.codearbiter/audits/<YYYY-MM-DD>.md (second run thesame day appends -2, -3, … — an existing packet is never overwritten). Surface the path and
a three-line summary: commits, overrides, open items.
Read-only over every source — MUST NOT modify any log, decision, or checkpoint while assembling.
MUST NOT overwrite an existing packet. MUST quote override and low-confidence sprint entries
verbatim — never paraphrase an audit line. An empty section is stated as empty, never omitted —
"no overrides in window" is itself the finding.
$ca-status.$ca-checkpoint (this command only reports what reviews already found).Take arbiterforge/ca-audit from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.