audit agents

128 tagged audit, measured the same way as everything else here.

Browse within: compliance 18cmmc 14code audit 14code-quality 14devsecops 14fedramp 14github-copilot 14automation-framework 10compliance-as-code 10continuous-delivery 10devops-platform 10admin-dashboard 9authentication 9authorization 9

AGENTS

25

l-agence/agence

Agent

Agent "AGENTS" from l-agence/agence, covering agence agents: quick reference, 1. aider, → generates patch → applies via aider cli, 2. chad and that's a right dog's dinner. batch 'em up...

4 3mo ago A 0 tokens

ROUTING

26

l-agence/agence

Agent

Agent "ROUTING" from l-agence/agence, covering agence model routing reference (v0.3.0), routing layers (precedence, highest first), operational modes (agenceroutermode), blastradius — code mode sub-tiers (agenceblastradius, v0.5) and @provider.tier routing hint syntax.

4 3mo ago A 0 tokens

api

27

hannsxpeter/godaudits

Agent

This pillar covers fixture API contracts.

4 14d ago A 0 tokens original MIT

auth

28

hannsxpeter/godaudits

Agent

Agent "auth" from hannsxpeter/godaudits, covering scope, context, decisions, rules and workflows.

4 14d ago A 0 tokens original MIT

data

29

hannsxpeter/godaudits

Agent

Agent "data" from hannsxpeter/godaudits, covering scope, context, decisions, rules and workflows.

4 14d ago A 0 tokens original MIT

audit-executor

30

AleksandarBisevac/claude-plugins

Agent

Part of audit

Task executor for the audit orchestrator. Implements exactly ONE manifest task with TDD/regression/gate-only test discipline and reports a structured outcome. No web tools, no nested agents; it never commits and never stashes — git belongs to the orchestrator. Spawned by the audit plugin; not meant for direct use.

4 5d ago A 69 tokens original MIT

audit-explorer

31

AleksandarBisevac/claude-plugins

Agent

Part of audit

Read-only codebase auditor for /audit:init fan-out. Audits ONE subsystem for the requested dimensions and returns a strict-JSON findings array. Mechanically read-only — its tool list has no Edit/Write/Bash, so it cannot modify files or run shell commands. Spawned by the audit plugin; not meant for direct use.

4 5d ago A 72 tokens original MIT

guide

32

AleksandarBisevac/claude-plugins

Agent

Part of audit

Answers questions about the audit plugin itself — what a config key does, how the plan gate grades, how the capability policy resolves, what the journal can and cannot prove — from the plugin's own README, reference docs, schemas and SECURITY.md, with a citation for every claim. Mechanically read-only (Read/Grep/Glob…

4 5d ago A 96 tokens original MIT

bead-epic-auditor

33

jeremylongshore/dolt-mcp-vcs-plugin

Agent

Part of dolt-mcp-vcs

Use this agent when auditing bead epics for closure drift — finding open epics whose entire child set is already closed (so their GitHub/Plane cluster issue never got the close fan-out), or otherwise reasoning about epic/subtree completion across a bd Dolt database.

4 8d ago A 63 tokens original Apache-2.0

davidteren/intent-engineering

Agent

Part of intent-engineering

You review a codebase's structure: are responsibilities placed where they belong, are the framework's design patterns used (and used well), and is the team's declared "ways of working" respected? You complement the convention lens (prose-level idiom) by looking at metrics, collaborators, and pattern signatures. The…

3 17d ago A 116 tokens original MIT

davidteren/intent-engineering

Agent

Part of intent-engineering

You enforce Convention over Configuration and framework idiom. Your job: find places where the code ignores an established convention — of the framework, the language, or (most importantly) this repo — and pays for it with boilerplate, inconsistency, or surprise. Following a convention buys behavior and predictability…

3 17d ago A 78 tokens original MIT

davidteren/intent-engineering

Agent

Part of intent-engineering

You enforce Human Interface Guidelines, Look and Feel, and UX design. Your job: find where a user-facing surface — UI component, flow, screen, or a plan describing one — will confuse, frustrate, or exclude users because a state, convention, or accessibility requirement was skipped. You review the experience decisions…

3 17d ago A 63 tokens original MIT

audit-lead

37

beriktassuly/solana-audit-skill

Agent

Scope Solana and Anchor audit work, choose minimal references, classify attack surface, and route evidence to the right audit workflow.

3 2mo ago A 29 tokens original MIT

finding-writer

38

beriktassuly/solana-audit-skill

Agent

Convert reviewed Solana audit evidence into precise report-ready findings without overstating unsupported exploit claims.

3 2mo ago A 22 tokens original MIT

Code Reviewer

39

mcpambassador/server

Agent

Quality assurance reviewer for pull request review, standards enforcement, and code quality assessment.

3 7d ago A 19 tokens original Apache-2.0

QA Engineer

40

mcpambassador/server

Agent

Quality assurance and test engineer. Writes tests, validates acceptance criteria, tracks coverage, and performs gap analysis.

3 7d ago A 24 tokens original Apache-2.0

Technical Manager

41

mcpambassador/server

Agent

Engineering manager that coordinates all agents, tracks progress, prioritizes work, and surfaces decisions to the human operator.

3 7d ago A 25 tokens original Apache-2.0

policy-guardian

44

shihchengwei-lab/separation-and-audit-claude-code

Agent

Policy-layer text reviewer. Reads user-visible content (copy, UI strings, error messages, docs) and returns an evidence-level audit against your policy checklist. Runs mechanism recall on Step 0 automatically.

2 4mo ago A 44 tokens original MIT

cmmc-assessor

45

vaquarkhan/compliance-agent-skills

Agent

Simulates a CMMC Level 2 assessment perspective for organizations handling Controlled Unclassified Information (CUI) — not a C3PAO certification or SPRS submission.

2 9d ago A 0 tokens original MIT

vaquarkhan/compliance-agent-skills

Agent

Cross-framework compliance architect for organizations running AI agents and MCP servers under HIPAA, HITECH, FERPA, COPPA, NIST AI RMF, PCI-DSS v4.0, SOC 2, ISO 27001, NIST CSF 2.0, CCPA/CPRA, US state privacy, GDPR, FedRAMP, SOX, CMMC, and/or GLBA/FFIEC obligations simultaneously.

2 9d ago A 0 tokens original MIT

vaquarkhan/compliance-agent-skills

Agent

Simulates a FedRAMP Third Party Assessment Organization (3PAO) perspective for Moderate baseline authorization packages — not an official FedRAMP assessment or Agency ATO.

2 9d ago A 0 tokens original MIT

ledger-reviewer

48

eternal-roman/ledger

Agent Claude Code

Part of ledger

Strict reviewer for monetary values, accounts, and financial constructs. Ledger kernel + review + security. Use for PRs or pre-commit on value diffs.

1 3d ago A 36 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: