Audit Suite
Run a preset audit workflow (pre-release, audio-deep, security-deep, etc.) — executes a sequence of audits
---
description: "Run a preset audit workflow (pre-release, audio-deep, security-deep, etc.) — executes a sequence of audits"
argument-hint: "<preset-name>"
---
# Audit Suite — Preset Workflows
Run a predefined sequence of audits. This command **actually executes** each audit in the preset by launching a Task agent per audit.
See `.claude/commands/_audit-common.md` for project layout, methodology, and context management rules.
## Parameters (from $ARGUMENTS)
- `--preset <name>`: Which preset to run. Required. Options below.
## Available Presets
### `pre-release` — Run before tagging a release
- /audit-regression — Verify all known fixes still in place
- /audit-incremental — Check recent changes for new bugs
- /audit-security --depth shallow — Quick security sanity check
**When**: Before every release tag.
### `comprehensive` — Full platform audit
- /audit-engine — Deep audio engine dive
- /audit-backend — Deep backend dive
- /audit-frontend — Deep frontend dive
- /audit-integration — Cross-layer flow tracing
- /audit-security — OWASP Top 10
- /audit-concurrency — Race conditions and state integrity
- /audit-deprecation — Deprecated APIs and patterns
- /audit-tech-debt — Accumulated debt (markers, dead code, duplication, complexity)
**When**: Monthly or after major architecture changes.
### `tech-debt-deep` — Surface accumulated debt
- /audit-tech-debt — All 10 debt dimensions
- /audit-incremental --commits 30 — New debt introduced this sprint
**When**: After a milestone closes, before opening the next.
### `post-sprint` — End-of-sprint verification
- /audit-incremental --commits 30 — All changes this sprint
- /audit-regression — Verify fixes from this sprint
**When**: End of every sprint.
### `security-deep` — Deep security review
- /audit-security — Full OWASP Top 10
- /audit-frontend --focus auth,security — Frontend auth/security
- /audit-integration --flows 1,5 — Playback + WebSocket auth flows
**When**: After auth changes, before security review.
### `audio-deep` — Audio pipeline integrity
- /audit-engine — Full engine audit
- /audit-integration --flows 1,3 — Playback + Enhancement flows
- /audit-concurrency --focus 1,2 — Player + Processing pipeline
**When**: After DSP changes, crossfade modifications, or parallel processing updates.
## Execution
### Step 1: Print the Execution Plan
Print a table showing which audits will run:
Audit Suite:
| Step | Audit | Focus | Type |
|---|---|---|---|
| 1 | audit-regression | All known fixes | Lightweight |
| 2 | audit-incremental | Last 10 commits | Lightweight |
| 3 | audit-security --depth shallow | Quick check | Deep (subagents) |
### Step 2: Launch Audits in Parallel
Each audit is independent — they read different files and write separate reports. Launch them ALL simultaneously using the Agent tool.
**Parallelization strategy by preset**:
- **`comprehensive`** (7 audits): Launch ALL 7 as background agents in a single message. Each writes to its own report file — no conflicts.
- **`pre-release`** (3 audits): Launch all 3 in parallel.
- **`post-sprint`** (2 audits): Launch both in parallel.
- **`security-deep`** (3 audits): Launch all 3 in parallel.
- **`audio-deep`** (3 audits): Launch all 3 in parallel.
**Agent configuration for each audit**:
- `subagent_type`: `general-purpose`
- `run_in_background`: `true`
**Agent prompt template** (adapt for each audit):
You are running the
CRITICAL: You MUST perform a FRESH audit by reading and analyzing the CURRENT source code. Do NOT reuse, summarize, or reference any existing report files in docs/audits/. Existing reports may be outdated — the code has changed since they were written. Delete any previous report at the target path before starting.
Read the audit command file at .claude/commands/audit-<name>.md and follow ALL of its instructions exactly:
- Phase 1: Setup (create /tmp dirs, fetch dedup baseline)
- Phase 2: Launch dimension agents (as described in the file)
- Phase 3: Merge results into the final report
- Phase 4: Cleanup
<any --focus or --depth overrides from the preset>
Write the final report to: docs/audits/AUDIT_
IMPORTANT: Follow the context management rules from .claude/commands/_audit-common.md.
**Launch example for `comprehensive`**:
Send a SINGLE message with 7 Agent tool calls, all with `run_in_background: true`. Do NOT wait for one to finish before launching the next.
### Step 3: Wait for All Agents to Complete
You will be notified as each background agent completes. As each finishes, note:
- Whether it succeeded or failed
- The report path (if written)
- The finding count (read the executive summary section)
Wait until ALL agents have completed before proceeding to Step 4.
### Step 4: Print Final Summary
After ALL audits have completed, print:
Audit Suite Results:
| # | Audit | Status | Report | Findings |
|---|---|---|---|---|
| 1 | audit-regression | DONE | docs/audits/AUDIT_REGRESSION_ |
3 PASS, 1 FAIL |
| 2 | audit-incremental | DONE | docs/audits/AUDIT_INCREMENTAL_ |
5 findings |
| 3 | audit-security | DONE | docs/audits/AUDIT_SECURITY_ |
2 CRITICAL, 4 HIGH |
Next Steps
For each report with NEW findings, run /audit-publish in a new conversation:
/audit-publish docs/audits/AUDIT_REGRESSION_<TODAY>.md/audit-publish docs/audits/AUDIT_INCREMENTAL_<TODAY>.md/audit-publish docs/audits/AUDIT_SECURITY_<TODAY>.md
## Important Notes
- Each audit runs as an isolated background agent — it will NOT exhaust this conversation's context.
- Deep audits (engine, backend, frontend, etc.) internally launch
Maintain Audit Suite?
Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.
[Audit Suite on getagentictools](https://getagentictools.com/loops/matiaszanolli-audit-suite-preset-workflows?ref=badge)