agentCLAWHUBUnverified

tiered-audit

Runs a three-tier codebase audit (git history, targeted scans, full review) with gating Skill: tiered-audit Owner: athola Summary: Runs a three-tier codebase audit (git history, targeted scans, full review) with gating Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:19:39.886Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:39:49.189Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:56:37.407Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:04:46.458Z | user Release v1.9.14 v1.9.13 | 2026-06-27

OpenClaw

Rank

62

Safety

84

Downloads

1.6k

Updated

Oct 10, 2026

Version

1.9.19

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.6K downloadsadoption · observed Oct 10, 2026
Latest release
1.9.19release · observed Aug 26, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-pensive-tiered-audit
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-tiered-audit/snapshot"

Documentation

CLAWHUB

141,516 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: tiered-audit
description: |
  Runs a three-tier codebase audit (git history, targeted scans, full review) with gating
version: 1.9.8
triggers:
  - audit
  - git-history
  - code-quality
  - review
  - escalation
  - auditing a codebase before release or after incidents
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/pensive", "emoji": "\ud83e\udd9e", "requires": {"config": ["night-market.imbue:proof-of-work"]}}}
source: claude-night-market
source_plugin: pensive
---

> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.


# Tiered Audit

## Table of Contents

- [When to Use](#when-to-use)
- [When NOT to Use](#when-not-to-use)
- [Tier 1: Git History Audit](#tier-1-git-history-audit)
- [Tier 2: Targeted Area Audit](#tier-2-targeted-area-audit)
- [Tier 3: Full Codebase Audit](#tier-3-full-codebase-audit)
- [Output Contract](#output-contract)

## When To Use

- Auditing codebase quality, patterns, or problems
- Reviewing what changed on a branch before merge
- Investigating areas of instability or churn
- Pre-PR quality assessment

## When NOT to Use

- Reviewing a specific file (use pensive:code-reviewer)
- Architecture-only review (use pensive:architecture-review)
- Single-commit review (use imbue:diff-analysis)

## Tier 1: Git History Audit

**Always runs first.** Analyzes git log, diff stats, and
blame to identify areas of concern without reading any
source files.

### What Tier 1 Analyzes

Run these git commands for the target commit range
(default: current branch vs main):

```bash
# 1. Churn hotspots: files changed most often
git log --format="" --name-only {base}..HEAD \
  | sort | uniq -c | sort -rn | head -20

# 2. Diff stats: size of changes per file
git diff --stat {base}..HEAD

# 3. Fix-on-fix patterns: commits fixing previous commits
git log --oneline {base}..HEAD \
  | grep -iE "(fix|revert|patch|hotfix)"

# 4. New file clusters: modules with many new files
git diff --name-status {base}..HEAD \
  | grep "^A" | cut -f2 \
  | sed 's|/[^/]*$||' | sort | uniq -c | sort -rn

# 5. Large commits: single commits with big diffs
git log --format="%h %s" --shortstat {base}..HEAD
```

**Verification:** Confirm each command produces output.
If a command returns empty, the commit range may be wrong;
verify `{base}` resolves correctly with `git merge-base`.

### Tier 1 Output Format

Write findings to `.coordination/agents/tier1-audit.findings.md`:

```markdown
---
agent: tier1-audit
tier: 1
evidence_count: {N}
---

## Summary

{1-2 sentence overview of what the git history reveals}

## Churn Hotspots

{top 10 most-changed files with change counts}

[E1] Command: git log --format="" --name-only ...
     Output: {relevant output}

## Fix-on-Fix Patterns

{commits that fix previous commits in the same area}

[E

_meta.json

{
  "ownerId": "kn7d107jg9jv602h9ytsegydq184a42s",
  "slug": "nm-pensive-tiered-audit",
  "version": "1.9.19",
  "publishedAt": 1787750379886
}

modules/escalation-criteria.md

---
name: escalation-criteria
description: |
  Defines when and why to escalate between audit tiers.
  Tier 1 (git history) -> Tier 2 (targeted area) ->
  Tier 3 (full codebase).
category: audit-scoping
---

# Escalation Criteria

Audit tiers escalate based on evidence from the
previous tier, not by default.
Each escalation requires documented justification.

## Tier 1 -> Tier 2 Escalation

Tier 1 (git-history analysis) flags areas for Tier 2
when ANY of these criteria are met:

### Churn Hotspots

- **3+ files** in the same module changed in the
  analyzed commit range
- **AND** at least one file changed more than twice
- Indicates active development area worth deeper review

### Fix-on-Fix Patterns

- A commit that fixes a previous fix within the same
  module (commit messages containing "fix", "revert",
  "patch", "hotfix" targeting the same files)
- Indicates instability or insufficient testing

### Large Diffs

- Any single commit touching **200+ lines** in one
  module
- Large changes are statistically more likely to
  contain defects

### Suspicious Patterns

- Reverted commits (indicates something went wrong)
- Commits with no tests added alongside implementation
  changes
- Force-pushed branches affecting the module

### New File Clusters

- **5+ new files** added to a single module in the
  analyzed range
- Indicates new feature work that may lack review
  coverage

## Tier 2 -> Tier 3 Escalation

Tier 2 (targeted area audit) recommends Tier 3 when
ANY of these criteria are met:

### Cross-Cutting Concerns

- Findings in one area reveal issues that likely
  affect other areas (e.g., a shared utility function
  with a bug, a pattern used across modules)

### Architectural Issues

- Tier 2 findings indicate structural problems
  (circular dependencies, layering violations,
  inconsistent patterns across modules)

### Coverage Gaps

- Tier 2 reveals that the flagged area is
  representative of a broader pattern (e.g., all
  plugins share the same anti-pattern)

### Severity Threshold

- Tier 2 finds **3+ critical-severity issues** in
  a single area, suggesting systemic quality problems

## Tier 3 Gate

Tier 3 (full codebase audit) requires:

1. **Documented justification** from Tier 2 findings
2. **Explicit user approval** before proceeding
3. **Recommended execution mode**: dedicated sessions
   (not subagents), one area at a time, sequential

The system MUST present the justification and wait for
confirmation.
It MUST NOT auto-escalate to Tier 3.

## Escalation Log Format

Every escalation records:

```markdown
## Escalation: Tier {N} -> Tier {N+1}

**Date**: {timestamp}
**From tier**: {N}
**To tier**: {N+1}
**Target areas**: {list of modules/directories}

### Triggering Evidence

{specific findings from the previous tier that
triggered this escalation, with evidence tags}

### Justification

{why this escalation is warranted, referencing
the criteria above}
```

## No-Escalation Path

When Tier 1 finds NO flags:

- Audit completes at T

modules/tier2-targeted.md

---
name: tier2-targeted
description: |
  Tier 2 targeted area audit. Deep-dives into areas
  flagged by Tier 1, one area at a time, sequential.
category: audit
---

# Tier 2: Targeted Area Audit

Runs ONLY for areas flagged by Tier 1 escalation.
Each area is audited sequentially, never in parallel.

## Execution Protocol

For each flagged area in the escalation list:

1. Load the area context from plugin CLAUDE.md and
   skill descriptions
2. Read source files in the area
3. Analyze for:
   - Code quality patterns and anti-patterns
   - Test coverage (do tests exist for this code?)
   - Documentation currency (do docs match the code?)
   - Architectural fit (does this follow project
     conventions?)
4. Write findings to
   `.coordination/agents/tier2-{area-slug}.findings.md`
5. Validate findings against the Tier 2 output contract
6. Move to next area

## Output Contract (Tier 2)

```yaml
output_contract:
  required_sections:
    - summary
    - scope_analyzed
    - findings_by_severity
    - recommendations
    - evidence
  min_evidence_count: 8
  expected_artifacts: []
  retry_budget: 1
  strictness: strict
```

Tier 2 uses strict mode because it reads source files
and should produce thorough, evidence-backed analysis.

## Sequential Execution

Areas are processed one at a time because:

- Each area analysis fills a significant portion of
  the agent's context
- Sequential processing prevents context cross-
  contamination between areas
- The coordinator can review each area's findings
  before proceeding to the next
- If early areas reveal the issue is resolved, later
  areas can be skipped

## Escalation to Tier 3

After all Tier 2 areas are audited, check whether
Tier 3 is warranted per `escalation-criteria.md`.
If so, present justification to the user and wait
for explicit approval.

modules/tier3-gate.md

---
name: tier3-gate
description: |
  Gate for Tier 3 full-codebase audit. Requires explicit
  user approval and recommends dedicated sessions.
category: audit
---

# Tier 3: Full Codebase Audit Gate

Tier 3 is the most expensive audit tier.
It MUST NOT run without explicit user approval.

> **Why this stays opt-in.** Per
> [docs/inclusive-defaults.md][inc] (TRUE-exception
> category 7), Tier 1 (git history) is the inclusive
> default. Full-codebase scans burn compute and tokens
> at a rate that requires explicit user authorization.

[inc]: ../../../../../docs/inclusive-defaults.md

## Gate Protocol

When Tier 2 findings indicate Tier 3 is warranted:

1. Present the justification to the user:

```markdown
## Tier 3 Escalation Recommended

Tier 2 findings suggest a full codebase audit is
warranted.

### Justification

{specific Tier 2 findings that triggered this}

### Areas Already Reviewed (Tier 2)

{list of areas already audited}

### Estimated Scope

{number of remaining areas / files}

### Recommended Approach

- Use dedicated sessions (one per area)
- Process areas sequentially
- Coordinate via .coordination/ files
- Do NOT use parallel subagents

Proceed with Tier 3? [requires explicit yes]
```

2. Wait for user confirmation
3. If approved, execute with dedicated sessions
4. If declined, finalize with Tier 2 findings

## Execution Mode

Tier 3 MUST use dedicated sessions because:

- Full codebase analysis fills context windows quickly
- Parallel subagents would degrade quality
  (the exact problem this system solves)
- Dedicated sessions get full context windows with
  no completion pressure
- File-based coordination preserves all findings

## Output

Each area produces findings in the standard format:
`.coordination/agents/tier3-{area-slug}.findings.md`

Final synthesis reads all findings files and produces
a comprehensive report.
Github ReposUpdated 15h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/athola/skills/nm-pensive-tiered-audit",
      "sourceUrl": "https://clawhub.ai/athola/skills/nm-pensive-tiered-audit",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T07:08:31.244Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-tiered-audit/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-tiered-audit/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T07:08:31.244Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.6K downloads",
      "href": "https://clawhub.ai/athola/nm-pensive-tiered-audit",
      "sourceUrl": "https://clawhub.ai/athola/nm-pensive-tiered-audit",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T07:08:31.244Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.9.19",
      "href": "https://clawhub.ai/athola/nm-pensive-tiered-audit",
      "sourceUrl": "https://clawhub.ai/athola/nm-pensive-tiered-audit",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-26T13:19:39.886Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-tiered-audit/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-tiered-audit/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.9.19",
      "description": "Release v1.9.19",
      "href": "https://clawhub.ai/athola/nm-pensive-tiered-audit",
      "sourceUrl": "https://clawhub.ai/athola/nm-pensive-tiered-audit",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-26T13:19:39.886Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to tiered-audit and adjacent AI workflows.