- Home
- Skills
- Code Quality & Review
- AI Build Auditor
Works with the AI tools you already use
AI Build Auditor
Independently audit AI-built software for requirements, security, testing, scope, regressions, and ship readiness.
$25
AI Build Auditor
Example session with this skill installed
Perform a professional deep audit of this AI-built SaaS application before we ship it.
Audit it against the supplied requirements and inspect the implementation, tests, dependencies, configuration, changed files, and deployment setup where available.
Pay particular attention to
- missing or partially implemented requirements
- authentication and authorization
- data integrity
- API and database changes
- security vulnerabilities
- regression risk
- scope creep
- whether tests actually prove the required behavior
- production-readiness gaps
Do not assume the project is complete because the coding agent says it is done.
For every significant finding, include severity, verification status, evidence, impact, recommendation, and whether it blocks shipment.
Finish with a 0–100 readiness score when sufficient evidence exists and give one final verdict:
SHIP, SHIP WITH CONDITIONS, DO NOT SHIP, or CANNOT VERIFY.
- Read your context and instructions
- Compiled the ai build auditor
- Generated the document
AI BUILD AUDIT
Project: Client SaaS Application
Audit date: 2026-09-12
Audit confidence: MEDIUM
Readiness score: 78/100
Final verdict: DO NOT SHIP
Executive Summary
The core application functionality appears substantially implemented, but the available evidence does not support production delivery yet.
The strongest evidence is the presence of the primary application workflows, automated tests covering several core paths, dependency manifests, and a functioning build process.
However, two high-risk areas require resolution before shipment:
- Authorization enforcement is inconsistent across protected API routes.
- Payment failure handling does not provide sufficient evidence that application state remains consistent when a payment operation fails.
Additional verification gaps remain around production configuration, regression coverage, and deployment rollback procedures.
The project should not be considered production-ready solely because the application builds successfully.
Requirement Matrix
| ID | Requirement | Status | Evidence | Risk |
|---|---|---|---|---|
| REQ-01 | User authentication | PASS | Authentication implementation and tests | Low |
| REQ-02 | Role-based authorization | PARTIAL | Authorization present on primary routes, missing enforcement on two API paths | High |
| REQ-03 | Payment workflow | PARTIAL | Payment implementation and happy-path tests | High |
| REQ-04 | User dashboard | PASS | Implementation and integration tests | Low |
| REQ-05 | Data validation | PASS | Server-side validation and tests | Medium |
| REQ-06 | Production deployment | UNVERIFIED | Deployment configuration could not be independently verified | Medium |
Critical Findings
[P1] Inconsistent Authorization Enforcement
Status: CONFIRMED
Requirement: REQ-02
Evidence: Protected application functionality uses role checks, but two API endpoints do not demonstrate equivalent server-side authorization enforcement.
Impact: A user could potentially reach functionality outside their intended permission boundary.
Recommendation: Centralize authorization enforcement and add tests covering every protected endpoint and role combination.
Ship blocker: YES
[P1] Payment Failure State Handling
Status: PROBABLE
Requirement: REQ-03
Evidence: Happy-path payment tests are present, but sufficient evidence was not found for all failure and partial-transaction states.
Impact: A failed payment operation could potentially leave application state inconsistent with the external payment provider.
Recommendation: Add failure-path integration tests covering declined payments, interrupted requests, retries, duplicate events, and state reconciliation.
Ship blocker: YES
Functional Audit
The principal user workflows appear implemented.
Positive evidence includes
- authentication workflow
- dashboard functionality
- core data operations
- server-side validation
- primary payment flow
The largest functional concern is incomplete evidence around failure states.
Successful execution of the primary workflow does not establish that unexpected states are handled safely.
Security Audit
Authentication controls were identified and several protected workflows appear to enforce access restrictions.
However, authorization enforcement should be treated as incomplete until every protected API path has been verified.
No claim of complete security is made.
Within the examined scope, no additional confirmed critical security issue was identified, but the audit cannot establish that the system is fully secure.
Architecture & Code Quality
The implementation is generally understandable and does not appear to require unnecessary architectural complexity.
Some areas would benefit from stronger separation of authorization logic and more consistent error handling.
These concerns are not individually shipment blockers but should be addressed as part of normal technical maintenance.
Testing & Evidence
Tests found
- Unit tests
- Integration tests
- Selected workflow tests
- Build validation
Verification gaps
The presence of tests does not automatically prove requirement satisfaction.
Additional evidence is needed for
- authorization coverage across protected endpoints
- payment failure handling
- duplicate payment events
- regression coverage for shared components
- production deployment behavior
Scope Audit
The primary implementation appears aligned with the requested application functionality.
Additional refactoring and dependency changes were observed.
These should be classified as
- JUSTIFIED — required by the implementation
- BENEFICIAL — improves maintainability without changing product behavior
- UNRELATED — not necessary for the approved outcome
No change should automatically be treated as scope creep without comparing it against the approved requirements.
Regression Risk
Regression status: UNVERIFIED
Changes involving shared application components and API behavior require additional regression verification.
The absence of evidence should not be interpreted as evidence that existing functionality remains unaffected.
Production Readiness
The code may be approaching delivery readiness, but production readiness has not been established.
Before deployment, verify:
- production environment variables
- migration behavior
- startup behavior
- error handling
- logging
- monitoring
- backups
- rollback procedure
- deployment configuration
- removal of development settings
Required Actions Before Shipment
- Resolve the P1 authorization enforcement issue.
- Verify payment failure and state-reconciliation behavior.
- Add regression tests for affected shared/API functionality.
- Verify production configuration and deployment behavior.
- Document rollback and recovery procedures.
- Address lower-priority maintainability findings.
Final Decision
DO NOT SHIP
Two P1 issues remain unresolved: authorization enforcement and payment failure handling.
The remaining requirements are substantially implemented, but the available evidence does not support production delivery until these blockers are addressed and verified.
Build Readiness: 78/100
Audit Confidence: MEDIUM
Decision: DO NOT SHIP
ai-build-auditor.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
AI Build Auditor is an independent quality-audit skill for AI-assisted software projects.
It evaluates a build against its actual requirements and available evidence instead of trusting claims such as “done,” “working,” “tested,” or “production ready.”
The skill audits:
- Requirements and acceptance criteria
- Functional correctness
- Authentication and authorization
- Security risks
- Data integrity
- Architecture and code quality
- Dependencies
- Testing and test evidence
- Regression risk
- Scope deviations
- Deployment and production readiness
- Commercial delivery compliance
Every meaningful finding is classified by severity from P0 (Critical) through P3 (Low), with clear evidence, impact, recommendation, and shipment-blocker status.
AI Build Auditor also distinguishes between CONFIRMED, PROBABLE, and UNVERIFIED findings. Missing evidence is never silently converted into a PASS.
The final report provides a structured requirement matrix, critical findings, audit sections, prioritized remediation actions, a 0–100 Build Readiness Score when sufficient evidence exists, and one clear release verdict:
SHIP SHIP WITH CONDITIONS DO NOT SHIP CANNOT VERIFY
Use it before shipping an AI-built application, accepting work from an AI coding agent, deploying to production, or delivering a software project to a client.
It is an auditor, not an implementation agent: it challenges unsupported claims and reports what the available evidence actually establishes.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 21 days ago
- Passed all security checks, Safe to install