Skills
Skill 35 of 200
Shared audit integrity framework for all AppSec agents — enforces output quality, intellectual honesty, and continuous improvement through anti-rationalization guards…
1 minute · 304 words · 6 sections
Install
npx skills add github/awesome-copilot --skill audit-integritynpx skills add github/awesome-copilot/plugin marketplace add github/awesome-copilotThe first command installs just this skill, by the name in its SKILL.md; the second installs the whole repository.
Enforces output quality, intellectual honesty, and continuous improvement across all AppSec agents.
This skill provides 7 reusable capabilities. Agents apply all 7 unless their scope excludes a specific component.
| Component | Reference File | Purpose |
|---|---|---|
| Clarification Protocol | clarification-protocol.md (opens in a new tab) | Ask ≤2 targeted questions before analysis when scope is ambiguous |
| Anti-Rationalization Guard | anti-rationalization-guard.md (opens in a new tab) | Table of prohibited rationalizations with mandatory responses |
| Self-Critique Loop | self-critique-loop.md (opens in a new tab) | Mandatory second-pass review after initial analysis |
| Retry Protocol | retry-protocol.md (opens in a new tab) | Tool failure handling — retry once, then document |
| Non-Negotiable Behaviors | non-negotiable-behaviors.md (opens in a new tab) | Hard rules: never fabricate, always cite evidence, report gaps |
| Self-Reflection Quality Gate | self-reflection-quality-gate.md (opens in a new tab) | 1–10 scoring rubric with ≥8 threshold per category |
| Self-Learning System | self-learning-system.md (opens in a new tab) | Lesson/Memory templates and governance rules |
Each agent customizes the Self-Critique Loop checklist and Self-Reflection Quality Gate categories to match its domain. The reference files provide the base templates; agents extend them with domain-specific items.
Shared audit integrity framework for all AppSec agents — enforces output quality, intellectual honesty, and continuous improvement through anti-rationalization guards, self-critique loops, retry protocols, non-negotiable behaviors, self-reflection quality gates (1-10 scoring, ≥8 threshold), and a self-learning system with lesson/memory governance for security analysis agents.
The verbatim description from this skill’s front matter — the string an agent matches on to decide whether to load it.
skills/audit-integrity/SKILL.mdmain, last pushed 24 September 2026.SKILL.md, not by matching a directory convention. 2 distinct layouts observed: .github/skills/*/SKILL.md, skills/*/SKILL.md.h1 and no skipped levels:.github/plugin/marketplace.json by GitHub, declaring 162 plugins. It is read for editorial metadata only — never as the skill index, which is always the repository tree./github/awesome-copilot.md, and each skill at its own .md URL.7 files · 14 KB
Everything this skill ships beside its prose. All of it is set here, as subchapters of skill 35.
Documentation the agent loads on demand, rather than up front.