Audit Orchestrator
Run a structured audit by dispatching specialized audit agents in parallel.
Scope: Parse the user's request to determine scope and parameters. Accepted values: frontend, backend, infra, security, all (default: all).
Dispatch Rules
Based on scope, use spawn_agent to launch the appropriate audit agents in parallel. Use wait_agent / wait to collect results:
| Scope |
Agents dispatched |
frontend |
audit-frontend |
backend |
audit-backend |
infra |
audit-infra (if available) |
security |
security-scanner |
all |
audit-frontend + audit-backend + audit-infra + security-scanner (up to 4 agents in parallel) |
Only dispatch agents that exist in the project's skills directory. Skip unavailable agents with a note.
Execution Steps
Determine scope from the user's request (default: all)
Detect project structure to tailor audit scope:
- Scan for
go.mod, package.json, pyproject.toml, Cargo.toml, docker-compose.yml
- Map detected stacks to relevant audit agents
Launch agents in parallel — use spawn_agent to dispatch all relevant agents simultaneously:
- audit-frontend — UI/UX checks: hardcoded values, console.log, TypeScript strict, query patterns, accessibility, bundle size
- audit-backend — API/logic checks: SQL safety, error handling, PII leaks, auth gaps, input validation, stubs
- audit-infra — Infrastructure checks: Docker security, exposed ports, env secrets, health checks, resource limits
- security-scanner — Cross-cutting security: OWASP top-10, secrets in code, dependency vulnerabilities, auth bypass, CORS, rate limiting
Collect results from all agents using wait_agent / wait
Merge and deduplicate — if the same file:line flagged by multiple agents, keep highest severity
Output unified report
Agent Prompt Template
For each agent, send this prompt:
Run ALL checks from your checklist against the project codebase.
Scope: {scope}
Report every check as PASS/WARN/FAIL with evidence.
End with summary counts and action items for FAILs.
Output Format
After collecting all agent results, produce a unified report:
## Audit Report
Scope: {scope}
Date: {date}
Agents: {list of dispatched agents}
### Frontend (audit-frontend)
[results from agent, or "Skipped — no frontend detected / agent unavailable"]
### Backend (audit-backend)
[results from agent, or "Skipped — no backend detected / agent unavailable"]
### Infrastructure (audit-infra)
[results from agent, or "Skipped — agent unavailable"]
### Security (security-scanner)
[results from agent]
### Grand Summary
| Agent | PASS | WARN | FAIL |
|-------|------|------|------|
| frontend | X | Y | Z |
| backend | X | Y | Z |
| infra | X | Y | Z |
| security | X | Y | Z |
| **Total** | **X** | **Y** | **Z** |
### Critical Action Items (FAILs only)
1. [agent] file:line — description
2. ...
Notes
- All agents run in parallel — audit completes much faster than sequential
- Each agent has its own context window — no pollution of main conversation
- Overlapping checks (e.g., SQL injection in both backend and security) are deduplicated
- For targeted re-audit after fixes, specify a narrower scope
1---2name: audit-orchestrator3description: Run comprehensive parallel audit — dispatches specialized agents by scope (frontend, backend, infra, security)4---5
6# Audit Orchestrator
7
8Run a structured audit by dispatching specialized audit agents in parallel.
9
10**Scope**: Parse the user's request to determine scope and parameters. Accepted values: `frontend`, `backend`, `infra`, `security`, `all` (default: `all`).
11
12## Dispatch Rules
13
14Based on scope, use `spawn_agent` to launch the appropriate audit agents **in parallel**. Use `wait_agent` / `wait` to collect results:
15
16| Scope | Agents dispatched |
17|-------|-------------------|
18| `frontend` | audit-frontend |
19| `backend` | audit-backend |
20| `infra` | audit-infra (if available) |
21| `security` | security-scanner |
22| `all` | audit-frontend + audit-backend + audit-infra + security-scanner (up to 4 agents in parallel) |
23
24Only dispatch agents that exist in the project's skills directory. Skip unavailable agents with a note.
25
26## Execution Steps
27
281. **Determine scope** from the user's request (default: `all`)
29
302. **Detect project structure** to tailor audit scope:
31 - Scan for `go.mod`, `package.json`, `pyproject.toml`, `Cargo.toml`, `docker-compose.yml`
32 - Map detected stacks to relevant audit agents
33
343. **Launch agents in parallel** — use `spawn_agent` to dispatch all relevant agents simultaneously:
35 - **audit-frontend** — UI/UX checks: hardcoded values, console.log, TypeScript strict, query patterns, accessibility, bundle size
36 - **audit-backend** — API/logic checks: SQL safety, error handling, PII leaks, auth gaps, input validation, stubs
37 - **audit-infra** — Infrastructure checks: Docker security, exposed ports, env secrets, health checks, resource limits
38 - **security-scanner** — Cross-cutting security: OWASP top-10, secrets in code, dependency vulnerabilities, auth bypass, CORS, rate limiting
39
404. **Collect results** from all agents using `wait_agent` / `wait`
41
425. **Merge and deduplicate** — if the same file:line flagged by multiple agents, keep highest severity
43
446. **Output unified report**
45
46## Agent Prompt Template
47
48For each agent, send this prompt:
49```
50Run ALL checks from your checklist against the project codebase.
51Scope: {scope}
52Report every check as PASS/WARN/FAIL with evidence.
53End with summary counts and action items for FAILs.
54```
55
56## Output Format
57
58After collecting all agent results, produce a unified report:
59
60```
61## Audit Report
62Scope: {scope}
63Date: {date}
64Agents: {list of dispatched agents}
65
66### Frontend (audit-frontend)
67[results from agent, or "Skipped — no frontend detected / agent unavailable"]
68
69### Backend (audit-backend)
70[results from agent, or "Skipped — no backend detected / agent unavailable"]
71
72### Infrastructure (audit-infra)
73[results from agent, or "Skipped — agent unavailable"]
74
75### Security (security-scanner)
76[results from agent]
77
78### Grand Summary
79| Agent | PASS | WARN | FAIL |
80|-------|------|------|------|
81| frontend | X | Y | Z |
82| backend | X | Y | Z |
83| infra | X | Y | Z |
84| security | X | Y | Z |
85| **Total** | **X** | **Y** | **Z** |
86
87### Critical Action Items (FAILs only)
881. [agent] file:line — description
892. ...
90```
91
92## Notes
93- All agents run in **parallel** — audit completes much faster than sequential
94- Each agent has its own context window — no pollution of main conversation
95- Overlapping checks (e.g., SQL injection in both backend and security) are deduplicated
96- For targeted re-audit after fixes, specify a narrower scope