Production Readiness Audit
When to use
- Preparing a service for production deployment
- Conducting periodic security or quality review of a codebase
- Onboarding to assess codebase health and maturity
- Evaluating technical debt before a major release
- Validating compliance with Ring engineering standards
Skip when
- Project is a prototype or throwaway proof-of-concept not heading to production
- Codebase is a library or SDK with no deployable service component
- User only needs a single-dimension check (use targeted review instead)
Audit categories
- Structure (11): pagination, errors, routes, bootstrap, runtime, core deps, naming, domain modeling, nil-safety, api-versioning, resource-leaks
- Security (9): auth, IDOR, SQL, validation, secret-scanning, data-encryption, multi-tenant, rate-limiting, cors
- Operations (7): telemetry, health, config, connections, logging, resilience, graceful-degradation
- Quality (10): idempotency, docs, debt, testing, dependencies, performance, concurrency, migrations, linting, caching
- Infrastructure (6): containers, hardening, cicd, async, makefile, license
A multi-agent audit system evaluating 43 base dimensions + 1 conditional (multi-tenant) = up to 44 dimensions across 5 categories, aligned with Ring development standards. Detects project stack, loads relevant standards via WebFetch, runs explorers in batches of 10, appending results incrementally to a single report file.
Announce at start: "Using ring:production-readiness-audit to audit {N} dimensions in 5 batches."
Audit Dimensions
| Category |
Count |
Dimensions |
| A: Code Structure |
11 |
Pagination, Errors, Routes, Bootstrap, Runtime, Core Deps, Naming, Domain Modeling, Nil Safety, API Versioning, Resource Leaks |
| B: Security |
9 (+1c) |
Auth, IDOR, SQL, Input Validation, Secret Scanning, Data Encryption, Rate Limiting, CORS, Multi-Tenant* |
| C: Operations |
7 |
Telemetry, Health, Config, Connections, Logging, Resilience, Graceful Degradation |
| D: Quality |
10 |
Idempotency, API Docs, Tech Debt, Testing, Dependencies, Performance, Concurrency, Migrations, Linting, Caching |
| E: Infrastructure |
6 |
Containers, HTTP Hardening, CI/CD, Async, Makefile, License |
*Conditional on MULTI_TENANT detection. Max score: 430 base + 10 conditional = 440.
Execution Protocol
Step 0: Stack Detection
Glob("**/go.mod") → GO=true
Glob("**/package.json") → parse for React/Next (FRONTEND) or Express/Fastify (TS_BACKEND)
Glob("**/Dockerfile*") → DOCKER=true
Glob("**/Makefile") → MAKEFILE=true
Glob("**/LICENSE*") → LICENSE=true
Grep("MULTI_TENANT") → if found in env/config files: MULTI_TENANT=true
Step 0.5: Load Ring Standards
WebFetch based on detected stack. On failure, note and proceed with generic patterns.
Go stack: core.md, bootstrap.md, security.md, domain.md, api-patterns.md, quality.md, architecture.md, messaging.md, domain-modeling.md, idempotency.md from https://raw.githubusercontent.com/LerianStudio/ring/main/dev-team/docs/standards/golang/
If MULTI_TENANT: Also fetch multi-tenant.md from same base URL.
Always: devops.md and sre.md from https://raw.githubusercontent.com/LerianStudio/ring/main/dev-team/docs/standards/
Store fetched content for injection between ---BEGIN STANDARDS--- / ---END STANDARDS--- markers in each explorer prompt.
Step 1: Initialize Report File
Write header to docs/audits/production-readiness-{YYYY-MM-DDTHH:MM:SS}.md with detected stack, standards loaded, dimension count, and dynamic max score.
Step 2–6: Batch Execution
Read the dimension-specific prompts from dimensions/ subdirectory before dispatching each batch.
| Batch |
Read File |
Agents |
Category Focus |
| 1 |
dimensions/structure.md (agents 1-5) + dimensions/security.md (agents 6-9) + dimensions/operations.md (agent 10) |
10 |
Structure + Security start + Telemetry |
| 2 |
dimensions/operations.md (agents 12-15) + dimensions/quality.md (agents 16-20) |
9 |
Operations + Quality start |
| 3 |
dimensions/quality.md (agents 21-23) + dimensions/infrastructure.md (agents 24-27) + dimensions/structure.md (agents 28-30) |
10 |
Quality + Infrastructure + Structure cont. |
| 4 |
dimensions/quality.md (agents 31, 40) + dimensions/infrastructure.md (agents 32, 34) + dimensions/security.md (agents 33*, 37, 41) + dimensions/structure.md (agents 35, 38, 42) + dimensions/operations.md (agents 36, 39) |
varies |
Mixed (remaining dimensions) |
| 5 |
dimensions/security.md (agents 43-44) |
2 |
Rate Limiting + CORS |
*Agent 33 (Multi-Tenant) only if MULTI_TENANT=true.
After each batch: Append all results to report file before launching next batch.
CRITICAL: Each batch dispatches in a SINGLE turn with N parallel Task calls.
⛔ STOP-CHECK BEFORE DISPATCH (each batch)
Before emitting any Task call in a batch, count the explorers you intend to launch in this turn.
- Count MUST equal the batch size declared in the batch table above for the current batch.
- If your dispatch count diverges from the batch size → STOP and reconcile against the batch row.
- No substitutions, no omissions within a batch.
⛔ MUST NOT trickle-dispatch within a batch
All explorers in a batch leave in the SAME TURN, before reading any explorer output.
Forbidden sequences:
- Dispatch explorer 1 → read result → dispatch explorer 2
- Dispatch a subset of the batch → wait → dispatch the rest
- Dispatch follow-up explorers conditioned on partial output
- Loop sequentially over the batch's explorer list
If you find yourself about to dispatch an explorer in a turn AFTER any explorer in the SAME batch has already returned a result → STOP. You violated parallel dispatch. Report the violation and mark the batch INCOMPLETE rather than completing the trickle. (Sequential batch ordering is intentional; trickle within a batch is not.)
Self-verify after dispatch
After each batch's dispatch turn, verify all batched Task calls were emitted in that single turn. If fewer went out than the batch size, the batch did NOT execute correctly. Mark INCOMPLETE and surface the dispatch failure — do NOT silently continue with a partial batch.
Parallel dispatch — atomic batch (within this batch)
Emit all Task calls for THIS BATCH in a SINGLE TURN, as one atomic batch. (Batches themselves remain sequential — do not dispatch batch N+1 until batch N has fully returned.)
If your runtime exposes a multi_tool_use.parallel wrapper, use it to dispatch the complete batch in one wrapped invocation. This is the canonical fan-out mechanism on OpenAI-style tool envelopes and on certain Anthropic SDK consumers — naming it explicitly activates parallel emission on runtimes where trickle-dispatch is the default behavior.
If your runtime emits parallel tool_use blocks natively (Claude Code with Claude models), multi_tool_use.parallel may not be needed — but naming it is harmless and serves as an enforcement anchor.
The STOP-CHECK, anti-trickle, and self-verify guards above remain binding regardless of which mechanism your runtime uses.
Step 7: Consolidate Report
- Read
dimensions/scoring.md for scoring rules
- Calculate scores per dimension (0-10), category totals, overall score
- Determine readiness classification (percentage-based)
- Generate Standards Compliance Cross-Reference table
- Update report with Executive Summary prepended
Step 8: Visual Dashboard (MANDATORY)
Invoke Skill("ring:visualize") to produce an HTML dashboard at docs/audits/production-readiness-{timestamp}-dashboard.html.
Dashboard sections:
- Score Hero (score/max, readiness badge, color-coded)
- Category Scoreboard (5 cards with progress bars)
- Dimension Heatmap (44 dims, color by score range)
- HARD GATE Violations (if any)
- Critical Blockers (if any)
- Remediation Roadmap (4 phases)
- Standards Compliance Summary
Open in browser after generation.
Step 9: Present Summary
Summarize: stack detected, standards loaded, overall score/classification, critical/high counts, HARD GATE violations, top 3 recommendations, links to report and dashboard.
Customization Options
| Flag |
Effect |
--modules=matching,ingestion |
Only audit specified modules |
--dimensions=security |
Run only security-related auditors |
--format=json |
Structured JSON output |
--no-standards |
Skip Ring standards loading (generic mode) |
Blocker Conditions
| Condition |
Action |
| Stack undetectable |
STOP — ask user to specify stack |
| Standards WebFetch fails for critical modules |
STOP — audit requires standards |
| Entire batch fails |
STOP — report infrastructure issue |
| docs/audits/ not writable |
STOP — ensure directory exists |
1---2name: ring-production-readiness-audit3description: Ring-standards-aligned production readiness audit across Structure, Security, Operations, Quality, and Infrastructure — 43 base dimensions + 1 conditional (multi-tenant) = up to 44 dimensions. Use before production deployment, periodic reviews, onboarding, or major releases. Skip for prototypes, libraries, or single-dimension checks. Runs explorers in batches of 10 and produces a scored report (0-430 base, max 440 with multi-tenant) with severity ratings.4---5
6# Production Readiness Audit
7
8## When to use
9- Preparing a service for production deployment
10- Conducting periodic security or quality review of a codebase
11- Onboarding to assess codebase health and maturity
12- Evaluating technical debt before a major release
13- Validating compliance with Ring engineering standards
14
15## Skip when
16- Project is a prototype or throwaway proof-of-concept not heading to production
17- Codebase is a library or SDK with no deployable service component
18- User only needs a single-dimension check (use targeted review instead)
19
20## Audit categories
21- **Structure** (11): pagination, errors, routes, bootstrap, runtime, core deps, naming, domain modeling, nil-safety, api-versioning, resource-leaks
22- **Security** (9): auth, IDOR, SQL, validation, secret-scanning, data-encryption, multi-tenant, rate-limiting, cors
23- **Operations** (7): telemetry, health, config, connections, logging, resilience, graceful-degradation
24- **Quality** (10): idempotency, docs, debt, testing, dependencies, performance, concurrency, migrations, linting, caching
25- **Infrastructure** (6): containers, hardening, cicd, async, makefile, license
26
27A multi-agent audit system evaluating **43 base dimensions + 1 conditional (multi-tenant) = up to 44 dimensions** across 5 categories, aligned with Ring development standards. Detects project stack, loads relevant standards via WebFetch, runs explorers in **batches of 10**, appending results incrementally to a single report file.
28
29**Announce at start:** "Using ring:production-readiness-audit to audit {N} dimensions in 5 batches."
30
31## Audit Dimensions
32
33| Category | Count | Dimensions |
34|----------|-------|------------|
35| A: Code Structure | 11 | Pagination, Errors, Routes, Bootstrap, Runtime, Core Deps, Naming, Domain Modeling, Nil Safety, API Versioning, Resource Leaks |
36| B: Security | 9 (+1c) | Auth, IDOR, SQL, Input Validation, Secret Scanning, Data Encryption, Rate Limiting, CORS, Multi-Tenant* |
37| C: Operations | 7 | Telemetry, Health, Config, Connections, Logging, Resilience, Graceful Degradation |
38| D: Quality | 10 | Idempotency, API Docs, Tech Debt, Testing, Dependencies, Performance, Concurrency, Migrations, Linting, Caching |
39| E: Infrastructure | 6 | Containers, HTTP Hardening, CI/CD, Async, Makefile, License |
40
41*Conditional on MULTI_TENANT detection. Max score: 430 base + 10 conditional = 440.
42
43## Execution Protocol
44
45### Step 0: Stack Detection
46
47```
48Glob("**/go.mod") → GO=true
49Glob("**/package.json") → parse for React/Next (FRONTEND) or Express/Fastify (TS_BACKEND)
50Glob("**/Dockerfile*") → DOCKER=true
51Glob("**/Makefile") → MAKEFILE=true
52Glob("**/LICENSE*") → LICENSE=true
53Grep("MULTI_TENANT") → if found in env/config files: MULTI_TENANT=true
54```
55
56### Step 0.5: Load Ring Standards
57
58WebFetch based on detected stack. On failure, note and proceed with generic patterns.
59
60**Go stack:** core.md, bootstrap.md, security.md, domain.md, api-patterns.md, quality.md, architecture.md, messaging.md, domain-modeling.md, idempotency.md from `https://raw.githubusercontent.com/LerianStudio/ring/main/dev-team/docs/standards/golang/`
61
62**If MULTI_TENANT:** Also fetch multi-tenant.md from same base URL.
63
64**Always:** devops.md and sre.md from `https://raw.githubusercontent.com/LerianStudio/ring/main/dev-team/docs/standards/`
65
66Store fetched content for injection between `---BEGIN STANDARDS---` / `---END STANDARDS---` markers in each explorer prompt.
67
68### Step 1: Initialize Report File
69
70Write header to `docs/audits/production-readiness-{YYYY-MM-DDTHH:MM:SS}.md` with detected stack, standards loaded, dimension count, and dynamic max score.
71
72### Step 2–6: Batch Execution
73
74Read the dimension-specific prompts from `dimensions/` subdirectory before dispatching each batch.
75
76| Batch | Read File | Agents | Category Focus |
77|-------|-----------|--------|----------------|
78| 1 | `dimensions/structure.md` (agents 1-5) + `dimensions/security.md` (agents 6-9) + `dimensions/operations.md` (agent 10) | 10 | Structure + Security start + Telemetry |
79| 2 | `dimensions/operations.md` (agents 12-15) + `dimensions/quality.md` (agents 16-20) | 9 | Operations + Quality start |
80| 3 | `dimensions/quality.md` (agents 21-23) + `dimensions/infrastructure.md` (agents 24-27) + `dimensions/structure.md` (agents 28-30) | 10 | Quality + Infrastructure + Structure cont. |
81| 4 | `dimensions/quality.md` (agents 31, 40) + `dimensions/infrastructure.md` (agents 32, 34) + `dimensions/security.md` (agents 33*, 37, 41) + `dimensions/structure.md` (agents 35, 38, 42) + `dimensions/operations.md` (agents 36, 39) | varies | Mixed (remaining dimensions) |
82| 5 | `dimensions/security.md` (agents 43-44) | 2 | Rate Limiting + CORS |
83
84*Agent 33 (Multi-Tenant) only if MULTI_TENANT=true.
85
86**After each batch:** Append all results to report file before launching next batch.
87
88**CRITICAL:** Each batch dispatches in a SINGLE turn with N parallel Task calls.
89
90### ⛔ STOP-CHECK BEFORE DISPATCH (each batch)
91
92Before emitting any Task call in a batch, count the explorers you intend to launch in this turn.
93- Count MUST equal the batch size declared in the batch table above for the current batch.
94- If your dispatch count diverges from the batch size → STOP and reconcile against the batch row.
95- No substitutions, no omissions within a batch.
96
97### ⛔ MUST NOT trickle-dispatch within a batch
98
99All explorers in a batch leave in the SAME TURN, before reading any explorer output.
100
101Forbidden sequences:
102- Dispatch explorer 1 → read result → dispatch explorer 2
103- Dispatch a subset of the batch → wait → dispatch the rest
104- Dispatch follow-up explorers conditioned on partial output
105- Loop sequentially over the batch's explorer list
106
107If you find yourself about to dispatch an explorer in a turn AFTER any explorer in the SAME batch has already returned a result → STOP. You violated parallel dispatch. Report the violation and mark the batch INCOMPLETE rather than completing the trickle. (Sequential batch ordering is intentional; trickle within a batch is not.)
108
109### Self-verify after dispatch
110
111After each batch's dispatch turn, verify all batched Task calls were emitted in that single turn. If fewer went out than the batch size, the batch did NOT execute correctly. Mark INCOMPLETE and surface the dispatch failure — do NOT silently continue with a partial batch.
112
113### Parallel dispatch — atomic batch (within this batch)
114
115Emit all Task calls for THIS BATCH in a SINGLE TURN, as one atomic batch. (Batches themselves remain sequential — do not dispatch batch N+1 until batch N has fully returned.)
116
117**If your runtime exposes a `multi_tool_use.parallel` wrapper**, use it to dispatch the complete batch in one wrapped invocation. This is the canonical fan-out mechanism on OpenAI-style tool envelopes and on certain Anthropic SDK consumers — naming it explicitly activates parallel emission on runtimes where trickle-dispatch is the default behavior.
118
119**If your runtime emits parallel tool_use blocks natively** (Claude Code with Claude models), `multi_tool_use.parallel` may not be needed — but naming it is harmless and serves as an enforcement anchor.
120
121The STOP-CHECK, anti-trickle, and self-verify guards above remain binding regardless of which mechanism your runtime uses.
122
123
124### Step 7: Consolidate Report
125
1261. Read `dimensions/scoring.md` for scoring rules
1272. Calculate scores per dimension (0-10), category totals, overall score
1283. Determine readiness classification (percentage-based)
1294. Generate Standards Compliance Cross-Reference table
1305. Update report with Executive Summary prepended
131
132### Step 8: Visual Dashboard (MANDATORY)
133
134Invoke `Skill("ring:visualize")` to produce an HTML dashboard at `docs/audits/production-readiness-{timestamp}-dashboard.html`.
135
136Dashboard sections:
1371. Score Hero (score/max, readiness badge, color-coded)
1382. Category Scoreboard (5 cards with progress bars)
1393. Dimension Heatmap (44 dims, color by score range)
1404. HARD GATE Violations (if any)
1415. Critical Blockers (if any)
1426. Remediation Roadmap (4 phases)
1437. Standards Compliance Summary
144
145Open in browser after generation.
146
147### Step 9: Present Summary
148
149Summarize: stack detected, standards loaded, overall score/classification, critical/high counts, HARD GATE violations, top 3 recommendations, links to report and dashboard.
150
151## Customization Options
152
153| Flag | Effect |
154|------|--------|
155| `--modules=matching,ingestion` | Only audit specified modules |
156| `--dimensions=security` | Run only security-related auditors |
157| `--format=json` | Structured JSON output |
158| `--no-standards` | Skip Ring standards loading (generic mode) |
159
160## Blocker Conditions
161
162| Condition | Action |
163|-----------|--------|
164| Stack undetectable | STOP — ask user to specify stack |
165| Standards WebFetch fails for critical modules | STOP — audit requires standards |
166| Entire batch fails | STOP — report infrastructure issue |
167| docs/audits/ not writable | STOP — ensure directory exists |