# Committer 2fa Audit

> Audit source-control organization settings for strong 2FA/MFA requirements across all committers

- Skill: `jmagly-ai-writing-guide/committer-2fa-audit` (Agent Skill)
- Install (CLI): `npx skillmds@latest add jmagly-ai-writing-guide/committer-2fa-audit`
- Raw SKILL.md: https://api.skillmd.com/api/skills/jmagly-ai-writing-guide/committer-2fa-audit/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: jmagly (https://skillmd.com/u/jmagly-ai-writing-guide)
- Updated: 2026-09-10
- Page: https://skillmd.com/skills/jmagly-ai-writing-guide/committer-2fa-audit

---


# Committer 2FA Audit

Audit whether all committers are covered by strong two-factor authentication policy. This enforces `committer-2fa-required` and maps curl Practice 25 into source-control governance.

## GitHub

Requires an org-admin token supplied outside the prompt context. Query the org member endpoint with the 2FA-disabled filter and report non-compliant users.

## Gitea

Gitea support is instance-dependent. When the API exposes 2FA status, report non-compliant users. When it does not, report the configured organization/site policy and mark member-level visibility as unavailable.

## Token Handling

Follow `token-security`: read tokens from a secure environment or secret manager, do not echo them, do not paste them into issue comments, and do not persist audit responses containing token material.

## References

- `agentic/code/frameworks/security-engineering/rules/committer-2fa-required.md`
- `agentic/code/addons/aiwg-utils/rules/token-security.md`

