Source Command Audit WhitepapersCAUTION
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Overview
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
d90170da4369OBSERVED · 2026-10-07Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| codex | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: "source-command-audit-whitepapers"
description: "Audit version freshness, FR/EN parity, and metadata quality of all whitepapers and recap cards"
---
# source-command-audit-whitepapers
Use this skill when the user asks to run the migrated source command `audit-whitepapers`.
## Command Template
# Audit Whitepapers & Recap Cards
Comprehensive freshness and quality audit for all whitepapers (FR + EN) and recap cards (FR + EN). Scores each document against the current guide version, checks FR/EN parity, and validates metadata consistency.
## Arguments
- `--fix` - Generate update suggestions and frontmatter patches (does not modify files)
- `--verbose` - Show all criteria including passing ones, not just failures
- `--cards-only` - Audit only recap cards (skip main whitepapers)
- `--wp-only` - Audit only main whitepapers (skip recap cards)
## Usage
```bash
/audit-whitepapers # Full audit, failures only
/audit-whitepapers --fix # Audit + prioritized update suggestions
/audit-whitepapers --verbose # Full details for all criteria
/audit-whitepapers --cards-only # Recap cards only
/audit-whitepapers --wp-only # Whitepapers only
```
---
## Phase 1: Discovery
**Objective**: Locate and inventory all auditable documents.
### Steps
1. **Read current guide version**: Read the `VERSION` file at the project root. This is the target version all documents should be synced against.
2. **Scan directories** for `.qmd` files:
```
whitepapers/fr/ (main whitepapers FR)
whitepapers/en/ (main whitepapers EN)
whitepapers/recap-cards/fr/ (recap cards FR)
whitepapers/recap-cards/en/ (recap cards EN)
```
3. **Classify each file**:
- **Main whitepaper**: files matching `[0-9][0-9]-*.qmd` in `whitepapers/fr/` or `whitepapers/en/`
- **Cheatsheet**: files matching `*cheatsheet*.qmd` (tracked separately, not scored)
- **Custom whitepaper**: files matching `*-whitepaper.qmd` or `*-cheatsheet.qmd` from external partners (strangebee, purchasely, devwithai) -- excluded from scoring, listed separately
- **Recap card**: all `.qmd` files in `recap-cards/fr/` or `recap-cards/en/`
- **Bundle/include**: `fiches-recap-serie.qmd`, files in `fiches/` subdirectory -- excluded (they are composed documents)
4. **Parse YAML frontmatter** for each included file (read between first `---` and second `---`). Extract:
- `title`, `subtitle`, `author`, `date`
- `version` (guide version tracked in main WPs and recap cards)
- `wp-version` (whitepaper own semver, main WPs only)
- `guide-version` (explicit guide version field used in recap cards)
- `card-number`, `category`, `difficulty` (recap cards only)
- `series` (main WPs only)
5. **Display discovery summary**:
```
Guide version: {VERSION}
Found: {N} main whitepapers ({FR}/{EN} FR/EN), {N} recap cards ({FR}/{EN} FR/EN)
Excluded: {N} custom files (strangebee, purchasely, devwithai), {N} bundle files
```
---
## Phase 2: Version Gap Analysis (40 points per file)
**Objective**: Score how current each document is relative to the guide.
### Semver comparison logic
Parse version strings as `MAJOR.MINOR.PATCH`. The staleness metric is `minor_gap = current_minor - file_minor` (using the same MAJOR). If MAJOR differs, treat as critical.
For **main whitepapers**, the guide version field is `version`.
For **recap cards**, the guide version field is `guide-version` (fall back to `version` if absent).
### Scoring table
| Criterion | Points | Detection |
|-----------|--------|-----------|
| Guide version current (0-1 minor behind) | 15 | `minor_gap` <= 1 |
| Guide version recent (2-3 minor behind) | 10 | `minor_gap` 2-3 (partial credit, replaces the 15) |
| Guide version old (4-10 minor behind) | 5 | `minor_gap` 4-10 (partial credit) |
| wp-version field present and valid semver | 5 | Field exists AND matches `\d+\.\d+\.\d+` (WP only) |
| wp-version consistent with FR/EN pair | 10 | Same `wp-version` value in the counterpart file (WP only) |
| guide-version consistent with FR/EN pair | 10 | Same `guide-version` (or `version`) in the counterpart (cards) |
**Freshness labels**:
- 0-1 minor behind: Fresh
- 2-3 minor behind: Stale
- 4-10 minor behind: Very Stale
- 11+ minor behind: Critical
Note: The 15, 10, 5 pts for guide version are mutually exclusive (award only the highest applicable tier).
---
## Phase 3: Content Staleness Check (20 points per file)
**Objective**: Detect whether the guide sections a whitepaper covers have changed since it was last updated.
### Whitepaper-to-guide mapping (embedded)
| WP# | FR filename prefix | EN filename prefix | Guide sections |
|-----|--------------------|--------------------|----------------|
| 00 | `00-introduction` | `00-series-introduction` | `guide/ultimate-guide.md` Ch.1-2 |
| 01 | `01-prompts` | `01-effective-prompts` | Ch.2 prompting sections |
| 02 | `02-personnalisation` | `02-customization` | Ch.3 Memory, Ch.4 Agents, Ch.5 Skills |
| 03 | `03-securite` | `03-security` | Ch.7 Hooks, security sections |
| 04 | `04-architecture` | `04-architecture` | Ch.2 internals, architecture sections |
| 05 | `05-equipe` | `05-team` | Ch.3 team config, Ch.9 CI/CD |
| 06 | `06-privacy` | `06-privacy` | Ch.2 data/privacy sections |
| 07 | `07-guide-reference` | `07-reference-guide` | Ch.10 Reference |
| 08 | `08-agent-teams` | `08-agent-teams` | Ch.9 agent teams |
| 09 | `09-apprendre` | `09-learning` | `guide/roles/learning-with-ai.md` |
| 10 | `10-budget` | `10-ai-budget` | Business/ROI content |
### Steps
1. For each main whitepaper, extract the `date` field. If the date is not in `YYYY-MM-DD` format, parse it (e.g., "2026-02-12" or "March 2026").
2. Run `git log --since="{date}" --oneline -- guide/ultimate-guide.md guide/roles/ guide/core/` to count commits that touched guide content since the whitepaper's date.
3. Score:
| Criterion | Points | Detection |
|-----------|--------|-----------|
| No guiTrust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
whitepapers/recap-cards/en/_extensions
whitepapers/recap-cards/fr/_extensions
Gates applied: no_behavioural_pass.
d90170da4369full audit observations/trust-audit/skill/florianbruniaux__source-command-audit-whitepapers.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d90170da4369 | CAUTION | B | 89 | first audit |
Questions
What does the Source Command Audit Whitepapers skill do?
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Is Source Command Audit Whitepapers safe to install?
With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Source Command Audit Whitepapers access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Source Command Audit Whitepapers work with?
Its documentation mentions codex. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (d90170da4369), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.