Audit template
repo
A whole-repo engineering review, scored against Google Eng, SRESite Reliability Engineering — operating systems with engineering, using SLOs and error budgets., and SLSASupply-chain Levels for Software Artifacts — a framework for build and supply-chain integrity..
Maps to: Google Eng · SRESite Reliability Engineering — operating systems with engineering, using SLOs and error budgets. · SLSASupply-chain Levels for Software Artifacts — a framework for build and supply-chain integrity.
specialists, in parallel
Each finding is evidence-bound and survives ≥2-of-3 adversarial skeptics.
How this audit works
A Principal-Engineer review that fans out ten specialist agents across architecture, tech-stack consistency, docs, code quality, testing, security, dependencies, CI/CD, observability, and git/release hygiene. Its lens is internal coherence: declared standards versus actual practice, with doc-code driftDivergence between what the documentation says and what the code actually does., .env-vs-code, and lint-config-vs-reality actively tested rather than assumed. Every finding cites file:line, is benchmarked against named reference repos, and must survive independent skeptics before it reaches the report.
Use it when
Inheriting an unfamiliar codebase
You just took over a repo and the README is the only map you have. The audit walks clone-to-running and flags the exact step where setup breaks, plus documented commands and env vars that no longer match what the code reads.
After two teams merged a codebase
A merger or reorg left one repo carrying two of everything. The tech-stack dimension lists competing libraries (two HTTP clients, two date libs), version driftThe same dependency or runtime pinned to inconsistent versions across configs, workspaces, or environments. across workspaces, and mixed paradigms with usage counts and a consolidation path.
Due diligence before a handoff
You are acquiring a repo or signing off ownership and need an honest baseline, not a vibe. You get a board-ready scorecard across all ten dimensions, an overall engineering grade, and the single biggest consistency risk named up front.
What you get
A graded ten-dimension scorecard plus verified findings filed as priority-sorted GitHub issues, each with file:line evidence and a before/after fix.