Audit template
repo
A whole-repo engineering review, scored against Google Eng, SRE, and SLSA.
Maps to: Google Eng · SRE · SLSA
How this audit works
A Principal-Engineer review that fans out ten specialist agents across architecture, tech-stack consistency, docs, code quality, testing, security, dependencies, CI/CD, observability, and git/release hygiene. Its lens is internal coherence: declared standards versus actual practice, with doc-code drift, .env-vs-code, and lint-config-vs-reality actively tested rather than assumed. Every finding cites file:line, is benchmarked against named reference repos, and must survive independent skeptics before it reaches the report.
Use it when
Inheriting an unfamiliar codebase
You just took over a repo and the README is the only map you have. The audit walks clone-to-running and flags the exact step where setup breaks, plus documented commands and env vars that no longer match what the code reads.
After two teams merged a codebase
A merger or reorg left one repo carrying two of everything. The tech-stack dimension lists competing libraries (two HTTP clients, two date libs), version drift across workspaces, and mixed paradigms with usage counts and a consolidation path.
Due diligence before a handoff
You are acquiring a repo or signing off ownership and need an honest baseline, not a vibe. You get a board-ready scorecard across all ten dimensions, an overall engineering grade, and the single biggest consistency risk named up front.
What you get
A graded ten-dimension scorecard plus verified findings filed as priority-sorted GitHub issues, each with file:line evidence and a before/after fix.
