AgentKit
ReferenceCLI commands

CLI commands

ak audit

Check installed kits for drift

ak audit

Check installed kits for drift

Synopsis

What it does: Read-only integrity check. Compares each installed AgentKit kit's plugin tree against the install-time fingerprint recorded at install (per-file sha256) and reports every divergence: modified (content changed), removed (file deleted), and added (untracked file). With no argument it audits every installed kit; pass a kit name to audit just that one. Exits 0 when the install matches its manifest and exits 1 when any drift is found. Pass --strict to also fail when the install manifest or plugin manifest is missing/unreadable. Use ak audit scripts for the advisory hook/skill script risk scanner.

Who it's for: Both: power devs (--json for CI integrity gates) and non-technical users (interactive summary with a repair hint).

When to use it: After an upgrade, after manual edits under ~/.claude/plugins/, or when something behaves unexpectedly and you suspect the install drifted.

Examples: ak audit # audit every installed kit ak audit engineer # audit one kit ak audit engineer --strict # fail if the manifest anchor is missing ak audit engineer --plugin-mode --project-dir . # audit a project plugin ak audit --json # machine-readable, schema_version-wrapped ak audit scripts ./kits/core # scan hook and skill scripts

What changes on disk: Read-only. Never writes; suggests ak kit refresh engineer --remote --yes for paid kit drift and ak kit refresh core --yes for public kit drift.

Output modes: pretty default on TTY (colors, ASCII markers) plain auto when stdout piped or --no-interactive json --json (single-object envelope, NDJSON-safe)

Exit codes: 0 success 1 runtime error 2 invalid flags 3 user-cancel (SIGINT, prompt-cancel) 0 every audited kit matches its recorded manifest (no drift) 1 drift detected, or the command itself failed (I/O error) 2 invalid kit name argument

ak audit [kit] [flags]

Options

  -h, --help                 help for audit
      --json                 Emit machine-readable JSON (implies --no-interactive)
      --no-interactive       Disable interactive prompts (CI-safe)
      --plugin-mode          Audit a Claude Code project plugin instead of a native project install
      --project-dir string   Audit a native project install; combine with --plugin-mode for a project plugin
  -q, --quiet                Suppress non-error output on stderr
      --strict               Exit non-zero when an installed AgentKit plugin lacks a readable install manifest
  -V, --verbose              Extra diagnostic output on stderr (loses to --quiet)
  -y, --yes                  Assume yes for all prompts

SEE ALSO

On this page