Setup and workflow
Use read-only repository access or a code snapshot at a known commit. Tests require an execution environment; a GitHub link is not execution evidence.
- Fix the commit and excluded directories, then read conventions and tests.
- Review evidence for all 20 checks and choose one reproducible finding for subsequent repair.
Input and output example
Illustrative example · not an execution result
Input
Demo: Only an order route is supplied. It calls a payment API without an idempotency key. Do not edit.
Output
Check 14: do not add retries immediately; first inspect payment idempotency to avoid duplicate charges. Checks needing whole-repository evidence remain uninspected. Return recommendations, not a claim that all 20 checks passed.
Limits and failure cases
- Static review does not replace penetration testing or prove the absence of vulnerabilities.
- Inaccessible directories and unexecuted tests remain uninspected.
What was verified
- Source check · Verified · 2026-09-05
- Compared with bots/codebase-hardening-auditor.md in BotDirectory commit 84dc42af7661. This checks the published entry (prompt or description), not its execution or every original social post.
- Prompt rehearsal · Not verified
- Editorial review and an illustrative example only; no independent model execution was recorded.
- Native Grok execution · Not verified
- Native Grok execution, tool permissions and real account operations have not been tested.
- Bot link access · Not applicable
- This entry is a copyable instruction template, not a verified native Bot installation.
Source and editorial adaptation
Adapted from Codebase Hardening Auditor in botdirectory.ai (listed contributor: nate-stellar), distributed under MIT. Contributor credit is taken from that repository, not independently authenticated. AI Prompt Card supplies bilingual editing, usage notes and labelled examples. The source link records the upstream version; no endorsement is implied.
Source license and attributionCopyable instruction template
Instructions curated or adapted by this site, not a claim to reproduce the native Bot’s internal system prompt. Check setup, tools and limitations before use.
0 opens · 0 copies
Editorial assessment
Useful when a prototype enters sustained maintenance. This edition aligns the previously inconsistent bilingual checklists. Function length, route-level queries and retries are contextual signals, not automatic defects; blindly retrying non-idempotent calls can be worse than no retry. The audit is read-only until a fix is approved.
This directory is an independent, fan-made catalog. It is not affiliated with, endorsed by, or sponsored by xAI or Grok. Grok and related names are trademarks of their respective owners. Live-bot links point to official x.ai pages.


