# What to use for audit

> 'Audit' — a formal check against a standard, with findings.

Source: https://tashan.sh/task/audit.html
Ranked by fit for the task, then how well it documents itself, then the tashan score
  (upkeep and freshness, gated by real adoption). Public evidence only — nothing paid can
  change a rank. Method: https://tashan.sh/methodology.html

## Ranked

| # | Capability | tashan score | Adoption evidence | Activity |
|---|---|---|---|---|
| 1 | [Sofagent](https://tashan.sh/capability/pkg-sofagent-mcp.html) | 65 | 683/wk | active |
| 2 | [Nsauditor AI](https://tashan.sh/capability/pkg-nsauditor-ai.html) | 66 | 536/wk | active |
| 3 | [GIA — Governed Intelligence Architecture](https://tashan.sh/capability/pkg-gia-mcp-server.html) | 50 | 95/wk | active |
| 4 | [GitHub Security](https://tashan.sh/capability/pkg-github-security-mcp.html) | 35 | 886/wk | abandoned |
| 5 | [Bastion](https://tashan.sh/capability/pkg-mcp-bastion.html) | 55 | 328/wk | active |
| 6 | [Audit · charlacsina](https://tashan.sh/capability/pkg-openaeo-audit.html) | 54 | 414/wk | active |
| 7 | [Nexus Agents](https://tashan.sh/capability/pkg-nexus-agents.html) | 53 | 194/wk | active |
| 8 | [Trustcard](https://tashan.sh/capability/pkg-mcp-trustcard.html) | 51 | 177/wk | active |
| 9 | [Cyberaudit Skill](https://tashan.sh/capability/pkg-cyberaudit-skill.html) | 46 | 37/wk | active |
| 10 | [Vorim](https://tashan.sh/capability/pkg-vorim-mcp-server.html) | 45 | 87/wk | active |
| 11 | [Roast My Design System](https://tashan.sh/capability/pkg-roast-my-design-system.html) | 71 | 2k/wk | active |
| 12 | [Kya OS](https://tashan.sh/capability/pkg-kya-os-mcp.html) | 70 | 1k/wk | active |
| 13 | [Claude Ads](https://tashan.sh/capability/plugin-agricidaniel-claude-ads-claude-ads.html) | 69 | 8k ★ | active |
| 14 | [Audit](https://tashan.sh/capability/pkg-sofagent-audit.html) | 67 | 827/wk | active |
| 15 | [Crosscheck](https://tashan.sh/capability/pkg-crosscheck-mcp.html) | 67 | 604/wk | active |
| 16 | [Lighthouse](https://tashan.sh/capability/pkg-danielsogl-lighthouse-mcp.html) | 65 | 1k/wk | active |
| 17 | [Claude Code](https://tashan.sh/capability/pkg-ory-claude-code.html) | 65 | 83/wk | active |
| 18 | [Npmjs](https://tashan.sh/capability/pkg-yawlabs-npmjs-mcp.html) | 62 | 383/wk | active |
| 19 | [Mcpscore](https://tashan.sh/capability/pkg-mcp-box-mcpscore.html) | 60 | 348/wk | active |
| 20 | [Uxlint](https://tashan.sh/capability/pkg-uxlint-net-uxlint.html) | 57 | 512/wk | active |
| 21 | [Seegeo](https://tashan.sh/capability/pkg-seegeo-mcp.html) | 57 | 274/wk | active |
| 22 | [Weakspot](https://tashan.sh/capability/pkg-weakspot-mcp.html) | 56 | 337/wk | active |
| 23 | [Midplane](https://tashan.sh/capability/pkg-midplane.html) | 55 | 387/wk | active |
| 24 | [Agent Lifecycle Kit](https://tashan.sh/capability/plugin-avksp-agent-lifecycle-kit-agent-lifecycle-kit.html) | 53 | 18 ★ | active |
| 25 | [Antigravity](https://tashan.sh/capability/pkg-ory-antigravity.html) | 53 | 11/wk | active |
| 26 | [three.ws Provenance](https://tashan.sh/capability/pkg-three-ws-provenance-mcp.html) | 52 | 204/wk | active |
| 27 | [Smartflow Verify](https://tashan.sh/capability/pkg-smartflow-verify-mcp.html) | 51 | 210/wk | active |
| 28 | [Wcag Checkr](https://tashan.sh/capability/pkg-wcag-checkr-mcp.html) | 51 | 145/wk | active |
| 29 | [Positif](https://tashan.sh/capability/pkg-positif-ai.html) | 50 | 191/wk | active |
| 30 | [Fullstackgtm](https://tashan.sh/capability/pkg-fullstackgtm.html) | 50 | 99/wk | active |
| 31 | [SEO Audit Tool](https://tashan.sh/capability/pkg-seo-audit-tool.html) | 49 | 131/wk | active |
| 32 | [Auditor](https://tashan.sh/capability/pkg-sitelint-auditor-mcp.html) | 48 | 48/wk | active |
| 33 | [Make Audit](https://tashan.sh/capability/pkg-make-audit-mcp.html) | 46 | 71/wk | active |
| 34 | [Risk](https://tashan.sh/capability/pkg-mcp-risk.html) | 45 | 40/wk | active |
| 35 | [Xlsx Audit](https://tashan.sh/capability/pkg-xlsx-audit-mcp.html) | 44 | 45/wk | active |
| 36 | [Hook Conformance](https://tashan.sh/capability/pkg-mcp-hook-conformance.html) | 43 | 84/wk | active |
| 37 | [Kronos Forgemesh](https://tashan.sh/capability/pkg-forgemeshlabs-kronos-forgemesh-mcp.html) | 41 | 29/wk | active |
| 38 | [Teralynk](https://tashan.sh/capability/pkg-teralynk-mcp-server.html) | 41 | 22/wk | active |
| 39 | [Stdio Shellguard](https://tashan.sh/capability/pkg-mcp-stdio-shellguard.html) | 40 | 62/wk | active |
| 40 | [Site Doctor](https://tashan.sh/capability/pkg-site-doctor.html) | 40 | 27/wk | active |

Showing the top 40 of 45. The full ranked shelf is at https://tashan.sh/task/audit.html.

## What these numbers are not

- The tashan score measures upkeep, freshness and adoption. It is **not** a security
  verdict and **not** a measure of whether the capability works well.
- `not scored` means too little public evidence to rank, never that something is bad.
- The security audit is separate and free per capability, on each page above.
