I got the pointers on what's expected to be checked...
If it's really an audit, it should come with specific questions that you need to provide answers to (or at least the best evidence you can find.)
If someone is both calling this an audit, and using light terms like "pointers", you're maybe being framed for a crime that's happening, or something. Probably not that extreme, but they don't sound like an ally.
I mean I might as well read the whole repo, but maybe that's too much?
You can stop reading when you find the answers to the requested questions. On the first one you do you'll read everything more than once. On future audits you'll know where to look and it'll go much quicker.