Maybe I am missing something, but the audit seems to look for xp_dirtree and xp_fileexists but not for xp_cmdshell.
It is a critical part of the audit, if command execeution is directly possible for an user or it is allowed to enable the xp_cmdshell.
Also some other known procedures like "sp_execute_external_script" would be nice to get audited, to not miss them.
Is this possible to add?