Yes it’s an audit checklist for when you need to know specifically what to use and with which parameters.
It’s unfortunate if there are mistakes in there. The people at OWASP would be very happy to receive feedback on their GitHub I’m sure.
It's a bad audit checklist! If OWASP volunteers can't do a good one, they should just not do one at all. It's fine for them not to cover things that are outside their expertise.
This is a mess, and I would actively steer people away from it.