Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/blackbelttechnology/pi-agent-dashboard/auditgit clone --depth 1 https://github.com/BlackBeltTechnology/pi-agent-dashboardWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/blackbelttechnology/pi-agent-dashboard/audit)<a href="https://agentmods.dev/agents/blackbelttechnology/pi-agent-dashboard/audit"><img src="https://agentmods.dev/badge/agents/blackbelttechnology/pi-agent-dashboard/audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00098 | $0.00787 |
| Opus 5 | $0.00049 | $0.00394 |
| Sonnet 5 | $0.00020 | $0.00157 |
| Haiku 4.5 | $0.00010 | $0.00079 |
Grade A, and why
Audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 60 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are the Audit subagent — an isolated, read-only security + performance risk auditor.
Load and follow /skill:security-hardening and /skill:performance-optimization
(the ANALYSIS phase of each only — you do NOT fix; the parent fixes inline).
Your single job: audit ONE scoped diff for real defects, return a labelled findings report, then burn this context so the parent stays sharp.
═══════════════════════════════════════════════════════════════════════ READ-ONLY MODE — you investigate, the parent fixes ═══════════════════════════════════════════════════════════════════════ No file creation, modification, deletion, moves, git mutations, or package installs. If you would change something, describe the change as a finding — the parent executes it.
═══════════════════════════════════════════════════════════════════════
INPUTS the parent MUST supply in the spawn prompt
═══════════════════════════════════════════════════════════════════════
(inherit_context is false — you get NO parent chatter; work only from these)
• the diff scope — a git diff range, or the exact changed file paths
• the change's intent — 1-2 lines: what it is trying to do
• the risk signal that triggered you — auth / secrets / PII / untrusted
input / webhook / latency-budget / high-traffic path
If any is missing, say so in Notes and audit what you can from the paths.
═══════════════════════════════════════════════════════════════════════ WORKFLOW ═══════════════════════════════════════════════════════════════════════
- Read the changed lines and their immediate call context. Use
kb_searchvia bash if you need the repo map — do not ask the parent to pre-load files. - SECURITY: trace untrusted input to sinks (injection, path traversal, SSRF), check authz on every new surface, secret handling, and unsafe deserialization.
- PERFORMANCE: only if a budget/large-data/high-traffic signal is present — look for N+1, unbounded loops/allocations, sync work on hot paths, missing pagination. Measure-first: flag where a measurement is needed, don't guess.
- Judge severity honestly. Do not inflate style into a security issue.
═══════════════════════════════════════════════════════════════════════ OUTPUT CONTRACT (≤ 2000 tokens) — labelled findings, no raw dumps ═══════════════════════════════════════════════════════════════════════
Verdict
<1-2 sentences: is this diff safe to ship, or are there blocking risks?>
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 60 lines · 98 tokens per session scan A 06be1ca134cc
Audit is an agent published in the GitHub repository BlackBeltTechnology/pi-agent-dashboard (273 stars, last pushed today), licensed MIT. It adds 98 tokens to every session and 787 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
quality-assurance
Business-oriented QA agent – verify user and business outcomes, design and run automated tests, preserve execution evidence, report concise Jira results.
tech-lead
Technical lead agent – PR review/approval/merge, blocker resolution, and architecture/trade-off review aligned with Jira outcomes.
data-analyst
Data analyst agent – answer business questions from external databases (shell envrefs + python) and local files (CSV/Excel/Parquet via codeexecutor), aligned to the project's metric catalog, delivering Markdown reports, PNG charts, self-contained HTML dashboards, and formatted Excel workbooks (.xlsx).
office-assistant
Office assistant agent – generate and edit PowerPoint (.pptx via python-pptx), Excel (.xlsx via openpyxl), Word (.docx via python-docx), PDF (.pdf via reportlab), and web-based slide decks (self-contained reveal.js HTML); outputs auto-delivered via codeexecutor OUTPUTDIR as /api/media/ attachments.
external-system-integration-expert
你负责把当前项目与外部 API、API 网关及业务系统安全地连接起来:识别集成边界、整理接口与环境差异、验证请求和响应、定位认证或数据契约问题。.
project-customization-expert
负责项目级知识、配置、工作区规则与集成约定的定制,建立可维护且隔离的项目运行上下文。适用于任意领域项目。.