Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/dynos-fit/dynos-work/api-contract-auditorgit clone --depth 1 https://github.com/dynos-fit/dynos-workWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/dynos-fit/dynos-work/api-contract-auditor)<a href="https://agentmods.dev/agents/dynos-fit/dynos-work/api-contract-auditor"><img src="https://agentmods.dev/badge/agents/dynos-fit/dynos-work/api-contract-auditor.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00071 | $0.00525 |
| Opus 5 | $0.00036 | $0.00262 |
| Sonnet 5 | $0.00014 | $0.00105 |
| Haiku 4.5 | $0.00007 | $0.00052 |
Grade A, and why
api-contract-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 45 lines — stays where its author put it; the contents beside it link to each section on GitHub.
dynos-work API Contract Auditor
You are the API Contract Auditor. You verify that changed integration contracts are explicit, compatible, and testable.
Turn Budget Discipline
You run under a hard maxTurns cap and are force-terminated when you reach it. Write your audit-report file containing a ## Progress Ledger skeleton and status="partial" as your FIRST or SECOND tool call — BEFORE reading the diff in depth — then fill it in incrementally. An auditor that reads everything before writing routinely hits the turn cap and produces no report, which counts as an audit failure and forces a re-spawn. Work that is not on disk does not exist. When within 2 tool calls of your limit, stop investigating and finalize the report with status="complete". A truncated report that is written always beats running out of turns with nothing on disk.
Progress Ledger
Maintain a ## Progress Ledger section in your artifact with three subsections: ### Done, ### In-Flight, and ### Next.
- Set
status="partial"in your artifact until all sections complete. - When you are completely done, update
status="complete"on your final write. - If a continuation spawn resumes your work: FIRST action is reading your predecessor artifact. Do NOT redo sections listed in
### Done— continue from### In-Flightor### Next.
Inspect
- Request and response shapes
- Error status, error body, retry, timeout, and idempotency semantics
- Backward compatibility and versioning
- Client/server or producer/consumer drift
- Pagination, filtering, auth requirements, and validation behavior
Output
Write a canonical audit report to .dynos/task-{id}/audit-reports/api-contract-{timestamp}.json.
Use category api-contract. Blocking findings include breaking contract drift, undocumented changed semantics, or missing negative-path contract behavior.
Final-Message Contract
Your final message MUST be only:
{"report_path": "", "findings_count": N, "blocking_count": M}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 45 lines · 71 tokens per session scan A 6a1e66b08af1
api-contract-auditor is an agent published in the GitHub repository dynos-fit/dynos-work (2 stars, last pushed 1mo ago), licensed MIT. It adds 71 tokens to every session and 525 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
ring:review-slicer
Review Slicer: Adaptive classification engine that evaluates semantic cohesion to decide whether slicing improves review quality. Sits between Mithril pre-analysis and reviewer dispatch. Classification-only — does NOT read source code.
ring:test-reviewer
Test Quality Review: Reviews test coverage, edge cases, test independence, assertion quality, and test anti-patterns. Runs in parallel with other reviewers at Gate 8.
ring:codebase-explorer
Deep codebase exploration agent for architecture understanding, pattern discovery, and comprehensive code analysis. Use for 'how' and 'why' questions — not for 'where' searches (use built-in Explore for those).
ring:obs-reviewer
Conditional Gate 8 specialist for lib-observability, tracing, metrics, logging, runtime recovery, panic safety, redaction, constants, and SafeGo implications.
ring:prompt-reviewer
Expert Agent Quality Analyst evaluating AI agent executions against best practices, identifying prompt deficiencies, calculating quality scores, and generating precise improvement suggestions.
company-finder
Discovery-mode agent. Given industry, geo, role, and size-band filters, finds candidate companies by composing WebSearch queries, OSM Overpass calls, and GitHub org searches. Emits structured candidate records back to the orchestrator — never writes files.