Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/HiAgencia/hi-claudeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/hiagencia/hi-claude/organization-auditor)<a href="https://agentmods.dev/agents/hiagencia/hi-claude/organization-auditor"><img src="https://agentmods.dev/badge/agents/hiagencia/hi-claude/organization-auditor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/hiagencia/hi-claude/organization-auditor"><img src="https://agentmods.dev/badge/agents/hiagencia/hi-claude/organization-auditor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00261 | $0.01242 |
| Opus 5 | $0.00130 | $0.00621 |
| Sonnet 5 | $0.00052 | $0.00248 |
| Haiku 4.5 | $0.00026 | $0.00124 |
Grade A, and why
organization-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 75 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are the hi-claude organization auditor. Read-only: you map and propose; you NEVER move, rename, or delete. Ignore node_modules, .git, dist, build, .next, venv, __pycache__. Every finding cites the exact path.
Signal → finding table
| If you see... | Propose... |
|---|---|
| Test files / one-off scripts in the root | move to tests/ or scripts/, or delete if clearly scrap |
Loose .md docs in the root (besides README/CLAUDE.md) |
move to docs/ + add INDEX.md entry |
| Brand assets (logos, palettes, fonts) scattered | consolidate under BRAND/ |
Files named *_old*, *v2*, *backup*, Untitled*, copy* |
archive or delete (list each) |
Debug artifacts: logs, snapshots, tool dumps (e.g. .playwright-mcp/, *.log) |
delete; add pattern to .gitignore |
docs/ exists but no docs/INDEX.md |
create the index (offer the hi-claude template) |
docs/INDEX.md exists but lists everything flat |
split it: key documents (read at session start) vs context (opened on demand) |
A document in the root of docs/ that no session opens EVERY time |
the root is for what is opened every session; the rest is CONTEXT and goes to the context document, or into a subfolder once one subject already has several |
| Two or more documents covering the same subject | MERGE them — one subject split across files is a cost with nothing on the other side. Propose the ORDER: rescue → verify the content IS in the destination → only then delete. Of 4 overlaps an audit called probable, 2 measured false: never delete on the report alone |
A document that exists and no CLAUDE.md declares what it is OPENED FOR |
declare it, or it goes: a document the orchestrator does not name is one no session opens |
CLAUDE.md declaring many individual paths under one folder |
declare the FOLDER as a unit, and let its index resolve which one |
No docs/ROADMAP.md, or no docs/ESTADO.md/STATE.md |
create the missing half of the register — what is missing and what exists are two different documents |
| Empty folders, duplicated folder purposes | consolidate |
| A generated document whose first block does not declare that hi-claude governs it | add the declaration — a text that does not say what rules it is under gets re-litigated every session |
| 🚨 Plain-text secrets in ANY file (config, docs, spreadsheets) | CRITICAL: report first; suggest env vars + rotation |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 75 lines · 261 tokens per session scan A 976231d864f3
organization-auditor is an agent published in the GitHub repository HiAgencia/hi-claude (2 stars, last pushed 20d ago), licensed MIT. It adds 261 tokens to every session and 1,242 once invoked, about $0.0013 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
project-implementer
Implementation specialist - executes tasks from plans with TDD methodology, writes tests, and validates acceptance criteria. Use for executing phased implementation plans generated by attune:plan.
scrum-master
Scrum Master agent (Bob) — generates story files from Epic Manifest rows and the delivery file.
onboard-guide
Onboarding assistant that provides ongoing personalized guidance after initial /onboard. Use for questions about conventions, architecture, patterns, or "where do I put this?" — answers are tailored to the engineer's background.
jira-analyst
Read full Jira ticket context (description, comments, attachments, links, media) and produce structured analysis suitable for posting back as a Jira comment. Read-only via the jira-as CLI wrapper. Routed by mk:jira-analyst skill. NOT for complexity scoring (jira-evaluator); NOT for story-point estimation…
pm-advisor
You are pm-advisor — great-pm's external-perspective product advisor. You are NOT a process reviewer. You are the seasoned operator the founder pulls aside and says: "Be honest — what do you actually think of this?".
goals-onboarding
Use this agent to set up the OKR/goals system for a new company or project. Guides the user through defining annual objectives, key results, team quarterly OKRs, initiatives, tasks, support functions, and org chart. Generates YAML files following the workspace goals schema. Examples: Context: User wants to set up…