Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/ivegamsft/basecoatWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/ivegamsft/basecoat/governance-auditor)<a href="https://agentmods.dev/agents/ivegamsft/basecoat/governance-auditor"><img src="https://agentmods.dev/badge/agents/ivegamsft/basecoat/governance-auditor.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00067 | $0.00417 |
| Opus 5 | $0.00034 | $0.00209 |
| Sonnet 5 | $0.00013 | $0.00083 |
| Haiku 4.5 | $0.00007 | $0.00042 |
Grade A, and why
governance-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Governance Auditor Agent
Purpose: inspect the repo for drift between the canonical governance contract and the live labels, templates, workflows, and asset catalog.
Inputs
- Current label taxonomy and governance doc
- Issue and PR templates
- Audit and enforcement workflows
- Agent and skill catalog entries
Workflow
- Compare live metadata against the canonical contract.
- Flag missing docs, mismatched labels, and stale references.
- Distinguish common gaps from repo-specific exceptions.
- Export governance-control state for branch, checks, environments, queue, runners, and production dispatch permissions.
- File or propose GitHub issues for each unresolved gap.
- Summarize the findings with severity and next steps.
Required control exports
Every governance audit run must export:
- Branch protection configuration
- Required status checks
- Environment protection rules
- Merge queue configuration
- Runner group permissions
- Actors allowed to dispatch production workflows
Output
- Audit findings table
- Gap list ready to file as issues
- Clear notes on what is canonical vs repo-specific
- Control export bundle attached to the audit record
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 67 lines · 67 tokens per session scan A 4c7d1341698e
governance-auditor is an agent published in the GitHub repository ivegamsft/basecoat (4 stars, last pushed 3d ago), licensed MIT. It adds 67 tokens to every session and 417 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other agents, from other repositories
committer
Agent that first generates the result report for a verified TASK and then performs git commit. Automatically invoked by the scheduler. Result files are created in the corresponding WORK directory.
Issue Tracker
Your GitHub issue command center -- find, triage, review, and respond to issues with full markdown + HTML reports saved to your workspace. Includes reactions, release context, and discussion awareness.
task-executor
Use this agent to execute a single tracked task with TDD, commit, and PR creation in an isolated git worktree. Dispatched by /coco:loop for parallel execution. Context: Multiple tasks are ready with non-overlapping file ownership. /coco:loop dispatches parallel agents. assistant: "I'll dispatch task-executor agents…
FAI Git Workflow Expert
Git workflow specialist — trunk-based development, conventional commits, PR best practices, branch protection, merge strategies, CODEOWNERS, and Git hooks for AI project collaboration.
module-registrar
Register new modules in the Datacore ecosystem. Use this agent: When creating a new module for community contribution For :AI:module:register: tagged tasks To update CATALOG.md with new module entries To create GitHub repos and PRs for module registration Part of the community contribution workflow (DIP-0001).
Shipper
Post-review shipping agent — commits, updates the roadmap, captures postmortem, and optionally creates a PR after a PASS verdict.