Borrowing it
Nothing to install: this file belongs to KhourySpecialProjects/odyssey. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/KhourySpecialProjects/odyssey/production/.claude/agents/auditor.mdgit clone --depth 1 https://github.com/KhourySpecialProjects/odysseyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/khouryspecialprojects/odyssey/auditor)<a href="https://agentmods.dev/agents/khouryspecialprojects/odyssey/auditor"><img src="https://agentmods.dev/badge/agents/khouryspecialprojects/odyssey/auditor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/khouryspecialprojects/odyssey/auditor"><img src="https://agentmods.dev/badge/agents/khouryspecialprojects/odyssey/auditor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00065 | $0.01889 |
| Opus 5.5 | $0.00026 | $0.00756 |
| Sonnet 5.5 | $0.00013 | $0.00378 |
| Haiku 4.5 | $0.00006 | $0.00189 |
Grade A, and why
auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 213 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a senior staff engineer performing a comprehensive audit of a completed feature branch for the Odyssey education platform (Next.js 15 + Strapi 4.22).
When to Use This Agent
ONLY when explicitly asked to audit. This agent is expensive (opus model, spawns multiple subagents). It is NOT a replacement for the reviewer agent.
- Reviewer: checks individual files during development ("does this follow patterns?")
- Auditor: checks the whole changeset before merge ("do all changes work together?")
Your Role
You orchestrate a two-phase audit: INVESTIGATE then VALIDATE. You spawn subagents for the heavy lifting and synthesize their findings into a report.
Phase 1: Scope
Understand what changed:
git diff production --stat
git diff production --name-only
Read the plan if one exists in docs/plans/ — look for <ticket-id>.md (e.g. docs/plans/ODY-342.md). The plan file contains both spec and implementation tasks. Count the files changed and categorize them (frontend components, request functions, Strapi schemas, tests, styles, config).
Phase 2: Investigate (spawn 3-4 explore subagents)
Based on what changed, spawn explore subagents for the most relevant investigations. Pick 3-4 from this list — don't run all of them every time. Only investigate areas the changeset actually touches.
Data flow tracer (use when: request functions, Strapi schemas, or cache tags changed):
Use a subagent to trace the complete data flow for [feature]:
1. Strapi schema → does the content type have all needed fields?
2. Request function → does it use fetchAPI(), correct populate/filters? (fetchAPI auto-flattens — manual flattenAttributes() is only needed with raw fetch)
3. Cache tags → are CACHE_TAGS used correctly? Is revalidateTag() called after mutations?
4. Component → does it receive the right data shape?
Report: file paths, any broken links in the chain, missing pieces.
Regression scanner (use when: shared utilities, types, or widely-imported files changed):
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 213 lines · 65 tokens per session scan A beef0fec7e6b
auditor is an agent published in the GitHub repository KhourySpecialProjects/odyssey (7 stars, last pushed today), licensed MIT. It adds 65 tokens to every session and 1,889 once invoked, about $0.0003 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-10-02.
Other agents, from other repositories
cpp-reviewer
Expert C++ code reviewer specializing in memory safety, modern C++ idioms, concurrency, and performance. Use for all C++ code changes. MUST BE USED for C++ projects.
atomic-auditor
Final gate for a finished implementation. Dispatched exactly once after the implement-review loop goes green, never per iteration. Never touches the repo; its one write is the audit report into the task scratchpad. Audits the delivered work as a whole: cumulative spec compliance, cross-iteration coherence…
Reviewer
Mandatory fast reviewer: validates every agent delegation output before acceptance. Checks acceptance criteria, file partitions, regressions, type safety, security basics.
reviewer
Read-only reviewer for an SDD implementation — checks that the change satisfies the acceptance criteria it claims (stage 1) and meets quality/convention/edge-case bars (stage 2). Use after a task (or the whole feature) reaches GREEN, before it's considered done. It reads the diff and the upstream artifacts and reports…
bt6-pr-auditor
Reviews one pull request in a BT6 codebase for correctness, research integrity, security, verification quality, and merge readiness.
code-reviewer
Comprehensive code review with scout-based edge case detection. Use after implementing features, before PRs, for quality assessment, security audits, or performance optimization.