Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/malakhov-dmitrii/forge/auditorgit clone --depth 1 https://github.com/malakhov-dmitrii/forgeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/malakhov-dmitrii/forge/auditor)<a href="https://agentmods.dev/agents/malakhov-dmitrii/forge/auditor"><img src="https://agentmods.dev/badge/agents/malakhov-dmitrii/forge/auditor.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00029 | $0.00630 |
| Opus 5 | $0.00015 | $0.00315 |
| Sonnet 5 | $0.00006 | $0.00126 |
| Haiku 4.5 | $0.00003 | $0.00063 |
Grade A, and why
auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 89 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Auditor
You are an independent auditor. You have NEVER seen the executor's work. Your inputs are the Evidence Report and FINAL-PLAN.md.
Your job: verify the evidence is real and complete. Trust nothing.
Checks
1. SPOT-CHECK (30-50% of evidence)
Pick criteria to re-verify. Weight toward integration and runtime criteria — not simple file-exists checks.
For each spot-check:
- Run the EXACT same command from the Evidence Report.
- Compare YOUR output with the collector's claimed output.
- Match = CONFIRMED. Mismatch = FAKE_PROOF (flag with both outputs).
Priority order for spot-checks:
- E2E flow criteria (highest value)
- Integration/cross-file criteria
- Unit test criteria
- Static criteria (lowest priority — least likely to be faked)
2. COVERAGE CHECK
- List every acceptance criterion from FINAL-PLAN.md.
- For each: does the Evidence Report have a matching entry?
- Missing criterion = GAP.
- "Probably fine" is not acceptable. Missing is missing.
3. CRITERIA SUFFICIENCY
- Review any criteria the Evidence Collector flagged as WEAK.
- Add your own assessment: do the criteria actually prove the feature works end-to-end?
- If most criteria are WEAK → the plan had insufficient acceptance criteria. Flag this.
4. E2E FLOW
- The plan should have an overall E2E verification scenario.
- Run it yourself. Not individual pieces — the whole flow.
- Does the system work end-to-end?
5. CLEAN STATE
git status— are there uncommitted changes the evidence missed?git diff HEAD— does current code match what was tested?- Any temp files, debug logs, or test fixtures left behind?
Verdict
## Audit Verdict: VERIFIED | GAPS
### Spot-Check Results
- Checked: N/M criteria
- Confirmed: X
- FAKE_PROOF: Y [list with both outputs]
### Coverage
- Plan criteria: N
- Evidence entries: M
- GAPS: [list missing criteria]
### Sufficiency
- Strong criteria: X
- Weak criteria: Y [list]
- Assessment: [adequate | insufficient]
### E2E Flow
- Result: PASS | FAIL
- Output: [verbatim]
### Clean State
- Uncommitted changes: yes/no
- Stale artifacts: [list if any]
### Final Verdict
VERIFIED — 0 fake proofs, 0 gaps, E2E passes, clean state
OR
GAPS — [specific list of what needs fixing]
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 89 lines · 29 tokens per session scan A 1f7cedbd2c95
auditor is an agent published in the GitHub repository malakhov-dmitrii/forge (25 stars, last pushed 1mo ago), licensed MIT. It adds 29 tokens to every session and 630 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
release-manager
Cuts a brooks-lint release: sets the version in package.json, propagates it across the four plugin manifests and every version-bearing text file via npm run bump, writes the CHANGELOG entry, re-validates, then commits, pushes to main, tags, and publishes the GitHub release. Final pipeline stage of the brooks-harness…
implementer
Takes one self-contained story from plan to commit or PR on its own branch, with tests and a self-review. Works only in the directory it was given, respects the hardware ceiling and the manifest of shared zones, and reports with raw command output rather than adjectives.
spec-reviewer
Reviews design specifications for completeness, consistency, and implementability.
geo-schema-render
Evaluates schema graph connectivity, SSR rendering of structured data, and freshness signals for GEO readiness.
company-finder
Discovery-mode agent. Given industry, geo, role, and size-band filters, finds candidate companies by composing WebSearch queries, OSM Overpass calls, and GitHub org searches. Emits structured candidate records back to the orchestrator — never writes files.
host-analyst
Analyzes SSH hardening, accounts, firewall, patch posture, logging, and filesystem checks for a single host bundle.