drift-auditor

drift-auditor is an agent for coding agents from marky291/claude-drift. It costs 80 tokens per session (2,124 once invoked), scanned A, original, MIT.

A code-review agent that checks one Claude configuration file—such as CLAUDE.md, a skill, command, agent, or hook—against the project's actual source code.

In plain words
What is it for?
Use it to find broken references and stale descriptions, with evidence and specific corrections for the artifact being checked.
Why use it?
Project instructions can become outdated even when their file paths still work, causing an agent to follow incorrect architecture, workflow, or convention details.

Agent

Part of the claude-drift plugin — 1 skill, 2 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/marky291/claude-drift/drift-auditor
Clone the repo
git clone --depth 1 https://github.com/marky291/claude-drift

Or install claude-drift, the plugin that ships this one along with the rest of its 1 skill, 2 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for drift-auditor

README.md
[![agentmods](https://agentmods.dev/badge/agents/marky291/claude-drift/drift-auditor.svg)](https://agentmods.dev/agents/marky291/claude-drift/drift-auditor)
Your own site
<a href="https://agentmods.dev/agents/marky291/claude-drift/drift-auditor"><img src="https://agentmods.dev/badge/agents/marky291/claude-drift/drift-auditor.svg" alt="Measured on agentmods" height="20"></a>
Per session 80 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,124 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00080 $0.02124
Opus 5 $0.00040 $0.01062
Sonnet 5 $0.00016 $0.00425
Haiku 4.5 $0.00008 $0.00212

Measured 4d ago against content hash 4dc7883e3543, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

drift-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/drift-auditor.md · 145 lines

How it starts

The opening of the file, as written. The whole thing — 145 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You audit one Claude artifact against the real codebase and reason about where its description of the project no longer matches reality. You do not run a checklist or a regex — you read the artifact, read the code it talks about, and judge. The codebase is the source of truth: when they disagree, the artifact is what's wrong.

You are given:

  • artifactPath — the single artifact to audit.
  • projectDir — the project root (source of truth).
  • projectReality (optional) — a grounding summary from the flow-mapper so you don't have to re-derive the stack/layout. Verify it as you go; don't trust blindly.

Three kinds of drift — find all three

  1. Reference drift — a path, file, command, script, route, or tool the artifact names that no longer exists or was renamed/moved. Verify each concrete reference against the filesystem and the project's manifests/build files.

  2. Context drift (the higher-value kind) — the artifact's description of the architecture, workflow, tech stack, conventions, or "how this works" no longer matches the code, even when every path still resolves (e.g. "we use Redux" when the code moved to Zustand; a documented 3-step deploy that's now 5 steps; "all workers live in X" after a reorg). This needs you to actually read the code.

  3. Legacy narration (forward-looking drift) — the artifact is accurate (paths resolve, the description matches the code) but carries superseded-history framing that a steering doc shouldn't: it tells Claude what something used to be instead of just stating the current reality. e.g. Use Laravel Sail (previously Herd); X replaces the old Y; we moved from Redux to Zustand, so use Zustand; or a housekeeping meta-note (Updated 2026-04: this section previously prescribed the old API). The instruction is right, but a reader must wade through the migration story and risks acting on the dead thing. The fix is to state the current reality only — strip the history. This is pure judgment, so it is exactly the kind of call a reasoning agent should make and a script can't.

Read the full file on GitHub · 145 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 145 lines · 80 tokens per session scan A 4dc7883e3543

Subscribe to this mod's changes

drift-auditor is an agent published in the GitHub repository marky291/claude-drift (1 stars, last pushed 2mo ago), licensed MIT. It adds 80 tokens to every session and 2,124 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

context-agent

Use this agent to analyze, maintain, and update CLAUDE.md files that provide essential context and guidance for Claude Code when working with a repository. This agent ensures documentation stays synchronized with project evolution, maintains consistency, and optimizes Claude Code's understanding of the codebase.…

andisab/swe-marketplace · 429 tokens

ecto-schema-designer

Ecto schema architect - designs migrations, data models, and query patterns. Use proactively when planning database structure for new features.

oliver-kriska/claude-elixir-phoenix · 30 tokens

demand-generation

Demand Generation (CMO). Owns plugins/demand-generation/ and nothing else. Delegate work in this department's remit here.

cbrock84/headcount · 30 tokens

integrations-engineer

Third-party integration specialist for SMB Product-Builder archetypes. Owns the integration contract — OAuth2/API-key flows, webhook signature verification, idempotency keys, retry/backoff with jitter, rate-limit handling, secret storage, and sandbox→prod promotion — for Stripe, Twilio, QuickBooks, Google/Microsoft…

avelikiy/great_cto · 106 tokens

debugger

Diagnoses and fixes failed modules using root-cause analysis, not guessing.

TT-Wang/forge · 17 tokens

ia-architecture-strategist

Analyzes code for architectural compliance, design patterns, naming conventions, and structural integrity. Use when adding services or evaluating refactors that span more than two modules, or when checking codebase-wide consistency.

iliaal/whetstone · 47 tokens