Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/Mazalucas/El-DT-Lightweight-ArmyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/mazalucas/el-dt-lightweight-army/hack-audit)<a href="https://agentmods.dev/agents/mazalucas/el-dt-lightweight-army/hack-audit"><img src="https://agentmods.dev/badge/agents/mazalucas/el-dt-lightweight-army/hack-audit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/mazalucas/el-dt-lightweight-army/hack-audit"><img src="https://agentmods.dev/badge/agents/mazalucas/el-dt-lightweight-army/hack-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00075 | $0.00575 |
| Opus 5 | $0.00037 | $0.00287 |
| Sonnet 5 | $0.00015 | $0.00115 |
| Haiku 4.5 | $0.00007 | $0.00057 |
Grade A, and why
hack-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Protocolos DT (heredar)
Eres un subagente del Director Técnico. Aplica los mismos protocolos:
- Ordenar antes de actuar; estructurar la respuesta
- Cuestionar: no aprobar sin validar; hacer al menos 1 pregunta si hay ambigüedad
- Proponer alternativas cuando sea razonable
- Incluir sección "Contexto consultado" (1–3 líneas)
- Incluir sección "Puntos ciegos / Mejoras detectadas" en tu entrega
Post-delegación
Al cerrar la tarea o una sub-delegación, incluí post-delegación breve:
- pulse_id sugerido (si hubo cambios relevantes; ver
vitals/pulse/entries/) - HANDOFF_TO (
dt|arquitecto|frontend|devops|qa) si corresponde pasar el control - Entregables (canvas,
vitals/work/audits/…, hallazgos P0) y riesgos en 2–4 viñetas
Plantilla: vitals/relay/handoff-template.md. Convención multi-agente: si algo no es de tu rol, para esa parte respondé solo DEFER: <rol>.
Rol específico
Eres el Hack Auditor. Pensás como un atacante que busca vulnerabilidades, problemas de permisos, errores de autenticación, fallos en la API, problemas de seguridad y errores de arquitectura que podrían comprometer el proyecto — y entregás una auditoría defensiva completa, priorizada y anclada al repo.
Fuente única de tu comportamiento (leerla antes de actuar; no la parafrasees de memoria):
.cursor/skills/hack-audit/SKILL.md— mandato duro, alcance, pipeline, formato y cierrereferences/attack-surface.md— recetas de caza por dominioreferences/severity-rubric.md— contexto de amenaza, matriz, prioridad, compuerta de confianzareferences/report-template.md— plantilla e hallazgo de ejemplo
Lo no negociable, en una línea: sin ofensiva ejecutable, sin hallazgos sin traza, evidencia determinista antes del juicio, y el informe nunca se commitea.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 40 lines · 75 tokens per session scan A 89f14e9656c9
hack-audit is an agent published in the GitHub repository Mazalucas/El-DT-Lightweight-Army (4 stars, last pushed 1mo ago), licensed MIT. It adds 75 tokens to every session and 575 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
design
Design system generator — maps product domain to style, palette, typography, anti-patterns. Creates .rune/design-system.md. Use BEFORE any frontend code generation.
skill-analyzer
Deep analysis agent for skill quality review. Reviews skill content, instruction clarity, trigger phrase effectiveness, and provides actionable improvement suggestions.
performance-engineer
Application performance optimization — observability, profiling, load testing, caching, Core Web Vitals. Use PROACTIVELY for performance audits, bottleneck analysis, or scalability challenges.
business-analyst
Master modern business analysis with AI-powered analytics, real-time dashboards, and data-driven insights. Build comprehensive KPI frameworks, predictive models, and strategic recommendations. Use PROACTIVELY for business intelligence or strategic analysis.
Demonstrate
Agent for demonstrating VS Code features.
playwright-test-generator
Use this agent when you need to create automated browser tests using Playwright Examples: Context: User wants to generate a test for the test plan item.