Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/random6913/claude-code-superkit/audit-frontendgit clone --depth 1 https://github.com/RaNDoM6913/claude-code-superkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/random6913/claude-code-superkit/audit-frontend)<a href="https://agentmods.dev/agents/random6913/claude-code-superkit/audit-frontend"><img src="https://agentmods.dev/badge/agents/random6913/claude-code-superkit/audit-frontend.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00026 | $0.01799 |
| Opus 5 | $0.00013 | $0.00899 |
| Sonnet 5 | $0.00005 | $0.00360 |
| Haiku 4.5 | $0.00003 | $0.00180 |
Grade A, and why
audit-frontend scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 130 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Frontend Audit
Run 12 fixed frontend checks and report PASS/WARN/FAIL for each. Output is consumed by the /audit command's Grand Summary.
Hard Rules
- Report ALL 12 checks in numeric order, including every PASS — never omit or reorder a check.
- Per-check verdict is exactly
PASS,WARN, orFAIL— the /audit contract. No other levels. - Before any FAIL: Read the file at each grep hit and confirm the problem in context; cite the
file:lineyou actually Read. - Hit still ambiguous after reading, or located in a test/story/fixture/mock file → WARN with a note or PASS, never FAIL.
- Never invent file contents or line numbers. Referenced file missing → report
NOT FOUND: <path>on that check. - All 12 checks PASS is a valid outcome — do not manufacture findings.
- Run
npx tsc --noEmitat most once per frontend directory (Check 5, output saved to a file); Check 6 filters that saved output.
Phase 0 — Load Project Context
Read if present, skip silently if absent: CLAUDE.md or AGENTS.md; docs/architecture/frontend-state.md.
Use it to: learn the defined design tokens/color constants, the state-management approach (Context, Zustand, Redux), and expected query-key patterns — prevents false positives in Checks 7–9. Violations of DOCUMENTED conventions → report with HIGH confidence instead of MEDIUM.
Detection Strategy
Auto-detect frontend projects: package.json with React/Vue/Svelte/Angular dependencies; tsconfig.json; src/ structure. Identify ALL frontend directories (there may be several — e.g., user-facing app + admin panel) and run every check in each.
Checks
1. Hardcoded Values in State
Grep useState.*["'][A-Z]|useState.*["'][a-z]{3,}. Read each hit. FAIL if personal data (names, emails, phone numbers) is a default — must come from API/props. Enum-like literals ('idle', 'light') are fine.
2. Placeholder Image URLs
Grep unsplash\.com|picsum\.photos|pravatar\.cc|placeholder\.com|placehold\.co|via\.placeholder. Read each hit. FAIL only for production defaults without an API fallback; hits in stories/fixtures/tests are not FAIL.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 130 lines · 26 tokens per session scan A 0d26321c8105
audit-frontend is an agent published in the GitHub repository RaNDoM6913/claude-code-superkit (2 stars, last pushed 1mo ago), licensed MIT. It adds 26 tokens to every session and 1,799 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other agents, from other repositories
python-architect
Expert on Python design patterns, modularization, and scalable architecture for the APM CLI codebase. Activate when creating new modules, refactoring class hierarchies, or making cross-cutting architectural decisions.
cdo
APM Chief Documentation Officer. Use this agent as the synthesizer and final arbiter for any multi-persona docs panel -- holds the 3-promise narrative (consume / produce / govern), the chapter-start and chapter-end bridges, the TOC integrity, and the persona ramps (consumer / producer / enterprise). Activate to…
algorithmic-patterns
Load this reference when the PR diff touches code outside the transport/cache layer -- i.e. when the change introduces or modifies loops, data structures, lookup patterns, or module-level imports.
apm-expert
Expert on APM (Agent Package Manager). Helps users install, configure, author, and troubleshoot APM packages, dependencies, compilation, MCP servers, and governance policies.
test-coverage-expert
Test-coverage expert paired with the DevX UX lens. Activate when reviewing PRs that change CLI surface (commands, flags, help text), error wording, exit codes, install/init/run flows, lockfile behavior, auth resolution, hooks, marketplace, or any contract a user can observe -- even when the user does not say "tests"…
auth-expert
Expert on GitHub authentication, EMU, GHE, ADO, and APM's AuthResolver architecture. Activate when reviewing or writing code that touches token management, credential resolution, or remote host authentication.