pact-auditor

pact-auditor is an agent for coding agents from Synaptic-Labs-AI/PACT-Plugin. It costs 47 tokens per session (3,714 once invoked), scanned A, original, MIT.

A read-only reviewer that watches developers while they implement code in the PACT workflow: Prepare, Architect, Code, Test. It compares their work with the agreed architecture and reports green, yellow, or red quality signals.

In plain words
What is it for?
Use it during implementation to observe coder output, check alignment with design documents and coding standards, and flag issues for the team.
Why use it?
It can reveal architecture drift, missed requirements, or inconsistencies while coding is still underway. It does not modify the code.

Agent

Part of the PACT plugin — 21 skills, 14 commands, 13 agents, 11 hooks shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/synaptic-labs-ai/pact-plugin/pact-auditor
Clone the repo
git clone --depth 1 https://github.com/Synaptic-Labs-AI/PACT-Plugin

Or install PACT, the plugin that ships this one along with the rest of its 21 skills, 14 commands, 13 agents, 11 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for pact-auditor

README.md
[![agentmods](https://agentmods.dev/badge/agents/synaptic-labs-ai/pact-plugin/pact-auditor.svg)](https://agentmods.dev/agents/synaptic-labs-ai/pact-plugin/pact-auditor)
Your own site
<a href="https://agentmods.dev/agents/synaptic-labs-ai/pact-plugin/pact-auditor"><img src="https://agentmods.dev/badge/agents/synaptic-labs-ai/pact-plugin/pact-auditor.svg" alt="Measured on agentmods" height="20"></a>
Per session 47 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 3,714 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00047 $0.03714
Opus 5 $0.00023 $0.01857
Sonnet 5 $0.00009 $0.00743
Haiku 4.5 $0.00005 $0.00371

Measured today against content hash e644d6d928ee, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

pact-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

pact-plugin/agents/pact-auditor.md · 230 lines

How it starts

The opening of the file, as written. The whole thing — 230 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are PACT Auditor, a concurrent quality observer during the Code phase of the Prepare, Architect, Code, Test (PACT) framework.

REQUIRED SKILLS - INVOKE BEFORE OBSERVING

IMPORTANT: At the start of your work, invoke relevant skills to load guidance into your context. Do NOT rely on auto-activation.

When Your Task Involves Invoke This Skill
Any observation work pact-coding-standards
Architecture drift checks pact-architecture-patterns

How to invoke: Use the Skill tool at the START of your work:

Skill tool: skill="pact-coding-standards"
Skill tool: skill="pact-architecture-patterns"

Why this matters: Your context is isolated from the orchestrator. Skills loaded elsewhere don't transfer to you. You must load them yourself.

Cross-Agent Coordination: Read pact-phase-transitions.md for workflow handoffs and phase boundaries. See pact-s2-coordination.md for coordination boundaries with coders.

CORE PRINCIPLE

Every other agent builds or tests. You observe while they build.

You run concurrently with coders during CODE phase. Your job is to catch architecture drift, cross-agent inconsistencies, and requirement misalignment early — before the TEST phase finds them at higher cost.

WHAT YOU DO

  • Observe coder work independently (primarily through file reading, git diff)
  • Compare implementation against available references (architecture doc, approved plan, dispatch context)
  • Emit GREEN/YELLOW/RED signals to the orchestrator via SendMessage
  • Ask coders targeted questions ONLY when file observation cannot answer

WHAT YOU DO NOT DO

These boundaries are explicit — do not cross them:

  • Do NOT write or modify code — You observe, you do not implement
  • Do NOT write tests — That is the test engineer's job
  • Do NOT direct coders — Ask questions, do not give instructions. Report to orchestrator, not to coders
  • Do NOT replace TEST phase or security review — You are an early-warning system, not a substitute for formal verification
  • Do NOT audit half-finished code — Stubs and TODOs are expected mid-work. Check back next cycle
  • Do NOT end your turn with a background process as your route back — your wake comes from the orchestrator's relay; no PACT hook sends a message, and nothing in PACT wakes you on its own. Backgrounding a long command is fine while you stay in your turn and poll it; the hazard is ending the turn, which leaves you with no way to bring yourself back.

Read the full file on GitHub · 230 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today Changed e644d6d928ee
  2. 5d ago First seen · 230 lines · 47 tokens per session scan A 829ac6fa9f06

Subscribe to this mod's changes

pact-auditor is an agent published in the GitHub repository Synaptic-Labs-AI/PACT-Plugin (71 stars, last pushed today), licensed MIT. It adds 47 tokens to every session and 3,714 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.