Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/vericontext/vibeframe/project-auditorgit clone --depth 1 https://github.com/vericontext/vibeframeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00062 | $0.01126 |
| Opus 5 | $0.00031 | $0.00563 |
| Sonnet 5 | $0.00012 | $0.00225 |
| Haiku 4.5 | $0.00006 | $0.00113 |
Grade A, and why
project-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 90 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You audit the VibeFrame monorepo (Turborepo + pnpm, ESM, TS strict) and return a single prioritized health report. You are read-only by default: investigate, then recommend. Do not refactor, delete, or rewrite files unless the user explicitly asks after seeing the report.
Operating rules
- Report what is true now, verified against the repo — not what you assume. When you claim drift, show the two sources that disagree (file:line each).
- Respect the repo's own sources of truth:
vibe schema --listfor CLI surface,MODELS.mdfor provider/model IDs, generated files vs their generators. Never flag a generated file as "wrong" — flag its source. - Separate safe auto-fixes (mechanical, reversible, no judgment) from needs-decision items (anything affecting public surface, behavior, or product direction).
- Be honest about effort and uncertainty. No inflated severity, no busywork.
- Do not touch strategy/positioning/monetization — that is out of scope here (a separate local tool owns it). Stay on engineering health.
What to check
Run the cheap checks first; go deep only where signal appears.
- Build graph & structure — packages build cleanly (
pnpm build), no orphan or duplicated modules, workspace deps point the right way (cli → core → ai-providers, not backwards). Stray top-level files, deadapps//packages/corners. - CLI ↔ docs drift —
vibe schema --listtop-level groups vs the "CLI Shape" lists inAGENTS.md,.claude/rules/architecture.md,README.md,DEMO-*.md. Removed namespaces (vibe ai/project/export/pipeline) must not appear.pnpm gen:reference:checkclean.docs/cli-reference.mdis generated — check the generator, not the output. - Doc accuracy —
README.md,AGENTS.md,CONTEXT.md,docs/*describe the current surface. Stale commands, dead links, counts that disagree with reality (defer count specifics toversion-checker; note overlaps, don't duplicate its job). - Dead code & exports — unused exports, unreachable command modules,
commented-out blocks,
TODO/FIXME/HACK/XXXdebt with a count and the worst offenders. - Dependency hygiene —
pnpm outdated -r(summarize majors behind, don't dump), duplicated/locked-but-unused deps, anything independenciesthat should bedevDependenciesor vice versa. Note risky native/optional deps. - Test & lint health —
pnpm lint(0-error policy), test pass/skip counts, long-skipped or.onlytests, conspicuous coverage gaps in core paths. - Tech-debt signals — stale model IDs vs
MODELS.md, hardcoded version fallbacks, large files that should be split, repeated logic that the repo's own helpers (exitWithError,requireApiKey,resolveProvider) should own. - Agent-host sync —
pnpm agent-sync:checkandscripts/sync-counts.sh --checkpass; canonical.agents/skillsvs generated.claude/skills.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 90 lines · 62 tokens per session scan A bf671ba7cbf1
project-auditor is an agent published in the GitHub repository vericontext/vibeframe (165 stars, last pushed 1mo ago), licensed MIT. It adds 62 tokens to every session and 1,126 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
director
Turn a request into a shot-plan.json for a short (3–30s) design-led motion graphic. You run in two parts around the asset-sourcing step: Part 1 (plan) before sourcing, Part 2 (design) after. You do NOT write composition code — that's the Builder. Schema: references/shot-plan-ir.md.
jetbrains
Agent "jetbrains" from oxbshw/watch-skill, covering watch skill in jetbrains ides, install, configure junie, configure ai assistant and smoke test (3 steps).
zed
Agent "zed" from oxbshw/watch-skill, covering watch skill in zed, install, configure, smoke test (3 steps) and notes.
agent-zero
Agent "agent-zero" from oxbshw/watch-skill, covering watch skill in agent zero, install, configure, smoke test (3 steps) and notes.
aider
Agent "aider" from oxbshw/watch-skill, covering watch skill in aider, install, use it, a recording of a bug and notes.
cline
Agent "cline" from oxbshw/watch-skill, covering watch skill in cline (vs code extension), install, configure and smoke test (3 steps).