audit

A command for running a complete project audit with four agents working in parallel. An audit is a structured review that looks for problems across a software project.

In plain words
What is it for?
Use it to start a full project audit, consume a prepared audit summary, or report that a required Docker or SonarQube choice is pending.
Why use it?
It uses prepared audit information when available and follows a defined startup process before reviewing the project. In automated command-line use, it stops when a human decision about Docker or SonarQube is needed.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/686f6c61/alfred-dev/audit
Clone the repo
git clone --depth 1 https://github.com/686f6c61/alfred-dev
Per session 12 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,931 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00012 $0.01931
Opus 5 $0.00006 $0.00966
Sonnet 5 $0.00002 $0.00386
Haiku 4.5 $0.00001 $0.00193

Measured 2d ago against content hash 063ccb6d5ba8, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

commands/audit.md · 117 lines

How it starts

The opening of the file, as written. The whole thing — 117 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/alfred-dev:audit

Eres Alfred, orquestador del equipo. El usuario quiere una auditoría completa del proyecto.

Protocolo helper-first y modo headless

Antes de leer contexto en detalle, lanzar agentes o hacer análisis manual, intenta consumir un prefetch determinista ya preparado por el hook:

python3 .claude/alfred-continuity.py consume-prefetch "$PWD" --expected audit

Si el prefetch existe y devuelve salida, responde con esa salida y termina. Si no existe, arranca la sesión canónica y el preflight determinista de SonarQube con:

python3 .claude/alfred-continuity.py start-flow "$PWD" --command audit --raw "Auditoría completa del proyecto"

En modo headless (claude -p), SDK sin callback usable de AskUserQuestion, auditoría automática o si una herramienta indica que hay prefetch consumido, NO lances los 4 agentes, no llames agentes ni ejecutes una auditoría completa. Devuelve el resumen del helper con AUDIT_HEADLESS_START o, si Docker requiere decisión humana, con AUDIT_DOCKER_INSTALL_MENU_HEADLESS / AUDIT_DOCKER_START_MENU_HEADLESS. No instales Docker, no arranques Docker Desktop y no autoelijas "seguir sin SonarQube"; deja la decisión pendiente y termina.

En sesión interactiva normal, puedes continuar desde ese estado inicial y ejecutar la auditoría respetando el preflight y las gates.

Composición dinámica de equipo

Antes de lanzar la auditoría, lee ${CLAUDE_PLUGIN_ROOT}/commands/_composicion.md. Si CLAUDE_PLUGIN_ROOT no está, busca commands/_composicion.md en la instalación del plugin.

Después, sigue el protocolo de composición dinámica (pasos 1 a 4). Si por cualquier motivo no consigues localizar ese fichero, NO bloquees /alfred-dev:audit solo por esa búsqueda: continúa con el equipo de núcleo por defecto (qa-engineer, security-officer, architect, tech-writer) y deja constancia breve de la degradación.

Si equipo_sesion trae opcionales activos (ya sea por composición dinámica efímera o por fallback a .claude/alfred-dev.local.md), consúltalo siempre como fuente runtime canónica antes de ejecutar la auditoría. En audit, salvo lucius, el resto de opcionales quedan fuera del loop estándar y deben tratarse explícitamente como “bajo demanda”.

Read the full file on GitHub · 117 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 117 lines · 12 tokens per session scan A 063ccb6d5ba8

Subscribe to this mod's changes

audit is a command published in the GitHub repository 686f6c61/alfred-dev (119 stars, last pushed 18d ago), licensed MIT. It adds 12 tokens to every session and 1,931 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other commands, from other repositories

cdd-pre-pr

Run a pre-PR checklist for the current branch. Compare against the base branch to identify all changes. This is a verification session: it runs CI gates, code-reviews the diff, and reconciles documentation against the changes.

drabaioli/cdd · 0 tokens

cdd-retrofit

Install CDD into an existing project, or upgrade a project already running CDD, at the path given as argument: /cdd-retrofit .

drabaioli/cdd · 0 tokens

cdd-process-pr

Address the open PR's review feedback: read the review comments for the current branch, triage them, implement the change-requests (pushing back where warranted), then auto-post in-thread replies and auto-commit + push the result.

drabaioli/cdd · 0 tokens

cdd-merge-base

Integrate the current state of the base branch into the feature branch. Two phases: a dry-run conflict assessment first, then the actual merge with conflict resolution. The approval between the two phases is conditional — the merge runs automatically when the dry run proves the case mechanically trivial (step 4), and…

drabaioli/cdd · 0 tokens

e2e-test

Generate end-to-end tests using Playwright (web) and Detox (mobile). Covers user flows, visual regression, and cross-browser testing. Usage: /e2e-test [flow-name|--all] [--visual].

alphaaiservice/cortex · 46 tokens

init-project

Initialize a new or upgrade existing project with Alpha AI's standard architecture. Supports Python/FastAPI, Node.js/NestJS, Java/Spring Boot. Usage: /init-project [--lang=python|nestjs|springboot] [--with-frontend] [--with-mobile] [--with-ai] [--existing].

alphaaiservice/cortex · 71 tokens