Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/alifanov/darkflow/docs-auditgit clone --depth 1 https://github.com/alifanov/darkflowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00018 | $0.01506 |
| Opus 5 | $0.00009 | $0.00753 |
| Sonnet 5 | $0.00004 | $0.00301 |
| Haiku 4.5 | $0.00002 | $0.00151 |
Grade A, and why
docs-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 129 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Audit the docs/ knowledge base against the actual code and recent history — find drift between what the docs claim and what the code does — then create tasks for each significant mismatch.
This is a verification check: it answers "are the docs still true?" It does not rewrite docs (that is a human/fix-issues decision) and it does not produce a product narrative (that is /darkflow:product-overview).
Step 1 — Read project config
Load the project config (contract in .darkflow.d/claude.md → Project config). Uses: language.
Step 2 — Audit docs against code
Read docs/README.md and docs/agent-workflow.md first to learn the layer map, then check each layer against reality. Skip files that are missing or still placeholder stubs — note them as "not yet written", not as drift.
Check, layer by layer:
state/spec/data-model.mdvs the real schema — compare the documented data model against the ORM schema (prisma/schema.prisma,models.py, migrations, etc.). Flag entities/fields/relations that exist in code but not in docs, or vice versa.state/spec/screens.mdvs routes/pages — compare the documented screen list against actual routes/pages/views in the code. Flag screens added or removed in code but not reflected.state/spec/flows/*.mdvs implemented flows — for documented flows (auth, checkout, onboarding…), check the steps still match the code.state/product/metrics.mdvs instrumented events — compare documented analytics event/metric definitions against event names actually fired in the code. Flag events in code that aren't documented, and documented events with no callsite.state/product/pricing.mdvs billing code/config — if pricing/plans are encoded in code or config, flag mismatches.CLAUDE.md/README.mdcommands — verify documented commands (build, test, dev, lint) exist inpackage.json/Makefile/pyproject.toml.state/arch.md## Decisionsvs current code — flag any recorded decision the code now contradicts and that has no successor line saying it was replaced.README.mdmanifest vs the actual files — compare the file manifest indocs/README.mdagainst what really exists underdocs/. Flag a file that exists on disk but is not listed in the manifest (undocumented doc), and a manifest entry that names a wrong path. Do not flag a manifeston demandentry that simply isn't written yet — that's expected, not drift.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 129 lines · 18 tokens per session scan A e8d4ea894008
docs-audit is a command published in the GitHub repository alifanov/darkflow (2 stars, last pushed 3d ago), licensed MIT. It adds 18 tokens to every session and 1,506 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
loop
Iteratively fix issues until all resolved or max iterations reached.
feature
Create a feature specification using spec-driven development.
quality-gate
Command "quality-gate" from VoDaiLocz/kilo-kit-mcp, covering ✅ quality gate command, workflow, gates, gate 1: pre-execution and gate 2: per-behavior.
memory
Search, store, and manage AI Team Memory — agent expertise, decisions, learnings, and code patterns. File-based by default, with an optional memory MCP overlay.
deep-audit.skeleton
Aciklama: Bu bolum Bootstrap tarafindan manifest verileriyle doldurulur. Gerekli manifest alanlari: project.description, stack.primary, project.structure, project.subprojects, stack.orm, stack.authmethod Ornek cikti.
do-it-retrospective
开关本项目的本地行为反馈记录,或输出已记录问题的去敏复盘报告。参数为 on / off / status / report。.