github

A GitHub repository-audit workflow for checking correctness and improving a project's public presentation. GitHub is a service for hosting code, issues, pull requests, and repository information.

In plain words
What is it for?
Use it to verify README content against the code, run documented commands, inspect repository metadata, and turn real unfinished work into GitHub issues.
Why use it?
README claims, command examples, version numbers, and repository metadata can become outdated or misleading. The workflow reports problems before proposing changes and asks for approval before irreversible actions.

Command for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/alinotfoundbtw/sounding/github
Clone the repo
git clone --depth 1 https://github.com/alinotfoundbtw/sounding

Made for: Claude Code.

Per session 16 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 381 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00016 $0.00381
Opus 5 $0.00008 $0.00191
Sonnet 5 $0.00003 $0.00076
Haiku 4.5 $0.00002 $0.00038

Measured yesterday against content hash 44f81401642e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

github scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/commands/github.md · 51 lines

What it actually says

Audit and improve the public presence of this repository. Report everything before changing anything, and stop for confirmation before anything irreversible (see the hard rules in CLAUDE.md).

1. Correctness first

Run /check. If the tree does not pass, nothing about presentation matters yet.

2. Verify every public claim

Read README.md line by line against reality:

  • Test count — run them and compare
  • Rule counts per adapter — count the registries
  • Version numbers in examples
  • Roadmap markers — is "you are here" on the right line
  • Every terminal block — re-run the command and confirm the output still matches

Report each mismatch. Stale numbers in a README are the cheapest possible way to look unmaintained.

3. Repository metadata

Check and propose (do not apply yet):

  • Description — one sentence, states the problem, not "a tool for X"
  • Topics — mcp, ai-agents, security, linter, model-context-protocol
  • Pinned repositories on the profile
  • Social preview image

4. Known gaps become issues

Anything real and unfinished gets an issue rather than silence. Currently:

  • pin / diff supports MCP only — not skills or prompts, though drift matters more for skills
  • The playground's browser rendering has never been exercised by anyone
  • Prompt rules have no eval layer; only skills have routing analysis

Write each as a problem statement, not a feature request. Do not open an issue for something already fixed.

5. Report

Give me a list of what you would change, grouped by whether it needs my approval. Then wait.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 51 lines · 16 tokens per session scan A 44f81401642e

Subscribe to this mod's changes

github is a command published in the GitHub repository alinotfoundbtw/sounding (4 stars, last pushed 6d ago), licensed MIT. It adds 16 tokens to every session and 381 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.