Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/ferroxlabs/ijfw/cross-auditgit clone --depth 1 https://github.com/FerroxLabs/ijfwWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/ferroxlabs/ijfw/cross-audit)<a href="https://agentmods.dev/commands/ferroxlabs/ijfw/cross-audit"><img src="https://agentmods.dev/badge/commands/ferroxlabs/ijfw/cross-audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00055 | $0.02819 |
| Opus 5 | $0.00028 | $0.01409 |
| Sonnet 5 | $0.00011 | $0.00564 |
| Haiku 4.5 | $0.00006 | $0.00282 |
Grade A, and why
cross-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 246 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Structured peer review from a different agent. Solves "don't trust a single model." Works by preparing a prompt for you to paste into another CLI tab, then comparing their response against our own findings.
Subcommands
| Form | Behavior |
|---|---|
/cross-audit |
Zero-arg auto-pick. Detect target from git state (staged → unstaged → last commit). Pick default auditor (first non-self). Generate request. |
/cross-audit <target> |
Pick default auditor (first non-self). Generate request for the named target. |
/cross-audit --with <id> [target] |
Force a specific auditor: codex, gemini, opencode, aider, copilot, claude. Target optional (auto-detect if omitted). |
/cross-audit list |
Show the roster with self marker. No request generated. |
/cross-audit compare |
Read .ijfw/cross-audit/response.md, render agreement/new/disputed table, archive. |
Smart target auto-detection (bare /cross-audit)
When invoked without a target, run this detection cascade and use the first non-empty result as the target:
- Staged changes --
git diff --cached --name-only(the user is mid-commit) - Unstaged changes --
git diff --name-only - Last commit --
git diff HEAD~1 --name-only - If all empty: print the roster and ask "what would you like audited?" -- don't guess at random files.
Tell the user which step succeeded:
Cross-audit target auto-detected: 3 staged file(s)
installer/src/install.js
installer/src/marketplace.js
installer/test.js
(Override with /cross-audit <path> or /cross-audit --with <id> <path>.)
If >5 files match, group them in the request body but list all paths so the auditor can scope themselves. If a single huge file (>2000 lines), include only the diff hunks not the full file, to stay under typical context windows.
The natural-language phrase "cross audit this" / "second opinion"
fires the intent router (see mcp-server/src/intent-router.js) which
nudges Claude to invoke /cross-audit automatically -- same auto-detect
flow runs.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 246 lines · 55 tokens per session scan A 53eae290c196
cross-audit is a command published in the GitHub repository FerroxLabs/ijfw (210 stars, last pushed 10d ago), licensed MIT. It adds 55 tokens to every session and 2,819 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
constitution
根据交互输入或已提供原则创建或更新项目章程,并确保相关模板保持同步。.
meta-theory-verify
Run the appropriate MetaKim verification path.
core-review
Review code changes against SpecOps project-specific patterns. Catches recurring failure modes from real PRs — tool abstraction violations, generated file drift, cross-platform gaps, variable inconsistencies, and more. Complements full-review-gate (generic quality) and pr-fix (applying bot comments).
resolve-conflicts
Resolve merge conflicts on a GitHub PR by merging the base branch into the PR branch in an isolated git worktree, with JSON/markdown-aware conflict resolution.
ship-pr
Commit all changes to a new branch, push, and open a PR for review. The original branch stays clean.
implement
Execute implementation by processing atomic task files one at a time with Context Pinning (Atomic Traceability Model).