Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/frankxai/Starlight-Intelligence-SystemWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/frankxai/starlight-intelligence-system/openclaw-audit)<a href="https://agentmods.dev/commands/frankxai/starlight-intelligence-system/openclaw-audit"><img src="https://agentmods.dev/badge/commands/frankxai/starlight-intelligence-system/openclaw-audit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/frankxai/starlight-intelligence-system/openclaw-audit"><img src="https://agentmods.dev/badge/commands/frankxai/starlight-intelligence-system/openclaw-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00044 | $0.00742 |
| Opus 5 | $0.00022 | $0.00371 |
| Sonnet 5 | $0.00009 | $0.00148 |
| Haiku 4.5 | $0.00004 | $0.00074 |
Grade A, and why
openclaw-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 82 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/openclaw-audit
Load SIP.md (especially Layer 5 sovereignty clause and Layer 2 attestation).
Positioning: Layer 4 sovereign command. Owned by the protocol-defender node (an OpenClaw adopter; identity in the private alliance register). Other nodes may run it; rulings on open-vs-closed and attestation format require the protocol-defender's sign-off by domain.
Target
$ARGUMENTS
Process
-
Classify. Code / spec / canon / artifact / release. Different class → different lens.
-
Trust boundary map. Every boundary the target crosses: node → node, open → closed, public → private, trusted → untrusted. For each: what assumption guards it?
-
Leak surface. What would a motivated adversary learn at each boundary? Name the three worst disclosures.
-
Attestation gaps. Is the target carrying signed provenance? SBOM? SIP attestation? Commit signing? Hash? Name what must be added.
-
Open vs closed ruling. Per SIP § 5 and the license rules in
SIP.md, issue one of:OPEN— MIT / CC-BY-SA / CC-BY-NC per file type.CLOSED— retained under vertical owner (Arcanea BV / sovereign / etc).GATED— open with named auth mechanism.
-
Defects. Rank CRITICAL / HIGH / MEDIUM / LOW. Each has an owner node and a remediation artifact.
-
Ship recommendation.
SHIP/SHIP-WITH-REMEDIATION/HOLD.
Output shape
# OpenClaw Audit — <target>
**Class:** code | spec | canon | artifact | release
**Target pin:** <sha or version>
## Trust boundaries
- <boundary> · guard: <assumption> · verified: yes/no
- …
## Leak surface (top 3)
1. <disclosure + where it bites>
2. …
3. …
## Attestation gaps
- <gap> → <required addition>
- …
## Open / closed ruling
**Decision:** OPEN | CLOSED | GATED
**Rationale:** <one sentence>
**Gate mechanism (if GATED):** <named>
## Defects
| Severity | Defect | Owner | Remediation artifact |
|----------|--------|-------|----------------------|
| CRITICAL | | | |
| HIGH | | | |
| … | | | |
## Ship recommendation
SHIP | SHIP-WITH-REMEDIATION | HOLD
---
**Built on SIP** · OpenClaw Audit · <date>
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 82 lines · 44 tokens per session scan A 19554e1d25f9
openclaw-audit is a command published in the GitHub repository frankxai/Starlight-Intelligence-System (8 stars, last pushed today), licensed MIT. It adds 44 tokens to every session and 742 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
memories
View and manage learned memories.
mpm-session-resume
Load context from paused session.
forget
Delete specific memories.
learn
Add new learning to memory.
gbu-retro
Post-session retrospective — harvest this session's lessons into durable doctrine.
consolidate
Write a compact checkpoint summary of the current frontier.