Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/insight-services-apac/ingenious/auditgit clone --depth 1 https://github.com/Insight-Services-APAC/ingeniousWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/insight-services-apac/ingenious/audit)<a href="https://agentmods.dev/commands/insight-services-apac/ingenious/audit"><img src="https://agentmods.dev/badge/commands/insight-services-apac/ingenious/audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00520 |
| Opus 5 | $0.00000 | $0.00260 |
| Sonnet 5 | $0.00000 | $0.00104 |
| Haiku 4.5 | $0.00000 | $0.00052 |
Grade A, and why
audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 84 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Security Hardening Using ESLint Security Plugins
Use ESLint security plugins and npm audit to detect common JavaScript/TypeScript security issues.
1. Run Security Scans
# Check for vulnerable dependencies
npm audit
# Run ESLint with security rules (if configured)
npx eslint --ext .js,.ts,.vue . --rule 'no-eval: error'
For comprehensive security scanning:
npm audit --audit-level=moderate
2. Install Security Plugins (if missing)
npm install -D eslint-plugin-security @typescript-eslint/eslint-plugin
Add to .eslintrc.js:
{
plugins: ['security'],
extends: ['plugin:security/recommended-legacy']
}
3. Common Security Issues
- detect-object-injection - Bracket notation with user input
- detect-non-literal-fs-filename - Dynamic file paths
- detect-non-literal-regexp - User input in regex
- detect-eval-with-expression - eval() with variables
- detect-no-csrf-before-method-override - CSRF vulnerabilities
- detect-possible-timing-attacks - String comparison timing attacks
4. Fix Patterns
Common issues and actions:
eval()/new Function()-> Use safe alternatives, JSON.parse for datainnerHTML/dangerouslySetInnerHTML-> Use textContent or sanitize- Dynamic
require()-> Use static imports - Unvalidated redirects -> Whitelist allowed URLs
- SQL/NoSQL injection -> Use parameterized queries
- Prototype pollution -> Freeze objects, use Object.create(null)
5. Fix Incrementally
For each finding:
npm test
npx eslint <affected_files>
Commit if clean:
git add <files>
git commit -m "security(eslint): mitigate <issue> in <file>"
6. Suppressing False Positives
Use eslint-disable comments sparingly:
// eslint-disable-next-line security/detect-object-injection -- key is validated enum
const value = obj[validatedKey];
7. Final Quality Gate
npm audit --audit-level=high
npx eslint . --ext .js,.ts,.vue
npm test
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 84 lines · 0 tokens per session scan A ddc04d63bb7d
audit is a command published in the GitHub repository Insight-Services-APAC/ingenious (24 stars, last pushed 7mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 520 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-04.
Other commands, from other repositories
akb-production-review
Review AKB production-governance docs and hooks.
b00t
Show b00t hive status — git, zellij, governance gates, cake balance, open issues.
requirement-review
需求文档多角色评审(requirement-review):需求文档 → 7-Agent 并行评审 → 重构高质量需求文档(Runtime 受控流程,0-7 阶段状态机).
wish-review
description: Execute an end-to-end review loop for a wish, combining test execution, Death Testament aggregation, and scoring.
review
Review a change against the repository's rule-driven modern C++ contract.
add-charts
Integrate Chart.js or Recharts for data visualization. Create reusable chart components: line, bar, pie, area, scatter. Implement responsive sizing with container-based dimensions. Add interactive tooltips showing detailed data on hover. Create customizable legends with click-to-hide series. Support real-time data…