Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/jezweb/claude-skills/ux-auditgit clone --depth 1 https://github.com/jezweb/claude-skillsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00101 | $0.00358 |
| Opus 5 | $0.00051 | $0.00179 |
| Sonnet 5 | $0.00020 | $0.00072 |
| Haiku 4.5 | $0.00010 | $0.00036 |
Grade A, and why
ux-audit scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Unrestricted tool accesslowExcessive agency
A wildcard tool grant or "run any command" leaves no least-privilege boundary at all.
allowed-tools: "*" Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
What it actually says
Load the ux-audit skill and run the audit.
The audit is interaction-first. It cannot produce a verdict without an Interaction Manifest proving real typing, clicking, sending, observing. A static DOM sweep terminates with verdict Incomplete.
Hard gates (cannot be downgraded): console errors / warnings = 0, network 5xx = 0, layout collapse at any tested viewport = 0. A console warning is High minimum. A 5xx is Critical automatically.
If $ARGUMENTS describes a persona ("as a busy broker", "first-time user"), lock it. If $ARGUMENTS scopes the audit ("the dashboard", "just the settings flow"), scope to that area — still exhaustive within the scope.
URL is auto-detected from wrangler.jsonc or running dev server.
Examples:
/ux-audit/ux-audit as a time-poor client logging in for the first time/ux-audit the billing flow/ux-audit as an SME owner — multi-pane stress focus
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 22 lines · 101 tokens per session scan A 8d8784c8e6c9
ux-audit is a command published in the GitHub repository jezweb/claude-skills (982 stars, last pushed 2mo ago), licensed MIT. It adds 101 tokens to every session and 358 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 1 finding (unrestricted tool access). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
changelog
Generate a new changelog entry by reading all changeset files and creating a properly formatted entry in .changelog/v3.mdx.
release-note-csoar
Automates the creation of Cloud SOAR (Automation Service) release notes for platform updates, integration changes, and bug fixes.
doc
Use this command to create a new feature doc, how-to, concept, reference, or troubleshooting guide — it scaffolds the file, frontmatter, structure, and sidebar entry.
speckit-gaia-plan-close
Close a plan after implementation+merge. Offers wiki-promote for the plan's consolidated SUMMARY.md, cold-consolidates an out-of-band merge, then early-reaps the local plan folder once cost is represented in cost.jsonl.
speckit-gaia-spec-close
Close a SPEC after implementation+merge. Optional drain of deferred wiki-promote, cold-consolidates an out-of-band merge into SUMMARY.md, then early-reaps the local SPEC folder once cost is represented in cost.jsonl.
init
Initialize a project for on-brand Marmo UI generation — detect or interview for brand basics (layout, primary color, fonts, radius, spacing) and write a DESIGN.md if one doesn't exist.