Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/justinjdev/fellowship/audit-plugingit clone --depth 1 https://github.com/justinjdev/fellowshipWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00017 | $0.00624 |
| Opus 5 | $0.00009 | $0.00312 |
| Sonnet 5 | $0.00003 | $0.00125 |
| Haiku 4.5 | $0.00002 | $0.00062 |
Grade A, and why
audit-plugin scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 85 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Audit Plugin
Checks plugin structure against best practices. Run during development to catch issues before release.
Step 1: Collect Files
Gather all plugin files:
- Skills:
plugin/skills/*/SKILL.md - Commands:
plugin/commands/*.md - Agents:
plugin/agents/*.md
Step 2: Line Count Check
For each SKILL.md and command file, count lines. Flag any file over 500 lines with a warning:
⚠ plugin/skills/quest/SKILL.md — 313 lines (limit: 500)
Only flag files that exceed the limit. For files that pass, no output needed.
Why 500: Skill content loads fully on invocation. Large skills bloat context and should extract detailed content into supporting files (resources/, reference files) that load on-demand.
Step 3: Frontmatter Validation
For each file, verify YAML frontmatter:
Skills (SKILL.md):
- Must have
namefield matching the directory name - Must have
descriptionfield - Flag if
namedoesn't match directory (e.g.,plugin/skills/missive/SKILL.mdshould havename: missive)
Commands:
- Must have
descriptionfield - Must NOT have
namefield (commands use filename, not frontmatter name)
Agents:
- No frontmatter requirements (they use a different format)
Step 4: Name Collision Check
Check skill and command names against Claude Code built-in commands. Flag any collisions:
Built-in names to check against: help, clear, config, status, login, logout, init, doctor, listen, review, compact, cost, memory, permissions, mcp, bug, terminal-setup, fast, slow, model, vim, hooks, install-github-app
✗ plugin/skills/config/SKILL.md — "config" collides with Claude Code built-in
Step 5: Validate Docs
Invoke the validate-docs skill using the Skill tool. Include its output in the final report below.
Step 6: Report
Summarize results:
Plugin Lint Results
Skills: 9 checked
Commands: 6 checked
Agents: 3 checked
✓ All checks passed
Or if issues were found:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 85 lines · 17 tokens per session scan A e4266bc0ae81
audit-plugin is a command published in the GitHub repository justinjdev/fellowship (5 stars, last pushed 18d ago), licensed Apache-2.0. It adds 17 tokens to every session and 624 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
auto-mode
Idea-to-running-code lifecycle orchestration. 10-phase pipeline with 5 hard decision gates, wave-based parallelism, and STATE.json resumability. Composes /deep-research, /auto-swarm-nth, /production-upgrade, /security-audit, and /ship into a single end-to-end flow.
max-research
Nuclear-scale autonomous research — deploys 500-1000 agents in ONE massive simultaneous wave for exhaustive topic saturation. Deep-research methodology × auto-swarm scale = maximum parallel intelligence. WARNING: Extreme resource consumption.
omni-plan
ProductionOS flagship — 13-step orchestrative pipeline with tri-tiered evaluation, recursive convergence, CEO/Eng/Design review chain, CLEAR framework evaluation, multi-model judge tribunal, and autonomous PIVOT/REFINE/PROCEED decisions. Targets 100% production-ready output.
auto-swarm-nth
Nth-iteration agent swarm — spawns parallel agent waves, evaluates strictly per wave, re-swarms gaps until 100% coverage and 10/10 quality. Can invoke any ProductionOS skill or command within waves.
frontend-upgrade
Full-stack frontend upgrade pipeline — fuses /production-upgrade iterative audit with /plan-ceo-review vision and /plan-eng-review rigor. Deploys parallel auto-swarm agents for iterative audit and execution. Enriched with /deep-research for competitive parity.
omni-plan-nth
Nth-iteration omni-plan — recursive orchestration that chains ALL ProductionOS skills and agents, evaluates strictly per iteration, and loops until 10/10 is achieved. Each iteration can invoke any command or skill in the system.