audit

A command that performs a focused security review of a specific function or module. It traces how an attack could reach the code and produces a report with risks and recommendations.

In plain words
What is it for?
It is for auditing named functions or modules, searching for matching functions, tracing calls, assessing vulnerability risk, and optionally producing a Mermaid call-graph diagram.
Why use it?
It helps uncover security weaknesses in code paths that a general code review may overlook, including unsafe input handling and reachable attack routes.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/marcosd4h/deepextractruntime/audit
Clone the repo
git clone --depth 1 https://github.com/marcosd4h/DeepExtractRuntime
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 9,270 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.09270
Opus 5 $0.00000 $0.04635
Sonnet 5 $0.00000 $0.01854
Haiku 4.5 $0.00000 $0.00927

Measured 2d ago against content hash 5e8481cf12a1, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

commands/audit.md · 607 lines

How it starts

The opening of the file, as written. The whole thing — 607 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Security Audit

Overview

Perform a focused security audit of a specific function -- building a comprehensive security dossier, tracing attack reachability, and reporting findings with risk assessment and recommendations.

The text after /audit specifies the function name and optionally the module:

  • /audit AiCheckSecureApplicationDirectory -- searches all modules
  • /audit appinfo.dll AiCheckSecureApplicationDirectory -- targets specific module
  • /audit appinfo.dll --search CheckSecurity -- pattern search
  • /audit appinfo.dll AiLaunchProcess --diagram -- include Mermaid call graph diagram

If no function is specified, ask the user.

IMPORTANT: Execution Model

This is an execute-immediately command. Do NOT present anything for user confirmation Run and write the final audit report straight to the chat as your response. The user expects to see the completed report.

Workspace Protocol

Before running the multi-skill audit pipeline:

  1. Create a run directory under .claude/workspace/ (for example, .claude/workspace/<module>_audit_<function>_<timestamp>/).
  2. Run every skill script with:
    • --workspace-dir <run_dir>
    • --workspace-step <step_name>
  3. Keep only compact summaries in context/chat output.
  4. Read full details only on demand from:
    • <run_dir>/<step_name>/results.json
    • <run_dir>/<step_name>/summary.json
  5. Use <run_dir>/manifest.json as the source of truth for completed steps.
  6. Staleness check (when reusing an existing workspace): If a workspace directory already exists and manifest.json shows all steps with status: success, check freshness before reusing results:
    • Read manifest.json created_at timestamp.
    • Compare against the analysis DB file modification time (mtime of the .db file resolved in Step 0).
    • If the DB mtime is newer than manifest.created_at, warn the user: "Workspace was created before the current DB was last modified. Results may be outdated. Re-run with --no-cache to regenerate all steps." Then proceed with the stale results unless the user explicitly requests regeneration.
    • If the workspace is older than 24 hours (regardless of DB age), emit an informational note at the start of the report: "Note: Workspace is N hours old. Results may be stale if the extraction has been re-run since creation."
    • These are warnings only — do not block execution. The user decides whether to re-run.

Read the full file on GitHub · 607 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 607 lines · 0 tokens per session scan A 5e8481cf12a1

Subscribe to this mod's changes

audit is a command published in the GitHub repository marcosd4h/DeepExtractRuntime (20 stars, last pushed 3mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 9,270 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.