trudi-check-alerts

trudi-check-alerts is a command for Claude Code from nebulae/trudi. It costs 17 tokens per session (3,091 once invoked), scanned A, original, MIT.

A command that checks a TRUDI live-monitoring case for new alerts and investigates each group of alerts found during a polling cycle. TRUDI appears to be a monitoring system, but the input does not explain what it monitors.

In plain words
What is it for?
Use it in a repeating loop to poll a case, group alerts by cycle, and record the investigation traces and alert acknowledgements.
Why use it?
It removes the need to watch for alerts and start investigations manually at fixed intervals.

Command for Claude Code

Written for Claude Code: argument-hint in frontmatter.

Good fit Use it in a repeating loop to poll a case, group alerts by cycle, and record the investigation traces and alert acknowledgements.

Compare 6 commands from other repositories ↓
Install with agentmods
npx agentmods add commands/nebulae/trudi/trudi-check-alerts
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/nebulae/trudi

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for trudi-check-alerts

README.md
[![agentmods](https://agentmods.dev/badge/commands/nebulae/trudi/trudi-check-alerts/github.svg)](https://agentmods.dev/commands/nebulae/trudi/trudi-check-alerts)
Your own site
<a href="https://agentmods.dev/commands/nebulae/trudi/trudi-check-alerts"><img src="https://agentmods.dev/badge/commands/nebulae/trudi/trudi-check-alerts/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for trudi-check-alerts

Your own site · 80×15
<a href="https://agentmods.dev/commands/nebulae/trudi/trudi-check-alerts"><img src="https://agentmods.dev/badge/commands/nebulae/trudi/trudi-check-alerts.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 17 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 3,091 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00017 $0.03091
Opus 5 $0.00009 $0.01545
Sonnet 5 $0.00003 $0.00618
Haiku 4.5 $0.00002 $0.00309

Measured 11d ago against content hash adf80370775c, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

trudi-check-alerts scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

claude/commands/trudi-check-alerts.md · 277 lines

How it starts

The opening of the file, as written. The whole thing — 277 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/trudi-check-alerts

Polls the active TRUDI live-monitoring case for new alerts and runs one investigation per /loop tick over the entire bundle of alerts drained in that tick. Designed to be called on a fixed interval via /loop 15s /trudi-check-alerts so anomalies are investigated within ~30s of firing on the victim host.

The argument, if supplied, names the case. Otherwise read it from ~/cases/.common/active_case.

Trace routing contract — read first

Live-monitoring cases use per-investigation traces. Each /trudi-check-alerts tick that finds alerts opens (or resumes) ONE investigation, identified by an INV-NNN id. Its trace lives at <case>/analysis/<case>_<INV-NNN>_trace.json — flat under analysis/ so the dashboard scan picks it up. All alerts drained in that tick share that single trace.

The case-wide trace at <case>/analysis/<case>_trace.json records orchestration only: monitor.list_watchers, monitor.check_alerts, monitor.next_investigation_id, monitor.open_investigation_state, monitor.start_investigation / extend_investigation / end_investigation markers, monitor.ack_alert, and any operator messages typed outside an open investigation.

The switch happens via monitor.start_investigation and monitor.end_investigation. Do not call misc.start_execution_log during this workflow — those helpers manage the trace path.

Operator-typed messages follow the same routing automatically: the UserPromptSubmit hook reads ~/.cache/trudi/session.json (which log.configure() updates whenever the trace flips) and appends the typed prompt to whichever trace is currently active. That's how approve ACT-N lands in the per-investigation trace and how the operator_text_required gate finds it.

If response actions are pending operator approval at end of tick, the investigation stays open across ticks — _open_investigation.json holds the state, and the next tick rehydrates the same trace via start_investigation (it's idempotent).

Read the full file on GitHub · 277 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 277 lines · 17 tokens per session scan A adf80370775c

Subscribe to this mod's changes

trudi-check-alerts is a command published in the GitHub repository nebulae/trudi (58 stars, last pushed 10d ago), licensed MIT. It adds 17 tokens to every session and 3,091 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.