audit

A broad review process for an llm-wiki knowledge base. It checks wiki maintenance, differences in generated output, source history, and whether new research is needed.

In plain words
What is it for?
Use it to review an active wiki, check its sources and outputs, maintain its contents, and research uncertain topics.
Why use it?
It helps find outdated, inconsistent, or weakly supported information before you rely on it. It also gives one place to investigate when the wiki cannot be trusted.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/nvk/llm-wiki/audit
Clone the repo
git clone --depth 1 https://github.com/nvk/llm-wiki
Per session 33 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,165 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00033 $0.02165
Opus 5 $0.00016 $0.01082
Sonnet 5 $0.00007 $0.00433
Haiku 4.5 $0.00003 $0.00216

Measured 3d ago against content hash 2dfdb3401fa3, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

claude-plugin/commands/audit.md · 170 lines

How it starts

The opening of the file, as written. The whole thing — 170 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Your task

Resolve the wiki. Do NOT search the filesystem or read reference files until the wiki location is known — follow these steps:

  1. Read $HOME/.config/llm-wiki/config.json. If it has hub_path, expand leading ~ only (not tildes in com~apple~CloudDocs) and prefer that path; use resolved_path only as a fallback cache when the expanded hub_path is unavailable and resolved_path is initialized. If config has only resolved_path, use it. If the configured path can be statted but reading wikis.json or listing topics/ fails with Operation not permitted, stop and ask the user to grant Full Disk Access/iCloud Drive access to the launcher; do not fall back to ~/wiki or resolved_path. Do not write machine-specific resolved_path into shared configs.
  2. If no config -> read $HOME/wiki/_index.md. If it exists -> HUB = $HOME/wiki. If nothing found, ask the user where to create the wiki.
  3. Wiki location (first match): --local -> .wiki/ in CWD; --wiki <name> -> HUB/wikis.json lookup with portable path resolution (<HUB>, ~, absolute, or HUB-relative); if the registry path is stale, fall back to HUB/topics/<name>; CWD has .wiki/ -> use it; else -> HUB.
  4. Read <wiki>/_index.md to verify. If missing -> stop with "No wiki found. Run /wiki init first."

Read the audit reference at skills/wiki-manager/references/audit.md. If you need a fresh wiki-only pass, also read commands/librarian.md and reuse its scan protocol rather than inventing a parallel one.

Inventory awareness: audit findings that require future action should be offered as inventory candidates, not only buried in .audit/REPORT.md. Examples include blocked verification work, stale source queues, watch items, and important missing corpora. Show a small sample before creating more than a few records, and never treat inventory records as evidence for factual verdicts.

Parse $ARGUMENTS

Default subcommand is scan.

  • scan: Run the umbrella trust audit
  • report: Display the latest .audit/REPORT.md

Read the full file on GitHub · 170 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 170 lines · 33 tokens per session scan A 2dfdb3401fa3

Subscribe to this mod's changes

audit is a command published in the GitHub repository nvk/llm-wiki (1,175 stars, last pushed 6d ago), licensed MIT. It adds 33 tokens to every session and 2,165 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.