Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/yeaight7/agent-powerups/security-auditgit clone --depth 1 https://github.com/yeaight7/agent-powerupsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/yeaight7/agent-powerups/security-audit)<a href="https://agentmods.dev/commands/yeaight7/agent-powerups/security-audit"><img src="https://agentmods.dev/badge/commands/yeaight7/agent-powerups/security-audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00022 | $0.00488 |
| Opus 5 | $0.00011 | $0.00244 |
| Sonnet 5 | $0.00004 | $0.00098 |
| Haiku 4.5 | $0.00002 | $0.00049 |
Grade A, and why
security-audit scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads MCP configurationlowAgent snooping
mcp.json carries server URLs and auth tokens; reading it lets a mod discover and abuse other integrations.
| `.mcp.json` | Hardcoded secrets, unpinned `npx -y`, missing descriptions | Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
What it actually says
/security-audit — Agent Config Security Audit
Scan agent configuration files for security issues. Run before committing config changes.
Usage
/security-audit [path|.] [--min-severity p0|p1|note]
- Default target: current directory (
.) --min-severity: filter output to findings at or above this level
Scope
Scan every config file found under the target path:
| File | What to check |
|---|---|
.claude/settings.json |
Wildcard allow lists, missing deny lists |
.mcp.json |
Hardcoded secrets, unpinned npx -y, missing descriptions |
.codex/config.toml |
Same as MCP checks for Codex config |
AGENTS.md, CLAUDE.md |
Auto-run instructions, prompt injection patterns, missing prohibitions |
hooks/ |
Command injection via interpolation, outbound network calls, silent error suppression |
plugins/*/plugin.json |
Overly broad tool grants |
.apx/relay/ |
Secrets in relay artifact files |
Classification
| Level | Definition |
|---|---|
| P0 | Direct security risk or secret leak — fix before any commit |
| P1 | Weakened safety controls or increased attack surface — fix before merging |
| Note | Best practice gap with no direct risk — log and fix in follow-up |
Required Output
Security Audit — <path>
P0:
[P0] <file>:<location> — <description>
Fix: <instruction>
P1:
[P1] <file>:<location> — <description>
Fix: <instruction>
Notes:
[Note] <file> — <description>
Summary: <N> P0, <N> P1, <N> Notes
If no findings, state No findings. explicitly — do not omit the summary line.
Arguments
$ARGUMENTS:
[path|.]— target path (default:.)--min-severity p0|p1|note— minimum severity to include in output
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 64 lines · 22 tokens per session scan A 926698bc80d9
security-audit is a command published in the GitHub repository yeaight7/agent-powerups (6 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 22 tokens to every session and 488 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (reads mcp configuration). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
t800-bootstrap
Запускайте один раз при установке плагина или для новичка в чате.
validate-pipeline
Validate data pipeline configuration and data quality rules.
advisor
Get a second opinion from Codex (GPT-5) on your current plan, diff, or a specific question.
aidd-churn
Rank files by hotspot score to identify prime candidates for refactoring before PR review.
pn-audit-security
OWASP-guided security review — auth posture, input validation, secrets, CORS, JWT, rate limiting. Surgical command for backend security. Use standalone or as part of pn-backend-audit.
pn-distill
Remove content, sections, and features that don't earn their place — information architecture reduction. Use when there's too much stuff on the page. For visual decoration reduction, use pn-quieter.