Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/adaptico/adaptico-osnpx agentmods add skills/adaptico/adaptico-os/gtm-auditWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/adaptico/adaptico-os/gtm-audit)<a href="https://agentmods.dev/skills/adaptico/adaptico-os/gtm-audit"><img src="https://agentmods.dev/badge/skills/adaptico/adaptico-os/gtm-audit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/adaptico/adaptico-os/gtm-audit"><img src="https://agentmods.dev/badge/skills/adaptico/adaptico-os/gtm-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Data Exfiltration · line 485 Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.Fix: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00115 | $0.09900 |
| Opus 5 | $0.00057 | $0.04950 |
| Sonnet 5 | $0.00023 | $0.01980 |
| Haiku 4.5 | $0.00012 | $0.00990 |
Grade A, and why
gtm-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 549 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Marketing Audit Orchestrator
Default lens: a SaaS / AI software startup. Advise a technical founder marketing their own modern software product (SaaS, AI/API, dev tool, or app). Tailor every recommendation to that reader.
Stage-fit (
audit): Tier 1 Core · Tier 2 Core · Tier 3 Core. Appropriate at every served tier - generate with no stage note.
Full persona and general guidance: read
../gtm/templates/advisor-prompt.md(installed with the gtm orchestrator); if the file is absent, continue with the default lens above.
Bundled scripts: the
node .claude/skills/...commands below assume the per-project copy path. When that path doesn't exist (a plugin install, or another agent's skills directory), the scripts sit beside this skill - resolve each path relative to this skill's own folder before running.
You are the full marketing audit engine for /gtm audit <target>. You launch the audit subagents whose signals exist on this site, validate their outputs, and produce a unified, date-stamped report (YYYY-MM-DD-gtm-audit.md). When a previous audit exists, what changed since it is the headline - score movement per vector, fixed items, regressions - before the full report.
Three promises define this skill:
- Provenance - the audit never invents or estimates a metric. Every number traces to the fetched pages, the page-analyzer output, the profile/log, or a named published benchmark; anything unknowable from those sources is listed as a named gap, not guessed.
- Honest cadence - re-audit monthly or quarterly to measure strategy movement (positioning, channel, revenue quality shift over weeks, not days); re-run weekly only to verify that a batch of shipped fixes moved its vector. Don't sell daily re-runs; scores that jitter without underlying change teach the founder to ignore them.
- Quiet terminal - the terminal carries progress lines and the final condensed summary only. Full analyzer JSON goes to
--outfiles (1.1b), agent outputs go to temp files (2.1), and the report body exists only in the saved file. Never print any of these payloads to the terminal - when a field is needed from a JSON artifact, extract that field from the file instead of dumping the object.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 549 lines · 115 tokens per session scan A 74e9ce397993
gtm-audit is a skill published in the GitHub repository adaptico/adaptico-os (18 stars, last pushed 22d ago), licensed MIT. It adds 115 tokens to every session and 9,900 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
audit
Analyze whether TikTok or Instagram search traffic is a viable growth channel for your business. Uses ScaleBrick's framework to evaluate demand, competition, content fit, and intent categories. Ends with a go/no-go recommendation.
competitors
Audit competitors using ScaleBrick's 3-surface framework (social, web/pages, SEO). Categorizes their pricing, features, and landing pages. Identifies gaps you can exploit, positioning angles no one is claiming, and specific moves you can make this week.
strategy
Generate a full marketing strategy using ScaleBrick's "TikTok as Search Engine" framework. Produces themes, pillars, voice, keyword plan, and posting schedule specific enough to execute on day one.
keywords
Research high-intent TikTok and Instagram search keywords using ScaleBrick's framework. Returns categorized keywords with intent type, search volume estimate, difficulty score, and content angle for each.
ads-audit
Run a source-grounded paid-advertising audit for one or more of Google, Meta, YouTube, LinkedIn, TikTok, Microsoft, Apple, Amazon, Reddit, Pinterest, Snapchat, and X. Use for full ad checks, account health reviews, paid-media diagnostics, partial audits after authentication or worker failure, missing-platform…
ads-landing
Audit paid-ad landing pages for message match, mobile experience, performance, accessibility, trust, forms, consent, tracking, security, and conversion friction. Use for landing-page audit, post-click experience, LP audit, conversion-rate optimization, form optimization, ad-to-page message match, redirects, blocked…