auditing-agent-architecture

auditing-agent-architecture is a skill for Claude Code from atretyak1985/swarmery. It costs 118 tokens per session (1,327 once invoked), scanned A, original, Apache-2.0.

A guide for designing and reviewing Claude-based software agents, including their repeated work loops, hand-offs between agents, tool hooks, task breakdowns, and saved session state. It covers how agents decide when to stop and how they resume work.

In plain words
What is it for?
Use it when building or reviewing agent systems, coordinating multiple agents, invoking subagents, passing context, adding Agent SDK hooks, decomposing tasks, or supporting session resumption.
Why use it?
It helps identify failures such as agents stopping too early, passing incomplete context, repeating work, or enforcing workflows in the wrong place.

Skill for Claude Code

Written for Claude Code: PreToolUse hook event. Also seen: mentions subagents.

Part of the claude-eng-pack plugin — 5 skills shipped together

Good fit Use it when building or reviewing agent systems, coordinating multiple agents, invoking subagents, passing context, adding Agent SDK hooks, decomposing tasks, or supporting session resumption.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/atretyak1985/swarmery/auditing-agent-architecture
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add atretyak1985/swarmery --skill auditing-agent-architecture
Clone the repo
git clone --depth 1 https://github.com/atretyak1985/swarmery

Made for: Claude Code.

Or install claude-eng-pack, the plugin that ships this one along with the rest of its 5 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for auditing-agent-architecture

README.md
[![agentmods](https://agentmods.dev/badge/skills/atretyak1985/swarmery/auditing-agent-architecture/github.svg)](https://agentmods.dev/skills/atretyak1985/swarmery/auditing-agent-architecture)
Your own site
<a href="https://agentmods.dev/skills/atretyak1985/swarmery/auditing-agent-architecture"><img src="https://agentmods.dev/badge/skills/atretyak1985/swarmery/auditing-agent-architecture/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for auditing-agent-architecture

Your own site · 80×15
<a href="https://agentmods.dev/skills/atretyak1985/swarmery/auditing-agent-architecture"><img src="https://agentmods.dev/badge/skills/atretyak1985/swarmery/auditing-agent-architecture.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 118 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,327 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00118 $0.01327
Opus 5 $0.00059 $0.00664
Sonnet 5 $0.00024 $0.00265
Haiku 4.5 $0.00012 $0.00133

Measured 6d ago against content hash 3c1e32408f00, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

auditing-agent-architecture scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/claude-eng-pack/skills/auditing-agent-architecture/SKILL.md · 101 lines

How it starts

The opening of the file, as written. The whole thing — 101 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Auditing Agent Architecture

Overview

Best-practice reference for the architecture layer of Claude-based agents: the execution loop, orchestration topology, subagent contracts, enforcement gates, hooks, decomposition, and session state. Each reference module states the correct pattern, the named anti-patterns, and ends with an Audit Checklist of verifiable conditions.

When to use

  • Reviewing or designing an agent loop, coordinator, or subagent structure
  • Debugging: premature termination, infinite loops, dropped tool results, stalled or repeating agents, coverage gaps between subagents
  • Deciding: prompt guidance vs hard gates, hooks vs prompts, fixed pipeline vs dynamic decomposition

Not for tool schemas or MCP servers (use designing-tools-and-mcp) or context-window degradation (use managing-context-reliability).

Quick reference

Module Read when the question is about
references/1-1-agentic-loops.md Loop lifecycle, stop_reason branching, termination anti-patterns
references/1-2-multi-agent-orchestration.md Hub-and-spoke coordination, context isolation, decomposition coverage gaps
references/1-3-subagent-invocation-and-context-passing.md Task tool, structured metadata handoff, parallel spawning, fork_session
references/1-4-workflow-enforcement-and-handoff.md Prompt guidance vs programmatic gates, prerequisite gates, handoff protocols
references/1-5-agent-sdk-hooks.md PreToolUse/PostToolUse policy enforcement, hooks vs prompt instructions
references/1-6-task-decomposition-strategies.md Fixed sequential vs dynamic decomposition, attention dilution
references/1-7-session-state-and-resumption.md Session persistence, stale context, targeted re-analysis

How to audit

  1. Match the system under review to modules in the table; read those files.
  2. Run each module's Audit Checklist item by item against the actual code/config.
  3. Report every unchecked item as a finding with file:line evidence and the module's recommended fix.

Read the full file on GitHub · 101 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago Changed · +32 tokens per session 3c1e32408f00
  2. 11d ago First seen · 101 lines · 86 tokens per session scan A b0290afd5a66

Subscribe to this mod's changes

auditing-agent-architecture is a skill published in the GitHub repository atretyak1985/swarmery (5 stars, last pushed yesterday), licensed Apache-2.0. It adds 118 tokens to every session and 1,327 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

notebooklm

Programmatic access to Google NotebookLM for creating notebooks, adding sources (URLs, YouTube, PDFs, audio, video, images), chatting with content, generating artifacts (podcasts, videos, reports, quizzes, mind maps, flashcards, infographics), and downloading results. Includes capabilities beyond the web UI.

jmagar/claude-homelab · 67 tokens

gh-address-comments

This skill should be used when addressing GitHub pull request review comments systematically with mandatory resolution tracking. Use when user says "address PR comments", "fix review feedback", "handle PR review", "resolve PR threads", or needs to ensure all review comments are addressed before merging. Fetches…

jmagar/claude-homelab · 85 tokens

prowlarr

Search indexers and manage Prowlarr. Use when the user asks to "search for a torrent", "search indexers", "find a release", "check indexer status", "list indexers", "prowlarr search", "sync indexers", or mentions Prowlarr/indexer management.

jmagar/claude-homelab · 68 tokens

sonarr

This skill should be used when managing TV shows in Sonarr. Use when the user asks to "add a TV show", "search Sonarr", "find a series", "add to Sonarr", "remove a show", "check if show exists", "Sonarr library", "TVDB lookup", or mentions TV show management or Sonarr operations.

jmagar/claude-homelab · 75 tokens

commit-message

Use ANY time the user signals they want to commit staged changes — including bare "commit", "/commit", "commit this", "commit these changes", "let's commit", "make a commit", "git commit", "write a commit message", "make a conventional commit", "use conventional commits", or any equivalent phrasing in context (e.g.…

netopsengineer/axiom · 218 tokens

dependency-versions

MUST consult this skill before answering whenever the user's task involves external versioned dependencies — even if you think you can handle it directly. This applies to: checking if packages/tools are up to date, upgrading npm/pip/cargo/go dependencies, planning or writing CI/CD workflows (GitHub Actions, CircleCI…

netopsengineer/axiom · 216 tokens