Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/beel-es/claude-plugins/auditarnpx skills add beel-es/claude-plugins --skill auditargit clone --depth 1 https://github.com/beel-es/claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/beel-es/claude-plugins/auditar)<a href="https://agentmods.dev/skills/beel-es/claude-plugins/auditar"><img src="https://agentmods.dev/badge/skills/beel-es/claude-plugins/auditar.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00348 | $0.03965 |
| Opus 5 | $0.00174 | $0.01982 |
| Sonnet 5 | $0.00070 | $0.00793 |
| Haiku 4.5 | $0.00035 | $0.00396 |
Grade A, and why
auditar scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 176 lines — stays where its author put it; the contents beside it link to each section on GitHub.
compliance-es — Motor de cumplimiento (España), multi-marco y self-service
Auditar una aplicación contra uno o varios packs de norma, resolver las decisiones con el criterio
de la norma y generar toda la documentación rellenada (sin dejar tarea), dejando un estado versionado
en el repo que se re-corre en el tiempo. Objetivo: que un founder/autónomo cumpla solo; el abogado es
opcional (ver references/cuando-acudir-a-abogado.md).
DISCLAIMER OBLIGATORIO — No constituye asesoramiento jurídico ni garantiza el cumplimiento de la normativa (un software no asume la responsabilidad legal del usuario; la interpretación de las autoridades y de los tribunales puede diferir, y la norma cambia). Genera borradores fundados en la normativa española y de la UE para cumplir sin abogado; se recomienda que un abogado revise el resultado, especialmente ante alto riesgo, categorías especiales de datos o un procedimiento en curso. Incluir este disclaimer al pie de cada documento legal generado.
Modelo mental
- Controles = unidades reutilizables que satisfacen varios marcos a la vez. Catálogo + crosswalk:
references/controls.md. - Packs = una norma cada uno (
packs/<id>/pack.md): obligaciones, controles que exige y documentos a generar. Hoy:rgpd-lopdgdd,lssi-cookies,compliance-penal,verifactu. Los marcos emergentes sin pack (Data Act, accesibilidad, AI Act, NIS2) se evalúan conreferences/radar-normativo.md. - Estado = el output vive en
<repo>/.compliance/versionado por git. Formato:references/output-model.md. - Fuentes (verdad) = textos OFICIALES (BOE, EUR-Lex, AEPD, AEAT). Extractos literales grepeables en
sources/textos/(offline, con SHA-256 ensources/FUENTES.md) y URLs oficiales para re-verificar online con WebFetch. Toda afirmación legal cita norma + artículo + fuente: grepear el extracto ensources/textos/o abrir la URL; lo no verificable se marca[verificar contra fuente oficial]. NADA inventado. Numeración ya verificada:references/mapa-articulos.md.
What ships with it
45 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- packs/compliance-penal/pack.md 6.0 KB
- packs/compliance-penal/templates/acta-organo-cumplimiento.md 2.0 KB
- packs/compliance-penal/templates/codigo-etico.md 2.5 KB
- packs/compliance-penal/templates/matriz-riesgos-penales.md 2.2 KB
- packs/compliance-penal/templates/politica-canal-denuncias.md 3.2 KB
- packs/compliance-penal/templates/politica-compliance-penal.md 3.6 KB
- packs/lssi-cookies/pack.md 4.8 KB
- packs/lssi-cookies/templates/aviso-legal.md 1.8 KB
- packs/lssi-cookies/templates/politica-cookies.md 2.1 KB
- packs/lssi-cookies/templates/registro-aceptaciones.md 2.1 KB
- packs/lssi-cookies/templates/terminos-contratacion.md 2.4 KB
- packs/rgpd-lopdgdd/pack.md 6.3 KB
- packs/rgpd-lopdgdd/templates/anexo-transferencias.md 2.1 KB
- packs/rgpd-lopdgdd/templates/canal-derechos.md 2.4 KB
- packs/rgpd-lopdgdd/templates/consentimiento.md 2.5 KB
- packs/rgpd-lopdgdd/templates/dpa.md 2.5 KB
- packs/rgpd-lopdgdd/templates/eipd.md 2.7 KB
- packs/rgpd-lopdgdd/templates/plan-respuesta-brechas.md 2.3 KB
- packs/rgpd-lopdgdd/templates/politica-privacidad.md 3.0 KB
- packs/rgpd-lopdgdd/templates/rat.md 1.8 KB
- packs/rgpd-lopdgdd/templates/registro-brechas.md 1.2 KB
- packs/verifactu/pack.md 6.5 KB
- packs/verifactu/templates/checklist.md 2.7 KB
- packs/verifactu/templates/declaracion-responsable.md 1.9 KB
- packs/verifactu/templates/politica-conservacion.md 2.4 KB
- references/build/derechos-y-datos.md 3.6 KB
- references/build/facturacion.md 3.0 KB
- references/build/index.md 1.9 KB
- references/build/monitoreo.md 3.0 KB
- references/build/seguridad.md 3.3 KB
- references/controls.md 8.1 KB
- references/cuando-acudir-a-abogado.md 3.4 KB
- references/instructivo-situaciones.md 4.6 KB
- references/mapa-articulos.md 11 KB
- references/output-model.md 3.1 KB
- references/radar-normativo.md 4.7 KB
- references/revisiones-periodicas.md 4.2 KB
- sources/descargar-fuentes.py 3.4 KB runs code
- sources/FUENTES.md 8.8 KB
- sources/textos/cp-resp-penal-pj.txt 15 KB
- sources/textos/ley-2-2023-canal.txt 9.5 KB
- sources/textos/lgt-facturacion.txt 7.1 KB
- sources/textos/lopdgdd.txt 18 KB
- sources/textos/lssi.txt 25 KB
- sources/textos/rd-1007-2023-verifactu.txt 10.0 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 176 lines · 348 tokens per session scan A b393b840f1ba
auditar is a skill published in the GitHub repository beel-es/claude-plugins (4 stars, last pushed 8d ago), licensed MIT. It adds 348 tokens to every session and 3,965 once invoked, about $0.0017 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
achieving-cmmc-level-2-compliance
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when…
fedramp
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). Use this skill whenever a user asks about FedRAMP authorization, ATO (Authority to Operate), cloud security for federal government, NIST SP 800-53 controls, CSP compliance, or any of the core FedRAMP document…
app-store-preflight-compliance
Pre-submission compliance scanner workflow for Apple App Store apps. Use when reviewing iOS, macOS, tvOS, watchOS, or visionOS projects (Swift, Objective-C, React Native, Expo) for App Store rejection risks, submission readiness, privacy compliance, or guideline violations.
nis2
EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. 21 risk management measures, Art. 23 incident reporting timelines (24h/72h/1 month), Art. 20 governance obligations, supply chain security (Art. 21(2)(d); coordinated risk assessments Art.…
ism
Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. Use for ISM control selection, gap analysis, system authorisation, IRAP assessment preparation, security documentation, and ASD compliance. Triggers on: ISM controls, ASD compliance, IRAP assessment, PROTECTED…
catalyst-center-readonly
Query Cisco Catalyst Center read-only — device inventory, site hierarchy, wireless, assurance health, compliance, software images, events. All 514 read-only API operations reachable through 8 grouped dispatchers. Use when asked what Catalyst Center manages, where a device sits, what its health or compliance state is…