Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add bunhine0452/Ocul-PM --skill self-auditgit clone --depth 1 https://github.com/bunhine0452/Ocul-PMWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/bunhine0452/ocul-pm/self-audit)<a href="https://agentmods.dev/skills/bunhine0452/ocul-pm/self-audit"><img src="https://agentmods.dev/badge/skills/bunhine0452/ocul-pm/self-audit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/bunhine0452/ocul-pm/self-audit"><img src="https://agentmods.dev/badge/skills/bunhine0452/ocul-pm/self-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00039 | $0.00760 |
| Opus 5 | $0.00019 | $0.00380 |
| Sonnet 5 | $0.00008 | $0.00152 |
| Haiku 4.5 | $0.00004 | $0.00076 |
Grade A, and why
self-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
self-audit — 완료 선언 전 자기 감사
작업을 끝냈다고 말하기 전에, 아래를 스스로 검증하고 형식 강제 원장으로 보고하세요. 자유 산문 리뷰는 금지 — 형식이 곧 규율입니다.
절차
- 요구사항 대조 — 사용자가 요청한 것을 다시 읽고, 산출물이 각 항목을 실제로 충족하는지 하나씩 대조한다.
- 게이트 실행 — 프로젝트의 빌드/테스트/린트 명령을 실제로 실행하고 exit 0 을 확인한다 (추측 금지).
- diff 재검토 — 변경 diff 를 처음 보는 리뷰어의 눈으로 훑는다.
- 발견된 문제는 고치고 1~3 을 반복한다. 두 번 연속 깨끗하면 완료를 선언한다.
발견 보고 형식 (강제)
발견 1건 = 1줄, 고정 태그만 사용:
<file>:L<line>: <tag> <무엇>. <수정>.
위치가 없는 발견은 위치 대신 대상을 쓴다 (형식 예외 — 날조 금지):
gate: <명령> exit <code>. <수정>.
unlogged: <미기록 작업 요약>. journal_write 실행.
debris:디버그 잔재·주석 처리 코드·의도치 않은 파일gap:요구사항 미충족·누락된 에지 케이스gate:게이트 실패·미실행 (exit code 와 명령 명시)unlogged:변경했는데 일지/플랜에 반영 안 된 것secret:시크릿/키 노출 의심
마지막 줄은 반드시 지표: net: <N> findings, <M> fixed. — 발견이 없으면 정확히 clean. ship. 한 줄.
신뢰도 게이트 — 보고 전 4문항
각 발견에 대해 하나라도 "아니오"면 보고하지 말고 버린다 (리뷰 드리프트 방지):
- 정확한 위치(파일:라인) 또는 실행 증거(명령·exit code·누락 대상)를 인용할 수 있는가?
- 구체적 실패 시나리오를 말할 수 있는가?
- 주변 전체 문맥을 실제로 읽었는가?
- 심각도를 반박에 방어할 수 있는가?
오탐으로 취급 — 보고 금지
프레임워크가 관리하는 경로의 에러 핸들링 부재 · 테스트 픽스처의 하드코딩 값 · 의도적 단순화 마커(oculpm-defer:)가 붙은 지름길 · 스타일 취향(포매터의 몫) · 정확성·보안·성능의 깊은 분석(전용 리뷰의 몫 — 여기는 완료 직전 최종 점검).
거짓 완료 방지
실패했거나 건너뛴 것이 있으면 "완료" 대신 실제 상태를 그대로 보고한다. net: 에 미해결이 남아 있으면 완료를 선언하지 않는다.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 56 lines · 39 tokens per session scan A 564a1f5f9844
self-audit is a skill published in the GitHub repository bunhine0452/Ocul-PM (7 stars, last pushed 2d ago), licensed MIT. It adds 39 tokens to every session and 760 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
agentbro-pr-merge
Use when reviewing, fixing CI for, approving workflows for, or merging AgentBro pull requests into dev/main, especially external contributor PRs where contributor attribution matters.
claude-delegate
Delegate a coding task to a separate Claude Code CLI process or another Claude session as an implementer, then review its diff and land it yourself. Use only when the user explicitly asks to delegate implementation to Claude Code, another Claude session, or the claude CLI — for example, "have another Claude implement…
cursor-delegate
Delegate a coding task to the Cursor Agent CLI (cursor-agent) as a background implementer, then review its diff and land it yourself. Use this whenever the user wants to hand implementation work to Cursor — phrasings like "have Cursor implement X", "delegate this to Cursor", "run it through Cursor Agent", or "use…
warp-delegate
Delegate a coding task to the Warp Agent CLI (oz) as a background implementer, then review its diff and land it yourself. Use this whenever the user wants to hand implementation work to Warp - phrasings like "have Warp implement X", "delegate this to the Warp CLI", "run it through Warp", "use oz to…
zcode-delegate
Delegate a coding task to the Z.AI ZCode CLI as a background implementer, then review its diff and land it yourself. Use this whenever the user wants to hand implementation work to ZCode — phrasings like "have ZCode do X", "delegate this to ZCode", "run it through ZCode", or "use ZCode to implement/fix/refactor" — or…
cline-delegate
Delegate a coding task to the Cline coding agent CLI (cline) as a background implementer, then review its diff and land it yourself. Use this whenever the user wants to delegate implementation work to Cline - phrasings like "have Cline implement X", "delegate this to cline", "run it through Cline", or "use cline to…