audit-cardinality

audit-cardinality is a skill for Claude Code, Codex from danygiguere/audit-skills. It costs 71 tokens per session (142 once invoked), scanned A, original, MIT.

A checklist for checking whether database operations target exactly the intended rows when a query uses a field that may not be unique.

In plain words
What is it for?
Use it to review UPDATE and DELETE conditions, single-record lookups, and cases where application code assumes a field is unique without a database UNIQUE constraint.
Why use it?
It helps prevent an update or deletion from affecting multiple or incorrect records, or a single-record lookup from returning an unintended match.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: installed under .agents/ (shared by several agents).

Good fit Use it to review UPDATE and DELETE conditions, single-record lookups, and cases where application code assumes a field is unique without a database UNIQUE constraint.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/danygiguere/audit-skills/audit-cardinality
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add danygiguere/audit-skills --skill audit-cardinality
Clone the repo
git clone --depth 1 https://github.com/danygiguere/audit-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for audit-cardinality

README.md
[![agentmods](https://agentmods.dev/badge/skills/danygiguere/audit-skills/audit-cardinality/github.svg)](https://agentmods.dev/skills/danygiguere/audit-skills/audit-cardinality)
Your own site
<a href="https://agentmods.dev/skills/danygiguere/audit-skills/audit-cardinality"><img src="https://agentmods.dev/badge/skills/danygiguere/audit-skills/audit-cardinality/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for audit-cardinality

Your own site · 80×15
<a href="https://agentmods.dev/skills/danygiguere/audit-skills/audit-cardinality"><img src="https://agentmods.dev/badge/skills/danygiguere/audit-skills/audit-cardinality.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 71 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 142 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00071 $0.00142
Opus 5 $0.00036 $0.00071
Sonnet 5 $0.00014 $0.00028
Haiku 4.5 $0.00007 $0.00014

Measured 12d ago against content hash 8bfabd82e21c, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

audit-cardinality scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.agents/skills/audit-cardinality/SKILL.md · 10 lines

What it actually says

Read ../audit/references/correctness/cardinality.md and apply its checklist to the code the user specified (or the current diff if none was given). Verify each candidate with ../audit/references/methodology/verify.md before reporting. Report findings with severity and file:line references.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 10 lines · 71 tokens per session scan A 8bfabd82e21c

Subscribe to this mod's changes

audit-cardinality is a skill published in the GitHub repository danygiguere/audit-skills (5 stars, last pushed 2mo ago), licensed MIT. It adds 71 tokens to every session and 142 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

auditing-datastore-exposure-and-abuse

Audit in-memory and cache datastores such as Redis and memcached for exposure and command abuse: an instance reachable without authentication, a request that composes datastore commands from untrusted input, or server-side scripting and module or config commands that reach code execution or a file write. Covers…

UnboundCompute/security-agent-skills · 175 tokens

backend-engineer

Plan, implement, and validate backend service changes. Use when patching or adding backend features in an existing API, data, auth, worker, or service codebase.

jscraik/Agent-Skills · 38 tokens

hunting-connection-string-and-jdbc-url-injection

Hunt injection into database connection strings and JDBC or driver URLs where untrusted input sets the host, a driver property, or a URL parameter, turning a data connection into a request to an attacker server or an unsafe driver feature. Covers a tenant, hostname, or option taken from input and spliced into a…

UnboundCompute/security-agent-skills · 166 tokens

hunting-search-engine-injection

Hunt injection into search and analytics engines such as Elasticsearch, OpenSearch, and Solr where untrusted input reaches a query DSL body, a query-string or Lucene query, a script field, or a stored scripting expression. Covers request data that becomes query structure (a filter clause, a field selector, an…

UnboundCompute/security-agent-skills · 166 tokens

hunting-nosql-operator-and-where-injection

Hunt NoSQL injection where untrusted input becomes query structure rather than a bound value: a request body whose keys turn into query operators, a value that arrives as an object instead of a scalar, or input reaching a server-side JavaScript evaluation such as $where, a mapReduce function, or an aggregation…

UnboundCompute/security-agent-skills · 171 tokens

hunting-orm-and-query-builder-injection

Hunt injection that survives an object-relational mapper or query builder: untrusted input reaching a raw-query escape hatch, an unparameterizable identifier (a column, table, or sort order), or a structured filter or update object whose keys become query operators or column references. Covers raw-query methods that…

UnboundCompute/security-agent-skills · 177 tokens