Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/fabioc-aloha/Alex_Skill_Mallnpx agentmods add skills/fabioc-aloha/alex_skill_mall/currency-auditWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/fabioc-aloha/alex_skill_mall/currency-audit)<a href="https://agentmods.dev/skills/fabioc-aloha/alex_skill_mall/currency-audit"><img src="https://agentmods.dev/badge/skills/fabioc-aloha/alex_skill_mall/currency-audit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/fabioc-aloha/alex_skill_mall/currency-audit"><img src="https://agentmods.dev/badge/skills/fabioc-aloha/alex_skill_mall/currency-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00024 | $0.02566 |
| Opus 5 | $0.00012 | $0.01283 |
| Sonnet 5 | $0.00005 | $0.00513 |
| Haiku 4.5 | $0.00002 | $0.00257 |
Grade A, and why
currency-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 225 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Currency Audit
Full assessment: external freshness + internal consistency + semantic accuracy. Stamp only when all pass.
brain-qa.cjs checks the date mechanically (the lastReviewed field). This skill defines the full review that earns that date. A re-stamp means both "content matches external reality" AND "content is internally consistent."
Critical Thinking Discipline
Every audit item must pass through critical thinking — not just mechanical verification. Apply these disciplines throughout:
| Discipline | Application to Currency Audit |
|---|---|
| Alternative hypotheses | "This API exists" isn't enough — is the usage correct? Could the documented pattern be outdated even if the API isn't? |
| Missing data | What's NOT in the file that should be? Missing caveats, undocumented prerequisites, absent error handling? |
| Evidence quality | Is the file's advice based on official docs, or a single blog post from 2021? |
| Self-report skepticism | "Best practice" claims — verified against what source? "Works on current versions" — actually tested? |
| Bias detection | Anchoring on the file's current content. Challenge: would you write this the same way from scratch today? |
| Falsifiability | What would prove this advice wrong? If nothing could, the claim may be unfalsifiable hand-waving |
| Materiality gate | If this item were stale, would it cause real harm? Prioritize fixes that affect decisions over cosmetic accuracy |
The key question at every checklist item: "Am I verifying this is correct, or am I assuming it's correct because it looks plausible?"
When to Use
- brain-qa shows files with expired or missing
lastRevieweddates - Before a release that ships brain files to heirs
- On a scheduled cadence (target: full audit every 90 days)
- After a major external change (new API version, deprecated pattern, VS Code update)
Quick Reference
| Step | Action | Outcome |
|---|---|---|
| Triage | Run node scripts/brain-qa.cjs, read the stale-file output |
Ordered work list |
| Research | Check latest docs, changelogs, releases for the file's domain | Delta list |
| Compare | Diff current content against latest practices | Stale advice identified |
| Audit | Check terminology, cross-references, claims, process logic | Internal consistency verified |
| Update | Fix stale content, wrong terms, broken references, contradictions | Full assessment complete |
| Stamp | Set lastReviewed: YYYY-MM-DD to today in frontmatter |
Pass restored |
| Verify | Re-run brain-qa, confirm file passes | Clean output |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 225 lines · 24 tokens per session scan A c1d8657a05d7
currency-audit is a skill published in the GitHub repository fabioc-aloha/Alex_Skill_Mall (4 stars, last pushed today), licensed MIT. It adds 24 tokens to every session and 2,566 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
apply-cross-functional-leadership
Use when a manager needs to lead a project or initiative that depends on team members or stakeholders they do not formally manage — to build voluntary cooperation, alignment, and momentum across organizational boundaries through influence rather than authority.
build-psychological-safety
Use when a team leader wants to assess and improve the degree to which team members feel safe to speak up, admit mistakes, ask questions, and disagree — because psychological safety is the strongest predictor of team learning and high performance.
run-performance-improvement-plan
Use when a direct report has a documented pattern of performance falling below role expectations — after informal feedback has not produced sustained change — to create a structured, time-bound plan with clear success criteria before making a continuation decision.
run-underperformance-conversation
Use when a manager first observes that a direct report's performance is declining or falling below expectations — to have an early, direct, non-punitive conversation that names the gap and opens a path to correction before the situation requires formal process.
apply-change-leadership
Use when a manager's team is experiencing a significant organizational change — restructuring, strategy shift, leadership change, layoffs, or major process transition — and needs leadership that maintains team stability, preserves trust, and converts uncertainty into direction.
apply-distributed-team-practices
Use when managing a team where members work in different locations, time zones, or on hybrid schedules — to adapt management practices so remote members have equal access to information, relationships, and advancement opportunities as in-office members.