Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add hoatv2211/GameStudio-CodexKIT --skill localization-authority-auditgit clone --depth 1 https://github.com/hoatv2211/GameStudio-CodexKITWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hoatv2211/gamestudio-codexkit/localization-authority-audit)<a href="https://agentmods.dev/skills/hoatv2211/gamestudio-codexkit/localization-authority-audit"><img src="https://agentmods.dev/badge/skills/hoatv2211/gamestudio-codexkit/localization-authority-audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00042 | $0.00767 |
| Opus 5 | $0.00021 | $0.00383 |
| Sonnet 5 | $0.00008 | $0.00153 |
| Haiku 4.5 | $0.00004 | $0.00077 |
Grade A, and why
localization-authority-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 79 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Localization Authority Audit
Overview
Identify the localization source of truth and compare every generated or copied map without rewriting multilingual data or masking encoding problems.
When to use
Use for missing keys, extra keys, stale translations, client/server text drift, generated localization copies, encoding mismatches, UTF-8 versus legacy encodings, or mojibake.
When NOT to use
Do not use for Lua packet/RPC field contracts or bulk encoding conversion without project-specific approval and backup.
Required inputs and context discovery
Collect authority path, copy/generated paths, generation pipeline, locale list, key format, encoding evidence, fallback behavior, runtime owner, and protected vendor/generated data.
Safety and risk level
Read-only audit first. Never bulk-convert encodings, normalize multilingual text, or edit generated copies before source authority and backup are verified.
Workflow
- Identify source authority, generated copies, runtime consumers, and fallback order. Completion criterion: unknown authority remains BLOCKED.
- Verify file encodings with evidence before decoding or comparing text. Completion criterion: mojibake is not mistaken for a translation difference.
- Normalize keys without changing source text and compare missing, extra, and mismatched entries. Completion criterion: every finding cites authority and copy locations.
- Trace generation or copy synchronization for stale outputs. Completion criterion: the editable source and regeneration path are known.
- Propose source-first fixes, targeted encoding handling, and verification fixtures. Completion criterion: no bulk conversion or generated-file hand edit is proposed without safeguards.
Evidence and output contract
Produce localization-audit.json with authority, encodings, locales, missing/extra/mismatched keys, generation paths, runtime fallback, limitations, and source-first recommendations.
Handoff contract
Record authority and copy paths, encoding evidence, key mismatches, generated no-touch files, unresolved locale ownership, and next safe action.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 79 lines · 42 tokens per session scan A 5fb7713bf89d
localization-authority-audit is a skill published in the GitHub repository hoatv2211/GameStudio-CodexKIT (3 stars, last pushed yesterday), licensed MIT. It adds 42 tokens to every session and 767 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
kirby-i18n-workflows
Manages Kirby multi-language workflows, translations, and localized labels. Use when dealing with languages, translation keys, placeholders, or importing/exporting translations.
global-data-post-resolve
Resolve an address or coordinates into a full location profile — city, country, timezone, UTC offset, current time, working days this month, and next holiday.
global-data-get-{country}
Retrieve working days, public holidays, and next upcoming holiday for any country and optional year/month. Covers 100+ countries.
detect-language-post-detect-language
Identifies the language of the provided text and returns the language name, ISO 639-1 code, and confidence score.
deep-discovery
Use when the user asks for deep discovery, 100-question brainstorming, idea interrogation, architecture stress testing, strategy vetting, weakness finding, hole-poking, exhaustive exploration, planning or auditing Codex plugins or skills, or pre-commitment review of a design, plan, strategy, architecture, product…
prewalk
Use when the user wants a coding task executed with a strong planner model first and a faster/cheaper executor model after the first successful implementation edit.