auditing-workspaces

auditing-workspaces is a skill for Claude Code from kamiazya/whiteboard. It costs 60 tokens per session (1,134 once invoked), scanned A, original, Apache-2.0.

A procedure for reviewing a whiteboard workspace's documents and finding spatial canvases that may be empty, abandoned, or duplicates. A spatial canvas is a document arranged visually rather than as ordinary text.

In plain words
What is it for?
It is for listing documents, checking their types and scene summaries, and deciding which canvases are worth opening or replacing.
Why use it?
It helps prevent workspace clutter and avoids creating another canvas when a suitable one already exists.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the whiteboard plugin — 19 skills, 18 agents, 3 hooks, 1 MCP server shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/kamiazya/whiteboard/auditing-workspaces
Any agent
npx skills add kamiazya/whiteboard --skill auditing-workspaces
Clone the repo
git clone --depth 1 https://github.com/kamiazya/whiteboard

Made for: Claude Code.

Or install whiteboard, the plugin that ships this one along with the rest of its 19 skills, 18 agents, 3 hooks, 1 MCP server.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for auditing-workspaces

README.md
[![agentmods](https://agentmods.dev/badge/skills/kamiazya/whiteboard/auditing-workspaces.svg)](https://agentmods.dev/skills/kamiazya/whiteboard/auditing-workspaces)
Your own site
<a href="https://agentmods.dev/skills/kamiazya/whiteboard/auditing-workspaces"><img src="https://agentmods.dev/badge/skills/kamiazya/whiteboard/auditing-workspaces.svg" alt="Measured on agentmods" height="20"></a>
Per session 60 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,134 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00060 $0.01134
Opus 5 $0.00030 $0.00567
Sonnet 5 $0.00012 $0.00227
Haiku 4.5 $0.00006 $0.00113

Measured 3d ago against content hash 1c85f4e73585, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

auditing-workspaces scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/auditing-workspaces/SKILL.md · 110 lines

How it starts

The opening of the file, as written. The whole thing — 110 lines — stays where its author put it; the contents beside it link to each section on GitHub.

auditing-workspaces

List a workspace's documents, then use the spatial ones' scene digests to judge which look empty or abandoned. There is no server-side audit endpoint — this skill is a recipe for composing the regular document tools toward that end, nothing more.

For the main drawing workflow, see the drawing-visuals skill in skills/drawing-visuals/SKILL.md.


When To Use It

  • When a workspace has been in heavy use and you want a sense of what is in it before adding more
  • When you want to check for a likely-duplicate path before calling wb_document_create
  • When you want to know whether a spatial document is worth opening without rendering it

Execution Flow

Step 1: List The Workspace's Documents

wb_document_list({ workspaceId })

Returns { documents: [{ documentId, path, name?, kind?, updatedAt?, shadowed? }] } — placement only, no content. An unknown workspaceId is an error here, not an empty list, so a typo reads as a failure rather than "nothing found."

Step 2: Classify, Then Sample Each Document

Step 1's listing carries no kind, and wb_document_get is the only tool that reports one — so classification comes first, and it costs one wb_document_get per document:

wb_document_get({ workspaceId, documentId })
// markdown -> { kind: "markdown", content: "...", frontmatter: {...} }  (the body, directly)
// spatial  -> { kind: "spatial", content: "..." }                        (full JSON Canvas payload)
// no recorded kind -> throws a "no recorded kind" error — itself a signal worth reporting

Read the kind before reading the content. A spatial read refuses a document it knows to be markdown rather than reporting its containers as empty, so it cannot silently answer "nothing here" about a document full of prose — but it also cannot tell you the kind of a document you have not identified yet. wb_document_get is what establishes that.

Once a document is KNOWN spatial (from wb_document_get's kind, or because this session created it), wb_canvas_snapshot is the cheap re-probe for later passes — node text, geometry and lock state without the untruncated JSON Canvas payload:

Read the full file on GitHub · 110 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago Changed 1c85f4e73585
  2. 6d ago First seen · 110 lines · 60 tokens per session scan A 69783ec5b823

Subscribe to this mod's changes

auditing-workspaces is a skill published in the GitHub repository kamiazya/whiteboard (6 stars, last pushed yesterday), licensed Apache-2.0. It adds 60 tokens to every session and 1,134 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.