Borrowing it
Nothing to install: this file belongs to katopz/katgpt-rs. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/katopz/katgpt-rs/develop/.agents/skills/goat-audit/SKILL.mdgit clone --depth 1 https://github.com/katopz/katgpt-rsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/katopz/katgpt-rs/goat-audit)<a href="https://agentmods.dev/skills/katopz/katgpt-rs/goat-audit"><img src="https://agentmods.dev/badge/skills/katopz/katgpt-rs/goat-audit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/katopz/katgpt-rs/goat-audit"><img src="https://agentmods.dev/badge/skills/katopz/katgpt-rs/goat-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00116 | $0.06822 |
| Opus 5 | $0.00058 | $0.03411 |
| Sonnet 5 | $0.00023 | $0.01364 |
| Haiku 4.5 | $0.00012 | $0.00682 |
Grade A, and why
goat-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 255 lines — stays where its author put it; the contents beside it link to each section on GitHub.
goat-audit — Cross-Repo GOAT/Gain Cherry-Pick Audit
Use this skill when auditing whether the riir-* private repos have consumed the GOAT-validated primitives shipped in katgpt-rs. It detects four failure classes:
- Stalls — primitive default-on in katgpt-rs for ≥7 days, zero runtime wiring in riir-*.
- DRY violations — riir-* ships a local copy of substrate that should consume
katgpt-core/katgpt-transformer/katgpt-pruners. - SOLID violations — primitive consumed in the wrong layer (e.g. a sync-boundary primitive wired into a latent-only runtime, or vice versa).
- Fork drift (the Issue 019 class) — riir-* is a fork of katgpt-rs (e.g.
riir-engine/src/lib.rssays "Extracted from katgpt-rs (MIT, frozen at v0.1.0)") and a Layer 2 struct-name grep hits a file that defines its ownpub struct SameNamewith zerouse katgpt_*::imports. The audit must distinguish consumer (true positive, primitive wired) from duplicate (false positive, primitive re-implemented locally — the canonical has bit-rotted since v0.1.0).
When to use
- Quarterly hygiene gate — re-audit after every major katgpt-rs release.
- Before opening a plan that consumes a katgpt-rs primitive — confirm it isn't already wired (avoid duplicate work).
- When a user asks "did riir-* get every good thing from katgpt-rs yet?" (the canonical trigger).
- After a promotion in katgpt-rs — track that the riir-* runtime wiring plan is filed within 7 days.
DO NOT use for
- Paper distillation (use the
researchskill). - Single-repo refactors with no cross-repo angle.
- Bug fixes with no architectural impact.
Repos in scope (the product set of 8 — audit focuses on the 4 cherry-pick targets)
Canonical list:
katgpt-rs/AGENTS.md§"Repo count".riir-dapps(dApp layer, added 2026-08-20) is the 8th and is OUT OF SCOPE here for the same reason as riir-game-sdk: it composes outcomes, it hosts no feature-gated katgpt primitive to audit.
katgpt-rs ← public engine (substrate: katgpt-core + 16 leaf crates + root)
riir-ai ← private runtime/game (cognitive, ARG, CLR, HLA, karc, cwm, etc.)
riir-chain ← private chain (LatCal, quorum, asset lifecycle)
riir-neuron-db ← private neuron-shard leaf (Pod, freeze, consolidation, AnyRAG)
riir-train ← private training vault (OUT OF SCOPE — training-only methods)
riir-game-sdk ← private game-vocabulary facade + dev-tool workspace (OUT OF SCOPE —
consumes vocabulary from riir-games-shared in riir-ai, not katgpt-rs
engine primitives directly; transitively reaches katgpt-core only via
the always-on path dep, no feature-flag-gated primitives to audit)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · +1 lines 8b64e81c61d7
- 7d ago Changed · +27 lines 7b429e39eac7
- 11d ago First seen · 227 lines · 116 tokens per session scan A c9f72d47233d
goat-audit is a skill published in the GitHub repository katopz/katgpt-rs (98 stars, last pushed yesterday), licensed MIT. It adds 116 tokens to every session and 6,822 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
prowler-commit
Creates professional git commits following conventional-commits format. Trigger: When creating commits, after completing code changes, when user asks to commit.
gh-auth-isolation
Safely manage multiple GitHub identities (EMU + personal) in agent workflows.
comet-github
A routing guide for Comet-related GitHub work. It directs requests about pull requests, issues, CI failures, ideas, and fixes to the appropriate review or implementation process.
github-skill
Work with GitHub via the gh CLI — clone repositories, create/list/merge pull requests, create/list issues, and run any other gh command (API calls, workflow runs, releases, repo administration). List operations return parsed JSON.
re0-merge
Review and land an external contribution the way this suite does: gate it against the thesis, land it with the author's credit intact, complete a new skill rather than merging it raw, then approve, credit, and explain before closing. Use when reviewing a pull request, as any collaborator or maintainer, not only the…
nvca-chart-release
Release NVCA Operator chart changes from the native monorepo source to the vendored Helm chart. Use when updating the vendored NVCA Operator chart, changing NVCA image refs, publishing helm-nvca-operator, or validating the chart against a self-managed control plane.