Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/lacerbi/dotclaude/auditnpx skills add lacerbi/dotclaude --skill auditgit clone --depth 1 https://github.com/lacerbi/dotclaudeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/lacerbi/dotclaude/audit)<a href="https://agentmods.dev/skills/lacerbi/dotclaude/audit"><img src="https://agentmods.dev/badge/skills/lacerbi/dotclaude/audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00012 | $0.00438 |
| Opus 5 | $0.00006 | $0.00219 |
| Sonnet 5 | $0.00002 | $0.00088 |
| Haiku 4.5 | $0.00001 | $0.00044 |
Grade A, and why
audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Files to Audit
$ARGUMENTS
Context
- Project structure: !
ls -la - Recent modifications: !
git status --short 2>/dev/null || echo "Not a git repository"
Your Task
Treat the audit as read-only. Do not fix findings, edit files, create issues, or write an audit artifact unless the user explicitly asks for one.
Deploy specialized sub-agents as needed to audit the specified files across these key areas. Use Opus for all audit tasks (Sonnet only for mechanical checks like linting output, test pass/fail status, or counting TODOs; never Haiku).
1. Correctness & Quality
- Bugs, errors, or logical flaws
- Completeness and accuracy
- Whether the file effectively serves its intended purpose
2. Codebase Integration
- Inconsistencies with related files (same directory, imports, dependencies)
- Conflicting patterns or duplicated functionality
- Missing companion files (tests, docs, configs)
- Broken references or dependencies
3. Standards & Best Practices
- Security vulnerabilities or unsafe patterns
- Performance issues or inefficiencies
- Maintainability concerns (complexity, documentation, naming)
- Compliance with project/industry standards
4. Impact & Risk
- What depends on these files
- Potential breaking changes
- Areas needing immediate attention
Output: Report the audit in the conversation by default. Include:
- Executive summary
- Detailed findings by area
- Prioritized action items
- Recommendations
If the user explicitly requests a file, write it at the repository's prescribed location or use
AUDIT_[descriptor]_[timestamp].md when no convention exists, then also provide a brief summary in
the conversation highlighting critical findings.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 53 lines · 12 tokens per session scan A f69d1fd2a2b6
audit is a skill published in the GitHub repository lacerbi/dotclaude (2 stars, last pushed 5d ago), licensed MIT. It adds 12 tokens to every session and 438 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
bet-on-it
Use when debugging or changing behavior based on an uncertain causal hypothesis that the next action can test.
prove-me-wrong
Use when a leading diagnosis or nontrivial fix has initial support and needs one adversarial counterexample before acceptance.
archaeologist
Use when changing unusual or defensive code, mature APIs, dependencies, or architecture, or estimating a migration where Git history may reveal hidden constraints.
no-vibes
Use when completion depends on an end-to-end outcome across components, environments, or external systems.
red-button
Use when an action could cause material, hard-to-reverse harm to production, data, security, finances, users, or external systems.
organizing-files
Organizes macOS files across Desktop, Documents, Downloads, and iCloud Drive into a consistent structure. Use when the user asks to organize files, clean up folders, sort downloads, declutter desktop, tidy up documents, or structure their filesystem. Triggers on "organize", "clean up", "sort files", "declutter", "file…