Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/laurigates/claude-plugins/meta-auditnpx skills add laurigates/claude-plugins --skill meta-auditgit clone --depth 1 https://github.com/laurigates/claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/laurigates/claude-plugins/meta-audit)<a href="https://agentmods.dev/skills/laurigates/claude-plugins/meta-audit"><img src="https://agentmods.dev/badge/skills/laurigates/claude-plugins/meta-audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00038 | $0.01665 |
| Opus 5 | $0.00019 | $0.00833 |
| Sonnet 5 | $0.00008 | $0.00333 |
| Haiku 4.5 | $0.00004 | $0.00167 |
Grade A, and why
meta-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 231 lines — stays where its author put it; the contents beside it link to each section on GitHub.
meta-audit
When to Use This Skill
| Use this skill when... | Use custom-agent-definitions instead when... |
|---|---|
Reviewing existing .claude/agents/*.md files for missing frontmatter, overprivileged tools, or wrong models |
Authoring a new agent definition file from scratch |
| Validating read-only vs write-enabled agent privilege boundaries before committing | Configuring a single agent's model, allowed-tools, or context: fork |
| Auditing agents across an entire project for naming and security consistency | Copying or generalising another project's agents (use meta-assimilate) |
Context
- Agent definitions: !
find . -path '*/.claude/agents/*' -name "*.md" -not -name "settings*" - Settings file: !
find . -path '*/.claude/agents/*' -maxdepth 3 -name "settings.local.json" -type f
Your task
1. Discovery Phase
- Use Glob to find all agent definition files in
.claude/agents/ - Read each agent file to extract frontmatter and configuration
- Identify the settings.local.json for permission overrides
2. Frontmatter Validation
For each agent, verify required fields are present:
- ✅ name: Agent identifier (must match filename)
- ✅ model: an alias (
opus,fable,sonnet,haiku,inherit) or a current full ID (e.g.claude-fable-5-1); a dated ID from a superseded generation (claude-opus-4-7,claude-sonnet-4-6) is a finding — recommend the alias unless the pin is deliberate - ℹ️ effort: optional
low…max(overrides the session effort while the agent runs; default inherits); recommendlowwhere the body describes mechanical work - ✅ color: Hex color code for UI (e.g., "#E53E3E")
- ✅ description: Clear usage guidance with "Use proactively when..."
- ✅ tools: Tool list or "All" for full access
Flag issues:
- Missing required fields
- Mismatched name vs filename
- Invalid model names
- Malformed color codes
3. Tool Assignment Analysis
Evaluate tool assignments for security and appropriateness:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · +1 lines 6f13b9e35a4d
- 5d ago First seen · 230 lines · 38 tokens per session scan A fd8f0f8fe49a
meta-audit is a skill published in the GitHub repository laurigates/claude-plugins (58 stars, last pushed today), licensed MIT. It adds 38 tokens to every session and 1,665 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
plan
Produce structured implementation plans with goal, approach, test strategy, blast-radius assessment, parallelism analysis, and a user approval gate before any code is written. Persisting PLAN.md for fresh-session handoff. Use when: 'plan this', 'architect this', 'how should we implement', 'implementation plan', 'write…
extract-ssot
Deduplicate repeated markdown content, rule files, skill bodies, ADRs, docs, into a single named source of truth and migrate every call site to cite it by exact heading. Use when the same prose, literal, or concept appears (or is reworded) across files: 'DRY this prose', 'extract a shared rule', 'single source of…
map-corpus
Map a multi-resource documentation corpus into a verified, classified, triaged slice BEFORE any digesting: bounded discovery (llms.txt + sitemap), a user-approved link map classifying every discovered URL, deterministic node manifests over immutable snapshots, and a per-node relevance inventory whose evidence a script…
feature-branch-pr-writing
Use this skill when the user asks to write, draft, create, or improve a PR description for a Shopware core repository PR — AND that PR targets a non-trunk feature branch (not trunk itself). Trigger phrases like "write a PR description", "draft the PR", "what should I put in the PR body". The skill detects the target…
ci-log-interpretation
Use this skill when reading or analyzing CI logs from a Shopware GitHub Actions workflow to figure out why a build failed — phrases like "why did CI fail", "what broke the build", "check the pipeline", "interpret these logs", "debug this red build" — or whenever raw run logs, job logs, or check annotations from a…
repo-activity
Scan all git repositories under /repos and report recent activity — last commit age, branch, uncommitted changes — in age-bucketed tables. Use when the user asks for a repo activity overview, "what have I been working on", portfolio status, or which repos are active/dormant.