Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add madaeroblade/atlas --skill atlas-auditgit clone --depth 1 https://github.com/madaeroblade/atlasWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/madaeroblade/atlas/atlas-audit)<a href="https://agentmods.dev/skills/madaeroblade/atlas/atlas-audit"><img src="https://agentmods.dev/badge/skills/madaeroblade/atlas/atlas-audit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/madaeroblade/atlas/atlas-audit"><img src="https://agentmods.dev/badge/skills/madaeroblade/atlas/atlas-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00033 | $0.00430 |
| Opus 5 | $0.00016 | $0.00215 |
| Sonnet 5 | $0.00007 | $0.00086 |
| Haiku 4.5 | $0.00003 | $0.00043 |
Grade A, and why
atlas-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Atlas Audit
Resolve Atlas
Read and follow:
$ATLAS_ROOT/engine/audit/ENGINE.md$ATLAS_ROOT/engine/audit/HEALTH.md
If .atlas/ does not exist, report that Atlas is not initialized.
Phase separation
Perform the audit in two stages.
Stage 1 — Read-only audit
Inspect Atlas and relevant repository evidence.
Produce findings before making repairs.
Stage 2 — Repair
After the findings are established, repair Atlas according to the Audit Engine.
Do not modify application source code.
Re-derive, do not re-read
Stage 1 is not a proofread. Every count, table sum, enumeration, cited command
and path:line reference in Atlas must be recomputed against the repository.
A wrong number reads exactly like a right one, and no other check catches it.
Repair scope
Allowed Atlas repairs include:
- stale canonical knowledge;
- a
GRAPH.yamlbelow the current schema version — migrate it; - wrong counts, sums and citations;
- invalid paths;
- graph relationships;
- registers mistyped as nodes;
- a
GRAPH.yamlover budget; - knowledge duplicated into the always-loaded
CLAUDE.md; - obsolete observations;
- duplicated facts;
- bloated documents;
- benchmark scenarios with
.atlas/provenance; - benchmark coverage metadata.
Do not rewrite healthy knowledge for style alone.
Completion
Report:
- health findings by severity;
- health score (out of 16);
- every count or citation that failed re-derivation, even where the surrounding claim was correct;
- routing cost in bytes —
GRAPH.yaml,INDEX.md,CLAUDE.md— and whether it grew; - repairs made;
- knowledge removed/merged;
- graph changes;
- benchmark coverage gaps and INVALID scenarios;
- unresolved uncertainties.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 75 lines · 33 tokens per session scan A 8028c419c9f3
atlas-audit is a skill published in the GitHub repository madaeroblade/atlas (2 stars, last pushed 1mo ago), licensed MIT. It adds 33 tokens to every session and 430 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
mem0-status
Diagnoses mem0 connectivity, API key validity, and memory read/write functionality. Use when memory operations fail, searches return empty, addmemory errors occur, or to verify the plugin is working correctly.
inspector-workbench
Runs Inspector UI work on the standalone Threads state lab so the agent can see the overlay. Use when a CopilotKit employee asks an agent to fix, polish, add, or debug Inspector UI, chrome, panes, overlay actions, launcher, Home, Threads, Playground, Memory, or any visual behavior in @copilotkit/web-inspector. Don't…
md-audit
Read-only code quality audit — scan the current working directory for common issues (bugs, dead code, security hotspots, missing error handling) and return a prioritised findings report. No files are edited. Use when asked to "audit the code", "quick audit", "find issues", "code scan", or "what's wrong with this…
potpie-debug-memory
Use while debugging or troubleshooting failures, flaky tests, incidents, production alerts, CI failures, local dev setup issues, repeated bugs, prior fixes, failed attempts, and verification history.
browserwing-admin
Manage and operate BrowserWing — an intelligent browser automation platform. Install dependencies, configure LLM, create/manage/execute automation scripts, use AI-driven exploration to generate scripts, browse the script marketplace, and troubleshoot issues.
exploiting-format-string-vulnerabilities
Methodology for exploiting format string bugs where attacker-controlled data reaches the format argument of printf-family functions, enabling stack/memory disclosure (info leaks for ASLR/PIE/canary defeat) and arbitrary write primitives (%n) to hijack control flow via GOT/.finiarray overwrites.