skill-audit

skill-audit is a skill for Claude Code from magnusrodseth/dotfiles. It costs 89 tokens per session (616 once invoked), scanned A, original, no licence file.

An audit tool for installed Claude Code skills, including their context cost and recorded use in project transcripts.

In plain words
What is it for?
Use it to inventory skills, estimate their description cost, review past invocations, or find unused skills.
Why use it?
It shows which skills consume always-loaded context and which appear unused, helping identify candidates for cleanup.

Skill for Claude Code

Written for Claude Code: installed under .claude/.

Good fit Use it to inventory skills, estimate their description cost, review past invocations, or find unused skills.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/magnusrodseth/dotfiles/skill-audit
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add magnusrodseth/dotfiles --skill skill-audit
Clone the repo
git clone --depth 1 https://github.com/magnusrodseth/dotfiles

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for skill-audit

README.md
[![agentmods](https://agentmods.dev/badge/skills/magnusrodseth/dotfiles/skill-audit.svg)](https://agentmods.dev/skills/magnusrodseth/dotfiles/skill-audit)
Your own site
<a href="https://agentmods.dev/skills/magnusrodseth/dotfiles/skill-audit"><img src="https://agentmods.dev/badge/skills/magnusrodseth/dotfiles/skill-audit.svg" alt="Measured on agentmods" height="20"></a>
Per session 89 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 616 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00089 $0.00616
Opus 5 $0.00044 $0.00308
Sonnet 5 $0.00018 $0.00123
Haiku 4.5 $0.00009 $0.00062

Measured 8d ago against content hash ca713fec0a78, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

skill-audit scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

The scan reads SKILL.md. This mod also ships 1 executable file (scripts/skill-audit.sh), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Enumerates other installed skillslowAgent snooping

Other skills' SKILL.md files reveal prompts, capabilities and secrets that should be invisible to peers.

| `local` | nothing (untracked real dir in `~/.claude/skills`) | delete the dir; or move keepers into `~/dotfiles/.claude/skills/` so they become tracked and validated |

Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.

.claude/skills/skill-audit/SKILL.md · 53 lines

The source is not reproduced here

No licence file

A repository with no LICENSE is all rights reserved by default, so the body is not copied here. The metadata, the measurements and the link are.

Read it on GitHub

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 53 lines · 89 tokens per session scan A ca713fec0a78

Subscribe to this mod's changes

skill-audit is a skill published in the GitHub repository magnusrodseth/dotfiles (2 stars, last pushed 3d ago), with no licence file. It adds 89 tokens to every session and 616 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 1 finding (enumerates other installed skills). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

batch-grill-me

A relentless interview that asks every frontier question at once, round by round.

M0rtalPhe0nix/dotfiles · 20 tokens

modern-css

Specialized knowledge for writing modern high-quality CSS. Trigger this skill when starting a new CSS project/file, when the user asks about new CSS features (e.g. Masonry, View Transitions, Container Queries, Scroll-driven animations), or requests refactoring of legacy styles to modern standards.

paulirish/dotfiles · 61 tokens

npm-trusted-publishing

Set up or debug npm Trusted Publishing (OIDC) from GitHub Actions. Handles permissions, metadata validation, and provenance.

paulirish/dotfiles · 31 tokens

buildless-types

Use when the user asks to "set up types without a build step", "use vanilla JS with types", "configure erasable syntax", or mentions "JSDoc type checking". It provides instructions for modern type safety using JSDoc in browsers and native TypeScript execution in Node.js.

paulirish/dotfiles · 63 tokens

qmd-expert

How to effectively use QMD (Quick Markdown Search) to pull in extra relevant context, run multi-query searches, extract high-scoring chunk IDs, and fetch their contents. Use this skill when asked to search across a large markdown knowledge base, run QMD queries, or retrieve deep context using the qmd CLI.

paulirish/dotfiles · 69 tokens

pauls-project-setup

Paul's modern stack conventions for new projects (pnpm, native node test, esbuild, buildless-types). Consult when starting a new project or repository.

paulirish/dotfiles · 38 tokens