audit

audit is a skill for Claude Code from markmhendrickson/neotoma. It costs 3 tokens per session (5,344 once invoked), scanned A, original, MIT.

A read-only health check for a Neotoma database, which stores entities, observations, relationships, schemas, and raw source fragments. It reports inconsistencies and quality problems by category and severity, with suggested existing tools for repair.

In plain words
What is it for?
Use it to inspect graph health with standard deterministic checks or an optional deeper language-model-assisted mode. It can identify drift and inconsistencies and point to tools for merging, correcting, splitting, deleting, or updating records and schemas.
Why use it?
It finds problems across the whole database without changing anything. This gives the user a reviewable list of issues before choosing individual repairs.

Skill for Claude Code

Written for Claude Code: installed under .claude/. Also seen: positional $N argument.

Good fit Use it to inspect graph health with standard deterministic checks or an…

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/markmhendrickson/neotoma/audit
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add markmhendrickson/neotoma --skill audit
Clone the repo
git clone --depth 1 https://github.com/markmhendrickson/neotoma

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for audit

README.md
[![agentmods](https://agentmods.dev/badge/skills/markmhendrickson/neotoma/audit.svg)](https://agentmods.dev/skills/markmhendrickson/neotoma/audit)
Your own site
<a href="https://agentmods.dev/skills/markmhendrickson/neotoma/audit"><img src="https://agentmods.dev/badge/skills/markmhendrickson/neotoma/audit.svg" alt="Measured on agentmods" height="20"></a>
Per session 3 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 5,344 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00003 $0.05344
Opus 5 $0.00002 $0.02672
Sonnet 5 $0.00001 $0.01069
Haiku 4.5 $0.00000 $0.00534

Measured 7d ago against content hash c409f5356011, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/skills/audit/SKILL.md · 248 lines

How it starts

The opening of the file, as written. The whole thing — 248 lines — stays where its author put it; the contents beside it link to each section on GitHub.

audit

Purpose

Run a comprehensive read-only audit of the user's Neotoma database, surfacing graph-health issues by category and severity. Each finding includes a structured remediation pointing at an existing Neotoma tool — this skill never mutates state.

Neotoma has strong write-path discipline (idempotency, schema-first, immutability, deterministic IDs) but no holistic read-path "is my graph healthy?" tool. /audit fills that gap.

Scope

In scope: detection of inconsistencies, drift, and quality issues across entities, observations, relationships, schemas, and raw_fragments.

Out of scope: mutation of any kind. Repair is performed by delegating to other tools or skills (merge_entities, correct, split_entity, delete_entity, register_schema, update_schema_incremental). The user opts into each repair individually after reviewing findings.

Modes

  • /audit — Run all deterministic checks. No LLM cost. Default.
  • /audit --deep — Run deterministic + LLM-assisted checks. Requires an LLM API key (read from NEOTOMA_AUDIT_LLM_KEY env var or passed via --key=…). Models default to a cheap small model; override with --model=….
  • /audit --scope=<entity_type|relationship|schema|fragments> — Restrict checks to one category.
  • /audit --since=<ISO date> — Restrict to entities/observations created or updated since the date.
  • /audit --user=<user_id> — Audit a specific user's records (defaults to authenticated user).
  • /audit --dup-min-count=<N> — Minimum entity count for a type to be auto-scanned for potential duplicates beyond the always-checked contact/person/organization set (default 100).
  • /audit --format=<table|json|markdown> — Output shape; table default for interactive, json for piping into repair tooling.

Prerequisites

  • Neotoma MCP server connected (prod by default: mcpsrv_neotoma).
  • For --deep: LLM API key configured (NEOTOMA_AUDIT_LLM_KEY or --key=…).

Read the full file on GitHub · 248 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 7d ago First seen · 248 lines · 3 tokens per session scan A c409f5356011

Subscribe to this mod's changes

audit is a skill published in the GitHub repository markmhendrickson/neotoma (31 stars, last pushed 3d ago), licensed MIT. It adds 3 tokens to every session and 5,344 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

security-observability

A read-only tool for examining security events already saved by agent-sec-cli, a command-line security log. It can connect those events to an agent session, run, or trace.

alibaba/anolisa · 145 tokens

add-backend

Guide for adding a backend (Rust or Python) to the agent-sec-core security middleware. Use when creating new backends, integrating Rust or Python code into the security middleware, or extending with new backend actions.

alibaba/anolisa · 46 tokens

skill-ledger

A security record for agent skills, which are reusable instruction packages for coding agents. It shows their status, reviews risk exposure, and can certify them with quick or user-approved deeper scans.

alibaba/anolisa · 67 tokens

regex-mastery

Use this skill when writing regular expressions, debugging pattern matching,optimizing regex performance, or implementing text validation. Triggers on regex, regular expressions, pattern matching, lookahead, lookbehind, named groups, capture groups, backreferences, and any task requiring text pattern matching.

alibaba/anolisa · 60 tokens

pr-body

A tool that reviews all commits on the current branch and creates or updates a pull request title and description. A pull request is a proposed code change submitted for review.

alibaba/anolisa · 68 tokens

prompt-scanner

A scanner for text sent to an AI agent, looking for prompt injection and jailbreak attempts. Prompt injection is text that tries to override an agent's instructions; a jailbreak tries to bypass its safety limits.

alibaba/anolisa · 103 tokens