Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add markmhendrickson/neotoma --skill auditgit clone --depth 1 https://github.com/markmhendrickson/neotomaWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/markmhendrickson/neotoma/audit)<a href="https://agentmods.dev/skills/markmhendrickson/neotoma/audit"><img src="https://agentmods.dev/badge/skills/markmhendrickson/neotoma/audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00003 | $0.05344 |
| Opus 5 | $0.00002 | $0.02672 |
| Sonnet 5 | $0.00001 | $0.01069 |
| Haiku 4.5 | $0.00000 | $0.00534 |
Grade A, and why
audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 248 lines — stays where its author put it; the contents beside it link to each section on GitHub.
audit
Purpose
Run a comprehensive read-only audit of the user's Neotoma database, surfacing graph-health issues by category and severity. Each finding includes a structured remediation pointing at an existing Neotoma tool — this skill never mutates state.
Neotoma has strong write-path discipline (idempotency, schema-first, immutability, deterministic IDs) but no holistic read-path "is my graph healthy?" tool. /audit fills that gap.
Scope
In scope: detection of inconsistencies, drift, and quality issues across entities, observations, relationships, schemas, and raw_fragments.
Out of scope: mutation of any kind. Repair is performed by delegating to other tools or skills (merge_entities, correct, split_entity, delete_entity, register_schema, update_schema_incremental). The user opts into each repair individually after reviewing findings.
Modes
/audit— Run all deterministic checks. No LLM cost. Default./audit --deep— Run deterministic + LLM-assisted checks. Requires an LLM API key (read fromNEOTOMA_AUDIT_LLM_KEYenv var or passed via--key=…). Models default to a cheap small model; override with--model=…./audit --scope=<entity_type|relationship|schema|fragments>— Restrict checks to one category./audit --since=<ISO date>— Restrict to entities/observations created or updated since the date./audit --user=<user_id>— Audit a specific user's records (defaults to authenticated user)./audit --dup-min-count=<N>— Minimum entity count for a type to be auto-scanned for potential duplicates beyond the always-checkedcontact/person/organizationset (default 100)./audit --format=<table|json|markdown>— Output shape;tabledefault for interactive,jsonfor piping into repair tooling.
Prerequisites
- Neotoma MCP server connected (prod by default:
mcpsrv_neotoma). - For
--deep: LLM API key configured (NEOTOMA_AUDIT_LLM_KEYor--key=…).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 248 lines · 3 tokens per session scan A c409f5356011
audit is a skill published in the GitHub repository markmhendrickson/neotoma (31 stars, last pushed 3d ago), licensed MIT. It adds 3 tokens to every session and 5,344 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
security-observability
A read-only tool for examining security events already saved by agent-sec-cli, a command-line security log. It can connect those events to an agent session, run, or trace.
add-backend
Guide for adding a backend (Rust or Python) to the agent-sec-core security middleware. Use when creating new backends, integrating Rust or Python code into the security middleware, or extending with new backend actions.
skill-ledger
A security record for agent skills, which are reusable instruction packages for coding agents. It shows their status, reviews risk exposure, and can certify them with quick or user-approved deeper scans.
regex-mastery
Use this skill when writing regular expressions, debugging pattern matching,optimizing regex performance, or implementing text validation. Triggers on regex, regular expressions, pattern matching, lookahead, lookbehind, named groups, capture groups, backreferences, and any task requiring text pattern matching.
pr-body
A tool that reviews all commits on the current branch and creates or updates a pull request title and description. A pull request is a proposed code change submitted for review.
prompt-scanner
A scanner for text sent to an AI agent, looking for prompt injection and jailbreak attempts. Prompt injection is text that tries to override an agent's instructions; a jailbreak tries to bypass its safety limits.