Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/melodic-software/claude-code-plugins/audit-derivabilitynpx skills add melodic-software/claude-code-plugins --skill audit-derivabilitygit clone --depth 1 https://github.com/melodic-software/claude-code-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/melodic-software/claude-code-plugins/audit-derivability)<a href="https://agentmods.dev/skills/melodic-software/claude-code-plugins/audit-derivability"><img src="https://agentmods.dev/badge/skills/melodic-software/claude-code-plugins/audit-derivability.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00202 | $0.04763 |
| Opus 5 | $0.00101 | $0.02381 |
| Sonnet 5 | $0.00040 | $0.00953 |
| Haiku 4.5 | $0.00020 | $0.00476 |
Grade A, and why
audit-derivability scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 166 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Pre-computed context
Current branch: !git branch --show-current 2>/dev/null || echo "unknown"
Uncommitted .md files (first 20; empty = none matched or the probe returned nothing): !bash "${CLAUDE_SKILL_DIR}/scripts/uncommitted-md.sh" 20 2>/dev/null || echo "(status unavailable)"
Purpose
Docs carry a standing tax: every tracked document must be kept true as the code it describes moves, and every low-signal document a reader (human or agent) wades through costs attention. A document earns that tax only when it holds something a reader could NOT cheaply reconstruct for themselves. This skill audits one axis the siblings do not: document-level worth. Should this whole document exist at all?
The test is derivability: could a fresh agent reach this document's conclusions by natively exploring the repository, reading the code, config, metadata, and structure, without being handed the document? A document that only restates what the code already says is a derivation cache at best and dead weight at worst; a document that records why a decision was made, a constraint that is not visible in any single file, or a fact that lives outside the repo owns something exploration can never recover.
Read-only classifier: it surfaces a verdict per document with the reasoning; the author owns every deletion and rewrite. Deletion is the highest-stakes doc edit, so, like the sibling /docs-hygiene:audit-noise, this skill never applies it.
The rubric. Four factors, never derivability alone
A verdict is never "derivable, therefore delete." Derivability is one factor of four; weigh all four together. context/rubric.md holds the scoring detail this file only summarizes: factor definitions, the Diataxis fact-ownership mapping, the audience cost model, the spot-test protocol, and worked examples. Load it when a verdict is close.
| Factor | Question | Pushes toward |
|---|---|---|
| Derivable? | Could a fresh agent reconstruct these conclusions from native exploration alone? | derivable → delete/pointer; not derivable → keep |
| Re-derivation cost | If deleted, how expensive is it for the next reader to rebuild, a 2-second grep, or a multi-file investigation? | cheap → delete; expensive → keep-as-cache |
| Drift risk | How fast does the source move underneath this document, and how silently does the doc rot when it does? | high drift → delete/pointer; low drift → cache is safer |
| Fact ownership | Does the document OWN non-derivable facts. Rationale, decisions, constraints, external facts, cross-cutting invariants no single file states? | owns facts → keep, regardless of derivability of the rest |
What ships with it
7 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- context/rubric.md 11 KB
- evals/evals.json 14 KB
- evals/fixtures/decision-rationale.md 1.0 KB
- evals/fixtures/derivable-with-source/runtime-settings.md 241 B
- evals/fixtures/derivable-with-source/settings.json 210 B
- scripts/uncommitted-md.sh 1.1 KB runs code
- scripts/uncommitted-md.test.sh 3.3 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 166 lines · 202 tokens per session scan A cee93447e1d9
audit-derivability is a skill published in the GitHub repository melodic-software/claude-code-plugins (15 stars, last pushed today), licensed MIT. It adds 202 tokens to every session and 4,763 once invoked, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
parallel-orchestrator
Manage parallel Claude Code workstreams using git worktrees. Use when: splitting large tasks across multiple workers, coordinating parallel development, monitoring worker progress, integrating completed work, analyzing work item documents (code reviews, issue lists). Triggers: parallel, orchestrator, worktrees…
parallel-worker
Execute focused implementation tasks in a parallel workflow. Use when: working on assigned files in a worktree, making checkpoint commits, signaling dependencies or blockers, completing orchestrator-assigned tasks. Triggers: worker, checkpoint, worktree, assigned scope, commit prefix, parallel task.
build-priority-queue
For ordered processing: A search, Dijkstra, event simulation, task scheduling. Efficient min/max extraction with heap-based queue.
catch-expected-errors
For iteration with errors: catch exceptions during exploration, skip invalid cases, continue to next attempt.
compose-small-helpers
For complex behavior: build from tiny functions, chain transformations, make code read like a pipeline of operations.
count-combinations
For probability and counting: permutations, combinations, sample spaces, Monte Carlo simulation, brute-force enumeration, card/dice problems.