audit

audit is a skill for Claude Code, Codex from mifunedev/openharness. It costs 125 tokens per session (1,634 once invoked), scanned A, original, Apache-2.0.

An audit dispatcher that routes requests to checks for implementations, pull requests, pull-request queues, test harnesses, context budgets, skills, evaluation quality, and framework drift. A pull request is a proposed code change awaiting review.

In plain words
What is it for?
Use it to audit a task or pull request, triage open pull requests, inspect harness or context health, review skill integrity, check evaluation quality, detect drift, or run a full campaign.
Why use it?
It provides a defined audit target and result for different kinds of review instead of guessing what should be checked from vague wording.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/mifunedev/openharness/audit
Any agent
npx skills add mifunedev/openharness --skill audit
Clone the repo
git clone --depth 1 https://github.com/mifunedev/openharness

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for audit

README.md
[![agentmods](https://agentmods.dev/badge/skills/mifunedev/openharness/audit.svg)](https://agentmods.dev/skills/mifunedev/openharness/audit)
Your own site
<a href="https://agentmods.dev/skills/mifunedev/openharness/audit"><img src="https://agentmods.dev/badge/skills/mifunedev/openharness/audit.svg" alt="Measured on agentmods" height="20"></a>
Per session 125 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,634 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00125 $0.01634
Opus 5 $0.00063 $0.00817
Sonnet 5 $0.00025 $0.00327
Haiku 4.5 $0.00013 $0.00163

Measured 4d ago against content hash 78a2fddd6d75, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

The scan reads SKILL.md. This mod also ships 6 executable files (scripts/audit-evidence.sh, scripts/audit-run.sh, scripts/implementation-gates.sh, …), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.oh/skills/audit/SKILL.md · 109 lines

How it starts

The opening of the file, as written. The whole thing — 109 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Audit — explicit target dispatcher

Usage validation happens before any reference is read, run identity is created, or state changes. The dispatcher never guesses a missing target from prose. Trigger families include: audit this task; audit PR N; triage the PR queue; audit the harness; audit context budget; audit skills; lint evals; check framework drift; and full audit campaign.

Canonical usage

usage: /audit <implementation|pr|prs|harness|context|skills|eval-quality|drift|full> [target options]
Target Invocation Native result
implementation /audit implementation <slug> [--pr N --repo O/N] [--base B] [--branch B] AUDIT-PASS / AUDIT-FAIL
pr /audit pr <N> [--repo O/N] [--base B] [--deep] [--proof] [--dry-run] PR-AUDIT-PROMOTABLE / PR-AUDIT-BLOCKED / PR-AUDIT-UNKNOWN
prs /audit prs [--repo O/N] [filters/actions] buckets + PRS-AUDIT-COMPLETE / PRS-AUDIT-PARTIAL
harness `/audit harness [--focus area] [--external URL path] [actions]`
context `/audit context [all --baseline]`
skills `/audit skills [all root
eval-quality `/audit eval-quality [all probes
drift /audit drift per-class OK / aggregate DRIFT:
full /audit full [--repo O/N] [--focus area] [--health-target target] AUDIT-CAMPAIGN-COMPLETE / AUDIT-CAMPAIGN-PARTIAL

For missing/unknown targets or missing required arguments, print the exact usage line and this table, then stop. Exactly these nine cases are public:

Target Authoritative route
implementation references/implementation.md
pr references/pr.md
prs references/prs.md
harness references/harness.md
context references/context.md
skills references/skills.md
eval-quality references/eval-quality.md
drift references/drift.md
full references/full.md

Read the full file on GitHub · 109 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 109 lines · 125 tokens per session scan A 78a2fddd6d75

Subscribe to this mod's changes

audit is a skill published in the GitHub repository mifunedev/openharness (36 stars, last pushed 4d ago), licensed Apache-2.0. It adds 125 tokens to every session and 1,634 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

data-visualization

Use for creating publication-quality charts and multi-panel analysis summaries. Triggers when tasks involve visualizing data, plotting results, creating charts, or producing visual reports from analysis output.

langchain-ai/deepagents · 40 tokens

cuml-machine-learning

Use for GPU-accelerated machine learning on tabular data using NVIDIA cuML. Triggers when tasks involve classification, regression, clustering, dimensionality reduction, or model training on datasets.

langchain-ai/deepagents · 43 tokens

blog-post

Writes and structures long-form blog posts, creates tutorial outlines, and optimizes content for SEO with cover image generation. Use when the user asks to write a blog post, article, how-to guide, tutorial, technical writeup, thought leadership piece, or long-form content.

langchain-ai/deepagents · 58 tokens

social-media

Drafts engaging social media posts, writes hooks, suggests hashtags, creates thread structures, and generates companion images. Use when the user asks to write a LinkedIn post, tweet, Twitter/X thread, social media caption, social post, or repurpose content for social platforms.

langchain-ai/deepagents · 58 tokens

remember

Review the current conversation and capture valuable knowledge — best practices, coding conventions, architecture decisions, workflows, and user feedback — into persistent memory (AGENTS.md) or reusable skills. Use when the user says: (1) remember this, (2) save what we learned, (3) update memory, (4) capture…

langchain-ai/deepagents · 71 tokens

textual-screenshot

Capture a Textual terminal UI as an SVG using its headless test harness. Use when asked to make, attach, or preview a screenshot of deepagents-code/dcode or another Textual app, visually verify a TUI state, or render a modal, screen, or widget without a desktop or browser.

langchain-ai/deepagents · 67 tokens