Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/pantheon-org/tekhne/cache-auditnpx skills add pantheon-org/tekhne --skill cache-auditgit clone --depth 1 https://github.com/pantheon-org/tekhneWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pantheon-org/tekhne/cache-audit)<a href="https://agentmods.dev/skills/pantheon-org/tekhne/cache-audit"><img src="https://agentmods.dev/badge/skills/pantheon-org/tekhne/cache-audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00038 | $0.02110 |
| Opus 5 | $0.00019 | $0.01055 |
| Sonnet 5 | $0.00008 | $0.00422 |
| Haiku 4.5 | $0.00004 | $0.00211 |
Grade A, and why
cache-audit scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directorieslowAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
**Read:** `~/.claude/settings.json`, all active `CLAUDE.md` files in the project hierarchy Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
How it starts
The opening of the file, as written. The whole thing — 216 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Prompt Cache Audit Skill
Trigger: /cache-audit or "audit my caching" or "check my cache setup" or "am I breaking the cache?"
What it does: Reads your live Claude Code configuration and checks it against the 6 prompt caching rules from Anthropic's engineering team. Returns a scored report with specific, actionable fixes.
Reference: Based on Thariq Shihipar's thread "Lessons from Building Claude Code: Prompt Caching Is Everything"
When Invoked
Run all checks automatically. Do not ask for confirmation. Read the relevant files and produce the full report in one pass.
The 6 Checks
Check 1 — Prompt Ordering (Static Before Dynamic)
Read: ~/.claude/settings.json, all active CLAUDE.md files in the project hierarchy
What to look for:
- Does the system prompt load in the right order? Rule: static content first, dynamic content last
- Correct order: System prompt → Tools → CLAUDE.md → Session context → Messages
- Flag: Any dynamic content (timestamps, git status, current date, user stats) appearing in the system prompt itself
- Flag: CLAUDE.md files that include session-specific or time-sensitive data
- Pass: CLAUDE.md files that are purely static instructions, conventions, and file references
Scoring:
- PASS: System prompt is fully static, dynamic data injected via messages
- WARNING: Some dynamic data in system prompt but low-frequency change
- FAIL: High-churn dynamic content (timestamps, file contents) in system prompt
Check 2 — Dynamic Updates via Messages (not System Prompt Edits)
Read: All hook files listed under SessionStart and UserPromptSubmit in ~/.claude/settings.json
What to look for:
- Hooks should output dynamic data as
additionalContextin their JSON response (which becomes a<system-reminder>message) — not by modifying the system prompt - Check each hook's output format: does it use
hookSpecificOutput.additionalContext? ✅ - Flag: Any hook that writes to a system prompt file, modifies CLAUDE.md, or injects into the static prefix
- Pass: Hooks that return JSON with
additionalContextkey
What ships with it
12 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- evals/instructions.json 1.0 KB
- evals/scenario-1/capability.txt 66 B
- evals/scenario-1/criteria.json 651 B
- evals/scenario-1/task.md 165 B
- evals/scenario-2/capability.txt 53 B
- evals/scenario-2/criteria.json 664 B
- evals/scenario-2/task.md 155 B
- evals/scenario-3/capability.txt 56 B
- evals/scenario-3/criteria.json 654 B
- evals/scenario-3/task.md 149 B
- evals/summary.json 151 B
- references/checklist.md 389 B
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 216 lines · 38 tokens per session scan A f95a50dda311
cache-audit is a skill published in the GitHub repository pantheon-org/tekhne (10 stars, last pushed 4d ago), licensed MIT. It adds 38 tokens to every session and 2,110 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
claude-md-improver
Audit and improve CLAUDE.md files in repositories. Use when user asks to check, audit, update, improve, or fix CLAUDE.md files. Scans for all CLAUDE.md files, evaluates quality against templates, outputs quality report, then makes targeted updates. Also use when the user mentions "CLAUDE.md maintenance" or "project…
gke-reliability
Improves GKE workload reliability, using PDBs, health probes, and topology spread constraints. Use when configuring GKE workload reliability, setting up PDBs, or configuring GKE health probes (liveness, readiness, startup). Don't use for disaster recovery setup or full cluster backups (use gke-backup-dr instead).
gke-workload-security
Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running cluster security audits (auditcluster.sh), configuring Workload Identity Federation (impersonation, KSA/GSA binding, and pod setup), enforcing Network Policies (default-deny…
atlas-obscura
Search Atlas Obscura for weird, wonderful, and hidden gem places near any destination. Find the interesting stuff, not boring plaques. Search by coordinates, get full details with descriptions and images.
cf-validate
Валидация конфигурации 1С. Используй после создания или модификации конфигурации для проверки корректности.
agent-code-generator
Generates Agent definitions (.md files) based on user intent and standard templates.