Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/pekral/cursor-rules/production-auditnpx skills add pekral/cursor-rules --skill production-auditgit clone --depth 1 https://github.com/pekral/cursor-rulesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pekral/cursor-rules/production-audit)<a href="https://agentmods.dev/skills/pekral/cursor-rules/production-audit"><img src="https://agentmods.dev/badge/skills/pekral/cursor-rules/production-audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00055 | $0.01820 |
| Opus 5 | $0.00028 | $0.00910 |
| Sonnet 5 | $0.00011 | $0.00364 |
| Haiku 4.5 | $0.00006 | $0.00182 |
Grade A, and why
production-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 95 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Production Audit
Constraints
- Read-only skill — never modify code, never run any git write operation (
git add,git commit,git push,git reset,git checkout -- …,git stash). Reading the working tree, diff, and log is the entire job; output is the audit report only. - Local evidence only — work from the local repository, git history, CI config, and committed files. Never upload repo contents, diffs, or secrets to any external service. If a deployed URL is in scope, restrict to your own HTTP/browser checks; do not exfiltrate data.
- Never print secrets. If a secret is found committed, name the file and key, not the value.
- This is a readiness audit, not a vulnerability audit — exploit-level findings belong to
@skills/security-review/SKILL.mdand@skills/laravel-security/SKILL.md; reference them, do not duplicate them. - Apply
@rules/git/general.mdcwhen reading the release surface,@rules/code-review/general.mdcfor risk judgement,@rules/laravel/laravel.mdcand@rules/laravel/architecture.mdcfor Laravel boundaries,@rules/security/backend.mdfor the auth/data/secret lenses, and@rules/reports/general.mdcfor report language.
Use when
- Someone asks "is this production-ready?", "can we ship this?", or "what could break in production?".
- A pre-release / pre-deploy gate is needed for a branch, PR, or the whole app.
- A go/no-go decision is wanted with a concrete list of blockers and fixes, fast, without external tooling.
Defer to security-review/laravel-security for deep vulnerability hunting, to @skills/docker-patterns/SKILL.md for Docker image correctness, and to @skills/code-review/SKILL.md for line-level code quality. This skill consumes their concerns as readiness signals; it does not replace them.
Execution
1. Establish the release surface (git, local)
git status— uncommitted or untracked work that would not ship, or worse, would.git log --oneline origin/master..HEAD(or the project default branch) — what this release actually contains.git diff origin/master...HEAD --statthen targetedgit diffon the riskiest files — the concrete change set to judge.- Scope the audit to this surface. A whole-app audit only when no branch/PR is named.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 95 lines · 55 tokens per session scan A b43bc84f47ac
production-audit is a skill published in the GitHub repository pekral/cursor-rules (6 stars, last pushed 4d ago), licensed MIT. It adds 55 tokens to every session and 1,820 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
data-charts-tako
Search and visualize the world's data - get charts, insights, and embeddable knowledge cards for finance, economics, demographics, sports, and more.
monorepo-management
Master monorepo management with Turborepo, Nx, and pnpm workspaces to build efficient, scalable multi-package repositories with optimized builds and dependency management. Use when setting up monorepos, optimizing builds, or managing shared dependencies.
browse-and-evaluate
Use when exploring the ai-agent-skills catalog to find, compare, and evaluate skills before installing. Always use --fields to limit output size and --dry-run before committing to an install.
skill-benchmark
Benchmark AI skill effectiveness by measuring implementation quality against legacy constraints.
render-airdrop-carousel
Assemble a viral iOS "AirDrop" notification-carousel video ad (≈6–8s, 9:16) from a brand line plus 6–16 real product photos — a native AirDrop share-sheet card ("Brand would like to share a · Decline / Accept") springs up and its preview window CYCLES through the products, landing on a range/lineup payoff with an…
render-3d-product-showcase
Assemble a premium 3D product-showcase ad from a config — four beat clips (an orbiting hero rotation, a macro push-in, a physics reveal, a typographic close) normalized to the brand-color canvas, hard-concatenated in order, closed on a deterministic Playwright brand end card, and mixed under one instrumental bed at…