Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/synvoya/codeinspectus/codeinspectus-fix-onenpx skills add Synvoya/codeinspectus --skill codeinspectus-fix-onegit clone --depth 1 https://github.com/Synvoya/codeinspectusWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00076 | $0.00680 |
| Opus 5 | $0.00038 | $0.00340 |
| Sonnet 5 | $0.00015 | $0.00136 |
| Haiku 4.5 | $0.00008 | $0.00068 |
Grade A, and why
codeinspectus-fix-one scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Fix One CodeInspectus Finding
Treat an "accepted finding" as one finding the user selected for investigation. Do not interpret the local triage state Accepted as reproduction, patch, or checkpoint approval.
- Establish the exact case.
- Require one prior
scan_id, one finding ID, and the exact target path. - Load that stored scan and finding. Stop if either identity or scope differs.
- Keep every other finding out of the patch. Report unrelated findings separately.
- Require one prior
- Adjudicate before changing code.
- Inspect the source, sink, controls, and reachability in repository context.
- Classify the target as actionable, disproven, or unverified. A scanner match is evidence, not exploitability proof.
- If disproven, explain the evidence and stop without editing. Do not call it
resolved.
- Gate reproduction independently.
- Do not reproduce by default. Propose only a bounded, local, reversible, non-destructive reproduction.
- Reproduce only after explicit user approval. Never expose secrets, attack external systems, alter production, or execute unsafe target content.
- If reproduction is unsafe or impractical, record that proof gap and continue with static evidence only if a safe patch can still be justified.
- Design a focused regression.
- Identify or propose the smallest test that traces to this finding. Do not add it yet.
- Propose one minimal edit set.
- Show the intended source and test files, behavior change, test, risks, and exclusions.
- Ask for patch approval separately from investigation, triage, reproduction, or checkpoint approval. Do not edit before approval.
- If rejected, stop with no edit.
- Apply only the approved test and source patch.
- Make no source or test edit before explicit patch approval.
- Add the focused regression first and capture failing-before-fix evidence when practical. If the test cannot run or does not reproduce the condition, stop before the source patch unless the user explicitly accepts that named proof gap.
- Preserve unrelated behavior and findings. Do not opportunistically refactor or batch adjacent issues.
- Verify in separate evidence lanes.
- Run the focused regression, then relevant surrounding tests. Report failures as test evidence.
- Call
codeinspectus_rescanwith the same target path and the exact originalscan_idasprior_scan_id; never rely on the most-recent-scan default. - Claim scanner resolution only when the target appears in CodeInspectus
resolved. Treatremainingas unresolved andnot_recheckedas a proof gap. Never convert missing coverage into success.
- Report four sections: investigation evidence, regression evidence, test evidence, and rescan/proof gaps. List unrelated remaining or introduced findings without fixing them.
Keep CodeInspectus itself read-only. The agent owns only the separately approved source and test edits.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 39 lines · 76 tokens per session scan A a5ad33ff3b39
codeinspectus-fix-one is a skill published in the GitHub repository Synvoya/codeinspectus (44 stars, last pushed 7d ago), licensed Apache-2.0. It adds 76 tokens to every session and 680 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
dast-config
Reviews DAST tool configurations against OWASP Top 10:2021 and OWASP Testing Guide v4.2. Auto-invoked when reviewing OWASP ZAP configurations, DAST CI/CD integration, scan policies, or authenticated scanning setups. Produces a DAST maturity assessment covering scan policy configuration, active vs passive scanning, API…
sast-config
Reviews and tunes SAST tool configurations against OWASP ASVS 4.0.3 and CWE Top 25. Auto-invoked when reviewing Semgrep rules, CodeQL queries, SAST CI integration, or false positive triage workflows. Produces a SAST maturity assessment covering rule authoring, severity tuning, custom rule development, and CI…
secrets-management
Performs a structured secrets management review against OWASP Secrets Management Cheat Sheet and NIST SP 800-57 Part 1 Rev 5 (Recommendation for Key Management). Auto-invoked when reviewing secret handling patterns, vault configurations, .env files, or credential rotation policies. Produces a secrets management…
pipeline-security
Reviews CI/CD pipeline configurations against SLSA v1.0 build levels and OWASP Top 10 CI/CD Security Risks. Auto-invoked when reviewing GitHub Actions workflows, GitLab CI configs, Jenkins pipelines, or when discussing supply chain security. Produces a pipeline security assessment with SLSA level determination and…
forensics-kit
Digital forensics and incident response toolbox. Load when the operator asks about a pcap, a binary, a memory dump, a suspicious file, malware triage, IOC hunting, or post-incident analysis. Covers network (tshark), binaries (radare2, strings, binwalk, file, exiftool), memory (volatility), and pattern matching (YARA).…
agents-sdk
Build AI agents on Cloudflare Workers using the Agents SDK. Load when creating stateful agents, durable workflows, real-time WebSocket apps, scheduled tasks, MCP servers, or chat applications. Covers Agent class, state management, callable RPC, Workflows integration, and React hooks.