github-repo-audit

github-repo-audit is a skill for Claude Code, Codex from techysy/yangyu-hermes-skills. It costs 118 tokens per session (4,869 once invoked), scanned A, original, no licence file.

A review process for checking whether a GitHub repository and its release materials are complete and consistent.

In plain words
What is it for?
Use it to inspect version numbers, ZIP or CRX release packages, translations, licensing, repository cleanliness, large multilingual project structure, missing files, and whether the project can run.
Why use it?
It catches mismatches between source code and packaged files, missing project files, broken language support, and structural problems before release.

Skill for Claude CodeCodex

Which agent this was written for is unclear — body not stored (licence); the path alone says nothing.

Good fit Use it to inspect version numbers, ZIP or CRX release packages, translations, licensing, repository cleanliness, large multilingual project structure, missing files, and whether the project can run.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/techysy/yangyu-hermes-skills/github-repo-audit
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add techysy/yangyu-hermes-skills --skill github-repo-audit
Clone the repo
git clone --depth 1 https://github.com/techysy/yangyu-hermes-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for github-repo-audit

README.md
[![agentmods](https://agentmods.dev/badge/skills/techysy/yangyu-hermes-skills/github-repo-audit/github.svg)](https://agentmods.dev/skills/techysy/yangyu-hermes-skills/github-repo-audit)
Your own site
<a href="https://agentmods.dev/skills/techysy/yangyu-hermes-skills/github-repo-audit"><img src="https://agentmods.dev/badge/skills/techysy/yangyu-hermes-skills/github-repo-audit/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for github-repo-audit

Your own site · 80×15
<a href="https://agentmods.dev/skills/techysy/yangyu-hermes-skills/github-repo-audit"><img src="https://agentmods.dev/badge/skills/techysy/yangyu-hermes-skills/github-repo-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 118 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,869 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00118 $0.04869
Opus 5 $0.00059 $0.02434
Sonnet 5 $0.00024 $0.00974
Haiku 4.5 $0.00012 $0.00487

Measured 10d ago against content hash bcec75115c9e, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

github-repo-audit scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

The scan reads SKILL.md. This mod also ships 1 executable file (scripts/audit_repo.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

import zipfile, json, urllib.request
skills/software-development/github-repo-audit/SKILL.md · 244 lines

The source is not reproduced here

No licence file

A repository with no LICENSE is all rights reserved by default, so the body is not copied here. The metadata, the measurements and the link are.

Read it on GitHub

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 244 lines · 118 tokens per session scan A bcec75115c9e

Subscribe to this mod's changes

github-repo-audit is a skill published in the GitHub repository techysy/yangyu-hermes-skills (5 stars, last pushed 16d ago), with no licence file. It adds 118 tokens to every session and 4,869 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

mx-pr

Draft a pull request from the feature spec and git log, run an autonomous commit-history cleanup (content check), then publish to GitHub or GitLab (Bitbucket experimental) — or hand off. Use when a feature branch is ready for PR, standalone or from mx-flow. Usage: /mx-pr [name].

maxence2997/mx-harness · 67 tokens

breaking-change-audit

Audit shipctl's public interface before a release — compare flags, exit codes, and output formats against the previous tag to catch accidental breaking changes. Use when preparing a release, when asked to "check for breaking changes", or as a gate before tagging a new version.

zakelfassi/skills-driven-development · 59 tokens

git-conventional-commits

Author standardized conventional commit messages (feat, fix, docs, refactor, chore), generate automated semver releases, and format pull request descriptions.

pedroiff0/awesome-skills · 36 tokens

github-profile-readme

Build or rewrite a GitHub profile README (the username/username special repo) with a personalized theme — animated SVG banner, stats cards, contribution snake, tech badges, project/research tables. Includes the git conflict pitfall when the local clone is stale vs GitHub web edits, and the PyYAML on: quirk for…

pedroiff0/awesome-skills · 76 tokens

github-repo-management

Clone/create/fork repos; manage remotes, releases.

clowlove/Hermes-House · 17 tokens

github-pr-workflow

Complete guide for managing the PR lifecycle. Each section shows the gh way first, then the git + curl fallback for machines without gh.

AtlasOmnia/donna-starter · 25 tokens