Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add terrylica/cc-skills --skill notes-auditgit clone --depth 1 https://github.com/terrylica/cc-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/terrylica/cc-skills/notes-audit)<a href="https://agentmods.dev/skills/terrylica/cc-skills/notes-audit"><img src="https://agentmods.dev/badge/skills/terrylica/cc-skills/notes-audit.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00100 | $0.00811 |
| Opus 5 | $0.00050 | $0.00405 |
| Sonnet 5 | $0.00020 | $0.00162 |
| Haiku 4.5 | $0.00010 | $0.00081 |
Grade A, and why
notes-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 54 lines — stays where its author put it; the contents beside it link to each section on GitHub.
notes-audit — analyze, then PROPOSE (never act unilaterally)
Self-Evolving skill — if the smell table stops matching how the operator actually organizes (new smells found, false positives), evolve the table in this SKILL.md; see the Post-Execution Reflection at the bottom.
This skill is an analysis workflow, not a script: you (Claude) gather the data with the
plugin's CLIs, reason over it, and present a proposal. No reorganization happens in this
skill — execution belongs to notes-organize, only after operator approval.
1. Gather
NC="$HOME/.claude/plugins/marketplaces/cc-skills/plugins/notes-commander/scripts/notes.ts"
bun "$NC" inventory --json # folder tree + counts (fast; always do this)
bun "$NC" export # full snapshot when content-level analysis is wanted
For content-level auditing, Read the snapshot's manifest.json (note names, per-note
modified dates, char counts) and sample individual markdown files — do NOT paste hundreds of
notes into context; sample representatives per folder.
2. Analyze — look for these smells
| Smell | Signal in the data | Typical proposal |
|---|---|---|
| Empty/near-empty folders | count 0–2 |
merge into a sibling or an Archive |
| Dumping ground | one folder ≫ others (e.g. a 100+ default "Notes") | split by detected themes |
| Duplicate purpose | two folders whose names/content overlap | merge, keep the better-named one |
| Mixed-language taxonomy | sibling folders in different languages for related topics | group under one parent per domain, keep native names as leaves |
| Stale content | manifest modified dates years old across a folder |
move to Archive / <year> |
| Deep-vs-flat mismatch | 20+ flat top-level folders | introduce 3–6 domain parents, nest leaves |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 54 lines · 100 tokens per session scan A dc210d033b49
notes-audit is a skill published in the GitHub repository terrylica/cc-skills (62 stars, last pushed yesterday), licensed MIT. It adds 100 tokens to every session and 811 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
session-status
Analyzes current session state without any cleanup. Full mode (default): resolves the active plan file, reads plan checklist + TaskList, gathers unfinished work/issues from conversation history, and emits a /handoff-built next-session prompt. Mid-session mode (/session-status mid): a fast plain-language 'done vs…
ship
Commit, push, create PR(s), and auto-finalize — full automation pipeline. Handles uncommitted changes and recently created PRs.
calendar
Google Calendar integration — check schedule, create events, daily briefings, proactive reminders. Triggers on "what's on my calendar", "add to calendar", "schedule a meeting", "when am I free", "daily briefing", or any calendar-related request.
native-first
Stack-agnostic discovery playbook for finding the native, non-custom way to do something before writing any script or wrapper. Use when tempted to write a shell/python/glue script, add a dependency, or build a custom helper — and whenever a script-guards hook blocks a script write. Climbs a fixed ladder (tool's own…
configure
Set up the Telegram channel — save the bot token and review access policy. Use when the user pastes a Telegram bot token, asks to configure Telegram, asks "how do I set this up" or "who can reach me," or wants to check channel status.
github-release-management
GitHub release orchestration — automated versioning, testing, deployment, and rollback. Use when cutting a release, tagging a version, drafting release notes, or coordinating a deploy/rollback workflow.