read-only-workspace-audit

read-only-workspace-audit is a skill for Claude Code, Codex from xiaojiou176-open/campus-copilot. It costs 26 tokens per session (328 once invoked), scanned A, original, MIT.

A read-only check of an imported CampusCopilot workspace snapshot. CampusCopilot is a local workspace for reviewing academic information from sites such as Canvas, Gradescope, EdStem, and MyUW.

In plain words
What is it for?
Use it to see what is open, identify which site contains particular evidence, and decide whether the snapshot is detailed enough for exports or cited AI answers.
Why use it?
It shows what evidence is available in the snapshot without pretending to know the current state of live websites or browser sessions.

Skill for Claude CodeCodex

Which agent this was written for is unclear — built for openclaw. Also seen: mentions Claude Code; mentions Codex; built for openclaw.

Good fit Use it to see what is open, identify which site contains particular evidence, and decide whether the snapshot is detailed enough for exports or cited AI answers.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/xiaojiou176-open/campus-copilot/read-only-workspace-audit
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add xiaojiou176-open/campus-copilot --skill read-only-workspace-audit
Clone the repo
git clone --depth 1 https://github.com/xiaojiou176-open/campus-copilot

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for read-only-workspace-audit

README.md
[![agentmods](https://agentmods.dev/badge/skills/xiaojiou176-open/campus-copilot/read-only-workspace-audit/github.svg)](https://agentmods.dev/skills/xiaojiou176-open/campus-copilot/read-only-workspace-audit)
Your own site
<a href="https://agentmods.dev/skills/xiaojiou176-open/campus-copilot/read-only-workspace-audit"><img src="https://agentmods.dev/badge/skills/xiaojiou176-open/campus-copilot/read-only-workspace-audit/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for read-only-workspace-audit

Your own site · 80×15
<a href="https://agentmods.dev/skills/xiaojiou176-open/campus-copilot/read-only-workspace-audit"><img src="https://agentmods.dev/badge/skills/xiaojiou176-open/campus-copilot/read-only-workspace-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 26 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 328 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00026 $0.00328
Opus 5 $0.00013 $0.00164
Sonnet 5 $0.00005 $0.00066
Haiku 4.5 $0.00003 $0.00033

Measured 11d ago against content hash 46a98ba0db05, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

read-only-workspace-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/read-only-workspace-audit/SKILL.md · 38 lines

What it actually says

Read-Only Workspace Audit

Use this skill when you have an imported CampusCopilot workspace snapshot and need to answer:

  • what is currently open
  • which site carries which evidence
  • whether the current snapshot is rich enough for export or cited AI

Rules:

  • stay read-only
  • operate on imported snapshots or exported current-view artifacts
  • do not claim live browser/session truth from snapshot-only evidence
  • keep CampusCopilot positioned as a local-first academic decision workspace

Suggested toolchain:

  1. campus-copilot summary --snapshot <path>
  2. campus-copilot site --snapshot <path> --site <canvas|gradescope|edstem|myuw>
  3. pnpm --filter @campus-copilot/mcp-server start for the generic BFF + snapshot MCP flow, or one of the site-scoped pnpm --filter @campus-copilot/mcp-readonly start:<site> commands for snapshot-only reads

Companion examples:

  • examples/integrations/codex-mcp.example.json
  • examples/integrations/claude-code-mcp.example.json
  • examples/workspace-snapshot.sample.json

Good fit:

  • Codex / Claude Code evaluation of the read-only toolbox
  • OpenClaw-style local consumers that need a strict audit trail
  • repo-local verification of whether one snapshot is ready for export, cited AI, or MCP consumption
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 38 lines · 26 tokens per session scan A 46a98ba0db05

Subscribe to this mod's changes

read-only-workspace-audit is a skill published in the GitHub repository xiaojiou176-open/campus-copilot (2 stars, last pushed 10d ago), licensed MIT. It adds 26 tokens to every session and 328 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

canvas-homework

Check Canvas for outstanding assignments and either surface the assignment, or draft a response in Max's voice. Use whenever Max asks what assignments / homework / coursework he still has to do, asks to pull an assignment's instructions or files from Canvas, or asks to start/draft an assignment. Orchestrates the…

98ping/chip · 92 tokens

myopenmath

Work a MyOpenMath / IMathAS math homework set that is launched from Canvas — read the questions, compute the answers, fill the boxes, and submit. Use whenever Max points at a MyOpenMath assignment, says a math homework is "in my Canvas", asks to do/finish/check a numbered homework like "2.1" or "2.2/2.3", or when a…

98ping/chip · 128 tokens

canvas-quiz

Work a Canvas-native quiz (Classic Quizzes) — find it, open the attempt, read every question, save it to output/, fill the answers, and stop short of submitting. Use whenever Max points at a Canvas quiz, asks about a "syllabus quiz" or a quiz he still has to take, asks what a quiz is asking, or when a Canvas…

98ping/chip · 117 tokens

mylab-pearson

Work a Pearson MyLab / MyLab Statistics / MathXL homework set or quiz — launch it through the popup, read each question, compute, fill the answer boxes, and submit. Use whenever Max points at a MyLab, MyLab Stats, Mastering, MathXL or Pearson assignment, says a stats homework is "in MyLab", asks to do/finish/check a…

98ping/chip · 181 tokens

crux

Invoke only when the user explicitly mentions $crux. When invoked, analyze papers, coach research, or support consequential decisions by finding the variable that could change the outcome, separating evidence from rhetoric, and controlling how much help to reveal. Do not activate for ordinary paper, research, or…

Sunrich-HT/crux · 70 tokens

obsidian-mindset

Build and update Obsidian learning artifacts from user questions. Use when the user wants to learn concepts, decompose requests into task queues, create or revise question notes, generate or adjust concept comparison Canvas files, compress or overwrite a recent standard artifact, convert learning outputs, or route…

rider-amazon/obsidian-mindset-skill · 70 tokens