Assumption Audit

Assumption Audit is a skill for Claude Code, Codex from zgbrenner/agentcounsel. It costs 50 tokens per session (1,197 once invoked), scanned A, original, MIT.

An audit of the assumptions and missing information behind a legal draft, including facts, documents, jurisdiction, deadlines, client role, and business decisions.

In plain words
What is it for?
Use it to identify follow-up questions, placeholders, escalation items, and unresolved issues in memos, reviews, updates, letters, and risk tables.
Why use it?
It reveals where a draft may have silently filled gaps or reached a conclusion that depends on facts not yet confirmed.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it to identify follow-up questions, placeholders, escalation items, and unresolved issues in memos, reviews, updates, letters, and risk tables.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/zgbrenner/agentcounsel/assumption-audit
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add zgbrenner/agentcounsel --skill assumption-audit
Clone the repo
git clone --depth 1 https://github.com/zgbrenner/agentcounsel

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for Assumption Audit

README.md
[![agentmods](https://agentmods.dev/badge/skills/zgbrenner/agentcounsel/assumption-audit/github.svg)](https://agentmods.dev/skills/zgbrenner/agentcounsel/assumption-audit)
Your own site
<a href="https://agentmods.dev/skills/zgbrenner/agentcounsel/assumption-audit"><img src="https://agentmods.dev/badge/skills/zgbrenner/agentcounsel/assumption-audit/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for Assumption Audit

Your own site · 80×15
<a href="https://agentmods.dev/skills/zgbrenner/agentcounsel/assumption-audit"><img src="https://agentmods.dev/badge/skills/zgbrenner/agentcounsel/assumption-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 50 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,197 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00050 $0.01197
Opus 5 $0.00025 $0.00598
Sonnet 5 $0.00010 $0.00239
Haiku 4.5 $0.00005 $0.00120

Measured 9d ago against content hash b5f07b2ebae8, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

Assumption Audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/legal-methodology/assumption-audit/SKILL.md · 103 lines

How it starts

The opening of the file, as written. The whole thing — 103 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Assumption Audit

Purpose

Audit a draft legal output for assumptions and unresolved gaps. The skill extracts explicit assumptions, hidden assumptions, missing facts, missing documents, jurisdiction gaps, deadline gaps, client-role ambiguity, attorney escalation items, business decision points, and professional-responsibility concerns.

It then recommends revisions or placeholders for any output that relies on unresolved assumptions.

Use When

  • A draft may have filled gaps silently or treated uncertain facts as established.
  • A document review, research memo, client update, demand letter, or risk matrix contains assumptions or missing-input notes.
  • The user asks what facts are still needed, what assumptions are built into the analysis, or what could change the conclusion.
  • A matter is moving from a draft output into attorney review or a matter workspace.

Required Inputs

  • The complete draft to audit.
  • The source documents, user facts, and instructions available for comparison.
  • The intended use, audience, client role, and jurisdiction if known.

If the draft is missing, stop and request it. If source materials are missing, audit the draft internally and mark the source-comparison limitation.

Do Not Use When

  • The task is to supply missing facts or legal analysis. This skill identifies gaps; it does not fill them.
  • The user wants a final legal conclusion despite missing information.
  • The task is citation-focused; use citation-integrity-check or source-validation.
  • Produce draft legal work product for attorney review. This is not legal advice.
  • Follow core/source-and-citation-discipline.md and core/jurisdiction-and-deadline-gates.md.
  • Do not resolve missing facts, documents, jurisdiction, deadlines, or client-role ambiguity by guessing.
  • Do not convert an assumption into a fact. Label assumptions and route them for confirmation.
  • Preserve confidentiality and privilege.

Workflow

  1. Confirm scope and inputs. Identify the draft type, source materials, intended use, audience, and known jurisdiction/client role.
  2. Extract explicit assumptions. List every statement labeled as assumption, premise, caveat, limitation, or subject-to-confirmation item.
  3. Find hidden assumptions. Identify conclusions that depend on unstated facts, documents, legal rules, party status, timing, client objectives, or business decisions.
  4. Find missing facts. List absent facts that could change the analysis, risk rating, recommendation, or tone.
  5. Find missing documents. List agreements, amendments, exhibits, policies, communications, filings, source law, or evidence the draft appears to need.
  6. Audit jurisdiction and deadlines. Flag missing or assumed jurisdiction, governing law, venue, agency, court, effective dates, filing dates, response dates, notice periods, and other legal dates.
  7. Audit client-role ambiguity. Identify uncertainty about who the client is, who the output protects, what side the client is on, and whether conflicts or privilege concerns may exist.
  8. Identify escalation items. Flag attorney judgment items, business decision points, professional-responsibility concerns, and confidentiality/privilege concerns.
  9. Recommend safer markings. For each unresolved assumption or gap, recommend a revision, placeholder, or stop-and-ask item.

Read the full file on GitHub · 103 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 103 lines · 50 tokens per session scan A b5f07b2ebae8

Subscribe to this mod's changes

Assumption Audit is a skill published in the GitHub repository zgbrenner/agentcounsel (19 stars, last pushed 1mo ago), licensed MIT. It adds 50 tokens to every session and 1,197 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

claim-verification-checklist

Generates a point-by-point checklist of every verifiable claim in a draft article, categorized by claim type and accompanied by the specific evidence needed to confirm each one.

ur-grue/autopunk-media-skills · 39 tokens

legal-research

A legal research skill for finding and analysing laws and court cases, including similar cases. It requires access to a reliable legal research database before producing a formal report.

code-lawyer/Legal-Agent-Skills · 144 tokens

document-fill

A document-filling assistant that uses a supplied template and case files to fill in forms, contracts, or legal documents. It also reports where each filled value came from and which details are missing.

code-lawyer/Legal-Agent-Skills · 61 tokens

contract-review

A contract-review workflow for agreements governed by Chinese law, United States law, or both. It examines clauses one by one and produces a list of legal-risk questions, with an optional marked-up Word document.

code-lawyer/Legal-Agent-Skills · 86 tokens

fedramp

Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). Use this skill whenever a user asks about FedRAMP authorization, ATO (Authority to Operate), cloud security for federal government, NIST SP 800-53 controls, CSP compliance, or any of the core FedRAMP document…

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance · 236 tokens

eu-cra

Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the EU. Use this skill for gap analysis, product classification (Default / Class I / Class II), conformity assessment route…

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance · 133 tokens