Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Zoverions/AXIOM-MESH --skill axiom-authority-auditorgit clone --depth 1 https://github.com/Zoverions/AXIOM-MESHWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zoverions/axiom-mesh/axiom-authority-auditor)<a href="https://agentmods.dev/skills/zoverions/axiom-mesh/axiom-authority-auditor"><img src="https://agentmods.dev/badge/skills/zoverions/axiom-mesh/axiom-authority-auditor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zoverions/axiom-mesh/axiom-authority-auditor"><img src="https://agentmods.dev/badge/skills/zoverions/axiom-mesh/axiom-authority-auditor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00056 | $0.01699 |
| Opus 5 | $0.00028 | $0.00849 |
| Sonnet 5 | $0.00011 | $0.00340 |
| Haiku 4.5 | $0.00006 | $0.00170 |
Grade A, and why
axiom-authority-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 262 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AXIOM Authority Auditor
Use this skill when an agent is considering a consequential action involving tools, APIs, files, repositories, databases, credentials, money, messages, infrastructure, personal data, other agents, or any external effect where the difference between can and may matters.
This skill is advisory only.
It does not:
- execute the proposed action;
- create authority;
- expand an existing grant;
- infer permission from capability, connectivity, credentials, or prior success;
- substitute for the policy system that actually governs the environment;
- certify AXIOM-MESH or any other runtime as secure;
- decide moral legitimacy merely because authorization exists.
Core rule
Reachability, discovery, possession of credentials, and technical capability do not create authority on their own.
When required authority cannot be established for a consequential action, treat the authority state as not established. Do not upgrade uncertainty into permission.
Procedure
Before the action, build an Authority Assessment using the ten checks below.
1. Identity
Determine who or what would act.
Ask:
- Is the actor's identity explicit?
- Is the runtime or principal distinguishable from another actor?
- Could the actor have been silently replaced, delegated, or proxied?
- Is the identity relevant to the authority evidence actually bound to that identity?
If identity is ambiguous, authority is not established.
2. Capability
State what the actor can actually do.
Separate:
- claimed capability;
- demonstrated capability;
- reachable resources;
- available tools;
- credentials or tokens currently present.
Do not treat any of these as permission.
3. Authority
Identify the exact basis for permission.
Record:
- who granted it;
- what action is permitted;
- which resource or destination is covered;
- scope and limits;
- effective time and expiry;
- whether the permission is still valid now;
- whether enforcement exists outside the agent's own intention to comply.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 262 lines · 56 tokens per session scan A 00ba9ec99043
axiom-authority-auditor is a skill published in the GitHub repository Zoverions/AXIOM-MESH (2 stars, last pushed today), licensed Apache-2.0. It adds 56 tokens to every session and 1,699 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
jacquard
Install and use Jacquard; write, check, run, format, hash, infer, test, and compile effect-typed, content-addressed .jac programs. Use for Jacquard surface syntax, capability manifests, handlers, discrete Dist models, Code values, Warp tests, canonical identity, replay, and native AOT builds.
submit
Inspect or re-submit a work unit payload. Lists work units, assembles the payload for a given ID, and optionally re-POSTs it to the proof/submit endpoint if the push hook failed.
tracer
Query the contAIned tracer database for session history, audit log, and file changes. Use when asked about past agent sessions, what files changed, what commands were run, or any audit events.
git-flow
Větvení, checkpointy a odevzdání práce přes agenticdev-git.
discovery-distribution
Run the discovery → synthesis → build → verify → elite-package → distribute loop to turn domain insight into a multi-surface, verified GitHub product. Use when productizing an idea, packaging agentic systems, or raising a repo to elite open-source standards before launch.
diagnosing-bugs
Use for defects, regressions, crashes, wrong output, or unexplained slowness.