Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

rymac-4r-icm-audit

ASecurity

Runs the 4R audit (Read, Run, Reality, Report) on an ICM workspace or any folder system an AI works from. Reads the structure, has a fresh agent with no memory do 1 real job in a throwaway copy, plants real mistakes to prove the guards catch them, and writes a plain English report with ranked fixes and file and line evidence. Use when the user says "am I crazy", "am I crazy?", "4R audit", "audit my ICM", "audit this ICM", "run the audit", "audit day", "is my workspace drifting", "am I driftin...

3 stars
0 votes
0 copies
0 views
Added 9/28/2026
ai-agentsgobashgit

Works with

cli

Security Analysis

A100/100

Scanned 9/28/2026

Install to Claude Code

$npx -y skills add oathdriven/rymac-4r-icm-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of rymac-4r-icm-audit?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for rymac-4r-icm-audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/oathdriven-rymac-4r-icm-audit/badge)](https://www.skillsdirectory.com/skills/oathdriven-rymac-4r-icm-audit)

More formats (shields.io, HTML) on the badges page.

Files
SKILL.md
---
name: rymac-4r-icm-audit
description: Runs the 4R audit (Read, Run, Reality, Report) on an ICM workspace or any folder system an AI works from. Reads the structure, has a fresh agent with no memory do 1 real job in a throwaway copy, plants real mistakes to prove the guards catch them, and writes a plain English report with ranked fixes and file and line evidence. Use when the user says "am I crazy", "am I crazy?", "4R audit", "audit my ICM", "audit this ICM", "run the audit", "audit day", "is my workspace drifting", "am I drifting", or asks whether a folder system, an agent folder, or an ICM workspace actually works. Make sure to use this skill whenever someone doubts their ICM setup or asks for an audit of one.
argument-hint: [target folder · blank = the workspace this session is in]
---

# The 4R audit: Read, Run, Reality, Report

A look at the files tells you what a workspace SAYS. Only running the workspace tells you
what it DOES. This audit does both, then proves the guards catch what they claim to catch.

Supporting files, read each 1 when its layer starts:
- `references/read.md`: layer 1, the 8 questions and the script behind each
- `references/run.md`: layer 2, the cold walk and the prompt for the fresh agent
- `references/reality.md`: layer 3, planting mistakes and checking the claims that say done
- `references/report.md`: layer 4, the shape of the report and the record
- `templates/report.html`: the report page, fill the slots
- `templates/record.md`: the record kept in the results home

Scripts, run them, do not read them: `scripts/routes.sh`, `scripts/nested-repos.sh`,
`scripts/secrets.sh`, `scripts/placeholders.sh`, `scripts/guards.sh`,
`scripts/copy-target.sh`. `scripts/selftest.sh` proves every script on planted cases.
Run it first on a new machine.

## The 3 promises this audit keeps

1. **The target is never changed.** Not 1 byte. Everything that runs, writes, or gets
   planted happens in a throwaway copy outside the target. An audit that edits what it
   measures has measured itself.
2. **Every finding cites a file and a line, or a command and its output.** No citation, no
   finding. Unknown is an honest answer. A guess is not.
3. **No invented score.** The report gives counts that were counted (routes that resolve,
   guards proven, places a stranger got stuck) and ranked fixes. Never a grade out of 100.

## Setup, before layer 1

1. **Target:** the folder in the arguments, else the workspace this session is in (walk up
   to the folder holding the root `CLAUDE.md`).
2. **Results home:** if the target's `CLAUDE.md` or `CONTEXT.md` names a home for 4R
   audits, use that folder and leave that folder out of every layer. Otherwise use a folder
   named `4r-audits/` beside the target, never inside the target.
3. **Scratch copy:** `bash scripts/copy-target.sh <target> <scratch>` into the session's
   temp or scratch folder. Layers 2 and 3 only ever touch the scratch copy.
4. **Last audit:** if the results home holds an earlier record for this target, read the
   record. The change since last time is the headline of the report.

## The 4 layers, in order. Copy this and tick each 1 off

- [ ] **1. READ.** Answer the 8 questions in `references/read.md`. 6 of them have a script.
      Run the scripts, never answer those 6 by reading alone.
- [ ] **2. RUN.** Pick 1 real job the workspace exists to do. Hand the scratch copy and the
      job to a fresh agent with the prompt in `references/run.md`. Record whether the job got
      done, how many files the agent read before knowing where to go, and every place the
      agent got stuck, each with file and line.
- [ ] **3. REALITY.** For the 3 biggest promises the workspace makes, plant 1 mistake each
      guard should catch and 1 clean case the guard should pass, in the scratch copy or on a
      copy of the guard's input. Then check 3 claims that say done, live, or approved against
      the thing each claim describes. `references/reality.md` has the method.
- [ ] **4. REPORT.** Write the record into the results home with `templates/record.md`, then
      the page with `templates/report.html`. The 3 fixes are ranked by what each 1 would
      have cost the owner. Say plainly what the audit could not see.

## Rules

1. **Run the layers in order.** Layer 2 often explains a layer 1 finding, and layer 3 often
   shows a layer 1 guard never worked.
2. **A rule held only by a sentence is a finding, even when everyone obeys the rule.** A
   sentence works until the day the agent forgets the sentence.
3. **A guard that exists is not a guard that works.** Only a planted mistake proves a guard.
4. **When torn between 2 readings, take the harsher 1 and say you were torn.**
5. **Write for the owner, not for a builder.** Plain words a 9th grader follows. Any
   technical word gets explained in the same sentence. Numbers as digits.
6. **Name what the audit could not see**: a folder too big to copy, a guard that needs a paid
   service, a job the workspace cannot do without a person.
7. **Never fix during the audit.** Fixes come after the report, in their own pass, followed by
   a re-audit so the change is measured.

## Credit

ICM, Interpretable Context Methodology, is Jake Van Clief and David McDermott's method,
https://arxiv.org/abs/2603.16021. The 4R audit is RyMac's own instrument (filesnfolders.com).
2 ideas in layer 1 come from Jake's own ICM audit, written fresh in these words: a rule that
lives only in a sentence, and an example that breaks the rule printed beside it.

Attribution

oathdrivenoathdriven
View sourceMore from oathdriven →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

695601 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →