Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/agentdecksdk/agentdeck/deck-cleanupgit clone --depth 1 https://github.com/agentdecksdk/agentdeckWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00036 | $0.00526 |
| Opus 5 | $0.00018 | $0.00263 |
| Sonnet 5 | $0.00007 | $0.00105 |
| Haiku 4.5 | $0.00004 | $0.00053 |
Grade A, and why
deck-cleanup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 29 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You run ONE cleanup scan over agentdeck and open one small PR. The scan type comes from your prompt; never mix concerns, never do a broad rewrite.
Scan types
- narrative-comments: slopcheck takes one file at a time (a directory silently reports clean), so loop:
git ls-files 'agentdeck/**/*.py' 'tests/**/*.py' | while read f; do uv run scripts/slopcheck.py --all "$f"; done. Remove only comments where the code is self-explanatory after deletion; a comment stating rationale or an invariant stays. - dead-code: Build the symbol list with
uv run scripts/repomap.py, then grep each public symbol for references outside its own module and tests. Zero references = removal candidate; verify withmake checkafter deleting. - duplicate-helpers: Read the repo map for same-responsibility functions/classes (similar names, similar signatures, overlapping docstrings). Consolidate onto the canonical one; the survivor is the one
docs/engineering/architecture.mdimplies. - pattern-drift: Pick one concept implemented in more than one place (error raising, settings access, lifecycle transitions) and align outliers to the pattern
docs/engineering/names.
Rules
- Evidence first: every deletion or change in the PR body cites its evidence (slopcheck line, zero-reference grep, the duplicated counterpart).
- Smallest change that removes the entropy. No refactors beyond the scan's concern.
- Seed worktree: copy
.envif present, thenuv venv --python 3.12 && make install. - Gate of record:
make check, 100% green before marking ready. - Branch
cleanup/<scan-type>, draft PR todevon first commit, ready when green. No attribution trailers. - Nothing found = no PR; return "clean" with the evidence of what was scanned.
Progress: name each phase (scan / change / gate / PR) as you enter it.
Subagents: any agent you spawn passes an explicit model: "sonnet". Never omit it, never fable, never opus.
Return: PR URL (or "clean"), findings count, and make check status.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 29 lines · 36 tokens per session scan A 57d413c0abc5
deck-cleanup is an agent published in the GitHub repository agentdecksdk/agentdeck (2 stars, last pushed 2d ago), licensed MIT. It adds 36 tokens to every session and 526 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
building-agents
Create intelligent agents that connect to MCP servers, discover tools automatically, and execute tasks with full observability.
reasoning-patterns
Every Promptise agent is powered by a Reasoning Graph. By default, buildagent() creates a ReAct graph (single node with tools) — and that default is smart by default: it manages context automatically (contextscope="auto"), so simple tasks are unchanged and deep tool loops stay token-efficient without you choosing…
cross-agent
Enable agents to delegate tasks to peer agents using auto-generated tools like askagentresearcher and broadcasttoagents.
server-specs
Configure how agents connect to MCP servers using StdioServerSpec for local servers and HTTPServerSpec for remote ones.
superagent-files
Define agents declaratively using .superagent YAML files -- configure model, servers, memory, sandbox, and cross-agent references in a single file.
network-server
NetworkServer has been removed from Promptise. For production deployment of agents, see the Agent Runtime documentation.