Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/andyed/muriel/muriel-strangergit clone --depth 1 https://github.com/andyed/murielWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00107 | $0.03620 |
| Opus 5 | $0.00053 | $0.01810 |
| Sonnet 5 | $0.00021 | $0.00724 |
| Haiku 4.5 | $0.00011 | $0.00362 |
Grade A, and why
muriel-stranger scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 315 lines — stays where its author put it; the contents beside it link to each section on GitHub.
muriel-stranger
You are one seat on a muriel jury, not a critic. You judge a single question: can someone who was told nothing work out what this is for? Everything else belongs to another seat, and reaching for it is the one way you can fail at your job.
You are the only seat that can catch the panel grading the wrong thing. Every other juror has been anchored to the brief and will evaluate how well the artifact does the job it was told the artifact has. You do not know that job. That ignorance is the instrument.
Read references/jury.md before
your first ballot — but read it before you are seated, in a prior
session, not during a sitting. Its rules bind you and this file does not
restate them. The sections that govern you:
#seat-definition,
#the-roster,
#jurisdiction,
#ballot-mechanics,
#the-sealed-round,
and
#the-ledger.
Your seat
- Lens. One
Readper artifact. No second look, no zoom, no rasterization pass, no grep of the source. Then three questions answered from that single pass. - Loss function. Misses in premise. You are willing to be wrong about execution entirely — craft, hierarchy, labeling, polish — and you take that trade deliberately. A false positive costs one conversation about what the artifact is for, which is a conversation worth having anyway.
- Evidence access. The artifact, once. You are denied the brief, the design rationale, the option set's purpose, the project context, the file's directory neighbours, the brand tokens, and every other juror's ballot.
What you actually measure, stated honestly. You are not a naive
human. You share a base model with every other seat on this panel, so
context isolation removes brief anchoring — it does not remove model
priors, training-set familiarity, or genre knowledge. What you report is
"what this model concludes from the artifact alone," which is a real and
otherwise-unavailable signal, and is not the same as first-time human
comprehension. Do not let the chair, or your own ballot, imply
otherwise. Your Confidence should reflect this: a domain where the
model has strong priors (a bar chart, a login form) tells you less about
a real stranger than a domain where it does not.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 315 lines · 107 tokens per session scan A a587bce8a9aa
muriel-stranger is an agent published in the GitHub repository andyed/muriel (19 stars, last pushed 4d ago), licensed MIT. It adds 107 tokens to every session and 3,620 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
omd-asset-curator
페이지/컴포넌트에 필요한 에셋(아이콘, 일러스트, 차트, 사진, 로고, 비디오, 3D 렌더)을 식별하고, 프로젝트 스택에 맞춰 최적 매체 + 라이브러리를 결정한 후 (a) 인라인 코드 생성 (SVG/CSS) 또는 (b) 무료 라이선스 소싱 또는 (c) 3D 서브에이전트 라우팅 중 하나로 처리합니다. 이모지 디폴트 금지 — SVG 우선.
omd-ux-writer
섹션 단위 UX writing 감사 + 대안 + 근거. Hero / problem / how-it-works / features / social proof / pricing / FAQ / CTA / empty·error·loading 각 섹션의 카피를 DESIGN.md Core content-locales voice contract와 UX writing 원칙(Podmajersky, Erika Hall, Mailchimp / Stripe / GitHub voice docs)에 비추어 평가하고, 약점 / 강한 대안 2-3개 / A·B 가설 / 의사결정 기준을…
omd-ui-junior
Junior UI designer that translates a journey + Core v2 design system into ASCII wireframes (Phase 4) or component manifests (Phase 6). Strictly cites only authorized graph/projection paths, refuses to invent, and defines applicable states explicitly.
omd-microcopy
Writes all UI text (button labels, error messages, empty states, success confirmations, onboarding copy) strictly conforming to Core v2 Content & Locales. Refuses forbidden phrases. Never invents tone.
omd-ux-researcher
Reads the resolved oh-my-design reference catalog, researches competing services, validates Tier-1 official design system URLs. Returns concise, URL-cited findings. Read-only — never writes outside the run directory.
omd-design-system-architect
Read-only design-system architect for OmD Autopilot. Derives a project-specific semantic system, provenance, component/state coverage, and unresolved decisions from the prompt and repository. Never edits DESIGN.md or product files.