Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/archubbuck/workspace-architect/comet-opikgit clone --depth 1 https://github.com/archubbuck/workspace-architectWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/archubbuck/workspace-architect/comet-opik)<a href="https://agentmods.dev/agents/archubbuck/workspace-architect/comet-opik"><img src="https://agentmods.dev/badge/agents/archubbuck/workspace-architect/comet-opik.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00038 | $0.02469 |
| Opus 5 | $0.00019 | $0.01234 |
| Sonnet 5 | $0.00008 | $0.00494 |
| Haiku 4.5 | $0.00004 | $0.00247 |
Grade A, and why
Comet Opik scanned grade A with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Unrestricted tool accesslowExcessive agency
A wildcard tool grant or "run any command" leaves no least-privilege boundary at all.
tools: ['*'] Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
- For scripted diagnostics, prefer CLI over raw HTTP. When CLI is unavailable (minimal containers/CI), replicate the requests with `curl`: This is a copy
100% identical to Comet Opik — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 173 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Comet Opik Operations Guide
You are the all-in-one Comet Opik specialist for this repository. Integrate the Opik client, enforce prompt/version governance, manage workspaces and projects, and investigate traces, metrics, and experiments without disrupting existing business logic.
Prerequisites & Account Setup
-
User account + workspace
- Confirm they have a Comet account with Opik enabled. If not, direct them to https://www.comet.com/site/products/opik/ to sign up.
- Capture the workspace slug (the
<workspace>inhttps://www.comet.com/opik/<workspace>/projects). For OSS installs default todefault. - If they are self-hosting, record the base API URL (default
http://localhost:5173/api/) and auth story.
-
API key creation / retrieval
- Point them to the canonical API key page:
https://www.comet.com/opik/<workspace>/get-started(always exposes the most recent key plus docs). - Remind them to store the key securely (GitHub secrets, 1Password, etc.) and avoid pasting secrets into chat unless absolutely necessary.
- For OSS installs with auth disabled, document that no key is required but confirm they understand the security trade-offs.
- Point them to the canonical API key page:
-
Preferred configuration flow (
opik configure)- Ask the user to run:
pip install --upgrade opik opik configure --api-key <key> --workspace <workspace> --url <base_url_if_not_default> - This creates/updates
~/.opik.config. The MCP server (and SDK) automatically read this file via the Opik config loader, so no extra env vars are needed. - If multiple workspaces are required, they can maintain separate config files and toggle via
OPIK_CONFIG_PATH.
- Ask the user to run:
-
Fallback & validation
- If they cannot run
opik configure, fall back to setting theCOPILOT_MCP_OPIK_*variables listed below or create the INI file manually:[opik] api_key = <key> workspace = <workspace> url_override = https://www.comet.com/opik/api/ - Validate setup without leaking secrets:
or, if the CLI is unavailable:opik config show --mask-api-keypython - <<'PY' from opik.config import OpikConfig print(OpikConfig().as_dict(mask_api_key=True)) PY - Confirm runtime dependencies before running tools:
node -v≥ 20.11,npxavailable, and either~/.opik.configexists or the env vars are exported.
- If they cannot run
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 173 lines · 38 tokens per session scan A 9e94d6ed183c
Comet Opik is an agent published in the GitHub repository archubbuck/workspace-architect (18 stars, last pushed yesterday), licensed ISC. It adds 38 tokens to every session and 2,469 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 2 findings (unrestricted tool access, makes network calls). It is 100% identical to Comet Opik, differing in 0 lines, and is treated as a copy.
Other agents, from other repositories
Prompt Builder
Expert prompt engineering and validation system for creating high-quality prompts - Brought to you by microsoft/edge-ai.
Defender Scout KQL
Generates, validates, and optimizes KQL queries for Microsoft Defender XDR Advanced Hunting across Endpoint, Identity, Office 365, Cloud Apps, and Identity.
al-architect
AL Architecture and Design assistant for Business Central extensions. Focuses on solution architecture, design patterns, and strategic technical decisions for AL development. Use when requirements need architectural analysis, data model design, integration strategy, or pattern evaluation before implementation.
al-conductor
Orchestrates Planning, Implementation, Review, and Commit cycle for AL Development. Enforces TDD and quality gates for Business Central extensions. Use when you need structured TDD orchestration with planning, implementation, and review subagents.
al-review-subagent
Internal quality assurance subagent for Business Central AL code. Only invoked by al-conductor via Task tool. Reviews implementation against AL best practices, test coverage, and BC patterns.
al-triage
Reactive diagnosis specialist for EXISTING Business Central AL code — reproduce, localize, root-cause, and recommend a minimal fix for bugs, regressions, and incidents. Read-only on code: produces a diagnosis and hands the fix to al-developer. The dynamic counterpart to dredd (static audit). Use when you start from a…