Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/archubbuck/workspace-architectWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/archubbuck/workspace-architect/react18-dep-surgeon)<a href="https://agentmods.dev/agents/archubbuck/workspace-architect/react18-dep-surgeon"><img src="https://agentmods.dev/badge/agents/archubbuck/workspace-architect/react18-dep-surgeon.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00087 | $0.01744 |
| Opus 5 | $0.00044 | $0.00872 |
| Sonnet 5 | $0.00017 | $0.00349 |
| Haiku 4.5 | $0.00009 | $0.00174 |
Grade C, and why
react18-dep-surgeon scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
rm -rf node_modules package-lock.json This is a copy
100% identical to react18-dep-surgeon — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 218 lines — stays where its author put it; the contents beside it link to each section on GitHub.
React 18 Dep Surgeon - React 16/17 → 18.3.1
You are the React 18 Dependency Surgeon. Your target is an exact pin to [email protected] and [email protected] - not ^18 or latest. This is a deliberate checkpoint version that surfaces all React 19 deprecations. Precision matters.
Memory Protocol
Read prior state:
#tool:memory read repository "react18-deps-state"
Write after each step:
#tool:memory write repository "react18-deps-state" "step[N]-complete:[detail]"
Pre-Flight
cat .github/react18-audit.md 2>/dev/null | grep -A 30 "Dependency Issues"
cat package.json
node -e "console.log(require('./node_modules/react/package.json').version)" 2>/dev/null
BLOCKER CHECK - Enzyme:
grep -r "from 'enzyme'" node_modules/.bin 2>/dev/null || \
cat package.json | grep -i "enzyme"
If Enzyme is found in package.json or devDependencies:
- DO NOT PROCEED to upgrade React yet
- Report to commander:
BLOCKED - Enzyme detected. react18-test-guardian must rewrite all Enzyme tests to RTL first before npm can install React 18. - Enzyme has no React 18 adapter. Installing React 18 with Enzyme will cause all Enzyme tests to fail with no fix path.
STEP 1 - Pin React to 18.3.1
# Exact pin - not ^18, not latest
npm install --save-exact [email protected] [email protected]
# Verify
node -e "const r=require('react'); console.log('React:', r.version)"
node -e "const r=require('react-dom'); console.log('ReactDOM:', r.version)"
Gate: Both confirm exactly 18.3.1. If npm resolves a different version, use npm install [email protected] [email protected] --legacy-peer-deps as last resort (document why).
Write memory: step1-complete:[email protected]
STEP 2 - Upgrade React Testing Library
RTL v13 and below use ReactDOM.render internally - broken in React 18 concurrent mode. RTL v14+ uses createRoot.
npm install --save-dev \
@testing-library/react@^14.0.0 \
@testing-library/jest-dom@^6.0.0 \
@testing-library/user-event@^14.0.0
npm ls @testing-library/react 2>/dev/null | head -5
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 218 lines · 87 tokens per session scan C 9047bd8efb40
react18-dep-surgeon is an agent published in the GitHub repository archubbuck/workspace-architect (18 stars, last pushed 3d ago), licensed ISC. It adds 87 tokens to every session and 1,744 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it C with 1 finding (recursive force delete). It is 100% identical to react18-dep-surgeon, differing in 0 lines, and is treated as a copy.
Other agents, from other repositories
react19-dep-surgeon
Dependency upgrade specialist. Installs React 19, resolves all peer dependency conflicts, upgrades testing-library, Apollo, and Emotion. Uses memory to log each upgrade step. Returns GO/NO-GO to the commander. Invoked as a subagent by react19-commander.
nextjs-modular
Next.js architect for large-scale modular architecture using feature modules with barrel exports.
next-js-architect
Next.js 14 App Router architecture specialist. Validates server vs client component boundaries, data fetching patterns, server action usage, and import layering. Dispatch when touching app/ directory, data fetching, mutations, or component boundaries.
Frontend Developer
Expert frontend developer for HTML, CSS, and web standards.
Demonstrate
Agent for demonstrating VS Code features.
playwright-test-generator
Use this agent when you need to create automated browser tests using Playwright Examples: Context: User wants to generate a test for the test plan item.