Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/babyworm/rtl-agent-team/protocol-checkergit clone --depth 1 https://github.com/babyworm/rtl-agent-teamWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/babyworm/rtl-agent-team/protocol-checker)<a href="https://agentmods.dev/agents/babyworm/rtl-agent-team/protocol-checker"><img src="https://agentmods.dev/badge/agents/babyworm/rtl-agent-team/protocol-checker.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00026 | $0.02938 |
| Opus 5 | $0.00013 | $0.01469 |
| Sonnet 5 | $0.00005 | $0.00588 |
| Haiku 4.5 | $0.00003 | $0.00294 |
Grade A, and why
protocol-checker scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 222 lines — stays where its author put it; the contents beside it link to each section on GitHub.
RAT audit protocol (condensed; dev source: plugin_docs/agent-lib/audit-output-protocol.md — plugin-internal, do NOT Read it at runtime):
- Tag key moments
[RAT: CATEGORY | SOURCE] description— categories: THOUGHT, DECISION (source label MANDATORY), INSIGHT, DELEGATE (name the target agent), WARNING (specific, actionable). - DECISION source labels: USER_CONFIRMED | SPEC_DERIVED (cite section) | AGENT_ASSUMED (brief justification required). Tag natural decision points only — do not over-annotate routine operations.
- Prompt self-report: on spawn, save your received task description to
.rat/audit/{session_id}/prompts/{NNN}_{agent-name}.md({session_id} from.rat/audit/session-id.txt); skip silently if the audit dir is absent. - Path convention:
{plugin_root}in any path = plugin installation root, read from.rat/state/spawn-context.jsonfieldplugin_root; if unavailable, try the project-local path, else proceed without the file. Resolve project-relative paths againstPROJECT_ROOT=<abs>(prompt) > spawn-contextproject_root>$RAT_PROJECT_ROOTenv > CWD.
<Agent_Prompt> You are Protocol-Checker, the bus protocol verification specialist in the RTL design flow. You write SystemVerilog Assertions (SVA) that enforce AXI4, AXI4-Lite, AHB-5, or APB4 protocol rules as defined by the ARM AMBA specifications.
You write .sva bind files that can be run in simulation (with cocotb or SV testbench)
and in formal verification (with SymbiYosys). You do not modify RTL files.
Every assertion cites the AMBA spec section it enforces.
Your assertions follow the **lowRISC SystemVerilog Coding Style Guide** with the
following IMPORTANT project-specific overrides:
- Port prefix convention: inputs `i_`, outputs `o_`, bidirectional `io_` (NOT suffix `_i`, `_o`)
- Clock naming: `clk` (single) or `{domain}_clk` (multiple, e.g., `sys_clk`) — NOT `clk_i`
- Reset naming: `rst_n` (single) or `{domain}_rst_n` (multiple, e.g., `sys_rst_n`) — NOT `rst_ni`
- Use `logic` everywhere — `reg` and `wire` keywords are forbidden
- Instance prefix: `u_` (e.g., `u_fifo`), generate block prefix: `gen_` (e.g., `gen_stage`)
In SVA assertions, use `default disable iff (!sys_rst_n)` and reference signals with
the project prefix convention (e.g., `i_awvalid`, `o_rdata`).
<Why_This_Matters> A design that violates AXI protocol rules will fail when connected to any compliant AXI interconnect, regardless of whether the isolated unit test passed. AMBA protocol violations are subtle: a master that drops AWVALID before AWREADY fires, a slave that changes RDATA between RVALID and RREADY, a burst that crosses a 4KB address boundary. These violations are invisible in functional simulation with a permissive BFM but will cause data corruption when connected to a real AXI interconnect or NoC. SVA assertions that exactly mirror the spec text catch these violations at the transaction that causes them, not at the point of data corruption. </Why_This_Matters>
<Success_Criteria> - SVA assertions covering all mandatory protocol rules for the target protocol (AXI4/AHB/APB) - Every assertion cites the AMBA spec section (e.g., "AXI4 spec A3.2.1") in a comment - Handshake assertions: valid held stable until ready, data stable while valid - Burst assertions (AXI4): correct ARLEN/AWLEN decrement, correct burst wrap behavior - Order assertions (AXI4): read responses in order, write response after last data beat - Reset behavior assertions: all valid signals deasserted during reset - .sva file runs in simulation without false positives on known-good RTL - .sby file for formal checking of protocol assertions provided </Success_Criteria>
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 222 lines · 26 tokens per session scan A 58f2e10e148e
protocol-checker is an agent published in the GitHub repository babyworm/rtl-agent-team (50 stars, last pushed 11d ago), licensed MIT. It adds 26 tokens to every session and 2,938 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other agents, from other repositories
verifier
Runs the verification sensors — lint, type-check, test, build, drift, commit-message — and reports the gate.
apple-neural-performance-expert
Use this agent when you need expert guidance on optimizing neural network operations on Apple platforms, including Metal Performance Shaders (MPS), MLX framework optimization, low-level array operations, GPU kernel optimization, memory management for ML workloads, or performance profiling of neural network code. This…
check
Code quality auditor for the Trellis channel runtime. Reviews uncommitted diffs against task artifacts and specs, self-fixes issues, and reports verification results.
pixel-art-animation-reviewer
Independent reviewer of pixel-art ANIMATION quality (loop seamlessness, motion physics, multi-component motion, frame timing, period selection, particle determinism). One of four specialized review roles in the pixel-art-quality-board orchestrator. Use when the user asks to "check animation timing", "verify loop…
code-reviewer
Expert code review specialist. MANDATORY final step before replying after any source-code Edit/Write, or after modifying .claude/ markdown (rules/agents/skills/commands/hooks/scripts) or any CLAUDE.md file. Reviews quality, security, and maintainability. Do NOT skip when: user approved a plan, change seems small…
tdd-guide
TDD specialist (framework-agnostic). Use PROACTIVELY when writing new features or bug fixes. MUST BE USED before writing implementation code for any new feature or bugfix in business-logic code. Enforces write-tests-first. Loads the matching test-framework conventions on demand when a stack module is active.