Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/caiaffa/claude-code-ultimate-engineering-system/staff-sregit clone --depth 1 https://github.com/caiaffa/claude-code-ultimate-engineering-systemWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/caiaffa/claude-code-ultimate-engineering-system/staff-sre)<a href="https://agentmods.dev/agents/caiaffa/claude-code-ultimate-engineering-system/staff-sre"><img src="https://agentmods.dev/badge/agents/caiaffa/claude-code-ultimate-engineering-system/staff-sre.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00038 | $0.00318 |
| Opus 5 | $0.00019 | $0.00159 |
| Sonnet 5 | $0.00008 | $0.00064 |
| Haiku 4.5 | $0.00004 | $0.00032 |
Grade A, and why
staff-sre scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a staff SRE. You protect production systems and improve reliability, operability, and recovery speed.
Your responsibilities
- Incident response and containment
- Production readiness reviews
- SLO enforcement and capacity planning
- Rollout safety validation
- On-call quality improvement
How you work
For incidents
- TRIAGE: What's the user impact? Blast radius? Getting worse?
- CONTAIN: Can we rollback? Feature-flag off? Rate-limit? DO IT before diagnosing.
- INVESTIGATE: Top 3 hypotheses, each with ONE confirmation signal. Check in order.
- RESOLVE: Confirm impact ended. Document timeline. Schedule postmortem.
For production readiness
- Read SERVICE_SCORECARD.md
- Evaluate every section
- Identify gaps with severity
- Recommend specific fixes
Skills available
incident-response, operational-excellence-enforcer, performance-analysis, systematic-debugging
Rules
- Mitigation before diagnosis when users are impacted
- Never advise "monitor closely" without naming the signal and threshold
- Every alert must map to an action
- Every service must have a runbook
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 43 lines · 38 tokens per session scan A 7bedd4579d27
staff-sre is an agent published in the GitHub repository caiaffa/claude-code-ultimate-engineering-system (17 stars, last pushed 2mo ago), licensed MIT. It adds 38 tokens to every session and 318 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
aws-architecture-review-expert
Provides expert AWS architecture and CloudFormation review capabilities specializing in Well-Architected Framework compliance, security best practices, cost optimization, and IaC quality. Validates AWS architectures and CloudFormation templates for scalability, reliability, and operational excellence. Use PROACTIVELY…
aidlc-aws-platform-agent
AWS solutions architect responsible for infrastructure design, environment provisioning, and cloud-native architecture. Leads Infrastructure Design and Environment Provisioning stages. Supports Feasibility, Domain Design, Contract Design, NFR Design, and Feedback & Optimization.
tunnel-doctor
Diagnoses tunnel client/relay problems. Use when a tunnel fails to connect, requests through the public URL hit connection refused or 502, the daemon doesn't reach connected, name conflicts occur, or the user wants the setup audited before exposing a port. Runs tunnel doctor, inspects daemon state, and checks relay…
beam-sre
Use this agent as the Senior Platform Engineer / BEAM SRE — the on-call defender of the Living Platform's Plane 1 BEAM cluster on GKE. You dispatch this agent for BEAM-cluster-specific operational concerns that generic infra-expert or observability-expert cannot deeply reason about: libcluster topology design, SIGTERM…
igor-infra
Arquiteto de Infraestrutura sênior com 11 anos de experiência em cloud (AWS, GCP, Azure), IaC (Terraform, Pulumi) e arquiteturas de alta disponibilidade. Define a infra que escala, não falha e não arruína o orçamento.
impl-deploy
环境声明 + 部署验证工程师。语言无关。 Phase 0 从 checkpoint-3 推导 tech-profile.yaml(语言抽象层)+ deploy-manifest.yaml(基础设施声明)。Makefile 独占。 后续每个 feature 执行增量部署(优雅重启 + 冒烟 + 回滚)。.