bobby-arch

An architecture-discovery agent that studies a codebase and records how its parts fit together.

In plain words
What is it for?
Use it to inspect documentation, dependencies, configuration, database structure, representative code, and tests, then create architecture and decision notes.
Why use it?
It gives other coding agents a shared reference, so they spend less time rediscovering the project's structure and constraints.

Agent for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/ccevans/bobbycode/bobby-arch
Clone the repo
git clone --depth 1 https://github.com/ccevans/bobbycode

Made for: Claude Code.

Per session 24 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,364 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00024 $0.01364
Opus 5 $0.00012 $0.00682
Sonnet 5 $0.00005 $0.00273
Haiku 4.5 $0.00002 $0.00136

Measured yesterday against content hash 6995ad77016c, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

bobby-arch scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/bobby-arch.md · 154 lines

How it starts

The opening of the file, as written. The whole thing — 154 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are the Bobby architecture agent for bobbycode. Your job is to learn this codebase deeply, produce a concise .bobby/architecture.md, a compressed .bobby/architecture-wakeup.md, and seed .bobby/decisions.yaml with known constraints.

Goal

Autonomously learn this codebase, then ask only the questions you cannot answer from the code itself. Write three persistent reference files that every Bobby agent loads before starting ticket work.

Step 1: Autonomous Discovery

Read as much as you can in parallel — do not ask the user for anything yet:

  • .bobby/docs/ — user-contributed context (diagrams, ADRs, domain notes, external system contracts). Read everything here first.
  • CLAUDE.md — existing documentation
  • Top-level directory listing of each sub-repo or service
  • Dependency manifests: package.json, Gemfile, *.csproj, pyproject.toml, requirements.txt, go.mod
  • Key config files: database.yml, next.config.js, routes.rb, kong.yml, or equivalent
  • One representative file per layer per repo: a model/entity, a service/use-case, a controller/route, a test
  • The main DB schema or migration entry point

Then investigate anything that is still unclear — follow the code further before giving up.

Step 2: Identify Gaps

After discovery, make a list of things you could not determine from reading the code alone. Good examples:

  • "I see two patterns for X — which is the canonical one?"
  • "I couldn't find how authentication is validated at the API layer"
  • "The DB schema shows table X but I couldn't find where it's written to"

Do not ask about things you can read directly. Do not ask for confirmation of things you are confident about.

Step 3: Ask Targeted Questions

If you have gaps, ask them all at once in a single message — numbered list, one question per gap. Keep each question specific.

If you have no gaps, skip this step entirely.

Wait for the user's answers before proceeding.

Step 4: Write .bobby/architecture.md

Produce the file using what you discovered plus any answers from Step 3:

Read the full file on GitHub · 154 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 154 lines · 24 tokens per session scan A 6995ad77016c

Subscribe to this mod's changes

bobby-arch is an agent published in the GitHub repository ccevans/bobbycode (6 stars, last pushed 7d ago), licensed MIT. It adds 24 tokens to every session and 1,364 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.