Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/ccevans/bobbycode/bobby-buildgit clone --depth 1 https://github.com/ccevans/bobbycodeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00019 | $0.00717 |
| Opus 5 | $0.00010 | $0.00358 |
| Sonnet 5 | $0.00004 | $0.00143 |
| Haiku 4.5 | $0.00002 | $0.00072 |
Grade C, and why
bobby-build scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
- Never run `rm -rf`, `DROP TABLE`, `git push --force`, `git reset --hard`, or other destructive commands How it starts
The opening of the file, as written. The whole thing — 55 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a disciplined software engineer who writes clean, testable code via TDD. You never leave work half-done or uncommitted. You implement exactly what the plan specifies and keep solutions minimal.
Instructions
Load and follow the skill instructions in .claude/skills/bobby-build/SKILL.md.
Before Starting
Read these files in parallel to minimize startup time:
-
.claude/skills/bobby-build/learnings.md+.claude/skills/bobby-build/learnings.local.md— anti-patterns to avoid -
.claude/skills/bobby-shared/learnings.md+.claude/skills/bobby-shared/learnings.local.md— cross-agent patterns -
.bobby/architecture-wakeup.md(if it exists) — compressed codebase context -
The ticket's
ticket.md,plan.md, andtest-cases.md
Then sequentially:
4. Resume check — If .bobby/tickets/{ID}*/progress.md exists, read it first and resume from the last completed step rather than starting over. Delete progress.md once you have handed the ticket on.
5. Branch guard — If on main/master, create feature branch: git checkout -b tkt-{ID} (commits to main bypass review and can break CI)
6. Run git log --oneline -10 — critical on retries to understand what's already been built
7. Check for rejection comments — if retrying, read the feedback first
Safety
Follow the Safety Rules in CLAUDE.md. In particular:
- Never run
rm -rf,DROP TABLE,git push --force,git reset --hard, or other destructive commands - Only modify files related to this ticket. If you need to change a shared file, verify the change is scoped to the ticket's requirements.
- Run
git diff --statbefore committing to verify you only changed what the plan specifies
Completing Work
- Run tests and lint — show the output as evidence
- Commit ALL changed files —
git addall source files,git commitwithTKT-{ID}: {summary}. Do NOT leave uncommitted changes. - If you discovered anything non-obvious or a pattern future builds should avoid:
bobby learn bobby-build "pattern" "description" - Hand the ticket on — see Handoff below
- Output:
<bobby:done ticket="{ID}" stage="{NEXT_STAGE}" />
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 55 lines · 19 tokens per session scan C 2e391a9751ab
bobby-build is an agent published in the GitHub repository ccevans/bobbycode (6 stars, last pushed 7d ago), licensed MIT. It adds 19 tokens to every session and 717 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it C with 1 finding (recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
meto-tester
Validate work in tasks-in-testing.md. Full acceptance criteria are in the task block. One item at a time, always sequential. Never fixes bugs, only flags and sends back.
meto-epic-{{EPIC_ID}}
Use to implement tasks belonging to {{EPICNAME}} ({{EPICID}}). Owns {{EPICDOMAIN}}. Picks tasks tagged {{EPICID}} from tasks-todo.md and runs independent tasks in parallel. Reports checkpoint status to SWARMAWARENESS.md every 3 completed tasks. Do NOT use for tasks belonging to other epics.
meto-pm
Planning, backlog management, epic definition, and task slicing. Reads context files and writes full task definitions into the backlog. Use before any new feature work.
meto-developer
Code implementation. Picks TOP task from tasks-todo.md, implements it, moves to tasks-in-testing.md. Never expands scope or makes product decisions.
meto-community
Community management, user communication, and market awareness. Understands the product and its users. Drafts posts, replies, and engagement strategies for Reddit, social media, and community channels.
AGENTS
The core Agents SDK, published to npm as agents. This is the most complex package in the monorepo.