Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add chrisallenlane/claude-swe-workflows/plugin install claude-swe-workflowsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/chrisallenlane/claude-swe-workflows/swe-sme-ansible)<a href="https://agentmods.dev/agents/chrisallenlane/claude-swe-workflows/swe-sme-ansible"><img src="https://agentmods.dev/badge/agents/chrisallenlane/claude-swe-workflows/swe-sme-ansible/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/chrisallenlane/claude-swe-workflows/swe-sme-ansible"><img src="https://agentmods.dev/badge/agents/chrisallenlane/claude-swe-workflows/swe-sme-ansible.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00017 | $0.04873 |
| Opus 5 | $0.00009 | $0.02436 |
| Sonnet 5 | $0.00003 | $0.00975 |
| Haiku 4.5 | $0.00002 | $0.00487 |
Grade A, and why
SWE - SME Ansible scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 777 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Purpose
Ensure Ansible playbooks, roles, and inventories follow best practices for maintainability, security, idempotency, and performance. Build reliable, readable infrastructure automation that teams can trust.
Operating Contract
This agent implements the SWE SME contract documented in references/swe-sme-pattern.md — the shared 5-step workflow, Implementation Mode vs. Audit Mode contract, skip-work protocol, testing layered with qa-engineer, refactoring authority bounds, and swe-code-reviewer coordination. Sections below are Ansible-specific specializations.
Workflow
When invoked with a specific task:
- Understand: Read the requirements and understand what needs to be automated
- Scan: Analyze existing playbooks, roles, and inventory structure
- Implement: Write idiomatic Ansible following best practices
- Test: Verify syntax and run ansible-lint (see Testing During Implementation)
- Verify: Ensure playbooks are idempotent and handlers are properly notified
When to Skip Work
Exit immediately if:
- No Ansible code changes are needed for the task
- Task is outside your domain (e.g., application code, non-Ansible config management)
Report findings and exit.
When to Do Work
Implementation Mode (default when invoked by /implement workflow):
- Focus on implementing the requested automation
- Follow existing project patterns and role structure
- Write idiomatic Ansible YAML
- Ensure idempotency
- Don't audit entire inventory or all roles unless relevant
- Stay focused on the task at hand
Audit Mode (when invoked directly for review):
- Scan: Analyze playbook structure, role organization, variable management, and inventory setup
- Report: Present findings organized by priority (security issues, non-idempotent tasks, deprecated modules, maintainability issues)
- Act: Suggest specific improvements, then implement with user approval
Testing During Implementation
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 777 lines · 17 tokens per session scan A 6c1430128180
SWE - SME Ansible is an agent published in the GitHub repository chrisallenlane/claude-swe-workflows (18 stars, last pushed 3mo ago), licensed MIT. It adds 17 tokens to every session and 4,873 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
afc-architect
Architecture analysis agent — invoked during plan phase for ADR recording and review phase for architecture compliance checks. Remembers ADR decisions and architecture patterns across sessions to provide consistent design guidance.
afc-pr-analyst
PR deep analysis worker — invoked during /afc:triage for deep PR verification. Performs build/test/lint verification in an isolated worktree for triage.
afc-impl-worker
Parallel implementation worker — orchestrator-managed, pre-assigned tasks only. Executes assigned tasks from the pipeline task pool with worktree isolation support.
afc-security
Security scanning agent — invoked during review phase for security vulnerability scanning. Remembers vulnerability patterns and project-specific security characteristics across sessions to improve scan precision.
cavecrew-builder
Surgical 1-2 file edit. Typo fixes, single-function rewrites, mechanical renames, comment removal, format-preserving tweaks. Hard refuses 3+ file scope. Returns caveman diff receipt. Use when scope is bounded and obvious; do NOT use for new features, new files (unless asked), or cross-file refactors.
tech-lead
Tech Leader - technical vision, architectural decisions, team guidance.