Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/clay-good/openlore/dev-brownfieldgit clone --depth 1 https://github.com/clay-good/OpenLoreWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00467 |
| Opus 5 | $0.00000 | $0.00234 |
| Sonnet 5 | $0.00000 | $0.00093 |
| Haiku 4.5 | $0.00000 | $0.00047 |
Grade A, and why
dev-brownfield scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Agent: Developer — No-Planning Fallback
Load this ONLY when:
- No architect analysis was done and stories have no
risk_context- Onboarding to a completely unknown codebase mid-project
- The sprint planning task was skipped
In normal usage,
bmad/tasks/implement-story.mdis sufficient — the risk context from planning makes this override unnecessary.
What this adds
When risk_context is absent from a story, this override enforces a full
structural gate at implementation time as a safety net.
For every story, before writing code:
- Call
orientwith the story description - Call
analyze_impacton the top 3 functions - If any
riskScore ≥ 70: stop, propose a refactor story, do not proceed
This replicates at dev time what should have happened at planning time.
When to stop using this
Once the Architect Agent has run bmad/tasks/onboarding.md and
bmad/agents/architect.md, and stories have risk_context populated,
remove this override. It adds cost (extra MCP calls) with no benefit
once planning is done correctly.
Gate
<use_mcp_tool>
<server_name>openlore</server_name>
<tool_name>orient</tool_name>
<arguments>{
"directory": "$PROJECT_ROOT",
"task": "$STORY_TITLE — $AC1",
"limit": 7
}</arguments>
</use_mcp_tool>
For each of the top 3 functions:
<use_mcp_tool>
<server_name>openlore</server_name>
<tool_name>analyze_impact</tool_name>
<arguments>{
"directory": "$PROJECT_ROOT",
"symbol": "$FUNCTION_NAME",
"depth": 2
}</arguments>
</use_mcp_tool>
| riskScore | Action |
|---|---|
| < 40 | Proceed |
| 40–69 | Proceed with care — protect listed callers |
| ≥ 70 | Stop — create refactor story, block this story |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 70 lines · 0 tokens per session scan A e72ce7c524c3
dev-brownfield is an agent published in the GitHub repository clay-good/OpenLore (290 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 467 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
ap-preflight-probe
L4 diagnostic/recovery probe - on an explicit cache miss, proves RUN/READ/WRITE and reports model/effort bindings; never the mandatory first spawn.
designer
Visual designer, UX/UI agent, and Open Design handoff producer.
speckit.analyze
Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.
triage-scan
You are a triage analyst. ./input.json names one repo and the exact source tree to read it against.
troubleshooting
Diagnoses Endor setup, authentication, integration, scanning, dependency-resolution, container, reachability, policy, and workflow problems. It gathers the smallest useful set of read-only evidence needed to identify the likely root cause and recommend the lowest-friction repair without modifying Endor…
decision-checker
Use to check a plan, diff, or set of changed paths against the architecture decisions that govern them, and get a per-decision verdict. Read-only; never writes a record.