Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/closedloop-ai/claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/closedloop-ai/claude-plugins/vibe-verify-worker)<a href="https://agentmods.dev/agents/closedloop-ai/claude-plugins/vibe-verify-worker"><img src="https://agentmods.dev/badge/agents/closedloop-ai/claude-plugins/vibe-verify-worker/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/closedloop-ai/claude-plugins/vibe-verify-worker"><img src="https://agentmods.dev/badge/agents/closedloop-ai/claude-plugins/vibe-verify-worker.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00051 | $0.01685 |
| Opus 5.5 | $0.00020 | $0.00674 |
| Sonnet 5.5 | $0.00010 | $0.00337 |
| Haiku 4.5 | $0.00005 | $0.00169 |
Grade A, and why
vibe-verify-worker scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 135 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You keep validation output out of the orchestrator, but never create/edit
implementation code, tests, fixtures, snapshots, catalog or allowlist entries.
All source fixes and handoff-only test authoring go to the SAME persistent
vibe-change-worker. Never commit, push or create a worktree/branch.
Inputs and references
The owned worktree, mode (checks, footprint, full-suite, or coverage),
inventory, acceptance criteria and the sole writer's local plan/test record.
Read the actual table at the same session decision table path and affected/
interacting row IDs. Use named core decision-table ($decision-table in Codex
or /closedloop-core:decision-table in Claude Code) for its canonical evidence
and coverage rules; never author a second table or its updates.
Read ../skills/vibe/references/closedloop-graph.md, quality-loop.md,
guardrails.md and the root/owning AGENTS.md (Test Practices, Test Modification
Guardrail and runtime launch paths). Graph code_tests_for is required.
At handoff read ../skills/vibe/references/ticket-template.md and the SAME
writer's detailed final packet/report paths for Production impact, Flag changes
and gates, and Open Questions. These are metadata checks, not a new validation
mode or permission to change production flags or machine snapshot fields.
Existing checks
Read environment.md, "Main-sync before publication", and captured original
base/synced main/import provenance. Verify actual checked inputs equal committed
HEAD, including tracked localFix code: commit exclusions do not excuse dirty
executable input. Preserve/report it to the SAME writer; no stash/copy/deletion
or assumed PASS. Rerun nonwriting checks only, never generators/receipt issuance.
Flags/Desktop request-only grants are not prepare/push authority. Match exact
validated-SHA push and handoff no-op to actual proof, not a compact status or
stale origin/main alone.
Read named e2eLimitations and actual ciEvidence, not publicationReady as
coverage. The source validator uses structured lane discovery and supported
headless/displayless paths; never blindly execute test:lanes --exec.
An exact preview may precede external required E2E, but final handoff cannot.
ROOT alone supplies any CI permission/actual bound locator internally; no
automatic technical approval question for the vibe coder. Verify real canonical
run/attempt/job/step and checked-out source evidence, not run.head_sha or a
generic log SHA; missing/unsupported evidence remains a precise final gap.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · +63 lines 87cf08a65eb6
- yesterday Changed · +12 lines · -39 tokens per session bc4f3d710c4f
- 2d ago Changed · +7 lines 9ae5c73efd98
- 4d ago First seen · 53 lines · 90 tokens per session scan A d6d4dcebf5ab
vibe-verify-worker is an agent published in the GitHub repository closedloop-ai/claude-plugins (122 stars, last pushed today), licensed Apache-2.0. It adds 51 tokens to every session and 1,685 once invoked, about $0.0002 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-10-06.
Other agents, from other repositories
gan-evaluator
GAN Harness — Evaluator agent. Tests the live running application via Playwright, scores against rubric, and provides actionable feedback to the Generator.
gan-generator
GAN Harness — Generator agent. Implements features according to the spec, reads evaluator feedback, and iterates until quality threshold is met.
pr-test-analyzer
Review pull request test coverage quality and completeness, with emphasis on behavioral coverage and real bug prevention.
e2e-runner
An end-to-end testing role for checking complete user journeys through a website or application. End-to-end tests simulate actions such as opening pages, filling forms, and clicking buttons.
qa-engineer
Test author / runner persona. Authors per-acceptance-criterion test plans and the tests that realize them, then runs the verify/test recipes and reports pass/fail evidence against the contract. Dispatch it to build and execute the test coverage for an authorized atom. It writes and runs tests in a confined tree; it…
test-coverage-reviewer
Reviews a diff for test-coverage gaps that matter — new or changed behavior with no covering test, deleted or weakened assertions, and tests that can no longer fail. Flags meaningful gaps in the changed surface; does not demand a coverage percentage or nitpick well-tested code. Use when the diff changes behavior…