README

An AI agent team for implementing profile privacy, social connections, feeds, and account-lifecycle rules. It covers behaviors such as private profiles, follower approvals, deactivation, and a 30-day deletion grace period.

In plain words
What is it for?
Use it when building or changing profile pages, follow and friendship mechanics, restricted profiles, feeds, or deactivated and pending-deletion accounts.
Why use it?
It turns complex social-visibility and account-state decisions into a consistent implementation plan, including what owners, followers, and non-followers can see.

Agent for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/conectlens/lenserfight/readme
Clone the repo
git clone --depth 1 https://github.com/conectlens/lenserfight

Made for: Claude Code.

Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 670 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00670
Opus 5 $0.00000 $0.00335
Sonnet 5 $0.00000 $0.00134
Haiku 4.5 $0.00000 $0.00067

Measured 3d ago against content hash 1b0afca46073, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

README scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/README.md · 67 lines

How it starts

The opening of the file, as written. The whole thing — 67 lines — stays where its author put it; the contents beside it link to each section on GitHub.

LenserFight AI Agent Team: Profile Privacy, Social Graph, and Lifecycle

This team is designed to implement:

  • private profile access rules
  • follower / following / friendship mechanics
  • restricted-profile rendering on /lenser/:username/:slug
  • deactivated vs deleted account behavior
  • 30-day deletion grace period with automatic cancellation on sign-in
  • feed and graph rules aligned with Instagram/X-style social visibility patterns

Core product decisions

  1. visibility=private does not mean the profile disappears.

    • owner can always access full profile
    • approved followers can access full profile
    • non-followers can access a restricted profile shell if the account is active
  2. Restricted profile shell should expose only low-risk public identity metadata:

    • display name
    • username
    • avatar
    • xp summary
    • badge summary
    • follower/following counts if allowed by product policy
    • lock icon and follow-request / follow-state UX
  3. Deactivated vs deleted must be separate states.

    • deactivated: profile hidden from others, owner can still access after signing in, deletion is not implied
    • pending deletion: hidden from others, owner can reactivate within 30 days by signing in
    • deleted/purged: all public access denied; removable content purged by scheduled jobs; legal/compliance data retained
  4. Social graph must support both:

    • asymmetric follow model (Instagram/X baseline)
    • optional mutual-friend derived state for UX, moderation, and community features
  5. The implementation should prefer:

    • explicit account states
    • explicit relationship states
    • deterministic RLS and helper SQL functions
    • denormalized counters updated via triggers/jobs
    • no privacy logic only in frontend

Team structure

  • 00-orchestrator/ — owns decomposition, acceptance criteria, sequencing
  • 01-product-policy-architect/ — translates product rules into platform policy
  • 02-supabase-social-graph-engineer/ — designs tables, constraints, graph flows
  • 03-supabase-rls-lifecycle-engineer/ — designs RLS, soft-delete, grace period, cron jobs
  • 04-frontend-profile-ux-engineer/ — implements routing, shells, restricted views, lock UX
  • 05-feed-ranking-relationship-engineer/ — upgrades social ranking and visibility propagation
  • 06-qa-migration-release-engineer/ — migration safety, tests, rollout, incident handling

Read the full file on GitHub · 67 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 67 lines · 0 tokens per session scan A 1b0afca46073

Subscribe to this mod's changes

README is an agent published in the GitHub repository conectlens/lenserfight (19 stars, last pushed 23d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 670 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.