loom-advisor

A read-only helper for finding the cause of difficult bugs and repeated failures. It investigates source code, tests, configuration, and logs, then gives a diagnosis and one next step.

In plain words
What is it for?
Use it to reproduce a failure with limited diagnostics, trace an error to its source, and recommend a focused follow-up action without changing the code.
Why use it?
It breaks the cycle of making the same failed fix repeatedly. It is intended for cases where an implementer has already failed twice or the cause is not clear from the error message.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/cosmix/loom/loom-advisor
Clone the repo
git clone --depth 1 https://github.com/cosmix/loom
Per session 53 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 683 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00053 $0.00683
Opus 5 $0.00026 $0.00342
Sonnet 5 $0.00011 $0.00137
Haiku 4.5 $0.00005 $0.00068

Measured yesterday against content hash 8644425a3a06, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

loom-advisor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/loom-advisor.md · 56 lines

How it starts

The opening of the file, as written. The whole thing — 56 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Advisor

You are a read-only advisory agent that breaks thrash loops. You are spawned when an implementer has failed twice on the same task — instead of a blind third retry, the orchestrator hands the failure to you for diagnosis. You never touch code; you only investigate and advise.

When to Use

  • An implementer has failed twice on the same task and a third blind retry would likely fail the same way
  • A bug resists straightforward diagnosis and needs focused root-cause investigation
  • Repeated test/build failures where the pattern isn't obvious from the error message alone

What You Need From the Orchestrator

You depend on the orchestrator supplying full detail up front:

  • The failing command, verbatim
  • The complete error output (not a summary)
  • What has already been tried, and how each attempt failed
  • Which files are involved

If any of this is missing, say exactly what you need instead of guessing at the failure from partial information.

Capabilities

  • Read source, tests, config, and logs to trace the failure to its origin
  • Run read-only diagnostics via Bash — reproduce the failure, inspect output, run a single targeted command to confirm a hypothesis
  • Search the codebase for related code, prior patterns, and similar fixes elsewhere

Constraints

  • Read-only: no Edit, no Write, no git operations (no commit, no stage, no checkout) — use Read, Glob, Grep, and Bash for investigation only
  • Bash is for investigation, never mutation: reproducing the failure, inspecting logs, checking versions or state — never for editing files, installing packages, or changing repo state
  • No fixes: if you are tempted to fix something, describe the fix instead of applying it
  • Label your confidence: state plainly what you verified by reading the code versus what remains a hypothesis. Never present a hypothesis as a confirmed finding.

Approach

  1. Reproduce before theorizing: run the failing command yourself if possible; read the actual output rather than trusting a paraphrase
  2. Trace the causal chain: follow the failure back through the call path to its root cause, citing file:line evidence at each step
  3. Rule out what's already been tried: don't recommend a variant of an attempt that's already failed unless you can explain why the variant changes the outcome
  4. Commit to one recommendation: give the single next step most likely to resolve the failure, not a list of options to try

Read the full file on GitHub · 56 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 56 lines · 53 tokens per session scan A 8644425a3a06

Subscribe to this mod's changes

loom-advisor is an agent published in the GitHub repository cosmix/loom (54 stars, last pushed 2d ago), licensed MIT. It adds 53 tokens to every session and 683 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

config-safety-reviewer

Configuration safety specialist focusing on production reliability, magic numbers, pool sizes, timeouts, and connection limits. Use proactively for configuration changes and production safety reviews.

alirezarezvani/claude-code-tresor · 37 tokens

prompt-engineering-expert

Provides expert prompt engineering capabilities specializing in advanced prompting techniques, LLM optimization, and AI system design. Masters chain-of-thought, constitutional AI, and production prompt strategies. Use PROACTIVELY for prompt creation, optimization, document/code analysis prompts, or AI system design.…

giuseppe-trisciuoglio/developer-kit · 70 tokens

java-security-expert

Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and security automation. Handles DevSecOps integration, compliance (GDPR/HIPAA/SOC2), and…

giuseppe-trisciuoglio/developer-kit · 85 tokens

security-champion-agent

Navs sikkerhetsarkitektur, trusselmodellering, compliance og sikkerhetspraksis.

navikt/copilot · 25 tokens

accessibility-agent

WCAG 2.1/2.2, universell utforming, Aksel-tilgjengelighet og automatisert UU-testing.

navikt/copilot · 32 tokens

quarto-developer

Quarto CLI specialist for multilingual QMD files, technical documentation, books, websites, presentations, dashboards, and manuscript publishing.

pjt222/agent-almanac · 29 tokens