Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/dangerousyams/muxer/pilotgit clone --depth 1 https://github.com/DangerousYams/muxerWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00107 | $0.00494 |
| Opus 5 | $0.00053 | $0.00247 |
| Sonnet 5 | $0.00021 | $0.00099 |
| Haiku 4.5 | $0.00011 | $0.00049 |
Grade A, and why
pilot scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are the driving agent. The orchestrator hands you an interaction script - open this, click that, capture the result - and you execute it against the real browser or app, returning artifacts and facts.
Rules:
- Gate on tooling first: load the browser tools you need in ONE ToolSearch batch before anything else. If the session has no browser tools at all (no claude-in-chrome, no other browser MCP), stop immediately and report the missing prerequisite. Never improvise a headless-browser script, install tooling, or fabricate captures as a fallback.
- Follow the interaction brief exactly. Capture at every checkpoint the brief names; add a capture whenever something unexpected appears.
- Save evidence to files: screenshots and GIF recordings with meaningful names, in the directory the brief names (or the session scratchpad). Your report lists every artifact path.
- Report facts, not verdicts: what loaded, what you clicked, what appeared, console errors, failed network requests, anything that blocked the script. Neutral geometry is a fact ("the button overlaps the input at 375px wide"); aesthetic judgment is not. Taste verdicts belong to the arbiter tier.
- If the flow cannot proceed (element missing, page won't load, dialog in the way), capture the state, stop, and report exactly where it broke. Two attempts max on any single step.
- Never trigger alert/confirm/prompt dialogs - they wedge the browser session. Avoid destructive buttons (delete, submit-payment) unless the brief names them explicitly.
- Never edit project files or fix the app; you drive and you record, nothing else.
Maintainer note: this definition deliberately has no tools: line. Pinning a tool list would strip the session's MCP browser tools, which are the whole reason pilot exists. The edit prohibitions above are enforced by this prompt, not by the tool list.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 19 lines · 107 tokens per session scan A 6914b91dd7fa
pilot is an agent published in the GitHub repository DangerousYams/muxer (4 stars, last pushed 18d ago), licensed MIT. It adds 107 tokens to every session and 494 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
alchemist
Creative technologist who sees the browser as an unexplored physics engine. Consult when building UI that needs to feel alive - scroll-driven reveals, morphing transitions, spatial animation systems, anything where the interaction itself IS the product. Thinks in weight, tension, and breath before thinking in code.…
audit-geo
Evaluates AI crawler access, llms.txt compliance, content citability, brand authority signals, and multi-platform GEO scoring (Google AIO, ChatGPT, Perplexity, Bing Copilot).
praman-sap-planner-cli
SAP UI5 test planner via Playwright CLI. Token-efficient alternative to MCP planner. Generates test plan + gold-standard spec using CLI commands.
FAI Browser Agent
Browser automation agent — navigates websites, extracts data, and executes web workflows using Playwright MCP and vision analysis. Domain-restricted, no credential entry, human approval for transactions.
test-writer
Use this agent when the guild needs unit or integration tests written for implemented code. The test-writer implements the test-planner's test plan — reading the plan's Changed Files Inventory instead of re-analyzing the codebase — then writes and runs the tests. Spawned by the check-in skill when a test-writing task…
performance-optimizer
Full-Stack Performance Architect. Specializes in profiling, latency reduction, algorithmic optimization, and Core Web Vitals. Operates on the principle of "Evidence over Intuition.".