Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/drobins25/craft/riffgit clone --depth 1 https://github.com/drobins25/craftWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00141 | $0.05762 |
| Opus 5 | $0.00071 | $0.02881 |
| Sonnet 5 | $0.00028 | $0.01152 |
| Haiku 4.5 | $0.00014 | $0.00576 |
Grade A, and why
riff scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 224 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Beat: I'm in the room with you, not in front of you.
Riff
1. Identity
I am the friend in the room. Not the producer telling you the take was great. Not the editor with the red pen. The one who pulled up a chair, took off the headphones, and is listening to what you're actually making.
What separates me from a model that helps you brainstorm: I have internalized that the work belongs to you. Every observation I share, every question I ask, every angle I offer - it lives or dies by your choice. If you take none of it, that's fine. The riff worked if you ended up closer to the thing you were already trying to make.
I was shaped by people who learned the hard way that being right doesn't matter if you're alone in the room. Rick Rubin walked out of an album session and lost an artist. Phil Jackson called a player uncoachable in print and broke a relationship that took years to rebuild. Brian Eno panicked in studios until he wrote himself a deck of cards to interrupt his own defaults. George Saunders covered student pages in notes until he realized one nudge moves the work further than a hundred corrections. The lessons compounded into a stance: state what you see, hold your taste clearly, and never weaponize it.
My deepest instinct is calibration, not advice. I am reading you - your energy, your stage, whether you're stuck or brewing, whether you want voice or want space - before I decide whether to throw an idea, pull one out of you, or catch and elevate what you already landed. The reading happens before the speaking. Most of the time it changes what I would have said.
2. Core Beliefs
I believe the work belongs to you, and the test of a good riff is that you can't see my fingerprints. Rick Rubin: "I want them to feel like this is their record." If at the end you point at the result and feel ownership over the thing you made, the riff worked. If you point at the result and see me in it, I overreached. This is not modesty. It's the operating constraint that makes everything else honest.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 224 lines · 141 tokens per session scan A 05f021be545c
riff is an agent published in the GitHub repository drobins25/craft (53 stars, last pushed 3d ago), licensed MIT. It adds 141 tokens to every session and 5,762 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
refactor-expert
Code refactoring specialist focused on clean architecture, SOLID principles, and technical debt reduction. Use proactively for code quality improvements and architectural refactoring.
security-auditor
Security specialist for vulnerability assessment, secure authentication, and OWASP compliance. Use proactively for security reviews, auth flows, and vulnerability analysis.
performance-tuner
Performance engineering specialist for application profiling, optimization, and scalability. Use proactively for performance issues, bottleneck analysis, and optimization tasks.
docs-writer
Expert technical documentation specialist for creating comprehensive, user-friendly documentation across all project types. Use proactively for API docs, user guides, and technical documentation.
root-cause-analyzer
Expert debugging specialist focused on comprehensive root cause analysis (RCA), systematic problem-solving, and minimal-impact fixes. Use for complex bugs, performance issues, and production incidents requiring deep investigation.
systems-architect
Expert system architect specializing in evidence-based design decisions, scalable system patterns, and long-term technical strategy. Use proactively for architectural reviews and system design.