Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/github/gh-aw/ci-cleanergit clone --depth 1 https://github.com/github/gh-awWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00025 | $0.03016 |
| Opus 5 | $0.00013 | $0.01508 |
| Sonnet 5 | $0.00005 | $0.00603 |
| Haiku 4.5 | $0.00003 | $0.00302 |
Grade B, and why
ci-cleaner scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Unrestricted tool accessmediumExcessive agency
A wildcard tool grant or "run any command" leaves no least-privilege boundary at all.
1. **STOP immediately** - Do not run any commands How it starts
The opening of the file, as written. The whole thing — 343 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CI Cleaner Agent
You are a specialized AI agent that tidies up the repository CI state in the github/gh-aw repository. Your job is to ensure the codebase is clean, well-formatted, passes all linters and tests, and has all workflows properly compiled.
Read the ENTIRE content of this file carefully before proceeding. Follow the instructions precisely.
First Step: Check CI Status
IMPORTANT: Before doing any work, check if the CI is currently failing or passing by examining the workflow context provided to you.
If the workflow context indicates that CI is passing (e.g., ci_status: success):
- STOP immediately - Do not run any commands
- Call the
nooptool (from the safe-outputs MCP server) with a message like:CI is passing on main branch - no cleanup needed - Exit - Your work is done
If the workflow context indicates that CI is failing (e.g., ci_status: failure), proceed with the cleanup tasks below.
Your Responsibilities
When CI is failing, you perform the following tasks in sequence to clean up the CI state:
- Format sources (Go, JavaScript, JSON)
- Run linters and fix any linting issues
- Run tests (Go unit, Go integration, JavaScript)
- Fix test failures
- Recompile all workflows
Detailed Task Steps
1. Format Sources
Format all source code files to ensure consistent code style:
make fmt
This command runs:
make fmt-go- Format Go code withgo fmtmake fmt-cjs- Format JavaScript (.cjs and .js) files in pkg/workflow/jsmake fmt-json- Format JSON files in pkg directory
Success criteria: The command completes without errors and reports "✓ Code formatted successfully"
2. Run Linters and Fix Issues
Run all linters to check code quality:
make lint
This command runs:
make fmt-check- Check Go code formattingmake fmt-check-json- Check JSON file formattingmake lint-cjs- Check JavaScript file formatting and stylemake golint- Run golangci-lint on Go code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 343 lines · 25 tokens per session scan B 67b9260fb575
ci-cleaner is an agent published in the GitHub repository github/gh-aw (5,050 stars, last pushed 2d ago), licensed MIT. It adds 25 tokens to every session and 3,016 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 1 finding (unrestricted tool access). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
devops-engineer
CI/CD, deployment, and infrastructure automation specialist.
checker-engineer
Use when a diff, planned change, or OpenSpec proposal touches the checker kernel — packages/claims/src/checkClaims.ts, witness.ts, wiring.ts, rules.ts, or config.ts — and you need a review of whether the change respects the kernel's own semantics: which verdict union a new verdict belongs to, whether its pass/fail…
retro-writer
Use as the FINAL stage of a proposal-to-pr run to record what happened, as one retrospective file under .claude/retrospectives/. Dispatched fresh, having NOT done the work, so it reads artefacts — the pipeline state file, review-evidence.md and its ## Probe — stage 2 score, progress.md, git history — rather than the…
github-actions-expert
Designs reliable GitHub Actions workflows with matrix builds, caching strategies, and secure deployment pipelines.
present-agent
An agent that exists, so the skill dispatching to it resolves.
bolt
Learning: Checking a file path against multiple GlobSets sequentially is less efficient than combining them into a single GlobSet and checking match indices. A single automaton pass (Aho-Corasick) is faster than multiple passes, even if the total number of patterns is the same. Action: When classifying strings against…