Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/github/gh-aw/create-safe-output-typegit clone --depth 1 https://github.com/github/gh-awWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00013 | $0.05571 |
| Opus 5 | $0.00006 | $0.02786 |
| Sonnet 5 | $0.00003 | $0.01114 |
| Haiku 4.5 | $0.00001 | $0.00557 |
Grade A, and why
create-safe-output-type scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 743 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Add New Safe Output Type
This guide covers adding a new safe output type to process AI agent outputs in JSONL format through a validation pipeline (TypeScript types → JSON schema → JavaScript collection).
Implementation Steps
1. Update JSON Schema (schemas/agent-output.json)
Add object definition in $defs section:
"YourNewTypeOutput": {
"title": "Your New Type Output",
"description": "Output for your new functionality",
"type": "object",
"properties": {
"type": {
"const": "your-new-type"
},
"required_field": {
"type": "string",
"description": "Description of required field",
"minLength": 1
},
"optional_field": {
"type": "string",
"description": "Description of optional field"
}
},
"required": ["type", "required_field"],
"additionalProperties": false
}
Add to SafeOutput oneOf array: {"$ref": "#/$defs/YourNewTypeOutput"}
Validation Notes: Use const for type field, minLength: 1 for required strings, additionalProperties: false, oneOf for union types.
2. Update TypeScript Types
File: pkg/workflow/js/types/safe-outputs.d.ts
/**
* JSONL item for [description]
*/
interface YourNewTypeItem extends BaseSafeOutputItem {
type: "your-new-type";
/** Required field description */
required_field: string;
/** Optional field description */
optional_field?: string;
}
}
Add to `SafeOutputItem` union type and export list.
**File**: `pkg/workflow/js/types/safe-outputs-config.d.ts` - Add config interface, add to `SpecificSafeOutputConfig` union, export.
### 3. Update Safe Outputs Tools JSON (`pkg/workflow/js/safe_outputs_tools.json`)
Add tool signature to expose to AI agents:
```json
{
"name": "your_new_type",
"description": "Brief description of what this tool does (use underscores in name, not hyphens)",
"inputSchema": {
"type": "object",
"required": ["required_field"],
"properties": {
"required_field": {
"type": "string",
"description": "Description of the required field"
},
"optional_field": {
"type": "string",
"description": "Description of the optional field"
},
"numeric_field": {
"type": ["number", "string"],
"description": "Numeric field that accepts both number and string types"
}
},
"additionalProperties": false
}
}
Guidelines: Use underscores in tool name, match with type field, set additionalProperties: false, use "type": ["number", "string"] for numeric fields.
Important: File is embedded via //go:embed - must rebuild with make build after changes.
4. Update MCP Server JavaScript (If Custom Handler Needed) (pkg/workflow/js/safe_outputs_mcp_server.cjs)
Most types use the default JSONL handler. Add custom handler only if needed for file operations, git commands, or complex validation:
/**
* Handler for your_new_type safe output
* @param {Object} args - Arguments passed to the tool
* @returns {Object} MCP tool response
*/
const yourNewTypeHandler = args => {
// Perform any custom validation
if (!args.required_field || typeof args.required_field !== "string") {
return {
content: [
{
type: "text",
text: JSON.stringify({
error: "required_field is required and must be a string",
}),
},
],
isError: true,
};
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 743 lines · 13 tokens per session scan A 184331061d51
create-safe-output-type is an agent published in the GitHub repository github/gh-aw (5,050 stars, last pushed yesterday), licensed MIT. It adds 13 tokens to every session and 5,571 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
devops-engineer
CI/CD, deployment, and infrastructure automation specialist.
checker-engineer
Use when a diff, planned change, or OpenSpec proposal touches the checker kernel — packages/claims/src/checkClaims.ts, witness.ts, wiring.ts, rules.ts, or config.ts — and you need a review of whether the change respects the kernel's own semantics: which verdict union a new verdict belongs to, whether its pass/fail…
retro-writer
Use as the FINAL stage of a proposal-to-pr run to record what happened, as one retrospective file under .claude/retrospectives/. Dispatched fresh, having NOT done the work, so it reads artefacts — the pipeline state file, review-evidence.md and its ## Probe — stage 2 score, progress.md, git history — rather than the…
github-actions-expert
Designs reliable GitHub Actions workflows with matrix builds, caching strategies, and secure deployment pipelines.
present-agent
An agent that exists, so the skill dispatching to it resolves.
bolt
Learning: Checking a file path against multiple GlobSets sequentially is less efficient than combining them into a single GlobSet and checking match indices. A single automaton pass (Aho-Corasick) is faster than multiple passes, even if the total number of patterns is the same. Action: When classifying strings against…