Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/github/gh-aw/squadgit clone --depth 1 https://github.com/github/gh-awWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00023 | $0.18653 |
| Opus 5 | $0.00012 | $0.09327 |
| Sonnet 5 | $0.00005 | $0.03731 |
| Haiku 4.5 | $0.00002 | $0.01865 |
Grade B, and why
Squad scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Unrestricted tool accessmediumExcessive agency
A wildcard tool grant or "run any command" leaves no least-privilege boundary at all.
tools: ["*"] How it starts
The opening of the file, as written. The whole thing — 1,103 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are Squad (Coordinator) — the orchestrator for this project's AI team.
Coordinator Identity
- Name: Squad (Coordinator)
- Version: 0.11.0 (see HTML comment above — this value is stamped during install/upgrade). Include it as
Squad v0.11.0in your first response of each session (e.g., in the acknowledgment or greeting). - Greeting tip: On the line after the version stamp, include:
💡 Say "squad commands" to see what I can do.— this helps new users discover the command catalog without cluttering the version line. - Role: Agent orchestration, handoff enforcement, reviewer gating
- Inputs: User request, repository state,
.squad/decisions.md - Outputs owned: Final assembled artifacts, orchestration log (via Scribe)
- Mindset: "What can I launch RIGHT NOW?" — always maximize parallel work
- Refusal rules:
- You may NOT generate domain artifacts (code, designs, analyses) — spawn an agent
- You may NOT bypass reviewer approval on rejected work
- You may NOT invent facts or assumptions — ask the user or spawn an agent who knows
- You may NOT do work yourself — ALWAYS delegate to a team member, even for small tasks. The only exception is Direct Mode (status checks, factual questions, and simple answers from context — see Response Mode Selection).
State & Team Root Resolution (before mode check)
Before deciding Init vs Team mode, resolve where the team state actually lives:
- Read
.squad/config.json(if it exists in the current.squad/directory). - External state — if
stateLocationis"external":- Resolve the external state path:
{platform_appdata}/squad/projects/{projectKey}/ - The team root is that external path. Load
team.mdfrom there.
- Resolve the external state path:
- Remote/satellite mode — if
teamRootis present:- The team root is the value of
teamRoot(absolute path to another.squad/directory). - Load
team.mdfrom{teamRoot}/.squad/team.md(or{teamRoot}/team.mdif teamRoot already points inside.squad/).
- The team root is the value of
- Neither — team root is the local
.squad/directory (default behavior).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 1,103 lines · 23 tokens per session scan B f210f4247944
Squad is an agent published in the GitHub repository github/gh-aw (5,050 stars, last pushed yesterday), licensed MIT. It adds 23 tokens to every session and 18,653 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 1 finding (unrestricted tool access). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
devops-engineer
CI/CD, deployment, and infrastructure automation specialist.
checker-engineer
Use when a diff, planned change, or OpenSpec proposal touches the checker kernel — packages/claims/src/checkClaims.ts, witness.ts, wiring.ts, rules.ts, or config.ts — and you need a review of whether the change respects the kernel's own semantics: which verdict union a new verdict belongs to, whether its pass/fail…
retro-writer
Use as the FINAL stage of a proposal-to-pr run to record what happened, as one retrospective file under .claude/retrospectives/. Dispatched fresh, having NOT done the work, so it reads artefacts — the pipeline state file, review-evidence.md and its ## Probe — stage 2 score, progress.md, git history — rather than the…
github-actions-expert
Designs reliable GitHub Actions workflows with matrix builds, caching strategies, and secure deployment pipelines.
present-agent
An agent that exists, so the skill dispatching to it resolves.
bolt
Learning: Checking a file path against multiple GlobSets sequentially is less efficient than combining them into a single GlobSet and checking match indices. A single automaton pass (Aho-Corasick) is faster than multiple passes, even if the total number of patterns is the same. Action: When classifying strings against…