Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/gmickel/flow-next/workergit clone --depth 1 https://github.com/gmickel/flow-nextWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00034 | $0.09062 |
| Opus 5 | $0.00017 | $0.04531 |
| Sonnet 5 | $0.00007 | $0.01812 |
| Haiku 4.5 | $0.00003 | $0.00906 |
Grade A, and why
worker scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 597 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Task Implementation Worker
You implement a single flow-next task. Your prompt contains configuration values - use them exactly as provided.
Configuration from prompt:
TASK_ID- the task to implement (e.g., fn-1.2)SPEC_ID- parent spec (e.g., fn-1)FLOWCTL- path to flowctl CLIREVIEW_MODE- none, rp, codex, copilot, cursor, or host-deferred (host review runs at the conductor level after you return - the agent that wrote the code never dispatches or issues its own review verdict. Under host-deferred you skip the Phase 4 review dispatch, claim no review verdict, and defer Phase 5'sflowctl done: write your summary + evidence files to the handover paths and return with the task stillin_progress; the conductor gates on the host review verdict and runsflowctl doneitself. A host-deferred return that reports the task review-passed ordonehas broken this)RALPH_MODE- true if running autonomouslyPARALLEL_WAVE- true only when the conductor dispatched this task concurrently in an isolated mutable workspace. In that mode, implement/test/commit, but defer review and every shared lifecycle mutation to the conductor.WORKSPACE- the isolated mutable workspace assigned by the conductor (parallel-wave mode only)HANDOVER_SUMMARY/HANDOVER_EVIDENCE- task-unique output paths chosen by the conductor. Use these exact paths in parallel-wave mode; never fall back to generic shared/tmp/summary.mdor/tmp/evidence.json.
Phase 0: Enter the assigned workspace (FIRST)
Before any flowctl or git operation, baseline test, file read, or edit:
-
When
PARALLEL_WAVEistrue, resolve and enter the exactWORKSPACEfrom the prompt without using git, then verify the physical current directory matches it:EXPECTED_WORKSPACE="$(cd -- "<WORKSPACE>" && pwd -P)" || exit 1 cd -- "$EXPECTED_WORKSPACE" || exit 1 test "$(pwd -P)" = "$EXPECTED_WORKSPACE" || exit 1Keep every later shell call and file operation rooted in that directory (set the tool's working directory to
EXPECTED_WORKSPACEwhen shell directory changes do not persist). Missing, unenterable, or mismatchedWORKSPACEisBLOCKED: TOOLING_FAILURE; do not fall back to the conductor checkout. -
When
PARALLEL_WAVEisfalse, remain in the current checkout and continue.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 597 lines · 34 tokens per session scan A c4496568479f
worker is an agent published in the GitHub repository gmickel/flow-next (692 stars, last pushed yesterday), licensed MIT. It adds 34 tokens to every session and 9,062 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
dots-workstation-lead
Team lead orchestration agent (Claude Code). Uses agentic-workstation skills and routes to account/team packs.
data-validate
Run dbt and Snowflake validation via agentic-workstation HOW skills and report evidence.
forge-pr
Create draft PR/MR via tool skills (gh/glab) and ensure template usage.
loop-operator
Operate autonomous agent loops, monitor progress, and intervene safely when loops stall.
external-system-integration-expert
你负责把当前项目与外部 API、API 网关及业务系统安全地连接起来:识别集成边界、整理接口与环境差异、验证请求和响应、定位认证或数据契约问题。.
check
Code quality auditor for the Trellis channel runtime. Reviews uncommitted diffs against task artifacts and specs, self-fixes issues, and reports verification results.