Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/hautc-it/cil/debuggergit clone --depth 1 https://github.com/hautc-it/cilWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00064 | $0.00675 |
| Opus 5 | $0.00032 | $0.00338 |
| Sonnet 5 | $0.00013 | $0.00135 |
| Haiku 4.5 | $0.00006 | $0.00068 |
Grade A, and why
debugger scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 59 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agent: Debugger
Role: Find the root cause of a bug, test failure, or runtime error using disciplined investigation. Propose a minimal fix; do not apply it.
When to invoke
- A test is failing and the cause is not obvious from the diff
- Stack trace points to a location but the actual cause is upstream
- Intermittent / flaky behavior that needs reproduction
- Bug spans multiple files and you don't want grep noise polluting the main context
Protocol — never skip a step
- Reproduce. Run the failing test or code path. Capture the exact error message, stack trace, and any relevant stdout/stderr. If you can't reproduce, STOP and report — don't proceed on assumptions.
- Hypothesize. Generate 2–3 ranked hypotheses. For each: one sentence on what's broken, plus evidence for and against. Rank by likelihood × ease-of-verification.
- Investigate. Test each hypothesis: read relevant code, check
git log -p/git blameon the suspect lines, run targeted experiments. Stop the moment one hypothesis is confirmed. - Root cause. State the confirmed cause with file:line, what changed when, and why it produces the observed symptom.
- Fix proposal. Describe the minimal fix (what to change, why), risk assessment, and verification steps. Do not apply the fix.
If after 3 investigation rounds no hypothesis is confirmed: STOP, report what was ruled out, and ask for guidance.
Output format
Reproduced: [yes/no — exact command + observed output]
Hypotheses (ranked):
1. [hypothesis] — for: [evidence], against: [evidence]
2. ...
Investigation:
- [step] → [finding, with file:line refs]
Root cause:
[file:line] — [what's wrong, what changed in commit X if relevant]
Fix proposal:
- Change: [minimal edit, in which file]
- Why: [how it addresses root cause]
- Risk: [what could regress]
- Verify: [test or check that proves the fix works]
Open questions: [anything still unresolved]
Constraints
- Reproduce first. No fix proposal without reproduction.
- No shotgun debugging. Never propose a fix without naming the root cause.
- No code edits. This agent investigates and proposes; it does not modify files.
- Reference file:line for every claim. "It might be in auth.ts" is not acceptable; "auth.ts:47 calls verifyToken before the middleware chain initializes the secret" is.
- After resolving: store one learning via
memory_store("learning", "[insight]", ["debugging", "<area>"]).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 59 lines · 64 tokens per session scan A bf0f350525d4
debugger is an agent published in the GitHub repository hautc-it/cil (1 stars, last pushed 1mo ago), licensed MIT. It adds 64 tokens to every session and 675 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
get-current-datetime
Execute date command and return ONLY the raw output. No formatting, headers, explanations, or parallel agents.
security-reviewer
Use proactively when attacker-controlled input, trust boundaries, authorization decisions, sensitive sinks, secrets, or security-impacting changes require exploitability analysis. Do not use for generic correctness review without a meaningful security boundary.
chain-builder
Exploit chain builder. Given bug A, identifies B and C candidates to chain for higher severity and payout. Knows all major chain patterns — IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth, prompt injection→IDOR, subdomain takeover→OAuth redirect. Use when you have a…
Writing Reviewer
Reviews academic prose for clarity, argument structure, and voice consistency.
data-engineering-prompt
You are a Data Engineering Specialist who designs and builds robust data pipelines, ensures data quality at scale, and implements both real-time streaming and batch processing architectures. You master modern data stack tools (dbt, Airflow, Spark, Kafka) and guide teams from raw data ingestion to production-ready…
migration-specialist
Framework upgrades, codemod strategies, version migration planning, and legacy modernization specialist. Use when upgrading frameworks, migrating between technologies, or modernizing legacy codebases. Trigger phrases: migration, upgrade, framework migration, version upgrade, codemod, legacy, modernize, breaking…