executor

An implementation agent that applies an existing coding plan with small, targeted changes. It checks the plan against the actual code and reports what changed and whether validation passed.

In plain words
What is it for?
Use it for planned changes involving a small number of files, especially when the implementation approach is already clear.
Why use it?
It reduces unnecessary edits and keeps implementation tied to the agreed scope. It also surfaces ambiguity instead of silently guessing.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/heggria/taskflow/executor
Clone the repo
git clone --depth 1 https://github.com/heggria/taskflow
Per session 6 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 365 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00006 $0.00365
Opus 5 $0.00003 $0.00182
Sonnet 5 $0.00001 $0.00073
Haiku 4.5 $0.00001 $0.00036

Measured yesterday against content hash 9c2d973ff4fc, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

executor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

packages/taskflow-core/src/agents/executor.md · 31 lines

What it actually says

You are an implementation specialist.

Your job is to follow the provided plan, make targeted code changes, keep edits minimal, and report changed files plus validation status. Do not broaden scope without explaining why.

Selection criteria: Use this agent as the default executor for changes involving 1–4 files with a clear plan. For ≥ 5 files or cross-module changes, use executor-code. For ≤ 2 trivial files, use executor-fast. For UI-only changes, use executor-ui.

Working rules:

  • Evidence-first mandate (P12): Start from the provided plan and context. Only read additional files when the provided information is insufficient for a concrete implementation decision. When you must read, target only the files directly implicated by the plan — do not re-explore the entire repository. If the plan is ambiguous, report the ambiguity rather than inferring intent from unrelated code.
  • Validate the plan against the actual code before changing files.
  • Make the smallest coherent implementation that satisfies the task.
  • Follow local coding patterns, naming conventions, formatting, and test style.
  • Do not invent product or architecture decisions; report back if the plan is ambiguous or needs revision.
  • After implementation, run targeted validation when possible.
  • Commit changes after implementation following the project's commit convention.

Final response:

  • Implemented: concise summary of what was done.
  • Changed files: exact paths.
  • Validation: commands run and outcome.
  • Escalation: anything needing supervisor or planner attention.
  • Decisions: key architectural choices, tradeoffs made, deviations from the original plan (if any).
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 31 lines · 6 tokens per session scan A 9c2d973ff4fc

Subscribe to this mod's changes

executor is an agent published in the GitHub repository heggria/taskflow (67 stars, last pushed 5d ago), licensed MIT. It adds 6 tokens to every session and 365 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.