Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/heretyc/subagent-mcp/git_collaborationgit clone --depth 1 https://github.com/Heretyc/subagent-mcpWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00713 |
| Opus 5 | $0.00000 | $0.00357 |
| Sonnet 5 | $0.00000 | $0.00143 |
| Haiku 4.5 | $0.00000 | $0.00071 |
Grade A, and why
GIT_COLLABORATION scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 73 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agent Git Collaboration Checklist
Use this checklist for repository work. The normative policy is
docs/spec/dev-loop/git-collaboration.md; AGENTS.md holds root invariants.
Before Work
- Run
git status --short --branch. - Identify unowned dirty files. Do not overwrite, stage, commit, reset, clean, rebase, move, or hide them without explicit owner authorization.
- Follow
docs/spec/safety-scope.mdfor interactive cascades, automated declarations, credential handling, and sub-agent prompts. - Read the task scope and name the owned files or directories.
- Use a topic branch for non-trivial work unless the owner explicitly directed a different workflow that still respects protected/default-branch rules.
Branches
- Branch names must pass
git check-ref-format --branch. - Use
<type>/<short-topic>or<type>/<actor>/<short-topic>. - Allowed types:
feature,fix,hotfix,release,docs,test,refactor,chore,agent,user,integration,audit. - Use lowercase ASCII, digits, hyphen, underscore, period, and single slash separators only.
- Do not reuse merged, closed, abandoned, or stale branches.
- Do not force-push or rewrite shared history without explicit coordination.
Worktrees
- Use at most one writable worktree per branch.
- Put linked worktrees under a sibling worktree root, never inside another repository or worktree.
- Before branch/worktree cleanup or force-updates, inspect
git worktree list --porcelain -z. - Use
git worktree removefor cleanup and do not remove unclean worktrees unless work is committed, preserved, or confirmed disposable.
Commits
- Inspect the exact staged diff before committing.
- Commit the smallest coherent logical unit.
- Do not commit unrelated changes, conflict markers, secrets, debug output, generated noise, caches, large artifacts, or unverified work.
- Add tests or validation for behavior changes, or record why not.
- Do not add AI attribution or co-author lines.
- Do not use
--no-verifyor empty commits unless policy explicitly requires it.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 73 lines · 0 tokens per session scan A eca97118d329
GIT_COLLABORATION is an agent published in the GitHub repository Heretyc/subagent-mcp (3 stars, last pushed 4d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 713 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
content-producer
Agent san xuat noi dung — viet script, copy, brief creator, lap lich noi dung.
personal-brand-builder
Agent xay dung thuong hieu ca nhan voi AI Avatar — chien luoc, content engine, monetization, community cho founder/coach/creator.
accessibility-specialist
Accessibility expert: WCAG 2.2 audits, screen reader compat, keyboard navigation, ARIA patterns, automated a11y testing.
external-system-integration-expert
你负责把当前项目与外部 API、API 网关及业务系统安全地连接起来:识别集成边界、整理接口与环境差异、验证请求和响应、定位认证或数据契约问题。.
ba-designer
Use when execute-round skill's Phase 2 (BA design pass) needs to produce a complete BA design doc for the current round. Generates D-1..D-N decisions, reference scan triplet, file-level decomposition, and test plan.
Audit
Deep security + performance audit of a specific diff. Wraps /skill:security-hardening and /skill:performance-optimization (analysis phase only). Use when a change touches auth, untrusted input, secrets, webhooks, PII, or a latency/throughput budget — a focused, read-only risk pass that returns findings the parent…