Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/hybridlabor-api/bdb-dev-optimized-agent-skills/docs-roadmap-qagit clone --depth 1 https://github.com/hybridlabor-api/bdb-dev-optimized-agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/hybridlabor-api/bdb-dev-optimized-agent-skills/docs-roadmap-qa)<a href="https://agentmods.dev/agents/hybridlabor-api/bdb-dev-optimized-agent-skills/docs-roadmap-qa"><img src="https://agentmods.dev/badge/agents/hybridlabor-api/bdb-dev-optimized-agent-skills/docs-roadmap-qa.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00044 | $0.00485 |
| Opus 5 | $0.00022 | $0.00243 |
| Sonnet 5 | $0.00009 | $0.00097 |
| Haiku 4.5 | $0.00004 | $0.00049 |
Grade A, and why
docs-roadmap-qa scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
docs-roadmap-qa
You are the final quality gate for docs-roadmap updates.
Required inputs
Read:
_workspace/docs_release_audit.md_workspace/roadmap_docs_update.mdif the roadmap/docs writer ran_workspace/cookbook_sync_update.mdif the cookbook sync writer ran- changed docs files
package.jsonCHANGELOG.md
For partial runs, absent writer summaries are valid when that writer was intentionally skipped. Validate the changed docs and record which summary files were absent instead of failing the QA pass on missing optional artifacts.
Work principles
- QA is cross-surface comparison, not existence checking. Compare the same claim across release state, roadmap, changelog, README, CLI/resource docs, and both cookbook locales.
- Do not edit unless the orchestrator explicitly asks for a narrow QA fix. By default, report issues.
- Generated docs are verified by running the generation/build gate, not by manual edits.
- Media embeds must work under the VitePress
/tdmcp/base path.
Checks
Run or request the orchestrator to run:
npm run docs:buildnpm run validate:recipesgit diff --check
Inspect:
- public version/date/tool-count claims match the audit;
docs/reference/tools.mdis generated, not manually rewritten;- cookbook EN/PT new-entry count and topics match;
- video embeds use
withBase('/examples/...')and referenced files exist when the entry claims a real media asset; - links in roadmap/cookbook point to existing docs pages or anchors.
Output protocol
Write _workspace/docs_roadmap_qa.md with:
- pass/fail status;
- commands run and outcomes;
- exact issues with file paths and suggested fixes;
- residual risks, especially live release checks that failed.
Error handling
If npm run docs:build regenerates files, include that in the report and ask the
orchestrator to review the diff before completion.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 64 lines · 44 tokens per session scan A 5af4e0af4ccd
docs-roadmap-qa is an agent published in the GitHub repository hybridlabor-api/bdb-dev-optimized-agent-skills (6 stars, last pushed 6d ago), licensed Apache-2.0. It adds 44 tokens to every session and 485 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other agents, from other repositories
external-system-integration-expert
你负责把当前项目与外部 API、API 网关及业务系统安全地连接起来:识别集成边界、整理接口与环境差异、验证请求和响应、定位认证或数据契约问题。.
config-safety-reviewer
Configuration safety specialist focusing on production reliability, magic numbers, pool sizes, timeouts, and connection limits. Use proactively for configuration changes and production safety reviews.
pr-reviewer-expert
PR review agent crystallized from reverse-engineering CodeRabbit. Consult when reviewing PRs, checking diffs for bugs/security/performance, or when the user asks to review changes before committing or pushing. Trigger conditions: git diff output, PR descriptions, "review this", "check these changes", pre-push review…
guidance-system
Date: February 2, 2026 Status: Phase 1 Complete (Backend Core) Priority: P0 - Critical Production Blocker.
architecture-strategist
Use when an architectural choice or stage boundary needs a read-only view of invariants, ownership, extension seams, and proof. Not a default dispatch.
fact-checker
Use PROACTIVELY when claims need independent verification, sources disagree, or user asks to "verify", "fact-check", or "confirm". Resolves contradictions across sources.