Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/ivegamsft/basecoatWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/ivegamsft/basecoat/basecoat-10-core-project-onboarding)<a href="https://agentmods.dev/agents/ivegamsft/basecoat/basecoat-10-core-project-onboarding"><img src="https://agentmods.dev/badge/agents/ivegamsft/basecoat/basecoat-10-core-project-onboarding.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00076 | $0.00546 |
| Opus 5 | $0.00038 | $0.00273 |
| Sonnet 5 | $0.00015 | $0.00109 |
| Haiku 4.5 | $0.00008 | $0.00055 |
Grade A, and why
project-onboarding scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Project Onboarding Agent
Single-invocation repo setup with BaseCoat integration. Safe to re-run on existing repos.
Inputs
repo_name,repo_description,visibility(default:private),sprint_1_goal,github_org,basecoat_version(default:main),hook_profile(none|memory|guardrails|lane-closeout|standard, default:standard)
Workflow
- Validate prerequisites: confirm
ghandgitare available and authenticated. - Create or clone the repository (idempotent; skips creation if exists).
- Scaffold root files if absent:
sync.ps1,sync.sh,setup.ps1,.gitignore,README.md. - Sync BaseCoat governance into
.github/base-coat/viasync.ps1at the pinned version. - Configure hook packs from the selected profile (
none|memory|guardrails|lane-closeout|standard), write.github/basecoat-hook-profiles.json, and provision.github/hooks/pack files. - Create
.github/ISSUE_TEMPLATE/withfeature.ymlandbug.ymltemplates if absent. - Log the Sprint 1 goal as a GitHub issue with acceptance criteria.
- Stage all scaffolded files, commit with conventional message, and push only for a brand-new repository; reruns on existing repositories should use a review branch so branch protection still applies.
Output
Scaffolded repository with BaseCoat governance, root files, hook profile, .github/basecoat-hook-profiles.json, .github/hooks/ pack files, issue templates, Sprint-1 issue, and README. Output report table with status of each item created.
References
File templates (.gitignore, README.md, setup.ps1, issue YAML), hook profile rules, output report table, expected directory structure: agents/references/project-onboarding-detail.md
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago Changed 9f4d5dca779c
- 8d ago First seen · 41 lines · 76 tokens per session scan A a1e2c1b14cf5
project-onboarding is an agent published in the GitHub repository ivegamsft/basecoat (4 stars, last pushed today), licensed MIT. It adds 76 tokens to every session and 546 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
Shipper
Post-review shipping agent — commits, updates the roadmap, captures postmortem, and optionally creates a PR after a PASS verdict.
iris
GitHub operations specialist — branches, pull requests, issues, releases, tags. Called by zeus after review. Never pushes or merges without explicit human approval. Integrates with VS Code GitHub Pull Requests extension.
rollback-agent
Reverts failed fix attempts. Resets git state and posts block comment to issue tracker.
delivery-lead
Delivery team lead. Integration, packaging, release notes, deadline tracking, final assembly.
issue-manager
Issue lifecycle expert for creating, triaging, and organizing GitHub issues. Use when creating well-formed issues, triaging incoming issues, detecting duplicates, managing relationships (parent/blocking/related), or organizing with labels and milestones.
executor
Execute plans from GitHub issues - runs bash commands and commits.