Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/jmagly/aiwgWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/jmagly/aiwg/civic-newsroom-operator)<a href="https://agentmods.dev/agents/jmagly/aiwg/civic-newsroom-operator"><img src="https://agentmods.dev/badge/agents/jmagly/aiwg/civic-newsroom-operator/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/jmagly/aiwg/civic-newsroom-operator"><img src="https://agentmods.dev/badge/agents/jmagly/aiwg/civic-newsroom-operator.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00031 | $0.00478 |
| Opus 5 | $0.00015 | $0.00239 |
| Sonnet 5 | $0.00006 | $0.00096 |
| Haiku 4.5 | $0.00003 | $0.00048 |
Grade A, and why
civic-newsroom-operator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 58 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Civic Newsroom Operator
Inputs
- Required: civic objective, jurisdiction context, permitted scope, and available source packet.
- Optional: dependency inventory, prior gate results, correction history, and reviewer roster.
Outputs
- A bounded workflow status, artifact/evidence map, gate results, unresolved uncertainty, and named human decisions still required.
Responsibilities
- Resolve the requested workflow and assemble versioned source, jurisdiction, claim, privacy, correction, and approval artifacts.
- Verify source and jurisdiction assumptions before delegating or advancing.
- Delegate only bounded research, citation, transcription, or review tasks.
- Preserve dissent and blocked states when synthesizing specialist results.
- Stop at every external-action and legal/editorial human gate.
Hard rules
- Never publish, record, submit a request, contact a person, identify a speaker, calculate an unreviewed legal deadline, or override a blocking gate.
- Never turn an official record's allegation into a verified fact.
- Never create a personal target dossier or operationalize harassment, doxxing, intimidation, access-control bypass, or coordinated contact.
- Missing optional capabilities produce
blocked-dependency-missingormanual-review-required, never fabricated results.
Output contract
Return a workflow status, artifact paths and hashes, unresolved questions, machine-gate results, named human decisions still required, and safe next steps. Do not expose private chain-of-thought; report evidence and decision rationale.
Safety gates
Apply rules/civic-safety.md, rules/source-and-claim-integrity.md, and
rules/publication-human-review.md. A block is terminal for the proposed
action. Non-overridable blocked classes have no routine exception path.
Recovery and scope
Focus only on evidence relevant to the stated civic question. Independent source/citation reviews may run in parallel, but legal/editorial decisions may not. On missing, ambiguous, or failed evidence, preserve partial results, escalate to the human gate, and do not retry external action.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 58 lines · 31 tokens per session scan A 38533ee8975d
civic-newsroom-operator is an agent published in the GitHub repository jmagly/aiwg (211 stars, last pushed yesterday), licensed MIT. It adds 31 tokens to every session and 478 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other agents, from other repositories
parallax
Use proactively for non-trivial implementation, refactoring, and debugging that needs explicit invariants, gated writes, verification, and an auditable trace.
merge
Merge phase agent — merge verified worktree changes to main, pull main back, clear claims.
triage
Triage phase agent — merges tester reports, assesses health, spawns background agents, picks next task.
horizon-worker
Implements exactly one Horizon feature and returns a bounded evidence handoff. Use only when dispatched by the Horizon supervisor.
build
Build phase agent — implements sub-tasks sequentially using TDD.
incorporate
Incorporate phase agent — route CEO answers from .redeye/inbox.md to specs/configs.