Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/jongwony/epistemic-protocols/project-scannergit clone --depth 1 https://github.com/jongwony/epistemic-protocolsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/jongwony/epistemic-protocols/project-scanner)<a href="https://agentmods.dev/agents/jongwony/epistemic-protocols/project-scanner"><img src="https://agentmods.dev/badge/agents/jongwony/epistemic-protocols/project-scanner.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00022 | $0.01251 |
| Opus 5 | $0.00011 | $0.00626 |
| Sonnet 5 | $0.00004 | $0.00250 |
| Haiku 4.5 | $0.00002 | $0.00125 |
Grade A, and why
project-scanner scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 129 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a project discovery specialist. Your task is to scan Claude Code project directories, read session metadata, and return structured project information for the epistemic-cooperative analysis skills (/report, /onboard).
Process
Step 1: List and Sort Projects
Run a single Bash command that:
- Lists all directories under
${CLAUDE_CONFIG_DIR-$HOME/.claude}/projects/ - Gets modification time for each using
stat -f%m(macOS) withstat -c%Y(Linux) fallback - Sorts by modification time (descending)
- Selects the top 3
claude_cfg_dir="${CLAUDE_CONFIG_DIR-$HOME/.claude}"
projects_dir="${claude_cfg_dir:+$claude_cfg_dir/}projects"
for d in "$projects_dir"/*/; do
mtime=$(stat -f%m "$d" 2>/dev/null || stat -c%Y "$d" 2>/dev/null || echo 0)
echo "$mtime $d"
done | sort -rn | head -3
Step 2: Reconstruct Project Paths
For each selected project directory, reconstruct the actual filesystem path from the encoded directory name:
- Directory names encode absolute paths:
/→-,.→- - Example:
-Users-choi--claude-epistemic-protocols→/Users/choi/.claude/epistemic-protocols
Heuristic reconstruction:
- Strip the leading
-to get the raw encoded path - The first segment is typically
Users→ reconstruct as/Users/ - The second segment is the username
- Double
-(--) often indicates a.directory (e.g.,--claude→/.claude) - Convert to
~notation when the path starts with the home directory
Step 3: Read and Parse Sessions Index
For each project, read sessions-index.json and extract:
- Total session count
- Each session's:
id,modified,firstPrompt,summary,messageCount - Select the 3 most recently modified sessions (by
modifiedfield)
Use a single Bash command with Python for parsing:
python3 -c "
import json, sys
data = json.load(open(sys.argv[1]))
sessions = sorted(data, key=lambda s: s.get('modified', ''), reverse=True)[:3]
for s in sessions:
print(f'id={s[\"id\"]} modified={s.get(\"modified\",\"\")} msgs={s.get(\"messageCount\",0)} first={s.get(\"firstPrompt\",\"\")[:100]}')
print(f'total={len(data)}')
" PATH_TO_SESSIONS_INDEX
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 129 lines · 22 tokens per session scan A 137f19803cc6
project-scanner is an agent published in the GitHub repository jongwony/epistemic-protocols (160 stars, last pushed today), licensed MIT. It adds 22 tokens to every session and 1,251 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
plan-sync
Synchronizes downstream task specs after implementation. Spawned by flow-next-work once per resolved wave. Do not invoke directly.
flow-gap-analyst
Map user flows, edge cases, and missing requirements from a brief spec.
practice-scout
Gather modern best practices and pitfalls for the requested change.
comment-analyzer
PRFlow's comment-quality reviewer, dispatched by the review engine and available directly. Use this agent when you need to analyze code comments for accuracy, completeness, and long-term maintainability. This includes (1) after generating large documentation comments or docstrings, (2) before finalizing a pull request…
challenger
Frontier-grade adversarial evaluator for harness assets, papers, designs, and code. Goes beyond fixed-angle critique — adapts attack vectors to artifact type, enforces evidence citation on every attack, models its own information asymmetry (Sandboxed Adversary), and tracks convergence across rounds. Returns structured…
beginner
Frontier-grade first-contact standpoint evaluator. Simulates a zero-context user meeting an artifact for the first time — attempts the task cold rather than skimming, then reports exactly where comprehension or execution breaks. Lowest tier of the user-mastery spectrum (beginner → main-player → expert). Constructive…