libgpod-node

Guidance for working on the libgpod N-API bindings. See AGENTS.md for project overview.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/jvgomg/podkit/libgpod-node
Clone the repo
git clone --depth 1 https://github.com/jvgomg/podkit
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 703 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00703
Opus 5 $0.00000 $0.00351
Sonnet 5 $0.00000 $0.00141
Haiku 4.5 $0.00000 $0.00070

Measured today against content hash e4e5355838fb, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

libgpod-node scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/libgpod-node.md · 50 lines

How it starts

The opening of the file, as written. The whole thing — 50 lines — stays where its author put it; the contents beside it link to each section on GitHub.

libgpod-node: Native Bindings

Guidance for working on the libgpod N-API bindings. See AGENTS.md for project overview.

The @podkit/libgpod-node package provides N-API bindings to libgpod. While it aims to closely follow libgpod's API, some operations have enhanced behavior to handle edge cases that libgpod doesn't address automatically.

Documentation Requirement

When modifying libgpod-node native code:

  1. Document behavioral deviations - If the binding behaves differently from raw libgpod, document it in:

    • packages/libgpod-node/README.md under "Behavioral Deviations from libgpod"
    • Inline comments in the native C++ code explaining the deviation
  2. Explain the "why" - Include:

    • What libgpod does (or doesn't do)
    • What problems this causes (assertion failures, data corruption, etc.)
    • How our implementation differs
    • Why we can't just use libgpod's default behavior
  3. Add test coverage - Create integration tests that verify the edge case is handled correctly

Current Deviations

See packages/libgpod-node/README.md for the full list. Key deviations:

Operation libgpod Issue Our Fix
removeTrack() Doesn't remove from playlists Remove from all playlists first
create() No master playlist Create master playlist
clearTrackChapters() NULL chapterdata crashes Create empty chapterdata
replaceTrackFile() copyTrackToDevice() no-ops if already transferred Reset transferred flag, overwrite file in place

Scope: Database Operations Only (post-P2)

As of P2 (m-18 device-capability architecture), @podkit/libgpod-node is database-only. It handles reading and writing the iTunesDB via libgpod — nothing else.

USB firmware inquiry (itdb_read_sysinfo_extended_from_usb, the dlsym shim, the libusb build dependency) was removed in TASK-293.04. That capability now lives entirely in @podkit/ipod-firmware, which uses the usb npm package (which bundles its own prebuilt libusb). The native binding no longer requires libusb at build or runtime — no HAVE_LIBUSB patch, no libusb-1.0-0-dev system header.

Read the full file on GitHub · 50 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today First seen · 50 lines · 0 tokens per session scan A e4e5355838fb

Subscribe to this mod's changes

libgpod-node is an agent published in the GitHub repository jvgomg/podkit (39 stars, last pushed 8d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 703 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-01.