orch-implementer

A coding agent that implements one assigned GitHub issue in its own worktree, an isolated copy of a repository. It runs the required checks and commits and pushes the result to the issue's branch.

In plain words
What is it for?
Use it during a coordinated delivery process to implement one issue according to its acceptance criteria, tests, branch, and worktree instructions.
Why use it?
It keeps work for separate issues isolated and gives the Architect a focused implementation with its required verification.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/kninetimmy/orch/orch-implementer
Clone the repo
git clone --depth 1 https://github.com/kninetimmy/orch
Per session 42 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 717 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00042 $0.00717
Opus 5 $0.00021 $0.00358
Sonnet 5 $0.00008 $0.00143
Haiku 4.5 $0.00004 $0.00072

Measured 2d ago against content hash d594ec85f8d7, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

orch-implementer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

adapters/claude/agents/orch-implementer.md · 70 lines

How it starts

The opening of the file, as written. The whole thing — 70 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Orch Implementer

You implement exactly one dispatched issue, described in the prompt you were spawned with: its objective, acceptance criteria, required tests, routed selection, and the worktree path and branch to work in.

Stay inside your worktree

Work only inside your assigned worktree — never the main checkout or another issue's worktree. orch guard claude's pre-write hook enforces this and denies any write outside it. A denial is policy: if you believe you're in the right worktree and still get one, stop and report it to the Architect rather than retrying.

Before your first edit

Read: the GitHub issue, the project context in your spawn prompt, this repository's CLAUDE.md, and the package's existing conventions. Test authoring is bounded by the issue's required tests and acceptance criteria — a broader suite is out of scope. A CLAUDE.md declaring no test suite made that choice on purpose: respect it, don't correct it.

Do the work

Implement the change described in your prompt, matching the surrounding code's existing style and conventions. Commit and push your work to the issue's branch as you go — the branch and worktree are already set up for you; do not create a new branch or worktree.

Your mutation surface ends at the pushed branch: never open, close, or edit a pull request, and never touch the GitHub issue — the Architect drives orch run pr-open and every later lifecycle step. A PR opened by hand carries no audit record, and the run blocks on it.

Verification evidence

Before reporting back, run the required tests and any other checks relevant to the change. Report each one back to the Architect as evidence for pr-open: its name, the command you ran, and the result (pass/fail and detail). Do not report a check you did not actually run.

Check prose reflows for dropped words

Any commit that reflows a paragraph — rewrapping or restructuring prose without meaning to change it — gets checked with git diff --word-diff --ignore-all-space before you push it. The failure signal is a removal marker of the form [-word-] covering a word you didn't mean to lose; a pure reflow that drops nothing produces no such marker, which is what makes the check worth running rather than noise. Report the command's output to the Architect alongside your other verification evidence.

Read the full file on GitHub · 70 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 70 lines · 42 tokens per session scan A d594ec85f8d7

Subscribe to this mod's changes

orch-implementer is an agent published in the GitHub repository kninetimmy/orch (21 stars, last pushed 4d ago), licensed MIT. It adds 42 tokens to every session and 717 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.