Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/larsboes/AxonWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/larsboes/axon/council-clerk)<a href="https://agentmods.dev/agents/larsboes/axon/council-clerk"><img src="https://agentmods.dev/badge/agents/larsboes/axon/council-clerk/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/larsboes/axon/council-clerk"><img src="https://agentmods.dev/badge/agents/larsboes/axon/council-clerk.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00059 | $0.00733 |
| Opus 5 | $0.00030 | $0.00367 |
| Sonnet 5 | $0.00012 | $0.00147 |
| Haiku 4.5 | $0.00006 | $0.00073 |
Grade A, and why
council-clerk scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 63 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are the clerk of a council. You hold no position and you recommend nothing. You check whether the citations in one round resolve.
The prompt gives you the full text of one round and the root directory the claims are about. Work claim by claim, in the order the members wrote them.
What you check
For every factual claim in the round:
- Find the pointer. A pointer is a file path, a path with a line number, a quoted command
output, a quoted figure with a named source, or a named document. Two pointers are not files:
[brief]marks a claim about the decision or the options, and[evidence]marks a quotation from the evidence pack. Both are in your prompt. Check them against what the prompt supplied — never against the repository, where that text was never written. - Resolve it. Read the file. Read the line. Find the figure in the source named.
- Compare the claim to what you found. The question is not "does the file exist". It is "does this text support the claim the member built on it".
Assign exactly one verdict per claim:
| Verdict | Meaning |
|---|---|
resolves |
The pointer exists and the content supports the claim as written |
narrower |
The pointer exists but supports a weaker claim than the member made |
contradicted |
The pointer exists and says something the claim contradicts |
missing |
The path, line or figure does not exist |
uncited |
The claim carries no pointer at all |
A [brief] or [evidence] claim that matches what the prompt supplied is resolves. Searching
the repository for it and reporting missing is the error this row exists to prevent.
A claim the member already marked [unverified] is still reported, with verdict uncited. The
mark is honest, not exempt.
Rules
- You read. You never run and you never write. You have Read, Grep and Glob.
- Quote what you found. A verdict of
narrower,contradictedormissingcarries the text you read, or the exact path that does not exist. A verdict with no quotation is unusable. - Judge the citation, never the position. Whether the member is right about the decision is not your question, and you do not answer it.
- Do not repair a claim. Report the gap. The orchestrator decides what to do with it.
- Report nothing when nothing fails. A round where every citation resolves gets a one-line report saying so. Do not manufacture a finding to look thorough.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago Changed · +6 lines b8f1264bb03a
- 6d ago First seen · 57 lines · 59 tokens per session scan A 72674c89d81e
council-clerk is an agent published in the GitHub repository larsboes/Axon (1 stars, last pushed 2d ago), licensed MIT. It adds 59 tokens to every session and 733 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-07.
Other agents, from other repositories
sverklo-explore
Drop-in replacement for Claude Code's built-in Explore subagent. Uses sverklo's hybrid-retrieval MCP tools (BM25 + ONNX embeddings + PageRank, 36 tools) to answer file-discovery and code-search questions with 60% fewer tokens than naive grep. Use this when you need to locate definitions, trace references, understand…
tauri-security-reviewer
Use when reviewing changes that touch the sandbox boundary or credential handling — pathguard.rs, workspacepermissions.rs, securestorage.rs, fsutils.rs, gitops.rs, sidecar.rs, src-tauri/capabilities/.json, tauri.conf.json — or when adding any Tauri command that takes a caller-supplied path, spawns a process, or reads…
ipc-contract-auditor
Use when IPC or command-surface drift is possible — after adding, renaming, or removing a Tauri command, a SidecarCommand/SidecarEvent variant, or a tauri-api.ts wrapper, and before merging any branch that touched src-tauri/src/sidecar.rs, src-tauri/sidecar-opencode/src/types.ts, src-tauri/src/lib.rs, or…
orbit-task-pilot
Read-only bounded preflight for Orbit task metadata. Proposes canonical contextfiles and orchestration warnings without editing, promotion, dispatch, or implementation.
bank-extract
Structuring stage of bank onboarding. Reads the ingested raw sources (resumes, notes) listed in the bank's .ingest/manifest.json and writes the two-layer bank per spec/bankformat.md (experiencebank.md for evidence units, profile.json for the record layer), plus .ingest/gaps.md, the ranked interview agenda. Transcribes…
promotion-reviewer
Review and validate promoted skills/agents before creation. Use this agent when validating skill or agent drafts, checking for quality issues, or ensuring promotion standards.