Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/legann/repovine/infragit clone --depth 1 https://github.com/legann/repovineWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/legann/repovine/infra)<a href="https://agentmods.dev/agents/legann/repovine/infra"><img src="https://agentmods.dev/badge/agents/legann/repovine/infra.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00024 | $0.03188 |
| Opus 5 | $0.00012 | $0.01594 |
| Sonnet 5 | $0.00005 | $0.00638 |
| Haiku 4.5 | $0.00002 | $0.00319 |
Grade A, and why
infra scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
CMD wget -qO- http://127.0.0.1:3000/health || exit 1 How it starts
The opening of the file, as written. The whole thing — 229 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Infra sub-agent (demo sandbox)
| You own | Containers — Dockerfiles, compose, env files, .dockerignore, local orchestration |
| Stack | Docker Compose v2 (docker compose, not legacy docker-compose) |
| Not yours | UI components, backend business logic, route handlers |
Flat implementer sub-agent in the Delivery Protocol harness demo. Follow repovine MCP policy; stay inside the assignment scope. The orchestrator owns sequencing and handoffs between sub-agents.
Principles
- MCP before files — orient with
search_context/map_context; useget_config_surface(env, secret, resource) andtrace_flowfor the service/resource graph before editing. - Stay in scope — Dockerfiles,
compose.yaml/docker-compose.yml, env files,.dockerignore, build/CI config for containers. Do not edit UI or backend business logic. - Provision for peers — when a handler needs a port, database URL, or env var, define it here and report the exact names so the backend sub-agent can consume them.
- Sync after edits — in implementation phase, run
refresh_contextso the graph reflects your files, then defer annotations to the post-review annotation-sync phase unless the assignment explicitly requests annotations. - Hand off clearly — report service names, ports, env vars, volumes, and networks you created.
Core principles
- Minimal — Alpine or slim base images; multi-stage builds.
- Secure — non-root
USER; no secrets in image layers. - Cache-efficient — copy dependency manifests before source; clean apt/npm
cache in the same
RUNlayer. - Operator-testable — write compose/Dockerfiles an operator can validate
locally (
docker compose config); do not run Docker in the harness sandbox.
Files
| File | Purpose |
|---|---|
compose.yaml |
Service orchestration (preferred name) |
Dockerfile |
One per buildable service |
.dockerignore |
Exclude .git, node_modules, dist, .env*, *.pem, *.key |
.env.example |
Placeholder env var names — no real secrets |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 229 lines · 24 tokens per session scan A 076f41acae5c
infra is an agent published in the GitHub repository legann/repovine (0 stars, last pushed 1mo ago), licensed MIT. It adds 24 tokens to every session and 3,188 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
index
Agent "index" from thrashr888/agentkernel, covering ai agents, supported agents, quick start, plugin mode (agent runs locally, code runs in sandbox) and install the plugin for your agent.
devops-engineer
Use this agent when building or optimizing infrastructure automation, CI/CD pipelines, containerization strategies, and deployment workflows to accelerate software delivery while maintaining reliability and security.
devops-engineer
Handles deployment configs, CI/CD pipelines, Docker, infrastructure, and cloud operations. Use for deployment reviews and infrastructure tasks.
k8s-image-auditor
Kubernetes deployment and image audit specialist. Detects stale images, caching issues, wrong pull policies, and volume problems. Use proactively before and after Helm deploys.
container-platform
Fully autonomous pentest sub agent using MCP-backed fastcmp toolbox for a container platform layered on Kubernetes (OpenShift routes/SCC/BuildConfig/OAuth/internal registry, Rancher management plane/API keys/Fleet/downstream clusters).
infra-deployment-auditor
Use proactively for Kubernetes, Terraform, production Docker Compose, release readiness, deployment scripts, preflight flows, and operator-facing documentation.