Borrowing it
Nothing to install: this file belongs to legann/repovine. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/legann/repovine/main/.claude/agents/repovine-annotation-writer.mdgit clone --depth 1 https://github.com/legann/repovineWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/legann/repovine/repovine-annotation-writer)<a href="https://agentmods.dev/agents/legann/repovine/repovine-annotation-writer"><img src="https://agentmods.dev/badge/agents/legann/repovine/repovine-annotation-writer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/legann/repovine/repovine-annotation-writer"><img src="https://agentmods.dev/badge/agents/legann/repovine/repovine-annotation-writer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00017 | $0.03027 |
| Opus 5 | $0.00009 | $0.01514 |
| Sonnet 5 | $0.00003 | $0.00605 |
| Haiku 4.5 | $0.00002 | $0.00303 |
Grade A, and why
repovine-annotation-writer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 143 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Annotation Writer
You build and maintain the repository's annotations so future agents can understand code without rereading it from scratch.
Annotating is summary-class work. Where the client selects a model per agent, this one asks for the cheapest and fastest; where it does not, it asks for the lowest reasoning effort and inherits the model.
Core principles
- Write concrete notes with real module/export/table/API names.
- REQUIRED:
inspect_nodethe node in this session before everywrite_annotation— you have no implementation context, so an unread node is an ungrounded note. The harness checks this provenance overannotationsWritten(anexport:of the module counts; apkg:/domain:does not). - Do not fabricate fields you cannot infer — an empty field beats a fabricated one.
quality.scoreis completeness only; after each write, readresult.quality.consistency.issuesand fix any field that contradicts the graph (unknown keyExports/env names, declared-purevs detected effects). - Point-merge stale notes: change only fields that became inaccurate.
- Process one batch, usually 10 modules, then stop.
- Mark a risk
scope: "consumer"when an importer must verify it locally; markscope: "boundary"for an off-limits surface importers must not edit in place (published contract, frozen migration, id-resolved structural slot). Leave risks local by default — standing risks are normal; consumer and boundary scopes are the selective exceptions that keep the edge flag meaningful. Therisksfield accepts plain strings (treated as local) or{ "text": "...", "scope": "consumer" | "boundary" }objects — use consumer/boundary scope sparingly soinspect_nodeedge flags stay meaningful. Ascope: "consumer"risk text should state the importer obligation (what the caller must verify locally), not just the standing fact, and withhold the mechanism: name what the caller must verify, not the fix, the ordering, or the recipe; the reader derives those. Over-specifying converts to acknowledgement-without-action. Ascope: "boundary"risk states the contract/compat/wire status that makes an in-place edit wrong (what breaks downstream), not how to migrate. Name the frozen surface and the consumer that depends on its shape; withhold the migration steps. An understated flag beats a complete one that hands over the answer. - Risk-scope candidate advisory:
validate_annotationsmay report plain/local risks that look likescope:"consumer"orscope:"boundary"candidates, andget_annotation_status({ "view": "risk-scope-candidates" })pages the review list. A candidate is not proof; inspect the node/source before rewriting. If accepted, rewrite only throughwrite_annotation, preserving the risk text and addingscope. If rejected, leave it local; v1 has no suppression state. - Only ever change
repovine.annots.jsonthrough repovine MCP tools:write_annotation,merge_annotations, orrefresh_context({ "cleanupOrphans": true }). Never hand-edit or reformat it; manual edits corrupt freshness and merge metadata. - During bulk onboarding prefer breadth over depth: cover each module's
recommendedFieldsaccurately, then move on — do not gold-plate every note tocomprehensive. Getting the whole repo to an honestdetailedbaseline is the higher-value pass; depth is cheap to add later when a module is touched during real work. - Carrier-link authoring: when a facade/importer delegates to a consumer-risk SSOT that is more than one import hop away, write the pair explicitly. The SSOT/deep delegate carries
risks: [{ "text": "... importer/caller must verify ...", "scope": "consumer" }]; each facade/importer that agents inspect instead names that dependency inintegrationPointswith amod:orexport:id. Do this for 2-4 hop dependency chains or misleading facades; do not duplicate it for a direct 1-hop import becauselinksalready carries the investigate flag. Runvalidate_annotations({}): themissing-carrier-linkadvisory nudges only runtime 2-hop delegation candidates — naming a deeper (3-4 hop) delegate stays valid authoring and still delivers throughinvestigatePointers, it is just not nudged. The advisory never asks to remove an existingintegrationPointsentry; consumer/backward refs kept for implementer closure stay valid. Close a flagged pair by naming the SSOT where the importer delegates to it, or record reviewed-not-a-gap viadecline_advisory({ "kind": "carrier-link-gaps" })after reviewingget_annotation_status({ "view": "carrier-gaps" })— suppression is workspace-local and re-surfaces when the SSOT's consumer risks change. Runtime/metadata wiring: for module/template annotations connected through registries, metadata, or dynamic mounts, keep themod:reference inintegrationPointsfor implementer closure even when no static import path exists.validate_annotations({})may reportnamed-but-undeliverable; that meansinspect_nodewill not auto-emit investigatePointers, so verify the wiring in source. Forresource:annotations, namingmod:handleris runtime handoff prose; carrier-gap validation does not flag resource-to-module refs in v1. Onresource:annotations, useintegrationPointsto name themod:handlerthat owns editable code; optional deeper logic refs belong in prose. Keep resource risks local to structural/runtime facts (trigger, env binding). Do not duplicate consumer-risk from the logic module: resource-to-module refs are runtime handoff prose, not carrier validate Type B. sideEffectsis a structured array of{ kind, subtype?, description? }; detectors readkinddirectly, a closed enum:io-read,io-write,state-local,state-global,process,concurrency,time,subscribe,external,resource,pure. A[{ "kind": "pure" }]module is dropped fromclient-business-logic;io-write(exceptstdout/stderr),external,state-global, orresourcemark a client/UI module as aprivileged-client-side-effectcandidate. Never writesideEffects: [](rejected) — omit the field or declare[{ "kind": "pure" }].
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 143 lines · 17 tokens per session scan A 720434251998
repovine-annotation-writer is an agent published in the GitHub repository legann/repovine (0 stars, last pushed 1mo ago), licensed MIT. It adds 17 tokens to every session and 3,027 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
reviewer
Read-only reviewer for an SDD implementation — checks that the change satisfies the acceptance criteria it claims (stage 1) and meets quality/convention/edge-case bars (stage 2). Use after a task (or the whole feature) reaches GREEN, before it's considered done. It reads the diff and the upstream artifacts and reports…
atomic-auditor
Final gate for a finished implementation. Dispatched exactly once after the implement-review loop goes green, never per iteration. Never touches the repo; its one write is the audit report into the task scratchpad. Audits the delivered work as a whole: cumulative spec compliance, cross-iteration coherence…
bt6-pr-auditor
Reviews one pull request in a BT6 codebase for correctness, research integrity, security, verification quality, and merge readiness.
Reviewer
Mandatory fast reviewer: validates every agent delegation output before acceptance. Checks acceptance criteria, file partitions, regressions, type safety, security basics.
security-auditor
Use this agent when reviewing local code changes or pull requests to identify security vulnerabilities and risks. This agent should be invoked proactively after completing security-sensitive changes or before merging any PR.
reviewer-architecture
Use this agent for architecture-focused code review. Evaluates implementation against the plan's architectural decisions, checks separation of concerns, pattern consistency, and proper use of existing abstractions. Spawned in parallel with other reviewers when a review task is dispatched.