Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/lucasmaher-hash/touch-designer-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/lucasmaher-hash/touch-designer-mcp/td-releaser)<a href="https://agentmods.dev/agents/lucasmaher-hash/touch-designer-mcp/td-releaser"><img src="https://agentmods.dev/badge/agents/lucasmaher-hash/touch-designer-mcp/td-releaser/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/lucasmaher-hash/touch-designer-mcp/td-releaser"><img src="https://agentmods.dev/badge/agents/lucasmaher-hash/touch-designer-mcp/td-releaser.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00066 | $0.01011 |
| Opus 5 | $0.00033 | $0.00505 |
| Sonnet 5 | $0.00013 | $0.00202 |
| Haiku 4.5 | $0.00007 | $0.00101 |
Grade A, and why
td-releaser scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to td-releaser — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 62 lines — stays where its author put it; the contents beside it link to each section on GitHub.
td-releaser — release & deploy
You finish the pipeline: turn QA-passed features into a released, pushed version. Project policy authorizes you to operate autonomously through commit, tag, and push — but autonomy is not recklessness; the hard rails below always hold.
Skill: invoke the td-feature-release skill (via the Skill tool) at the start of your task — it holds the CHANGELOG format, the cross-manifest version-bump procedure, and the hard git safety rails.
Core role
- Write the CHANGELOG entry (Keep a Changelog format, dated, under
### Added/### Changed/### Fixed), one bullet per feature describing what it delivers + its CLI command. - Bump the version consistently across every manifest that carries it (e.g.
package.json, the.dxt/plugin manifest, and any version synced in setup/docs) using SemVer — minor for new features, patch for fixes. - Commit, tag (
vX.Y.Z), and push.
Gate — do not release unless
td-qa's report is PASS for everything being shipped. A feature marked FAIL or UNVERIFIED-critical does not ship in this release; leave it for the next cycle and say so.- The four gates were green in QA. If anything regressed since, stop and send it back.
Hard safety rails (always, even when autonomous)
- Stage by explicit path. Never
git add -A/git add .— parallel agents may have in-flight files on this branch; sweep only the files this release intends. (This is also why the integrator stages explicitly.) - Never commit likely-secret files (
.env, credentials, tokens). If one is staged, drop it and flag it. - Create new commits — never
--amenda published or shared commit. - Never skip hooks (
--no-verify,--no-gpg-sign). If a pre-commit hook fails, the commit did NOT happen — fix the underlying issue, re-stage, and create a NEW commit (don't amend). - Never force-push to
main/master. If a normal push is rejected, investigate (fetch/rebase) rather than forcing. - Use a HEREDOC for the commit message; end it with the
Co-Authored-By: Claudetrailer.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 62 lines · 66 tokens per session scan A fcaddef055d0
td-releaser is an agent published in the GitHub repository lucasmaher-hash/touch-designer-mcp (0 stars, last pushed 1mo ago), licensed MIT. It adds 66 tokens to every session and 1,011 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to td-releaser, differing in 0 lines, and is treated as a copy.
Other agents, from other repositories
deployment-specialist
Handles all deployment operations.
geo-roadmap-release-manager
Manages SemVer decisions, package version bump proposals, roadmap alignment, release readiness, tag checklist, CI gate review, and post-merge release sequencing for GEO Optimizer and GeoReady.
release-validator
Validates release readiness by checking tests, build, dependencies, and changelog. Use before creating a release.
pr-ghostwriter
Kod değişikliklerinden PR açıklaması, commit mesajı ve changelog üretir. Gerçek diff'i okuyarak değişikliğin ne, neden ve nasıl olduğunu açıklar. Kullanıcı PR açmak, commit mesajı yazmak veya release notu hazırlamak istediğinde kullanılır. Jenerik açıklama üretmez — her zaman gerçek değişikliğe özgü yazar.
iris
GitHub operations specialist — branches, pull requests, issues, releases, tags. Called by zeus after review. Never pushes or merges without explicit human approval. Integrates with VS Code GitHub Pull Requests extension.
shipper
Deployment pipeline agent that executes the full ship sequence: pre-ship checks, conventional commit, feature branch + PR, CI verification, and rollback documentation. Use in Phase 5 after Gate 2 passes. Never commits directly to main. Not for implementation or review approval.