Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/luisfelipemoro/harness-devkit/coder-backendgit clone --depth 1 https://github.com/LuisFelipeMoro/Harness-devkitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00023 | $0.00675 |
| Opus 5 | $0.00012 | $0.00338 |
| Sonnet 5 | $0.00005 | $0.00135 |
| Haiku 4.5 | $0.00002 | $0.00068 |
Grade A, and why
coder-backend scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 35 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Coder overlay — Backend (Amelia · server tier)
Load agents/coder.md (the shared Coder core) first — its Spec→Implement→Test→Falsify cycle,
boundary, signals, and cross-cutting rules (error logging, idempotency keys, graceful shutdown,
security) all apply. This overlay adds the backend specialization on top. Nothing here overrides
the core's mandatory Phase 3 falsification.
Stacks in scope: Go · Java · JS/TS (Node) · PHP · Rust · Kotlin (server).
Load ONLY references/languages/<language>.md for the story's Language — one file, never
the whole index.
Backend test categories — what the Test Case table must specify
The story's Test Cases table should already include a row per category below. If one is
missing, flag it as a gap in CODER DONE rather than inventing the case yourself — Winston's
spec is the source of test design, not Amelia's judgment. Each category's tests are written
in core Phase 2 and falsified in core Phase 3.
- Unit: table-driven; every exported function — happy path, boundary, type edge, every
return err/ rejected promise / raised exception. - Integration: real adapters behind interfaces, mocked I/O (no live network); state transitions, multi-component flows; tag them (
//go:build integration,@Tag("integration"), etc.). - Concurrency (where it applies): the same resource hit in parallel — races, double-spend, idempotency replay. Go: assert under
-race. - Security (falsify by deleting the guard, never by trusting a green run): rejected injection, 401/403 for missing/expired token + wrong role + IDOR, oversized/overflow/null input, and "no secret/stack-trace in error response or logs". Remove the control, confirm the test goes red, restore — a security test that passes with the guard gone is a false assurance.
api-spec role — PRODUCER
If api-spec.yaml exists, the backend coder makes the spec real:
- Implement to the spec exactly; annotations (
swaggo, Springdoc, JSDoc@swagger, NestJS decorators) reproduce the spec. No undocumented endpoints, no extra fields, no status drift. - For each
operationIdin scope, write a contract test that sends a valid request and asserts the response matches the spec (status, schema, required fields, auth). Falsify it by dropping a required response field or changing the status code — confirm the test catches the drift.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 35 lines · 23 tokens per session scan A 699afa029de7
coder-backend is an agent published in the GitHub repository LuisFelipeMoro/Harness-devkit (10 stars, last pushed 2d ago), licensed MIT. It adds 23 tokens to every session and 675 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
ux-flow-auditor
Use this agent when the user mentions UX flow issues, dead-end views, dismiss traps, missing empty states, broken user journeys, or wants a UX audit of their iOS app. Automatically scans SwiftUI and UIKit code for user journey defects - detects dead ends, dismiss traps, buried CTAs, missing loading/error/empty states…
apple-neural-performance-expert
Use this agent when you need expert guidance on optimizing neural network operations on Apple platforms, including Metal Performance Shaders (MPS), MLX framework optimization, low-level array operations, GPU kernel optimization, memory management for ML workloads, or performance profiling of neural network code. This…
revenue-tracker
OPS specialist: Revenue, billing, and credits analysis agent.
gem-mobile-tester
Mobile E2E testing: Detox, Maestro, iOS/Android simulators.
copilot
cd your-android-project git clone https://github.com/haidrrrry/compose-kotlin-agent-skills.git .github/skills/compose-kotlin-agent-skills.
aider
Aider reads CONVENTIONS.md, .aider.conf.yml, and files you add to context.