bibliography_agent

bibliography_agent is an agent for Claude Code from Lzy599775/agent-auto-sci-skills. It costs 26 tokens per session (7,755 once invoked), scanned C, a copy of bibliography_agent, MIT.

A literature-search and bibliography agent that finds, selects, annotates, and formats sources in APA 7 style. An annotated bibliography lists sources with short explanations of their relevance.

In plain words
What is it for?
Use it to search research literature, apply inclusion and exclusion rules, create an annotated bibliography, and prepare APA 7 references.
Why use it?
It makes source collection more systematic and records how the search was performed and which sources were included.

Agent for Claude Code

Written for Claude Code: PreToolUse hook event. Also seen: mentions Codex.

Good fit Use it to search research literature, apply inclusion and exclusion rules, create an annotated bibliography, and prepare APA 7 references.

Compare 6 agents from other repositories ↓
Install with agentmods
npx agentmods add agents/lzy599775/agent-auto-sci-skills/bibliography_agent
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/Lzy599775/agent-auto-sci-skills

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for bibliography_agent

README.md
[![agentmods](https://agentmods.dev/badge/agents/lzy599775/agent-auto-sci-skills/bibliography_agent/github.svg)](https://agentmods.dev/agents/lzy599775/agent-auto-sci-skills/bibliography_agent)
Your own site
<a href="https://agentmods.dev/agents/lzy599775/agent-auto-sci-skills/bibliography_agent"><img src="https://agentmods.dev/badge/agents/lzy599775/agent-auto-sci-skills/bibliography_agent/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for bibliography_agent

Your own site · 80×15
<a href="https://agentmods.dev/agents/lzy599775/agent-auto-sci-skills/bibliography_agent"><img src="https://agentmods.dev/badge/agents/lzy599775/agent-auto-sci-skills/bibliography_agent.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 26 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 7,755 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00026 $0.07755
Opus 5 $0.00013 $0.03877
Sonnet 5 $0.00005 $0.01551
Haiku 4.5 $0.00003 $0.00775

Measured 3d ago against content hash d6dc70e8775a, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade C, and why

bibliography_agent scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Hidden instructionshighPrompt injection

Directives inside HTML comments, invisible characters or bidirectional overrides are read by the model and not by the person reviewing the file.

<!-- canonical:instruction-data-boundary -->
Origin

This is a copy

100% identical to bibliography_agent — 36 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

skills/urban-exposure-review-radar-workflow/subskills/academic-research-suite/ars/deep-research/agents/bibliography_agent.md · 474 lines

How it starts

The opening of the file, as written. The whole thing — 474 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Bibliography Agent — Systematic Literature Search & Curation

Role Definition

You are the Bibliography Agent. You conduct systematic, reproducible literature searches. You identify relevant sources, apply inclusion/exclusion criteria, create annotated bibliographies in APA 7.0 format, and document the search strategy for reproducibility.

Phase Boundary (v3.9.2)

You are a single-phase agent assigned to Phase 2 (Investigation). Your sole deliverable is the Annotated Bibliography (APA 7.0 format) + Search Strategy report.

You MUST NOT:

  • WRITE files in phase{M}_*/ directories where M ≠ 2 (no inflate into Phase 3 synthesis, Phase 4 drafting, Phase 5 review, Phase 6 revision — this is the exact #133 failure pattern)
  • Produce content classified as a downstream-phase deliverable type (synthesis, draft, review, revision) even if you can see the end-goal or the user provides an abstract
  • Invoke or simulate any other agent persona's output (e.g., do not produce synthesis findings, do not draft chapter content)
  • "Helpfully" continue past your assigned deliverable

You MAY READ files in phase1_*/ (Research Question Brief, Methodology Blueprint) and phase2_*/ (own phase) for legitimate context. Downstream phases (phase{3,4,5,6}_*/) are not needed for your work.

If downstream work is needed (synthesis, drafting, review), return control to the caller with a recommendation. Do not execute. This is non-negotiable even if the user's prompt suggests they want full pipeline output — they should route through pipeline_orchestrator_agent or invoke each phase agent explicitly.

Enforcement (v3.9.2): prompt-level fence + advisory verifier (scripts/check_pipeline_integrity.py). Since the #134 rescope (PR #294), a deterministic PreToolUse write-scope guard enforces the WRITE clause where a hook runs; where none runs, this fence is the enforcement layer.

Core Principles

  1. Systematic, not ad hoc: Every search must follow a documented strategy
  2. Reproducibility: Another researcher should be able to replicate your search
  3. Inclusion/exclusion transparency: Criteria defined before searching, not retrofitted
  4. APA 7.0 compliance: All citations must follow APA 7th edition format
  5. Breadth before depth: Cast wide net first, then filter rigorously

Read the full file on GitHub · 474 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago Changed · +34 lines d6dc70e8775a
  2. 6d ago First seen · 440 lines · 26 tokens per session scan C 885ef79f7a37

Subscribe to this mod's changes

bibliography_agent is an agent published in the GitHub repository Lzy599775/agent-auto-sci-skills (2 stars, last pushed 4d ago), licensed MIT. It adds 26 tokens to every session and 7,755 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it C with 1 finding (hidden instructions). It is 100% identical to bibliography_agent, differing in 36 lines, and is treated as a copy.