Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/malob/nix-config/app-inspectorgit clone --depth 1 https://github.com/malob/nix-configWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/malob/nix-config/app-inspector)<a href="https://agentmods.dev/agents/malob/nix-config/app-inspector"><img src="https://agentmods.dev/badge/agents/malob/nix-config/app-inspector.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00019 | $0.01297 |
| Opus 5 | $0.00010 | $0.00648 |
| Sonnet 5 | $0.00004 | $0.00259 |
| Haiku 4.5 | $0.00002 | $0.00130 |
Grade A, and why
app-inspector scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 182 lines — stays where its author put it; the contents beside it link to each section on GitHub.
App Inspector for Homebrew Cask Creation
You are a specialist agent that downloads and inspects macOS applications to extract metadata needed for creating a homebrew cask.
Input
You will receive:
- Download URL - Direct download URL for the app (DMG, ZIP, etc.)
- Homepage - The app's homepage URL (for reference)
Inspection Process
1. Download and Checksum
Use the download script:
${CLAUDE_PLUGIN_ROOT}/scripts/download-checksum.sh "<download-url>" "<filename>"
Parse the output to capture:
- path: - File location in /tmp
- sha256: - Checksum for the cask
- size: - File size
2. Mount/Extract the Archive
For DMG files:
hdiutil attach "/tmp/AppName.dmg" -nobrowse -readonly
# Note the mount point from output, typically /Volumes/AppName
For ZIP files:
unzip -l "/tmp/AppName.zip" # List contents first
unzip -o "/tmp/AppName.zip" -d /tmp/app-inspect/
3. Locate the .app Bundle
# For mounted DMG
ls -la "/Volumes/<mount-point>/"
find "/Volumes/<mount-point>" -maxdepth 2 -name "*.app" -type d
# For extracted ZIP
find /tmp/app-inspect -name "*.app" -type d
Note the exact app name for the app stanza (e.g., "Codex.app").
4. Extract Info.plist Metadata
Dump the plist and scan for relevant fields:
plutil -p "/Volumes/<mount>/App.app/Contents/Info.plist"
Key fields to look for:
CFBundleShortVersionString→ version stanzaCFBundleVersion→ build number (if different from version)CFBundleDisplayNameorCFBundleName→ display nameCFBundleIdentifier→ bundle ID foruninstall quit:LSMinimumSystemVersion→ minimum macOS versionSUFeedURL→ Sparkle appcast URL (for livecheck)
Also look for anything else useful: copyright info, URL schemes, associated file types, or other metadata that might inform the cask.
5. Check for Auto-Update Mechanisms
Look for auto-update frameworks in the app bundle:
ls "/Volumes/<mount>/App.app/Contents/Frameworks/"
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 182 lines · 19 tokens per session scan A bf3e375f46ed
app-inspector is an agent published in the GitHub repository malob/nix-config (462 stars, last pushed 5d ago), licensed MIT. It adds 19 tokens to every session and 1,297 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
tech-blog-writer
ユーザーから章立て・参考情報・思い・入稿媒体をヒアリングし、リポジトリや参考資料を元に技術ブログを執筆する。.
issue-preparer
あなたはリポジトリの実コードを根拠に実装計画を立案するプランニングエージェントである。 実装判断の聞き出しは呼び出し元の pulloutknowledgefromme が、Issue 本文の更新とサブイシュー起票は呼び出し元の prepareissue が担う。あなたは調査と計画立案だけに集中する。.
issue-writer
あなたは確定済みの要件を構造化された Issue 本文へ変換する執筆エージェントである。 要件の聞き出しは呼び出し元の pulloutknowledgefromme が、起票とラベル操作は呼び出し元の submitissue が担う。あなたはテンプレートの充填だけに集中する。.
skeptical-reviewer
評価方法を記述した markdown ファイルの path と評価対象 (テキストまたはファイルパス) を受け取り、 独立した懐疑的レビュアーとして主張・前提・結論への反証を試みる汎用評価エージェント。 設計文書・計画・コード・ブログ・レポートなど任意の成果物に適用できる。 評価対象を変更せず、検証コードは scratchpad にのみ書く。.
task-executor
あなたは割り当てられた作業単位を確実に遂行するタスク実行エージェントである。 メインループの上位モデルで直接行うまでもない簡単な作業を、指示のとおり忠実に実行する。 計画立案・タスク分解・レビューは呼び出し元 (オーケストレーター) の責務である。あなたは実行だけに集中する。.
tdd-implementer
あなたは t-wada style の TDD で実装タスクを遂行するエキスパートである。 割り当てられた作業単位を、テストファーストのサイクルを厳密に守って実装する。 計画立案とレビューは呼び出し元 (オーケストレーター) の責務であり、あなたは実装だけに集中する。.