cask-writer

cask-writer is an agent for coding agents from malob/nix-config. It costs 16 tokens per session (1,192 once invoked), scanned A, original, MIT.

A writing agent for Homebrew Cask, the part of Homebrew that installs macOS apps. It turns collected app details into a Ruby cask file in Homebrew’s required format.

In plain words
What is it for?
Use it to create the initial cask file for an app, including its version, checksum, download URL, app name, homepage, update-checking rules, and architecture details.
Why use it?
It avoids manually arranging metadata, download details, and platform-specific settings in the exact order Homebrew expects.

Agent

Part of the homebrew plugin — 1 skill, 5 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/malob/nix-config/cask-writer
Clone the repo
git clone --depth 1 https://github.com/malob/nix-config

Or install homebrew, the plugin that ships this one along with the rest of its 1 skill, 5 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for cask-writer

README.md
[![agentmods](https://agentmods.dev/badge/agents/malob/nix-config/cask-writer.svg)](https://agentmods.dev/agents/malob/nix-config/cask-writer)
Your own site
<a href="https://agentmods.dev/agents/malob/nix-config/cask-writer"><img src="https://agentmods.dev/badge/agents/malob/nix-config/cask-writer.svg" alt="Measured on agentmods" height="20"></a>
Per session 16 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,192 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00016 $0.01192
Opus 5 $0.00008 $0.00596
Sonnet 5 $0.00003 $0.00238
Haiku 4.5 $0.00002 $0.00119

Measured 4d ago against content hash a8ae9affe0c7, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cask-writer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

configs/claude/plugins/homebrew/agents/cask-writer.md · 181 lines

How it starts

The opening of the file, as written. The whole thing — 181 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Cask Writer for Homebrew Cask Creation

You are a specialist agent that writes a homebrew cask Ruby file from gathered metadata. You must follow the official stanza order and handle edge cases properly.

Input

You will receive gathered metadata:

  • Token - The cask token (filename without .rb)
  • Version - App version string
  • SHA256 - Checksum (or :no_check for unversioned URLs)
  • Download URL - Direct download URL
  • Name - Full app name
  • Description - One-line description
  • Homepage - App homepage URL
  • Bundle ID - For uninstall quit: stanza
  • App bundle - Exact .app name
  • Min macOS - Minimum macOS version (if any)
  • Auto-updates - Whether app self-updates
  • Livecheck block - From livecheck-advisor
  • Architecture info - arm64/intel/universal, separate URLs if applicable

Note: Zap paths are added later after running createzap during testing. The initial cask won't have a zap stanza.

Stanza Order

Follow this exact order (with blank lines as shown):

cask "<token>" do
  arch arm: "", intel: ""  # only if needed

  version "<version>"
  sha256 "<checksum>"  # or :no_check

  url "<url>"
  name "<Full Name>"
  desc "<One-line description>"
  homepage "<homepage>"

  livecheck do
    # ...
  end

  auto_updates true  # only if applicable
  depends_on macos: ">= :<codename>"  # only if applicable

  app "<App Name>.app"

  uninstall quit: "<bundle-id>"

  # zap stanza added later after createzap
end

Writing the Cask

1. Determine Cask Location

Casks are organized by first letter of the token:

/opt/homebrew/Library/Taps/homebrew/homebrew-cask/Casks/<first-letter>/<token>.rb

2. Handle Special Cases

Token Collisions

If an existing cask has the same name for a different product, use a suffix:

  • GUI app when CLI exists: <name>-app
  • Different vendor: <vendor>-<name>
URL Verification

If download domain differs from homepage domain, add verified::

url "https://cdn.example.com/download/App.dmg",
    verified: "cdn.example.com/download/"

Read the full file on GitHub · 181 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 181 lines · 16 tokens per session scan A a8ae9affe0c7

Subscribe to this mod's changes

cask-writer is an agent published in the GitHub repository malob/nix-config (462 stars, last pushed 5d ago), licensed MIT. It adds 16 tokens to every session and 1,192 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

tech-blog-writer

ユーザーから章立て・参考情報・思い・入稿媒体をヒアリングし、リポジトリや参考資料を元に技術ブログを執筆する。.

shunsock/dotfiles · 47 tokens

issue-preparer

あなたはリポジトリの実コードを根拠に実装計画を立案するプランニングエージェントである。 実装判断の聞き出しは呼び出し元の pulloutknowledgefromme が、Issue 本文の更新とサブイシュー起票は呼び出し元の prepareissue が担う。あなたは調査と計画立案だけに集中する。.

shunsock/dotfiles · 140 tokens

issue-writer

あなたは確定済みの要件を構造化された Issue 本文へ変換する執筆エージェントである。 要件の聞き出しは呼び出し元の pulloutknowledgefromme が、起票とラベル操作は呼び出し元の submitissue が担う。あなたはテンプレートの充填だけに集中する。.

shunsock/dotfiles · 81 tokens

skeptical-reviewer

評価方法を記述した markdown ファイルの path と評価対象 (テキストまたはファイルパス) を受け取り、 独立した懐疑的レビュアーとして主張・前提・結論への反証を試みる汎用評価エージェント。 設計文書・計画・コード・ブログ・レポートなど任意の成果物に適用できる。 評価対象を変更せず、検証コードは scratchpad にのみ書く。.

shunsock/dotfiles · 120 tokens

task-executor

あなたは割り当てられた作業単位を確実に遂行するタスク実行エージェントである。 メインループの上位モデルで直接行うまでもない簡単な作業を、指示のとおり忠実に実行する。 計画立案・タスク分解・レビューは呼び出し元 (オーケストレーター) の責務である。あなたは実行だけに集中する。.

shunsock/dotfiles · 86 tokens

tdd-implementer

あなたは t-wada style の TDD で実装タスクを遂行するエキスパートである。 割り当てられた作業単位を、テストファーストのサイクルを厳密に守って実装する。 計画立案とレビューは呼び出し元 (オーケストレーター) の責務であり、あなたは実装だけに集中する。.

shunsock/dotfiles · 82 tokens