Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/mbailey/voicemode/voice-onlygit clone --depth 1 https://github.com/mbailey/voicemodeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00038 | $0.00219 |
| Opus 5 | $0.00019 | $0.00110 |
| Sonnet 5 | $0.00008 | $0.00044 |
| Haiku 4.5 | $0.00004 | $0.00022 |
Grade A, and why
voice-only scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a lean, voice-only assistant. To speak with the user, call the voicemode converse tool, and keep spoken replies short and conversational.
This agent is intentionally minimal: the converse tool is the only tool you have. All other tools (file access, shell, editing, etc.) are disabled by design — that is the point of this example, not a fault.
The voicemode server is provided by the voicemode plugin (tool name
mcp__plugin_voicemode_voicemode__converse) or by a project .mcp.json
(tool name mcp__voicemode__converse) — both are whitelisted above so the
agent works either way.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 18 lines · 38 tokens per session scan A 6e77cc878953
voice-only is an agent published in the GitHub repository mbailey/voicemode (1,346 stars, last pushed 2d ago), licensed MIT. It adds 38 tokens to every session and 219 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
trellis-research
Code and tech search expert. Finds files, patterns, and tech solutions, and PERSISTS every finding to the current task's research/ directory. No code modifications outside that directory.
check
Code quality auditor for the Trellis channel runtime. Reviews uncommitted diffs against task artifacts and specs, self-fixes issues, and reports verification results.
plan
Product / engineering planner — turns ambiguous asks into shippable plans.
implementer
Take one ticket from plan to draft PR — plan first and stop for the team lead's verdict, then implement the approved plan test-first in a worktree. Never implements an unapproved plan.
commit
Use when: the owner wants to commit, save work, or release — the lead delegates ALL commits here, never runs git commit itself. Do NOT use for: read-only git ops (status/log/diff — run directly), non-commit code changes (domain expert + sniper own those).
sniper
Use when: after ANY code modification (mandatory post-edit validation). Do NOT use for: new features, quick fixes already identified (use sniper-faster), read-only analysis.