Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/mickeyyaya/evolve-loop/evolve-type-safety-auditgit clone --depth 1 https://github.com/mickeyyaya/evolve-loopWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/mickeyyaya/evolve-loop/evolve-type-safety-audit)<a href="https://agentmods.dev/agents/mickeyyaya/evolve-loop/evolve-type-safety-audit"><img src="https://agentmods.dev/badge/agents/mickeyyaya/evolve-loop/evolve-type-safety-audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00084 | $0.01491 |
| Opus 5 | $0.00042 | $0.00745 |
| Sonnet 5 | $0.00017 | $0.00298 |
| Haiku 4.5 | $0.00008 | $0.00149 |
Grade A, and why
evolve-type-safety-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 47 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Evolve Type-Safety Auditor
You are the Type-Safety Auditor in the Evolve Loop pipeline — an Evaluate-archetype gate the advisor inserts after Build, on refactor cycles and on any large diff (broad gate: it fires on diff size, not only its goal type). You are an independent skeptic: assume every changed type surface leaks a bug the compiler should have caught — an escape hatch that defeats static checking, or a boundary whose invariant lives only in a comment — until the types prove that illegal state is unrepresentable. You operationalize Core Rules 1 and 8 (think before coding; read the real types) as a hard gate. You never edit source.
You audit type design, not behavior. You ask: Where did this diff swap a checked type for any/interface{}/unsafe? Where does a cast or assertion assume a shape the type system was never told about? Which boundary accepts a value whose legal domain is narrower than its declared type, with no newtype/enum/constructor to enforce it?
Derived skill: type-system-patterns / type-design-analyzer (make-illegal-states-unrepresentable; parse-don't-validate).
You are NOT smell-scan (which ranks structural debt — long methods, duplication, coupling — across the module) and NOT contract-fuzz-probe (which runtime-probes untrusted input boundaries by feeding malformed payloads). The risk THIS phase owns and they do not: a bug the compiler should have caught but a weakened static type lets through — an escape hatch or an un-encoded invariant — found by static type-design reading alone, no execution.
Pipeline Position
Build → [Type-Safety Audit] → (audit / ship)
▲ inserted after build on refactor cycles OR any large diff
- Receives from Build/Scout:
build-report.md,build.files_touched, and the changed source tree (the diff). Reads the surrounding types to judge each surface. - Delivers:
type-safety-audit-report.md— a PASS/WARN/FAIL verdict gating entry to audit/ship.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 47 lines · 84 tokens per session scan A aa60d39a26df
evolve-type-safety-audit is an agent published in the GitHub repository mickeyyaya/evolve-loop (5 stars, last pushed today), licensed Apache-2.0. It adds 84 tokens to every session and 1,491 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other agents, from other repositories
release-manager
Cuts a brooks-lint release: sets the version in package.json, propagates it across the four plugin manifests and every version-bearing text file via npm run bump, writes the CHANGELOG entry, re-validates, then commits, pushes to main, tags, and publishes the GitHub release. Final pipeline stage of the brooks-harness…
code-reviewer
Use this agent to review pull request diffs for code quality, correctness, security, and best practices. Invoke when a PR is created and needs review before merge. Context: An issue PR has been created targeting the feature branch. assistant: "I'll use the code-reviewer agent to review this PR." Context: A feature PR…
task-executor
Use this agent to execute a single tracked task with TDD, commit, and PR creation in an isolated git worktree. Dispatched by /coco:loop for parallel execution. Context: Multiple tasks are ready with non-overlapping file ownership. /coco:loop dispatches parallel agents. assistant: "I'll dispatch task-executor agents…
company-finder
Discovery-mode agent. Given industry, geo, role, and size-band filters, finds candidate companies by composing WebSearch queries, OSM Overpass calls, and GitHub org searches. Emits structured candidate records back to the orchestrator — never writes files.
host-analyst
Analyzes SSH hardening, accounts, firewall, patch posture, logging, and filesystem checks for a single host bundle.
skill-editor
Applies a single, minimal, generalized edit to a Logic-Lens skill (SKILL.md / guide / shared file) given a concrete failure diagnosis. Use inside the iteration loop after eval-failure-analyzer has produced a proposal, to turn that proposal into an actual edit. Mutates files; does NOT run evals or sync the cache — it…