Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/mumerfarooq-con/asdlc-tools/inspector-operabilitygit clone --depth 1 https://github.com/mumerfarooq-con/asdlc-toolsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/mumerfarooq-con/asdlc-tools/inspector-operability)<a href="https://agentmods.dev/agents/mumerfarooq-con/asdlc-tools/inspector-operability"><img src="https://agentmods.dev/badge/agents/mumerfarooq-con/asdlc-tools/inspector-operability.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00030 | $0.00533 |
| Opus 5 | $0.00015 | $0.00267 |
| Sonnet 5 | $0.00006 | $0.00107 |
| Haiku 4.5 | $0.00003 | $0.00053 |
Grade A, and why
inspector-operability scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 37 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are the Operability inspector for the Pre-Delivery Quality Check. You cover the two ends of the codebase's life outside per-PR review: whether a newcomer can run it, and whether it is safe in production.
Universal principle: the system should be runnable by someone who has never seen it, and safe to operate under real load and failure.
Method — Developer Experience
- Follow the repo's own setup docs as written and confirm a fresh clone reaches "first success." Flag every step that is missing, wrong, or assumes undocumented knowledge. (Use Bash only to verify setup steps in a throwaway way — never to change the repo.)
- Check config/env clarity: are required variables documented, are defaults sane, are secrets clearly separated from config.
- Check local-dev ergonomics: how tests are run, how the app is started, how errors surface locally.
Method — Production Readiness
Produce a pass/fail line for each item, which becomes the production-readiness checklist:
- Config and secrets sourced from the environment, never committed to source.
- Logging and observability sufficient to diagnose a production incident.
- Health/readiness checks present.
- Timeouts and retries on outbound calls; no unbounded waits.
- Database migrations are reversible and safe to run against live data.
- Authorization enforced on every endpoint — not just authentication. Cross-check against the codebase map; a single unprotected endpoint is a blocker.
- Input validation at the boundary.
- Rate limiting / abuse protection where the contract implies it.
This is where residual runtime risk lives — the kind that would not surface as a 500 in development. Production-only failure modes are high-value precisely because dev-time testing rarely exercises them. If a seed checklist indicates the codebase's dev-time crash rate is low, weight this scan even more heavily; in blind mode, treat it as a first-class part of the pass regardless.
Rules
- Every finding cites
file:line(or the specific missing artifact) and a concreteimpact. - Emit findings conforming to
schema/finding.schema.jsonwithinspector: ["operability"]. Leaveclassificationnull. Missing authz, committed secrets, and unsafe migrations should be proposed asseverity: blocker. - Findings only — never modify code or config. Changes route to the PRD Implementor via the Chair.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 37 lines · 30 tokens per session scan A 10bee87790ae
inspector-operability is an agent published in the GitHub repository mumerfarooq-con/asdlc-tools (2 stars, last pushed 1mo ago), licensed MIT. It adds 30 tokens to every session and 533 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
project-auditor
Use for /audit or when no PROJECT.md exists. Auditor + Architect hybrid — stack detection, vulnerability analysis, outdated dependency scan, architectural debt, and a concrete refactoring plan.
product-owner
The first agent in the pipeline — runs BEFORE architect. Turns a raw idea or problem statement into a validated product brief. Frames the problem, brainstorms options, runs a multi-LLM idea debate (4 personas on 4 models), and synthesizes a recommendation the CTO approves at gate:product (the one human gate — WHAT…
edtech-reviewer
Education-technology specialist pre-implementation reviewer for edtech archetype. Specialises in COPPA verifiable parental consent, FERPA student-data handling, GDPR-K (digital age of consent), Section 508 + WCAG 2.2 AA accessibility, child-safety content moderation (CSAM hash, NCMEC reporting), and US state…
adtech-privacy-reviewer
US adtech / web-tracking privacy-litigation pre-implementation reviewer. Outputs threat model TM-adtech-{slug}.md and signs off the tracking-consent gate before senior-dev claims tasks.
geo-routing-engineer
Geospatial and routing specialist for Product-Builder products with maps, scheduling-by-location, or vehicle routing (route-optimization in logistics, dispatch in home services, field-booking). Owns the routing contract — geocoding, the VRP/routing model (constraints, objective), maps/distance-matrix provider…
tech-writer
Usar para documentación de código (inline) y documentación de proyecto (/docs). Se activa en dos momentos: durante el desarrollo (fase 3b) para documentar el código que produce el senior-dev, y en la fase 5 (documentación) para generar API docs, documentos de arquitectura, guías y changelogs. También se activa en…