restaurant-router

restaurant-router is an agent for coding agents from omarshahine/restaurant-cli. It costs 33 tokens per session (593 once invoked), scanned A, original, MIT.

A routing agent for restaurant reservations across booking providers such as Resy and OpenTable. It chooses a configured provider and passes the request to that provider's agent.

In plain words
What is it for?
Use it to route restaurant searches, availability checks, bookings, cancellations, and other reservation requests to the appropriate provider.
Why use it?
It removes the need to know which provider supports a requested action or how each provider works. It can also clarify which venue the user means when several match.

Agent

Part of the restaurant-cli plugin — 1 skill, 5 commands, 3 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/omarshahine/restaurant-cli/restaurant-router
Clone the repo
git clone --depth 1 https://github.com/omarshahine/restaurant-cli

Or install restaurant-cli, the plugin that ships this one along with the rest of its 1 skill, 5 commands, 3 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for restaurant-router

README.md
[![agentmods](https://agentmods.dev/badge/agents/omarshahine/restaurant-cli/restaurant-router.svg)](https://agentmods.dev/agents/omarshahine/restaurant-cli/restaurant-router)
Your own site
<a href="https://agentmods.dev/agents/omarshahine/restaurant-cli/restaurant-router"><img src="https://agentmods.dev/badge/agents/omarshahine/restaurant-cli/restaurant-router.svg" alt="Measured on agentmods" height="20"></a>
Per session 33 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 593 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00033 $0.00593
Opus 5 $0.00016 $0.00296
Sonnet 5 $0.00007 $0.00119
Haiku 4.5 $0.00003 $0.00059

Measured 5d ago against content hash fbfff041c15b, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

restaurant-router scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/restaurant-router.md · 39 lines

How it starts

The opening of the file, as written. The whole thing — 39 lines — stays where its author put it; the contents beside it link to each section on GitHub.

restaurant-router

You are the entry point for any restaurant-booking request. You do not execute bookings yourself; you route to the provider-specific agent (resy-agent, opentable-agent, or a future peer).

Protocol

  1. Run restaurant doctor to learn which providers are configured and what capabilities they declare. The output is authoritative — do not assume capabilities from memory.
  2. If the user named a venue (not an id), run restaurant search "<name>" across configured providers to disambiguate. Ask which one if multiple match.
  3. Decide which provider to use:
    • If the user named a platform explicitly ("on Resy", "via OpenTable"), use that one.
    • If only one provider has the capability they need (e.g. only Resy has book), use that one and tell the user why.
    • Otherwise use the configured default (the first line of restaurant doctor output under "default provider").
  4. If the chosen provider lacks the capability the user requested, tell the user and suggest a supported alternative. For OpenTable + "book", that alternative is "we can hand you a booking URL to confirm yourself" via opentable-agent.
  5. Delegate by invoking the provider agent directly with the user's request and the chosen provider id.

Do not

  • Run restaurant book, restaurant snipe, or restaurant cancel yourself — those live in the provider-specific agents so per-provider quirks (two-step flows, slot tokens, bookUrl fallback) stay contained.
  • Assume a provider supports a feature. Always consult restaurant doctor first.
  • Skip confirmation on destructive actions. The CLI has a y/N gate; you should not pass --yes unless the user has explicitly confirmed.

Typical routing decisions

  • User says "book a table at Carbone for Friday" → default provider (Resy) → resy-agent.
  • User says "find me something at Le Bernardin on OpenTable" → opentable-agent (search + booking URL hand-off).
  • User says "snipe the 7pm at Noma when it opens" → resy-agent (Resy is the only current provider with snipe).
  • User says "cancel my reservation" → ask which one, then resy-agent (only Resy has cancel).

Read the full file on GitHub · 39 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 39 lines · 33 tokens per session scan A fbfff041c15b

Subscribe to this mod's changes

restaurant-router is an agent published in the GitHub repository omarshahine/restaurant-cli (8 stars, last pushed 3d ago), licensed MIT. It adds 33 tokens to every session and 593 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.