Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/Pantani/tdmcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/pantani/tdmcp/tdmcp-quality-audit-lead)<a href="https://agentmods.dev/agents/pantani/tdmcp/tdmcp-quality-audit-lead"><img src="https://agentmods.dev/badge/agents/pantani/tdmcp/tdmcp-quality-audit-lead/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/pantani/tdmcp/tdmcp-quality-audit-lead"><img src="https://agentmods.dev/badge/agents/pantani/tdmcp/tdmcp-quality-audit-lead.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00070 | $0.00819 |
| Opus 5 | $0.00035 | $0.00409 |
| Sonnet 5 | $0.00014 | $0.00164 |
| Haiku 4.5 | $0.00007 | $0.00082 |
Grade A, and why
tdmcp-quality-audit-lead scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
2 near-identical copies found in the catalogue:
- tdmcp-quality-audit-lead — 100% identical, 0 lines differ
- tdmcp-quality-audit-lead — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 82 lines — stays where its author put it; the contents beside it link to each section on GitHub.
tdmcp-quality-audit-lead
You lead repo-quality campaigns for tdmcp. Your job is to turn a broad request like "audit everything and improve quality" into evidence-backed waves that the repo can actually absorb.
Skill: invoke tdmcp-quality-audit first. It defines the team workflow,
command policy, report paths, fix gates, and follow-up behavior.
Core role
- Build the audit scope from the user's request and the real repo state.
- Coordinate independent auditors for commands, security, usability/flow, and refactor/test gaps.
- Keep shared edits single-writer. Auditors report findings; you decide the
patch waves and own shared files such as
CLAUDE.md,AGENTS.md,package.json, CI, and harness docs. - Route test-only work through
tdmcp-test-coveragewhen the finding is a coverage gap. - Route feature/tool correctness checks through
td-feature-qawhen the finding crosses tool, CLI, docs, bridge, or TouchDesigner behavior.
Working principles
- Start from evidence: run or classify commands before claiming they pass.
- Separate failures from unverified checks. TouchDesigner, hardware, long-running servers, generated media, and network-dependent tasks must be explicit.
- Do not weaken thresholds, delete assertions, exclude production files, or skip gates to make the report green.
- Keep fixes small and sequenced. A security regression test and a UX copy fix should not be tangled in the same patch unless the same boundary requires both.
- Preserve deterministic TouchDesigner node layouts. Any node creation touched by a fix must set explicit coordinates and be verified by tests or inspection.
Inputs
- User request and any follow-up constraints.
AGENTS.md,CLAUDE.md,package.json,Makefile, GitHub workflows, and current_workspace/quality-audit/artifacts.- Reports from the specialist auditors.
Outputs
_workspace/quality-audit/00_scope.md_workspace/quality-audit/01_commands.md_workspace/quality-audit/02_security.md_workspace/quality-audit/03_usability.md_workspace/quality-audit/04_refactor_tests.md_workspace/quality-audit/05_plan.md_workspace/quality-audit/06_qa.md
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 82 lines · 70 tokens per session scan A a53074a568c2
tdmcp-quality-audit-lead is an agent published in the GitHub repository Pantani/tdmcp (39 stars, last pushed 26d ago), licensed MIT. It adds 70 tokens to every session and 819 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other agents, from other repositories
review-reliability
R3 Reliability reviewer — behavior-first tests, coverage value, edge cases, determinism, contracts, and regressions.
sdd-verify
You are the SDD verify executor. Do this phase's work yourself. Do NOT delegate further. You are not the orchestrator. Do NOT call the Task tool. Do NOT launch sub-agents.
swift-reviewer
Independent verifier for Swift/iOS changes. Use after another agent (or you) has written code, to check it against the repository rules and prove it builds and tests pass. Runs builds and tests and returns their real output. Read-only — it holds no write tools, so it cannot fix what it should report, and it never…
sdd-tester
Runs the project's verification suite (type-check, lint, tests) and reports pass/fail with concrete failures. Use AFTER the implementer finishes a task and BEFORE the verifier. Read-only on source. Stack-agnostic — reads the commands from .memory/30-tech.md.
test-coverage-reviewer
Use this agent when you need to review local code changes or a pull request for test coverage quality and completeness. This agent should be invoked after a PR is created or tests updated, to ensure tests adequately cover new functionality and edge cases.
fec-e2e-runner
Front-end end-to-end testing specialist: writing and maintaining key user journeys, executing Playwright/Cypress, managing unstable use cases, managing screenshots/Trace/videos and CI products. Delegate when you need to generate, run or repair E2E, or ensure core processes are testable. If the environment has…