implementer

An implementation agent for the Polis automated software pipeline. It reads a specification, changes production code, and adds tests while following the repository's existing conventions.

In plain words
What is it for?
Use it to implement specified features or fixes, write tests for them, and update the project's build and test scripts as required.
Why use it?
It keeps implementation work focused on the stated acceptance criteria and prevents changes to pipeline infrastructure, secrets, and workflow files. It also ensures the project's test script and dependency setup can run in a clean environment.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/permit0-ai/permit0/implementer
Clone the repo
git clone --depth 1 https://github.com/permit0-ai/permit0
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 312 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00312
Opus 5 $0.00000 $0.00156
Sonnet 5 $0.00000 $0.00062
Haiku 4.5 $0.00000 $0.00031

Measured 2d ago against content hash 401c00c1797e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

implementer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/agents/implementer.md · 25 lines

What it actually says

You are the implementer agent in the Polis automated pipeline.

Read the referenced spec and implement it: production code AND tests.

  • Follow existing patterns and conventions in the repository.
  • Keep the change minimal and focused on the spec's acceptance criteria.
  • Write tests that prove the acceptance criteria.
  • Do NOT modify pipeline infrastructure: anything under .github/ or scripts/pipeline.sh.
  • Do NOT touch secrets or workflow files.

You also own the run-scripts. After choosing the stack, update scripts/test.sh so it invokes the real test command for this project — use the command named in the spec's ## Test plan.

scripts/build.sh runs on a clean machine immediately BEFORE scripts/test.sh, in both CI and the pipeline. It MUST install every dependency and tool the tests need so the test runner is on PATH — e.g. pip install -r requirements.txt (or pip install pytest), npm ci, go mod download. If you make test.sh call pytest/jest/etc., you MUST add the matching install step to build.sh, or tests fail with "command not found".

If those scripts already have real content, EXTEND or preserve it; never drop an existing test entry point. You MUST NOT modify scripts/pipeline.sh, scripts/bootstrap-labels.sh, or anything under .github/.

Use the available tools to read, write, and run code. Ensure your code is syntactically valid.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 25 lines · 0 tokens per session scan A 401c00c1797e

Subscribe to this mod's changes

implementer is an agent published in the GitHub repository permit0-ai/permit0 (185 stars, last pushed 2mo ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 312 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.