Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/pivanov/agents-wire/geminigit clone --depth 1 https://github.com/pivanov/agents-wireWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00509 |
| Opus 5 | $0.00000 | $0.00254 |
| Sonnet 5 | $0.00000 | $0.00102 |
| Haiku 4.5 | $0.00000 | $0.00051 |
Grade A, and why
gemini scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 77 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Gemini CLI
Agent ID: gemini
Google's Gemini CLI. Speaks ACP via a peer-installed bridge package.
Install
npm install -g @google/gemini-cli
gemini auth login
The @google/gemini-cli package must be installed as a peer - it is not bundled with agents-wire.
Quick Start
import { agents } from "@pivanov/agents-wire";
const result = await agents.ask(
"gemini",
"Summarize this PR",
{
permission: "auto-allow",
},
);
console.log(result.text);
Model Selection
options.model is forwarded as ACP modelPreference (best-effort). The gemini --acp
bridge does not accept CLI model flags, so model selection depends entirely on whether the
ACP bridge implements setSessionConfigOption. options.effort is sent via the same
mechanism (best-effort).
To see which models Gemini currently advertises for a session, read session.configOptions:
import { createSession } from "@pivanov/agents-wire";
const session = await createSession("gemini");
const opts = session.configOptions ?? [];
const modelOpt = opts.find((o) => o.configId === "model" && o.type === "select");
if (modelOpt && modelOpt.type === "select") {
console.log(modelOpt.options); // live model list from the agent
}
Capabilities
| Feature | Supported |
|---|---|
ask / stream / session |
✅ |
askJson |
✅ |
| MCP stdio | ✅ |
| MCP http/sse | ✅ |
Session listing (listSessions) |
❌ |
| Tool call interception | ✅ |
Cost Tracking
Gemini reports per-turn costUsd. Full cost tracking and maxCostUsd budget enforcement work.
Auth Failure Detection
If gemini auth login hasn't been run or credentials have expired, the SDK throws AgentUnauthenticatedError.
Gotchas
- The
@google/gemini-clipackage is a peer dependency - install it separately. - Session listing is not supported;
listSessions()throwsCapabilityNotSupportedError. - Gemini CLI requires a Google account with the Gemini API enabled, or a paid API key.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 77 lines · 0 tokens per session scan A 41fa3153a280
gemini is an agent published in the GitHub repository pivanov/agents-wire (5 stars, last pushed 3mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 509 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
codex-execute
Implement a SPECIFIC, well-defined plan or plan-step with Codex. Use ONLY when the user has a written plan, plan-step, named files, or acceptance criteria to execute ("execute this via codex", "implement this plan", "/codex:execute", or a --plan file is in context). Do NOT use when the user is stuck/exploring (use…
cursor-delegate
Delegate a SPECIFIC, well-defined implementation task or plan step to Cursor in agent mode on the Auto model. Cursor is the fast lane for mechanical writing — long file writes (200+ lines), pattern-following across many files, bulk refactors. Supports autonomous multi-step runs via --until-done. Pair with…
cursor-research
Delegate read-only EXTERNAL web/documentation research to Cursor. Use when the user wants current library/API/docs research, "what's the current way to…", or to compare approaches — and you'd rather not spend Claude's context on web reading. Cursor runs read-only (ask mode) with web search + fetch and returns findings…
opencode-research
Delegate read-only EXTERNAL web/documentation research to OpenCode. Use when the user wants current library/API/docs research, "what's the current way to…", or to compare approaches — and you'd rather not spend Claude's context on web reading. OpenCode runs read-only (ask mode) with web search + fetch and returns…
codex-rescue
Hand an OPEN-ENDED or stuck problem to Codex for independent investigation. Use ONLY when the user says "stuck", "second opinion", "rescue", "dig deeper", "I'm not sure why X", OR hands off a substantial unbounded task with no written plan. Do NOT use when a plan or plan-step file is in context (use codex-execute) or…
cursor-explore
Delegate quick read-only CODEBASE exploration to Cursor. Use to answer questions about the current repository ("where is X handled?", "how does Y flow?", "summarize the adapter layer") without spending Claude's tokens reading files. Cursor runs read-only (ask mode) using semantic search, grep, and its Explore…