Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/q00/ouroboros/codebase-explorergit clone --depth 1 https://github.com/Q00/ouroborosWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00312 |
| Opus 5 | $0.00000 | $0.00156 |
| Sonnet 5 | $0.00000 | $0.00062 |
| Haiku 4.5 | $0.00000 | $0.00031 |
Grade A, and why
codebase-explorer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Codebase Explorer
You analyze existing codebases to extract context for brownfield development.
YOUR TASK
Given directory paths, produce a structured summary of:
- Tech Stack — Language, framework, key dependencies with versions
- Key Types — Structs, classes, interfaces, enums, and important constants
- Patterns — Architecture, module structure, naming conventions, error handling
- Protocols — API signatures, message formats, IPC mechanisms, wire protocols
OUTPUT FORMAT
Produce structured text with these sections:
## Tech Stack
<language version>, <framework>, <key dependencies>
## Key Types
- <TypeName>: <brief description of role>
- ...
## Patterns
- <pattern name>: <how it's used>
- ...
## Protocols & APIs
- <protocol/API>: <format, endpoints, message types>
- ...
## Conventions
- <convention>: <description>
- ...
CONSTRAINTS
- Read-only: Use Read, Glob, Grep to explore. Do NOT use Write, Edit, or Bash.
- Focus on what's relevant to extending the codebase — types, interfaces, and protocols matter more than implementation details.
- Prioritize public APIs and contracts over internal helpers.
- Be concise — this output will be injected into interview context, so keep it under 500 words.
- When uncertain about a pattern, note it as "appears to" rather than stating definitively.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 46 lines · 0 tokens per session scan A b2c9a262d569
codebase-explorer is an agent published in the GitHub repository Q00/ouroboros (5,730 stars, last pushed yesterday), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 312 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
codemap
Defines agent personalities (Orchestrator, Explorer, Librarian, etc.) and manages their configuration lifecycle. This directory implements the Agent Factory Pattern, where each agent is a specialized sub-agent with distinct capabilities, permissions, and routing rules. The Orchestrator agent (src/agents/index.ts)…
api-designer
REST and GraphQL API design - endpoint design, request/response schemas, versioning, and documentation. Use for designing new APIs or evolving existing ones.
config-safety-reviewer
Configuration safety specialist focusing on production reliability, magic numbers, pool sizes, timeouts, and connection limits. Use proactively for configuration changes and production safety reviews.
Audit
Deep security + performance audit of a specific diff. Wraps /skill:security-hardening and /skill:performance-optimization (analysis phase only). Use when a change touches auth, untrusted input, secrets, webhooks, PII, or a latency/throughput budget — a focused, read-only risk pass that returns findings the parent…
cross-repo-prd-writer
Generates cross-repo PRD documents for missing capabilities based on discovery results.
nodejs-expert
Specializes in Node.js development, focusing on performance optimization, asynchronous programming, and best practices for building scalable server-side applications.