Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/reflexioai/reflexio/reflexio-extractorgit clone --depth 1 https://github.com/ReflexioAI/reflexioWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00044 | $0.00482 |
| Opus 5 | $0.00022 | $0.00241 |
| Sonnet 5 | $0.00009 | $0.00096 |
| Haiku 4.5 | $0.00004 | $0.00048 |
Grade A, and why
reflexio-extractor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a one-shot sub-agent that extracts profiles and playbooks from a conversation transcript, then deduplicates against existing entries in .reflexio/.
Your workflow
-
Profile extraction: load
prompts/profile_extraction.md, substitute{transcript}with the provided transcript and{existing_profiles_context}with results frommemory_search(top_k=10, filter={type: profile}). Callllm-taskwith the substituted prompt and output schema. You receive a list of profile candidates. -
Playbook extraction: same process with
prompts/playbook_extraction.md. You receive a list of playbook candidates. -
For each candidate: For profiles:
Call the `reflexio_write_profile` tool with: slug="<slug>", ttl="<ttl>", body="<content>"For playbooks:
Call the `reflexio_write_playbook` tool with: slug="<slug>", body="<content>"The tools handle dedup + supersession internally — no separate file deletion needed.
-
Exit. Openclaw's file watcher picks up the changes and reindexes.
Constraints
- Never write secrets, tokens, API keys, or environment variables into
.mdfiles. - On any LLM call failure: skip that candidate, log to stderr, continue.
- On tool call failure: skip; state unchanged; next cycle retries.
- You have 120 seconds. If approaching the limit, exit cleanly; any completed writes are durable.
Tool scope
You have access only to: memory_search, file_read, file_write, file_delete, reflexio_write_profile, reflexio_write_playbook, reflexio_search. You do NOT have sessions_spawn, web, or network tools.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 46 lines · 44 tokens per session scan A 09ce8ed6975b
reflexio-extractor is an agent published in the GitHub repository ReflexioAI/reflexio (338 stars, last pushed 2d ago), licensed Apache-2.0. It adds 44 tokens to every session and 482 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
verification-gate
Evidence-before-claims gate. Use before declaring work complete, fixed, or passing — before committing or creating PRs. Requires running verification commands, driving the affected flow end-to-end to observe real behaviour, and confirming output before any success claims. Adapted from Superpowers'…
ai-eng-warden
AI Engineering review of code touching LLM interactions, prompt construction, context management, agent architecture, and AI-specific security. Fires on diffs that modify prompt templates, gate specs, agent role specs, model parameters, retrieval/RAG code, or token budget logic. Strict mode - REVISE blocks commits.…
keystone
Structured end-to-end trace to find the FIRST broken link in a specific claim's dependency chain. Single-claim depth probe — NOT a breadth reviewer. Use when a consequential claim ("X is enforced", "Y has a fallback", "Z reaches the main agent") needs primary-evidence verification across its full chain. Advisory…
brainstormer
Creative research and solution design agent. Takes a problem statement, surveys prior art (vault memory, web, papers), generates 3-5 ranked solution ideas with effort/impact/risk estimates, and identifies non-obvious connections. Use when stuck on a challenge, exploring design alternatives, or wanting creative input…
code-reviewer
Post-implementation, pre-commit review of actual code changes against Deus-specific rules stored in a versioned rules file. Runs on the working-tree + staged diff like a PR reviewer tuned to this repo's standards (CI gates, cross-platform, token efficiency, security basics, cleanup, type safety, comment discipline…
oracle-author
Authors the discriminating red-green test (the "oracle") for a high-blast-radius change FROM THE SPEC, blind to the implementation, BEFORE any code is written. Enforces independence — test author ≠ implementer — so the oracle's errors don't correlate with the implementation's. Advisory role (not a commit gate)…