chezmoi

chezmoi is an agent for coding agents from rios0rios0/guide. It costs 54 tokens per session (2,545 once invoked), scanned A, original, MIT.

An assistant focused on chezmoi, a tool that manages configuration files across computers. It covers templates, setup scripts, encrypted files, platform-specific settings, and apply errors.

In plain words
What is it for?
Editing chezmoi files, testing templates, managing encrypted settings, and troubleshooting configuration deployment.
Why use it?
It helps you change shared configuration safely when the same files must work on systems such as Linux, Windows, and Android. It also helps diagnose what chezmoi will deploy.

Agent

Part of the engineering-standards plugin — 5 skills, 8 commands, 7 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/rios0rios0/guide/chezmoi
Clone the repo
git clone --depth 1 https://github.com/rios0rios0/guide

Or install engineering-standards, the plugin that ships this one along with the rest of its 5 skills, 8 commands, 7 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for chezmoi

README.md
[![agentmods](https://agentmods.dev/badge/agents/rios0rios0/guide/chezmoi.svg)](https://agentmods.dev/agents/rios0rios0/guide/chezmoi)
Your own site
<a href="https://agentmods.dev/agents/rios0rios0/guide/chezmoi"><img src="https://agentmods.dev/badge/agents/rios0rios0/guide/chezmoi.svg" alt="Measured on agentmods" height="20"></a>
Per session 54 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,545 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00054 $0.02545
Opus 5 $0.00027 $0.01273
Sonnet 5 $0.00011 $0.00509
Haiku 4.5 $0.00005 $0.00254

Measured 4d ago against content hash aafd571b13c0, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

chezmoi scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/workflows/generate-ai-rules/agents/chezmoi.md · 212 lines

How it starts

The opening of the file, as written. The whole thing — 212 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are a chezmoi dotfiles specialist. This repository manages cross-platform dotfiles targeting Linux (Kali on WSL), Windows 11, and Android (Termux) using chezmoi with 1Password CLI for secrets and age for encryption.

Essential Commands

chezmoi status                        # show managed files and state
chezmoi diff                          # preview pending changes
chezmoi apply --dry-run --verbose     # test without applying
chezmoi apply --verbose               # apply configuration
chezmoi update                        # pull repo + apply
chezmoi cat ~/.ssh/config             # decrypt and display encrypted file
chezmoi execute-template < file.tmpl  # test template rendering
chezmoi doctor                        # diagnose issues
chezmoi add --encrypt ~/.secret       # add file with age encryption

File Naming Conventions

Prefix/Suffix Meaning
dot_ Becomes . in target (dot_zshrc -> ~/.zshrc)
.tmpl Processed as Go template before deployment
encrypted_*.age Age-encrypted, decrypted on apply
run_once_before_* Script runs once before file deployment
run_after_* Script runs after every chezmoi apply
modify_* Script receives current file on stdin, outputs merged result
private_ Deployed with restricted permissions (0600)

Go Template Syntax Reference

1Password Functions (results cached per arguments within a single chezmoi apply)

{{/* Fetch entire item — returns object with .fields array */}}
{{- $item := onepassword "Active SSHs" "personal" "my" -}}

{{/* Read single field by URI path */}}
{{- $title := onepasswordRead (printf "op://Private/%s/title" .value) "my" | trim -}}

{{/* Fetch all fields as map — 1 call, then free lookups */}}
{{- $f := onepasswordItemFields .value "Private" "my" -}}
{{- $username := (index $f "ssh username").value -}}
{{- $publicKey := (index $f "public key").value -}}

Prefer onepasswordItemFields over multiple onepasswordRead calls to minimize op CLI invocations (each takes ~2-3s on Android through proot).

Read the full file on GitHub · 212 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 212 lines · 54 tokens per session scan A aafd571b13c0

Subscribe to this mod's changes

chezmoi is an agent published in the GitHub repository rios0rios0/guide (2 stars, last pushed 2d ago), licensed MIT. It adds 54 tokens to every session and 2,545 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

cpp-reviewer

Expert C++ code reviewer specializing in memory safety, modern C++ idioms, concurrency, and performance. Use for all C++ code changes. MUST BE USED for C++ projects.

affaan-m/ECC · 41 tokens

dynamic-agents

Dynamic agents use functions instead of static values for instructions, model, and tools. These functions receive runtime context and return the appropriate configuration for each operation.

VoltAgent/voltagent · 0 tokens

confluence-searcher

Searches Confluence and related tickets for product, architecture, rollout, and test-data context. Use when implementation or verification needs internal documentation without loading raw pages into main context.

HoangNguyen0403/agent-skills-standard · 40 tokens

pixel-art-animation-reviewer

Independent reviewer of pixel-art ANIMATION quality (loop seamlessness, motion physics, multi-component motion, frame timing, period selection, particle determinism). One of four specialized review roles in the pixel-art-quality-board orchestrator. Use when the user asks to "check animation timing", "verify loop…

AnastasiyaW/codex-claude-code-config · 140 tokens

seo-meta-optimizer

Creates optimized meta titles, descriptions, and URL suggestions based on character limits and best practices. Generates compelling, keyword-rich metadata. Use PROACTIVELY for new content.

echoVic/blade-code · 39 tokens

answered-questions-subagent

Processes answered questions from plan.json and incorporates them into relevant tasks.

closedloop-ai/claude-plugins · 19 tokens